Showing posts with label S 2764. Show all posts
Showing posts with label S 2764. Show all posts

Friday, August 9, 2019

S 2181 Introduced – Aircraft Cybersecurity


Last month Sen. Markey (D,MA) introduced S 2181, the Cybersecurity Standards for Aircraft to Improve Resilience (Cyber AIR) Act of 2019. This bill is very similar to S 2764 that Markey introduced in the second half of the 114th Congress.

Differences


The major difference between the two bills is that the reporting congressional reporting requirements found in §5 of the earlier bill have been removed from the current version. That would have required annual reports to Congress on the attacks reported to the FAA by air carriers and manufacturers under provisions of §3.

Two other changes are found in §5 of the current bill. The formatting is changed from §6 of S 2764 and the last subparagraph {§6(c)(2)} from the earlier bill has been deleted in S 2181. That subparagraph would have required that the report to Congress from the FAA-FCC Leadership Group would have been required to be “submitted in unclassified form, but may include a classified annex”.

Moving Forward


Markey is still a member of the Senate Commerce, Science, and Transportation Committee and he has added a cosponsor {Sen. Blumenthal (D,CT)} who is a senior Democrat on that Committee. This increases the likelihood that this bill would see consideration in Committee. In the 114th Congress. I suspect that the bill, if considered, would receive substantial opposition from Republicans, thus killing any chances that the bill would move to the floor of the Senate.

Commentary


There is no reference in this bill to cooperation with the DHS Cybersecurity and Infrastructure Security Agency. CISA was not in existence when the earlier version of the bill was introduced, but I would have expected this version to be updated to substitute CISA for generic references to cooperation or coordination with ‘the Secretary of Homeland Security'. CISA is, of course, supposed to be the Federal government’s expert on all thing’s cybersecurity.

Over the years I have been a strong proponent of actively involving ICS-CERT and now CISA in anything involving Federal oversight of control system security in all of its guises. Mainly, I have asserted that the limited availability of control system security expertise in government (and to a somewhat lesser extent in the private sector) meant that that the localization of that talent in a single agency would probably make a great deal of sense. I am starting to rethink that proponency (hmmm, that may be a new word according to spell check).

First, it appears that DHS in general, and CISA in particular, has ‘deemphasized’ the importance of control system security expertise with the effective elimination of ICS-CERT. This has always been the problem of putting all of your ‘eggspertice’ in one administrative basket; bureaucratic adjustments in the size of that basket have unintended consequences outside of the agency’s mandate.

More importantly, not requiring safety regulatory agencies (like the FAA in this case) to have cybersecurity expertise in general, and control system expertise in particular, fails to recognize the impact of cybersecurity on safety. Safety regulators are going to increasingly become control-system cybersecurity regulators as more and more safety systems rely on interconnected control-system components. Safety regulatory agencies are going to have to be forced by Congress to formalize and grow their cybersecurity capabilities.

With that in mind, I would like to suggest an addition to §3 of the bill:

(c) The Secretary will establish within the FAA an Aviation Cybersecurity Office (ACO) to receive the cyberattack reports described in (a) and develop recommendations for, and implement, regulatory actions described in (b). The Director of the ACO will be familiar with avionics control systems and cybersecurity of such systems. Additionally, the ACO will:

(1) Receive cybersecurity incident reports from covered air carriers and covered manufacturers;
(2) Prepare anonymized reports on such incidents that would identify security vulnerabilities (as defined in 6 USC 1501) that could affect other carriers and manufacturers and coordinate the disclosures of those security vulnerabilities;
(3) Establish procedures and processes by which security researchers can report security vulnerabilities for further coordinated disclosure; and
(4) Coordinate with the National Cybersecurity and Communications Integration Center on sharing security vulnerability information.

Monday, April 11, 2016

S 2764 Introduced – Aircraft Cybersecurity

Last week Sen. Markey (D,MA) introduced S 2764, the Cybersecurity Standards for Aircraft to Improve Resilience (Cyber Air) Act of 2016. The bill replicates the three amendments that Markey proposed to HR 636, the FAA authorization bill currently under consideration in the Senate.

Definitions


With the combination of the three amendments §2 provides a common set of definitions. Terms included in this section are:

• Covered air carrier;
• Covered manufacturer;
• Cyberattack;
• Critical software systems; and
• Entry point.

The two critical terms are ‘cyberattack’ and ‘critical software systems’. Cyberattack is defined as “the unauthorized access to aircraft electronic control or communications systems or maintenance or ground support systems for aircraft, either wirelessly or through a wired connection” {§2(3)}. The term ‘critical software systems’ is defined as “software systems that can affect control over the operation of an aircraft” {§2(4)}.

Incident Reporting


Section 3 of the bill is essentially SA 3468, the first of three cybersecurity amendments that Markey proposed to HR 636. It would require the Administrator to prescribe regulations requiring air carriers and manufacturers to disclose cyberattacks to the FAA. The attacks would have to be reported whether or not they were successful. The attacks would have to be reported “whether or not the system is critical to the safe and secure operation of the aircraft, or any maintenance or ground support system for aircraft, operated by the air carrier or produced by the manufacturer, as the case may be” {§3(a)}.

FAA would use the information disclosed by air carriers and manufacturers to inform future regulatory actions. The FAA would also be required to “notify air carriers, aircraft manufacturers, and other Federal agencies of cybersecurity vulnerabilities in systems on board an aircraft or maintenance or ground support systems for aircraft” {§3(b)}.

