Showing posts with label IoT Security. Show all posts
Showing posts with label IoT Security. Show all posts

Wednesday, November 18, 2020

HR 1668 Passed in Senate – IoT Cybersecurity

Yesterday the Senate passed HR 1668, the IoT Cybersecurity Improvement Act of 2020, by unanimous consent. The bill was passed in the House in September and alert readers will recall that the version voted upon in the House was not the version reported out of Committee. The bill now goes to the President for signature. There have been no indications from the White House about how President Trump intends to deal with this bill.

As I mentioned in my earlier post, it seems to me that this is more of an IT security bill than an IoT security bill, other than for the requirement for GAO to report on “broader Internet of Things efforts, including projects designed to assist in managing potential security vulnerabilities associated with the use of traditional information technology devices, networks, and systems” {§8(a)}.

Thursday, July 13, 2017

S 1475 Introduced – Cyber Hygiene

Last month Sen. Hatch (R,UT) introduced S 1475, the Promoting Good Cyber Hygiene Act of 2017. This is very similar to HR 3010. While not strictly a companion measure (due to changes in formatting, word order and organization) this bill would establish the same voluntary cybersecurity program; principally for use by the Federal Government.

Moving Forward


Unlike the sponsorship situation with HR 3010, Sen. Markey (D,MA), a cosponsor of this bill, is a member of the Senate Commerce, Science, and Transportation Committee (Hatch is not) so there is a possibility that this bill could be considered by that Committee.

Markey has worked hard on establishing a reputation as a cybersecurity gadfly (I use that term with a certain amount of admiration) in the Senate. Unfortunately, his scattergun approach to crafting cybersecurity language has left him with a significant amount of inherent opposition to his bills; none of the bills that he has offered to date (admittedly still early in the session) has been considered in Committee.

Commentary



This bill sounds good, but, like its companion, it has some serious definition problem in the IoT provisions. That ICS-inclusive definition has essentially no effect on the study required because that study is to be to consider the effects of the identified cybersecurity concerns upon Federal IT systems.

Tuesday, November 15, 2016

ICS-CERT Publishes Advisory and IOT Security Documents

Today the DHS ICS-CERT published a control system security advisory for a product from Lynxspring. They also established a new web page and published two documents related to cybersecurity for internet-of-thing (IoT) devices.

Lynxspring Advisory


This advisory describes multiple vulnerabilities in the Lynxspring BAS Bridge application. The vulnerabilities were reported by Maxim Rupp. Lynxspring reports that the BAS Bridge has been discontinued and recommends that owners upgrade to the Onyxx Bridge product.

The reported vulnerabilities are:

• Permissions, privileges and access controls - CVE-2016-8357;
• Missing authentication for critical function - CVE-2016-8361;
• Insufficiently protected credentials - CVE-2016-8378; and
• Cross-site request forgery - CVE-2016-8369.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerabilities to change permissions and access controls and gain access to the system.

IOT Security


The new IOT web page provides links to two new IoT security publications:

IOT Fact Sheet; and

The IoT security discussion is based upon six principles:

• Incorporate Security at the Design Phase;
• Advance Security Updates and Vulnerability Management;
• Build on Proven Security Practices;
• Prioritize Security Measures According to Potential Impact;
• Promote Transparency across the IoT; and
• Connect Carefully and Deliberately

The Fact Sheet briefly describes these principles and the Strategy document fleshes out the discussion. Nothing really new in the discussion, but it is all brought together into a single document. The Strategy is written at a slightly more technical level than most recent ICS-CERT documents, directed more at CIO’s and security managers than CEO’s. It also provides a fairly diverse set of links in the Guidance and Additional Resources Appendix (I was especially pleased to see links to two documents from I Am The Cavalry (Five Star Automotive Cyber Safety Framework and Hippocratic Oath for Connected Medical Devices).

This discussion addresses the technical issues, but only briefly touches on the underlying problem of the wide diversity of IoT devices, vendors and users. Trying to get all of the parties to understand the state of the problem and the necessity of taking care of the problem cannot be overlooked in any discussion of IoT security. One area of that problem that receives very little attention in these documents is how to deal with the currently installed base (and devices already in the supply chain) of IoT devices that meet none of the principles discussed in the document.


To be fair to ICS-CERT these problems are more political and sociological than technical. It would have been nice, however, for ICS-CERT to at least identified these problems in these documents.
 
/* Use this with templates/template-twocol.html */