Showing posts with label S 413. Show all posts
Showing posts with label S 413. Show all posts

Thursday, February 24, 2011

S 413 – Risk Based Security Measures

As I noted in my initial blog posting on the recently introduced S 413, the Cybersecurity and Internet Freedom Act of 2011, would require to establish regulations to require security protections for industrial control systems in certain critical infrastructure facilities. Today I would like to take a look at the requirements for those regulations outlined in this bill.

Risk Assessment

Section 248(a) of the bill would require the Director of the National Center for Cybersecurity and Communications (NCCC), in conjunction with appropriate governmental regulating agencies, to conduct a cyber risk assessment “on a continuous and sector-by-sector basis [emphasis added], [to] identify and evaluate the cyber risks to covered critical infrastructure” {§248(a)(1)}. The risk assessment would look both at the potential for attack and the consequences of a potential attack.

The first such report would be due within 180 days of the passage of this legislation. There is also a requirement for annual updates of these reports. The reports would be submitted to Congress, but to aid in the widest possible dissemination of the information, the reports are required to be unclassified. To allow Congress to be informed of risks based upon classified information, the Director may include a classified annex to the report.

An interesting component of this risk assessment is the requirement for the Director to establish “process under which owners and operators of covered critical infrastructure may provide input on the findings of the reports” {§248(a)(3)(B)}. A potential method that could be used to fulfill this responsibility would be to establish a cyber security fusion center.

Risk-Based Security Performance Measures

After the first risk assessments are required to be completed the Director would have an additional 90 days to publish, again in ‘coordination’ with the appropriate federal regulating authorities, “interim final regulations establishing risk-based security performance requirements to secure covered critical infrastructure against cyber risks through the adoption of security measures that satisfy the security performance requirements identified by the Director” {§248(b)(1)}. The phrase ‘interim final regulations’ is important because it allows (but does not require) the director to skip the requirement for publishing a notice of proposed regulation, shortening the regulation development process.

These regulations would provide for notification of owners and operators of ‘covered critical infrastructure’ of the cyber risks identified by the Director, security performance requirements and identified best practices to remediate or mitigate those risks. The regulations would provide for owner/operators to select appropriate security measures and/or best practices to deal with those risks and report that selection to the Director. The regulations would also prescribe a process that the Director would use to “determine whether the proposed security measures satisfy the security performance requirements established by the Director” {§248(b)(2)(D)(ii)}.

The regulations would allow facilities to develop their own ‘best practices or security measures’ and report those to the Director. These reports would be protected by “applicable law relating to the protection of trade secrets” {§248(b)(2)(E)(iii)} not the stronger protections provided for security measures afforded to facilities under other federal security rules like CFATS or MTSA.

This section includes language similar to that found in the §550 authorization for the CFATS program, stating that “the Director may not disapprove under this section any proposed security measures, or combination thereof, based on the presence or absence of any particular security measure if the proposed security measures, or combination thereof, satisfy the security performance requirements established by the Director” {§248(b)(4)(C)(i)}.

As we have seen during the implementation of the CFATS process, this complicates the regulatory process, but does provide the maximum flexibility for owners/operators to design their security processes. The drafters of this legislation have attempted to decrease those potential complications by specifically allowing the Director to ‘recommend’ (but not require) specific security measures “that will satisfy the security performance requirements established by the Director” {§248(b)(4)(C)(ii)}.

International Cooperation

There is an interesting component of this section that I have never seen before. Section 248(b)(3) provides authority for the Director to inform the owner/operator of facilities outside of the United States of cyber risks to those facilities as long as the ‘disruption’ of the facility “could result in national or regional catastrophic damage in the United States” {§248(b)(3)(i)}. The awkwardly worded paragraph also allows the Director to make such a notification to the foreign government involved.

Surprisingly this is the only portion of §248 that specifically refers to ‘information infrastructure’ so it would not apply to industrial control systems outside of the United States.

Wednesday, February 23, 2011

S 413 - Coverage of Industrial Control Systems

As I mentioned in Monday’s blog, while most of S 413 refers to ‘information systems’ in the federal government, there is a section of the bill that looks like it may provide authority for DHS to regulate the security of industrial control systems in critical infrastructure facilities. Section 248(b)(1) requires the Director of the National Center for Cybersecurity and Communications (NCCC) to “issue interim final regulations establishing risk-based security performance requirements to secure covered critical infrastructure [emphasis added] against cyber risks through the adoption of security measures that satisfy the security performance requirements identified by the Director”

Covered Facilities

The whole issue of what facilities would be covered hinges on a complex set of rules set forth later in the proposed legislation. The definition of ‘covered critical infrastructure’ is found in § 241(4); “the term ‘covered critical infrastructure’ means a system or asset identified by the Secretary as covered critical infrastructure under section 254”.

