Showing posts with label Supply Chain Security. Show all posts
Showing posts with label Supply Chain Security. Show all posts

Saturday, March 9, 2024

FAR sends Supply Chain Software Security NPRM to OMB

On Thursday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from FAR on “Federal Acquisition Regulation (FAR); FAR Case 2023-002, Supply Chain Software Security”. 

According to the Fall 2023 Unified Agenda entry for this rulemaking:

“This rule will require suppliers of software available for purchase by Federal agencies to comply with, and attest to complying with, applicable secure software development practices.  This rule is being issued in accordance with section 4(n) and 4(k) of the Executive Order 14028 titled "Improving the Nation's Cybersecurity” and Office of Management and Budget Memorandum 22-18 and 23-16.”

Interesting to note that the UA entry ‘expected’ the NPRM to be published in December of 2023. It will almost certainly be another month or three before this rulemaking makes its way into the Federal Register.

Friday, March 1, 2024

Review - BIS Publishes Connected Vehicle Supply Chain Security ANPRM

Today, DOC’s Bureau of Industry and Security (BIS) published an advanced notice of proposed rulemaking (ANPRM) in the Federal Register (89 FR 15066-15072) on “Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles”. BIS is looking for public comments on the potential impacts of EO 13873, Securing the Information and Communications Technology and Services Supply Chain, on connected automotive vehicles.

Public Comments

The purpose of this ANPRM is to solicit a wide range of public input into the topics discussed above. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # BIS–2024–0005). Comments should be submitted by April 30th, 2024.

Commentary

While there is certainly some amount of justification at specifically looking at the vulnerabilities associated with devices and equipment manufactured by Chinese companies associated with ICTS, this should be viewed within the larger construct of vulnerabilities in ICTS in general. This is especially true since various Chinese government and governmentally influenced APT groups have shown a propensity and capability to compromise vulnerabilities in American and allied ICTS products. Targeting Chinese ICTS components cannot be viewed as a solution to the vulnerability of ICTS products, but only as a small part of the necessary efforts to secure those supply chains.

 

For more details about the provisions of this ANPRM, including a look at some of the questions for which BIS is seeking public comment, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bis-publishes-connected-vehicle-supply - subscription required.

Wednesday, November 23, 2022

DOC Submits Final Rule on ICT Supply Chain Security to OMB

Yesterday, OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the Department of Commerce on “Securing the Information and Communications Technology and Services Supply Chain; Connected Software Applications”. 

The Spring 2022 Unified Agenda listing for this rulemaking describes its purpose as:

“To implement Executive Order 14034, Protecting Americans’ Sensitive Data from Foreign Adversaries (EO 14034), the Department of Commerce is proposing to amend its Interim Final Rule on Securing the Information and Communications Technology and Services Supply Chain (Supply Chain IFR), that was published on January 19, 2021.  Specifically, this proposed rule would update the Supply Chain IFR to clarify that the term information and communications technology and services (ICTS) includes connected software applications. This update also would add the term connected software applications to the definition section of the Supply Chain IFR, as well as to the definition of ICTS and ICTS Transaction.  Additionally, this proposed rule would make other conforming changes to the Supply Chain IFR to explicitly state that ICTS Transactions include transactions that involve connected software applications.”

Saturday, March 26, 2022

CRS Reports – Cyber Supply Chain Risk Management

This week the Congressional Research Service (CRS) published a report on “Cyber Supply Chain Risk Management: An Introduction”. This is an overview type report without links or footnotes to the associated reference material.

The report does note that there are two different components to supply chain security for cyber related products. Traditional supply chain concerns relate to the uninterrupted access to products and services. That remains a concern when discussing supply chain for cyber products. An additional concern is that vendors (or actors making changes to products after manufacturing) could adulterate a cyber product with vulnerabilities that could pose a cyber threat to end users. This report does not discuss a third component to cyber supply chain risk, the existence of unrecognized vulnerabilities in third-party components of the products.

This report focuses on information technology and communications technology products, but the same supply chain risks exist in operational technology products.

The report closes with a discussion about potential items of interest to Congress:

• Clarity of Responsibility,

• Increased Awareness,

• Oversight,

• Prohibition on Specific Companies, and

• Single Evaluator

Friday, March 25, 2022

Review - HR 7138 Introduced – IoT Supply Chain Security

Last week, Rep Obernolte (R,CA) introduced HR 7138, the Protecting Against Compromised Internet of Things Technology Act. The bill would require the DOC’s Bureau of Industry and Security to submit (and periodically update) to the End-User Review Committee a list of foreign persons that “pose a threat to the security of supply chains of Internet of Things devices”.

