Showing posts with label NARA. Show all posts
Showing posts with label NARA. Show all posts

Friday, December 23, 2016

OMB Approves National Industrial Security Program NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the National Archives and Record Administration’s (NARA) Information Security Oversight Office (ISOO) proposing changes to the National Industrial Security Program (NISP – 32 CFR 2004). This rule implements provisions of Executive Order 12829 and the insider threat provisions of Executive Order 13587.


This rulemaking may have effects on organizations receiving, storing, or producing classified threat intelligence information including cybersecurity threat information.

Wednesday, December 21, 2016

FERC Publishes CEII Revision Final Rule

Today the DOE’s Federal Energy Regulatory Commission (FERC) published a final rule implementing changes to the Critical Energy Infrastructure Information (CEII) program mandated by §61003 (16 USC 824o–1) of the Fixing America's Surface Transportation (FAST) Act (PL 114-94). The notice of proposed rulemaking NPRM (FERC uses a different acronym – NOPR) was published in June of this year. This rule is unlikely to be overturned by the 115th Congress.

Congressional Mandate


The FAST Act required FERC to:

• Establish criteria and procedures to designate information as critical electric infrastructure information;
• Prohibit the unauthorized disclosure of critical electric infrastructure information;
• Ensure there are appropriate sanctions in place for Commissioners, officers, employees, or agents of the Commission or the Department of Energy [DOE] who knowingly and willfully disclose critical electric infrastructure information in a manner that is not authorized by the statute; and
• Facilitate voluntary sharing of critical electric infrastructure information  between, and by Federal, State, political subdivision, and tribal authorities; the Electric Reliability Organization; regional entities; information sharing and analysis centers; owners, operators, and users of critical electric infrastructure in the United States; and other entities determined appropriate by the Commission.

CEII


A number of commenters on the NPRM requested that the Commission provide more details on what constitutes CEII. The preamble to this rule notes that §824o-1(a)(2) provides a definition of CEII. As a result FERC does not see any need to provide additional guidance on what constitutes CEII. FERC reminds commenters that CEII protections only apply to information submitted to FERC and DOE so no other agencies (including the NRC) may designate information CEII. That does not, however, prohibit other agencies from providing protections to electric grid related information submitted to non-DOE agencies.

Protection of CEII and CUI


FERC declined to provide clarification of what constitutes ‘a secure place’ for storing CEII. The preamble to this rule failed to note that by not specifying regulatory requirements for storing CEII that the controlled unclassified information (CUI) regulations of the National Archives and Records Administration provide the controlling authority to define those requirements (including NIST SP 800-171 for electronic storage and transmission) since CEII is a covered CUI listed in the CUI registry.

Effective Date


This rule will become effective on February 21st, 2017. As I noted earlier, this rule is unlikely to be considered for review by the 115th Congress. The rule implements requirements set by the Republican 114th Congress so there will be little impetus for essentially the same Congress to negate this rulemaking even though it fulfills many of the definitional requirements of a ‘midnight rule’.

Commentary


The CEII program only protects information submitted to FERC and the DOE from disclosure by those agencies or personnel with whom those agencies share the information. It does not establish any requirements for protection of that information by submitting organizations. The only drawback that I see is that FERC/DOE are not required to make a determination that the information actually qualifies for CEII protections until the CEII Coordinator at FERC makes that determination in response to a request for the information.


FERC maintains in this rulemaking that the protect submitted information as if it were CEII until such determinations are made. I think that a good lawyer for a whistleblower could maintain that any disclosures of information by FERC/DOE employee prior to a determination being made by the CEII Coordinator. To my mind it would make more sense to declare all submitted material CEII upon receipt and then to remove that declaration when appropriate when the CEII Coordinator is asked to review the information for possible release.

Monday, September 12, 2016

NARA Sends Industrial Security Program NPRM to OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the National Archives and Records Administration (NARA) for revisions of the National Industrial Security Program (NISP, 32 CFR 2004). NISP was established by Executive Order 12829.

According to the Spring 2016 Unified Agenda abstract:

“The Information Security Oversight Office (ISOO), a component of NARA, is proposing this rule pursuant to Executive Order 12829, relating to the National Industrial Security Program (NISP). The proposed changes are primarily administrative, bringing together the original 2006 regulation, the 2010 change, and some updated requirements. However, a small portion of the new provisions deal with requirements from Executive Order 13587 [link added] to implement the insider threat program, and could have a potentially significant effect on agencies implementing that program's requirements.”


