Showing posts with label PCII. Show all posts
Showing posts with label PCII. Show all posts

Saturday, January 27, 2018

DHS Updates PCII Web Page


Earlier this week DHS updated their Protected Critical Infrastructure Information (PCII) Program web page; providing an imbedded video describing the PCII program. There appears to be a glitch in the video. It locks up at about (±15 seconds) 2-minutes in and I can no longer access (I get a “Could not Connect” warning; ERR_SPDY_PROTOCOL_ERROR) a number of .gov web sites from the open browser (CHROME) window. I can access the same web sites from either a new browser window or by restarting the browser until I run the video. The video also locks up when I view it with FIREFOX, but I do not have problems accessing those .gov sites (though I do get certificate warnings on the PCII site and other .gov sites).

You might want to be careful viewing this video.

Thursday, July 7, 2016

ICS-CERT Publishes Two Advisories and the Monitor

Today the DHS ICS-CERT published two control system security advisories for products from Moxa and WECON. They also published the latest edition of the ICS-CERT Monitor.

Moxa Advisory


This advisory describes an authorization bypass advisory in the Moxa Device Server Web Console. The vulnerability was reported by Maxim Rupp. Support for the device ended in 2012, but Moxa has provided recommendations to mitigate this vulnerability. There is no indication that Rupp has been provided an opportunity to verify the efficacy fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain access to change settings and data on the target device.

Moxa suggests disabling two ports and restricting access to three others. They note that such restrictions could impact remote systems administration.

WECON Advisory


This advisory describes two buffer overflow vulnerabilities in the WECON LeviStudio software. The vulnerabilities were reported by Rocco Calvi and Brian Gorenc via the Zero Day Initiative. WECON has not (and apparently does not plan to) released a product fix to address these vulnerabilities; CAVEAT EMPTOR.

The two vulnerabilities are:

• Heap-based buffer overflow - CVE-2016-4533; and
• Stack-based buffer overflow - CVE-2016-5781

ICS-CERT has a new take on social engineering attacks, and I quote:

“An attacker with low skill would be able to exploit these vulnerabilities. Crafting a working exploit for these vulnerabilities would not be difficult; however, social engineering is required to convince the user to accept the malformed file or visit a malicious web site. This decreases the likelihood of a successful exploit.”

May-June 2016 Monitor


The Monitor covers ICS-CERT operations during May and June of this year. The lead-off article on a specific incident takes an oblique look at the use of SHODAN for identifying control system components facing the internet. Beyond pointing out that some sort of internet facing device (presumably a control system component?) was identified by ICS-CERT via SHODAN, the only information of note is that devices identified with an ISP IP address cannot be directly identified by ICS-CERT. They have to forward notification to the owner via the ISP. Good to know that ISPs are protecting our privacy (at least in this instance).

We also see four pieces about ICSJWG meetings. The first is a recap of an ICS-CERT presentation at the Spring meeting about “Viewing Your Network through the Eyes of an Attacker”. There is also a listing of the other ICS-CERT presentations at that meeting. Then there is a brief preview of the Fall Meeting. The final item is a lengthy item about the Advanced Analytical Lab’s presentation at the Spring Meeting.

This issue contains a little bit more information about the system assessments that ICS-CERT does. It contains a brief article outlining the top six weaknesses that ICS-CERT identified in their assessments in 2015. Those weaknesses are:

(1) Boundary protection;
(2) Least functionality;
(3) Authenticator management;
(4) Identification and authentication;
(5) Least privilege; and
(6) Allocation of resources

There are also two brief pieces on Protected Critical Infrastructure Information (PCII). The first is a short article on what facilities need to do to claim PCII protections for information that they submit to ICS-CERT. While the overview is pretty good, there is a lack of detail on what exactly must be in the Express Statement and in the Certification Statement. Those details are available on the PCI web site.


On the whole, this issue of the Monitor is well worth reading.

