Monday, June 13, 2016

S 3018 Response from Senator

Last week I encouraged folks to write their Senator in support of S 3018, the Securing Energy Infrastructure Act. This is a time honored technique that the average citizen can use to help influence the course of legislation in Washington. Unfortunately, it is also a disappointing way to learn how well your Senator’s staff reads and understands constituent communications.

Remember, unless you are a big donor, your Senator or Representative seldom actually sees your letter or email, it is typically read by a staffer who compiles statistics about how constituents feel on topics and selects an appropriate reply to that communication.

I received such a reply this morning from one of my Senators. It started off with the expected platitudes about being glad to hear from me and thanking me for sharing my concerns. Then it went into a canned response about the Senator’s support for a broad based energy security program based upon a “national energy policy to implement innovative solutions to increase electric generation and transmission, reduce gas prices”. Oops, they are talking about supply chain security and I was talking about cybersecurity.

Now one of two things was occurring there in the Washington office this morning. Either the staffer responsible for the reply did not know the difference between ‘supply chain security’ and ‘cybersecurity’, and/or the office does not have a canned response to cybersecurity and the staffer used the closest thing available. Both would be more than a little disturbing, but I would hope for the former, but knowing congresscritters I suspect that it is more likely that both would be true.

Now, does this mean that I think writing letters to your representatives in Washington is a waste of time? No, I would not have sent off my two letters if I felt that that was the case. Did I expect that my letter would have a major impact on the Senator? No, I’m not a major donor, nor do I have local political connections, so I doubt that the Senator actually sees my letter.

What I do expect, is that if the Senator is receiving multiple letters on this bill, when it comes up for consideration, the staff will tell the Senator that there is some level of constituent support for the bill and that will be taken into account when it comes time for a vote. If there is no opposition to the bill in the Senator’s office, that may be enough all by itself to get a positive vote. And if there is enough constituent support, some level of opposition can be overcome. If the Senator is against the bill, you don’t have much hope of changing that vote unless you get overwhelming constituent support or you make a real big campaign donation; and neither of those is absolutely sure of overcoming real opposition.


So, please, write your Senator and Representative, in support of S 3018 or any bill that you feel strongly about. You may not be able to influence their decision, but you certainly cannot if you do not write.

Saturday, June 11, 2016

NIST Framework Update – 06-09-16

This week the National Institute of Standards and Technology (NIST) published a document summarizing the results of the workshop that they held in April on the future of the Cybersecurity Framework (CSF). The document summarizes the views expressed by workshop participants and outlines the continuing steps that NIST intends to undertake in support of the CSF.

There were seven major topic areas covered in the document with two receiving detailed discussion. The seven topics were:

• Background;
• Cybersecurity Framework Use;
• Evolution and Maintenance;
• “Best Practice” Sharing;
• Roadmap for Improving Cybersecurity;
• Update; and
• Next Steps

The first area that included a more detailed discussion was the Roadmap. Topics discussed included:

• Authentication;
• Automated Indicator Sharing;
• Assessment and Confidence Mechanisms;
• Cybersecurity Workforce;
• Federal Alignment;
• International Aspects, Impacts, and Alignment;
• Supply Chain Risk Management; and
• Technical Privacy Standards

As expected the final area to receive detailed attention was the ‘Next Steps’ portion of the document. This was divided into two sections; NIST Actions and Recommended Stakeholder Actions. The later included discussions on:

• Customizing the Framework for your sector or community;
• Publishing a sector or community Profile or relevant “crosswalk.”;
• Advocating for the Framework throughout your sector or community, with related sectors and communities;
• Publishing “summaries of use” or case studies of your Framework implementation; and
• Sharing your Framework resources with NIST.

There is no time table mentioned in the document for updating the CSF, but it is being reported (here and here) that NIST is expecting to publish an update next year. If past history is any guidance, I would expect NIST to hold a series of future workshops during the development process.

Friday, June 10, 2016

CFATS Update

I mentioned last week that I would have some more information on the latest CFATS update. I had a chance to talk to some folks from ISCD headquarters yesterday. I don’t have the details that I had hoped for (though we may see them in the July update), but I did pick-up some interesting tidbits of information about the CFATS program.

Expedited Approval Program


Back in December 2014 when Congress updated the Chemical Facility Anti-Terrorism Standards (CFATS) authorization they included a mandate for the DHS Infrastructure Security Compliance Division (ISCD) to establish an Expedited Approval Program to help ISCD reduce the backlog of site security plan (SSP) approvals. The idea was that the EAP would provide facilities with a specific blue print for a site security plan instead of having to negotiate a site security plan with ISCD. Congress thought that this would speed up the SSP approval process.

