Showing posts with label S 3018. Show all posts
Showing posts with label S 3018. Show all posts

Monday, July 11, 2016

Committee Hearings – Week of 7-10-16

Both the House and Senate are in Washington this week, but it is scheduled to be their last week until early September. The hearing schedule is fairly light this week with only three hearings of interest to readers of this blog; two cybersecurity and one PHMSA oversight hearing.

Cybersecurity


On Wednesday the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee will be holding a hearing on “Value of DHS’ Vulnerability Assessments in Protecting Our Nation’s Critical Infrastructure”. This will deal with cybersecurity assessments conducted by the DHS Office of Cybersecurity and Communications (CS&C) and Office of Infrastructure Protection (presumably including assessments conducted by ICS-CERT). The witness list includes:

• Matthew J. Eggers, US Chamber of Commerce;
• Robert H. Mayer, United States Telecom Association;
• Mark Clancy, Soltra;
• Mordecai Rosen, CA Technologies; and
• Ola Sage, e-Management

On Tuesday the Energy Subcommittee of the Senate Energy and Natural Resources Committee will be holding a hearing on S 3018. The witness list includes:

• Patricia Hoffman, US Department of Energy;
• Duane D. Highley, Arkansas Electric Cooperative Corporation;
• Rob Manning, Electric Power Research Institute; and
• Brent Stacey, Idaho National Laboratory

Readers will recall that this is the bill that I called for support via a letter writing campaign.

PHMSA


On Tuesday the Surface Transportation and Merchant Marine Infrastructure, Safety, and Security Subcommittee of the Senate Commerce, Science and Transportation Committee will be holding a hearing looking at “The FAST Act, the Economy, and Our Nation’s Transportation System”. It is not clear what portions of the FAST Act will actually be covered in this hearing. The witness list includes:

• Patrick J. Ottensmeyer, Kansas City Southern Railway Company;
• Jay Thompson, Commercial Vehicle Safety Alliance
• David Eggermann, BASF
• Stephen J. Gardner, Amtrak 

On the Floor

There will be a large number of bills considered in the House this week under suspension of the rules with limited debate, no amendments, and requiring a super majority to pass the bill. Of those being considered only one is of specific (if very minor) interest to readers of this blog; HR 5639, the National Institute of Standards and Technology Improvement Act.


The Senate will take another try at starting debate on HR 5293, the FY 2017 DOD spending bill. Amendments (including one to substitute language from S 3000) will not be filed until the first cloture vote is agreed to. I’m not holding my breath, but this could possibly pass and go to conference before the summer recess.

Monday, June 13, 2016

S 3018 Response from Senator

Last week I encouraged folks to write their Senator in support of S 3018, the Securing Energy Infrastructure Act. This is a time honored technique that the average citizen can use to help influence the course of legislation in Washington. Unfortunately, it is also a disappointing way to learn how well your Senator’s staff reads and understands constituent communications.

Remember, unless you are a big donor, your Senator or Representative seldom actually sees your letter or email, it is typically read by a staffer who compiles statistics about how constituents feel on topics and selects an appropriate reply to that communication.

I received such a reply this morning from one of my Senators. It started off with the expected platitudes about being glad to hear from me and thanking me for sharing my concerns. Then it went into a canned response about the Senator’s support for a broad based energy security program based upon a “national energy policy to implement innovative solutions to increase electric generation and transmission, reduce gas prices”. Oops, they are talking about supply chain security and I was talking about cybersecurity.

Now one of two things was occurring there in the Washington office this morning. Either the staffer responsible for the reply did not know the difference between ‘supply chain security’ and ‘cybersecurity’, and/or the office does not have a canned response to cybersecurity and the staffer used the closest thing available. Both would be more than a little disturbing, but I would hope for the former, but knowing congresscritters I suspect that it is more likely that both would be true.

Now, does this mean that I think writing letters to your representatives in Washington is a waste of time? No, I would not have sent off my two letters if I felt that that was the case. Did I expect that my letter would have a major impact on the Senator? No, I’m not a major donor, nor do I have local political connections, so I doubt that the Senator actually sees my letter.

