Wednesday, September 13, 2017

Senate Amendments to HR 2810 (FY 2018 NDAA) – 9-12-17

Yesterday the Senate leadership continued to work out a deal for determining which proposed amendments would be considered on the floor for HR 2810, the FY 2018 National Defense Authorization Act (NDAA). Meanwhile, more amendments continue to be proposed. In addition to the previously proposed amendments (see here, here and here) a large number of possible amendments to HR 2180 were proposed in the Senate yesterday; including three that may be of specific interest to readers of this blog:

• SA 948. Mr. MORAN - national guard bureau public-private cyber-security coalition (pg S5222)
• SA 989. Mr. ROUNDS - cybersecurity of industrial control systems. (a) designation of integrating official (pg S5234)
• SA 1001. Mr. ROUNDS - designation of official for matters relating to integrating cybersecurity and industrial control systems within the department of defense (pg S5240)

ICS Cybersecurity


Both of the proposed amendments from Sen. Rounds (R,SD) would require DOD to designate a single individual to be responsible “for all matters relating to integrating cybersecurity and industrial control systems within the Department of Defense” {§1630C(a)(1)}. The difference between the two amendments is that SA 989 identifies broader responsibilities for that designated individual. Those responsibilities would include {§1630C(a)(2)}:

• Developing, implementing, and be accountable for plans, programs, and policies to improve the cybersecurity of industrial control systems [only in SA 989]; and
• Developing Department-wide certification standards for integration of industrial control systems and taking into consideration frameworks set forth by the National Institute of Standards and Technology for the cybersecurity of such systems [in both amendments].

SA 989 would also require DOD to consider conducting pilot programs designed to “to assess the feasibility and advisability of implementing various solutions for protecting industrial control systems against cyber-attacks and discerning the specific criteria that a solution should demonstrate in order to be certified for military use” {§1630C(b)(1)}. Priority would be given to “the determination of certification criteria for military energy industrial control systems” {§1630C(b)(2)}.

Moving Forward


More political wrangling on what amendments to include in the debate on HR 2810 is expected overnight. There was one amendment voted upon today (in a round-about manner) and we could see additional votes tomorrow.


ICS-CERT Publishes Two Advisories

Yesterday the DHS ICS-CERT published two advisories. One was a medical device security advisory for products from Philips. The other was a control system advisory for products from mySCADA.

Philips Advisory


This advisory describes two vulnerabilities in the Philips IntelliVue MX40 Patient Worn Monitor. The vulnerabilities are self-reported. There are no FDA Safety Communications about these vulnerabilities. Philips has issued an update that mitigates one of the vulnerabilities; another update is due later this year.

The two reported vulnerabilities are:

• Improper cleanup on thrown exception - CVE-2017-9657; and
• Improper handling of exceptional conditions - CVE-2017-9658

ICS-CERT reports that a relatively low skilled attacker with access to an adjacent network could exploit these vulnerabilities to issue 802.11 Wi-Fi management commands that can impact reporting availability of MX40 device local monitoring to a central monitoring station.

mySCADA Advisory


This advisory describes an unquoted search path or element vulnerability in the mySCADA myPRO HMI/SCADA management platform. The vulnerability was reported by Karn Ganeshen, who publicly disclosed the vulnerability on 7-28-17. mySCADA has produced a new version that mitigates the vulnerability. There is no indication that Ganeshen was provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker but authenticated attacker to execute arbitrary code with elevated privileges.


NOTE: Karn is pretty well known for his coordinated disclosure, so this public disclosure is unusual. There are no explanations on either the ICS-CERT or the iPositiveSecurity web site explaining why the early disclosure was made. It would be interesting to know ‘the rest of the story’.

ISCD Publishes CFATS Quarterly

Yesterday the DHS Infrastructure Security Compliance Division (ISCD) published the latest version of their Chemical Facility Anti-Terrorism Standards (CFATS) Quarterly. According to the ‘Latest News Entry” on the CFATS Knowledge Center: “This issue highlights the CSAT 2.0 SVA/SSP surveys, cybersecurity, an update on new Chiefs of Regulatory Compliance, new resources and materials, as well as the 2017 Chemical Sector Security Summit.”

