Showing posts with label Maritime Cybersecurity. Show all posts
Showing posts with label Maritime Cybersecurity. Show all posts

Tuesday, January 21, 2025

Review - CG Published Maritime Cybersecurity Final Rule

Last week, the Coast Guard published a final rule in the Federal Register (90 FR 6298-6453) on Cybersecurity in the Marine Transportation System. The notice of proposed rulemaking was published on February 22nd, 2024 (see additional NPRM posts here and here – both removed from paywall). This rule updates the maritime security regulations by establishing minimum cybersecurity requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities subject to the Maritime Transportation Security Act of 2002 regulations.

In addition to the obligatory cybersecurity point-of-contact requirement, the final rule requires covered ships, platforms and facilities to have a cybersecurity plan that includes:

Account security measures,

Device security measures, and

Data security measures,

Additionally, the final rule addresses,

Cybersecurity training,

Risk management,

Supply chain issues,

Resilience,

Network segmentation, and

Physical security.

Effective Date

The effective date for this final rule is July 16th, 2025.

Friday, November 22, 2024

CG Sends Maritime Cybersecurity Final Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the Coast Guard on “Cybersecurity in the Marine Transportation System”. The notice of proposed rulemaking (NPRM) was published [removed from paywall] on February 22nd, 2024.

According to the 2024 Spring Unified Agenda entry for this rulemaking:

“The Coast Guard has published a proposed rule to update its maritime security regulations by adding regulations specifically focused on establishing minimum cybersecurity requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and U.S. facilities subject to the Maritime Transportation Security Act of 2002 regulations.  This proposed rulemaking is part of an ongoing effort to address emerging cybersecurity risks and threats to maritime security by including additional security requirements to safeguard the marine transportation system.”

Sunday, July 12, 2020

S 4023 Introduced – Maritime Cybersecurity

Last month Sen Markey (D,MA) introduced S 4023, the Enhancing Maritime Cybersecurity Act of 2020. The bill would require that the DHS Cybersecurity and Infrastructure Security Agency (CISA) ensure the availability of a resource, or a consolidated series of resources, to assist maritime operators in identifying, detecting, protecting against, responding to, and recovering from cyber incidents. No funding is authorized by this bill.

Definitions


Section 2(a) of the bill provides the definition of key terms used in the legislation. It takes the definition of the term ‘cyber incident’ from the Presidential Policy Directive #41 (July 26th, 2016). That document defines the term as:

“An event occurring on or conducted through a computer network that actually or imminently jeopardizes the integrity, confidentiality, or availability of computers, information or communications systems or networks, physical or virtual infrastructure controlled by computers or information systems, or information resident thereon. For purposes of this directive, a cyber incident may include a vulnerability in an information system, system security procedures, internal controls, or implementation that could be exploited by a threat source.”

Cybersecurity Resources


Section 2(b) of the bill would require CISA, in consultation with the Maritime Administration and the Coast Guard, to make available cyber security resources designed to “to assist maritime operators in identifying, detecting, protecting against, responding to, and recovering from cyber incidents” {2(b)(1)}. The cybersecurity resources would be based upon the NIST Cybersecurity Framework and the IMO “Guidelines on Maritime Cyber Risk Management”. The resources directive includes a mandate for CISA to “establish a structured cybersecurity assessment and development program” {§2(b)(2)(C)}.

Cyber Coordinator


Section 2(c) would require the DOT’s Maritime Administration to “designate an office as a ‘cyber coordinator’. That office would be responsible for:

• Coordinating with the CISA and the Coast Guard on cybersecurity activities for the commercial maritime sector and cyber incidents that affect maritime operators,
• Ensuring that maritime operators are aware of available secure methods of notifying the United States Government of cyber incidents,
• Notifying the CISA and the Coast Guard of unaddressed cyber incidents that affect maritime operators,
• Ensuring that maritime operators have access to educational resources, conducting outreach, and ensuring awareness on fundamental principles and best practices in cybersecurity for maritime systems, including the cyber resource developed under this section.

Moving Forward


Markey is a member of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration. Markey is the Ranking Member of the Security Subcommittee. This should mean that he would have enough influence to see this bill considered in Committee. Unfortunately, this is a COVID-19 reduced election year where minor bills like this are unlikely to receive consideration.

I see nothing in this bill that would engender serious opposition to the bill, especially since no monies are authorized.

Commentary


With no cosponsors associated with the bill, this looks like another stone in Markey’s cybersecurity house that will not be going anywhere. It will help to establish Markey as a cybersecurity legislator but will do nothing to see actual cybersecurity law or policy affected.

If this bill were to advance there are a couple of changes that I would like to see included in the bill. First I would like to see §2(c) changed from designating an existing office as ‘cybersecurity coordinator’ to establishing an Office of Maritime Cybersecurity. That Office would work closely with the Coast Guard’s Cyber Command on maritime cyber incident investigations. It would also be responsible for sharing anonymized information about cybersecurity incidents with maritime operators. Finally, the Office would be responsible for working with the United States Merchant Marine Academy and six State Maritime Academies to ensure that cybersecurity education is an integral part of the academic program at the academies.

Tuesday, June 23, 2020

Bills Introduced – 6-22-20


Yesterday with the Senate in Washington and the House meeting in pro forma session there were 41 bills introduced. Two of those bills are likely to see additional coverage in this blog:

S 4023 A bill to enhance maritime cybersecurity. Sen. Markey, Edward J. [D-MA]

S 4024 A bill to establish in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security a Cybersecurity Advisory Committee. Sen. Perdue, David [R-GA] 

I will be watching both bills for definitions and language that specifically include control system cybersecurity issues.

Sunday, December 23, 2018

CG Updates Cyber Guidelines for Vessels


Earlier this month the Coast Guard published an updated version of “The Guidelines for Cybersecurity Onboard Ships”.  The 53-page .PDF document provides a non-technical overview of cybersecurity concerns and activities that is not technically an official Coast Guard document. While it addresses both IT and OT cybersecurity issues it concentrates on the interaction of cybersecurity and safety; coming up with an interesting new term that those in the OT cybersecurity field are sure to find helpful: “cyber safety incidents”.

There is lots of useful information in this document for the non-technical management of cybersecurity risks. One of the interesting aspects of the way that the information is presented it that it includes numerous examples of real-life incidents where a wide variety of cyber safety incidents led to high-cost results. While the authors are careful to remove identifying data from the incident descriptions, many of the incidents used were high-profile news stories.

This is certainly a useful document, both for managers responsible cyber risk management, but also for security professionals to better help them communicate with those non-technical managers who control the cybersecurity purse strings.

One minor point for the presentation designers of this document; the page numbers are awfully hard to read.



 
/* Use this with templates/template-twocol.html */