Friday, May 13, 2016

DHS Announces PCII Listening Sessions

Today the Department of Homeland Security published a meeting notice in the Federal Register (81 FR 29799-29800) for a series of public listening sessions looking for input on their recent advance notice of proposed rulemaking (ANPRM) for updating the Protected Critical Infrastructure Information (PCII) program. The three listening sessions will be held in Arlington, VA. The dates will be May 12th, May 17th, and May 19th.

The Information Sought


DHS is specifically looking for information on (note this is a slightly different list that proposed in ANPRM):

• Automated submissions and an expansion of categorical inclusions;
• Marking PCII;
• Sharing PCII with foreign governments;
• Regulatory access;
• Safeguarding;
• Oversight and compliance;
• Alignment with other information protection programs; and
• The administration of PCII at the State, local, tribal, and territorial level

Public Comments


With five hours on each day available for public oral comments there should be plenty of time for everyone to get their say. Written comments may also be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2016-0032). Yes, this notice did include the docket # and it is the same as I provided in an earlier blog post. The deadline for written comments is still July 20th, 2016.

Commentary


I’m not sure why this notice was delayed in publication, but it certainly makes someone look silly for announcing a meeting for a date that has already passed. The remaining two dates are also fairly short notice, but then again I don’t suspect that DHS really expects anyone to make travel plans to attend these three sessions. These dates are almost certainly targeted at organizations with physical (or at least a lobbyist) presence in the Washington area.

I will be extremely disappointed if there are not more listening date announcements associated with this ANPRM and even more disappointed if they are not scattered across the country.

Thursday, May 5, 2016

ICS-CERT Publishes March-April 2016 Monitor

Late yesterday the DHS ICS-CERT published the latest edition of their Monitor; a periodic report on the activities of the organization. This is one of the better issues with some interesting topics.

Incident Response


As we have come to expect, ICS-CERT leads off the publication with a brief piece discussing a recent anonymized attack. Also, as we have come to expect, the attack being used in the discussion is on an organization that would be expected to have an extensive industrial control system operation (a water utility in this case), but the attack never apparently reached the control system.

The attack was a ransomware attack on the utility, so this is a timely issue. The author uses the mixed response from the utility (one system with good backup recovery and a second system with a backup recovery with significant gaps) to explicate the need for timely backups to respond to this type of attack. Unfortunately, the discussion never reaches beyond IT systems and the topic of backups for control systems is never broached.

The second article also addresses incident response, this time giving an overview of the role of ICS-CERT in incident response. The discussion is somewhat marred however by the apparently fictional response to a water utility incident that could be used as a story proposal for a CSI Cyber television episode. While my cybersecurity application talents are more than a little out-of-date, I would be really surprised if the ICS-CERT team could remotely start an effective whitelisting application on a system before they had even seen network logs.

Protected Critical Infrastructure Information


The third major article is a brief overview of the importance of the PCII program. This is an important information sharing tool that allows a covered entity to submit data to a federal agency while protecting that information from public disclosure. The article does a good job of providing a description of the importance of the program and an overview of its protections.

The article does fall short, however, in failing to discuss the major problem with the program; facilities must use a very specific phrase at the start of any document that attempts to claim PCII protection. Failure to include the Express Statement (and two the other key pieces of information discussed on that page) will mean that the information will not be protected by the PCII program. While the article does provide a link to the extensive PCII web site failure to explicitly mention that there are specific requirements for claiming PCII protections does a disservice to the readers.

To be fair this problem is not limited to this ICS-CERT article about the PCII program. I have not yet seen a government discussion of the PCII program that really emphasized the importance of properly claiming PCII protection.

NOTE: Remember that DHS is in the process of trying to revise the PCII regulations (see here and here).

Strong Passwords


No discussion of cybersecurity would be complete without the topic of passwords being addressed. The fourth (and last) major article of this issue of the Monitor addresses this important topic. While there have been periodic discussions in the industry of replacing passwords with some neat new technology, ICS-CERT apparently remains a strong proponent of strong passwords. Their definition of a strong password is now 12 characters using: caps, lower case, numbers and symbols. Remember it must be unique, but easily remembered as you should never write it down. Sharing passwords or multiple users using the same password are both strictly verboten.