NISP is a DOD defense industrial base information security program addressing classified information security and thus will have little direct effect on most manufacturing facilities. It could be instructive, however, for possible future regulations on other classified information sharing programs.

Tuesday, August 9, 2016

OMB Approves NARA CUI Final Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the final rule from the National Archives and Records Administration (NARA) concerning the administration of the various Federal Controlled Unclassified Information (CUI) programs. The final rule was submitted to OIRA back in October of last year. The notice of proposed rulemaking (NPRM) was published in May, 2015 and I did a series of blog posts on the provisions of that NPRM.

This rulemaking is mainly targeted at protecting CUI on government and contractor IT systems. It is expected that it will require the implementation of NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations, as the IT security standard for contractors and other non-government organization that are required to protect CUI.

Readers of this blog will be interested in this rule making because of its potential effects on the following CUI programs:



I expect that the final rule will be published in the Federal Register later this week.

NOTE: Corrected SSI program link - 08-10-16 21:30 EDT

Thursday, February 25, 2016

3 DHS Acquisition Cybersecurity Rules to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received three notices of proposed rulemaking (NPRM) from the DHS Office of the Secretary relating to cybersecurity requirements in the DHS acquisition process. Those rulemakings were:


Only the first rulemaking has been published in the Unified Agenda so we can only make assumptions as to the content of the other two. It is very possible that the second does not really address cybersecurity issues at all.

The unified agenda listing for the Safeguarding of Sensitive Information rule only specifically mentions personally identifiable information, but the way that it is worded could certainly include controlled but unclassified (CBU) information that will be regulated by rules being established by the National Archives and Records Administration (final rule under review at OIRA). It will be interesting to see if this DHS rule includes the same NIST computer standards that are expected to be included in the NARA rule.


OIRA typically approves acquisition rulemakings faster than wider regulatory issues so we might see an approval here in the next month or so.

Saturday, October 31, 2015

NARA Sends CUI Final Rule to OMB

Earlier this week (but available on-line for the first time today) the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that that the National Archives and Records Administration (NARA) had submitted their final rule on Controlled Unclassified Information for review. The notice of proposed rulemaking on this rule was published last May.

NARA has moved pretty quickly on this final rule with the comment period on the NPRM having closed in July. They were assisted on this by the relatively low number of comments (13) received on the NPRM.


It will be interesting to see how long it takes OIRA to approve the final rule. The NPRM took alomost a year to approve (May 20, 2014 to May 5, 2015). I’m sure that a bunch of the delay was working out agreements with the various affected Federal agencies. That may mean that this is a done deal within the government, but you never can tell.

Thursday, May 14, 2015

CUI NPRM – Safeguarding CUI

This is the second in a series of posts on the notice of proposed rulemaking (NPRM) recently published by the National Archives and Records Administration’s (NARA) Information Security Oversight Office (ISOO) on the establishment and harmonization of controls on controlled unclassified information (CUI). Other posts in the series include:


In this post I will look at one of the key elements that make up the CUI program, the requirements for safeguarding CUI outlined in §2002.12. The guiding principle that must be remembered when considering the safeguarding requirements is that CUI must be protected at all times in a manner that “minimizes the risk of unauthorized disclosure while allowing for access by authorized holders”.

In all discussions about CUI protections it must be remembered that the CUI regulation will only apply to federal government agencies. Any agency that shares or discloses CUI to an entity outside of the federal government is encouraged by NARA to “enter formal information-sharing agreements and include a requirement that any non-executive branch party to the agreement comply with the Order, this part, and the CUI Registry”. Such language should also be part of any contractor agreement where CUI could be shared.

What Standards Apply

There are actually two sets of safeguarding standards that can apply to CUI information. The first is CUI Basic. These standards are outlined in the CUI regulations. The second is CUI Specified. These standards are set by law, regulation, or government wide policy. The agencies may only apply CUI Specified standards if the category or subcategory listed in the CUI Registry notes that the particular CUI is specified. When the underlying law, regulation or policy for a specified CUI is silent on a particular standard set in the CUI Basic, then the CUI Basic requirements apply to that safeguarding method.

Controlled Environment

This rulemaking would require that authorized holders of CUI must have access to a controlled environment in which to access CUI while protecting it from unauthorized access or observation. In addition authorized holders having conversations about CUI need to take reasonable precautions against the conversation being overheard by unauthorized individuals.

When CUI is handled outside of a controlled environment it must either be under the direct control of an authorized holder or must be protected by at least one physical barrier that reasonably protects the information from unauthorized access or observation.