Moving Forward

While Obernolte is not a member of either the House Foreign Affairs or Oversight and Reform Committee, the two committees to which this bill was assigned for consideration, his sole cosponsor {Rep Jacobs (D,CA)} is a member of the Foreign Affairs Committee. This means that there may be enough influence to see the bill considered in Committee. I see nothing in the bill that would engender any organized opposition. If the bill were introduced in Committee, I would expect that there would be significant revisions made to make the bill more effective (see ‘Commentary’), that could change the potential for support.

Commentary

This bill does not actually appear to accomplish anything. The definition of the term ‘covered foreign person’ limits the people that could be affected by suggested listing by BIS to overseas vendors of IoT devices. These are not typically the people that we are concerned with when it comes to endangering the security of IoT supply chains. If, for some reason, they do endanger that supply chain security, we prohibit people in this country from selling items to the affected vendors. Which means that the federal government is adversely impacting the supply chain of those IoT vendors, which further threatens the supply chain that started the whole thing into motion.

I do not see any simple fix for this problem without defining ‘security of supply chains’ and then describing what actions might endanger that security. I would like to suggest that the definition should specifically address software security requirements.

For more details about the provisions of the bill, see my article at CFSN Detailed Analysis - - subscription required.

Saturday, February 19, 2022

Review - NIST RFI to Support CSF – Supply Chain Security Integration

This Monday DOC’s National Institute of Science and Technology (NIST) is publishing (available on line today) in the Federal Register (87 FR 9579-9581) a request for information on “Evaluating and Improving NIST Cybersecurity Resources: The Cybersecurity Framework (CSF) and Cybersecurity Supply Chain Risk Management.” NIST is considering aligning the CSF and the National Initiative for Improving Cybersecurity in Supply Chains (NIICS). In this RFI, NIST is requesting information that will support the identification and prioritization of supply chain-related cybersecurity needs across sectors.

NIST is looking for comments in the following areas:

Use of the Cybersecurity Framework,

Relationship of the CSF to Other Risk Management Resources, and

Cybersecurity Supply Chain Risk Management

Comments Requested

NIST is soliciting comments on this RFI. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NIST-2022-0001). Comments should be submitted by April 25th, 2022.

Commentary

The CSF is a corporate level cyber risk management tool rather than a true cybersecurity tool. Its greatest strength has always been that NIST proactively works to keep it current and responsive to current needs. It has relied heavily on the input from the public and outside experts. This RFI continues that tradition.

 

For more details about this RFI, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-rfi-to-support-csf-supply-chain - subscription required.

Wednesday, January 12, 2022

S 2201 Passed in Senate – Supply Chain Security Training

Yesterday the Senate took up S 2201, the Supply Chain Security Training Act of 2021. The reported version of the bill was withdrawn and the Senate considered an amendment (SA 4899) in the form of a substitute. The amendment and the bill were adopted by unanimous consent without debate.

The substitute language in SA 4899 was nearly identical to the substitute language that was reported by the Senate Homeland Security and Governmental Affairs Committee. The only difference in the new language was the addition of the phrase “and the Director of the National Institute of Standards and Technology” at the end of §2(c)(2).

The bill now goes to the House for consideration. If/when the bill makes it to the floor for consideration it will likely be taken up under the suspension of the rules process. This would mean limited debate and the bill would require a supermajority to pass. Based upon the action in the Senate, I would suspect to see the bill receive substantial bipartisan support.

It is interesting to see that there is no definition of ‘supply chain security’ included in this bill. With both CISA and NIST referred to as coordination targets, I would suspect that the crafters were at least partially considering protecting hardware and software against unauthorized manipulation in transit between the manufacturer and the Federal user. It could also mean ensuring that there were backup suppliers vetted and approved in the event the primary provider is unable to keep supplies moving due to conditions (like Covid for example) beyond their immediate control.

Tuesday, November 16, 2021

OMB Approves Software Supply Chain NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs announced that it had approved a Department of Commerce (DOC) notice of proposed rulemaking (NPRM) on “Securing the Information and Communications Technology and Services Supply Chain; Connected Software Applications”. This rulemaking is not listed in the Spring 2021 Unified Agenda.

