Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Monday, September 12, 2016

NARA Sends Industrial Security Program NPRM to OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the National Archives and Records Administration (NARA) for revisions of the National Industrial Security Program (NISP, 32 CFR 2004). NISP was established by Executive Order 12829.

According to the Spring 2016 Unified Agenda abstract:

“The Information Security Oversight Office (ISOO), a component of NARA, is proposing this rule pursuant to Executive Order 12829, relating to the National Industrial Security Program (NISP). The proposed changes are primarily administrative, bringing together the original 2006 regulation, the 2010 change, and some updated requirements. However, a small portion of the new provisions deal with requirements from Executive Order 13587 [link added] to implement the insider threat program, and could have a potentially significant effect on agencies implementing that program's requirements.”


NISP is a DOD defense industrial base information security program addressing classified information security and thus will have little direct effect on most manufacturing facilities. It could be instructive, however, for possible future regulations on other classified information sharing programs.

Tuesday, June 25, 2013

NARA Announces NISPPAC Meeting – 7-17-13

Today the National Archives and Records Administration (NARA) published a meeting notice in the Federal Register (78 FR 38077) for a July 17th meeting of the National Industrial Security Program Policy Advisory Committee (NISPPAC) in Washington, DC.

There is no information in the notice about the agenda and the NISPPAC web page does not appear to publish agenda’s in advance of their meetings.


Anyone wishing to attend this public meeting must register with the Information Security Oversight Office (ISOO) by contacting David Best (david.best@nara.gov) by July 12th, 2013.

Thursday, June 20, 2013

Impediments to Information Sharing

There is an interesting article over at FederalNewsRadio.com discussing some of the challenges that DHS is trying to overcome in order to provide an information sharing environment about cybersecurity issues. One of the issues raised in the article concerns the difficulty that DHS is having in expanding the participation in the Enhanced Cybersecurity Services (ECS) program. This is the program established to share classified threat information with potentially affected private sector organizations.

Sharing Classified Information

In order to encourage the sharing of this classified information, Congress has focused on directing the DHS Secretary to work on reducing the red tape necessary to get security clearances for private sector employees. Unfortunately, the effective sharing of classified information requires lot more than just providing security clearances; an infrastructure must be put into place to receive, store and protect that information.

Security Requirements for Classified Information

Unless DHS is going to rely on couriers with manacled briefcases to deliver and retrieve classified documents to and from private sector organizations, some sort of secure communications equipment will have to be installed. While modern crypto gear has certainly progressed past the point of the equipment I used in the Army 30 years ago, this still requires special equipment that must be secured against theft and tampering and requires some level of training to operate. Even something as simple as a secure telephone must be placed in an isolated room so that classified conversations may not be overheard through other communications devices.

To be useful, classified threat information will have to be discussed within an organization, documents will have to be prepared, stored and shared, and provisions will have to be made for the destruction of classified documents and devices. An entire information security apparatus, maintained to government (ie: military) standards will have to be established, maintained and periodically audited by a government agency.

Cost of Classified Infosec Program

Now many organizations already work on classified projects for the military or intelligence community, so they will already have this type of operation in place. I would bet that the ‘seventeen or so’ companies that are currently participating in ECS program already had a DOD approved information security program in place. Establishing a military-grade infosec program will just be too costly (in set up and maintenance) to make it worthwhile for most organizations based upon possible access to actionable intelligence about a classified cyber-threat.

Alternative Required

No, while the ECS program will be viable for a limited number of organizations that already have an infosec program in place, DHS is going to have to come up with an alternative that does not rely on these specialized information control measures. Someone is going to have to establish a methodology for converting classified intelligence information into actionable information for the private sector that only requires limited infosec capabilities.


Readily achievable standards for the protection of that information will have to be developed if DHS expects to establish a cyber-threat information sharing capability that will involve the sharing of high-quality threat information with the bulk of critical infrastructure organizations. Something along the lines of the Chemical-Terrorism Vulnerability Information (CVI) program used by the CFATS program would probably be adequate since it has a manual that provides guidance on how to mark and protect the information.

Sunday, July 1, 2012

Differences Between S 2151 and S 3342


I noted last week Sen. McCain introduced S 3342 and without seeing the bill I expected that it was some sort of compromise between his earlier bill, S 2151, and the Senate bill that has been expected to move forward, S 2105. This weekend the GPO made S 2151 available on-line and it turns out that the new bill is more properly a tweaking of McCain’s earlier bill, falling well short of being a compromise measure.

Changes in the Bill


The new bill adds the following new sections:

§104. Construction.

§106. Inspector General review.

§205. Clarification of authorities.

§307. No new funding.

Only one section was removed; §408. Cybersecurity strategic research and development plan.

Additionally, a number of new definitions were added to §101. They include:

• Federal information system

• Information security

• Local government

• Significant cyber incident

• Tribal

Finally there were a number of wording changes that fine-tuned the privacy provisions and information sharing requirements of the bill. The details of those changes, and the added provisions, will probably only be of interest to lawyers and politicians.

There really are no significant changes in the bill and it still completely ignores the problem of cybersecurity of industrial control systems.

Moving Forward


With both the Senate and the House being on their extended July 4th holiday next week nothing is going to get done any time soon on the cybersecurity legislative front. This bill is dead in the water as the only bill that has any chance of moving forward in the Senate (after inevitable changes) is S 2105. Even that bill has little chance of passing before the election due to privacy concerns and business opposition to new regulations; too many people on both sides of the aisle oppose the bill, so it is unlikely to come to a vote. In most cases this opposition is not just election year posturing so passage even in the lame duck session is unlikely.
 
/* Use this with templates/template-twocol.html */