SVA/SSP Surveys


This brief article lists some new questions that facilities will have to answer when they first complete the CSAT 2.0 SVA/SSP. This list is a little different from the one that initially appeared on the SVA/SSP web site right after the CSAT 2.0 tool was introduced. The new list includes:

• Q3.10.050 Personnel Presence
• Q3.10.400 through Q3.10.420 Inventory Controls
• Q3.40.400 through Q3.40.430 Cyber Control and Business Systems (new)
• Q3.50.320 Personnel Surety, Types of Affected Individuals (new)
• Q3.50.710 Recordkeeping Affirmation (new)

Regulatory Compliance Managers


ISCD now has Regulatory Compliance Managers serving in each of its regional offices. The brief article notes that: “In addition to managing CFATS regional operations, CRCs will lead our regional efforts to coordinate with other federal, state, and local representatives and spearhead regional CFATS-related outreach and engagement.” The list of Compliance Managers includes contact information.

Commentary



It is interesting to compare this CFATS Quarterly to the recently published ICS-CERT Monitor. While both documents are used by the parent organization to share information about their programs with the affected public, the two publications are significantly different. The Monitor has the look and feel of a corporate annual report with a similar lack of useful information. The Quarterly is not nearly as sophisticated in its presentation, but it provides more useful information. That is especially important in a regulatory organization.

Bills Introduced – 09-12-17

With both the House and Senate in session there were 31 bills introduced yesterday. Of those, one may be of specific interest to readers of this blog:

S 1800 A bill to require a report on significant security risks of the national electric grid and the potential effect of any such security risks on the readiness of the Armed Forces. Sen. Warren, Elizabeth [D-MA]


I suspect that this bill will be very similar (if not identical to) the amendment Warren proposed for HR 2810 earlier this week.

S 1656 Introduced – Medical Device Cybersecurity

Last month Sen. Blumenthal (D,CT) introduced S 1656, the Medical Device Cybersecurity Act of 2017. The bill would provide enforceable cybersecurity standards for medical devices.

The bill would amend the Food, Drug, and Cosmetics Act by adding a new §502A, Cybersecurity for Devices. The new section would address the following:

• Definitions;
• Transparency of risk prior to marketing;
• Protecting remote access to managed solutions;
• Cybersecurity fixes or updates; and
• End-of-life device;

Additionally, the bill would give the DHS ICS-CERT specific responsibilities with respect to the cybersecurity of medical devices.

Definitions


Section 520A(a) provides definitions for two new terms; ‘cyber device’ and ‘cybersecurity fix or update’. Both definitions rely on the existing definition of device in 21 USC 321(h) for ‘device’ which is broadly “an instrument, apparatus, implement, machine, contrivance, implant, in vitro reagent, or other similar or related article” with established and recognized medical applications.

With that starting point a ‘cyber device’ is any device that has network or Internet connectivity, connects to an external storage device or external media, or has any other cyber capability. The term ‘cyber capability’ or even just ‘cyber’ is not defined. Similarly, a ‘cybersecurity fix or update’ is “any modification to a cyber device that addresses a software, firmware, or hardware error or known vulnerability, or a security update, and does not change the therapeutic or diagnostic function of the device” {§520A(a)(2)}.

Transparency of Risk Prior to Marketing


Section 520A(b) would require the FDA to develop a ‘report card’ that describes the cybersecurity functions of cyber devices. That report card would include {§520A(b)(2)}:

• Information pertaining to all essential elements described in the most recent version of the Manufacturer Disclosure Statement for Medical Device Security;
• A traceability matrix, accepted by the Secretary, that establishes design components and traces such components to design compensating controls;
• A description of any manufacturer compensating controls that effectively address known common vulnerabilities and exposures;
• A description of any cybersecurity evaluation conducted on the device, including any testing, validation, or verification of the device;
• A cybersecurity risk assessment conducted by the manufacturer, or a third party, explaining the risk of the device to patient safety and clinical hazards; and
• An indication of whether the device is capable of being remotely accessed along with an indication of any security measures and access protocols the device has in place to secure any such access if the capable.

The Department of Health and Human Services would be required to make a copy of the report card available to “any health care industry entity, consisting of any provider, device manufacturer, the Federal Government, health care information security researchers, and health care academia” {§520A(b)(3)(B)(ii)(I)}.

