Showing posts with label IOT Cybersecurity. Show all posts
Showing posts with label IOT Cybersecurity. Show all posts

Tuesday, September 15, 2020

HR 1668 Passed in House – IoT Cybersecurity

 

Today the House took up HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019, under the suspension of rules provisions. The bill was passed by a voice vote. The House Oversight and Reform Committee amended and adopted the bill back in June, but it does not appear that that was the version of the bill that was passed by the House today.

A quick look at the version of the bill printed in the Congressional Record [pg H4351] shows some significant differences from the introduced version and the substitute language taken up by the Committee. A quick-look listing of some of the differences includes:

• Passed version contains a ‘Sense of Congress’ section 2,

• Passed version does not include a definition of ‘covered device’, and

• Passed version adds definitions for ‘operational technology’, ‘information system’.

According to yesterday’s Congressional Record, the House Oversight and Reform Committee published their Report on the bill yesterday, but an official version of the Report has not yet been published by the GPO. A reported version of the bill is, however available, and it does not look like the version passed in the House yesterday.

I will have more on this as I get more information.

Sunday, June 16, 2019

Committee Amended and Adopted HR 1668 – IoT Cybersecurity


This week the House Oversight and Reform Committee adopted substitute language for HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019, by a voice vote. The new language was a complete re-write of the bill.

Changes in Definitions


In §2 of the bill there were significant changes in the definition provided. First the revised language added definitions for ‘Director of OMB’ and ‘Director of the Institute’ (NIST).

Next the definition of ‘covered device’ was substantially changed. The ‘connected to the internet’ and ‘computer processing capability’ portion of the original definition was kept (but reformatted), but the ‘is not a general-purpose computer’ exception portion of the definition was expanded and revised. The new language included a substantial revision of the ‘programmable logic controls’ language of the original bill to now read{§2(2)(C)(iv)}:

Programmable logic controller with an industrial control system specifically not designed for connection to the internet;

A new exception was also added to the definition{§2(2)(C)(v)}; ‘subcomponent of a device’. The new ‘covered device’ definition also removed provisions in the original bill that would have required OMB to establish a process for petitioning for a device to be specifically considered a ‘covered device’.

Finally, the freestanding definition of ‘security vulnerability’ was changed to an incorporation of the definition from 6 USC 1501. The earlier definition was essentially an expansion of the §1501 definition (it had added ‘firmware’ and ‘combination of 2 or more of these factors’), but the §1501 definition relies on the expanded definition of ‘information system’ that specifically includes control system language.

Security Standards


Section 3 of the original bill was spread out into two separate sections. The first would require the National Institute of Standards and Technology (NIST) to complete its current activities ‘regarding considerations for managing the security vulnerabilities of Internet of Things’ {§3} by December 31st, 2019. This is essentially the same language from §3(a)(1) of the original bill with a revision of the date (extended three months) to complete the actions.

The provisions of §3(b) in the original bill were expanded and modified in §4 of the revised language. First the requirement for NIST to establish ‘standards’ for use of internet of things devices by federal government was changed to establishing ‘guidelines’ which the OMB would later convert to ‘standards’.

The closing paragraph of §4 of the revised language requires that “the Federal Acquisition Regulation shall be revised to implement” the standards required to be set by OMB in §4(b). The simplified language in this new paragraph was designed to accomplish the requirement of §4(a) and (b) of the original language.

New Petition Requirement


The petition requirement that was removed from the definition of ‘covered device’ was moved to and expanded in §5 of the revised language. The new section would allow an ‘interested party’ to petition for a covered device to be exempt from the standards set in §4(b). The petitioner would have to establish that the procurement of the covered device {§5(b)(3)(A)}:

• With limited data processing and software functionality would be unfeasible; or
• That does not meet the standards promulgated by the Director of OMB under this Act is necessary for national security or for research purposes.

Coordinated Disclosure


Section 6 of the revised language is a substantial rewrite of §5 and §6 of the original bill. It would still require NIST to establish guidelines with respect to “reporting, coordinating, publishing, and receiving of information” {§6(a)(1)} security vulnerabilities of covered devices and the resolution of those vulnerabilities. The new language does add a requirement for ‘consultation’ with the DHS Cybersecurity and Infrastructure Security Agency (CISA) in the development of the guidelines.

Another important new addition to the guideline requirements is found in §6(b)(3); ensure such guidelines are consistent with the policies and procedures developed by CISA under 6 USC 659(m).

OMB would be required to convert the guidelines developed by NIST into standards to be used by government agencies using covered devices. This requirement specifically applies to including those standards in Federal Acquisition Regulations (FAR).

