Showing posts with label HR 5239. Show all posts
Showing posts with label HR 5239. Show all posts

Tuesday, January 15, 2019

HR 360 Introduced – Cyber Sense Program


Last week Rep. Latta (R,OH) introduced HR 360, the Cyber Sense Act of 2019. The bill is nearly identical to HR 5239 introduced last session and adopted by the House Energy and Commerce Commission. The new bill is most closely related to the reported version of the earlier bill.

Moving Forward


This bill was scheduled to be considered (along with HR 359)  in the House today under the suspension of the rules process, but that has since changed. This was apparently done to provide time for the consideration of HJ Res 27 as I mentioned earlier.

This bill received bipartisan support in Committee during the last session and I suspect that it will again, if/when it reaches the floor of the House.

The House has still not made committee assignments for its members (beyond most Chairs and Ranking Members), so it is not yet possible to definitively comment on the possibility of this bill being considered in the House Energy and Commerce Committee, it that is not pre-empted by floor action. I suspect that Latta and his co-sponsor {Rep. McNerney (D,CA)} will be influential members of that Committee.

Commentary


I still have concerns about the information sharing restrictions in the bill. Most of the devices that would be covered under the Cyber Sense program would be used by manufacturing facilities outside of the electric sector. They could be substantially harmed by restricting the sharing of vulnerability information about those devices by making that information Critical Electrical Infrastructure Information (CEII).

As I outlined in my post on the introduction to HR 5239, I would much rather see a requirement to provide restricted early notification of vulnerabilities to organizations in the electric sector before universal notifications are made by NCCIC-ICS.

Interestingly, device vendors would probably not be restricted from publishing vulnerability reports on their own products, even if ‘protected’ by the CEII labeling. CEII restrictions only apply to government agencies within the United States.

Wednesday, May 9, 2018

Energy and Commerce Committee Takes up Cybersecurity Bills


Today in a markup hearing that was billed as being about opioid abuse legislation (and mostly was) the House Energy and Commerce Committee took up four cybersecurity bills that had previously been adopted in subcommittee action. The all four cybersecurity bills were adopted by voice votes with two of them being amended. The action on these cybersecurity bills came at the end of the almost 4-hour long hearing.

The four cybersecurity bills were:

HR 5174, Energy Emergency Leadership Act;
HR 5175, Pipeline and LNG Facility Cybersecurity Preparedness Act;
HR 5239, Cyber Sense Act; and
HR 5240, Enhancing Grid Security through Public-Private Partnerships Act

Committee Amendments


The pipeline cybersecurity bill was amended. The amendment was offered by Rep. Upton (R,MI) who is the Chair of the Energy Subcommittee. The major portion of this amendment was the addition of §3, Savings Clause. That section states:

“Nothing in this Act shall be construed to modify the authority of any Federal agency other than the Department of Energy relating to physical security or cybersecurity for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, or liquefied natural gas facilities.”

This amendment indirectly addresses the roles of both the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) and DHS’ Transportation Security Administration in protecting pipeline safety and security. This should alleviate the conflicts with the House Transportation and Infrastructure Committee and the House Homeland Security Committee over jurisdictional issues that I identified in my earlier post.

The enhancing grid security bill was amended. The amendment was offered by Rep. Latta (R,OH). It added the Electric Reliability Organization as one of the agencies with which the Department of Energy would consult in developing the program outlined in the bill. The amendment also provided a definition of the term ‘Electric Reliability Organization’.

Moving Forward


This was probably the last time that there would be any opportunity to modify the language in these four bills. It is likely that they will move to the House floor, probably before the summer recess. They will almost certainly be considered under the House suspension of the rules provisions that limits debate and prohibits amendments from the floor. They will all almost certainly pass with broad bipartisan support.

If any of these bills get taken up by the Senate (impossible to predict) it will probably be under similar abbreviated consideration provisions as we will see in the House.

