Saturday, July 20, 2013

Cybersecurity Framework Update 07-20-13

It is still too early to see anything concrete from NIST on last week’s 3rd Cybersecurity Workshop. The NIST Framework website does have some additional information available in the form of two of the slide presentations made at the workshop; the opening slide presentation outlines the Framework development process and the closing presentation outlining the next steps.

Framework Development Process

The opening presentation was used to provide the attendees with an overview of the workshop’s part in the framework development process and outline what they would be doing in their working groups. It describes the five functions (Know, Prevent, Detect, Respond, and Recover) that the framework will be based upon and how those will be broken down into categories and sub-categories. In turn those will be used to develop Framework Implementation Levels (FILs).

It looks like the FILs will be the point where actions will be taken and/or evaluated. There will be separate FILs for each role (for example Senior Executive, Business Process Manager and Operations Manager) and each function, category and sub-category. It looks like, even if these are written at a high-level of generality (as I expect they will to allow for the broadest application), this document will get really wordy.

Hierarchy of FILs

There is an interesting hierarchy to the level of complexity to these FILs. The presentation provides an example on slides 19 thru 21.

Under ‘KNOW’ there are a number of FILs for the Senior Executive. The first is “I understand the organizational components that need to be protected. I have provided resources to support corporate knowledge of risk management components such as vulnerabilities, threats, and risk assessment.”

Supporting that at the Business Process Manager Level are a number of categories with their own FILs. One category is ‘Asset Management’ with the first FIL being: “I understand the importance of asset management and assume responsibility for lifecycle accountability.”

Supporting that at the Operations Manager Level are a number of sub-categories for each category. For example, supporting the ‘Asset Management’ FIL is ‘Hardware/Software Inventory’. At this level there is an ‘Informative Reference’ listing (ISO/IEC 27001) with a FIL for “An ad hoc asset tracking process is in place”.

As would be expected there is more detail at the operational level, but (if the detail provided in this example is carried through in the actual Framework) the FILs at that level are still going to be written broadly enough so that they will be broadly applicable throughout critical infrastructure.

Of course, the more broadly written the FILs are the easier it will be for individual organizations to take window dressing actions to be able to say that they comply with the Framework.

Where We Are

The out-briefing presentation started out with a ‘What We Heard’ slide that provides a high-level view of some of the concerns that were expressed during the Workshop. Most of these are expressed on the ‘motherhood and apple’ pie level, but there is at least one fundamental disagreement underlined in the listing. Here is the list:

• The Framework must support the business
• The Framework must enable cost-effective implementation
• The Framework language and communication is critical to success
• The Framework must reflect characteristics of people, processes, and technologies
• The Framework must be inclusive of and not disruptive to those good practices in use today
• The Framework must include the fundamentals
• Determination of risk tolerance for critical infrastructure must be informed by national interests
• Threat information must inform Framework implementation

The first, second and seventh topics define the problem. Business will not spend more money on security measures than they think they can afford and that determination will be made on internal risk-benefit analysis. The whole point of the government getting involved is that there are potential national and societal costs associated with failures of cybersecurity at critical infrastructure. Since the owning organization will not pay these costs, they will not inform the risk-benefit analysis used to determine the appropriate level of cybersecurity spending. Without some mechanism for requiring organizations to internalize the outside costs of failure there is no way to ensure that an ‘adequate level’ of cybersecurity is sought, much less obtained by a realistic risk-benefit analysis.

Areas to Address

The second slide in the out-brief details area that yet need to be addressed in the Framework development process. Again, here is the list from the slide:

• Find the right level of specificity
• Threat informed
• Taxonomy for the Framework
• Identify cross-cutting categories
• Clarify the compendium of Informative References
• Integration of cyber risk into business risk
• Address IT and ICS considerations
• Framework Implementation
• Long term governance

Given my long time misgivings about the whether or not the Framework would explicitly address industrial control system issues and comments I’ve seen on Twitter during and after the 3rd Workshop last week, I am very happy to see the seventh bullet point; “Address IT and ICS consideration”. Still, with October quickly approaching it is disheartening to see this topic just now appearing in the considerations.

Moving Forward

The third slide in the out-briefing is title ‘Topic-Specific Working Sessions’. I think these are the proposed working sessions for the 4th Workshop to be held in Dallas, TX in September. Those working sessions would be:

• Engage senior executives and boards through effective communication of the value proposition of Framework adoption
• Provide guidance and resources to aid small business implementations Understand unique privacy and civil liberties needs for Critical Infrastructures
• Define awareness and training needs in context of Critical Infrastructure
• Increase international engagements
• Connect the Framework and the Performance Goals

If these are the working sessions for the 4th Workshop, then I’m again disappointed about the lack of specific attention to control systems. I understand the political importance of ‘privacy and civil liberties’, but the failure to address ICS issues will ensure that the most dangerous portions of the cyber-vulnerabilities will not be addressed by the Framework.