What I do expect, is that if the Senator is receiving multiple letters on this bill, when it comes up for consideration, the staff will tell the Senator that there is some level of constituent support for the bill and that will be taken into account when it comes time for a vote. If there is no opposition to the bill in the Senator’s office, that may be enough all by itself to get a positive vote. And if there is enough constituent support, some level of opposition can be overcome. If the Senator is against the bill, you don’t have much hope of changing that vote unless you get overwhelming constituent support or you make a real big campaign donation; and neither of those is absolutely sure of overcoming real opposition.


So, please, write your Senator and Representative, in support of S 3018 or any bill that you feel strongly about. You may not be able to influence their decision, but you certainly cannot if you do not write.

Wednesday, June 8, 2016

Letter to Senator Supporting S 3018

I just sent the following letter to each of my two Senators. You can find the contact information for your Senators here. You can either send them an snail mail letter or you can use the link provide to send your message on-line. In either case, your letter of support for S 3018 will help.

Senator:


I write to you today to show my support for the recently introduced S 3018, the Securing Energy Infrastructure Act. As a chemical manufacturing professional I am very aware of the cybersecurity issues surrounding the use of industrial control systems used in so many sectors of our economy.

While the Congress has become more actively engaged in cybersecurity issues, it has for the most part neglected the entire field of cybersecurity related to industrial control systems, even though successful attacks against such systems could put people physically at risk. The attacks last December in the Ukraine against the electrical distribution system in that country provide an obvious object lesson for what can be accomplished by a relatively simple attack on the computer control systems widely used in that industry.


I urge you to support S 3018 and would like to suggest that you become a co-sponsor of that bill. The people of Georgia rely on the electrical systems in this state for their health, welfare and livelihood. Those systems need to be protected. Please do your part.

S 3018 Introduced – Industrial Control System Security

Earlier this week Sen. King (I,ME) introduced S 3018, the Securing Energy Infrastructure Act. It would require the Secretary of Energy to establish a 2-year pilot program to study control system security in the energy sector. The pilot program would be funded at $10 Million for the 2-year study.

The Pilot Program


Section 3 of the bill would require the establishment of a “2-year control systems implementation pilot program within the National Laboratories” {§3} to study control system security in voluntarily participating energy sector critical infrastructure facilities “where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security” (covered entity) {§2(1)}.

The pilot program would {§3}:

• Studying the covered entities in the energy sector that voluntarily participate in the Program to identify new classes of security vulnerabilities of the covered entities; and
• Researching, developing, testing, and implementing technology platforms and standards to isolate and defend industrial control systems of covered entities from security vulnerabilities and exploits in the most critical systems of the covered entities

The definition (both legal and operational) of ‘control system’ is very broadly written. It is specifically defined in the bill {§2(3)(a)} as “an operational technology used to measure, control, or manage industrial functions”. That definition specifically includes {§2(3)(b)}:

• Supervisory control and data acquisition systems;
• Distributed control systems; and
• Programmable logic or embedded controllers.

Additionally, the bill later operationally adds {§3(2)}:

• Analog and non-digital control systems;
• Purpose-built control systems; and
• Physical controls.

Working Group


The Energy Secretary is also required to form a working group to evaluate the technology platforms and standards used in the pilot program. More broadly the Working Group is tasked with {§4(a)(2)} developing “a national cyber-informed engineering strategy to isolate and defend covered entities from security vulnerabilities and exploits in the most critical systems of the covered entities”.

The Working Group would include representatives from{§4(b)}:

• The Department of Energy;
• The energy industry, including electric utilities and manufacturers recommended by the Energy
Sector coordinating councils.
• The Department of Homeland Security (or the Industrial Control Systems Cyber Emergency Response Team);
• The North American Electric Reliability Corporation;
• The Nuclear Regulatory Commission;
• The Office of the Director of National Intelligence (or the intelligence community);
• The Department of Defense (or the Assistant Secretary of Defense for Homeland Security and America’s Security Affairs):
• A State or regional energy agency;
• A national research body or academic institution; and
• The National Laboratories.