Friday, April 20, 2018

House Subcommittee Marks-Up Energy Security Bills


On Wednesday the Subcommittee on Energy, of the House Committee on Energy and Commerce, held a markup hearing on five energy bills. Four of the bills have been covered in this blog and those bills passed on voice votes; two of them were amended with substitute language from the original offerors. The four the bills that have been addressed in this blog:

HR 5174, Energy Emergency Leadership Act;
HR 5175, Pipeline and LNG Facility Cybersecurity Preparedness Act (amended);
HR 5239, Cyber Sense Act (amended); and
HR 5240, Enhancing Grid Security through Public-Private Partnerships Act

HR 5175 Changes


The one change made to HR 5175 in the substitute language is relatively minor. It adds a phrase to §2(1) to expand the coordination requirement by adding: “including through councils or other entities engaged in sharing, analysis, or sector coordinating”.

HR 5239 Changes


The changes to HR 5239 are mainly grammatical and would have little to do with the operation of the Cyber Sense program that is proposed by this bill. There is one potentially significant change; §2(b)(7) from the original bill was removed. That paragraph had provided a requirement for the Secretary of Energy to “establish procedures for disqualifying products that were tested and identified as cyber-secure under the Cyber Sense program but that no longer meet the qualifications to be identified cyber-secure products”. There is nothing in the revised program that would prohibit that disqualification.

Moving Forward


The bipartisan support received in the subcommittee will almost certainly be duplicated when these bills are taken up by the whole committee. The question then will be to see if the sponsors and the Committee leadership have enough influence (or are willing to expend the effort to influence) to bring these bills before the full House. I firmly expect that we will see some version of these bills reach the floor under the suspension of the rules procedure in the House. Again, that means limited debate and no floor amendments. I would not be surprised to see all five bills considered on a single day.

Commentary


The removal of the language in HR 5239 providing for the establishment of a process to disqualify products that no longer meet the Cyber Sense standards brings up an interesting legal situation. As I said earlier, there is nothing in the bill that would specifically prohibit the Secretary from establishing such rules. But, having said that, a good lawyer could argue before a friendly judge that the removal of the specific authority to establish such a disqualification process from the language in the bill establishes a congressional intent that such authority can no longer be exercised by the Secretary absent specific authorization by Congress.

What this very well could end up meaning is that once a vendor becomes authorized to use the ‘Cyber Sense’ label on their product, they will no longer have to work to maintain the ‘Cyber Sense’ standards because the Secretary would not have the authority to require the vendor to remove the ‘Cyber Sense’ labeling. If the vendor flaunting of the ‘Cyber Sense’ standards becomes wide spread, the efficacy of the whole program would be called into question, destroying the process.

If this problem is to be addressed, it will almost certainly have to be done during the Energy and Commerce mark-up hearing that will probably be conducted in the next couple of weeks. After that, if the bill moves forward, it would almost certainly be under processes in both the House and Senate that would not allow for amendments to the bill from the floor.

Thursday, March 29, 2018

HR 5239 Introduced – DOE Cyber Sense


Earlier this month Rep Lata (R,OH) introduced HR 5239, the Cyber Sense Act of 2018. The bill would require DOE to establish “a voluntary Cyber Sense program to identify and promote cyber-secure products intended for use in the bulk-power system” {§2(a)}. Similar provisions were included in §1106 of HR 8 in the 114th Congress (passed in House, stalled in Senate).

Cyber Sense Program


As I mentioned above, this bill has very similar requirements to establish and maintain a testing program “to identify products and technologies intended for use in the bulk-power system that are cyber-secure, including products relating to industrial control systems” {§2(b)(1)}. There are, however, three significant differences between this bill and the earlier §1106 provisions.

First, this bill removes the requirement for DOE to “promulgate regulations regarding vulnerability reporting processes for products tested and identified under the Cyber Sense program” that was found in §1106(b)(3). Both bills contain provisions requiring DOE to “establish and maintain cybersecurity vulnerability reporting processes and a related database” {(b)(2) in the respective sections}.

Second, this bill adds a requirement for DOE to “provide reasonable notice to the public, and solicit comments from the public, prior to establishing or revising the Cyber Sense testing process” {§2(b)(6)}.

