Showing posts with label HR 54. Show all posts
Showing posts with label HR 54. Show all posts

Friday, January 20, 2017

HR 54 Introduced – Cyber Defense

Earlier this month Rep. Jackson-Lee (D,TX) introduced HR 54, the Department of Homeland Security’s Cybersecurity Asset Protection of Infrastructure under Terrorist Attack Logistical Structure or CAPITALS Act. The bill would require DHS to conduct a study on the feasibility of establishing a Department of Homeland Security Civilian Cyber Defense National Resource.

Cyber Defense National Resource


There are no details in the bill about how such a resource would be organized or funded. The only thing that is clear is that this resource would be separate from any military organization (including the National Guard). There is nothing in the bill that would address whether or not the force would be able to address control system security issues.

The study required in this bill is very similar to the Cyber National Guard study required in HR 60 introduced last session by Jackson-Lee. The only substantial differences are the change in the agency responsible for the study (the HR 60 study was to be conducted by the Director of National Intelligence) and the name of the organization (HR 60 called it the Cyber Defense National Guard).

Section 2(b)(8) of the bill specifically directs the study to include a look at the impact of having substantial numbers of the ‘resource’ not having “military, intelligence, law enforcement, or government work experience”. This does raise questions about the source of personnel for such an organization and how much training in cybersecurity would be a pre-requisite for membership in the organization.

Moving Forward


The changes in the bill did have a practical political effect on the bill. HR 60 had been referred to the House Intelligence Committee for consideration. Since the new study and organization would be a DHS action, HR 54 has been referred to the House Homeland Security Committee and it’s Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee. Ms. Jackson-Lee is an influential Democrat on both the Committee and Subcommittee. Since the bill only requires the conduct of a study and authorizes no funds for that study and subsequent report, there appears to be no substantial impediment to this bill being considered.


I suspect that the changes made to this bill indicate that Jackson-Lee is seriously interested in seeing the bill passed. I suspect that we will see this bill considered by the Committee in the coming months. I would not be surprised to see the bill make it to the floor under the suspension of rules process where it would probably pass with substantial bipartisan support.

Friday, January 13, 2017

HR 59 Introduced – Chemical Facility Security

Last week Rep. Jackson-Lee (D,TX) introduced HR 59, the Frank Lautenberg Memorial Secure Chemical Facilities Act. This bill is nearly identical to HR 54 introduced last session and very similar to bills introduced by Ms Jackson-Lee and Rep. Thompson (D,MS) over the last eight years. It provides a complete re-write of the current chemical facility security rules passed in the 113th Congress.

The bill includes all of the button pushing issues that the Democrats love and the Republicans hate, so there is little chance (actually no chance) that this bill will be considered at any time during this session of congress. In fact, the last time that the Democrats controlled both the House and Senate a similar bill was passed in the House but could not make its way to the floor of the Senate for consideration.

There are, however, some cyber security provisions in this bill that readers of this blog might find of interest.

First the bill would take the current cybersecurity requirements found in 6 CFR 27.230(8) and include them in the language of the newly proposed 6 USC 2203(d)(8). The only changes being made to the language are solely intended to make the requirements more readable (physical formatting changes). Both sets of language require covered chemical facilities to have measures in place to “deterring cyber sabotage, including by preventing unauthorized onsite or remote access to critical process controls” and then lists the general types of systems to be protected, including:

• Supervisory control and data acquisition systems;
• Distributed control systems;
• Process control systems;
• Industrial control systems;
• Critical business systems; and
• Other sensitive computerized systems

The sole purpose of moving the existing risk-based performance standards from the CFR to the USC is to make it harder for DHS to make changes to these standards by regulatory means.

Secondly, under a new §2206, Timely Sharing of Threat Information, the owner/operator is required to notify DHS of “any intentional or unauthorized penetration of the physical security or cyber security of the covered chemical facility, whether successful or unsuccessful” {new §2206(b)(1)(B)}. While the lack of definition of the key term ‘penetration’ is not unusual, it does provide an added measure of lack of clarity when it comes to cybersecurity.

