Showing posts with label NPPD. Show all posts
Showing posts with label NPPD. Show all posts

Saturday, March 5, 2016

CG Publishes NPPD Report on Effects of Malicious Cyber Activity

This week the Coast Guard published a report by DHS-NPPD Office of Cyber and Infrastructure Analysis about the consequences of malicious cyber activity directed against seaport operations. The report, Consequences to Seaport Operations from Malicious Cyber Activity {sorry the CG Homeport does not use real links so: CG Homeport –> Cybersecurity –> Cyber Information (More)} takes a fairly high-level look at cyber threats.

Key Findings


The report makes the following four key findings:

• Unless cyber vulnerabilities are addressed, they will pose a significant risk to port facilities and aboard vessels within the Maritime Subsector;
• A cyber-attack on networks at a port or aboard a ship could result in lost cargo, port
disruptions, and physical and environmental damage depending on the systems affected;
• The impacts to critical infrastructure sectors depend on how a cyber-attack affects a port,
the level and length of disruption that occurs at the port, and the capability to divert
shipments to other ports;
• Several mitigation measures can increase the security and resiliency of ports: setting up maritime cybersecurity standards, sharing information across the sector, conducting routine vulnerability assessments, using best practices, mitigating insider threats, and developing contingency plans for cyber-attacks.

Cybersecurity Vulnerabilities


After providing a statistical overview of seaport operations in the United States and the various types of cyber systems (both land-side and ocean-going) that support those operations, the report provides a broad look at the various types of cybersecurity vulnerabilities that face operators of those systems. These include (with a brief discussion of each):

• Limited cybersecurity training and preparedness;
• Inadequately protected commercial off-the-shelf technologies and legacy systems;
• Errors in software;
• Network connectivity and interdependencies;
• Software similarities;
• Foreign dependencies;
• GPS jamming and spoofing; and
• Insider threats

This is followed by a brief discussion about how these vulnerabilities could be used to effect cyber-attacks on port operations and ship operations. Real-life illustrative examples are provided where available. For port operations the report looks at:

• Disruption of cargo operations;
• Accessing ICS;
• GPS disruption; and
• Other malicious activities

For ship operations the report looks at:

• GPS jamming and spoofing; and
• ICS access

Critical Infrastructure Effects


The report then looks at the consequences attacks on port systems could have on the general economy by addressing specific effects on various areas of critical infrastructure. A substantial number of real world examples are used to illustrate the potential effects. The effects on the following specific critical infrastructure sectors are looked at:

• Critical manufacturing;
• Commercial facilities;
• Food and agriculture;
• Energy;
• Chemical; and
• Transportation systems

Mitigation Measures


The concluding portion of this report very briefly discusses mitigation measures that could be employed. The measures discussed (at just a paragraph each) include:

• Establishing cybersecurity standards;
• Implementing information sharing systems;
• Conducting vulnerability assessments and exercises;
• Ensure the use of best practices;
• Resiliency efforts; and
• Ultimately, use unaffected alternative ports in the event of a real cyber-attack.

Commentary


One important vulnerability left out of this discussion is the area of information protection. Recent reports that sea going pirates are hacking shipping information about cargoes and shipping routes to target specific ships points out how much valuable information is being used in port information systems. Attacks on those information systems could also be used to misdirect the land-side shipment of high-value containers, expanding the reach of cargo hijackers.

While this report approaches the issue from a very high-level perspective of the port related cybersecurity problems facing the country, there is hardly a resounding call to action included in the report. The very brief and wholly inadequate discussion of mitigation measures leaves the impression that there is not much that can be done to prevent cyber-attacks or mitigate the effects of a cyber-attack. The final mitigation measure of just using an unaffected alternate port emphasizes the effective hands-off approach that the OCIA appears to be offering to the potential problem.


While I understand that the OCIA has no direct responsibility for port operations, the fact that this report was released by the Coast Guard means that it should have included, either as an addendum to the report or as a separate cover document, a proposed course forward for the Coast Guard, shippers, port operators and port facility owners. The failure to set the course will ensure that this document will settle into the Saragossa Sea of maritime bureaucratic effluvia, soon to be forgotten.

Wednesday, June 3, 2015

OMB Approves CI Security Clearance ICR

Yesterday the OMB’s Office of Information and Regulatory Affair (OIRA) announced that it had approved an information collection request (ICR) from DHS National Programs and Protection Directorate (NPPD) for information collected to support the Critical Infrastructure/Key Private Sector Clearance Program (CI PSCP). This is the security clearance program for members of the Sector Coordinating Council (SCC) and selected representatives of various private sector critical infrastructure organizations.