The final two slides in the out-brief outline what NIST will be doing leading up to the 4th Workshop to be held on September 11th – 13th (I like the unintended symbolism there) in Dallas. NIST needs to take the conflicting input received from the 3rd Workshop and use it to more fully populate the draft Framework. They plan to publish their draft of the Preliminary Framework sometime next month, probably towards the end of the month if past history is any guide.

NIST continues to solicit input on the Framework development and provide this email address (cyberframework@nist.gov) for communicating such information.


BTW: Since I now live just down the road a piece from Dallas, I am trying to get some sort of press credentials to allow me to observe at least part of the proceedings. If anyone can put in a good word for me with NIST I would appreciate it.

HR 2217 Reported in Senate – FY 2014 DHS Spending

Thursday the Senate Appropriations Committee adopted an amendment in the form of a substitute for HR 2014 and reported the bill favorably. Since an actual copy of the ‘amended’ bill is not yet available, it is difficult to determine all of the changes made to the bill. The Committee Report is available so there are a number of things that we can determine; for example the CFATS extension for 1-year remains in the bill but now as §535 instead of §532 as found in the House passed language.

CFATS

The CFATS program comes in for mention in a couple of places in the Report besides the afore mentioned program extension. This includes a discussion of coordination of federal chemical security efforts, ISCD funding, and CFATS implementation reporting.

The Committee Report talks about coordinating chemical security efforts in two separate places. On page 13 there is a general discussion where the Committee lauds the limited efforts to date by ISCD and the Coast Guard (and ignores the ISCD-NRC efforts) but notes that coordination with the TSA is lacking. They also suggest that “DHS should work in conjunction with the Office of Management and Budget to review and synchronize Federal entities involved in chemical security activities”. Presumably those other efforts would include EPA regulation of security of water treatment and waste water treatment facilities (including chemicals used therein) as well as PHMSA regulation of hazmat trucking security.

Then on page 100 in a general CFATS program discussion the lack of Top Screen submission by West Fertilizer is mentioned as demonstrating “the need for NPPD to have a more robust coordination effort to promote cooperation among industry and with other relevant Federal agencies in the chemical sector”. To help resolve this issue NPPD is required to “support the Chemical Sector Coordination Council in an effort to develop (and, of course, report to Congress on) recommendations to:

• Improve the coordination among Federal agencies;
• Streamline reporting requirements; and
• Improve the CFATS program to create efficiency and effectiveness.

The Committee Report sets the spending for Infrastructure Security Compliance (mainly CFATS program) at $ 85.6 million (pg 98; just below the $85.8 million requested by the President) compared to the House Committee’s Report $ 77.1 million (pg 82). And there is no mention of withholding funds in the Senate Report that we saw in the House Report.

There are, of course, the obligatory requirements for reporting to Congress. In addition to the reports mentioned above there is a requirement found on pages 100-101 for NPPD to report on the CFATS implementation process every six months (starting 90 days after this bill is adopted). The report would include:

• The number of: facilities covered:
• Inspectors;
• Completed inspections;
• Inspections completed by region;
• Pending inspections;
• Days inspections are overdue;
• Enforcements resulting from inspections; and
• Enforcements overdue for resolution

TWIC

There is only a brief mention of TWIC in the Report on page 71. It focuses on the TSA’s effort to implement §709 of the Coast Guard and Maritime Transportation Act of 2012 (PL 112-213) that required a one-visit process for issuing new TWICs. Another report to Congress is required; “on the plan and timeline for implementing section 709 and other plans to ease the burden on workers who must travel hundreds of miles at great personal expense to obtain a TWIC card”.

Chemical Defense Program
This relatively small ($0.8 million) program run out of the Office of Health Affairs is tasked with developing a comprehensive chemical defense framework. The Report notes (pg 108) that the “Committee believes all high-risk situations [emphasis added] should be considered for study to ensure useful information is made available on mitigation and response measures”; a pretty big order for such small funding. Another report (due August 2nd) is required “on the timeframe to finalize the awards and the risk factors that will be considered in awarding demonstration projects”.

Cybersecurity

In the NPPD section of the report (pgs 101 and 102) the cybersecurity discussion is mainly about support for the security of federal computer systems and networks. The report does discuss the President’s decreased spending request for cyber-workforce training and asks that the program be fully funded in the President’s FY 2015 request.

There is an interesting demand for a briefing from NPPD and FEMA on “the likely physical and psychological consequences of a cyber attack, including the potential magnitude of the effect; State, local, and tribal government preparedness and response coordination; and Federal coordination and readiness”. I would certainly like to hear that presentation.