As I noted when this rulemaking was sent to OMB for review, I suspect that this is related to §4 of EO 14028. This will probably appear in the Federal Register within the next week so we will know for sure what it covers then.

Friday, October 8, 2021

DOC Sends Software Supply Chain NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the DOC concerning “Securing the Information and Communications Technology and Services Supply Chain; Connected Software Applications”. This rulemaking was not included in the Spring 2021 Unified Agenda.

While EO 14028, Improving the Nation's Cybersecurity, does not specifically task DOC with a requirement to publish a rule concerning supply chain security, §4 of the EO does provide DOC with a laundry list of software supply chain responsibilities. I suspect that this NPRM is a natural outgrowth of those taskings.

Tuesday, October 15, 2019

Committee Hearings – Week of 10-13-19


This week both the House and Senate will be in session. Spending bills are being worked on behind closed doors. We do have one cybersecurity related hearing and a markup hearing of the ARPA-E Reauthorization bill.

Supply Chain Security


On Wednesday the House Homeland Security Committee will hold a hearing on “Public-Private Initiatives to Secure the Supply Chain”. The witness list includes:

• Robert Kolasky, CISA;
• Robert Mayer, U.S. Telecom; and
• John Miller, Information and Technology Industry Council

Markup Hearing


On Thursday the House Science, Space and Technology Committee will hold a markup hearing on three bills; including HR 4091, the ARPA-E Reauthorization Act of 2019.

Wednesday, September 4, 2019

DOC Sends IT Supply Chain Security Rule to OMB


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an interim final rule (IFR) from the Department of Commerce on Securing the Information and Communications Technology and Services Supply Chain for review. This rulemaking was not listed in the 2019 Spring Unified Agenda.

With this rulemaking starting out as an IFR, it must be implementing a specific congressional mandate. I suspect that it deals with restrictions on the use of Chinese telecom equipment.

Wednesday, June 20, 2018

Bills Introduced – 06-19-18


Yesterday with both the House and Senate in session there were 36 bills introduced. Of those there are three that may be of specific interest to readers of this blog:

HR 6147 Making appropriations for the Department of the Interior, environment, and related agencies for the fiscal year ending September 30, 2019, and for other purposes. Rep. Calvert, Ken [R-CA-42] 

S 3085 A bill to establish a Federal Acquisition Security Council and to provide executive agencies with authorities relating to mitigating supply chain risks in the procurement of information technology, and for other purposes. Sen. McCaskill, Claire [D-MO]

S 3088 A bill to amend the Energy Policy Act of 2005 to require the Secretary of Energy to establish a program to prepare veterans for careers in the energy industry, including the solar, wind, cybersecurity, and other low-carbon emissions sectors or zero-emissions sectors of the energy industry, and for other purposes. Sen. Duckworth, Tammy [D-IL]

HR 6147 is one of those spending bills that I expect will not receive any additional coverage here, but you never can tell what may be slipped into the Committee Report.

I will be watching S 3085 for the definitions it uses. Hopefully, someone on the staff realizes that the Federal government is a consumer of control systems in various guises.

Depending on the definitions used here for ‘cybersecurity’ I may be watching S 3088 for its effects on cybersecurity manpower development.

Wednesday, May 25, 2016

Amendments to S 2943, FY 2017 NDAA – 05-24-16

This afternoon the Senate officially began consideration of S 2943, the FY 2017 National Defense Authorization Act with a cloture vote of 98 – 0. The amendment offering process began on Monday with 13 amendments offered. Yesterday there were an additional 59 amendments offered. To date only one of those amendments may be of specific interest to readers of this blog; relating to the supply chain security of critical telecommunications equipment, technologies, or services.

Supply Chain Security


Sen. Gardner (R,CO) proposed SA 4130 (pg S3118). It would add a new §1641, “Comptroller General of the United States report on department of defense critical telecommunications equipment or services obtained from suppliers closely linked to a leading cyber-threat actor.”

The amendment would require a report to Congress on any critical telecommunications equipment, technologies, or services obtained or used by the Department of Defense or its contractors or subcontractors that is {§1641(a)(1)}:

• Manufactured by a foreign supplier, or a contractor or subcontractor of such supplier, that is closely linked to a leading cyber-threat actor; or
• From an entity that incorporates or utilizes information technology manufactured by a foreign supplier, or a contractor or subcontractor of such supplier, that is closely linked to a leading cyber-threat actor.

