Showing posts with label GAO Report. Show all posts
Showing posts with label GAO Report. Show all posts

Saturday, March 9, 2024

GAO Reports – Week of 3-2-24 – CISA and OT Cybersecurity

This week the Government Accountability Office (GAO) published a report on “Cybersecurity: Improvements Needed in Addressing Risks to Operational Technology”. This report outlines actions taken by CISA to support critical infrastructure organizations and sector risk management agencies in securing operational technology.

The 70-page report concludes by making four recommendations for CISA:

• Measure customer service for its OT products and services,

• Perform effective workforce planning for OT staff,

• Issue guidance to the sector risk management agencies on how to update their plans for coordinating on critical infrastructure issues, and

• Develop a policy on agreements with sector risk management agencies with respect to collaboration.

Saturday, December 23, 2023

GAO Reports – Week of 12-16-23 – Medical Device Cybersecurity Oversight

This week the Government Accountability Office (GAO) published a report on “Medical Device Cybersecurity”. The report was required by last year’s consolidated spending bill (§3305 of PL 117-328, 136 STAT. 5832). That section added §524B, Ensuring Cybersecurity of Devices, to the Federal Food, Drug, and Cosmetic Act. Subsection (g) of that new section required the GAO to examine:

Challenges for device manufacturers, health care providers, health systems, and patients in accessing Federal support to address vulnerabilities across Federal agencies,

How Federal agencies can strengthen coordination to better support cybersecurity for devices, and

Statutory limitations and opportunities for improving cybersecurity for devices.

The report identifies the agencies of the Federal government that share some level of responsibility for oversight of medical device cybersecurity with the Food and Drug Administration. In addition to various HHS agencies, these include CISA and the FBI.

While a number of agencies are named in this report, the GAO is only making recommendations to two agencies in this report. While there are two recommendations, they are actually two sides of the same one, for the FDA and CISA “to update the agencies’ agreement to reflect organizational and procedural changes that have occurred” since the current agreement was signed in 2018. 

Saturday, May 21, 2022

GAO Report – Protecting DOD’s Controlled Unclassified Information Systems

On Thursday, the Government Accountability Office published a report on “Defense Cybersecurity Protecting Controlled Unclassified Information Systems” (GAO-22-105259). The report looks at how well the DOD is doing in their efforts to get their CUI programs into regulatory compliance. The short answer, according to the GAO’s look at four basic program measures, it that DOD still has a way to go.

The four measures used by GAO to evaluate the DOD’s implementation process are:

• Categorize DOD CUI systems accurately (80 to 89% complete),

• Implement Cybersecurity Maturity Model Certification’s 110 security requirements (70 to 79% complete),

• Implement 266 security controls for moderate confidentiality impact systems (80 to 89% complete), and

• Authorize system to operate on DOD network (90% plus complete).

While this GAO Report just looks at the DOD, the CUI program under 32 CFR 2002 applies to all branches of the Federal Government and their contractors (and in some instances regulated entities). Some common federal information protection schemes that fall under the CUI protection regulations include (but are certainly not limited to):

• Chemical-terrorism Vulnerability Information (CVI),

• Critical Energy Infrastructure Information (CEII),

• Protected Critical Infrastructure Information (PCII), and

• Sensitive Security Information (SSI)

It would be interesting to see how other federal agencies (DOE and DHS for example) fair in their implementation of the §2002 regulations.

Saturday, January 15, 2022

GAO Reports – Cybersecurity Response

This week, the GAO published a report on the federal government response to the nearly concurrent SolarWinds attack and organized exploits of the Microsoft Exchange vulnerabilities. This report looks at those response activities and outlines three National Security Council recommendations for improving responses to future cyberattack. An appendix provides separate timelines for the response to both incidents.

The accompanying highlight document identifies four lessons learned by responding agencies:

• Coordinating with the private sector led to greater efficiencies in agency incident response efforts,

• Providing a centralized forum for interagency and private sector discussions led to improved coordination among agencies and with the private sector,

• Sharing of information among agencies was often slow, difficult, and time consuming, and

• Collecting evidence was limited due to varying levels of data preservation at agencies.

The GAO reports that the NSC identified three areas that the government could take to take to prevent and improve the response to future incidents (pg 36):

• Align technology investments with operational priorities. The review identified that the federal government should invest resources to increase its capabilities to identify, detect, protect, and respond to significant cybersecurity incidents.

• Improve public-private engagement. The federal government should improve its coordination and information sharing with the private sector.