Protecting Remote Access to Managed Solutions


Section 520A(c) establishes standards for remote access to cyber devices. First it requires that manufacturers “obtain consent for such access from the provider owning or operating the device and from any patient on which the device is used” {§520A(c)(1)(A)}. That consent may be documented in the sales agreement between the manufacturer and the provider. Second, the manufacturer is required to provide notification to the provider when such access is made. This notification can be made via provider accessible access logs.

Finally, the paragraph would establish cybersecurity standards for devices capable of remote access. Those standards would include requirements to {§520A(c)(1)(C)}:

• Implement multi-factor authentication for accessing any cyber capability of the device;
• Secure data in motion and data at rest with data encryption, and other best practices, approved by the National Institute of Standards and Technology;
• Install automated tools to track access, or identify attempts at unauthorized access, to any cyber capability of the device;
• Adopt whitelisting approaches and changeable passwords for accessing any cyber capability of the device; and
• Comply with the remote access provisions recommended by the National Institute of Standards and Technology, in the document entitled ‘Security for Telecommuting and Broadband Communications (NIST Special Publication 800–46)’, published in August 2002 [emphasis added].

Cybersecurity fixes or updates


Section 520A(d) provides guidance on the usage of ‘cybersecurity fixes or updates’. First it provides that generally “any cybersecurity fix or update shall not require a new notification under section 510(k) or application for premarket approval under section 515(c)” {§520A(d)(1)}. Finally, it provides that such fixes or updates will be provided free of charge until a date specifically agreed upon between the manufacturer and the provider, or 10 years after “the manufacturer discontinues marketing the device” {§520A(d)(2)(B)} if no such agreement is documented.

End-of-Life Devices


Section 520A(e) sets forth the requirements that manufacturers must conform to when they stop marketing a cyber device. This includes requirements to:

• Provide any provider owning or operating the device with the report card, as most recently updated;
• To the extent practicable, inform any provider owning or operating the device that the manufacturer will no longer be manufacturing such device;
• Provide notice to any provider owning or operating the device of the date on which the last cybersecurity fix or update will be provided by the manufacturer; and
• Notify the Secretary of such declaration;

Additionally, the manufacturer is required to provide the following information to the provider owning or operating the device {§520A(e)(5)}:

• Compensating controls on how to securely configure the cyber device if the device stays in operation past the date on which the manufacturer stops providing cybersecurity fixes or updates;
• Documentation on secure preparation for recycling and disposal of the device;
• Specific guidance regarding supporting infrastructure architecture, including network segmentation and device isolation requirements; and
• Instructions on how to delete any personally identifiable information, protected health information, or other site-specific sensitive data such as configuration files.

ICS-CERT and Cyber Devices


Separate from the §520A language, the bill also address the role of the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) in medical device cybersecurity. Section 2c of the bill would require DHS to expand the role of ICS-CERT to include {§520A(c)(2)}:

• Investigating cybersecurity vulnerabilities of cyber devices that may cause harm to human life or significant misuse of personal health information; and
• Coordinating device-specific responses to cybersecurity incidents and vulnerabilities with respect to cyber devices

The bill would also require DHS to establish rules concerning coordinated disclosure of cybersecurity vulnerabilities in cyber devices. Those regulations would {2(c)(4)}:

• Outline the roles and responsibilities of ICS–CERT and manufacturers and providers of cyber devices;
• Provide timelines for all required actions; and
• Provide for the enforcement of cooperation between ICS–CERT and manufacturers and providers of cyber devices

Moving Forward


Blumenthal is not a member of the Senate Health, Education, Labor, and Pensions Committee to which this bill was assigned for consideration. This means that the Committee is not likely to act on this bill; effectively killing it as a stand-alone measure. We could potentially see a version of this bill offered as an amendment to a Senate FDA authorization bill when that reaches the floor.

Commentary


While there is much to like in this bill, there are too many problems that would make the resulting regulations unworkable. I’ll mention just a few.

First and foremost, the bill completely dodges the issue of ownership of implantable cyber devices. Throughout the bill there is reference to ‘the provider owning or operating the device’ as it this person (or organization) is the only entity that has an interest in the cybersecurity of the device. The only mention of the patient is where the provider informs the patient of the agreement between the provider and the manufacturer providing the manufacturer with permission to remotely access the device. Ignoring the rights of wearers of implantable devices has got to stop.