Two key terms are defined in the amendment; ‘leading cyber-threat actor’ and ‘closely-linked’. The cyber-threat actor term is linked to the identification as a ‘leading threat actor in cyberspace’ in the “Worldwide Threat Assessment of the US Intelligence Community”, dated February 9, 2016. The term ‘closely-linked’ is used to describe a relationship between one of the identified cyber-threat actors and a foreign supplier, contractor or subcontractor. The term is used to describe that relationship when the supplier, contractor or subcontractor {§1641(c)(2)}:

• Has ties to the military forces of such actor;
• Has ties to the intelligence services of such actor;
• Is the beneficiary of significant low interest or no-interest loans, loan forgiveness, or other support of such actor; or
• Is incorporated or headquartered in the territory of such actor.

Moving Forward


Tomorrow we will start to get some idea of what amendments will be taken up during the consideration of S 2943 and we will continue to see amendments offered tomorrow and (probably) a week from Monday when the Senate comes back from their very extended Memorial day weekend.

The cloture vote today was a good sign that there is nothing fatal in the current language of S 2943. Whether or not that will remain the case as the amendment process moves forward remains to be seen.

Commentary


While the report requirement in Gardner’s amendment is technically targeted at all four countries (Russia, China, Iran and North Korea) listed in World Wide Threat Assessment (pg 3) it would seem to me that Gardner is really expecting the report to focus on China and its telecommunication industry. I think that anyone would have concerns about the potential problems of having communications equipment provided by companies with close ties to the Chinese government or (in particular) the Chinese Army.

This amendment may be exhibiting a tad bit more than a normal amount of paranoia when it includes any company that is incorporated or headquartered in the territory of one of the big four countries of cyber concern (again China is the obvious main target). While it may be hard to identify all of the companies that fall under the first three standards for ‘closely-linked’, the sweeping inclusion of all Chinese chip and equipment makers in the reporting requirements would seem to ensure that it would be extremely difficult to separate the wheat from the chaff in the resulting report.

And it may be my paranoia seeping through, but I am more than a little concerned that the report being required in the amendment is limited to just telecommunications equipment. The universe of electronic and cyber equipment that includes Chinese made chips and components is way larger than just telecommunications equipment. Since this is an amendment to the Defense authorization bill the report should be expanded to include all critical electronic or computer control systems used by DOD and its contractors.

The other thing that is missing from this amendment is any definition of the type of information to be included in the report. The proposed language specifies what types of equipment from what sources should be addressed in the report, but nothing more about the content of the report. For example, Gardner might have required the report to identify:

• What military end equipment or systems contained parts manufactured by a company that is closely-linked with a leading cyber-threat actor;
• Identify if there are other sources of supply of those parts;
• What methods were available to verify that parts from ‘closely-linked’ suppliers met all of the safety, security and quality requirements of the military; and
• What techniques are available to adequately isolate components manufactured by ‘closely-linked suppliers’ from post-installation communications with the military or intelligence agencies of the ‘leading cyber-threat actors’.

This amendment is unlikely to be modified by the current process for consideration of S 2943. To see the types of changes described above, I’m afraid that we would have to see a completely new amendment if my concerns are to be addressed; I’m not holding my breath.


BTW: A real odd amendment was offered yesterday, SA 4141 would add a new division to S 2943. It would add the FY 2017 spending for the State Department to the spending approved in the bill. The State Department and DOD have always had a more than little strained relationship because of their nearly opposite way of dealing with foreign adversaries. Pairing these two departments would be just a tiny bit ironic.

Monday, December 31, 2012

S 3454 Passes in House – Intel Authorization


This evening the House passed S 3454 in a bipartisan vote of 373 to 29. The Intelligence Authorization Act for FY 2013 contains a few cybersecurity provisions, one of which requires the Director of National Intelligence to report to Congress on the security implications of buying foreign made cyber-components that are manufactured by organizations that are part of, or closely linked with adversarial governments.

Saturday, December 29, 2012

S 3454 Passes in Senate


A little later than I predicted, but yesterday the Senate passed S 3454, the Intelligence Authorization Act for FY 2013. There was a short speech by Sen. Feinstein about the bill, but that was the limit of the debate. Also as predicted, there was no vote. The final version of the bill did contain the cyber supply-chain security provision I previously discussed.

