Showing posts with label SCADA. Show all posts
Showing posts with label SCADA. Show all posts

Saturday, March 11, 2017

HR 1335 Introduced – Communications Cybersecurity

Last week Rep. Clarke (D,NY) introduced HR 1335, the Cybersecurity Responsibility Act of 2017. The bill would require the FCC to issue rules providing cybersecurity requirements for communications networks.

Communications Security


Section 2 of the bill would require the FCC to “issue rules to secure communications networks through managing, assessing, and prioritizing cyber risks and actions to reduce such risks” {§2(a)}. It also requires that those rules would establish that communications networks would be considered critical infrastructure and that information submitted to the FCC and DHS about such networks would be protected as Critical Infrastructure Information.

The key term in this bill is ‘communication network’. The bill provides a broadly inclusive definition: “a network for the provision of wireline or mobile telephone service, Internet access service, radio or television broad casting, cable service, direct broadcast satellite service, or any other communications service” {§2(c)}.

Moving Forward


Clarke is a fairly senior member of the House Energy and Commerce Committee to which the bill was assigned for consideration. This means that she may have the influence necessary to have the bill be considered in Committee.

Since the bill, however, provides relatively broad regulatory powers to the FCC there will be a great deal of push back from industry. This means that there would be substantial Republican opposition to this bill. It is unlikely that there would be much support for moving this bill forward.

Commentary



The ‘any other communications service’ provisions of the communication network definition could provide FCC authority to regulate the communications networks associated with physically distributed control systems like SCADA networks. Initially, it would be unlikely that the FCC would exercise that sort of authority; developing regulations for more traditional communications networks would take up a great deal of time for the FCC.

Tuesday, March 2, 2010

ICSJWG Spring Agenda

The DHS CERT’s Industrial Control System Joint Working Group’s (ICSJWG) web page about their spring meeting now provides a link to a draft agenda for that meeting. Since it is prominently labeled draft, I would assume that there are still changes being planned, but it still looks like this meeting will provide a great deal of interesting information. It looks like there will be presentations from just about everybody of consequence in the ICS Cyber Security Community. The topics range from analysis of actual cyber security incidents, to defeating malicious code, to managing patch management. While there is not time to cover every possible topic, it looks like the organizers have done a good job at trying to accomplish just that.

The one topic that is missing that I am disappointed in is that there is no presentation on the implementation of the cyber security requirements for the chemical facility anti-terrorism standards (CFATS). As this program is just now hitting the actual enforcement stage of its implementation, I would have thought that some practical coverage of this program would be important for this group. Maybe it will show up in a later version of the agenda.

Friday, February 27, 2009

Control System Connections

A blog earlier this week over on ControlGlobal.com points out how hard it is for facilities to ensure that there control networks are not subject to off-site access. Joe Weiss reports on a Distributech webinar on the new Smart Grid technology to improve the reliability of the electrical grid. While the SCADA systems for the electrical grid are not the same as those for chemical manufacturing facilities, they do share the growing vulnerability of connections to systems outside of the facility gates. These outside connections allow for the potential attack on the control systems without physical penetration of the facility perimeter or insider complicity; obviously making them something to be avoided. Except that the latest technology discussed for addition to Smart Grid technology is the use of Blue tooth connections to elements system to allow for remote diagnostics. While this makes the control system tech’s job of system maintenance easier it also increases the ease of hacking the system to gain control. If this technology is being offered for electric control systems, the most closely regulated systems in the United States, it will not be long before it finds its way into SCADA systems at high-risk chemical facilities, increasing the risks there even more.
 
/* Use this with templates/template-twocol.html */