Showing posts with label Remote Access. Show all posts
Showing posts with label Remote Access. Show all posts

Thursday, July 10, 2025

Review - HR 2683 Introduced – Remote Access Export Controls

Back in April Rep Lawler (R, NY) introduced HR 2683, the Remote Access Security Act. The bill would authorize the DOC’s Bureau of Industry and Security (BIS) to regulate the use of remote access by a foreign person of items subject to the jurisdiction of the United States under the export control regulations. No new funding is authorized by this bill.

Committee Action

The House Foreign Affairs Committee held a business meeting on April 19th, 2025, where nine bills were considered, including HR 2683. The Committee adopted substitute language offered by Lawler and ordered it reported favorably by a vote of 57 to 0.

Moving Forward

The unanimous vote to adopt the bill in Committee suggests that the bill will be considered by the House under the suspension of the rules process. The problem, as with most legislation, will be in how this bill is considered in the Senate. It does not appear that this bill would be politically important enough to be considered under regular order. Again, the unanimous vote in Committee suggests that this bill could be considered under the unanimous consent process, but that is far from a sure thing.

Commentary

This is a broadly written bill that would give the DOC’s Bureau of Industry and Security (BIS) comprehensive authority to regulate the control of remote access to most devices on the export control list. Just how the Committee expects BIS to accomplish this regulatory task is not made clear.

 

For more information on the provisions of this bill, including a more detailed look at the changes in the substitute language, and an expanded commentary on the enforcement implications, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-2683-introduced-remote-access - subscription required.

Monday, March 14, 2016

PSP User Manual – Potential Problem Solutions

This is part of an on-going series of blog posts about the new Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety plan (PSP) User Manual. This manual sets forth the instructions for using the new PSP tool in the on-line Chemical Security Assessment Tool (CSAT). Other blogs in this series include:


Potential Problems Identified


Back in in early January, after DHS published their PSP program notice in the Federal Register, I wrote a blog post about potential problems with the system as it was explained in that notice. The potential problem areas identified in that post include:

• Multiple facilities
• Facility turnaround contractors
• Local delivery drivers
• Electronic access
• False positives

As expected, the User Manual did not specifically address any of these problems. It did, however, provide information to help resolve three of these problems; multiple facilities, facility turnaround contractors and electronic access.

Multiple Facilities


As long as all corporate facilities all have a single authorizer (the most likely situation), the PSP can be set up so that the Corporation Group would be a single account listing all company personnel with access to any of the covered facilities within the company. The Corporate Group could have a single submitter to support all facilities or individual submitters from each of the covered facilities. The latter would allow for a person at each covered facility who was able to review all of the personnel for whom PSP data submissions had been made.

If the company set up separate Groups for each facility that would still allow the Corporate Group to be set up for personnel from headquarters that could be visiting any of the covered sites within the company and might require unaccompanied access as ‘visitors’. Unfortunately, there would be no one at the facility who could verify data submission on those personnel in the Corporate Group, because the local Submitter would not have access to the Corporate Group data and one person cannot be a Submitter in multiple Groups within the same company.

A way around this would be to make someone else at the local facility a Submitter on the Corporate Group. Another way around the problem would be for HR to forward a completed template spread sheet with the required information for those company personnel that might be visiting the covered facility for that facility Submitter to upload to the local facility Group.

Facility Turnaround Contractors


The new PSP CSAT tool provides an easy solution for the problem of facility turnaround contractors without having to require possession of a TWIC or HME. The Authorizer can set up a Group for the main contractor responsible for turnarounds with a Submitter from that contractor.

The contractor would then be responsible for uploading the individual data for all personnel who would be working on that site. The contractor could then provide a status report for that facility that showed that all personnel data had been submitted. That document would, of course, be a Chemical-terrorism Vulnerability Information (CVI) protected document. The facility could then prepare a sign-in/sign-out sheet to help keep track of the contractors on site. As long as the sheet did not reference the PSP program or PSP status, this would not be a CVI protected document.

Electronic Access

Facilities that are going to allow vendors routine electronic access to physical components of control systems, building access systems, or security monitoring systems for maintenance purposes are going to have to include the vendor personnel who will have that access in their PSP program. This would require that they be set up as a separate Group on the PSP tool. Again the Authorizer would set up a vendor employee as a Submitter for that Group and establish an oversight Submitter from the company so that there would be someone in the company that could verify that data had been submitted.

Oversight Submitter


In a couple of places above I have suggested that the Authorizer establish a company employee as an ‘oversight Submitter’ on Groups that are being used to submit data on personnel who are not company employees. The idea here is that there would be someone from the covered facility that could access the Group data on the PSP tool to verify that an individual’s data had been submitted to the PSP tool prior to allowing that person access to a covered facility.

This is somewhat complicated by the fact that a person can only be a Submitter on one group under a given Authorizer. Small facilities could quickly run out of people who could verify the PSP status on multiple contractor or vendor Groups.

What is really needed is for the tool to be modified by adding a PSP Reviewer position. A reviewer would typically be the Security Manager or person fulfilling that type role on a local basis. The Authorizer could then specify multiple Groups within the company that each reviewer would be authorized to access to verify the submission status of contractor, vendor or corporate personnel desiring unaccompanied access to the critical areas of the facility.