Thursday, December 27, 2012

S 3454 Amendments – Intelligence Authorization Act


There is an interesting note on the House BillsThisWeek website about the possible consideration of S 3454, The Intelligence Authorization Act for FY 2013. Typically Senate bills are listed on this site only after they have passed in the Senate and are ready for consideration by the House. This bill, however, has not even begun consideration in the Senate, though it has been on the Senate Calendar since July. This is a high-profile authorization bill, so it may be brought up for consideration in the Senate today.

The other interesting thing about this notice is that the version of the bill is not the one introduced in the Senate by Sen. Feinstein (D,CA). It is instead an amendment in the nature of a substitute that has yet to be offered, officially, by Ms. Feinstein. There wasn’t anything in the original bill that really caught my attention, but that is not true of this substitute language.

Cyber Supply Chain Security


Section 503 of the proposed amendment addresses supply chain security measures for the “telecommunications networks of the United States”. It defines those networks as including{§503(c)}:

• Telephone systems;

• Internet systems;

• Fiber optic lines, including cable landings;

• Computer networks; and

• Smart grid technology under development by the Department of Energy.

The section requires the Director of National Intelligence (DNI) to produce a report within 90 days (awfully short reporting deadline if the research hasn’t already been done) that “identifies foreign suppliers of information technology (including equipment, software, and services) that are linked directly or indirectly to a foreign government” {§503(a)(1)}. It further defines those linkages as including:

• By ties to the military forces of a foreign government;

• By ties to the intelligence services of a foreign government; or

• By being the beneficiaries of significant low interest or no interest loans, loan forgiveness, or other support by a foreign government;

While this is almost certainly being targeted at various Chinese suppliers of cyber equipment and services, the final part of the definition could include any number of international suppliers depending on how sweeping the definition of  “other support” is employed by the DNI.

Most interestingly the report by the DNI is required to be unclassified {§503(b)} though classified annexes may be included. This almost insures that the report is intended to be publicly disclosed.

Moving Forward


It is entirely possible that the Senate could take up this bill today under a unanimous consent agreement and adopt the bill without discussion. The bill would then be taken up by the House if/when it meets in final session for the year under suspension of the rules with limited debate and no amendments. There is even the remote possibility that the bill could be considered without objection in a pro forma session of the House.

Tuesday, August 14, 2012

HR 6277 Introduced – Cyber Supply Chain Security


Back on August 2nd Rep. Slaughter (D,NY) introduced HR 6277, the Keep America Secure Act (Note: it was just published today by the GPO). The bill would protect national security by limiting the use of foreign produced electronic devices in purchases made by the US Government. One would like to assume that this is a supply chain security issue (as the term is used by the cybersecurity community) and not a simple attempt to protect some manufacturer in the Congresswoman’s District.

Prohibit Use of Foreign Electronic Components


The bill would require the Secretaries of Defense and Homeland Security to ensure that their respective Departments do not “purchase any equipment or military aircraft that contains electronic components that are not manufactured in the United States” {§2(a)}. The term ‘electronic components’ is given a very wide definition; it would include {§2(e)(1)}:

• Any integrated chip or sensing device;

• Communications systems and equipment;

• Search, navigation, and guidance systems and equipment; and

• Software associated with the items described

The only other area that would face similar restrictions would be the civil aviation sector. The FAA would be required to issue regulations that would require that “any passenger aircraft constructed after such date [one year after passage of this bill] and any replacement of electronic components on a passenger aircraft use electronic components (as defined in section 2(e)) manufactured in the United States” {§3}.

Interestingly, DHS and DOD have been provided an escape clause from their requirements if the Secretary determines that it would be “be inconsistent with the public interest or would result in unreasonable costs to the Department of Defense or the Department of Homeland Security” {§2(c)}. No such provision is made in the requirements for FAA regulations.

The Inevitable Study


The bill would require that DOD and DHS conduct a joint study into the “prevalence of counterfeit electronic components in the supply chains of the Department of Defense and the Department of Homeland Security and options for addressing the issue” {§2(d)(1)}.  Again, no such study is being required of the FAA.