Participant Protections


There are two types of protection provided to private sector participants in the pilot program; information protection and liability protection. Information voluntarily submitted during participation in the program is protected {§7(2)} from public disclosure requirements at the Federal, State and local levels. The bill also specifically states that {§8(a)} a “cause of action against a covered entity for engaging in the voluntary activities authorized under section 3 [the Pilot Program] shall not lie or be maintained in any court; and shall be promptly dismissed by the applicable court.”

Moving Forward


King {as well as one of his co-sponsors, Sen. Risch (R,ID)} is a member of the Senate Energy and Natural Resources Committee, to which this bill was referred for consideration. That means that there is a good chance that the bill will be considered in Committee. The only thing that might hold up consideration of this bill is the $10 Million dollars is authorizes to complete the pilot program and the $1.5 Million for operations of the Working Group and report preparation. That money has to be squeezed out of the budget somewhere.

Since the money authorization is included in this bill, I would not be surprised to see this bill again as a proposed amendment to a spending bill.

If the budget issue can be resolved, I do not see any impediments to the passage of this bill if it does make it to the floor of the Senate.

Commentary


Needless to say I am very excited to see this bill introduced. I am somewhat disappointed that it is limited to energy sector facilities, but I would bet that much of what is learned here could easily be used to improve control system security across multiple sectors of the economy. I would have preferred to see an unclassified version of the report required by the bill to aid in that information sharing.

I am especially happy to see how widely the bill defined control systems. This realistically reflects the fact that for reliability purposes these control systems rely on a wide variety of devices to protect the system from physical faults and they can be reasonably expected to help limit the effectiveness of any cyber-attack. Any study that fails to take those safeguards into account could lead to an overly expensive and complicated security system.

I have a couple of points that I would like to raise about the make-up of the Working Group. First, I would have preferred to see ICS-CERT listed as a standalone member of the Group instead of being listed as a possible substitute for a DHS representative. Hopefully the DHS Secretary would ensure that ICS-CERT had the seat at the table, but they are a rather low level entity in DHS and DHS internal politics could see them shunted to the side.

Secondly, the Working Group is missing someone from the operational side of things. I understand that it would be difficult to pick a single utility and/or vendor (I would really like to see both) to sit in on the Working Group, I think that the operational insight would be invaluable in the Working Group’s deliberations. Perhaps each of the participating entities could select a group spokesman to represent their view point. Selecting a vendor representative would be more difficult, but perhaps FERC could nominate a widely recognized consultant in control system implementation to provide insight into that side of operational planning.

I really think that this bill is important enough to call for a little political involvement by those in the control system security community. It would certainly help if people would start a letter writing campaign to their Senators and Representatives to urge their support for this bill. People that live and/or work in States where their Senator is on the Energy and Natural Resources Committee (see here for a list of members) should specifically encourage their support of this bill in Committee. For letters to Representatives, they should encourage the introduction of a companion bill in the House and support for the bill when it gets to the floor for consideration.


This is the first bill that I have seen that takes a proactive stance on control system security issues. More importantly it puts some money into that stance, something that has been missing from most cybersecurity bills. We need to get behind this and push it.

Tuesday, June 7, 2016

Bills Introduced – 06-06-16

With just the Senate back in session (the House returns to town today) there were eleven bills introduced. Of those three may be of specific interest to readers of this blog:

S 3017 An original bill to authorize appropriations for fiscal year 2017 for intelligence and intelligence-related activities of the United States Government, the Community Management Account, and the Central Intelligence Agency Retirement and Disability System, and for other purposes. Sen. Burr, Richard [R-NC]

S 3018 A bill to provide for the establishment of a pilot program to identify security vulnerabilities of certain entities in the energy sector. Sen. King, Angus S., Jr. [I-ME]

S 3024 A bill to improve cyber security for small businesses. Sen. Vitter, David [R-LA]


I’ll be watching the Intel authorization bill for cybersecurity related provisions. The same holds true for the other two bills as well.
 
/* Use this with templates/template-twocol.html */