Showing posts with label S 734. Show all posts
Showing posts with label S 734. Show all posts

Sunday, June 16, 2019

Committee Amended and Adopted HR 1668 – IoT Cybersecurity


This week the House Oversight and Reform Committee adopted substitute language for HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019, by a voice vote. The new language was a complete re-write of the bill.

Changes in Definitions


In §2 of the bill there were significant changes in the definition provided. First the revised language added definitions for ‘Director of OMB’ and ‘Director of the Institute’ (NIST).

Next the definition of ‘covered device’ was substantially changed. The ‘connected to the internet’ and ‘computer processing capability’ portion of the original definition was kept (but reformatted), but the ‘is not a general-purpose computer’ exception portion of the definition was expanded and revised. The new language included a substantial revision of the ‘programmable logic controls’ language of the original bill to now read{§2(2)(C)(iv)}:

Programmable logic controller with an industrial control system specifically not designed for connection to the internet;

A new exception was also added to the definition{§2(2)(C)(v)}; ‘subcomponent of a device’. The new ‘covered device’ definition also removed provisions in the original bill that would have required OMB to establish a process for petitioning for a device to be specifically considered a ‘covered device’.

Finally, the freestanding definition of ‘security vulnerability’ was changed to an incorporation of the definition from 6 USC 1501. The earlier definition was essentially an expansion of the §1501 definition (it had added ‘firmware’ and ‘combination of 2 or more of these factors’), but the §1501 definition relies on the expanded definition of ‘information system’ that specifically includes control system language.

Security Standards


Section 3 of the original bill was spread out into two separate sections. The first would require the National Institute of Standards and Technology (NIST) to complete its current activities ‘regarding considerations for managing the security vulnerabilities of Internet of Things’ {§3} by December 31st, 2019. This is essentially the same language from §3(a)(1) of the original bill with a revision of the date (extended three months) to complete the actions.

The provisions of §3(b) in the original bill were expanded and modified in §4 of the revised language. First the requirement for NIST to establish ‘standards’ for use of internet of things devices by federal government was changed to establishing ‘guidelines’ which the OMB would later convert to ‘standards’.

The closing paragraph of §4 of the revised language requires that “the Federal Acquisition Regulation shall be revised to implement” the standards required to be set by OMB in §4(b). The simplified language in this new paragraph was designed to accomplish the requirement of §4(a) and (b) of the original language.

New Petition Requirement


The petition requirement that was removed from the definition of ‘covered device’ was moved to and expanded in §5 of the revised language. The new section would allow an ‘interested party’ to petition for a covered device to be exempt from the standards set in §4(b). The petitioner would have to establish that the procurement of the covered device {§5(b)(3)(A)}:

With limited data processing and software functionality would be unfeasible; or
That does not meet the standards promulgated by the Director of OMB under this Act is necessary for national security or for research purposes.

Coordinated Disclosure


Section 6 of the revised language is a substantial rewrite of §5 and §6 of the original bill. It would still require NIST to establish guidelines with respect to “reporting, coordinating, publishing, and receiving of information” {§6(a)(1)} security vulnerabilities of covered devices and the resolution of those vulnerabilities. The new language does add a requirement for ‘consultation’ with the DHS Cybersecurity and Infrastructure Security Agency (CISA) in the development of the guidelines.

Another important new addition to the guideline requirements is found in §6(b)(3); ensure such guidelines are consistent with the policies and procedures developed by CISA under 6 USC 659(m).

OMB would be required to convert the guidelines developed by NIST into standards to be used by government agencies using covered devices. This requirement specifically applies to including those standards in Federal Acquisition Regulations (FAR).

Section 7 of the bill requires all contractors to comply with the requirements of the standards developed by OMB. It would specifically require each agency Chief Information Officer to “determine if such offeror or contractor has complied with each standard promulgated under section 6(c) with respect to such covered device” {§7(a)(1)(A)}.

Moving Forward


Technically, the House Science, Space, and Technology Committee still needs to act on this bill. This could end up being something as simple as a letter from the Chair saying that he agrees with the changes being offered by the Oversight Committee. Or we could see a full committee markup of the bill.

In any case, this bill may actually see its way to the floor of the House. With the bipartisan support that the revised language received in Committee, it is likely that it would be considered under the suspension of the rules process and would probably pass with similar support.

Commentary


Well, Rep. Kelly (D,IL), or more probably her staff, tried to correct the problems with the definition of ‘covered device’ that I had previously identified in the Senate version of this bill (S 734). Unfortunately the changes made just confuse the issue more.