The Joint report is required to be submitted to Congress within 12 months of the adoption of the legislation. No word on whether or not the report should be classified or not, so it almost certainly will be classified, probably without an unclassified version for public consumption.

Sensitive Electronic Components


There is an odd provision in this bill. It requires the establishment of a joint classification system by DOD and DHS to rank electronic components on “how sensitive the components, and the final products containing the components, are to national security” {§2(c)}. There is also, based upon that classification system, a definition of ‘sensitive electronic components’ that would describe those components that are “the most sensitive to national security” {§2(e)(2)}. This might prove interesting except that there is no other mention of ‘sensitive electronic components’ in the legislation.

Analysis


This is one of the oddest, most incomplete pieces of legislation that I have ever had the misfortune to read. There is no statement of findings or sense of Congress that describes the problem that Rep. Slaughter is trying to correct. While it is well understood in the cybersecurity community that the manufacture of electronic devices in adversarial countries leaves open the possibility of the insertion of back-doors, on-command defects, or cyber-espionage controls into the practically undecipherable electronic circuits of the devices, that potential problem goes well beyond DOD or DHS electronics.

Even if you were to concentrate on the protection of weapons systems, clearly a legitimate aim, why include DHS since it has no weapons systems (the Coast Guard systems would more properly come under their DOD mission)? And for heaven’s sakes, why burden the civil aviation system with this impossible ban? Even if we suspect that State sponsors of terrorism would engineer such systems to allow terrorist to gain control over an airliner (and the FAA portion of this rule goes far beyond just airliners), there are any number of industrial control systems that could be similarly engineered to create a much larger catastrophe than the downing of a couple of airliners.

Furthermore, this bill would be unenforceable. The international scope of the electronic engineering and manufacturing industry makes it virtually impossible for even DOD and DHS to come anywhere near implementing a realistic ban on foreign made electronic components and devices. Besides there are any number of international agreements where various components of weapons systems have been farmed out to companies in allied countries; NATO, Japan, and Taiwan just to mention a few.
This is just another example of how ‘easy’ it is for the technologically illiterate to solve problems involving electronic devices.

Wednesday, May 30, 2012

House Rules Committee Sets Rule for HR 5743


Yesterday I noted that the House Rules Committee would meet today to set up the rule for the consideration of HR 5743, the Intelligence Authorization Act for Fiscal Year 2013. I promised to look at the bill and the associated Committee Report for mentions of cybersecurity issues; and as I expected there were none; after all, most of the bill is classified. Fortunately, the nine amendments that have been cleared to be considered during the floor debate under a ‘structured rule’ are not classified, and two of them deal with cybersecurity.

Cleared Floor Amendments


Rep. Farr (D,CA) introduced an amendment that would add a rather short §306 to the bill. It would have no real force of law because it is a ‘sense of Congress’ resolution telling intelligence community leaders to “take into consideration foreign languages and cultures during the development by such element of the intelligence community of training, tools, and methodologies to protect the networks of the United States against cyber attacks and intrusions from foreign entities”. I’m not sure what the crafter of this bill intended to mean by the phrase ‘to take into consideration’. I am just as sure that it isn’t important in any case, it is after all just a ‘sense of Congress’ statement.

Rep. Myrick (R,NC) and Wolf (R,VA) introduce the last amendment that will be considered on the Floor for this bill. It required the Director of National Intelligence (DNI) to prepare a report to Congress on supply chain security issues related to foreign suppliers of “of information technology (including equipment, software, and services) that are linked directly or indirectly to a foreign government” {§502(a)(1)}. The DNI is required to assess the “vulnerability to malicious activity, including cyber crime or espionage, of the telecommunications networks of the United States due to the presence of technology produced by suppliers identified” {§502(a)(2)}. If the ‘linked directly or indirectly to a foreign government’ didn’t make the scope of this report large enough, the definition of ‘telecommunications networks’ solved the problem; it includes:

• Telephone systems;

• Internet systems;

• Fiber optic lines, including cable landings;

• Computer networks; and

• Smart grid technology

Nothing about the kitchen sink though.

Passed Over Amendments


There were three more cybersecurity related amendments offered to the Rules Committee that did not make the cut for being allowed to reach the Floor during the debate later this week. Those amendments included requirements for:

• A threat assessment for cyber threats to critical infrastructure; Clarke (D,NY);

• Each agency that deals with classified documents to report back in 1 year potential security risks associated with the acquisition of computer hardware; Cuellar (D,TX); and

• The Civil Liberties Protection Officer to review on an ongoing basis, and prepare, as necessary, privacy impact assessments on, the cybersecurity policies, programs, and activities of the Intelligence Community; Hahn (D,CA).