There is a brief mention of the President’s cybersecurity Executive order on page 102. It focuses on the incentives that the Administration will be considering to gain voluntary compliance with the Cybersecurity Framework. It does little more, however, than note that it “expects the Administration to provide a comprehensive review of the incentives to Congress, the private sector, and the public for input as soon as practicable”.

Another part of the Committee Report discussion on cybersecurity is found on page 135 in the Science and Technology section and emphasizes ‘war gaming and cyber exercise programs’. In particular it mentions the continued development “of a simulation based cybersecurity exercise tool for the financial services sector and supports the further extension of the financial sector tool into other critical infrastructure sectors such as energy, the defense industrial base, transportation, and healthcare”.

The report does specifically mention control systems in the same discussion noting that the “The Committee recognizes the cyber threats to the Nation’s electric grid and the other control systems vital to our security and economy”. To address those threats the Committee directs S&T (in collaboration with NPPD) to establish ‘operational cybersecurity research initiatives’ that include the “conduct experiments both at the lab scale and at real-world scale using test bed applications to verify models using a large-scale operational environment”.

All of this will be accomplished on a S&T cybersecurity budget of $74.5 million.

Moving Forward

The bill is now ‘cleared’ for floor action in the Senate. I have not seen anything on when this will be scheduled for debate, but I suspect that we may see this process start later this week or next. I expect that it will be amended and approved by the Senate before the summer recess. The Conference may even be named before the recess so that work on the differences between the two bills can get started.


This is one spending bill that has a good chance of getting to the President before October 1st.

Friday, July 19, 2013

July 2013 CFATS Fact Sheet

This afternoon the CFATS folks posted the link to the latest updated monthly CFATS Fact Sheet on their web site. Most of the fact sheet is boilerplate, but the fact box on the right side of page shows the current CFATS statistics which is really what everyone is looking for. The table below shows the latest four months of data from the worksheet.


April 2013
May 2013
June 2013
July
2013
Facilities currently covered by CFATS
4382
4351
4331
4298
Removed, reduced or modified COI holdings
2900
3000
3000
3000
Facility Assistance Visits
1202
1242
1253
1264
SSP Authorized
280
380
469
536
SSP Approved
53
85
125
166

Continuing Progress – Program Data

The numbers show a continuing increase in the number of SSPs that have been authorized and approved. Unfortunately, the numbers seem to indicate that the authorization rate has declined while the approval rate has held steady. The May-June period showed 89 authorizations while the June-July period showed only 67. The same time periods for the approval data shows 40 and 41 approvals respectively.

The first half of July does provide some legitimate excuses for not completing as many site visits. The 4th of July holiday falling on a Thursday almost certainly means that two days were not available in that week for regulatory visits. The next week had an additional two days taken out of the middle by the Chemical Sector Security Summit; I would like to think that at least the Area Commanders were participating at that activity.

There is one area that shows a significant increased rate of change in the same period; the decrease in the number of facilities that are no longer covered by the CFATS program. The change in May-June was 20 and June-July showed 33 fewer. At least I am assuming that it is a good thing, representing conscious decisions by management to reduce or eliminate the chemicals of interest (COI) held on site. Of course, it could be a negative statistic if it were due chemical companies going out of business. Or it could be essentially a meaningless number if facilities were making changes like going from 20% ammonia solutions to 19% ammonia solutions to avoid CFATS coverage. I really suspect that it is some sort of blend of the three.

What’s in the Words

ISCD is not spending a lot of time in preparing the written portion of the Fact Sheet, nor would I if this were my document to produce. In fact, the only new information in this month’s Fact Sheet is:

“As part of its outreach effort, DHS participated in the annual Chemical Sector Security Summit in July 2013, where CFATS personnel participated in various sessions. The Summit engaged both the public and private sectors to share industry best practices, conduct informational discussions, solicit feedback, and provide stakeholders and regulators the opportunity to discuss innovative approaches to further collaborate on strengthening chemical safety and security.”

While it might have been nice to include more information about the CSSS this is just a one page document with a limited amount of space. The limit to that space can be seen in the fact that the final sentence of the Fact Sheet was truncated. It reads:

“If DHS makes a final determination that a facility is high-risk, the facility must submit a Site Security Plan for DHS approval or an Alternative Security Program that includes security measures to meet applicable risk-“

The missing end of the sentence should probably read: “based performance standards”

Where is it at


I knew where to find the updated fact sheet at because an official at DHS notified me of the location. Normally I check the DHS Critical Infrastructure – Chemical Security web site, but that still has the link to the June 2013 document. The other location where I have found these links before was on the CFATS Knowledge Center, but that still shows the link for the April fact sheet. Fortunately for readers of this blog, DHS told me where to find the current fact sheet.