The way things are currently structured in the PSP tool there is only one person who has access to the PSP status of all personnel in multiple groups; the Authorizer. It does not make any kind of sense in having a corporate officer put in the position of potentially having to be available at all hours to verify that someone has been properly vetted through the PSP program.

Wednesday, January 6, 2016

Configuring and Managing Remote Access for Industrial Control Systems

This afternoon the DHS ICS-CERT published an abstract of and link to an interesting document developed by the British Centre for the Protection of National Infrastructure. The 67 page document addresses the design of systems to allow remote access for ICS.

The ICS-CERT abstract explains:

“Part of the security equation involves how operational assets are accessed and managed and how the cyber security posture of a control system can be impacted if the management of remote access is not understood by business or is conducted poorly. However, the application of proven and accepted remote access solutions may not map perfectly to control systems environments. Requirements for availability and integrity, combined with the unique nuances and attributes often found in ‘purpose built’ systems, drive new demand for guidance as it pertains to creating secure remote access solutions for industrial control systems environments.”

The table of contents lists some interesting topics:

• Remote access in industrial control system architectures;
• Roles and remote access in control system architectures;
• Types of remote access solutions;
• Security Considerations;
• Remote access security considerations unique to control systems;
• Applying good practices;

This looks like an interesting document that should provide some valuable insights. I’ll be looking at it in more detail in the coming days, but this is more of a technical document than the type of thing I address in detail in this blog.

Saturday, February 5, 2011

DHS Control System Security Program Page Update

The DHS Control System Security Program web page was updated yesterday to include links to news about the upcoming Industrial Control System Joint Working Group (ICSJWG) 2011 Spring Meeting in Dallas, Tx and a new ICS-CERT recommended practices document.

ICSJWG Spring Meeting

The 2011 Spring Meeting will be held on May 2nd thru 5th at the Dallas/Addison Marriott Quorum hotel. According to the meeting web page

“The ICSJWG Conference will consist of panel discussions, presentations, training, and working group meetings on various topics such as emerging technologies, standards development, threat and incident reporting, analysis tools and techniques, roadmap development initiatives, workforce development and certification, vulnerability management, research and development, information sharing, and international coordination.”
The page also includes a Call for Papers for this meeting. It provides a non-exclusive list of potential topics, a link to an electronic submission form for sending an abstract for a proposed presentation and a submission deadline of February 18th.

The last day of the Spring Meeting will be the typical ICSJWG all-day training course. For this meeting it will be the Intermediate Industrial Control Systems Cybersecurity training. Prior control system security experience or attendance at the basic-level course is the recommended prerequisite for this class. The training will include:

• The importance of protecting control systems from cyber attacks and why they are susceptible

• Understanding the risks and potential consequences of attacks

• Understanding common vulnerabilities in industrial control systems

• Discussion of system exposures to attacks, various attack scenarios, and associate mitigation strategies

• Control Systems Security Program products and services that are available to asset owners.
Both the Spring Meeting and the all-day training are free. Well, that’s not completely true; no charge for attending, but you do have to pay for travel and accommodations. As I expect that most travel budgets remain tight (I know mine is) I will make my standard recommendation that the organizers of this conference consider providing on-line access to at least some of the presentations. It would certainly expand the potential audience for this valuable information.

Remote Access for ICS

The DHS Control System Security Program and the Center for the Protection of Critical Infrastructure have produced a new best practices document; Configuring and Managing Remote Access for Industrial Control Systems. In a modern industrial setting there are many legitimate reasons to provide remote access to control systems this lengthy and dense document provide a detailed look at how that access can be provided in a secure manner.

This is not a how-to manual, but more of a policy discussion. As is typical for many policy discussion documents this means that the writing can get fairly intense. For example, here is the opening paragraph in the discussion of on ‘password policy’:

“In an ideal deployment, authentication mechanisms should be chosen based on the criticality of the system being accessed and should include not only passwords, but other mechanisms as well (see the section on ‘Two form factor authentication’). When using passwords, a secure remote access system should enforce complex passwords of 8 to 25 characters that are a mixture of upper and lower case letters, numbers and symbols.k In addition, corporate policy should demand that these passwords be changed at a rate that is commensurate with the value of the system being protected and regular audits of the strength of these passwords should be done as part of the organisational [sic] cyber security program. The corporate cyber security policy should dictate that these passwords are never shared and that each user ID is unique across the entire system.”
This seems fairly straightforward until you get down to the footnote referred to in the middle of the paragraph. That footnote (k) reminds the reader that:

“This guideline is a recommended best practice for general ICT security and the authors recognise [sic] that the creation and use of a 25-character complex password (although ideal) for day-to-day human machine interface operations may be inappropriate. The recollection and usage of such a password under duress may create circumstances that are unacceptable from a safety perspective.”
I think that this is a valuable manual to have and review, but I do have on major complaint about the mechanics of the document. There are a large number of high-density graphics included that make navigation through the 66-page document difficult and time consuming if you are using an older system. I had page load times of almost two minutes using my old Windows 2000 based lap top.
 
/* Use this with templates/template-twocol.html */