Cybersecurity and Operating/Manufacturing Certificates


Section 4 is essentially SA 3469. It would require the Secretary of Transportation to prescribe regulations incorporating cybersecurity standards into the requirements to obtain/maintain air carrier operating certificate or a production certificate under 49 USC Chapter 447. Those regulations would include requirements to {§4(b)(2)}:

• Require all entry points to the electronic systems of each aircraft operating in United States airspace and maintenance or ground support systems for such aircraft to be equipped with reasonable measures to protect against cyberattacks, including the use of isolation measures to separate critical software systems from noncritical software systems;
• Require the periodic evaluation of the measures described in subparagraph (A) for security vulnerabilities using best security practices, including the appropriate application of techniques such as penetration testing; and
• Require the entry point measures to be periodically updated based on the results of the evaluations conducted above.

Consumer Communications Equipment


Section 6 address the role of the DOT-FCC’s Commercial Aviation Communications Safety and Security Leadership Group as did amendment SA 3470. The bill would make them responsible for evaluating the cybersecurity vulnerabilities of broadband wireless communications equipment designed for consumer use on board aircraft operated by covered air carriers. They would be required to {§6(b)}:

• Ensure the development of effective methods for preventing foreseeable cyberattacks that exploit broadband wireless communications equipment designed for consumer use on board such aircraft; and
• Require the implementation by covered air carriers, covered manufacturers, and communications service providers of all technical and operational security measures that are deemed necessary and sufficient by the Leadership Group to prevent cyberattacks described above.

Reports to Congress

Section 5 of the bill can be found in the language of the first Markey amendment to HR 636. It requires an annual report to Congress on the attacks reported under provisions of §3.

Section 6(b) would require annual reports by the Leadership Group to Congress. Those reports would include {6(b)(1)}:

• The technical and operational security measures developed to prevent foreseeable cyberattacks that exploit broadband wireless communications equipment designed for consumer use on board aircraft operated by covered air carriers; and
• The steps taken by covered air carriers, covered manufacturers, and communications service providers to implement the measures described above.

Moving Forward


Markey is a rather junior Democrat on the Senate Commerce, Science and Transportation Committee. Normally this might provide him sufficient influence to have the Committee consider this bill. But slightly different versions of the HR 636 amendments that formed the basis for this bill were already considered and rejected by moderately bipartisan votes in the Committee during markup of S 2658. The Committee is extremely unlikely to take up this bill with that history.

Commentary


It looks like Markey is trying to make a name for himself as the cybersecurity Senator. He is well out in front of his colleagues in suggesting detailed legislative solutions to cybersecurity problems that most of his compatriots have not yet recognized as being serious problems. At this point that kind of leaves him as a voice crying in the wilderness. How long he will be willing to continue to do this in the face of general opposition in the Senate is an interesting political question.

Of course it will take a single high-visibility cyber incident to change Markey from a political odd ball into a prophet. If such an incident (probably with loss of life) occurs during the remainder of this session of Congress, we can expect that this bill would probably form the initial basis for the knee jerk reaction of the Senate.

With that in mind, let’s look at some of the problems that arise in legislation when politicians try to get too detailed in their technical mandates. The use of the term ‘critical software systems’ unnecessarily limits the application of this bill. It should instead read ‘critical control systems’ or maybe ‘critical electronic systems’ if one wanted to include electronic communications systems in the cybersecurity coverage. The way the bill is currently written, for example, completely ignores firmware issues.

In section 6 of the bill we see a similar problem with the use of the term ‘broadband wireless communications’ to describe potential cybersecurity problems caused by customer communications equipment. While wi-fi connections are a potential route of entry into critical aircraft systems, they are not the only consumer communications mode that may cause problems. Cyber radio and even potentially cell phone traffic could prove to be problematic in future configurations. To allow the broadest application of the intent of this section this probably would have been better written as ‘consumer communications equipment’.

One of the complaints I have heard repeatedly from cybersecurity specialists when we start talking about legislation in this realm is that such legislation is likely to be out-of-date or inadequately focused before the legislation is passed. Legislation like this bill is certainly what they are talking about. Legislation needs to be broadly written to allow the regulators with at least some technical background to address the changing technological environment in which the regulated industry operates.


Not only are legislators likely to get the technical details wrong, but legislators take even longer to adapt to change than do regulators. When you add the legislative delay on top of the regulatory delay you end up with obsolete regulations attempting to control completely unforeseen circumstances.

Friday, April 8, 2016

Bills Introduced – 04-07-16

The Senate was still alone on the Hill yesterday and a total of 13 bills were introduced. Of those only one was of potential specific interest to readers of this blog:

S 2764 A bill to require the disclosure of information relating to cyberattacks on aircraft systems and maintenance and ground support systems for aircraft, to identify and address cybersecurity vulnerabilities to the United States commercial aviation system, and for other purposes. Sen. Markey, Edward J. [D-MA]


By the description given this bill looks like the three amendments that Markey introduced on Wednesday to HR 636. That is an interesting move on his part. It would suggest that he does not think that those amendments will be considered on the Senate floor (I made that comment yesterday), but that they have some chance of being considered separately before the end of the year. That is highly unlikely since in an election year neither the Senate or the House typically take up legislation that should have been included in an authorization bill that was passed.
 
/* Use this with templates/template-twocol.html */