Tuesday, February 23, 2016

HR 3584 Passes in House

This afternoon the House passed HR 3584, the Transportation Security Administration Reform and Improvement Act of 2015 by a voice vote. While 40 minutes was allocated for the debate of this bill, the House only needed 8 minutes. The bill will now move to the Senate.


While the bill has broad bipartisan support, it is not yet clear that the language in this bill will actually be considered in the Senate (though I suspect that it likely will be). We will have to see if the Senate Commerce, Science and Transportation Committee will have substitute language that they would rather see in the bill. The current House language, if it is considered, will likely be passed under unanimous consent procedures.

ISCD Updates a CVI FAQ Response

Today the folks at DHS Infrastructure Security Compliance Division (ISCD) updated one of the frequently asked question (FAQ) responses on the CFATS Knowledge Center web site. It was a relatively minor change to the response to FAQ #516 dealing with the on-line training program for the Chemical-terrorism Vulnerability Information (CVI) program.

The latest revision to that FAQ response in December failed to include the “https:” in the description of the link to the CVI training web site. The older link worked perfectly well, but without the “https:” the reader did not know to expect that it was a secure website. Neither link accurately reflects the actual destination of the link which is https://csat.dhs.gov/dana/home/index.cgi.

BTW: While this change is relatively minor it does continue an apparent change in policy on the CFATS Knowledge Center of not announcing changes or additions to FAQs. This has apparently been in effect since December.

CG Notice Withdraws Frack Water Barge Shipment Policy Letter

Today the Coast Guard published a notice in the Federal Register (81 FR 8976-8978) withdrawing its proposed policy letter concerning the carriage of shale gas extraction waste water (SGEWW) in bulk via barge that was published in October of 2013. The Coast Guard will continue to approve such shipments on a case by case basis.

The Coast Guard regulations for transporting hazardous bulk liquid cargoes by barges are covered under 46 CFR Parts 151 and 153. SGEWW is not one of the listed products in §151.05 so any shipments of that material are required (§151.05-15) to obtain specific permission from the Commandant before it can be shipped by barge. The proposed policy letter would have set forth a standard procedure for requesting that approval.

The only reason given for the withdrawal of the proposed policy letter is that the low number of requests for approval to-date indicate a relative lack of interest on the part of the industry. The notice indicates that the Coast Guard will continue to collect information from the requests it has/will receive and re-evaluate the need for guidance documents or additional regulation at some future date.

Commentary

There is a discussion in the notice about the comments that the CG did receive during the comment period for the original notice. Over 70,000 comments were received with more than 68,000 coming in an organized campaign of form letters. The Coast Guard noted that those form letters expressed opposition to the policy letter but failed to offer “input regarding the substance of transporting SGEWW in bulk as described in the policy. In short the campaign was targeted at opposing fracking (which is outside of the control or regulation of the Coast Guard) rather being concerned with the safe transportation of the SGEWW.

The people behind these types of response campaigns to regulatory issues know full well that failure to address the specific issues involved in the proposed regulations/guidance means that the responses will largely be ignored by the regulatory agency. This is especially true when the issues raised in the form letters are not under the control of the agency soliciting public input. All this means is that the organizing entity is not really trying to influence government policy but is simply trying to raise money to keep their organization funded by appearing to address the concerns of its constituents.


Now there is nothing inherently wrong with organizing a letter writing campaign. In fact, a smaller campaign with only 140 signatories did raise specific issues with the policy letter and suggested that a rulemaking process might be better suited to this situation. The CG disagreed with that final point, but did agree with other points raised in the letter and noted that they would take them into consideration during the on-going case-by-case approval process.

Monday, February 22, 2016

ICS-CERT Announces CSET v7.1

Today the DHS ICS-CERT published an announcement that they have released version 7.1 of their Cyber Security Evaluation Tool (CSET). This marks a change in that in recent years the new version updates have only been announced in the next ICS-CERT Monitor.

According to the release notes the new version of the CSET includes:

• NIST SP800-161 Supply Chain Risk Management Practices for Federal Information Systems and Organizations was added to CSET;
• NERC CIP compliance risk based priority list;
• Enhanced dashboard; 
• Requirements organized according to standard: eg NERC CIP, CFATS, etc (including standards numbering scheme);
• Custom parameter values; and
• Doubled number of network components for network diagrams

There is no indication whether or not the CSAT standards have been updated with the specific requirements from the Chemical Facility Anti-Terrorism Standards (CFATS) Expedited Approval Program. The EAP process specifies particular security controls instead of the more general Risk Based Performance Standards used for the majority of Site Security Plans.

It does not look like the CSET Fact Sheet was updated for the new version of CSET since the Standards list does not include the new SP800-161 and it includes an old-style (2014) DHS email address for CSET.

The CSET Downloading and Installing web page was, however, updated as you can clearly see where they changed the CSET_x.x.iso to CSET_7.1.iso. It would have helped, though, if they had removed the old instructions for the ‘x.x’ situation.