• Improve threat intelligence acquisition, sharing, and use among federal agencies. The federal government should improve information sharing with its partners.


Monday, January 25, 2021

Latest GAO Report on CFATS Looks at Regulatory Collaboration

Last week the Government Accountability Office (GAO) published their latest report on the Chemical Facility Anti-Terrorism Standards (CFATS) program. This report looks at how the CFATS program interacts with eight other Federal chemical safety and security programs at both the Agency and installation levels. Includes recommendation to legislate additional chemical security requirements for water treatment facilities.

Other Programs

The report looks at how much of an overlap there is in security requirements between the CFATS program and eight other Federal regulatory programs. Those programs are:

• Explosives materials Program (ATF),

• Maritime Transportation Security Act program (Coast Guard),

• Hazardous materials transportation program (DOT),

• Resource Conservation and Recovery Act program (EPA),

• Risk Management Program (EPA),

• America’s Water Infrastructure Act program (EPA),

• Pipeline Security Program (TSA), and

• Rail Security program (TSA)

Using a very broad (and loosely defined as “engage in similar activities") term ‘align’ the GAO reports that all eight programs align with “six of 18 CFATS standards regarding restricting area perimeter; securing site assets; screening and controlling access; deterring, detecting, and delaying an attack; deterring theft and diversion, and deterring insider sabotage” {pg 21, using .PDF page numbers}. A table spanning three pages outlines which CFATS risk-based performance standards (RBPS) each of the Federal programs align with.

What is clear from a detailed reading of the report is that GAO, in looking for alignment, was looking for areas where regulatory compliance with another program could be used, at least in part, to comply with CFATS security plan requirements under the RBPS. While the GAO admits that some program coordination has taken place under the EO 13650 Working Group (see their lite web page) it takes DHS to task for not continuing to work on clarifying where compliance with other programs fits into CFATS compliance. The first GAO recommendation addresses this:

“The Secretary of DHS should direct its chemical safety and security programs to collaborate with partners and establish an iterative and ongoing process to identify the extent to which CFATS-regulated facilities are also covered by other programs with requirements or guidance that generally align with some CFATS standards.” {pg 53}

More specifically, recommendation five goes on to say:

“The Director of DHS’s Cybersecurity and Infrastructure Security Agency should update CFATS program guidance or fact sheets to include a list of commonly accepted actions facilities may have taken and information they may have prepared pursuant to other federal programs, and disseminate this information.” {pg 54}

Further recommendations are made to EPA, ATF and DOT to look at how their programs interface with the CFATS program.

DHS concurred with both of the above recommendations and had this specific response to recommendation five:

“DHS concurred with recommendation 5, stating in its letter that, among other actions, CISA will update or create a new guidance document or fact sheet by December 31, 2021, that includes a list of commonly accepted actions CFATS-regulated facilities may have taken and information they may have prepared pursuant to other federal programs and disseminate this information.” {pg 56}

Water Treatment Facility Security

This report states that water treatment and wastewater treatment facilities that are exempt from the coverage of the CFATS program “may present attractive terrorist targets due to their large stores of potentially high-risk chemicals and their proximities to population centers” {pg 47}. They go on to note that an earlier report “found that the Risk Management Program regulates at least 1,100 public water system and 500 wastewater treatment works facilities for many of the same chemicals at the same threshold quantities as the CFATS program’s chemical release attack scenario” {pgs 47-8}.

There are significant differences in the security aligned requirements of both the Risk Management Program and Water Infrastructure Act programs, and the CFATS program. “For example, the Risk Management Program and Water Infrastructure Act programs do not contain requirements or guidance regarding security training or background checks. In addition, while the Water Infrastructure Act program contains guidance on cybersecurity, the Risk Management Program does not.” {pg 48}

Water treatment facilities are also subject to the voluntary security guidelines of the American Water Works Association’s security practices management standard. They go on to note that EPA program officials reported that “the voluntary water and wastewater standards are not as comprehensive as the CFATS program’s 18 standards, and it is unclear the extent to which public water systems and wastewater treatment works implement the standard because its use is entirely voluntary” {pg 50}. Further, the report notes that DHS officials stated that “the general alignment of Water Infrastructure Act requirements or guidance with some CFATS standards may not reflect the level of security achieved because, unlike the CFATS program, the Water Infrastructure Act program does not include verification measures” {pg 51}.