There is an important caveat in the article that should be remembered by everyone:

“There is only one proven method to prevent your password from being cracked: leave your device sealed in the box in which it was shipped. Otherwise, all passwords can be cracked. Given enough time and processing power, even the longest most random password can be cracked.”

Standard Features


This issue includes all of the standard blurbs that we have come to expect, including:

• Onsite Assessments Activity;
• ICS-CERT News;
• Recent Product Releases;
• Coordinated Vulnerability Disclosure;
• Open Source Situational Awareness Highlights; and
• Upcoming Events

It is nice to see three chemical sites listed in the Onsite Assessments Activity chart. At the risk of offending the increasing number of businesses that provide a for-fee assessment (a valuable service that should be encouraged) any facility that is being regulated by the federal government program that addresses cybersecurity of control systems (not many to be sure) would be foolish not to avail themselves of the free assessments provided by ICS-CERT. That assessment should be supplemented by the best fee-based assessment that the budget allows, but an ICS-CERT assessment has got to look good to any Federal inspector.

The ICS-CERT news piece in this issue was yet another non-update on the December Ukraine attacks. Apparently ICS-CERT has no new information that can be shared with the general control system community. It does plug the latest update to IR-ALERT-H-16-043-01BP, “Cyber-Attack Against Ukrainian Critical Infrastructure”. This is only available on the US CERT Secure Portal. You can request access through ICS-CERT (see the ‘I Want To’ box on the bottom of their landing page).

There is an ironic touch in the discussion of coordinated disclosures this month. The first name on the list of personnel being praised for coordinated disclosures is none other than Reid Wightman for his work on the Moxa vulnerabilities. I am sure that this mention makes Reid very happy.

Thumbs Up


The nits picked above notwithstanding, I really did enjoy this issue of the Monitor. I would recommend it to anyone in the control system security community.

Thursday, April 21, 2016

DHS Publishes PCII ANPRM

Today the Department of Homeland Security (DHS) published an advance notice of proposed rulemaking (ANPRM) in the Federal Register (81 FR 23442-23445) for a possible update of the Protected Critical Infrastructure Information (PCII) program as established in 6 CFR Part 29. This program protects critical infrastructure information (CII) voluntarily submitted to DHS from public disclosure.

Information Sought


The notice provides background information on the initial establishment of the PCII program in 2006. It then goes on to explain that the program needs to be transitioned to a modern electronic environment that transition would:

• Enhance the submission and validation process for critical infrastructure information;
• Use state of the art technology for an automated interface for quicker access and dissemination of PCII;
• Modify requirements for the express and certification statements;
• Expand the use of categorical inclusions;
• Require portion marking of PCII; and
• Implement specific methods to capture and deliver metadata to the PCII Program.

Specifically, DHS is requesting information and comments on the following topics:


The first topic is the one about which DHS is seeking the most information. It is seeking comments on nine specific areas in this topic. Those areas include:

• How to enhance the submission methods for critical infrastructure information and automate sharing via structured information expression profiles and electronic exchange protocols;
• Whether an updated PCII rule should permit multiple submissions of information under one express statement and certification statement enabling the submission of multiple documents by an organization over the course of several weeks or months;
• Whether an updated PCII rule should allow submissions in a purely electronic format that includes an electronic express statement and certification statement in order to simplify the submission of large data sets in particular;
• Whether and to what extent an automated submission process should incorporate auditing and statistical reporting requirements to increase transparency of the frequency and types of data being submitted to the program;
• Addressing any process amendments or program enhancements to effectively implement automated submission processing in order to facilitate the submitter's ability to request and receive timely audits of access to the submissions;
• What effect, if any, an updated PCII Program would have on enabling broader sharing and analysis among other trusted recipients of cyber threat and risk data;
• Which specific programmatic-submission use cases that define data collection needs should be developed and established as categorical inclusions in specific data exchange activities in order to increase the submitters' community use and ease of submission in the PCII submission process;
• The extent to which specific programmatic-submission use cases should be developed and established as categorical inclusions in order to normalize a range of permissible and impermissible uses for specific types of data shared as PCII; and
Expanding categorical inclusions to the State governmental level to increase the range of submissions, enhance the efficiency of information sharing, and make the protection of critical infrastructure information more effective.

