Showing posts with label Energy Infrastructure Security. Show all posts
Showing posts with label Energy Infrastructure Security. Show all posts

Wednesday, June 17, 2020

S 3688 – Energy Infrastructure Security – Miscellaneous Provisions


This is the fifth in a series of posts about the introduction of S 3688, the Energy Infrastructure Protection Act of 2020. The earlier posts in the series were:

S 3688 Introduced – Energy Infrastructure Security
            S 3688 – Energy Infrastructure Security – Security Assistance to Energy Infrastructure
S 3688 – Energy Infrastructure Security – CEII disclosure authorization
In this blog post I will look at the last three sections that bill would add to the Federal Power Act:

§235. Designating information held by other governmental authorities,
§236. Wartime clearance,
§237. Enforcement and sanctions

Government Requests for CEII Designation


Section 235 establishes the procedures that will be used by eligible government entities to request the designation of information as Critical Electrical Infrastructure Information (CEII). In this section the term ‘eligible entities’ is defined as {§235(a)(1)}:

• A Federal, State, political subdivision, or Tribal authority [excluding DOE and FERC], and
• A utility owned or operated by 1 or more of the authorities above, including a joint action agency or similar entity.

While those agencies fall within the ‘any individual or entity’ terminology used in §231(c)(3)(B) authority to request CEII designation, requests under §235 require DOE or FERC, if they approve CEII designation, to apply that designation for 10 years, not the general period “the information is related to energy infrastructure in service” standard established under §231(c)(9)(A).

Paragraph (d) makes the requesting government entity responsible for the defense “against any claim for disclosure of the designated information” {§235(d)(2)}, not DOE or FERC.

Wartime Clearance


Section 236 allows DOE and FERC to loosen CEII disclosure rules “during the state of war or period of national disaster due to enemy attack” {§236(a)}. That loosening of disclosure rules is limited to the authority “to confer with individuals and grant individuals access to critical electric infrastructure information pending further investigation of those individuals”.

Enforcement


Section 237(a) provides that any entity that does not return an item of CEII within 90 days of a request by DOE or FERC will be subject to enforcement under 16 USC 825m, §825o, and §825o-1.

Section 237(b) requires DOE and FERC to establish appropriate sanctions for knowingly and willfully disclosing critical electric infrastructure information in a manner that is not authorized under this new subpart of the Federal Power Act. It specifically provides that the minimum sanctions for FERC Commissioner or former Commissioner who knowingly and willfully discloses CEII in an unauthorized manner will be {§237(b)(1)(A)}:

• The potential loss of access to critical electric infrastructure information; and
• The potential public issuance of letters of reprimand.

Sunday, June 14, 2020

S 3688 – Energy Infrastructure Security – CEII disclosure authorization


This is the fourth in a series of posts about the introduction of S 3688, the Energy Infrastructure Protection Act of 2020. The earlier posts in the series were:

S 3688 Introduced – Energy Infrastructure Security
            S 3688 – Energy Infrastructure Security – Security Assistance to Energy Infrastructure

Disclosure Exceptions


In general, §234 provides that neither DOE nor FERC may disclose Critical Energy Infrastructure Information (CEII), but paragraph (a) provides a long list of exceptions of persons to whom CEII disclosure is authorized. DOE and FERC are allowed to disclose CEII to {§234(a)(2)}:

• To the source of the information;
• To a party or participant in a proceeding before the Secretary or the Commission;
• To an individual who is an officer, employee, agent, or contractor of the Secretary or the Commission;
• To an officer, employee, agent, or contractor of the Electric Reliability Organization, a regional entity; or an information sharing and analysis center;
• To an officer, employee, agent, or contractor of the Federal Government;
• To the President, the National Security Council, a member of Congress, a Federal judge or magistrate, or any officer of the United States appointed by the President with the advice and consent of the Senate;
• To an individual who is an officer, employee, agent, or contractor of Congress, the Executive Office of the President, or a court created under article I or III of the Constitution of the United States;
• To a landowner the property of which has a boundary that is crossed by, or located within the vicinity of, energy infrastructure (with specific caveats);
• To an officer, employee, agent, or contractor of an authority of a State, political subdivision, or Indian Tribe, if each individual seeking access to the information has entered into a nondisclosure agreement with the Secretary or Commission, as applicable;
• To an individual holding a security clearance at the level of top secret or higher; or
• To any other individual, if the source of the information has given express consent to the disclosure of the information to the individual and there is an approved nondisclosure agreement between the source of the information and the party to whom the information will be released.