Section 7 of the bill requires all contractors to comply with the requirements of the standards developed by OMB. It would specifically require each agency Chief Information Officer to “determine if such offeror or contractor has complied with each standard promulgated under section 6(c) with respect to such covered device” {§7(a)(1)(A)}.

Moving Forward


Technically, the House Science, Space, and Technology Committee still needs to act on this bill. This could end up being something as simple as a letter from the Chair saying that he agrees with the changes being offered by the Oversight Committee. Or we could see a full committee markup of the bill.

In any case, this bill may actually see its way to the floor of the House. With the bipartisan support that the revised language received in Committee, it is likely that it would be considered under the suspension of the rules process and would probably pass with similar support.

Commentary


Well, Rep. Kelly (D,IL), or more probably her staff, tried to correct the problems with the definition of ‘covered device’ that I had previously identified in the Senate version of this bill (S 734). Unfortunately the changes made just confuse the issue more.

First, we have a measure of grammatical confusion. As written “programmable logic controller with an industrial control system specifically not designed for connection to the internet” would make it seem that an ‘industrial control system’ was part of a PLC instead of the other way around. Next, there is some subject confusion with the phrase ‘specifically not designed for connection to the internet’ (not to mention the awkward word order); does it refer to the PLC or the ICS. If we are to keep the intended (I think) concept here I would suggest the following revision of this language{§2(2)(C)(iv)}:

“programmable logic controller that is a component of an industrial control system which is specifically designed not to connect to the internet;”

There are still problems with this definition, mainly because it uses terms that are not further defined in the bill nor are they a part of general government usage. Does an ICS include building environmental systems or access control systems? Does the existence of a port designed to allow network connections to the device equate to ‘connect to the internet’ or must the device be physically (cable or WiFi or Bluetooth, or radio) attached to a network that connects to the internet?

If Congress does not specify in legislation than agencies like NIST and OMB get to make the decision. In many ways this can make for more agile regulation development. Unfortunately, it may leave the efficacy and the impact of the regulations to the whims of the regulators. In this case, an aggressive NIST or OMB staffer could decide that a close interpretation of the current exemption language would only apply to the PLC of a building environmental control system, but not the HMI used by the system or the sensors or actuators attached to the PLCs. Since those devices were equipped with ports that could allow internet connections, they would be included in the ‘covered device’ definition and would be regulated by the OMB standards. Or they could go the other way and decide that no one would intend to connect these devices to the internet (even though they had components that could allow such a connection) so they were not ‘covered devices’ and thus not regulated.

While I understand that congresscritters are not technically equipped to make many of these decisions, I am still uncomfortable in allowing the kind of regulatory leeway that I describe above to be exercised by nameless bureaucrats who may (NIST probably, OMB not so sure) a better technical background to make such decisions.

Wednesday, June 12, 2019

HR 1668 Hearing – IOT Cybersecurity


This morning the House Oversight and Reform Committee will be holding a business meeting that will include the markup of HR 1668. Rep. Kelly (D,IL), the sponsor of the bill, is offering substitute language for the bill which is essentially a complete re-write. Changes include a complete rewrite of the definition of ‘covered device’ which specifically excludes a wide range of devices including {§2(2)(c)(iv)}:

Programmable logic controller with an industrial control system specifically not designed for connection to the internet [emphasis added].

I will have more on this revised language in a future blog post.

Sunday, April 21, 2019

HR 1668 Introduced – IoT Cybersecurity


Last month Rep. Kelly (D,IL) introduced HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019. This is a companion bill to S 734.

Kelly (and at least two other cosponsors) is a member of the House Oversight and Reform Committee, one of the two committees to which this bill was assigned for consideration. Rep. Foster (D,IL) is a member of the House Science, Space, and Technology Committee, the other Committee to which the bill was assigned. This means that there is a decent chance that this bill will be considered in these committees.

This bill is more likely to advance in the House than S 734 is to advance in the Senate. I suspect that there would be significant bipartisan support and the bill would be passed in the House under the suspension of the rules process.

Tuesday, March 26, 2019

S 734 Introduced – IOT Cybersecurity


Earlier this month Sen. Warner (D,VA) introduced S 734, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019. Warner introduced a similarly titled bill last session (S 1691), but this bill is a complete re-write of the earlier effort.