It is interesting that two different amendments would address the supply chain security issue.

Oh, and special kudos to Ms. Clarke. She has tried to get this amendment made to every bill that looked like it might relate to cybersecurity, both in Committee and on the floor. Readers of this blog will know that I am not a big fan of reports to Congress, but this one sure seems legitimate to me. Keep plugging Congresswoman Clarke.

Moving Forward


According to the Majority Leader’s web site this bill will come to the floor tomorrow afternoon with work carrying on until it concludes sometime tomorrow night.

Wednesday, March 28, 2012

Supply Chain Security

I mentioned in a blog post this weekend that HR 4251 addressed supply chain security issues and noted that what it looked at was very different from what the cyber security community was concerned about when it talks about ‘supply chain security’. With that in mind I read an interesting article over on NextGov.com about cyber supply-chain security concerns in the Federal government that is well worth looking at.

The Threats


The article is based, in large part, on information provided by a recent GAO report on IT Supply Chain security. That report lists the following threats to the IT Supply Chain (pg12, 16 Adobe):

• Installation of hardware or software containing malicious logic;

• Installation of counterfeit hardware or software;

• Failure or disruption in the production or distribution of critical products;

• Reliance on a malicious or unqualified service provider for the performance of technical services; and

• Installation of hardware or software that contains unintentional vulnerabilities.

While the next couple of pages in the report discuss each of these threats in some detail, nowhere does it mention control systems. This is not terribly surprising since most of the Federal government does not make anything, so non-military control systems are few and far between. Even so a quick look at the descriptions by someone with a control system background will see that there are potentially clear links between these types of threats and control systems.

The GAO report goes on to look at specific examples of cyber supply-chain vulnerabilities (pgs 16-17 Adobe 20-21). They include:

• Acquisition of information technology products or parts from independent distributors, brokers, or the gray market;

• Lack of adequate testing for software updates and patches;

• Incomplete information on IT [cyber] suppliers; and

• Use of supply chain delivery and storage mechanisms that are not secure.

Once again it is clear that these vulnerabilities would also apply to control systems applications.

Government Response


The GAO report looks at how well three ‘National Security-Related Agencies’ (Defense, Homeland Security, Energy and Justice) have addressed these supply chain security issues. They note that DOD has the most complete program in place, but even it has not yet developed outcome-based performance measures to track their performance. DOJ has identified protective measures, but has not yet put forth a plan for implementing those measures or developed a tracking system to gauge performance. According to the report DOE and DHS have not yet done even that much.

Private Sector Requirements


To date, Congress has completely ignored this issue whenever the subject of cybersecurity has come up. I have yet to see any significant mention of requiring the private sector to look at IT supply chain security issues in any of the cybersecurity bills introduced to date.

It is possible that DHS could require supply chain security issues to be addressed in cybersecurity plans required under HR 2102. It is unlikely, however, given the Department’s poor record on developing and implementing in-house plans for their IT resources.

One would like to think that responsible owners and operators of control systems would already have such measures in place, or were at least developing such measures. I would be surprised, however, if any but the largest organizations have even considered this issue in developing the minimalistic cybersecurity plans that actually exist. I would bet that the vast majority of control systems owners, most of which have no cybersecurity efforts to speak of anyway, have not even considered the threats listed above as part of their facility security plans.

We already have a large number of control system security issues that are going to have to be addressed. This is just one more that needs to be added to the list.

Wednesday, December 1, 2010

Cyber Supply Chain Security

More and more companies are taking a serious look at the security of the supply chain for the raw materials that they need for their production, insuring that the suppliers maintain quality standards, will reliably deliver those materials, and can be trusted to do what they say they are going to do. The same attention needs to be paid to the suppliers of cyber hardware, software and services that are becoming an increasingly critical resource for manufacturers.

An interesting article over at SCMagazineUS.com looks at the issue of cyber supply chain security. It looks at a recent survey of security professionals at a number of critical infrastructure organizations, looking at their security practices related to their cyber supply chain. The results of the survey are disturbing, a solid majority of the respondents report inadequate procedures and processes to review cyber supply chain security.

