Showing posts with label Smart Cities. Show all posts
Showing posts with label Smart Cities. Show all posts

Wednesday, July 7, 2021

Review - HR 3386 Introduced - Smart Cities and Communities Act

Back in May Rep DelBene introduced HR 3386, the Smart Cities and Communities Act of 2021. The bill enhances the Federal Government coordination and outreach with respect to smart city or community technologies. It includes the formation of a federal cybersecurity working group and five cybersecurity ‘in passing’ mentions in four sections of the bill.

Section 202 requires the Department of Commerce to “convene a multistakeholder working group, to be known as the “Cybersecurity Working Group”, to develop tools for communities to use to evaluate the cybersecurity of smart city or community technologies.” The DOC will consider appointing individuals to the Working Group including:

• Representatives of consumer groups and civil liberties organizations,

• Representatives of small units of local government, as determined by the Secretary,

• Representatives of large units of local government, as determined by the Secretary,

• Manufacturers of smart city or community devices, equipment, and software,

• Individuals with expertise in communications networks,

• Federal, State, and local law enforcement officials,

• Individuals with other expertise necessary to carry out the duties of the Working Group, and

• Such representatives of the Council as the Secretary determines to be appropriate.

The Working Group will:

• Leverage and build on previous activities carried out by the Department of Commerce relating to Internet of Things (IoT) technology,

• Develop tools for communities to evaluate the cybersecurity of smart city or community technology being considered by the communities for adoption in those communities,

• Develop tools for communities to protect against cybersecurity threats relevant to the technology the community has chosen to adopt, and

• Submit to the Council a report that describes the findings of the Working Group.

Additionally, the Working Group will assess whether IoT cybersecurity standards should exist and if they should be voluntary or mandatory.

Moving Forward

While DelBene is not a member of the House Energy and Commerce Committee, the lead committee of the three committees to which this bill was assigned for consideration, one of her two cosponsors {Rep Clarke (D,NY)} is a member, so it is possible that this bill could be considered in Committee. I do not see anything in the bill that should engender any organized opposition to the bill. If it is considered in Committee, I would expect to see at least some level of bipartisan support for the bill.

The stronger the bipartisan support for this bill the more likely it will be to be considered on the floor of the House under the suspension of the rules process. If there is not strong bipartisan support, I do not see the Leadership brining the bill to the floor.

For a more detailed review of the bills provisions, including looking at each of the ‘cybersecurity in passing’ mentions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3386-introduced - subscription required.

Thursday, November 2, 2017

HR 4151 Introduced – STREET Act

Last week Rep. Comstock (R,VA) introduced HR 4151, the Smart Technology for Resilient, Efficient, Economic and Reliable Transportation in Cities and Communities (STREET) Act. The bill is designed to to promote smart technologies and systems to reduce transportation costs, traffic congestion, air pollution, energy use, and carbon emissions for communities of all sizes.

Definitions


Section 2 of the bill provides a number of lengthy definitions of the terms used in the bill. There are no specific cybersecurity definitions, but the terms ‘secure’ and ‘cybersecurity’ are used in the definition of ‘Smart System or Community’ in §2(7). It includes as a characteristic of a smart system or community the integration of measures “to enhance the resilience of civic systems against cybersecurity threats and physical and social vulnerabilities and breaches” {§2(7)(B)(v)(I)}.

Resource Guide


The Department of Energy (in coordination with the departments of Transportation, Housing and Urban Development, and the National Science Foundation) is required in §4 to publish on-line “a resource guide designed to assist States, communities, and cities in developing and implementing smart city or community programs” {§4(a)(1)}. The guide is permitted to include “voluntary, industry-led, international consensus standards and best practices, in collaboration with the National Institute of Standards and Technology, for safeguarding cybersecurity and appropriate data management and data privacy” {§4(b)(3)(C)}.

Grant Program


Section 5 of the bill would require DOT to establish another round to the Smart Cities Challenge “provide grants on a competitive basis to small- and medium-sized communities to implement smart transportation proposals” {§5(a)}. The grants would range between $20 million and $40 million and $100 million would be authorized for the grant program in each fiscal year between 2018 and 2022.

Moving Forward


Both Comstock and her cosponsor, Rep. Etsy (D,CT), are members of both the House Transportation and Infrastructure Committee and the Science, Space, and Technology Committee, the two committees  to which the bill was assigned for consideration. The bipartisan sponsorship increases the likelihood that the bill could be considered by the two committees.

The only portion of the bill that could raise significant opposition to its consideration is the inclusion of authorization for the grant program. As with any new money authorization, the money would have to come from some other program, probably within the Transportation Department.

Commentary


While there are no specific cybersecurity definitions within this bill (or references to existing cybersecurity definitions) there are numerous references to ‘information’ and ‘privacy’ and no references to control systems or vehicle operations. This would certainly lead one to conclude that this is an IT-centric bill if not actually limited to IT systems.

The bill should have included a definition of the term cybersecurity since the term is used in multiple places in the bill. Because of the rising importance of operations in smart technology the drafters would have been ill advised to use an IT-limited definition like that found in 6 USC 148.

In an earlier blog post I provided a definition of ‘cybersecurity risk’ after providing supporting definitions of ‘information system’ and ‘control system’. Using the same supporting definitions I would like to provide a legislative definition of ‘cybersecurity’:


The term cybersecurity means a set of actions, procedures or processes under taken to protect information systems or control systems from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information, information systems, or control systems, including such related consequences caused by an act of terrorism.

Tuesday, August 4, 2015

ICS-CERT Publishes GE Update and New Cybersecurity Report

This afternoon the DHS ICS-CERT published an update of an advisory on GE multilink switches and a new report on cyber-physical security issues from the DHS Office of Cyber and Infrastructure Analysis (DHS/OCIA).

GE Update

This update adds a third vulnerability to the two previously described.

● Resource consumption vulnerability - CVE-2014-5418; and
● Hard-coded key - CVE-2014-5419
● Cross-site scripting - CVE-2015-3976 (NEW)

Normally, I would have expected ICS-CERT to issue a new advisory for this vulnerability. Apparently, however, the firmware update that is now available fixes all three vulnerabilities so doing this as an update makes a certain amount of sense.

The new version of the advisory did, unfortunately (IMO) remove the mitigation measure from the previous version. It still remains useful for users that for some reason do not want to do a firmware update at this time. Fortunately it still remains (in somewhat more detail than previously supplied by ICS-CERT) in the GE Product Bulletin.

NOTE: ICS-CERT is still not listing these updates on their landing page. Fortunately they are tweeting about these updates as they are released. I suppose it could be a subtle ploy to get people to follow them on TWITTER® (@ICS-CERT). If so, it should be encouraged.

Smart Cities Report

This report from DHS/OCIA looks at some of the potential security risks associated with the increasing automation and interconnection of public services. I have not had time to do much more than peruse the Executive Summary, but it looks like there may be some interesting insights included in this report.

This is not an exhaustive look at all of the possible combinations of public services that are being linked into the internet of things under the rubric of Smart Cities. The graphic below (from page 3) shows the technologies upon which the report will focus.

Scope of Cyber-Physical Infrastructure Risk Report


I will probably have a more detailed look at this report in future blog posts.
 
/* Use this with templates/template-twocol.html */