Subparagraph (a)(2)(B) provides a separate authority to disclose CEII ‘academic, scientific or research purposes’ [actually, I think that should have read ‘academic or scientific research purposes’ but I may be mistaken]. That authorization is predicated upon:

• The receiving individual holds a Top Secret clearance,
• The source of the information provides specific consent, and
• There is a nondisclosure agreement between the source of the information and the individual that will be provided access to the CEII.

In both cases where a nondisclosure agreement between the source of the information and the individual being provided access by DOE or FERC, there is an additional requirement that the nondisclosure agreement must be approved by an administrative law judge from DOE or FERC respectively.

Subparagraph (a)(2)(C) reiterates that the authority to release CEII is not a requirement to release CEII to “any individual or entity” {§234(a)(2)(C)(i)(I); DOE or FERC “may withhold disclosure of critical electric infrastructure information at any time, for any reason, at the sole discretion of the Secretary or the Commission, as applicable”.

Nondisclosure Agreements


Paragraph (b) of §234 establishes the standards for nondisclosure agreements (NDAs) authorized or approved under the section. In general, the NDAs will {§234(b)(1)}:

• Reflect the individual circumstances concerning the parties to the agreement,
• Permit the auditing of compliance with the agreement, and
• Be enforceable in law and equity by any district court of the United States.

In addition to instances in paragraph (a) where NDAs are require between recipients of CEII and the source of the information, subparagraph (b)(3) allows DOE or FERC to require NDAs between recipients and the releasing authority.

Disclosure of Indicators, Methods or Tools


Paragraph (c) allows DOE or FERC to “disclose indicators, methods, and tools that have been used in penetrating or defending energy infrastructure” as long as:

• The source of the information consents to the release of that information; and
• The Secretary or the Commission, as applicable, removes all information that would enable an individual to identify the source of the information.

Again, we have reached a reasonable stopping point for this post. There are only three more sections of the bill to go.

Monday, June 8, 2020

S 3688 – Energy Infrastructure Security – Security Assistance to Energy Infrastructure


This is the third in a series of posts about the introduction of S 3688, the Energy Infrastructure Protection Act of 2020. The earlier posts in the series were:

S 3688 Introduced – Energy Infrastructure Security

FERC Assistance


The bill would add §232, Authority of the commission to offer assistance to owners and operators of energy infrastructure to the Federal Power Act. The new section would allow the Commission, upon request, to assist an ‘eligible entity’ by {§232(b)}:

• By reviewing the configuration of the assets of the eligible entity against threats,
• By reviewing the capability of the eligible entity to operate its assets after attacks on those assets,
• By providing information about methods and tools that owners and operators of energy infrastructure may use to defend assets against threats,
• By providing information regarding other resources that may be available to assist the eligible entity, and
• By reviewing data and other assets in the possession of the eligible entity for evidence that the data or other asset has been tampered with; or otherwise been the subject of threat activity.

The term ‘eligible entity’ is defined as {§232(a)}:

• An authority of a State, political subdivision, or Indian Tribe,
• A Transmission Organization,
• An electric utility,
• A natural-gas company,
• An oil pipeline, and
• Any other owner or operator of energy infrastructure

Paragraph (c) directs that any information collected or created by FERC in providing assistance under this section will be treated as if were Critical Electrical Infrastructure Information (CEII). If the information providing organization consents to release of the information, FERC is authorized to share the information with {§232(c)(2)(A)}:

• The Electric Reliability Organization;
• A regional entity;
• An information sharing and analysis center; or
• An authority of a State, political subdivision, or Indian Tribe that is involved in protecting energy infrastructure from threats.

FERC would be allowed to require advanced authorization to share the information with the organizations described above as a prerequisite to providing assistance under this section. Additionally, FERC is authorized to share any information with other Federal agencies under the condition that those agencies protect the information as CEII.