Definitions


While last session’s bill had a long series of complicated definitions, this new bill only defines three terms: ‘agency’, ‘covered device’ and ‘security vulnerability’. The ‘agency’ definition is a proforma, yet necessary definition that is of little real importance. The definition of ‘covered device’ is new to this bill and replaces the term ‘internet-connected device’ from the earlier bill. The new term is defined as a physical object that {§2(2)(A)}:

• Is capable of connecting to and is in regular connection with the Internet;
• Has computer processing capabilities that can collect, send, or receive data; and
• Is not a general-purpose computing device, including personal computing systems, smart mobile communications devices, programmable logic controls, and mainframe computing systems.

Sharp-eyed readers will note that this definition was taken from an amendment to HR 5515 last session that was proposed by Sen. Gardner (R,CO); one of the cosponsors to this bill.

Interestingly the definition of a covered device goes on to provide a requirement that the Office of Management and Budget (OMB) establish a process by which interested parties can petition to have a “a device that is not described in subparagraph (A) to be considered a device that is not a covered device” {§2(2)(B)(i)}.

The term ‘security vulnerability is defined as “any attribute of hardware, firmware, software, or combination of 2 or more of these factors that could enable the compromise of the confidentiality, integrity, or availability of an information system or its information or physical devices to which it is connected” {§(2)(3)}.

NIST Requirements


Section 3 of the bill requires the National Institute of Standards and Technology (NIST) to complete current efforts “regarding considerations for managing Internet of Things cybersecurity risks” {§3(a)(1)} to be completed by September 30th, 2019. Those considerations are to include, at a minimum {§3(a)(2)}:

• Secure Development;
• Identity management;
• Patching; and
• Configuration management.

By March 1st, 2020, NIST would be required to “develop recommendations for the Federal Government on the appropriate use and management by the Federal Government of Internet of Things devices owned or controlled by the Federal Government, including minimum information security requirements” {§3(b)(1)}.

Finally, NIST would be required within 180 days of the passage of this bill to publish a draft report on “the increasing convergence of traditional Information Technology devices, networks, and systems with Internet of Things devices, networks and systems and Operational Technology devices, networks and systems, including considerations for managing cybersecurity risks associated with such trends” {§(3)(c)}

OMB Requirements


Section 4 of the bill outlines the requirements for OMB to address IoT cybersecurity in the Federal Acquisition Regulations (FAR). Within 180 days of NIST’s publication of recommendations on the use of IoT devices, the OMB would be required to “issue guidelines for each agency that are consistent with such recommendations” {§4(a)}. Those guidelines would have to be consistent with the information security requirements of 44 USC Chapter 35, Subchapter II.

OMB and NIST would also be required to undertake reviews of the recommendations and guidelines described in this bill every five years.

Coordinated Disclosure Policy


Section 5 of the bill would establish NIST as the organization responsible for establishing policies and procedures for “for the reporting, coordinating, publishing, and receiving of information about” {§5(a)} security vulnerabilities of covered devices and their resolution. Those policies and procedures would be aligned as much as practicable with ISO 29147 and ISO 30111.

Section 6 of the bill would require OMB to issue guidelines to federal agencies on how to comply with the processes established by NIST.

Moving Forward


While Warner is not on the Senate Homeland Security and Governmental Affairs Committee, the committee to which this bill was assigned for consideration, one of his three cosponsors, Sen. Hassan (D,NH) is. This means that it is reasonable to assume that the bill may received consideration in that Committee. The main holdup is that the Chair, Sen. Johnson (R,WI), has deep-seated concerns about adding anything smacking of regulations concerning cybersecurity. While this bill does not specifically call for cybersecurity regulations, the ‘policies, procedures and guidelines’ that vendors selling covered devices to the government would be required to follow have the same general impact as regulations.

I would not be surprised if this bill did not make it out of Committee. One way that Johnson could ensure this is that after a markup hearing was held, the Committee report on the bill could be delayed indefinitely.

Commentary


This new version of the IoT cybersecurity bill is much better written than the version introduced in the last session. The limitations on the definition of ‘covered device’ generally make a reasonable distinction between ‘internet connected devices’ and IoT. I do, however, still have some nits to pick on the details of how that limitation/distinction is made.

The sub-paragraph in question removes ‘general-purpose computing devices’ from consideration as ‘covered devices’. It then lists the following examples of those g-p devices:

• Personal computing systems;
• Smart mobile communications devices;
• Programmable logic controls; and
• Mainframe computing systems

Since none of these exclusionary terms are defined in the bill, I would suspect that the staffers who crafted this bill wanted to provide NIST and OMB with significant latitude in what would be included in the exclusion from the definition of IoT. Generally speaking, that is a good thing. Having said that, I do have problems with the term ‘programmable logic controls’. First off, I need to get a tad bit anal retentive here; the term should be ‘programmable logic controllers’.