Next, while the bill attempts to specify a fairly comprehensive set of guidelines for remote access, it completely ignores the issue of who has responsibility for periodically checking the device logs to determine if/when unauthorized attempts were made to access the device or what actions should be taken when such access attempts are noted.

That same section of the bill makes a very rookie mistake when it specifies the date of a NIST publication that will be used as a standard for remote access requirements. This particular case is particularly egregious since there have been two updates to that specific standard since the date specified.

In §520A(e)(5) we see three specific actions that manufacturers are supposed to take at device end-of-life that really should have been required when devices are first authorized to be sold. These are the requirements to provide information on:

• Documentation on secure preparation for recycling and disposal of the device;
• Specific guidance regarding supporting infrastructure architecture, including network segmentation and device isolation requirements; and
• Instructions on how to delete any personally identifiable information, protected health information, or other site-specific sensitive data such as configuration files.

Not requiring that this information be provided until the end-of-life point of the cyber device is one of the most ludicrous problems with this bill.


Finally, the provisions regarding the role of ICS-CERT in the cyber device vulnerability disclosure process completely ignores the role of the security researchers that find most of the vulnerabilities in these devices. The way the paragraph reads it almost seems as if Blumenthal expects ICS-CERT to undertake the research necessary to find the vulnerabilities. If that is the case, the bill would certainly need to provide authorization for the funding and manpower needed to realistically undertake that mission.

Tuesday, September 12, 2017

Senate Amendments to HR 2810 (FY 2018 NDAA) – 9-11-17

Yesterday the Senate voted to close debate on the motion to close further debate on the motion to proceed to consideration of HR 2810, the FY 2018 National Defense Authorization Act (NDAA) by a vote of 89 to 3.This is the first step in the process to begin consideration of HR 2810. In addition to the previously proposed amendments (see here and here) a large number of possible amendments to HR 2180 were proposed in the Senate yesterday; including five that may be of specific interest to readers of this blog:

• SA 856. Mr. BROWN - Collaboration between federal aviation administration and department of defense on unmanned aircraft systems (pg S5118);
• SA 867. Ms. WARREN - Report on significant security risks of defense critical electric infrastructure (pgs S5121-2);
• SA 868. Mr. VAN HOLLEN - Strengthening allied cybersecurity (pgs S5122-3);
• SA 919. Mr. MCCAIN - Report on training infrastructure for cyber forces (pg S5146);
• SA 922. Mr. MCCAIN - Unmanned aircraft systems that pose a threat to the safety or security of certain department of defense facilities and assets (pg S5147)

Electric Infrastructure Security Risks


Yesterday’s amendment by Sen. Warren (D,MA) is nearly identical to the one she proposed last week (SA 794). The only change that I could see is that her staff added a definition of ‘security risk’:

“The term ‘‘security risk’’ shall have such meaning as the Secretary of Defense shall determine, in coordination with the Director of National Intelligence and the Secretary of Energy….”

Not much of a definition, but it does lay the onus for coming up with a useful definition with the people technically qualified to make the assessment.

DOD and UAS


SA 922 takes an interesting approach to the problem of shooting down unmanned aircraft systems (UAS) in United States airspace. Currently, damaging or shooting down an aircraft in US airspace is a criminal act under 18 USC 32 and there is no exemption in that section for actions by military personnel. This amendment would tangentially approach that problem for UAS by allowing the military to ‘seize’ UAS irrespective of the restrictions in 18 USC. Interestingly, there is no indication in the amendment on how DOD would be expected to seize those UAS or in what condition they would be when seized.

That authority would only be available at some very limited ‘covered facilities or assets’. Those would be defined as facilities relating to:

• The nuclear deterrence mission of the Department of Defense, including with respect to nuclear command and control, integrated tactical warning and attack assessment, and continuity of government;
• The missile defense mission of the Department; or
• The national security space mission of the Department.

Moving Forward


Yesterday’s vote is a pretty good indication that the Senate leadership has worked out an agreement on how to proceed with the consideration of HR 2810. There are still some procedural measures where that consideration could be derailed by a sizeable minority of the Senators, but at this point it looks like a much-amended HR 2810 will eventually get a floor vote in the Senate, maybe even this month.