Well, it turns out that only one facility has used the EAP to get their SSP approved to date. It is almost exactly a year since facilities could start the EAP process and only one facility decided that it was a worthwhile program. So, did ISCD waste their time in publishing the EAP guidance document? If you look at it from the number of facilities that opted to formally use the program, probably. In a larger sense, probably not.

Long time readers of this blog will know about my concerns with the Risk Based Performance Standards (RPBS) guidance documents that facilities have had to rely on for standing up their SSPs since 2009. The drafters of that document bent over backwards to ensure that they could not be accused of ‘specifying security measures’ because ISCD was prohibited from that particular committing that particular sin by the old §550 program authorization language. For facility security managers that did not have professional security training (most of them), the document was little better than no guidance. It is little wonder that virtually no first time SSP submission was approved by ISCD.

With the publication of the EAP guidance, facility security managers without security training can get a good idea what type of security measures ISCD is looking for. Facilities still have the ability to tailor their security measures to their own unique environment, but they have a clearer measure of what those measures are expected to accomplish.

BTW: When ISCD rolls out their new risk assessment/tier assignment methodology this fall it looks like they are intending to update a number of program documents to properly reflect that methodology. One of those documents is likely to be the RSBP guidance document.

Enforcement


With ISCD now spending 80% of their inspection time on compliance inspection, it is almost inevitable that there will be facilities that are not in compliance. ISCD has a long history of working with facilities to get security properly in place, and that has continued over to compliance inspections. Unfortunately, it seems that there have been some (no one is currently talking about how many) facilities that ISCD may be (have begun) taking enforcement actions against to ensure that they meet their SSP obligations. Hopefully, they will never meet a facility that is so intransigent that the Secretary will be forced to close the facility, but that is still the ultimate enforcement authority available.

BTW: It looks like ISCD will be announcing at the upcoming Chemical Sector Security Summit (CSSS #10) that they have completely cleared the back-log of SSP approvals. Not all facilities will have approved SSPs then, but SSP processing will be proceeding in regular order with no unreasonable delays between SSP submission and authorization/approval inspections.

Risk Assessment Process


DHS has taken a lot of flak since the beginning of the CFATS program about the methodology they use for determining which facilities that submit Top Screens (more than 50,000 to date) are assessed to be at high-risk for terrorist attack (and thus inclusion in the CFATS program) and then used to determine the Tier Ranking for facilities in the program. DHS was not willing to discuss the details of that assessment process and were obviously missing some information necessary to do a “real” risk assessment.

ISCD will be rolling out this fall their updated and more rigorously justified risk assessment process. ISCD has had their processes vetted by an academic review process as well as a stakeholder review process. So there should be fewer complains (anyone that expects no complaints is using too many good drugs) about the new process. One of the reasons for this is that ISCD is planning on sharing more information (NOT details) about that process with the chemical community. They realize that companies need to be able to take that risk assessment process as they plan to construct new or modify existing chemical facilities so that the security costs associated with the project can be included in the facility planning process.

We have seen the first change associated with this new risk analysis process when ISCD held their Top Screen webinar last February. Since a number of questions were moved into the new Top Screen from the Security Vulnerability Assessment, the SVA is also going to have to be changed. I think that we will see the debut of that new SVA tool at the CSSS. Hopefully ISCD will include that debut in the sessions that they share on the web.

CFATS Rulemaking


ISCD is continuing to work on their notice of proposed rulemaking for updating the CFATS regulations. That process began with their advance notice of proposed rulemaking (ANPRM) published in August 2014. The Spring 2016 Unified Agenda projects that the NPRM will be published in September. No details are available on what changes are going to be proposed for the program beyond what was discussed in the ANPRM.

Closely associated with the CFATS program (but a separate regulatory scheme) is the congressionally mandated Ammonium Nitrate Security program (6 USC 488 thru 488i). ISCD issued their NPRM for the program in August of 2011, but has failed to be able to overcome the cost-benefit questions raised about that proposed rule. Congress has taken cognizance of the problem and DHS, Congress and the potentially regulated industries have been working on a solution to the problem. One monkey wrench thrown into the works has been the significant ISIS use of improvised explosives made with other chemicals. I half-way expect to see a new congressional mandate for precursor chemicals for improvised explosive devices; especially if we see a significant domestic IED that does not use ammonium nitrate.

BTW: If there is another Oklahoma City sized ammonium-nitrate truck bomb, the problems of the cost-benefit analysis will be instantly resolved and a regulation based upon the NPRM will probably be quickly forthcoming.