First, we have a measure of grammatical confusion. As written “programmable logic controller with an industrial control system specifically not designed for connection to the internet” would make it seem that an ‘industrial control system’ was part of a PLC instead of the other way around. Next, there is some subject confusion with the phrase ‘specifically not designed for connection to the internet’ (not to mention the awkward word order); does it refer to the PLC or the ICS. If we are to keep the intended (I think) concept here I would suggest the following revision of this language{§2(2)(C)(iv)}:

“programmable logic controller that is a component of an industrial control system which is specifically designed not to connect to the internet;”

There are still problems with this definition, mainly because it uses terms that are not further defined in the bill nor are they a part of general government usage. Does an ICS include building environmental systems or access control systems? Does the existence of a port designed to allow network connections to the device equate to ‘connect to the internet’ or must the device be physically (cable or WiFi or Bluetooth, or radio) attached to a network that connects to the internet?

If Congress does not specify in legislation than agencies like NIST and OMB get to make the decision. In many ways this can make for more agile regulation development. Unfortunately, it may leave the efficacy and the impact of the regulations to the whims of the regulators. In this case, an aggressive NIST or OMB staffer could decide that a close interpretation of the current exemption language would only apply to the PLC of a building environmental control system, but not the HMI used by the system or the sensors or actuators attached to the PLCs. Since those devices were equipped with ports that could allow internet connections, they would be included in the ‘covered device’ definition and would be regulated by the OMB standards. Or they could go the other way and decide that no one would intend to connect these devices to the internet (even though they had components that could allow such a connection) so they were not ‘covered devices’ and thus not regulated.

While I understand that congresscritters are not technically equipped to make many of these decisions, I am still uncomfortable in allowing the kind of regulatory leeway that I describe above to be exercised by nameless bureaucrats who may (NIST probably, OMB not so sure) a better technical background to make such decisions.

Sunday, April 21, 2019

HR 1668 Introduced – IoT Cybersecurity


Last month Rep. Kelly (D,IL) introduced HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019. This is a companion bill to S 734.

Kelly (and at least two other cosponsors) is a member of the House Oversight and Reform Committee, one of the two committees to which this bill was assigned for consideration. Rep. Foster (D,IL) is a member of the House Science, Space, and Technology Committee, the other Committee to which the bill was assigned. This means that there is a decent chance that this bill will be considered in these committees.

This bill is more likely to advance in the House than S 734 is to advance in the Senate. I suspect that there would be significant bipartisan support and the bill would be passed in the House under the suspension of the rules process.

Tuesday, March 26, 2019

S 734 Introduced – IOT Cybersecurity


Earlier this month Sen. Warner (D,VA) introduced S 734, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019. Warner introduced a similarly titled bill last session (S 1691), but this bill is a complete re-write of the earlier effort.

Definitions


While last session’s bill had a long series of complicated definitions, this new bill only defines three terms: ‘agency’, ‘covered device’ and ‘security vulnerability’. The ‘agency’ definition is a proforma, yet necessary definition that is of little real importance. The definition of ‘covered device’ is new to this bill and replaces the term ‘internet-connected device’ from the earlier bill. The new term is defined as a physical object that {§2(2)(A)}:

• Is capable of connecting to and is in regular connection with the Internet;
• Has computer processing capabilities that can collect, send, or receive data; and
Is not a general-purpose computing device, including personal computing systems, smart mobile communications devices, programmable logic controls, and mainframe computing systems.

Sharp-eyed readers will note that this definition was taken from an amendment to HR 5515 last session that was proposed by Sen. Gardner (R,CO); one of the cosponsors to this bill.

Interestingly the definition of a covered device goes on to provide a requirement that the Office of Management and Budget (OMB) establish a process by which interested parties can petition to have a “a device that is not described in subparagraph (A) to be considered a device that is not a covered device” {§2(2)(B)(i)}.

The term ‘security vulnerability is defined as “any attribute of hardware, firmware, software, or combination of 2 or more of these factors that could enable the compromise of the confidentiality, integrity, or availability of an information system or its information or physical devices to which it is connected” {§(2)(3)}.

NIST Requirements


Section 3 of the bill requires the National Institute of Standards and Technology (NIST) to complete current efforts “regarding considerations for managing Internet of Things cybersecurity risks” {§3(a)(1)} to be completed by September 30th, 2019. Those considerations are to include, at a minimum {§3(a)(2)}:

• Secure Development;
• Identity management;
• Patching; and
• Configuration management.