This is a revision of an existing ICR (1670-0013). There were significant changes made to the collection burden estimates for this revision. The estimated number of annual information collection requests was increased from 450 to 500 to reflect the increase in submissions to this program in 2013 and 2014. According to the ICR approval notice OMB is reporting that the hours burden for this collection has increased from 75 hours to 833 hours. That is almost certainly a misprint because the supporting information provided by NPPD to OIRA (pg 6) indicates that the total hour burden for this ICR is only 83.33 hour (500 x 10 minutes/submission). This reflects no change in the per request burden estimate.

Commentary

As various threat information sharing programs start to come on-line or expand, this program at DHS will also likely see and expansion of the number of security clearance requests. Depending on how those programs are structured, DHS will expand this collection effort or initiate new ones. One would like to think that they would use the same form as the current program which would lead to an expansion of the expected burden numbers for this ICR.


Thursday, March 6, 2014

DHS Under Secretary Spaulding Confirmed

According to a TWEET® from @DSenFloor this morning the Senate  confirmed Suzanne Spaulding as the DHS Under Secretary for the National Protection and Programs Directorate. She has been filling this position as Acting Under Secretary since her predecessor Rand Beers moved up to the Acting DHS Secretary position. NPPD is responsible for both the CFATS program and ICS-CERT.

Not unexpectedly, the confirmation came by a voice vote.

Monday, September 16, 2013

Spaulding to be Undersecretary for NPPD

By way of a Senate Homeland Security and Governmental Affairs hearing notice we learn that Susan Spaulding, the current acting Undersecretary for National Protection and Programs (while Rand Beers fills in as Acting Secretary of DHS) is being nominated to fill that temporary position on an official basis. I suppose that means that Beers is going to either be appointed DHS Secretary or Deputy Secretary (currently empty as well) or is going to be retiring.


Actually it turns out, upon further research, that Spaulding’s promotion was announced last month. Still no real word on where Beers goes.

Saturday, May 18, 2013

NPPD Publishes 30-Day ICR for PCII Officers Questionnaire


The DHS National Protection and Programs Directorate’s Infrastructure Information Collection Division (IICD) published a 60-Day information collection request (ICR) notice in Monday’s Federal Register (78 FR 29375-29376; available on-line today) supporting a questionnaire targeted at State and local Protected Critical Infrastructure Information (PCII) Officers. The questionnaire would help the Department “to gather information from PCII Officers that can be used to assess their programs, their compliance with PCII rules and requirements, and the specific needs of their accredited programs”.

The Importance of PCII Programs

The Department posted a 60-day ICR notice in the Federal Register back in November, 2012. In a post about that notice I expressed some concerns about the Department’s just now getting around to assessing these State and local programs with which DHS shares selected PCII information. Since the promise of limited disclosure is the only incentive that DHS can provide critical infrastructure organizations to share security information with DHS, any questions about the efficacy of State and local PCII programs will act as a disincentive to information sharing.

The new Cybersecurity Framework under development will depend on PCII programs to protect the information about critical infrastructure computer systems and networks provided to the government. This means that the PCII protections are going to have to be a critical part of the Framework. Again, this makes assessment of State and local PCII programs all that more important.

Earlier Comments

The current notice states that “DHS received no comments”. A review of the Docket (DHS-2012-0046) at www.Regulations.gov shows that there was a comment submitted on November 28th. Terry Frank from Shell Oil Company noted that it would be difficult to assess the accuracy of the collection effort since a copy of the questionnaire is not made available. This is a point I also made in my earlier blog post. This is particularly aggravating since NPPD is required to include the questionnaire when it files this ICR with OMB. It could easily be placed in the current docket.

Mr. Frank also notes a discrepancy in the description of information disclosure protections provided by the PCII program. Since that comment is not really germane to the ICR in question, I suppose that DHS was justified in ignoring that portion of the comment. Still the comment should have been noted in this ICR notice.

Public Comments

NPPD is soliciting public comments on this 30-day ICR notice. Comments may be filed via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0046). The notice does not contain the customary ‘submit comments by’ information, but this is a 30-day notice so comments should be filed within 30 days of the publishing of the notice on Monday; so June 18th, 2013.

NOTE: With the failure to acknowledge the comment filed on the 60-day notice and the failure to include a comment closure date in this notice, perhaps NPPD should consider re-submitting this 30-day ICR notice in proper form.