To find §254 you have to go way back to Title V of the bill (pg 210). There you find three requirements that must be met for the Secretary to declare that the ‘system or asset’ is covered critical infrastructure. The first of these is that “the destruction or the disruption of the reliable operation of the system or asset would cause national or regional catastrophic effects identified under section 210E(a)(2)(B)(iii)” {§254(a)(2)(A)(i)}. That section is also added by this new bill and includes mass casualty events, severe economic consequences, and mass evacuations. We can easily see where industrial facilities might be included in these requirements, particularly some (though certainly not all) high-risk chemical facilities.

The second requirement is that “the system or asset is on the prioritized critical infrastructure list established by the Secretary under section 210E(a)(2)” {§254(a)(2)(A)(ii)}. That list is not generally available to the public, but we can assume that many of the facilities that would be included in the first requirement would also make placement on this list.

The final requirement is that the system or asset is either a component of the ‘national information infrastructure, or it relies upon that infrastructure for its ‘reliable operation’. Industrial control systems are not generally part of the ‘national information infrastructure’ (we hope) so the inclusion of an industrial control system under the coverage of this regulations required by this bill will hinge on the definition of ‘reliable operation’ which is not outlined in this bill.

Some assets like the electric grid or various pipeline systems that rely on internet communications or even telephone systems to coordinate the operations of its various components will certainly fall under the regulations required to be developed by this bill. Chemical facilities that rely on the inbound or outbound movement of chemicals via pipelines will also certainly be included.

Depending on how expansive a definition of ‘reliable operation’ the Secretary employs will determine how many other high-risk chemical facilities would be included under the cyber security regulations. Would, for example, facilities that rely on natural gas as an energy source be covered? Would the use of off-site electricity be sufficient? A positive answer to either would greatly expand the potential coverage of these regulations.

It might be interesting for Congress to consider more clearly defining what industrial control systems might be covered. As a suggestion, they might clearly state that CFATS covered facilities with release chemicals of interest as the primary source of their CFATS coverage would be included in the NCCC regulations.

Dual Regulatory Coverage

It would be hard to see how these regulations could made to apply to the control systems at all high-risk chemical facilities. Certainly none of the facilities covered under CFATS solely based upon the presence of theft/diversion COI could be included under the mass casualty provisions. So we would expect that if this bill passes that there will be at least two different types of CFATS covered facilities, those that are covered under the new cyber security regulations and those that are not.

It would be nice to see a requirement in this bill that would require the National Center for Cybersecurity and Communications (NCCC) and ISCD to coordinate their regulations of these facilities. I think it would be appropriate for the bill to specify that such dual coverage facilities would be exempt from or considered to have fulfilled the CFATS cyber security requirements under RBPS #8. One would assume that the cyber security experts at NCCC would provide more effective regulatory coverage of cyber security requirements than the limited expertise available to ISCD.

Similarly, facilities covered under MTSA that would also fall under these new regulations (many of the covered hazmat pipelines have port terminals) should have the relationship between MTSA and the NCCC regulations more clearly defined in this bill.

Another alternative would be a specific requirement that ISCD and the Coast Guard would be required to incorporate the cyber security rules developed by NCCC for control systems into their regulations for high-risk chemical facilities or MTSA covered facilities. Unfortunately, they would not be expected to have the personnel with the expertise to enforce such regulations.

Monday, February 21, 2011

S 413 Introduced – Cyber Security

Last Thursday Senators Lieberman (D, CT), Collins (R, ME) and Carper (D, DE) introduced S 413, the Cybersecurity and Internet Freedom Act of 2011. This bill would establish the Office of Cyberspace Policy (OCP) in the White House and the National Center for Cybersecurity and Communications (NCCC) in DHS. The OCP Director would have cyber security budget approval authority and the NCCC Director would have regulatory authority over cybersecurity activities within the Federal Government.

While this bill is mainly directed at “information infrastructure” there is one section in Title II that addresses cyber risks to covered critical infrastructure (§248) that very carefully never specifically limits its application to ‘information’ systems. That section requires the Director of the NCCC to “issue interim final regulations establishing risk-based security performance requirements to secure covered critical infrastructure against cyber risks through the adoption of security measures that satisfy the security performance requirements identified by the Director” {§248(b)(1)} within 270 days of passage of this bill.

Generally speaking the wording of this section looks like the crafters intend for establishment of a regulatory scheme similar in construction and operation to the CFATS regulations for high-risk chemical facilities. This nine page section of the bill certainly deserves a more detailed look in future blogs.

According to a press release on the Homeland Security and Governmental Affairs Committee web site, there “is no so-called ‘kill switch’ in our legislation because the very notion is antithetical to our goal of providing precise and targeted authorities to the President”. In fact, §2(c) specifically says that under this legislation “neither the President, the Director of the National Center for Cybersecurity and Communications, or any officer or employee of the United States Government shall have the authority to shut down the Internet”. This kill-switch issue stalled the earlier version of this bill in the last session. Hopefully this bill will now have a chance to move forward in the legislative process.

BTW: The official GPO version of this bill is not yet available. Sen. Lieberman has made a copy of the bill available via a link on the Senate Homeland Security Committee web site.
 
/* Use this with templates/template-twocol.html */