Missing Questions


I did not get a chance to ask all of the interesting questions that I wanted to, maybe in future conversations. But I would like to know if/when the folks at ISCD are going to remove their current ‘temporary’ exemption for agricultural production facilities from filing Top Screens. I still think this will be a ‘minor’ regulatory burden for almost all of the facilities involved because ISCD would be unlikely to determine that they are at high-risk of terrorist attack (for their chemicals anyway; food security is an Ag Department problem). This may be addressed with the roll out of the new Top Screen.

The other important topic that I did not get a chance to address was the progress being made in implementing the Personnel Surety Program. I think that it would be an interesting addition to the CFATS update if ISCD would include the total number of personnel that have been vetted against the terrorist screening database (TSDB). A number that we will probably never hear (for fairly legitimate reasons) is how many folks have turned up as a match against the TSDB during these checks. I personally expect that most of those positives will be false positives and that will cause problems for both ISCD, facility management and the folks improperly identified as having terrorist ties. I really hope that the number isn’t too large.


As always I appreciate the time that folks took to talk with me about the CFATS program. I have had my differences of opinion over the years with exact methodologies used by ISCD in their implementation of the CFATS program, but I have always admired how hard the folks have worked at making the process work especially how diligently they have tried to make the program a cooperative attempt to increase facility security rather than an adversarial program. Let’s hope that that can continue into the future.

More Amendments to S 2943 – FY 2017 NDAA – 06-09-16

Yesterday there were 65 amendments proposed for S 2943, the FY 2017 National Defense Authorization Act. Of those there were only two that may be of specific interest to readers of this blog:
• SA 4642. Mr. BOOKER (D,NJ) - SEC. 1097. Completion of outstanding transportation security requirements. Pg S3742
• SA 4659. Mr. FRANKEN (D,MI) - SEC. ll. Reporting requirements regarding oil well and petrochemical manufacturing plant safety. Pgs S3768-9

The Amendments


The Booker amendment is essentially the same as SA 4531 that he submitted on Tuesday. The only difference is some additional ‘sense of Congress’ language that references a recent DHS IG report on TSA rail security failings. The actual requirements section of the amendment remain the same.

The Franken amendment would require operators of oil wells or oil and gas production facilities to report OSHA safety violations and/or citations in their annual reports to the Security Exchange Commission.

Moving Forward


The Senate continued consideration of S 2943 yesterday, failing to evoke cloture on two amendments which were subsequently withdrawn. An agreement was reached that the Senate would have a cloture vote on the bill this morning. The deadline for submitting amendments to S 2943 was also set for this morning. If the cloture vote succeeds and unless an agreement is reached for an earlier vote on the bill, it will be sometime next week before the bill comes to a vote.

Commentary


These non-DOD related amendments are just another part of the Senate bill (sausage) making process. I would bet that both Booker and Franken are hoping that they can get enough Democratic support for these amendments that they can force McConnell to include their amendment in the consideration process by threatening a ‘No’ vote on the cloture process and stalling consideration of the bill. The fact that Booker revised his amendment indicates that he is actively working that processes. I do not think that it will work for either of these two amendments, but you never can tell.


NOTE: It was announced yesterday that the next spending bill to be considered in the Senate will be the Commerce, Science and Justice (CSJ) bill. The ‘vehicle’ for this bill will be the House bill passed last year (HR 2578) for FY 2016 spending, but the language will be an amendment offered (probably today) based upon S 2837.

Bills Introduced – 06-09-16

Yesterday with both the House and Senate in session there were 48 bills introduced. Of those, only one may be of specific interest to readers of this blog:

HR 5443 To provide for mandamus actions under chapter 601 of title 49 of the United States Code. Rep. Speier, Jackie [D-CA-14]


It will be interesting to see what type of new enforcement authority this bill would provide in the pipeline safety program.

Thursday, June 9, 2016

ICS-CERT Publishes Two Siemens Advisories and Updates a Third

This morning the DHS ICS-CERT published two new advisories for control system vulnerabilities in products from Siemens and updates a Siemens Advisory initially issued in April, 2016. They also provided some updated information for the Fall 2016 ICSJWG Meeting in Ft. Lauderdale.

Siemens SIMATIC S7-300 Advisory

This advisory describes a denial of service vulnerability in the SIMANTIC S7-300 CPU family. The vulnerability was reported separately by Mate J. Csorba of DNV GL, Marine Cybernetics Services, and Amund Sole of Norwegian University of Science and Technology. Siemens has produced a firmware update to mitigate the vulnerability. There is no indication that the researchers were provided a chance to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to go into defect mode, requiring a cold restart to recover the system. The Siemens-CERT advisory notes that the attacker would require network access and that enabling read-write protection on the device mitigates the vulnerability.

Siemens reported this yesterday on TWITTER.