Saturday, November 17, 2012

Another DHS-NPPD PCII Questionnaire ICR


On Friday the National Protection and Programs Directorate (NPPD) at DHS published a 60-day information collection request (ICR) notice in the Federal Register (77 FR 68795-68796) that would allow for the establishment of a questionnaire concerning the Protected Critical Infrastructure Information (PCII) program.

The Questionnaire


This is a different questionnaire from the one for which OMB recently approved a separate ICR. While the purpose of both questionnaires is to improve the PCII program, they are apparently targeted at different audiences. The earlier ICR was targeted at federal officials and contractors. According to this notice:

“This questionnaire is designed to gather information from PCII Officers that will be used by the NPPD/IP PCII Program to assess state and local programs, their compliance with PCII rules and requirements, and the specific needs of their accredited programs. These assessments are designed to help the DHS PCII Program and Officers to ensure that PCII is being properly protected and to limit the potential for mishandling and improper disclosures.”

We won’t see the actual questionnaire until the ICR is submitted to the Office of Management and Budget. That means that we won’t actually know what questions are being asked to accomplish the above objective.

Protecting PCII


I am concerned about the phrase “to ensure that PCII is being properly protected and to limit the potential for mishandling and improper disclosures”. The whole point of the PCII program is that the private sector voluntarily shares sensitive information about critical infrastructure with the federal government. The only incentive that the government is able to provide is that it will in turn provide actionable intelligence information that the participants might be able to use to protect their facilities.

Since everyone knows that that information will come infrequently at best (or hopes that it will be infrequent; no one wants to be targeted by terrorists) this is not much of an incentive. This means that any risk of governmental disclosure of the information will be enough to stop most facility owners from sharing critical information with the government.

NPPD certainly has a responsibility to ensure that the privately provided information shared with State and local officials continues to be protected from disclosure. There is nothing in this ICR notice that indicates that there are other tools being used by NPPD to ensure the adequate protection of the PCII information at the State and local level. I certainly wouldn’t advocate that all of the security measures be disclosed, but this notice that proposes that actions need to be taken to ensure that PCII is properly protected at the State and local level should include some sort of assurances that there are other measures already in place to ensure the same thing.

Public Comments


NPPD is soliciting public comments on this ICR. Comments can be filed using the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0046). Comments need to be filed by January 15, 2013.

Wednesday, October 24, 2012

Cybersecurity Reorganization at DHS


FederalNewsRadio.com is reporting that the National Protection and Programs Directorate (NPPD) of DHS is reorganizing the Office of Cybersecurity and Communications. There are not a lot of details yet available, but Jason Miller is reporting that:

“The National Cybersecurity and Communications Integration Center (NCIC), led by Larry Zelvin, will bring together the assorted operational offices, including the U.S. Computer Emergency Readiness Team (U.S. CERT), the Control Systems Security Program [emphasis added], the National Coordinating Center and national level exercises — all under one division.”

What this will mean for budgeting, personnel and operations remains to be seen.

Saturday, September 1, 2012

More on Bad CSSS Links


Yesterday I wrote about the updated Chemical Sector Security Summit web page (BTW: I had the wrong acronym on the title for that post, I have since corrected that error) and the bad links on that page to the presentations from last month’s Summit. I really expected that someone at DHS would read that post and have the problem corrected; as of 9:00 am EDT that still has not been accomplished.

This morning I tried to use a ‘report a bad link’ tool that was available on the silly page that one of the links did take me to, but that didn’t work either. In the process, however, I learned what was wrong with the links used. Here is the link from the CSSS web page for the first presentation listed on the page: http://www.dhs.gov/diversion. All of the other links have the same format; a title right off of the ‘dhs.gov’ domain. There is no way that that link is going to work and it never came close to pointing to the correct page.

Oh well, at least this isn’t a problem that can be laid at the folks at ISCD; they don’t own the Chemical Sector Security Summit. It comes out of a separate program in the Office of Infrastructure Protection; so it is still an NPPD problem.

Thursday, April 12, 2012

DHS Private Sector Clearance Program 60-day ICR Notice

Today the DHS National Protection and Programs Directorate (NPPD) published a 60-day ICR reinstatement notice in the Federal Register (77 FR 21989) for their Critical Infrastructure Private Sector [Security] Clearance Program (PSCP). OMB approval of this ICR would allow NPPD to collect information necessary to initiate the security clearance investigation process for selected critical infrastructure civilian personnel who would not otherwise be eligible for a clearance under Executive Order 12829.