Supply Chain Security

As a long-time process chemist for a manufacturer of industrial chemicals, a large part of my job was to provide information to customers that was used to assure them that we were following the necessary procedures to provide them consistently high-quality product that met all specifications and was manufactured by agreed upon processes. It was not enough to demonstrate that shipped products passed specific testing requirements, but manufacturing processes, key reaction parameters, quality assurance testing procedures, facility quality, safety and security programs were increasingly being evaluated before establishing, and audited during, our supplier relationship.

All of this was done because these customers realized that the materials that we produced for them were an integral part of the products that they sold. They held us, as a supplier, to the same high standards that they held their own manufacturing people, because the consistency of our production was an integral key to the quality of their production.

It goes without saying that industrial control systems are also an integral part of the quality chemical production process in most chemical manufacturing facilities. If one thinks seriously about that, it follows that the processes that bring the components of those ICS systems to the facility floor are as important as the processes that bring raw materials to the same location. But, how many companies apply the same high standards to the suppliers of their ICS components as they do to their raw material suppliers.

Cyber Supply Chain Security

Actually, I think that it can be successfully argued that the supply chain for our ICS components, including hardware, software and technical support personnel, may be more important to our modern chemical production processes. Particularly as it is becoming more evident every day that flaws in those cyber systems provide an opportunity for outsiders to gain access to those systems. That access could allow them to steal process information, adversely affect product quality or profitability, even to shut down the facility.

Chemical professionals are becoming increasingly aware that subtle differences in the manufacturing process may be as important a measure of the quality of a manufactured chemical as the specification testing done on the product. A similar awareness is becoming increasingly a concern for cyber security professionals. Small changes in component design or fabrication, substitution of counterfeit materials, and programming flaws can all have an adverse impact on cyber security. Proper examination of the manufacturing and programming processes to ensure that they are protected against manipulation, by outsiders as well as corrupted insiders, will help to ensure that the equipment and software installed at the manufacturing facility presents the minimum exposure to outsider attack.

Since ICS suppliers are not completely vertically integrated in their design, manufacturing and software processes, part of the vetting process must be the assurance that the ICS supplier is requiring the same sort of examination of their component and software suppliers. A single component that allows an unauthorized person access to the system potentially compromises the entire ICS system. This can include access through deliberate back doors as well as via inadequately documented communications protocols or the use of default passwords.

Personnel Surety

Another potential cyber supply chain security hole is the outsiders we routinely allow to access our control system equipment. Most chemical manufacturing sites do not have the on-site expertise necessary to install, update and maintain the control system hardware and software components. Only the biggest chemical companies can have a large enough staff of process control professionals to handle these requirements. Most facilities will have to rely on equipment/software producers, 3rd party venders, or consultants to handle these responsibilities.

Cyber security professionals need to be concerned about allowing these outsiders unfettered access to their industrial control systems. The cyber supply chain review process for the organizations providing these services needs to include adequate assurances that the people sent to the facility have been rigorously vetted and adequately trained on cyber security techniques. And procedures need to be in-place to verify that the vetting is current, each time one of these outsiders enters the facility.

High-risk chemical facilities covered under the CFATS program are required to ensure that background investigations of all personnel with unaccompanied access to critical or restricted areas have been conducted. It can certainly be argued that a vendor representative sitting at an ICS control computer has unaccompanied access to that system unless closely watched by someone with a detailed and comprehensive knowledge of that system. Anyone with this kind of access, or even just physical access to an unprotected USB port on any device connected to the system, needs to be appropriately vetted.

ICS Cyber Security

All facilities using industrial control systems have a responsibility to the owners and customers to ensure that those systems are protected against attack. Intellectual property protection and protection against directed process upsets are clearly of importance to all organizations. This is part of the fiduciary responsibility and contractual obligations of facility management.

High-risk chemical companies have an even higher duty to protect their industrial control system against attack. They have the same responsibility to customers and owners, but they also have a responsibility to protect their neighbors and communities from the potential affects of a terrorist attack via those control systems. The control systems could conceivably be used to turn the chemicals stored, used or produced at the facility, in some cases the very facility, into a weapon of mass destruction.

Close attention needs to be paid to industrial control system security by all using organizations. This security awareness needs to be applied to the whole cyber security supply chain.
 
/* Use this with templates/template-twocol.html */