Siemens SIMATIC WinCC Advisory

This advisory describes a weakly protected credentials vulnerability in the Siemens SIMATIC WinCC flexible. The vulnerability was reported to Siemens by Gleb Gritsai and Roman Ilin from Positive Technologies. Siemens has produced an update to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to possibly reconstruct user credentials. The Siemens-CERT advisory clarifies that the vulnerable credentials are those for the remote management module.

Siemens reported this yesterday on TWITTER.

Siemens glibc Update


This updates an advisory for a a buffer overflow vulnerability in the glibc library that could affect several of the Siemens industrial products. It updates the affected version numbers for the SINEMA Remote Connect product. It also reports that Siemens has added an update for that product. The SCALANCE M800/S615, and Basic RT V13 products have yet to be updated.

Siemens reported this yesterday on TWITTER. Without this Siemens TWEET we would never have known that the ICS-CERT advisory had been updated; and it still took some searching to find the updated advisory.

ICSJWG Meeting Update


ICS-CERT reports that:

“The ICSJWG Program Office is now accepting abstracts for the 2016 Fall Meeting in Ft. Lauderdale!  We will consider topics among a wide range of issues that relate to industrial control systems cybersecurity and resilience across critical infrastructure.  We encourage everyone who is interested in presenting to submit an abstract, as we look to populate the agenda with a variety of presentations.”

The abstract submission form is available on-line. Registration is now open on-line for attending the meeting.

S 3000 Introduced – FY 2017 DOD Spending

Last week Sen. Cochran (R,MS) introduced S 3000, the Department of Defense Appropriations Act, 2017. As we have come to expect with the DOD spending bill there is no specific mention of cybersecurity issues in the bill itself, but there are numerous references found in the Senate Appropriations Committee report on the bill. Few of the references have any direct impact on the industrial control system community, but operations of the largest cyber-active organization in the country will inevitably have an influence on all cybersecurity operations.

Cyber Defenses


With breaches of information systems being daily news the Committee is directing DOD to (Pg 183) “to undertake a comprehensive review of classified systems and systems that have PII information, and validate that protection measures are in place to insure data integrity and appropriate access” and report back to Congress with the results of the review.

Counterfeit Parts


The Committee continues to be concerned about the issue of counterfeit electronic parts. While recognizing that suppliers have the primary responsibility to prevent the use of these counterfeit parts, the Committee wants DOD (pgs 32-3) “to be proactive about identifying, developing, and validating independent tools that suppliers could easily use to rapidly identify counterfeit electronics in the supply chain accurately and at low cost”.

Cyberwarfare Training


Training for the cyberwarfare force continues to be a matter of concern for the Committee and the Report reflects this by identifying a number of specific training issues that it wants to see DOD address. These areas include

• Training shortfalls in the cyber kinetic combat environment (pg 33);
• Expanding training to sites with Active or Reserve components with secure infrastructure and qualified cyber personnel, including aggressor units and cyber red team units, capable of training military personnel in various cyber missions (pg 34); and
• Development of a competitive hacking environment that includes the ability for participants to build novel working exploits and defend against them (pg 34).

Cybersecurity Research


The Committee recognizes that building an effective cyberwarfare force is going to require additional R&D efforts. The Committee report identifies three specific areas that are of immediate concern in the R&D realm:

• The interdisciplinary nature of cyber systems including consideration of the role of human behavior (pg 160);
• Research in automated exploit generation, exploit hardening, and vulnerability identification capabilities of systems when source code is not available, and to focus on implementation, integration, and software tooling (pg 183); and
• Support institutions with strong cybersecurity, cyber-physical, and networks of systems research programs that will develop methods to identify vulnerabilities in large networked systems, rapidly prototype and build security prototypes and tools, and with institutional capabilities to transfer basic research into Department of Defense mission areas and platforms (pg 183).

UAS Defense


The Committee recognizes that the ubiquity of civilian and military unmanned aerial systems (UAS) means that a wide variety of adversaries are going to be able to deploy such devices against US forces. The Committee is encouraging DOD (pg 168) to continue research and development of tactics using radar systems, advanced communications, and cyber security technologies to counter UAS threats.

Moving Forward



The Defense spending bill is one of the bills that the House and Senate leadership would certainly want to see on the floor of both houses before the summer recess in mid-July. The two separate bills would then be combined in a conference committee with the desire to see final action before the end of the fiscal year. This Senate bill may not be able to get to the floor, however, because of Democratic concerns about increases in spending. If it is held up, it will be interesting to see if Sen. McCain modifies the spending levels in a subsequent bill in response to those concerns to move a bill to the floor, or waits to try to push the issue forward after the election.
 
/* Use this with templates/template-twocol.html */