Sunday, March 31, 2019

S 715 Introduced – Smart Manufacturing


Earlier this month Sen. Shaheen (D,NH) introduced S 715, the Smart Manufacturing Leadership Act. The bill would require the Secretary of Energy to develop a smart manufacturing plan and to provide assistance to small- and medium-sized manufacturers in implementing smart manufacturing programs. The bill is nearly identical to S 768 that was introduced in the 115th Congress. The earlier bill saw no action beyond its introduction.

Differences


The only differences between the two bills is that the staff added two sub-paragraphs to §4(b) of the bill. That paragraph outlined the actions that Federal agencies would take in support of the smart manufacturing plan required by this bill. The two new actions included in §4(b)(2) are:

• Actions to increase cybersecurity in smart manufacturing infrastructure;
Deployment of existing research results; and

Moving Forward


While Shaheen is not a member of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration, Sen. Alexander (R,TN) is. Adding Alexander as a cosponsor may see this bill considered by the Committee this session. No regulatory requirements are being added by this bill so there are unlikely to be any philosophical objections to the bill.

The major impediment to passage of this bill is the inclusion of a $10 million authorization for the grant program included in §7. That is small change in the Federal budget, but the money will have to come from somewhere. Shaheen avoided this spending problem in the other portions of her bill by requiring the money for the planning process to come out of Department unobligated funds; this left the spending allocation problem in the hands of DOE not Congress. That would have been difficult to do with a new grant program.

Commentary


It is interesting to see that one of the new sub-paragraph additions to this bill was similar in intent to a recommendation I made on S 768; readers would be unsurprised to realize that the language was dealing with cybersecurity. Unfortunately, the major cybersecurity suggestion I had for the bill was not adopted in the new version of the bill. I still think that the existing provisions are inadequate, so I would like to re-suggest the following addition be made to the definitions in §3:

§3(10): “VOLUNTARY CYBERSECURITY STANDARDS AND PROTOCOLS -The term “voluntary cybersecurity standards and protocols” means a standard and/or protocol developed by the National Institute of Standards and Technology (NIST) or recognized independent standards setting organizations that an electronic equipment manufacturer, system integrator or system owner may voluntarily apply in the manufacture, integration or operation of an industrial control system, energy management system or information and communication technology system, that would protect such systems from a cyber threat as that term is defined in 6 USC 1501.”

This definition would then be used in new wording for the added §4(b)(2)(D):

“encourage to the development, promulgation and implementation of voluntary cybersecurity standards and protocols in smart manufacturing operations; and”

As I noted in my post on S 768 this simple, generic language could add a significant measure of cybersecurity support to this bill without drawing any significant opposition from manufacturers fearing new government regulations.

Saturday, March 30, 2019

HR 1589 Reported in House – CBRN Intelligence


This week the House Homeland Security Committee published their report on HR 1589, the
CBRN Intelligence and Information Sharing Act of 2019. The Committee amended the bill in a hearing on March 13th.

This bill is currently scheduled to be considered by the full House on Monday, April 1st, 2019 under the suspension of the rules process. There will be limited debate and no floor amendments will be authorized. The bill is expected to be passed with substantial bipartisan support.


Public ICS Disclosures – Week of 03-23-19


This week we have one vendor notification from Phoenix Contact and an update of an earlier vendor notification from Rockwell Automation.

Phoenix Contact Advisory


VDE-CERT published an advisory for an improper access control vulnerability in the Phoenix Contact FL NAT SMx web UI. The vulnerability was reported by Maxim Rupp. Phoenix Contact provides generic control measures to mitigate this vulnerability. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

Rockwell Update


Rockwell provided an update to their advisory published earlier this week. The update provides links to:

• The Applied Risk report on the vulnerability; and
The ICS-CERT advisory

Friday, March 29, 2019

Bills Introduced – 03-28-19


Yesterday with both the House and Senate in session there were 106 bills introduced. Two of these may see future coverage in this blog:

HR 1975 To establish in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security a Chief Information Security Officer Advisory Committee. Rep. Katko, John [R-NY-24] 

S 954 A bill to provide grants to State, local, territorial, and Tribal law enforcement agencies to purchase chemical screening devices and train personnel to use chemical screening devices in order to enhance law enforcement efficiency and protect law enforcement officers. Sen. Brown, Sherrod [D-OH]

CISO’s typically have responsibility for operational technology in addition to information technology. It will be interesting to see if the definitions used in HR 1975 reflect that dichotomy.

