Tuesday, March 17, 2020

HSGA Amends and Adopts S 3207 – CISA Cybersecurity State Coordinators


Last week the Senate Homeland Security and Governmental Affairs committee held a business meeting that included consideration of S 3207, the Cybersecurity State Coordinator Act of 2020. Substitute language was offered by Sen Hassan (D,NH) who sponsored the bill. The Committee adopted that substitute language and favorably recommended the bill by a voice vote.

Changes


Most of the changes were relatively minor wording changes. For example in the proposed new §2215, subsection (b) saw the phrase “on a voluntary basis” inserted into four of the eight paragraphs describing the duties of the State Coordinator when describing the interactions of the State Coordinator with non-Federal entities.

Subsection (c) was completely re-written to increase the emphasis that the State Coordinators were intended to be an aid to, and should work closely with, State and local governments. The new subsection reads:

“(c) FEEDBACK.—The Director shall take into account relevant feedback provided by State and local officials regarding the appointment, and State and local officials and other non-Federal entities regarding the performance, of the Cybersecurity State Coordinator of a State.”

Finally §2(b) of the bill was modified to add a second report to Congress on the State Coordinator program two years after the initial report.

Moving Forward


While relatively minor, it would seem to me that these changes were made to ease any concerns about Federal-State interactions that this bill might have caused. This should make it easier for this bill to be considered under the Senate unanimous consent process. If objections were raised in that process, the only other way that this bill would move forward would be to include it in the DHS appropriations bill or a CISA reauthorization bill.

Commentary


None of the concerns that I expressed with the introduced version of this bill were addressed in the substitute language. If this bill moves forward (and I think that it will), these deficiencies would have to be addressed in the House.

The addition of the ‘voluntary basis’ language in the substitute raises some interesting issues; not so much in the areas where it was inserted, but rather with where it was not. It was not inserted into paragraphs 4,5, 7 or 8. Paragraph 4 talks about raising awareness of the availability of Federal assistance, so no big deal there. And paragraph 8 is the obligatory ‘other duties’ language, so, again, no problem. The other two, however may raise some interesting issues down the road.

Paragraph 5 deals with “supporting training, exercises, and planning for continuity of operations”. Not specifically adding the ‘voluntary basis’ language here when it was specifically added elsewhere might be seen as implying a federal requirement for State and local governments to conduct such ‘training, exercises, and planning’.

Similarly, in paragraph (7) the failure to include the language could be seen as a requirement for State and local governments to develop “vulnerability disclosure programs consistent with Federal and information security industry standards”.

Realistically, I do not see CISA trying to exercise such implied authority. It could, however, reasonably be expected to be used by lawyers in civil suits against such agencies when such failures by State and/or local governments (and potentially private sector entities) resulted in financial harm to their clients.

Monday, March 16, 2020

DOE Publishes CEII Admin Final Rule


Today the Department of Energy (DOE) published a final rule in the Federal Register (85 FR 14756-14772) concerning “Critical Electric Infrastructure Information; New Administrative Procedures”. The rule establishes procedures for the designation of critical electric infrastructure  information (CEII) under section 215A(d) of the Federal Power Act (16 USC 824o-1). The notice of proposed rulemaking (NPRM) for this action was published in October 2018. OMB approved this final rule on January 28th, 2020.

Changes from NPRM


Changes that were made in the final rule include:

Added definition of ‘confidential business information’;
Added definition of ‘CEII Coordinator’;
Specified that the CEII Coordinator or Coordinator's designee can designate certain information sought by DOE as CEII;
Expanded the coordination of implementation of DOE's CEII authority to include all CEII Coordinators;
Updated the marking of CEII as “CEII-CRITICAL ELECTRIC INFRASTRUCTURE INFORMATION—DO NOT RELEASE”;
Added dual marking requirement for material that is both confidential business information and CEII;
Clarified that a conference call will be scheduled within five days of when the CEII submitter is notified of the request;
Added DHS and NRC to the list of federal agencies that the CEII Coordinator will meet with annually to discuss CEII issues;
Added requirement that the designation decision be communicated “promptly” to the requestor;
Removed all references to “pre-designation” in the Final Rule;
Clarified that there are two methods for initiation of the re-designation process;
Clarified that  reconsideration requests can be made through a secure electronic submission or by mail;
Clarified that inadvertent disclosure does not affect the disclosed material's CEII status

Effective Date


The effective date on this rule is May 15th, 2020.

Committee Hearings – Week of 3-15-20


With just the Senate in session this week and amid COVID-19 disarray there are a very limited number of hearings currently scheduled. There is one of interest currently on the short list, a review of the report from the Cyberspace Solarium Commission.