It does appear that the old options for either downloading the CSET or requesting a disc from ICS-CERT remain in effect. Organizations also still have the option of running the CSET evaluation themselves or requesting an ICS-CERT team to help them with the process.

Committee Hearings – Week of 02-21-16

The House and Senate are back in Washington this week from their President’s Day recess. The spending issue season has started with three big budget hearings (for readers of this blog) this week. We also have a pipeline safety and cybersecurity hearings on the agenda.

FY 2017 Budget

The budget hearing process started in the Senate a couple of weeks ago and it gets into high gear in the House this week. Budget hearings are big picture looks at what government spending will look like in FY 2017 so don’t look for much in the way of details. The spending hearing will come later this spring.

The big three budget hearings this week are being held by House Appropriations Committee subcommittees. They are:


Department of Homeland Security Budget – Wednesday;
Department of Transportation Budget – Wednesday; and
Department of Defense Budget - Thursday

Pipeline Safety

The Subcommittee on Railroads, Pipelines, and Hazardous Materials of the House Transportation and Infrastructure Committee will be holding a hearing on Thursday on the “Reauthorization of DOT’s Pipeline Safety Program”. This is the start of the reauthorization process for FY 2017. The witness list includes:

• Marie Therese Dominguez, Administrator, PHMSA;
• Andrew Black, Association of Oil Pipe Lines (AOPL)
• Donald Santa, Interstate Natural Gas Association of America (INGAA)
• Cheryl Campbell, XCEL Energy; on behalf of the American Gas Association
• Carl Weimer, Pipeline Safety Trust

The Committee web site includes links to two interesting hearing documents; a staff briefing on the hearing issues and a staff review of the status of requirements from the 2011 Pipeline Safety Act.

Cybersecurity

The Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies of the House Homeland Security Committee will be holding a hearing on Thursday on the "Emerging Cyber Threats to the United States". The witness list includes:

• Frank Cilluffo, Center for Cyber and Homeland Security;
• Jennifer Kolde, FireEye Threat Intelligence;
• Adam Bromwich, Security Technology and Response; and
• Isaac Porche, The RAND Corporation

On the Floor

There is one bill currently scheduled to come to the House floor this week that may be of specific interest to readers of this blog. On Tuesday HR 3584, the Transportation Security Administration Reform and Improvement Act of 2015, will be considered under suspension of the rules. This typically means that the Leadership expects that the bill will get broad bipartisan support. No amendments will be made under this provision.

The Senate does not provide a real schedule of what will be considered in the coming week, but there is an outside chance that an agreement to finish consideration of S 2012, the Energy Policy Modernization Act of 2015. Readers should remember that there was a lengthy amendment process (here, here and here) mostly completed on the bill, but it was being held-up over possible consideration of a variety of amendments on the Flint, MI water crisis.


Saturday, February 20, 2016

Responses to Latest CSF RFI – 02-20-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period was extended and will remain open until February 23rd, 2016. The previous posts in this series include:



This week there were 37 new responses to the RFI and most of them were dated on or before February 9th, the original comment cut-off date. This lag has been fairly normal for the NIST RFI’s and is certainly due to the fact that they have to hand process these comments from emails. If NIST stays in the comment reception process they really need to come up with an automated system for receiving/posting the comments.

Since the new comment deadline is this week I expect that I will be doing these posts for at least two more weekends.

The comments posted this week come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

A couple of commenters recommended that the CSF continue to be voluntary in response to this question.

One commenter noted that DOD, DHS and NSA are developing separate voluntary and mandatory guidelines and approaches which makes compliance more difficult. Another commenter suggested that the CSF be used to harmonize cybersecurity regulatory development. It was suggested by yet another commenter that policy makers should collaborate with federal agencies and the private sector to prevent duplication of regulatory processes and prevent conflict with superseding of regulatory requirements. One health care commenter called for more alignment within the federal government in applying risk management principles. Another commenter suggested that regulators use CSF reporting frameworks as part of their regulatory scheme.

Continued cooperation between standards setting organizations was also suggested. One commenter suggested that a public/private sector guidance body be established.

One commenter noted that the voluntary nature of the CSF implementation was beneficial because it allowed an organization to ignore, add or eliminate processes so that the CSF would be more applicable to the organization.

Another commenter noted that NIST should expand its development of CSF profiles for different regulatory regimes or that regulators could reference the CSF in their rules. One commenter noted that Sector Specific Agencies be required to develop CSF implementation guidelines. Another commenter suggested that the CSF be expanded to an international scope. Another commenter suggested that the CSF should be expanded to include more specific measurable/observable criteria to better support regulatory reporting.

One commenter suggested that continued private sector involvement in CSF updates would ensure that the CSF does not conflict with regulatory requirements.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

A number of commenters (8) recommended that the CSF should continue to be updated as existing standards are updated and new standards are published. One commenter noted, however, that updates should be limited to allow for adequate implementation experience to guide future updates; this was reinforced by other commenters.

