Showing posts with label Energy Sector Security. Show all posts
Showing posts with label Energy Sector Security. Show all posts

Tuesday, February 5, 2019

HR 680 Introduced – Energy Sector Security


Last month Rep. Ruppersberger (D,MD) introduced HR 680, the Securing Energy Infrastructure Act. This is a companion bill to S 174 that I discussed yesterday. Ruppersberger introduced a similar bill last session (HR 3958), but no action was taken on that earlier bill.

Moving Forward


Neither Ruppersberger nor his single cosponsor {Rep. Carter (R,TX)} are members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that the bill is unlikely to receive consideration in that Committee unless additional sponsors are signed. As I mentioned yesterday, this study and report bill is unlikely to attract serious opposition other than the fact that it would require the appropriation of $11.5 million.

Interestingly, both Ruppersberger and Carter are on the House Appropriations Committee. That Committee has not been assigned consideration of the bill, but their bipartisan support could help alleviate concerns about the spending aspects of this bill if it were to make it to the floor of the House. Unfortunately, neither are on the Energy and Water Development, and Related Agencies Subcommittee which controls appropriations for DOE.

Commentary


Yesterday, in a LinkedIn comment on my S 174 post, Kenneth Crowther made the comment that “I hope when they. ... "discover new classes of vulnerabilities" they have a plan for responsible disclosure to the vendor...”  Unfortunately, there is nothing in the legislation that would require the pilot program to effect coordinated disclosures. It would certainly hamper the effort to increase grid security if they did not.

Crowther’s point is well taken, and I would suggest that language be added to §3 of both bills to require that vulnerabilities detected during the program be coordinated with the appropriate vendors via the DHS NCCIC-ICS. More importantly, that language should include provisions for delayed public disclosure of the vulnerabilities while secure disclosure is made to utilities after vendors have developed adequate mitigation measures. Here is how that language could read:

(b) Coordinated Disclosure

(1) Any vulnerabilities identified during the pilot program will be reported to vendors in coordination with the industrial control system team at the National Cybersecurity & Communications Integration Center (NCCIC-ICS) in the Department of Homeland Security;

(2) Once a vendor provides NCCIC-ICS with notification that appropriate mitigation measures have been developed, NCCIC-ICS would provide limited disclosure of the vulnerability through the Electricity Sector - Information Sharing and Analysis Center (ES-ISAC);

(3) Ninety days after the ES-ISAC is notified the NCCIC-ICS will provide public notification of the vulnerability; and

(4) If a vendor has not provided a reasonable schedule for mitigation of the reported vulnerabilities within 45 days of initial notification of the vulnerability by NCCIC-ICS, NCCIC-ICS will prepare an alert about the vulnerability and publish that report in accordance with (2) and (3) above.

Monday, February 4, 2019

S 174 Introduced – Energy Sector Security


Last month Sen. King (I-ME) introduced S 174, the Securing Energy Infrastructure Act. This bill is the same as the reported version of S 79 that was introduced in the 115th Congress (and actually dates back to S 3018 from the 114th). It calls for and finances a study on control system security in the electric sector.

King and Rep. Ruppersberger (D,MC), who has introduced what is probably a companion bill (HR 680 to be published) have been pushing hard for this idea for over two years now. Last session King got his version out of Committee, but could not get it to the floor of the Senate. This was almost certainly due to the cost of the bill ($11.5 million). With more news being released about the cybersecurity risks associated with the grid, we may see this bill get to the floor.

Friday, March 9, 2018

Senate Committee Marks-up S 79 – Energy Sector Security


Yesterday the Senate Energy and Natural Resources Committee marked up a number of bills, including S 79, the Securing Energy Infrastructure Act. The Committee adopted substitute language by voice vote. The new language made only minor changes.

Changes


In §2 of the bill, a new definition was added; ‘Appropriate Committee of Congress’. This is a standard term used to specify which committees are to receive copies of the reports outlined in the bill.

Section 5 of the bill was modified to add an interim report (after 180 days) to Congress in addition to the report after two years.

The order of sections 6, 7, and 8 was shuffled for some unfathomable reason.

The new §7 (previously 6) was reworded to more explicitly outline the protections from disclosure that would be applied to information shared by the private sector with DOE as part of the studies outlined in the bill.

Moving Forward


The second step in the legislative process (congressional hearings) has now been cleared on this bill. The bipartisan support that the bill received yesterday is certainly indicative of the support that could be expected if/when the bill makes it to the floor of the Senate. The question now is if the Committee Chair {Murkowski (R,AK)} will exert enough influence to get the bill to the Senate floor. The bill is innocuous enough (other than the spending provisions) that it would probably be considered under the Senate’s ‘without objection’ process; which eases the time constraint problem legislation has in the Senate.

Tuesday, October 10, 2017

HR 3958 Introduced – Energy Infrastructure Security

Last week Rep. Ruppersberger (D,MD) introduced HR 3958, the Securing Energy Infrastructure Act of 2017. This bill is very similar to S 79, introduced earlier this year. This is not technically a companion bill because several additions have been made to the language of the bill, but it does serve the same purpose.