In a broader context, even that corrected term may be an unnecessarily restrictive substitute for the term ‘industrial control system’. While PLCs are certainly very common components of industrial control system, there are a large number of other components of those systems that are not generally considered IoT (or IIoT, industrial internet of things), but could not be reasonably included in the term PLC.

While I am a strong believer in cybersecurity in industrial control system, I do not think that this bill and its loose regulatory framework are the appropriate place to establish standards for ICS cybersecurity and particularly the internet connected devices associated with industrial control systems. With that in mind, I would propose that the term ‘industrial control system’ should be substituted for the term ‘programmable logic controls’ in the definition of ‘covered device’.

Friday, June 30, 2017

HR 3010 Introduced – Cyber Hygiene

Last week Rep. Eshoo (D,CA) introduced HR 3010, the Promoting Good Cyber Hygiene Act of 2017. The bill would require the National Institute of Standards and Technology to establish a list of best practices for effective and usable cyber hygiene based upon the Cybersecurity Framework (CSF) established pursuant to EO 13636.

Information System Guidelines


The best practice guidelines would be available to all personnel “utilizing an information system or device”. Adoption of the best practices would be voluntary and should serve as a baseline upon which additional cybersecurity practices are established. NIST would be required to update the guidelines on an annual basis.

The guidelines would {§2(a)}:

• Be a list of simple, basic controls that have the most impact in defending against common cybersecurity threats and risks; and
• Utilize technologies that are commercial off-the-shelf and based on international standards

IOT Cyber Hygiene


Paragraph 2(h) of the bill would require DHS (in coordination with NIST and the Federal Trade Commission)  to conduct a study of “cybersecurity threats relating to the Internet of Things” (IoT) {§2(h)(2)}. The study would {§2(h)(3)}:

• Assess cybersecurity threats relating to the Internet of Things;
• Assess the effect such threats may have on the cybersecurity of the information systems and networks of the Federal Government; and
• Develop recommendations for addressing such threats.

In this paragraph IoT is defined as “the set of physical objects embedded with sensors or actuators and connected to a network” {§2(h)(1)}.

Moving Forward


Neither Eshoo nor her co-sponsor, Rep. Brooks (R,IN), is a member of the House Science, Space, and Technology Committee, the Committee to which this bill was assigned for consideration. This means that it is extremely unlikely that the bill will be considered in that Committee.

There is nothing in this bill that would cause any serious opposition to the bill if it was considered in committee or on the floor of the House or Senate.

Commentary


The lack of a definition of ‘information system or device’ would typically mean that the common usage of that term, the narrow IT centric definition, would probably exclude industrial control systems (ICS) from specific inclusion in the cyber hygiene guidelines.

Having said that, the very wide and ICS-inclusive definition of IoT that would support Federal information systems and networks throws the whole meaning of ‘information system’ open to serious interpretive problems.

For the purposes of this bill, however, since neither NIST nor DHS would be provided any funding to establishing the guidelines or conducting the study, the two agencies would use the narrowest, IT-centric definition. They would certainly be ignoring the much more complex ICS cybersecurity issues for the NIST guidelines.


This would greatly reduce the scope of any IoT study conducted under provisions of this bill. The only devices that would probably be considered would be devices supporting network communications and server farms. That is a very small part of the IoT cybersecurity problem. Including the IoT study in this bill underlines how poorly congresscritters and their staffs understand the potential scope of IoT cybersecurity issues.

Friday, April 14, 2017

NTIA Announces IOT Cybersecurity Meeting

Today the Department of Commerce’s National Telecommunications and Information Administration published a meeting notice in the Federal Register (82 FR 17977-17978) concerning their Multistakeholder Process on Internet of Things (IOT) Security Upgradability and Patching. The public meeting will be held on April 26th, 2017 in Washington, DC.

The earlier meetings on this topic were held by NTIA on October 19th, 2016 and January 31st, 2017.

An agenda for the meeting is not yet available, but according to the meeting notice:

“Stakeholders have identified four distinct work streams that could help foster better security across the ecosystem. The main objectives of the April 26, 2017 meeting are to share progress from the working groups and hear feedback from the broader stakeholder community. Stakeholders will also discuss their vision of the timing and outputs of this initiative, and how the different work streams can complement each other.”

The meeting will be webcast. See the Multistakeholder web site for more information. 
 
/* Use this with templates/template-twocol.html */