Finally, in the disclosure protection paragraph, there are two changes. The first is structural; since the language in §1106(c) referred to the disclosure reporting regulations that are not included in HR 5239, the disclosure protection language now refers to the broader vulnerability reporting processes and database in §2(b)(2). Second, the language specifically prohibiting disclosure under “section 552(b)(3) of title 5, United States Code, and any State, tribal, or local law requiring disclosure of information or records” {§1106(c)} has been removed in the new bill.

Moving Forward


Both Latta and his co-sponsor, Rep McNerney (D,CA) are senior members of the Energy and Commerce Committee to which this bill was assigned for consideration. Thus, it would seem likely that they would have the influence necessary to have the bill considered by Committee. There are no provisions in the bill that would draw the specific ire of the regulated community, so I suspect that there would be bipartisan support for this bill both in the Committee and before the full House.

Commentary


The vulnerability reporting requirements of the earlier bill were going to be problematic, because the regulated community has very little to do with the disclosure and reporting of vulnerabilities. Establishing effective regulations for vulnerability reporting would have to be targeted at either the independent researcher community (which is increasingly international in scope) or the manufacturers of the affected devices (which is very much international).

The earlier attempt to bring vulnerability reporting for Cyber Secure devices under the disclosure rules of the Critical Energy/Electric Infrastructure Information (CEII) program was doomed to failure. First, the CEII program only prohibits information disclosure by Federal, State and local governments agencies (including, of course FERC and NERC). It would not preclude independent researchers or vendors from releasing vulnerability information.

The interesting thing about the CEII provisions of both of these bills is that there might end up being unintended effects on ICS-CERT. A large portion of the devices that would likely be tested under the cyber sense program would also be used in control systems in other industries not directly affected by the CEII program. If ICS-CERT were notified by the operator of the Cyber Sense program (NERC?) of vulnerabilities reported under §2(b)(2), they would not be able share that information under their normal alert/advisory publication program. Similarly, if ICS-CERT were to share information with the Cyber Sense program, it could be argued that they could not subsequently share that information with the wider industrial control system community.

What the program should be required to do instead of labeling the vulnerabilities as CEII would be to require notifications to be made to registered members of the bulk power industry and then after a set period of time (two months?) the Cyber Sense operator would be required to notify ICS-CERT for general vulnerability publication for the remaining affected industries. Similarly, ICS-CERT would be required to check vulnerability disclosures to see if they involve Cyber Sense listed devices. If so, they would be required to first notify the Cyber Sense operator and withhold general industry notification for the same set period of time.

Tuesday, March 13, 2018

Not a Markup Hearing


Well, it turns out that the Energy Subcommittee hearing on the four DOE emergency response and security bills is not a mark-up hearing after all. Last night the witness list was announced, so it seems as if this will be an information gathering hearing with a possible mark-up at some later date.

Updated Hearing Information


The witness list includes:

Mark Menezes, US Department of Energy;
Scott Aaronson, Edison Electric Institute;
Mark Engels, Dominion Energy;
Kyle Pitsor, National Electrical Manufacturers Association;
Zachary Tudor, Idaho National Laboratory; and
Tristan Vance, Indiana Office of Energy Development

The links provided above are to the witness testimony that will be presented at tomorrow’s hearing. The Sub-Committee staff has also produced a background document for the meeting.

Interesting Info in Testimony


Menezes notes that (pg 1):

“To demonstrate our focus on the aforementioned mission [to protect the Nation’s critical energy infrastructure from physical security events, natural and man-made disasters, and cybersecurity threats], the Secretary announced last month that he is establishing an Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This organizational change will strengthen the Department’s role as the Sector-Specific Agency (SSA) for Energy Sector Cybersecurity, supporting our national security responsibilities.”

Menezes also notes that (pg 6):

“Advancing the ability to improve situational awareness of OT networks is a key focus of DOE’s current activities. The Department is currently in the early stages of taking the lessons learned from CRISP and developing an analogous capability for threat detection on OT networks via the Cybersecurity for the Operational Technology Environment (CYOTE) pilot project. Observing anomalous traffic on networks – and having the ability to store and retrieve network traffic from the recent past – can be the first step in stopping an attack in its early stages.”