Transmitting CUI

When CUI is processed, stored or transmitted via a federal information system it must be protected in accordance with FIPS Publications 199 and 200 as well as NIST SP 800-53. NIST is currently in the process of developing NIST SP 800-171 as a standard for non-federal information systems processing, storing or transmitting CUI. Again this standard should be specified by federal agencies in agreements with outside entities handling CUI.

When CUI is physically transferred outside of the control of an authorized person, it may be done by US Mail or commercial delivery service. The use of interoffice and interagency mail systems is also authorized. No CUI markings should be on the outside of the envelope or package. They should be marked, however, that they are intended for the recipient only and should not be forwarded.

Reproducing CUI

CUI can only be reproduced (by copying, scanning, printing, or electronically duplicating) in “furtherance of a lawful Government purpose”. When using copying devices you must ensure that a copy is not retained in the device or the device must be ‘sanitized’ in accordance with NIST SP 800-53.

Destroying CUI


The rulemaking would allow agencies to destroy CUI only when the agency no longer needs the information and records retention rules no longer require it to be held. When destroying electronic versions of CUI it must be done in a manner that “makes it unreadable, indecipherable, and irrecoverable” in accordance with established procedures. There is no discussion of standards for the destruction of physical versions of CUI.

Saturday, May 9, 2015

CUI NPRM – General Information

This is the second in a series of posts on the notice of proposed rulemaking (NPRM) recently published by the National Archives and Records Administration’s (NARA) Information Security Oversight Office (ISOO) on the establishment and harmonization of controls on controlled unclassified information (CUI). Other posts in the series include:


The first subpart of the rule outlines the general information about the CUI program. It includes:

∙ Purpose and scope.
∙ Definitions.
∙ CUI Executive Agent.
∙ Roles and responsibilities.

Purpose and Scope

This section explains that the CUI program “establishes policy for designating, handling, and decontrolling information that qualifies as CUI” {§2002.1(a)} as it attempts to balance “the need to safeguard CUI with the public interest in sharing information appropriately and without unnecessary burdens” {§2002.1(d)}.

While this rulemaking is primarily directed at executive branch agencies, it “also applies, by extension, to agency practices involving non-executive branch CUI recipients” {§2002.1(e)}. Those non-executive branch CUI recipients include contractors and other non-executive branch entities. Where laws, regulations or ‘government wide policies’ do not govern the sharing of CUI with those ‘other entities’, the rulemaking specifically recommends agencies establish formal information-sharing agreements that require the non-executive branch entity to comply with the underlying Executive Order (EO 13556) and this regulation.

Finally, this section makes it clear that this program does not supersede any existing requirements established by law, regulation or government wide policy; those requirements are incorporated as ‘CUI Specified’ requirements under this regulation.

Definitions

This section provides a very large number of definitions of terms used in this rulemaking. Some of the more important terms defined include:

CUI Basic;
Document (very expansive definition);

I will be discussing the concepts related to these terms in more detail in later posts.

CUI Executive Agent

In EP 13556 the President designated NARA as the Executive Agent for this program and that authority was further delegated to ISOO.

Roles and Responsibilities

This section outlines the responsibilities for various personnel in the establishment, implementation and oversight of the CUI program. The personnel included in this section are the:


While the first three listings show the normal establish, designate and oversee responsibilities associated with any regulatory program, the last one is a bit odd. This is the listing for the DNI {§2002.4(d)}:

“The Director of National Intelligence: After consultation with the heads of affected agencies and the Director of the Information Security Oversight Office, may issue directives to implement this part with respect to the protection of intelligence sources, methods, and activities. Such directives must be consistent with the Order, this part, and the CUI Registry.”


It would seem that even after the four plus years that this NPRM has been in the works, there is still some work that remains to be done.

Friday, May 8, 2015

Controlled Unclassified Information NPRM

Today the National Archives and Records Administration’s Information Security Oversight Office (ISOO) published a notice of proposed rulemaking (NPRM) in the Federal Register (80 FR 26501-26511) concerning the harmonization of the way that the Federal Government manages the security of Controlled Unclassified Information (CUI). The authority for this rulemaking is drawn from Executive Order 13556, Controlled Unclassified Information. The National Institute of Standards and Technology (NIST) is providing cybersecurity guidance supporting this program in SP 800-171.

The NPRM would add 32 CFR Part 20 to the Code of Federal Regulations. It would consist of three subparts:

Subpart A – General Information;
Subpart C – CUI Program Management

Purpose

The federal government produces a great deal of sensitive information. Some of that information is classified information with specific rules for classifying, marking and protecting the information. Those rules are not affected by this NPRM. This NPRM attempts to do establish the baseline rules for classifying, marking and protecting sensitive (but not classified) information in over 100 existing programs.

