Showing posts with label S 2151. Show all posts
Showing posts with label S 2151. Show all posts

Sunday, July 1, 2012

Differences Between S 2151 and S 3342


I noted last week Sen. McCain introduced S 3342 and without seeing the bill I expected that it was some sort of compromise between his earlier bill, S 2151, and the Senate bill that has been expected to move forward, S 2105. This weekend the GPO made S 2151 available on-line and it turns out that the new bill is more properly a tweaking of McCain’s earlier bill, falling well short of being a compromise measure.

Changes in the Bill


The new bill adds the following new sections:

§104. Construction.

§106. Inspector General review.

§205. Clarification of authorities.

§307. No new funding.

Only one section was removed; §408. Cybersecurity strategic research and development plan.

Additionally, a number of new definitions were added to §101. They include:

• Federal information system

• Information security

• Local government

• Significant cyber incident

• Tribal

Finally there were a number of wording changes that fine-tuned the privacy provisions and information sharing requirements of the bill. The details of those changes, and the added provisions, will probably only be of interest to lawyers and politicians.

There really are no significant changes in the bill and it still completely ignores the problem of cybersecurity of industrial control systems.

Moving Forward


With both the Senate and the House being on their extended July 4th holiday next week nothing is going to get done any time soon on the cybersecurity legislative front. This bill is dead in the water as the only bill that has any chance of moving forward in the Senate (after inevitable changes) is S 2105. Even that bill has little chance of passing before the election due to privacy concerns and business opposition to new regulations; too many people on both sides of the aisle oppose the bill, so it is unlikely to come to a vote. In most cases this opposition is not just election year posturing so passage even in the lame duck session is unlikely.

Sunday, March 4, 2012

S 2152 Language

Thanks to two different readers I now have a copy of S 2151, the Strengthening and Enhancing Cybersecurity by Using Research, Education, Information, and Technology (SECURE IT) Act of 2012 that was introduced by Sen. McCain on Thursday. The copy I have is the final draft version from committee files, but until the GPO publishes the final version it’s the best available information. It is a much more limited cybersecurity bill than S 2105, not providing any additional regulatory powers to DHS.

Information Sharing


For the civilian portion of critical infrastructure there is little more in the bill that some provisions that authorize information sharing from the civilian sector to the federal government. While at first glance it would not seem necessary to authorize that sharing, the provisions of the bill allow the sharing of ‘cyber threat information’ with existing federal ‘cybersecurity centers’ or ‘any other entity’ for the purpose of “preventing, investigating, or otherwise mitigating threats to information security [emphasis added]” {§102(a)(2)(B)}. Again, this bill uses the common definition of ‘information security’ that does not specifically include control systems from 44 USC 3502(8).

Nothing in the definition of ‘cyber threat’ includes specific language that would include information systems linked to control systems. Nor is the ICS-CERT listed as one of the current agencies listed as ‘cybersecurity centers’. In short the information sharing section (Title I) of this bill has no effect on control system security, nor does it authorize sharing of cyber threat information concerning control systems.

The information sharing provisions of this bill are important because the exempt the sharing of cyber threat information from the communications limitations of various anti-trust rules and regulations; provide public reporting exemptions under the Freedom of Information Act and pre-empts state laws regarding information sharing.

Criminal Penalties


There is an important control system related change being made in this bill in that it provides for criminal penalties for attacks on control systems in critical infrastructure. It adds Section 1030A to 18 USC that makes it an offense to knowingly cause, or attempt to cause, damage to a ‘critical infrastructure computer’ or the critical infrastructure associated with the computer. It provides for a sentence of 3 to 20 years for each offense.

A ‘critical infrastructure computer’ is defined as “a computer that manages or controls systems or assets vital to national defense, national security, national economic security, public health or safety, or any combination of those matters, whether publicly or privately owned or operated” {§1030A(a)(2)} and then goes on to list the following included sectors:

• Gas and oil production, storage, and delivery systems;

• Water supply systems;

• Telecommunication networks;

• Electrical power delivery systems;

• Finance and banking systems;

• Emergency services;

• Transportation systems and services; and

• Government operations that provide essential services to the public.

If and when someone actually gets caught attacking a non-refinery chemical control system we will find out how broadly the courts will interpret ‘national economic security, public health or safety’ as it pertains to facilities in sectors not specifically listed in the bill. It would have seemed more appropriate to list all of the current 18 Critical Infrastructure Sectors.

Research and Development


Title IV of this bill provides for an amendment to the National High-Performance Computing Act of 1991 by adding research on networking and information technology to the goals and priorities section of that act without adding any additional funding for such research goals.

Section 404(b) of the bill provides for special emphasis on research on technical solutions in a variety of cyber technologies including cybersecurity {§404(b)(1)} and ‘cyber-physical systems’ {§404(b)(5)}. Cyber-physical systems are defined as “physical or engineered systems whose networking and information technology functions and physical elements are deeply integrated and are actively connected to the physical world through sensors, actuators, or other means to perform monitoring and control functions [emphasis added]” {§401(g)(4)}; a clear, unequivocal reference to industrial control systems.

The ‘cyber-physical systems’ research is to be focused on improving “the methods available for the design, development, and operation of cyber-physical systems that are characterized by high reliability, safety, and security [emphasis added]” {§402(b)(3)}.

No Real Control System Security


So once again we have a cyber-security bill that essentially ignores the unique problems with control systems. Nor are there any regulatory requirements that would allow the government to force software vendors to address vulnerabilities in software systems in either the information security sector or in the control system sector.

Friday, March 2, 2012

S 2151 Introduced – Alternative Cybersecurity Legislation

Yesterday, as he promised during the hearing on S 2105, Sen. McCain (R,AZ) introduced S 2151 yesterday as an alternative method of regulating cybersecurity issues. McCain’s bill is not yet available on the GPO web site (nor anywhere else that I have looked in a cursory search) so I can’t really comment on the provisions of the bill. To see what the various sponsors think the bill says you can look at the press release on McCain’s Senate website.

An interesting procedural note; when the bill was introduced it was referred to the Senate Committee on Commerce, Science, and Transportation for action, not the Homeland Security and Governmental Affairs Committee. These two committees kind of share responsibility for cybersecurity issues in the Senate, so it isn’t too much out of the ordinary.

In the normal course of events one would suppose that the two bills being referred to two different committees would be a sign of a jurisdictional fight between them. That probably isn’t the case here as Chairman Rockefeller was a cosponsor of S 2105 and testified on its behalf before the Homeland Security Committee.

The bill will probably be available next week and I’ll take a detailed look at it then.
 
/* Use this with templates/template-twocol.html */