Finally, we see again the requirement for hackers (specifically including “blue hat, red hat, and white hat hackers {§2111(b)(6)}) to “validate the security measures instituted to address cyber based threats”. Ignoring for the moment the lack of definition of key terms including the different colored hats, the requirement does not make any sense. Penetration testing, properly done, can certainly be a good thing for evaluating security controls, but this requirement is placed in the section dealing with conducting assessments of “methods to reduce the consequences of a terrorist attack” not security protocols.

A similar problem is seen in the previous subparagraph in the same section. It refers to:

The design of computing systems and development of plans, exercises, and drills to re-engage computing systems used in the processing, transport, storage of chemicals that are designed as a ‘‘risk’’ by the Secretary using protocols for trusted recovery under the worse case conditions;”


Again, this sounds like good cybersecurity planning and both of these requirements (with adequate definitions of key terms) should be included in the performance standards portion of the bill, not the inherently safer technology portion. I am not sure if it was added here as a mistake or a serious misunderstanding of the role of cyber security.

Wednesday, January 4, 2017

Bills Introduced – 1-3-17

Yesterday was the first day of the 115th Congress. As expected there were a large number of bills (274) introduced in the House and a few (20) in the Senate. Many of these bills are repeats from previous sessions of congress and will continue to see little or no action. Of those introduced yesterday, three may be of specific interest to readers of this blog:

HR 54 To require the Secretary of Homeland Security to conduct a study on the feasibility of establishing a Civilian Cyber Defense National Resource in the Department of Homeland Security. Rep. Jackson Lee, Sheila [D-TX-18]

HR 59 To enhance the security of chemical facilities and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 150 To direct the Attorney General to create a special reward program for individuals providing information leading to the apprehension and conviction of persons committing offenses under section 1030 of title 18, United States Code, and for other purposes. Rep. Green, Al [D-TX-9]

I suspect that HR 54 will bear some semblance to HR 60 introduced (and died) in the 114th Congress. Since the current title contains no reference to ‘National Guard’, it would seem that Ms. Lee may have changed her mind about the military nature of the organization.

HR 59 will also probably bear some resemblance to HR 54 from the last session in that it will be an essential re-write of the current CFATS program. It will be interesting to see if it includes a cleaned-up version of the hacking provisions of the earlier bill.

HR 150 is almost certainly not a control system security bill, but any bill that ‘enhances’ enforcement of the cyber fraud provisions of the US Code (§ 1030)is certain to effect (unintentionally if nothing else) anyone in the cybersecurity research community, especially those that are not meticulous supporters of coordinated disclosure.


As always future coverage of these bills in this blog will depend on what the actual wording of the bill includes.

Thursday, January 15, 2015

HR 54 Requires Hacker Support

When I reviewed HR 54, the Frank Lautenberg Memorial Secure Chemical Facilities Act, I did not go into any great detail because the bill is dead in the water. I saw a TWEET yesterday from @5ean5ullivan that made me go back and look at one section much more closely. It seems that Rep. Jackson-Lee (D,TX) wants covered chemical facilities to employ hackers to checkout their cybersecurity.

Cybersecurity Requirements

Section 2111(b)(6) requires: “the conduct of tests of facilities should include blue hat, red hat, and white hat hackers to validate the security measures instituted to address cyber based threats”.

Interestingly this requirement does not come in the portion of the legislation that discusses site security plans or risk-based performance standards for security measures. Instead it is found in the section of the bill that deals with Methods to Reduce the Consequences of a Terrorist Attack, commonly referred to inherently safer technology (IST).

In the discussion of the required assessment of IST measures the §2111(b) describes the various things that a facility must look at in conducting their assessment. In an apparent after thought (and certainly never included in earlier versions of Democrat bills on chemical security) are two sub-paragraphs dealing with cybersecurity issues.

The first requires: the design of computing systems and development of plans, exercises, and drills to re-engage computing systems used in the processing, transport, storage of chemicals that are designed [should be ‘designated’] as a ‘‘risk’’ by the Secretary using protocols for trusted recovery under the worse case [worst case?] conditions” {§2111(b)(5)}.

This certainly sounds like a reasonable requirement, but it probably should have been included in §2103(d)(8) the discussion of deterring cyber sabotage in the risk based performance criteria that would be required by this bill.