Paragraph (d) allows a requesting entity to withdraw their request for assistance form FERC. Upon receipt of such a request will terminate its actions and return information provided by the requestor to the requestor.

Paragraph (e) prevents FERC from using information provided for the purposes of obtaining assistance “as a basis for any order, rule, opinion, or decision of the Commission” {§232(e)(1)}.

DOE Assistance


The bill would add §233, Authority of the secretary to offer assistance to owners and operators of energy infrastructure, to the Federal Power Act. Many of the provisions from §232 are duplicated in this section. There are some additional provisions found in §233.

In paragraph (b) two new items are added to the areas for which DOE can provide assistance to eligible entities (same definition for that term as in §232):

• By monitoring sensor data and other information flows of the eligible entity, and
• By testing equipment and other assets of the eligible entity.

Paragraph (c) has no counterpart in §232; it requires DOE to carry out a program of research to “gather information about the tools and methods that have been used to penetrate or defend any eligible entity or industrial control systems” {§232(c)(1)}. This would include tools or techniques developed by DHS, DOD, any other Federal agency or “any eligible entity”. The research would be directed to developing a plan “to ensure that the Federal Government has access to energy infrastructure during a time of war or national crisis” {§232(c)(2)} as well as a plan for “the response of the Secretary in the event that owners and operators of energy infrastructure are attacked” {§232(c)(3)}.

The remaining provisions of this section contain the same language found in §232.

Again, we have reached a reasonable stopping point for today’s post.

Sunday, June 7, 2020

S 3688 – Energy Infrastructure Security – CEII Changes


This is the second post about the introduction of S 3688, the Energy Infrastructure Protection Act of 2020. In the initial post I talked about the organizational changes the bill proposes for the Federal Power Act and the definitional changes proposed. In this post I will look at the changes the bill would make in the Critical Electric Infrastructure Information (CEII) program.

CEII Designation


Section 3(c) of the bill would revise §215(d), “Protection and sharing of critical electric infrastructure information”, of the Federal Power Act {16 USC 824o-1(d)(2)} [after changing the designation of that subsection to §231(c)].

First, paragraph (2), “Designation and sharing of critical electric infrastructure information”, is re-written, removing reference to sanctions {existing (2)(C)} and the ‘standards of the Electric Reliability Organization’ {existing (2)(D)}.

Then, paragraph (3), “Authority to designate”, is greatly expanded. The existing language is essentially rewritten as subparagraph (A). Then two new subparagraphs were added:

(B) Submission of request for designation, and
(C) Conflicts between designations by the secretary and the commission

Subparagraph (B) would allow anyone to request that either the Secretary or FERC designate any information in the respective agency’s possession as CEII. Upon receipt of such a request the agency would be required to treat the requested information as CEII until it is actually designated as such or 21 days after the agency notifies the requestor that the information was not so designated.

Subparagraph (C) would require the Department and FERC to confer anytime that there was a conflicting decision made on whether a specific piece of information would be designated as CEII. Absent a mutual resolution of such conflicts, each agency would be allowed to rely on its own designation in the protection of the information.

Segregation of CEII


Changes would also be made to the existing §215(d)(8), “Disclosure of nonprotected information” [re-designated §231(c)(8)]. The poorly named paragraph currently requires DOE and FERC to “segregate critical electric infrastructure information or information that reasonably could be expected to lead to the disclosure” of CEII within documents or communications. The new language would ease that requirement somewhat by changing “shall segregate” to “shall reasonably attempt to segregate”.

A new subparagraph (B) was added to provide legal cover for that easing of the segregation requirement by specifically noting that any such failure to segregate CEII in a document “shall not result in an inference or finding that the information should not be entitled to protection as critical electric infrastructure information”.

Duration of Designation


Paragraph §215(d)(9), “Duration of designation” [re-designated §231(d)(9)], is completely rewritten. The reference to the ‘5 year’ limitation on CEII designation is removed. The replacing limitation in the new subparagraph (A) would be not “for a period longer than the information is related to energy infrastructure in service”. Even for that broader limit an exception is provided, allowing DOE or FERC to re-designate information as CEII “before, on, or after the date on which an earlier designation has expired”.