Changes Made


This bill adds some relatively minor bits of language to that found in S 79. Those include:

• Section 2(2) – Adds the definition of ‘Director’ as the DOE Director of Intelligence and Counterintelligence;
• Section 5(a) – Adds a requirement for an interim report to Congress at 180 days; and
• Section 5(c) – Adds a definition of ‘Appropriate Committees of Congress’.

Moving Forward


Neither Ruppersberger, nor his single co-sponsor {Rep. Carter (R,TX) are members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that the bill is not likely to be taken up by that Committee.

There are some funds authorized by this bill ($10 million for the pilot and $1.5 million for government study and report) which makes passage of the bill more complicated. Ruppersberger and Carter are both on the House Appropriations Committee, so that problem may be lessened. There is nothing else in this bill that would engender any significant opposition if brought to a vote.

Commentary


As I mentioned when a version of this bill was introduced in the 114th Congress, I think that this is potentially game changing legislation. It is one of the few bills that actually tries to address a control system security issue with something that appears to be a workable route to a solution. The fact that funding is specifically provided instead of requiring an executive agency to rob Peter to pay Paul is especially encouraging.


It will be interesting to see if either this bill or S 79 moves forward at all in this session. The both bills have been introduced early enough that there should be no procedural hurdle to their consideration. It remains to be seen if the leadership of either house really has any intention of moving legislation forward that actually does something about a cybersecurity issue.

Saturday, January 28, 2017

S 79 Introduced – Energy Sector Security

Earlier this month Sen. King (I,ME) introduced S 79, the Securing Energy Infrastructure Act. It would require the Secretary of Energy to establish a 2-year pilot program to study control system security in the energy sector. The pilot program would be funded at $10 Million for the 2-year study. This bill is essentially the same as S 3018 introduced late in the 114th Congress; that bill saw no action in committee. Attentive readers might recall that I suggested a letter writing campaign to support that bill.

I am not going to repeat the detailed explanation of the bill since I covered that in my post on the introduction of S 3018. I would like to address two items that I did not mention in that earlier post; the definition of ‘industrial control system’ and the use of the term ‘cyber-informed engineering'.

Industrial Control System


The bill defines ‘industrial control system’ as “an operational technology used to measure, control, or manage industrial functions” {§(2)(3)(A)}. That definition is expanded in sub-paragraph (B) to specifically include “supervisory control and data acquisition systems, distributed control systems, and programmable logic or embedded controllers”.

The initial definition could clearly be interpreted to include manual control systems with no electronic component. This is important because later in the bill ‘physical controls’ (as opposed to digital or analog) are one concept that is suggested as a way to avoid the security vulnerabilities in existing systems.

Cyber-Informed Engineering


This term was first used in S 2943, the FY 2017 National Defense Authorization Act. There it was used to describe a pilot program the DOD would run “to increase the resilience of military installations against cybersecurity threats and prevent or mitigate the potential for high-consequence cyberattacks” {§1634(a)}. The Armed Services Committee report (S Rept 114-255) provides a more detailed explanation:

“A consequence-driven, cyber-informed engineering approach is based on an evaluation of the operating environment that discriminates between targeted and indiscriminate attacks, analyzes vulnerabilities beyond traditional Information Technology security, and addresses systems created to control critical infrastructure that were designed primarily to meet engineering requirements with little or sometimes no consideration of security requirements.”

In S 79 the term shows up in the §4 description of the working group. In the second portion of the description of the working group purpose the bill it states that the working group will “develop a national cyber-informed engineering strategy to isolate and defend covered entities from security vulnerabilities and exploits in the most critical systems [emphasis added] of the covered entities” {§4(a)(2)}.

This sounds very much like how safety systems are configured in chemical operations. The sensors and actuators of safety systems are isolated from the active control system so that a failure (or compromise) of components of the control system cannot affect the proper operation of the safety system. And those safety systems are only designed to protect against catastrophic failure of the chemical manufacturing system, not general failures of the control scheme to maintain product quality or process efficiency.

As I mentioned in my post about S 2943, there is an interesting paper from 2015 published by the Idaho National Laboratory (INL) about the concept of ‘cyber-informed engineering’ (Note: the link in the original post is no longer good, it has been corrected.)

Moving Forward


In the last session, this bill had bipartisan support in the Senate Energy and Natural Resources Committee and it does again this session. I suspect that the reason that the bill did not move forward in the last session was due to its late introduction and short amount of time available.


The biggest thing stopping this bill from moving forward is the spending authorization for the pilot program ($10 million) and the inclusion of spending authorization for the working group activities ($1.5 million). While that is not a great deal of money (at Federal spending levels), it is money that will have to come from somewhere. Figuring out the spending offsets for that §11.5 million will take some doing. Once that is accomplished, this bill should be able to move forward pretty easily if it makes it to the floor.
 
/* Use this with templates/template-twocol.html */