The requirements to use hackers described above is also out of place in the discussion of IST requirements. I am not so sure, however, that this was intended to be part of the planning requirements for facility security plans. It actually looks like it should have been included in §2104, Site Inspections. If that were the case it would call for DHS to use hackers to evaluate the cybersecurity protections that are part of the site security plan. That would be a radically new type of cybersecurity requirement that I have not seen suggested in any other regulatory program.

Problems with Hacker Requirement

Now I understand how this might sound like a good idea to some congress critter. This would seem to be the only way to verify that proper protective actions have been taken. But as a practical matter, this will cause more problems than it could possible solve. Before we get into any of the technical reasons why this is not a good idea we only need to look at the lack of personnel available to be able to do this type of hack. There are probably not 100 people world-wide familiar enough with control systems to conduct such an evaluation and I would venture to guess that none of them are familiar enough with all of the different types of control systems and components to be able to do a complete evaluation.

Secondly, as many recent presentations have pointed out (see my post here and upcoming posts on DigitalBond.com from S4x15) have pointed out, it will take a team of people, various control systems experts and chemical engineers, to cause catastrophic damage at a chemical facility. This is, in many ways good news as it is unlikely that the average terrorist group (particularly home-grown terrorists) will have that level of expertise available to conduct such an attack.

Finally, no chemical facility owner/operator is going to allow any outsider to hack into a live control system involved with the handling, storage or manufacture of hazardous chemicals. The potential for problems is just too high. And taking a system down to allow for such an evaluation off-line is just too costly for most chemical facilities.

Congress and Cybersecurity

It is good to see that Congress is starting to seriously think about cyber security. But provisions like this hacker requirement shows just how far removed from reality too many of these congress critters really are. It will be interesting to see how many problems congress tries to institute as they address the complicated problem of cybersecurity.

Monday, January 12, 2015

HR 54 Introduced – Chemical Facility Security

As I mentioned in an earlier post, Rep. Jackson-Lee (D,TX) introduced HR 54, the Frank Lautenberg Memorial Secure Chemical Facilities Act. This bill is comprehensive chemical facility security bill that is almost a direct copy of S 68 introduced by the late Sen. Lautenberg in the 113th Congress.

I’m not sure why Ms Jackson-Lee introduced this bill. It does not take into account that HR 4007 was introduced last year. It certainly has no chance of being considered in committee in a Republican controlled House, much less of being brought to the floor.


I am rather surprised that this bill was not re-written as a revision of the Title XXI that was put into place by HR 4007 last year. There are a number of provisions in this bill that have been and will remain priorities of many Democrats and some of their most important constituents.

Wednesday, January 7, 2015

Bills Introduced – 1-6-15

Yesterday marked the opening day of the 114th Congress. Along with the mandatory organizational business a large number of bills were introduced; 26 in the Senate and 160 in the House. Those that may be of specific interest to readers of this blog include:

HR 26 - To extend the termination date of the Terrorism Insurance Program established under the Terrorism Risk Insurance Act of 2002, and for other purposes. Rep. Neugebauer, Randy [R-TX-19]

HR 48 - To require a review of the completeness of the Terrorist Screening Database (TSDB) maintained by the Federal Bureau of Investigation and the derivative terrorist watchlist utilized by the.. Rep. Jackson Lee, Sheila [D-TX-18]

HR 53 - To codify an office within the Department of Homeland Security with the mission of strengthening the capacity of the agency to attract and retain highly trained computer and information security... Rep. Jackson Lee, Sheila [D-TX-18]

HR 54 - To enhance the security of chemical facilities and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 60 - To require the Director of National Intelligence to conduct a study on the feasibility of establishing a Cyber Defense National Guard. Rep. Jackson Lee, Sheila [D-TX-18]

HR 85 - To codify the objective of Presidential Policy Directive 21 to improve critical infrastructure security and resilience, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 104 - To protect cyber privacy, and for other purposes. Rep. Conyers, John, Jr. [D-MI-13]


As is the case with many introduced bills many of these will never be mentioned again. HR 26 will not be one of those as that has already been debated today on the floor of the House and will probably be voted upon (and passed) this evening.
 
/* Use this with templates/template-twocol.html */