Public Comments


DHS is soliciting public comments on the above topics and questions. Those comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # OOPS there is no docket number provide in today’s notice). I expect that we will see a revision notice next week in the Federal Register providing a docket number. Until then, the only other method of comment submission included in the notice is snail mail, not my recommendation. Still comments should be submitted by July 20th, 2016.

Commentary


The one thing missing from this notice is mention of the pending rule on Controlled Unclassified Information. The final rule on CUI was submitted to OMB back in October. This rulemaking from the National Archives and Records Administration (NARA) seeks to standardize the administration of CUI programs like PCII.

Since the PCII program was established by statute {the CII Act of 2002 (Sections 211-215, Title II, Subtitle B of the Homeland Security Act of 2002, PL 107-296)} most of the NARA regulations can be overridden by the PCII regulations. But, any areas of the NARA regulations that are not specifically addressed in the PCII regulations will have to comply with the NARA provisions. And there will be some areas of the NARA regulations that may not be superseded unless specifically authorized in legislation.

Unfortunately, this ANPRM cannot attempt to address those issues since the NARA regulations have not yet been approved. I suspect that the most likely areas of potential conflict will deal with page and paragraph marking requirements.


The other area of potential concern (though probably not an actual conflict since it has never been addressed) will be the requirements for cybersecurity of electronic copies of documents. This will be particularly important with this ANPRM because of the expressed intent of expanding the use of electronic data submission and sharing. But, again, it is hard to express concerns about these issues until the NARA rule is published.

Saturday, September 26, 2015

PCII and CVI Information

Earlier this week DHS did a complete update of their web site that deals with the Protected Critical Infrastructure Information (PCII) program. This controlled but unclassified information protection program was established in 2002 as Subtitle B of Title II of the Homeland Security Act of 2002 (PL 107-296). One of the new pages included in this re-worked site addresses information that is protected both by the PCII program and the Chemical Vulnerability Information (CVI) program under CFATS.

Differences Between PCII and CVI

Both programs provide similar degrees of protection against public disclosure of information submitted to the Federal government. There is a significant difference, however. Information submitted via the PCII program may not be used for regulatory purposes and the CFATS program is definitely a regulatory program.

This means, essentially, that the folks that work at the Infrastructure Security Compliance Division (ISCD) of NPPD do not have access to PCII. Facilities that submit documents to ISCD that have also been provided to DHS under the PCII program must ensure that there are no PCII markings on copies sent to ISCD.

Commentary

There is an interesting difference between document protection requirements in these two programs. While the CVI program sets rules for document protection at the facility that submits the documents, there are no such requirements included in the PCII program. The PCII program only sets the document protection requirements for government entities and contractors working for those entities.


If facilities are submitting the same documents under both programs it is important that the PCII marked documents are kept separate from the CVI marked documents. This is going to make keeping the documents up to date a tad bit more difficult as they will have to be maintained in separate computer files as well since electronic CVI documents are required to be saved with program markings.

Tuesday, May 5, 2015

OMB Approves NARA Controlled Unclassified Info NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs announced that it had approved the National Archives and Records Administration’s notice of proposed rulemaking (NPRM) on controlled unclassified information (CUI). This rulemaking was directed by President Obama in his executive order on CUI; EO 13556.

This rulemaking has been very long in the making. The EO was published in November of 2010 and the NPRM was finally submitted in May of last year. The delay in OIRA was not apparently due to public or corporate pressure as there are no reports of meetings on this rulemaking on the OIRA web site.

I would assume that the pressure came from various federal agencies that are going to have to rewrite their rules and procedures (and perhaps regulations) for the various CUI programs that this rule is supposed to harmonize. It would be in their self-interest to minimize the impact of this rulemaking on their internal operations.

Programs that will be affected by this NPRM (to what degree is as of yet unknown) will include the Chemical-terrorism Vulnerability Information (CVI) program, the Protected Critical Infrastructure Information program (PCII) and the Sensitive Security Information (SSI) program.