Bills Introduced – 07-18-13

With just about two weeks left before the summer recess I am expecting to see a surge of bills introduced that congresscritters will want to brag about when they talk to various audiences back home. It looks like one of those bills was introduced yesterday along with another Senate spending bill.

S 1329 Latest Title: An original bill making appropriations for Departments of Commerce and Justice, and Science, and Related Agencies for the fiscal year ending September 30, 2014, and for other purposes. Sponsor: Sen Mikulski, Barbara A. (D,MD)

HR 2728 Latest Title: To recognize States' authority to regulate oil and gas operations and promote American energy security, development, and job creation. Sponsor: Rep Flores, Bill (R,TX)


I’m watching the spending bill for possible mention of NIST’s cybersecurity work, the Cybersecurity Framework in particular. I’m not sure that the content of the House bill will be something that I’m interested in, but it could cover safety or (less likely) security issues.

Thursday, July 18, 2013

PHMSA Issues LPG Advisory Bulletin

The Pipeline and Hazardous Material Safety Administration (PHMSA) published an advisory notice in today’s Federal Register (78 FR 42889-42890) reminding certain liquefied petroleum gas (LPG) facilities that, while they were responsible for following ANSI/NFPA standards 58 or 59, they were also responsible for conforming to specific provisions of 49 CFR Part 192.

PHMSA regulations (§192.11) provide that LPG facilities supplying gas to distribution pipelines must comply with both the ANSI/NFPA standards and the §192 requirements. Where they conflict the ANSI/NFPA standards prevail (§192.11(c)}. This notice serves to remind owners and operators that there is no ANSI/NFPA reference to the topics in the Part 192 sections listed below, so those requirements must be appropriately addressed.

• Inspection requirements for distribution mains (§192.305 and §192.307).
• Backfill requirements for installing pipe in a ditch (§192.319).
• Underground pipe clearance requirements (§192.325).Show citation box
• Valve requirements for service lines (§192.363 and §192.365).
• Continuing surveillance (§192.613).
• Public awareness (except for small LP-gas systems) (§192.614).
• Operator qualification (except for small utility LP-Gas systems) (Subpart N).
• Distribution Pipeline Integrity Management (Subpart P).


PHMSA continues to consider making changes to the primacy provisions of §192.11.

FRA and PHMSA to Host Joint Public Railroad HMR Meeting

The Federal Railroad Administration (FRA) and the Pipeline Hazardous Material Safety Administration (PHMSA) published a joint meeting announcement in today’s Federal Register (78 FR 42998) about a joint two-day public meeting on August 27-28, 2013 in Washington DC addressing the transportation of hazardous materials by rail. This is part of a joint comprehensive review of operational factors that affect the safety of the transportation of hazardous materials by rail.

Public input on this topic is being solicited by FRA and PHMSA. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # FRA-2013-0067). Personnel desiring to make oral comments during the meeting need to register at least four days in advance with Kurt Eichenlaub (Kurt.Eichenlaub@dot.gov). FRA will be making a teleconference line available, contact Mr. Eichenlaub for details. There is no mention of web casting this meeting.

A more detailed agenda should be available by July 28th on the meeting docket at www.Regulations.gov.

PHMSA Submits Rail Petition ANPRM to OMB

On Tuesday the Pipeline and Hazardous Material Safety Administration submitted an advance notice of proposed rulemaking (ANPRM) to the Office of Management and Budget (OBM) that would enhance safety and revise and clarify the HMR applicable to the transportation of hazardous materials by rail. This rulemaking is being initiated in response to petitions for rulemaking submitted by the regulated community and NTSB recommendations that are associated with the petitions.

According to the Abstract for this rulemaking in the Unified Agenda this rulemaking would:

• Identify elements of non-conformity that do not require a movement approval from the Federal Railroad Administration (FRA);
• Correct an unsafe condition associated with pressure relief valves (PRV) on rail cars transporting carbon dioxide, refrigerated liquid;
• Revise outdated regulations applicable to the repair and maintenance of DOT Specification 110, DOT Specification 106, and ICC 27 tank car tanks (ton tanks);
• Except ruptured discs from removal if the inspection itself damages, changes, or alters the intended operation of the device; and
• Enhance the standards for DOT Specification 111 tank cars used to transport Packing Group I and II hazardous materials.

Since this ANPRM is in response to industry petitions, the political pressure that might delay OMB consideration of this rulemaking is probably not present, so we may see approval of this ANPRM within a month or so.


In light of the recent crude oil train derailment, fires and explosion, it will be interesting to see exactly what changes are being considered for the standards for DOT Specification 111 tank cars.
 
/* Use this with templates/template-twocol.html */