I suspect that this bill will contain language specifying fentanyl detection. While detection of that dangerous (toxic) drug is certainly important to law enforcement officers, I will be watching for language that includes a broader array of toxic chemical detections in the grant program.

Thursday, March 28, 2019

1 Advisory Published – 03-28-19


Today the DHS NCCIC-ICS published a control system security advisory for products from Rockwell.

The advisory describes a resources exhaustion vulnerability in the Rockwell PowerFlex 525 AC Drives. The vulnerability was reported by Nicolas Merle of Applied Risk. Rockwell has new firmware to mitigate the vulnerability. There is no indication that Merle has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to result in resource exhaustion, denial of service, and/or memory corruption.

NOTE: Is it just me, or does the timeline provided in the Applied Risk advisory seem a little bit long in the preliminary exchange of information?

HR 1592 Introduced – Cybersecurity Training


Earlier this month Rep. Langevin (D,RI) introduced HR 1592, the Cybersecurity Skills Integration Act. The bill would establish a grant program within the Department of Education to provide support to post-secondary education programs that incorporate cybersecurity training or integrate cybersecurity training into existing education programs.

Definitions


Section 3(h) establishes the definitions used in this bill. The key definition in the bill is for the term ‘cybersecurity education’; it is defined as “education about ensuring the confidentiality, integrity, availability, and safety of information systems used in critical infrastructure sectors, including control systems and operational technology” {§3(h)(2)}.

Grant Program


Program grants of up to $500,000 per year may be made under this program. The bill provides for $10 million to be authorized to support the grant program {§(g)}. There is no time limit on that authorization in the language of the bill.

Moving Forward


While Langevin is not a member of the House Education and Labor Committee, the committee to which the bill was assigned for consideration, one of his cosponsors, Rep. Thompson (R,PA), is a senior member of the Committee. This means that there may be enough influence to see this bill covered in Committee.

There are no provisions in the bill that would draw any serious opposition to the bill. The main impediment to passage will be the price tag.

Commentary


The general idea that cybersecurity needs to be a topic included in degree and certification programs other than computer science certainly is one worthy of discussion. Money is, of course, one of the impediments to achieving that goal, but it is only one of the problems. The other is that there are only so many classroom hours available in degree programs and adding any new classes mean that something else has to be given up to make room in the schedule.

As should be expected by most readers, I have some problems with the cybersecurity definition used in this bill. I have to acknowledge that the staffers who wrote this bill made an honest effort to ensure that industrial control system cybersecurity issues would be addressed by this grant program. As fairly usual, however, they have taken information technology language (in this case the standard ‘confidentiality, integrity and availability’ measure of security and tacked onto the end ‘including control systems and operational technology’. The fact that the CIA security standards are not directly applicable to control system security is of little matter.

It would be helpful if there were a clear delineation that different types of cybersecurity training are going to be applicable to different types of degree programs. Most students in business and liberal arts programs are going to find information technology security classes most helpful. Students in science and engineering programs, however, are going to be more concerned about protecting physical systems rather than information from cyber-attacks.

Having said that, of course, all students need some basic cyber hygiene training; passwords, two-factor authentication, phishing, etc. I am not sure, however, that these need to wait until post-secondary education. It seems to me that these types of training would be more appropriate in elementary or middle school given the widespread use of cellphones and tablets by people in that age groups.

Wednesday, March 27, 2019

Bills Introduced – 03-26-19


Yesterday with both the House and Senate in session there were 50 bills introduced. Of these, one will receive additional coverage in this blog:

S 876 A bill to amend the Energy Policy Act of 2005 to require the Secretary of Energy to establish a program to prepare veterans for careers in the energy industry, including the solar, wind, cybersecurity, and other low-carbon emissions sectors or zero-emissions sectors of the energy industry, and for other purposes. Sen. Duckworth, Tammy [D-IL]

 
/* Use this with templates/template-twocol.html */