At the rate things are proceeding with this rulemaking it will be a wonder if the final rule is published by the time of the next inauguration. At which time the new President will have the option to just cancel the program since there is no legislative mandate for this rationalization of the CUI programs.

Tuesday, April 14, 2015

NIST Publishes DRAFT CUI Cybersecurity Requirements

Earlier this month the National Institute of Standards and Technology (NIST) published the final draft of SP 800-171, Protecting Controlled Unclassified Information (CUI) in Nonfederal Information Systems and Organizations. The final version of this guidance document will support the regulations that the National Archives and Records Administration (NARA) is expected to publish later this year on marking and protecting CUI. The two types of CUI that most readers of this blog will deal with will be the Protected Critical Infrastructure Information (PCII) program and the Chemical-terrorism Vulnerability Information (CVI) program.

The security measures (both physical and cyber) outlined in this document are expected to apply to any computer systems used to store or transmit. It only applies to systems meeting the following criteria (1.1 pg 2):

∙ When the CUI is resident in nonfederal information systems and organizations;
∙ Where the CUI does not have specific safeguarding requirements prescribed by the authorizing law, regulation, or government-wide policy for the CUI category or subcategory listed in the Registry; and
∙ When the information systems where the CUI resides are not operated by organizations on behalf of the federal government.

Neither the PCII Procedures Manual nor the CVI Procedures Manual provide significant guidance on the protection of documents on computer systems. This should mean that the final version of these guidelines should apply to computer systems used to store or transmit PCII or CVI information. To be sure of that we will have to wait to see exactly what the NARA regulations say.

This document outlines fourteen security requirement families (Table 1, pg 7)

∙ Access control;
∙ Awareness and training;
∙ Audit and accountability;
∙ Configuration management;
∙ Identification and authentication;
∙ Incident and response;
∙ Maintenance;
∙ Media protection;
∙ Personnel security;
∙ Physical protection;
∙ Risk assessment;
∙ Security assessment;
∙ System and communications protection; and
∙ System and information integrity.

The security requirements for each of these families are outline briefly in Chapter 3. According to a footnote on page 8 these requirements may be waived for control systems containing CUI. It states:

“Some specialized systems such as medical devices, Computer Numerical Control (CNC) machines, or industrial control systems may have restrictions or limitations on the application of certain CUI requirements and may be granted waivers or exemptions from the requirements by the federal agency providing oversight.”

I suppose if we include in the definition of ‘industrial control systems’ such systems as access control systems and video surveillance systems, then we could conceivably find CVI or PCII on industrial control systems. I cannot imagine, however, anyone granting a waiver to such systems due to their direct impact on facility security.


NIST is soliciting public input on this document. As has become standard for the NIST comment process, a prepared comment template has been provided. Comments should be provided by May 15th, 2015. NIST expects to publish the final document in June, 2015. There is no specific indication when the NARA regulations will be published.

Tuesday, May 20, 2014

NARA Sends CUI NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs announced that the National Archives and Records Administration (NARA) had submitted a draft of its notice of proposed rulemaking for the establishment of its Controlled Unclassified Information program. The requirements for this long overdue rulemaking were set forth in EO 13556, Controlled Unclassified Information.

According to the latest Unified Agenda entry for this rulemaking (RIN: 3095-AB80) that EO established “an open and uniform program for managing information requiring safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies, excluding information that is classified under Executive Order 13526, or the Atomic Energy Act, as amended”.

The only details we have available about this proposed rulemaking at this date also come from that entry in the Unified Agenda. It notes that the NPRM would provide “guidance to agencies on safeguarding, disseminating, marking, and decontrolling CUI, self-inspection and oversight requirements, and other facets of the program”.

As I have noted in earlier posts on this EO this NPRM could potentially affect a number of chemical security related programs including CFATS (CVI), transportation security (SSI), and voluntary security information submissions to the government (PCII).


There is no telling how long it will take this rulemaking to percolate through OIRA. It is supposed to take just a couple of months, but in practice it can take years depending on the perceived political consequences of the rulemaking. Given the length of time that it has taken NARA to craft the NPRM, I expect this will be a lengthy process.