One commenter specifically recommended that health care organizations take an active role in the update process. Another commenter suggested that outdated measures should be removed. A suggestion was made that NIST and industry should work together to develop industry specific implementation guidelines. Yet another commenter suggested that there should be more public safety input into the CSF development process. It was suggested that the CSF remain technology neutral.

An equipment vendor noted that supply chain security issues need to be addressed in the CSF. Another commenter suggested that the internet of things and bring your own device problems should be addressed in the CSF. Yet another commenter suggested that high level control areas for PKI security be included. A government agency suggested that future updates should reflect all stakeholder needs.

One commenter opposed regular updates to the CSF, noting that continuity was more important in the changing field of cybersecurity.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

A number of commenters (10) noted that the private sector should continue to provide input on CSF improvements.

One commenter noted that the private sector should be providing input to both NIST and standards setting organizations. Another commenter noted that multiple inter-sector dependencies need to be identified. One commenter maintained that private sector involvement leads to a sustainable program. Yet another suggested that the private sector should play a critical role in the CSF governance with another suggesting that the private sector should own the CSF and its governance.

One commenter suggested that private sector input be limited to anonymized input on implementation issues.

Commentary

A total of 53 responses were ultimately received by the end of the original comment period from a broad cross section of responders. This actually ended up being a pretty decent number of responses for this type of non-regulatory request for comments. I was disappointed in the relative lack of responses from security researchers as I know that a number were involved in the original process that led to the publication of the CSF; I expect, however, that they would again get involved in any change process.

Having said that, it should be noted that I did not submit any comments to this RFI. Since the questions were mainly targeted at organizations that had either used the CSF or specifically decided not to use the Framework, I didn’t think that my more philosophical comments would really be appropriate. And that may have been why we saw so few comments from individuals in response to the RFI.

I want to remind folks that the continuing analysis of the responses to the RFI that I have been doing has been limited to those responses that specifically (and clearly) addressed specific questions in the RFI. For the most part I ignored (and suspect that NIST will largely ignore) the more verbose and erudite commentaries on the CSF that were submitted by a large number of the commenters. NIST was looking for specific information and those commenters were not helpful in that regards.

A number of those non-responsive responses were more targeted at the next version of the CSF and may have been more appropriately saved for that process. There was at least one exception to this; the comments submitted by HITRUST both addressed the NIST RFI questions and provided some in depth suggestions for how the next version of the CSF should look. If you are really interested in the future of the CSF I suggest that you take a look at their lengthy commentary; I expect (and hope) that they will be actively involved in the CSF revision process.

Readers of this series of posts will realize that I am a big fan of the NIST attempts to get commenters to use the spread sheet format for submitting responses to the questions that they asked. This makes the compilation and analysis of those comments so much easier. I would like to suggest that NIST continue to work at the development of this process and include the development of a methodology of automating the reception of those spread sheets.


OMB should be actively working with NIST on developing this process of automating the collection and analysis of public comments. This would go a long way to making the regulatory process more effective and reduce the time necessary to complete the regulatory process.

Thursday, February 18, 2016

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system advisories for products from Harmon AMX and B+B SmartWorx. Note: In January Advantech acquired B+B SmartWorx for $99.85 million.

AMX Advisory

This advisory describes dual credential management vulnerabilities in a wide variety of Harman AMX multimedia devices. The advisory does not credit the research team (SEC Consult) that reported the vulnerabilities even though it was a coordinated disclosure. ICS-CERT notes that this had previously been publicly disclosed (for example see ars technica). AMX has produced patches or updates for some of the products covered and the remainder are in progress. SEC Consult was not provided an opportunity to verify the final fixes.

There are two separate vulnerabilities reported, but they apply to different lists of affected products. They are both listed as credential management vulnerabilities with separate CVE number: CVE-2015-8362 and CVE-2016-1984.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities with publicly available exploits to gain system access with elevated privileges.

There is an interesting blog post about these vulnerabilities from SEC Consult. Long live S.H.I.E.L.D.

BTW: Vulnerable devices are apparently used at the White House.

SmartWorx Advisory

This advisory describes an authentication bypass vulnerability in B+B SmartWorx VESP211 serial servers. The vulnerability was reported by Maxim Rupp. SmartWorx is still in the process of mitigating this vulnerability.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to perform administrative functions on the network without authentication.

Advantech recommends only deploying the affected devices behind a firewall while further mitigation measures are developed.


NOTE: The CVE number is a 2016 based number, ICS-CERT is reporting this without real mitigation in place and there are no publicly available exploits. Something odd is going on here. ICS-CERT usually holds off announcing a vulnerability until at least some mitigation measures are in place unless the vendor response is slow played. The CVE number would seem to indicate a recent report….
 
/* Use this with templates/template-twocol.html */