An even broader duration designation is provided in subparagraph (C) for information “about a vulnerability or threat to energy infrastructure, or the planning and construction of a system or asset that is intended to address a vulnerability or threat to energy infrastructure”. This subparagraph allows DOE or FERC to designate such information as CEII “for the period during which the vulnerability or threat exists” {new §231(d)(9)(C)(i)} and “for any additional period determined to be appropriate” {new §231(d)(9)(C)(ii)}.

Removal of Designation


The bill deletes the current language of §215(d)(10), “Removal of designation” and provides ‘substitute’ language for §231(c)(10), “Removal of designation”. That is somewhat misleading though as the only actual change to the existing language is the insertion of the term ‘energy infrastructure’ before the words “the bulk-power system, or distribution facilities” at the end of the paragraph. This was necessary because of the expansion of the definition of term ‘critical electric infrastructure’ used in the definition of CEII.

Two New Paragraphs Added


The bill also adds two new paragraphs to §231(c):

(12) No immediate obligation to designate, and
(13) Effect of prior determinations

The first specifically allows DOE or FERC to sit on a CEII designation request until a request for disclosure of the information is made under 5 USC 552 (Freedom of Information Act) or any other law “requiring public disclosure of information or records”. Since, as noted above, lacking a determination, information is required to be treated as CEII upon request, this has little legal effect on the duty of DOE or FERC to protect the information as CEII.

The second new paragraph specifically allows DOE or FERC to designate information as CEII even if a previous decision had been made not to make such a designation in the past.

This is another good stopping point even though there are CEII changes in subsequent portions of this bill.

Friday, June 5, 2020

S 3688 Introduced – Energy Infrastructure Security


Last month Sen Murkowski (R,AK) introduced S 3688, the Energy Infrastructure Protection Act of 2020. The bill revises and expands the scope of 16 USC 824o-1, Critical electric infrastructure security, to include a wider range of energy production and delivery infrastructure.

Sense of Congress


Section 2 of the bill provides an outline of the importance of energy production and delivery infrastructure in the United States and the threats currently facing that infrastructure. It comes to two separate conclusions that inform the scope of this legislation. First {§2(11)}:

Owners and operators of electric infrastructure, entities involved with electric infrastructure, he Federal Energy Regulatory Commission, the Department of Energy, other Federal departments and agencies, States, and units of local government have information that can be used by those who seek to harm the United States to disrupt electricity service and should be protected from excessive dis- closure.

That conclusion is the reason for the existence of the current §824o-1, which among other things establishes the energy sector sensitive but unclassified information program, critical electric infrastructure information (CEII).

The second conclusion opines that {§2(12)}:

Owners and operators of electric infrastructure have been acting to reduce the vulnerability of their assets; and should have better opportunities to further reduce the vulnerability of their assets.

This second conclusion provides the basis for the expansion of the scope and coverage of the existing statute.

Regulatory Structure


The language of the bill takes the existing provisions of Part II of the Federal Power Act (16 USC 824 et seq) and labels that “Subpart A—General Requirements”. It then establishes a new Subpart B, Protecting Energy Infrastructure. The initial section of that new subpart, §230, is taken from the current §215(a) (§824o-1(a)) and re-titled as “Definitions”. The remaining paragraphs of 215 are moves to §231, Critical Electric Infrastructure Security. Additional new sections added to the new Subpart B are:

§232. Authority of the Commission to Offer Assistance to Owners and Operators of Energy Infrastructure,
§233. Authority of the Secretary to Offer Assistance to Owners and Operators of Energy Infrastructure,
§234. Access to Critical Electric Infrastructure Information,
§235. Designating Information Held by Other Governmental Authorities,
§236. Wartime Clearance, and
§237. Enforcement and Sanctions

All of this is going to cause some consternation amongst those responsible for the maintenance of the US Code. Currently most of Part II of the Federal Power Act is found in 16 USC Chapter 12, Subchapter II (§824 et seq). That subchapter already goes through §824w and includes such oddities as the aforementioned §824o-1. Shoehorning the new Subpart B into that structure would be difficult. I suspect that what will be done instead is to start a new Subchapter V, Protecting Energy Infrastructure, starting with §829 and call §232 thru §237 above §829a thru §829f.