There are a couple of factor that complicate the issue. First is the fact that some of those programs have procedures already in place that were established by law or regulation. This rulemaking will have minimal effect on those procedures. Secondly there has been no centralized authority to oversee the administration of these programs. That was changed by EO 13556 which gave NARA the authority which was further delegated to ISOO.


“The CUI Program provides a unified system for handling unclassified information that requires safeguarding or dissemination controls, and sets consistent, executive branch-wide standards and markings for doing so. The CUI Program has established controls pursuant to and consistent with already-existing applicable law, Federal regulations, and Government-wide policy. However, because those authorities, as well as ad hoc agency policies and practices, were often applied in different ways by different agencies, the CUI Program also establishes unambiguous policy, requirements, and consistent standards.”

CUI Registry

Well before this rulemaking was drafted NARA established the CUI Registry, a listing of all authorized CUI programs. It established 23 categories of CUI programs and a number of sub-categories; the sub-categories being essentially the approved CUI programs. There are two categories of principal interest to readers of this blog; Critical Infrastructure and Transportation. Specific programs/sub-categories include (* indicates programs with procedures established by law or regulations):


Impact

This rulemaking is principally targeted at government agencies that manage CUI programs and/or hold CUI information. The effects will be felt, however, by private sector entities that hold or produce CUI information. Generally where there are existing standards in place by regulation or law, this rulemaking will not generally change those standards. Where existing standards do not specifically address one or more of the requirements proposed (cybersecurity requirements for example) in this rulemaking the CUI standards will apply.

It is not clear whether or not agencies will have to conduct their own rulemakings to incorporate the additional requirements imposed by this CUI program, or if they will be able to just change their guidance documents to reference these new requirements. It may, in fact, be left up to agency discretion.

I will be looking at the proposed CUI program requirements in more detail in future posts.

Public Comments


NARA is soliciting public comments on this proposed rulemaking. Comments may be submitted via the Federal eRulemaking Portal (www.regulations.gov; Docket # NARA-2015-037). Comments need to be submitted by July 7th, 2015.

Tuesday, May 5, 2015

OMB Approves NARA Controlled Unclassified Info NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs announced that it had approved the National Archives and Records Administration’s notice of proposed rulemaking (NPRM) on controlled unclassified information (CUI). This rulemaking was directed by President Obama in his executive order on CUI; EO 13556.

This rulemaking has been very long in the making. The EO was published in November of 2010 and the NPRM was finally submitted in May of last year. The delay in OIRA was not apparently due to public or corporate pressure as there are no reports of meetings on this rulemaking on the OIRA web site.

I would assume that the pressure came from various federal agencies that are going to have to rewrite their rules and procedures (and perhaps regulations) for the various CUI programs that this rule is supposed to harmonize. It would be in their self-interest to minimize the impact of this rulemaking on their internal operations.

Programs that will be affected by this NPRM (to what degree is as of yet unknown) will include the Chemical-terrorism Vulnerability Information (CVI) program, the Protected Critical Infrastructure Information program (PCII) and the Sensitive Security Information (SSI) program.


At the rate things are proceeding with this rulemaking it will be a wonder if the final rule is published by the time of the next inauguration. At which time the new President will have the option to just cancel the program since there is no legislative mandate for this rationalization of the CUI programs.

Tuesday, May 20, 2014

NARA Sends CUI NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs announced that the National Archives and Records Administration (NARA) had submitted a draft of its notice of proposed rulemaking for the establishment of its Controlled Unclassified Information program. The requirements for this long overdue rulemaking were set forth in EO 13556, Controlled Unclassified Information.

According to the latest Unified Agenda entry for this rulemaking (RIN: 3095-AB80) that EO established “an open and uniform program for managing information requiring safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies, excluding information that is classified under Executive Order 13526, or the Atomic Energy Act, as amended”.

The only details we have available about this proposed rulemaking at this date also come from that entry in the Unified Agenda. It notes that the NPRM would provide “guidance to agencies on safeguarding, disseminating, marking, and decontrolling CUI, self-inspection and oversight requirements, and other facets of the program”.

As I have noted in earlier posts on this EO this NPRM could potentially affect a number of chemical security related programs including CFATS (CVI), transportation security (SSI), and voluntary security information submissions to the government (PCII).