The GAO makes two similar recommendations (#6 and #7) to DHS and the EPA about working with the other agency to “to assess the extent to which potential security gaps exist at water and wastewater facilities and, if gaps exist, develop a legislative proposal for how best to address them and submit it to the Secretary of Homeland Security and Administrator of EPA, and Congress, as appropriate” {pg 54}.

Commentary

The Working Group formed under Obama’s chemical safety and security executive order kind of faded away during the Trump administration. There was certainly some ongoing coordination there was no incentive (and many political disincentives) to forge any new regulatory efforts. This is very likely to change under the Biden Administration, though it will not likely be a top priority. Congressional efforts, if the two committees in the House can better their coordination, may be more persuasive.

The one CFATS legislative initiative that I think may be possible this session may be the introduction of bills to address the water facility security issue. The chance of their passage is still rather small given the CFATS three-year extension passed last year, but significant committee work and hearings this session may bear fruit in the 118th Congress.

Wednesday, June 15, 2011

Emerging Threats to Rail Security

Yesterday the Senate Committee on Commerce, Science, and Transportation held a full committee hearing on the emerging threats to rail security. I have not had a chance to review the video of the hearing, but a quick review of Administrator Pistole's written testimony and Chairman Rockefeller’s opening remarks continue to show that the main emphasis of the politician’s remains focused on passenger rail and transit operations, not freight rail. The GAO report that formed the written testimony of Mr. Lord does make significant observations about freight rail security matters, though it too concentrates on transit issues.

Training

The GAO report continues to take TSA to task for its failure to implement the training regulation requirements of the Implementing Recommendations of the 9/11 Commission Act of 2007. It does note that TSA reports that they intend to publish a notice of proposed rule making in the fall of this year. The report fails to note that according to the semi-annual Regulatory Agenda reports published every six months or so by DHS, TSA has had intentions of imminently publishing such an NPRM for quite some time.

Information Sharing

The GAO report addresses the multiple information sharing efforts for transit security, but notes that freight rail carriers are not satisfied with the security and intelligence information provided to them. Three of the Class I railroads that GAO interviewed for this report noted that they frequently receive intelligence information from the media before they receive the same information from TSA.

It will be interesting to see if the video of the hearing shows that the politicians on either side of the committee dais addressed these GAO concerns in their discussions during the questioning period of the hearing. I hope to have a chance to review that video this weekend.

Wednesday, April 1, 2009

Motor Carrier Transportation Security Report

Last Friday the GAO delivered to Chairman Thompson a report on the status of the DHS efforts to secure the commercial vehicle sector. This was the third in a series of GAO reports that the House Homeland Security Committee Chair had requested about surface transportation security. According to a committee press release, the reports indicate “serious security shortcomings in all modes of the nation’s surface transportation systems”. While the report excoriates TSA, and to a lesser extent DOT, for not following through on a multitude of congressional mandates there are some positives, especially for the chemical security community. Motor carriers that handle hazmat shipments, the report notes, do a significantly better job of instituting security measures than companies that did not. Interestingly, this is a matter of concern for the writers of the GAO report:
“In lieu of a completed risk assessment, TSA leadership has decided to implement a current strategy which focuses on examining security risks posed by the shipment of hazardous materials. However, available information from ongoing risk assessments does not appear to support this emphasis, and the basis for TSA’s decision for this strategy is unclear.” (page 8)
This is actually the basis for GAO’s complaints about TSA’s security efforts. They maintain that TSA has not done an adequate job of assessing the potential terrorist risks to the commercial motor carrier sector. Nor has it conducted a systematic vulnerability assessment for the sector. Without a comprehensive risk and vulnerability assessments, the report notes, TSA cannot formulate an effective security program to protect the public from the consequences of attacks on commercial motor carrier targets. The scope of the problem of conducting these assessments is briefly noted in the report. On page 98 in Table 5 the report notes that there are over one million truck motor carriers (with almost 12 million vehicles) currently operating in the United States and almost 4,000 motor coach carriers (with 75,000 vehicles) included in the commercial vehicle industry. Even if the problem were only restricted to hazmat carriers (Table 6, page 99), it would still mean evaluating more than 60,000 carriers with almost 4 million vehicles. The only way that TSA is going to be able to acquire any useable data to do an industry wide vulnerability assessment would be to develop a web-based vulnerability assessment tool similar to the SVA tool developed for CFATS implementation. That is not going to happen without direction and authorization from Congress.
 
/* Use this with templates/template-twocol.html */