Definitions


The new §230 includes the current definitions found in §215A(a). The bill would also add the following definitions:

• Commission {§230(2)},
• Critical electric infrastructure information {§230(4)},
• Energy infrastructure {§230(7)},
• Natural gas and natural-gas company {§230(10)},
• Oil and oil pipeline {§230(11)}, and
• Source of the information {§230(13)}

The key new term here is ‘energy infrastructure’. The definition provides the following list of ‘all systems or assets that’ {§230(7)}:

• Comprising the bulk-power system,
• Are owned by electric utilities,
• Allow for the transportation of fuel, electricity, water, steam, heat, cold, or any commodity that is used in the provision of electricity service,
• Facilitate the delivery of electrical energy to consumers, wholesale transactions in electrical energy, or the import or export of electrical energy, or
• Are subject to the jurisdiction of the Commission.

That new term is also added to the definition of the existing term ‘critical electric infrastructure’ so that would be defined as {§230(3)} “energy infrastructure or a system or asset of the bulk-power system, whether physical or virtual, the incapacity or destruction of which would negatively affect national security, economic security, public health or safety, or any combination of such matters. That, in turn, would make the Critical Electric Infrastructure Information’ (CEII) program apply to all of the defined energy infrastructure.

Future Posts


This is a long enough post for today, especially since the bill just gets more complicated from here. I will address the remaining portions of the legislation in future blog posts.

Thursday, October 5, 2017

Bills Introduced – 10-04-17

With both the House and Senate in session yesterday there were 42 bills introduced. Of those, on may be of specific interest to readers of this blog:

HR 3958 To establish a pilot program on securing energy infrastructure, and for other purposes. Rep. Ruppersberger, C. A. Dutch [D-MD-2]


I will be watching this bill for its cybersecurity provisions, particularly the definitions that it uses.

Thursday, September 14, 2017

S 1761 Introduced – FY 2018 Intel Authorization

Last month Sen. Burr (R,NC) introduced S 1761, the Intelligence Authorization Act for Fiscal Year 2018. This bill is the Senate counterpart of HR 3180 that was passed in the House on 7-28-17.

While a good portion of the bill is not publicly available (classified) there are a number of provisions that may be of specific interest to readers of this blog. In addition to Title V (Securing Energy Infrastructure), those sections include:

Sec. 604. Reports on the vulnerabilities equities policy and process of the Federal Government.
Sec. 605. Bug bounty programs.
Sec. 606. Report on cyber-attacks by foreign governments against United States election infrastructure.
Sec. 610. Limitation relating to establishment or support of cyber security unit with the Government of Russia.
Sec. 613. Notification of an active measures campaign.

Securing Energy Infrastructure


Title V is very closely patterned on S 79 of the same title. There are only three significant additions to the language of S 79 found in Title V:

• Adding a definition of the term ‘Director’ as the Director of Intelligence and Counterintelligence of the Department of Energy {§502(2)};
• Adding an interim 180-day report to Congress {§505(a)}; and
• Adding a definition of the term ‘appropriate committees of Congress’ as the intel committees, the Senate Committee on Energy and Natural Resources, and the House Energy and Commerce Committee {§505(c)}.

Joint Cybersecurity Unit


Section 610 is similar in intent to the three bills introduced to date (S 1544, HR 3191 and HR 3259)  that would prohibit funding for the establishment of a joint cybersecurity unit with elements of the Russian government. There is, however, a significant difference in the implementation of the restriction.

Section 610(a) would require the Director of National Intelligence to submit a report to Congress before and such unit is established. The report would include:

• The purpose of the agreement;
• The nature of any intelligence to be shared pursuant to the agreement;
• The expected value to national security resulting from the implementation of the agreement; and
• Such counterintelligence concerns associated with the agreement as the Director may have and such measures as the Director expects to be taken to mitigate such concerns.

Moving Forward



The Senate Intelligence Committee held a mark-up hearing on July 27th, 2017 and they approved the current version of the bill. A committee report was published on September 7th, 2017. The bill will be considered by the Senate at some point in the not too distant future as this is one of the ‘must pass bills’ that each house must consider. A bill will eventually pass, though not necessarily this bill, and it would then be reconciled with the House bill in a conference committee.
 
/* Use this with templates/template-twocol.html */