There is no telling how long it will take this rulemaking to percolate through OIRA. It is supposed to take just a couple of months, but in practice it can take years depending on the perceived political consequences of the rulemaking. Given the length of time that it has taken NARA to craft the NPRM, I expect this will be a lengthy process.

Tuesday, April 29, 2014

NARA Announces Meeting of NISPPAC

Today the National Archives and Records Administration (NARA) published a meeting notice in the Federal Register (79 FR 24019-24020) for a June 19th meeting of the National Industrial Security Program Policy Advisory Committee (NISPPAC). According to the notice the agenda includes a discussion of “National Industrial Security Program policy matters”.

The meeting is going to be held at the Gaylord National Resort in Prince George's Exhibition Hall B and due to “due to space limitations and access procedures” advanced registration is required? That might make some sense if sensitive matters were going to be discussed, but the notice clearly states that this meeting is ‘open to the public’.

And really: “The purpose of this meeting is to discuss National Industrial Security Program policy matters.” Does this fulfill the requirements of 41 CFR 02-3.150 to provide a “summary of the agenda, and/or topics to be discussed”? Of course NISPPAC is going to discuss NISP policy matters, but which ones?

Now NARA is to be commended for giving a month and a half notice instead of just the required 15 days, but is that just an effort to bury this meeting notice? I’m sorry but something smells here.


BTW: 41 CFR 102-3 addresses the management of Federal Advisory Committees not the long outdated 41 CFR 101-6.10 referenced in the notice. More obfuscation?

Friday, July 12, 2013

NARA Announces InfoSec Meeting

The National Archives and Records Administration posted a meeting notice in today’s Federal Register (78 FR 41959) for a July 24th meeting of the State, Local, Tribal, and Private Sector Policy Advisory Committee (SLTPS-PAC) in Washington, DC.

There is very little information about the meeting beyond that the purpose is to: “discuss the matters relating to the Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities”. That certainly covers a wide range of possible topics.


The public is invited to attend but there is only limited seating available. Advance registration ( robert.skwirot@nara.gov) by July 19th is required.

Tuesday, November 8, 2011

CVI as CUI

According to the Controlled Unclassified Information (CUI) web site maintained by the National Archives and Records Administration (NARA) the CUI office published their required listing of CUI categories on November 4th. They show 15 categories. The category of particular interest for the chemical security and control systems communities is Critical Infrastructure. The CUI office describes that category as:

“Systems and assets, whether physical or virtual, so vital that the incapacity or destruction of such may have a debilitating impact on the security, economy, public health or safety, environment, or any combination of these matters, across any Federal, State, regional, territorial, or local jurisdiction.”

Within the Critical Infrastructure Category NARA lists the following seven categories:








No work as yet been done on consolidating the large number of CUI programs, standardizing marking procedures and rules, or eliminating unnecessary over-control of this information. All of the above actions have been required by EO 13556.

There is little doubt that the basic requirements for Chemical-Terrorism Vulnerability Information (CVI) and Sensitive Security Information (SSI) will, absent Congressional action, remain in effect. There could be, however, some changes in the procedures for marking and controlling documents under those regimes as the NARA CUI office proceeds with its work.

BTW: Thanks to John CW Bennett for pointing out the publication of this web site on his blog “Maritime Transportation Security News and Views”.

Friday, July 15, 2011

NARA Announces Advisory Committee Meeting for July 27th

Today the National Archives and Records Administration (NARA) published a notice in the Federal Register (76 FR 41826) announcing a meeting of the State, Local, Tribal, and Private Sector Policy Advisory Committee (SLTPS-PAC). The SLTPS-PAC was chartered last December to “advise the President, the Secretary of Homeland Security, the Director of the Information Security Oversight Office (ISOO), and other executive branch officials on all matters concerning the policies relating to access to and . safeguarding of classified national security information by U.S. State, Local, Tribal, and Private Sector Entities, as specified in Executive Order 13549 and its implementing directive.” (SLTPS-PAC Charter, pg 1)

The July 27th meeting will be open to the public. The notice is remarkably reticent about the agenda for the meeting; saying simply that the “meeting will be held to discuss the matters relating to the Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities”.

There is limited public seating available for this meeting, so individuals planning on attending are being required to provide the ISOO (ISOO@nara.gov) with their name and phone number by July 25th.

With an increasing emphasis on the sharing of intelligence information with private critical infrastructure and key resource (CIKR) facilities, there will be more of a push for private entities to be able to handle classified information. This group could provide a valuable resource for ensuring that the Federal government understands the problems associated with the private sector meeting the requirements for handling this information.
 
/* Use this with templates/template-twocol.html */