Engels notes that (pg 3):

“A more expedient [coordinating security activities of DOT and TSA] approach may be to encourage a Memo of Understanding (MOU)between DOE and TSA that outlines roles and responsibilities for dealing with cyber and physical security for the ONG sector. TSA already has an MOU with the DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) which has responsibility for pipeline safety. Depending on the type of event, the TSA/DOT MOU has been critical in helping operators understand which Federal entity is the lead agency.”

Engels also notes that (pg 8):

“In 2016, TSA, again working with asset owners, industry associations, and the Department of Homeland Security’s Industrial Control System’s Cyber Emergency Response Team (DHS ICS-CERT), gathered input to update the Guidelines using the National Institute of Standards and Technology’s (NIST) Cyber Security Framework as a model. The updated [Pipeline Security] Guidelines are scheduled for release in the first half of 2018. Industry also provided input to augment the set of cybersecurity questions used in the Corporate Security Reviews (CSR) conducted by TSA.”

Engels also notes that (pgs 12-13):

“INL has undertaken several initiatives to stand up test environments for Industrial Control Systems (ICS). One such initiative was called RENDER (Risk Evaluation Nexus for Digital Age Energy Reliability). RENDER created a three way sharing arrangement involving the lab, the vendor and the asset owner. Previous projects excluded the asset owner from the equation, creating uncertainty associated with remediation of the vulnerabilities identified by INL. With RENDER, the asset owner not only could see what vulnerabilities were discovered, but provide input to the vendor about how critical or not the vulnerability was to the asset owner. This allowed the vendor to prioritize corrections that made the most sense to the asset owners.”

Tudor notes that (pg 4):

“INL developed and completed an initial pilot study of our proprietary Consequence driven, Cyber-informed Engineering (CCE) methodology with Florida Power and Light (FPL) through a Cooperative Research and Development Agreement (CRADA). CCE was developed to address the realization that constantly “chasing” threats and vulnerabilities, rather than getting ahead of these problems, is not sufficient to secure our critical systems. CCE is designed to assist asset owners in understanding the most effective and immediate actions they can take to eliminate the opportunity of the “worst-case” cyber-physical impacts from an attack by the most capable cyber adversaries. CCE leverages an organization’s knowledge and experiences with their systems and processes to “engineer out” the potential for the highest consequence events.”

This could be an interesting hearing.

Monday, March 12, 2018

Committee Hearings – Week of 03-11-18


Both the House and Senate will be in Washington this week. Budget hearings continue to be the big news with hearings starting to get down to the agency level. There is also one cybersecurity markup hearing scheduled.

Budget Hearings

Coast Guard, House, Subcommittee – Wednesday
TSA, House, Full Committee – Wednesday
DOT, House, Subcommittee – Thursday
DOE, House, Subcommittee – Thursday

I do not pay much attention to budget hearings. They are just the start of the appropriations process and it is the end game that provides specific funding for specific programs that really means something in the real world.

Cybersecurity Markup


On Wednesday the Energy Subcommittee of the House Energy and Commerce Committee will hold a markup hearing looking at four bills dealing with cybersecurity issues in the Department of Energy. The bills include:

HR 5174, Energy Emergency Leadership Act;
HR 5175, Pipeline and LNG Facility Cybersecurity Preparedness Act;
HR 5239, Cyber Sense; and
HR 5240, Enhancing Grid Security

All of these bills were introduced last week and I have not seen official copies on the Congress.gov web site, so I have not reviewed any of these bills in detail. The links provided above are to Committee drafts of the bills; I will start my reviews later today based upon these copies.

Saturday, March 10, 2018

Bills Introduced – 03-09-18


Yesterday, with just the House meeting in pro forma session, there were 12 bills introduced. Of those two may be of specific interest to readers of this blog:

HR 5239 To require the Secretary of Energy to establish a voluntary Cyber Sense program to identify and promote cyber-secure products intended for use in the bulk-power system, and for other purposes. Rep. Latta, Robert E. [R-OH-5]

HR 5240 To provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threats to, the electric grid, and for other purposes. Rep. McNerney, Jerry [D-CA-9]


 
/* Use this with templates/template-twocol.html */