Thursday, April 17, 2014

NPPD Makes CSF Notifications

The DHS National Protection and Programs Directorate (NPPD) published a notice in today’s Federal Register (79 FR 21780-21782) announcing that it had, in accordance with §9 of the President’s executive order on Improving Critical Infrastructure Cybersecurity (EO 13636), completed notification of facilities that they have been identified as “critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security”. The notice also outlines the procedure by which a facility can appeal that designation.

The actual list of designated facilities was submitted to the President on July 19th of last year. The facilities have been designated as “cyber-dependent critical infrastructure” and the list will be reviewed on an annual basis.

Definitions

Today’s notice provides several definitions that are important to understanding this program. They include:

Cyber incident; and

The above definitions seem to be IT system centric. For example the ‘cyber incident’ definition covers events that impair “the confidentiality, integrity, or availability of electronic information, information systems, services, or networks”. While this does not specifically exclude control systems, it certainly needs to be stretched to include them.

The definition of ‘critical infrastructure’ is taken verbatim from §2 of the EO. As I noted in an earlier blog the definition would be difficult to apply to any single production facility though national distribution networks (pipelines and the electric grid, for instance) would easily fall within the definition.

It is strange that NPPD did not use the §9(a) definition from the EO that expands coverage to facilities with potential catastrophic regional effects. This is especially true since §9(a) is the section directing DHS to prepare the list of critical infrastructure. Of course, since the list will not be publicly available, we will never really know how expansive the definition is in actual practice.

Listed Facilities

Being listed as a cyber-dependent critical infrastructure (CDCI) facility does not currently add to any regulatory burden, though adoption of the NIST Cybersecurity Framework (CSF) is encouraged. CDCI designation does provide facilities with the following perks:

● Ability to request expedited processing through the DHS Private Sector Clearance Program, which may provide access to classified government cybersecurity threat information as appropriate;
● May be prioritized for routine and incident-driven cyber technical assistance activities offered by DHS and other agencies; and
● May receive priority in gaining access to Federal resources and programs to enhance the security and resilience of critical infrastructure against cybersecurity threats.

Please note all of the permissive ‘mays’ in the descriptions. There are no guarantees provided. This is almost certainly due to the fact that this program is based upon an EO not legislative authority.

Status Appeal

The notice also provides instructions on how a facility can appeal their designation (or lack of designation) as a CDCI. The process for a request of reconsideration is actually quite simple in concept if not necessarily in actual execution. A letter or email is sent to the Under Secretary for NPPD requesting reconsideration. The request should include:

● The entity for which the reconsideration is being requested;
● The name, title, telephone number and email address of a designated point of contact, whether an employee or non-employee agent, for the owner or operator of that entity to whom all communications related to the reconsideration process will be directed; and
● If desired, a request for a meeting with DHS representatives.

After DHS confirms receipt of the initial request the process becomes less well defined as it involves the provision of information by the facility to DHS. That information will be the justification for why a facility should or should not be on the CDCI list. What the information might be and how much information will be necessary will vary considerably.

The notice does provide some very specific requirements for the formatting of information. It should be submitted by email (with certain exceptions) as a single attachment. It must be:

● Double-spaced;
● In 12 point Times New Roman text or visual material;
● Have 1” margins; and
● Have page numbers. 

The Notice specifically reminds submitters that the information provided may constitute Protected Critical Infrastructure Information (PCII) and provides a list of references about that program. Information designated as PCII (by the submitter) must be protected against disclosure by the Federal government and by anyone with whom it shares that information.

Anyone that submits information for this reconsideration process should become familiar with the PCII program as outlined in 6 CFR Part 29, and the PCII Program Procedures Manual (additional information can be found here). The single most important thing to remember is that information to be protected under the PCII program must be so designated {in a very prescribed manner, see §29.5(a)(3)} when it is submitted. If that is not done, the information is not required to be protected under the program.

The notice also reminds personnel submitting classified information that such information cannot be submitted by email.