By March 1st, 2020, NIST would be required to “develop recommendations for the Federal Government on the appropriate use and management by the Federal Government of Internet of Things devices owned or controlled by the Federal Government, including minimum information security requirements” {§3(b)(1)}.

Finally, NIST would be required within 180 days of the passage of this bill to publish a draft report on “the increasing convergence of traditional Information Technology devices, networks, and systems with Internet of Things devices, networks and systems and Operational Technology devices, networks and systems, including considerations for managing cybersecurity risks associated with such trends” {§(3)(c)}

OMB Requirements


Section 4 of the bill outlines the requirements for OMB to address IoT cybersecurity in the Federal Acquisition Regulations (FAR). Within 180 days of NIST’s publication of recommendations on the use of IoT devices, the OMB would be required to “issue guidelines for each agency that are consistent with such recommendations” {§4(a)}. Those guidelines would have to be consistent with the information security requirements of 44 USC Chapter 35, Subchapter II.

OMB and NIST would also be required to undertake reviews of the recommendations and guidelines described in this bill every five years.

Coordinated Disclosure Policy


Section 5 of the bill would establish NIST as the organization responsible for establishing policies and procedures for “for the reporting, coordinating, publishing, and receiving of information about” {§5(a)} security vulnerabilities of covered devices and their resolution. Those policies and procedures would be aligned as much as practicable with ISO 29147 and ISO 30111.

Section 6 of the bill would require OMB to issue guidelines to federal agencies on how to comply with the processes established by NIST.

Moving Forward


While Warner is not on the Senate Homeland Security and Governmental Affairs Committee, the committee to which this bill was assigned for consideration, one of his three cosponsors, Sen. Hassan (D,NH) is. This means that it is reasonable to assume that the bill may received consideration in that Committee. The main holdup is that the Chair, Sen. Johnson (R,WI), has deep-seated concerns about adding anything smacking of regulations concerning cybersecurity. While this bill does not specifically call for cybersecurity regulations, the ‘policies, procedures and guidelines’ that vendors selling covered devices to the government would be required to follow have the same general impact as regulations.

I would not be surprised if this bill did not make it out of Committee. One way that Johnson could ensure this is that after a markup hearing was held, the Committee report on the bill could be delayed indefinitely.

Commentary


This new version of the IoT cybersecurity bill is much better written than the version introduced in the last session. The limitations on the definition of ‘covered device’ generally make a reasonable distinction between ‘internet connected devices’ and IoT. I do, however, still have some nits to pick on the details of how that limitation/distinction is made.

The sub-paragraph in question removes ‘general-purpose computing devices’ from consideration as ‘covered devices’. It then lists the following examples of those g-p devices:

• Personal computing systems;
• Smart mobile communications devices;
• Programmable logic controls; and
Mainframe computing systems

Since none of these exclusionary terms are defined in the bill, I would suspect that the staffers who crafted this bill wanted to provide NIST and OMB with significant latitude in what would be included in the exclusion from the definition of IoT. Generally speaking, that is a good thing. Having said that, I do have problems with the term ‘programmable logic controls’. First off, I need to get a tad bit anal retentive here; the term should be ‘programmable logic controllers’.

In a broader context, even that corrected term may be an unnecessarily restrictive substitute for the term ‘industrial control system’. While PLCs are certainly very common components of industrial control system, there are a large number of other components of those systems that are not generally considered IoT (or IIoT, industrial internet of things), but could not be reasonably included in the term PLC.

While I am a strong believer in cybersecurity in industrial control system, I do not think that this bill and its loose regulatory framework are the appropriate place to establish standards for ICS cybersecurity and particularly the internet connected devices associated with industrial control systems. With that in mind, I would propose that the term ‘industrial control system’ should be substituted for the term ‘programmable logic controls’ in the definition of ‘covered device’.

Tuesday, March 12, 2019

Bills Introduced – 03-12-19


Yesterday with both the House and Senate in session there were 33 bills introduced. Two of these will receive future mention in this blog:

HR 1668 To leverage Federal Government procurement power to encourage increased cybersecurity for Internet of Things devices, and for other purposes. Rep. Kelly, Robin L. [D-IL-2]

S 734 A bill to leverage Federal Government procurement power to encourage increased cybersecurity for Internet of Things devices, and for other purposes. Sen. Warner, Mark R. [D-VA]

These bills are probably companion bills according to an article published yesterday on TheHill.com. Similar sounding bills (see here for example) have been introduced in the last two sessions of Congress and they have all suffered from an overly broad definition of ‘internet connected device’ that left them essentially useless. It will be interesting to see if anything has changed.

 
/* Use this with templates/template-twocol.html */