Showing posts with label Penetration Testing. Show all posts
Showing posts with label Penetration Testing. Show all posts

Wednesday, March 27, 2024

Review - HR 7447 Introduced – Election System Pentests

Last month, Rep Spanberger (D,VA) introduced HR 7447, the Strengthening Election Cybersecurity to Uphold Respect for Elections through Independent Testing (SECURE IT) Act. The bill would amend the Help America Vote Act of 2002, by adding to the existing election system certification system a requirement to conduct 3rd party penetration testing of such systems. It would also establish a voluntary vulnerability disclosure program. No new funding is authorized by the legislation.

Moving Forward

Neither Spanberger nor her two cosponsors {Rep Deluzio (D,PA) and Rep Valadao (R,CA)} are members of the House Administration Committee to which this bill was assigned for primary consideration, nor the House Science, Space, and Technology Committee to which the bill was assigned for secondary consideration. This means that there is practically no chance that the bill will be considered by either committee. I see nothing in the bill that would engender any organized opposition. I suspect that it would receive some level of bipartisan support were it considered.

Commentary

While the term ‘penetration testing’ is used in the legislation, it is never defined. I would suggest using the definition of that term found in NIST 800-95 (pg C-3):

“A method of testing where testers target individual binary components or the application as a whole to determine whether intra or intercomponent vulnerabilities can be exploited to compromise the application, its data, or its environment resources.”

 

For more details about the provisions of this legislation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7447-introduced - subscription required.

Friday, September 15, 2023

Review - HR 4552 Introduced – 2023 FISMA

Back in July, Rep Mace (R,SC) introduced HR 4552, the Federal Information Security Modernization Act of 2023. This is the perennial update of the Federal agency cybersecurity rules. It includes two items of potentially broader interest here: penetration testing policy and vulnerability disclosure policy.

Moving Forward

Mace, and all four of her cosponsors {Rep Raskin (D,MD) Rep Comer (R,KY), Rep Connolly (D,VA) and Rep Davis (D,NC)}, are members of the House Oversight and Accountability Committee to which the bill was assigned for consideration. This means that there is almost certainly sufficient influence to see the bill considered in Committee. I do not see anything that would engender organized opposition to the legislation. I suspect that there would be significant bipartisan support for the bill, probably enough that it could be considered under the House’s suspension of the rules process.

It will be interesting to see how much the Committee’s investigative efforts directed at the Biden Administration will affect their ability to consider bipartisan legislation like HR 4552.

Commentary

I found it odd that §12’s new §3559b removed the contractor cybersecurity requirements of 15 U.S.C. 278g–3e. There is nothing in that section that deals with VDP requirements. It looks to my suspicious mind like someone is trying to reduce cybersecurity requirements for contractors. In any case the deletion of that section should be remove from this section since it has nothing to do with VDP.

 

For more details about the penetration testing and vulnerability disclosure program provisions of the legislation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4552-introduced - subscription required.

Tuesday, August 14, 2012

Another High Profile Perimeter Security Incident


A little over a week ago I wrote about the perimeter breach at a nuclear fuel processing site. Yesterday there were news reports about a stranded jet-skier who walked from a beach at JFK to the terminal (across two runways and gained access to the terminal) without encountering security personnel until he asked an airline employee for assistance. In both instances amateurs easily gained effective access to high-profile security areas with little effort.

As a long-time reader and security professional noted in a response to my earlier blog posting (BTW: That response is well worth reading in its entirety.):

“With all of the academics discussing regional resiliency and other highly important subjects, it pains me that the journeymen of our industry still do not understand these basic tenants of industrial security.”

Why is Perimeter Security So Difficult?


With all of the advances in video surveillance, video analytics and intrusion detection systems, perimeter security remains a manpower intensive operation. Someone has to monitor these systems and someone has to respond to system alerts. Since security is not a profit center, the personnel responsible for monitoring and response are too often underpaid and under qualified. All too often this results in people that have no real incentive to care about their job.

In the real world effective automated detection systems have a high false alarm rate, if they don’t they make it too easy for professionals to penetrate the perimeter (NOTE: It is impossible to design a perimeter that cannot be penetrated). In the industry these false alarms are well known as ‘nuisance alarms’. As time passes the aggravation caused by these nuisances results in sensitivity adjustments to the automated systems to reduce the number of such alarms, or in people ignoring the alarms when they do occur. This is simply human nature. In any case this results in a perimeter that is easier to penetrate.

How to Avoid Security Complacency


Probably the best way to avoid perimeter security complacency is to conduct periodic penetration testing. Specially trained Red Teams are given the mission to penetrate the security perimeter. Special training is required so that these teams only use the amount of penetration skills appropriate to the security level of the facility being protected. For example a nuclear weapons storage facility would require a higher degree of professionalism to be used in the attempted penetration than would a warehouse holding high-cost consumer goods.

Bonuses can be given to the security team that detects and intercepts the Red Team; the earlier the detection and interception the higher the bonus. Penetrations such as those noted in the two recent news reports require the application of negative inducements and corrective reassessment of security measures including training.

Responsive Activities Require Training and Testing


Any kind of activity that requires an immediate and effective response to an outside stimulus requires periodic training and testing. If you require a high-level response to infrequent events you must invest the time and resources necessary. Proper training and periodic evaluation of the necessary skill sets is an absolute necessity. Otherwise your organization is going to be embarrassed by these types of incidents, or worse, you’re going to have a catastrophic failure of your security that is going to result in death and destruction.
 
/* Use this with templates/template-twocol.html */