Deadline

Facilities or organizations wishing to request a reconsideration must have their initial request submitted to NPPD by May 15th, 2014. Requests received after that date will not result in reconsideration, but may be added to the consideration process in the preparation of the next annual list of CDCI.


Once NPPD notifies a facility that there request was received, facilities will have 60-days to submit supporting information.

Saturday, November 30, 2013

NPPD Withdraws Troubled PCII ICR

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that the DHS National Protection and Programs Directorate (NPPD) had withdrawn their information collection request (ICR) for a questionnaire to be used by State Protected Critical Infrastructure Information (PCII) Officers to conduct a self-assessment of the protections applied to PCII at the State level.

NPPD has been having a number of administrative problems with this ICR since it was initiated last year. I noted back in May that they ignored a public comment posted in response to their 60-day ICR. Then OIRA rejected their initial submission of the ICR in July as being ‘improperly submitted’.

The actual questionnaire being proposed for the self-assessment program (down-loadable here) seems to address the issues that one would expect that someone conducting a compliance audit of the program would be looking at. Too many of the questions, however, solicit ‘Yes’ or ‘No’ answers and the wording of the question usually indicates the ‘proper’ response. Since only an inappropriate response requires an explanation, a cursory appropriate response is encouraged when filling out the form. This is a typical problem with a self-assessment program.

As I have repeatedly noted in the earlier posts about this ICR, I have concerns about the use of a self-assessment questionnaire in evaluating the protections put in place for the State level PCII programs. Critical infrastructure organizations are relying on NPPD and the Federal Government to ensure that the critical information that they are voluntarily submitting is properly protected.

Since that PCII must, in most cases, be shared with State and local agencies to ensure that those critical infrastructure facilities are appropriately protected, NPPD has an overarching requirement to ensure that the PCII programs are being properly administered at the State and local levels. Simply requiring that a self-assessment form be completed is not adequately ensuring that the protections are in place.


I wonder, how long has it been since Congress has exercised their oversight responsibility of this important information sharing program? I don’t recall the last time any committee has held hearings on the PCII program. With Congress interested in encouraging information sharing about cybersecurity matters, may be they ought to take a look at how well the government is protecting information already being shared by the same organizations.

Saturday, April 13, 2013

Comments on Incentives To Adopt Improved Cybersecurity Practices – 04-13-13


There have been a number of Federal agencies in the last couple of weeks that have asked for public comments on a wide variety of security related measures that are being covered in this blog. One that hasn’t drawn much in the way of response is the NIST/NTIA request for comments on potential incentives that can be used by the Federal government to encourage the adoption of improved cybersecurity practices outlined in the still to be developed Cybersecurity Framework. To date only one comment has been received and the closing date is just over two weeks away.

The one comment posted on the NTIA web site comes from Brian Rich and deals with the protections provided by the Protected Critical Infrastructure Information Program (PCII). While Brian is correct in that this program does provide for protection from certain disclosure requirements, there are some technical loopholes {including a specific statement that needs to be included in the disclosure document to claim PCII protections, 6 CFR §29.5(a)(3) } that need to be carefully understood by anyone desiring to claim PCII protections.

Saturday, November 17, 2012

Another DHS-NPPD PCII Questionnaire ICR


On Friday the National Protection and Programs Directorate (NPPD) at DHS published a 60-day information collection request (ICR) notice in the Federal Register (77 FR 68795-68796) that would allow for the establishment of a questionnaire concerning the Protected Critical Infrastructure Information (PCII) program.

The Questionnaire


This is a different questionnaire from the one for which OMB recently approved a separate ICR. While the purpose of both questionnaires is to improve the PCII program, they are apparently targeted at different audiences. The earlier ICR was targeted at federal officials and contractors. According to this notice:

“This questionnaire is designed to gather information from PCII Officers that will be used by the NPPD/IP PCII Program to assess state and local programs, their compliance with PCII rules and requirements, and the specific needs of their accredited programs. These assessments are designed to help the DHS PCII Program and Officers to ensure that PCII is being properly protected and to limit the potential for mishandling and improper disclosures.”