There is something odd going on with this ICR and it doesn’t look like the problem is in DHS. The original ICR was submitted in July 2008 and approved in November of that year. It was set to expire on November 30th, 2011. DHS submitted a request to re-approve the ICR in July of last year with a change in the number of potentially covered individuals from 250 to 450 with an equivalent change in the time burden (42 to 75). That was approved ‘without change’ by OMB on September 14th, 2011 with an expiration of November 30th, 2011; the same date upon which it was already set to expire.

Apparently no one at DHS noted the error in the OMB approval; they expected the normal three year ICR expiration which would have put it either in September or November of 2014. The ICR approval paperwork was probably put in an action item folder dated for some time in the early summer of 2014 and promptly forgotten.

Somehow someone noted that the ICR had expired prematurely. It would be nice to think that a simple phone call to the action officer at OMB would have cleared up the matter, but that is not the way that a bloated bureaucracy operates. Alternatively we could have expected to see NPPD submit an expedited or ‘emergency’ ICR approval request to get the program on a technically firm footing, but that probably would have required publicly pointing out OMB’s error and that doesn’t win much in the way of friendly bureaucratic cooperation. OMB already sits on NPPD requests for lengthy periods of time, no sense in antagonizing them.

It really doesn’t make much difference in any case. This is a voluntary program and people requesting security clearances under this program are certainly not going to object to providing this information on a form without an up-to-date OMB approval number in the corner. While the public can’t be required to provide the information on an unapproved collection, neither can NPPD be required to process a security clearance request.

Comments on this ICR are being solicited by NPPD. Comments may be submitted via the Federal eRulemaking Portal (www.regulations.gov; Docket # DHS-2012-0001). Comments should be submitted by June 11, 2012.

Monday, February 27, 2012

Congressional Hearings – Week of 02-27-12

Well Congress comes back this week from a week of celebrating President’s Day and there are some interesting hearings on this week’s schedule and two hearings already scheduled for the following week that may be of interest to the chemical and cyber security communities. This week we have a water security hearing, a cybersecurity hearing and an NPPD Budget hearing.

Water Security


Okay that may be a stretch but water facility security issues just might be mentioned in the hearing on “Local Government Perspectives on Water Infrastructure” on Tuesday being held by the Water and Wildlife Subcommittee of the Senate Environment and Public Works Committee. Local governmental officials are on the witness list. Any security related questions would come from Sen. Lautenberg (D,NJ) who has introduced legislation on water facility security issues (S 711).

Cybersecurity


On Tuesday the House Energy and Commerce Committee’s Subcommittee on Oversight and Investigations is holding a hearing on “Critical Infrastructure Cybersecurity: Assessments of Smart Grid Security.” The current witness list includes two GAO representatives (Gregory C. Wilshusen, Director of Information Security Issues and David Trimble, Director, Natural Resources and Environment) and a Congressional Research Service representative. It doesn’t sound like any control system expertise is involved; but Smart Grid isn’t about control systems is it? It’s all about personal privacy issues.

NPPD Budget


Under Secretary Rand Beers will be appearing at a closed door (classified) budget hearing before the Homeland Security Subcommittee of the House Appropriations Committee on Thursday. I have seen at least one news report that this hearing is all about the CFATS problems, but I really doubt that. The NPPD budget hearing is typically classified and the Subcommittee has too much on its plate this early in the budget cycle to concern itself in detail about the management issues in a small agency like ISCD.

No doubt that Beers will be questioned about the ISCD problems in this hearing; probably by Rep. Dent (R,PA) who has a history concern about the program and is the sponsor of the only one of the three House bills (HR 916) that has been ignored by both the Energy and Commerce Committee and the Homeland Security Committee.

I really expect that the bulk of the questions that require this classified briefing will have to deal with securing government information systems.

Preview of the Following Week


We already have two hearings on the schedule for the following week that will be of interest to readers of this blog; both will be held a week from Tuesday.

The House Homeland Security Committee’s Cybersecurity, Infrastructure Protection and Security Technologies Subcommittee will hold a CFATS oversight hearing. No witnesses are yet scheduled but we can certainly expect to see Beers and Director Anderson. It will be interesting to see if anyone else from the current or past staff of ISCD will provide testimony.

Commandant Papp will testify at a Coast Guard budget hearing before the Homeland Security Subcommittee of the House Appropriations Committee. I’m pretty sure that we will hear questions about the TWIC Reader program and possibly extending the expiration of the current TWIC cards.
 
/* Use this with templates/template-twocol.html */