When it eventually passes it will almost certainly be referred to a conference committee to work out the differences between the House and Senate versions of the bill. Still, we are likely to see a final version of the bill on the President’s desk well before the December deadline on other measures clogs up the legislative process.

Monday, September 11, 2017

Committee Hearings – Week of 09-10-17

Both the House and Senate are in town this week with most focus being on floor activities in both houses. There will be two hearings this week that may be of particular interest to readers of this blog; one on energy reliability and one on self-driving trucks.

Energy Reliability


On Tuesday the Energy Subcommittee of the House Energy and Commerce Committee will be holding a hearing on “Powering America: Defining Reliability in a Transforming Electricity Industry”. The witness list includes:

• Paul Bailey, American Coalition for Clean Coal Electricity;
• Gerry Cauley, North American Electric Reliability Corporation;
• Neil Chatterjee, Federal Energy Regulatory Commission;
• Kyle Davis, Enel Green Power North America, Inc;
• Marty Durbin, American Petroleum Institute;
• Patricia Hoffman, U.S. Department of Energy;
• Tom Kiernan  American Wind Energy Association;
• Maria G. Korsnick, Nuclear Energy Institute;
• Kelly Speakes-Backman, Energy Storage Association;
• Susan F. Tierney, Analysis Group, Inc.; and
• Steve Wright, Chelan Public Utility District

This hearing is on system reliability and ensuring the flow of electricity to customers. Interestingly, there is no mention in the background memo on this hearing on how this reliability may be effected by cybersecurity concerns. Admittedly, the reliability topic is complicated enough without considering cybersecurity, but it will be interesting to see if it is mentioned in the testimony and questioning.

Self-Driving Trucks


On Wednesday the Senate Commerce, Science, and Transportation Committee will be holding a hearing to look at “Transportation Innovation: Automated Trucks and Our Nation's Highways”. The witness list includes:

• Scott G. Hernandez, Colorado State Patrol
• Troy Clarke, Navistar
• Ken Hall, International Brotherhood of Teamsters
• Deborah Hersman, National Safety Council
• Chris Spear, the American Trucking Associations

While I have focused on cybersecurity issues associated with automated driving systems, this hearing reminds us that there are other concerns that are also going to have to be faced with this next stage of industrial automation; jobs.

On the Floor


I have already mentioned the two big bills seeing floor action this week, HR 3354 in the House and HR 2810 in the Senate.

There really is not much else happening on the floor of either house this week of specific interest, but you always have to be careful saying that. The Senate calendar is always up in the air with all sorts of jockeying for position and both intra-party and inter-party wrangling keeping the schedule very flexible. The House is usually much easier to predict since the Majority Leader actually publishes a weekly schedule.

But even the staid House throws up the occasional odd-ball scheduling change now and again. Today was a good case in point. This was supposed to be a speechifying day with no votes scheduled; at least that is what the Majority Leader’s schedules said. This is typical on Monday’s as it allows for some travel flexibility for members coming back to Washington from their districts. But then, at 4:23 pm EDT, Rep. Reichert (R,MN) asked unanimous consent that HR 3732 be discharged from committee and be considered on the floor of the House. With no debate and no vote, the bill was passed.

Interestingly this bill was introduced today (probably by Reichert, but I cannot tell until tomorrow for sure until the Library of Congress prints the list of bills introduced today) with broad title of “To amend section 1113 of the Social Security Act [42 USC 1313] to provide authority for increased fiscal year 2017 and 2018 payments for temporary assistance to United States citizens returned from foreign countries”. I suspect that a connected constituent was getting a run-around from the Social Security Administration and this bill was designed to remove a funding excuse for that runaround.

There were probably very few people on the floor of the House when this matter came up. The consideration of this bill was a mere formality (and it may die a slow death waiting in the Senate for action), but there was almost certainly no legislative trickery involved. Both parties keep at least one ‘responsible’ (to the leadership) member on the floor to object to any skullduggery being played under the guise of ‘unanimous consent’; a single voice crying from the back of the chamber would have killed the consideration of this bill. So, the leadership of both parties consented to this bill being passed, and no one has raised a stink about it. That means that the bill would almost certainly have passed if it had been considered under regular order.


But, it does just go to show that the politicos in Congress can get things done when they really want to, so we must keep a close eye on them.
 
/* Use this with templates/template-twocol.html */