We won’t see the actual questionnaire until the ICR is submitted to the Office of Management and Budget. That means that we won’t actually know what questions are being asked to accomplish the above objective.

Protecting PCII


I am concerned about the phrase “to ensure that PCII is being properly protected and to limit the potential for mishandling and improper disclosures”. The whole point of the PCII program is that the private sector voluntarily shares sensitive information about critical infrastructure with the federal government. The only incentive that the government is able to provide is that it will in turn provide actionable intelligence information that the participants might be able to use to protect their facilities.

Since everyone knows that that information will come infrequently at best (or hopes that it will be infrequent; no one wants to be targeted by terrorists) this is not much of an incentive. This means that any risk of governmental disclosure of the information will be enough to stop most facility owners from sharing critical information with the government.

NPPD certainly has a responsibility to ensure that the privately provided information shared with State and local officials continues to be protected from disclosure. There is nothing in this ICR notice that indicates that there are other tools being used by NPPD to ensure the adequate protection of the PCII information at the State and local level. I certainly wouldn’t advocate that all of the security measures be disclosed, but this notice that proposes that actions need to be taken to ensure that PCII is properly protected at the State and local level should include some sort of assurances that there are other measures already in place to ensure the same thing.

Public Comments


NPPD is soliciting public comments on this ICR. Comments can be filed using the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0046). Comments need to be filed by January 15, 2013.

Sunday, November 4, 2012

OMB Approves PCII Survey ICR


Earlier this week the Office of Management and Budget (OMB) announced the approval of an information collection request (ICR) submitted by DHS National Protection and Programs Directorate (NPPD) that would allow NPPD to collect information during a survey of participants of the Protected Critical Infrastructure Information (PCII) program. The ICR was approved without change.

The ICR


The original Federal Register notice for this ICR (76 FR 17935-17936) notes that:

The PCII Program helps government analysts, emergency responders, and other homeland security professionals access data about facilities and systems on which the Nation depends. The PCII Program is responsible for ensuring compliance with the regulation’s uniform procedures for the handling, use, dissemination, and safeguarding of PCII. In this capacity, the PCII Program oversees a community of stakeholders, including submitters of CII, authorized users of PCII and accredited Federal, State and local entities with homeland security duties.

The purpose of the survey covered by this ICR is to “gather information to improve relationships with stakeholders and maximize the value of the PCII Program” according to the abstract provided in the ICR notice. NPPD expects to have 100 responses to this survey and expects that it will take about 13 hours for a respondent to collect the data and respond. As is typical for NPPD submitted ICRs, they don’t expect this effort to cost the respondents any money; apparently they have never heard of the adage that time is money.

Interestingly, this ICR was originally submitted in February and then was withdrawn by NPPD in July; there is no word why the ICR was withdrawn at that time. It was resubmitted in September with no new Federal Register notices (ICR submissions require a 60-day notice and a 30-day notice before being sent to OMB), so one would like to assume that there were no significant changes made in the submission documentation.

The Questionnaire


There is a link to the approved PCII Stakeholder Survey provided in the ICR document; it is actually a Word® document version of the on-line survey. The version of the survey in the original submission is actually a series of web shots of the actual planned on-line survey. The only real differences between the two are differing sets of questions 11 thru 14. There is nothing startling in the differences in those questions other than the approved version appears to be asking for slightly less detail. Perhaps this was done to increase the anonymity of the responses.

While the new question 11 does include ‘Submitter’ as one of the responses to describe the person completing the survey, the responses to question 12 does make it clear that this survey is being targeted at government users of the PCII program, not the public portion that is actually providing the information. That may be why there is no cost associated with the 13 hours per response noted in the ICR.

Implications


I think that it is fair to say that the proper sharing of PCII is an important perquisite to ensuring that intelligence and security analysts have access to the necessary information necessary for doing their jobs. As such it is important for the PCII program managers to understand those things that are making that proper sharing of information more difficult.

The Wiki Leaks fiasco has also shown us what happens when it is too easy to share critical information. It would have been nice to see at least one question in the survey that would address the issues of inadequate information sharing controls.
 
/* Use this with templates/template-twocol.html */