CSC Report


On Wednesday the Subcommittee on Cybersecurity of the Senate Armed Services Committee will hold a hearing on “Findings of the Cyberspace Solarium Commission”. The witness list includes two Commission members:

• Sen King (I,ME); and
• Rep Gallagher(R,WI)

A copy of the Commission Report and the Executive Summary are available on the Commission web site.

Sunday, March 15, 2020

HSGA Amends and Adopts S 3045 – CISA Subpoena


Last week the Senate Homeland Security and Governmental Affairs Committee held a business meeting during which they considered S 3045, the Cybersecurity Vulnerability Identification and Notification Act of 2019. Substitute language was offered by Sen Hassan (D,NH), a co-sponsor of the bill. The substitute language was further modified by an amendment offered by Sen Paul (R,TN) and the modified language was subsequently adopted by a voice vote.

Limit on Authority


The original substitute language modified the language of the proposed §2209(o)(2)(B) by adding a new category of limits to the information that the Cybersecurity and Infrastructure Security Agency (CISA) can seek under the new subpoena authority. The added restriction is that a subpoena cannot be seek information on “more than 20 covered devices or systems” {§2209(o)(2)(B)(ii)}.

Information Sharing Within the Government


Both the substitute language and the Rand amendment made changes to the authorization for CISA to share information obtained through the newly authorized subpoena authority.

The substitute language modified New §2209(o)(7)(A)(ii) by adding two new clauses; additionally allowing the Agency to share information received with another Federal agency if a cybersecurity incident is involved and:

• The Director determines that sharing the nonpublic information with another Federal agency is necessary to take law enforcement or national security actions pertaining to such incident; and
• The entity to which the information pertains is notified of the Director’s determination, to the extent practicable consistent with national security or law enforcement interests

The Paul amendment would modify that authority requiring the affected entity to consent to the disclosure unless “another Federal agency identifies the entity to the Agency in connection with a suspected cybersecurity incident” {new §2202(o)(7)(A)(iv)}.

The Paul Amendment also added a new paragraph (12) that further restricted the sharing of information with other Federal agencies. It would prohibit the sharing of any information produced as a result of the subpoena with “any other Federal agency for any purpose other than a cybersecurity purpose” as defined in 6 USC 1501.

Information Sharing with Affected Entity


The substitute language would revise the proposed §2202(o)(7) by adding a new sub-paragraph (F) that would require CISA, when notifying an entity at risk, to include:

• A discussion or statement that responding to, or subsequent engagement with, the Agency, is voluntary; and
• To the extent practicable, information regarding the process through which the Director identifies security vulnerabilities.

The substitute language also modified the language of §2202(o)(7)(C) requiring, after information received as a result of a subpoena showed that the covered entity was not a critical infrastructure entity, that the affected entity be informed about the vulnerability information before the contact information for the entity was destroyed.

Moving Forward


Once the Committee submits their report on the bill along with the amended language, the bill would be cleared for consideration by the full Senate. It seems to me, however, that this bill is still too controversial to be considered under the Senate’s unanimous consent process; some one would object. That would require the bill to be considered under regular order. That is too time consuming this late in the session and the Senate leadership would never bring it to the floor. The only other hope for this bill is for it to be included in a CISA authorization bill, which may be high-enough priority to be considered under regular order.

I am going to add a new caveat to this ‘moving forward’ discussion; COVID-19. At the seriousness of this epidemic becomes more apparent and the economic consequences become more painful, the normal operations of the House and Senate are going to become affected as a lot of priorities shift. Add to the fact that we are inevitably going to see a number of legislators and their staffs personally affected by the disease and that is going to affect the legislative process in ways that are going to be difficult to predict.

Commentary


I think that the changes made this week by the Committee are all worthwhile changes. I will note that changes did address two items that I noted in my original post about S 3045. My proposed language changes at the end of that post were not specifically made, but the new language for that clause achieves the same end. I will pretend that I helped that change along.

The other change addressed the objections of a number of commenters about the broader than popularly described scope of the subpoena authority. The way this bill written, even after the changes here, does not limit the CISA subpoena power to just contact information from ISPs. As I noted in that post:

“A more effective use of this subpoena power, however, would be to contact control system equipment vendors or integrators about owners of equipment with known cybersecurity vulnerabilities, particularly where those vulnerabilities do not yet have effective mitigation measures available. There is nothing in this bill that would prevent such subpoenas.”

Well, the new language does hinder that use of the subpoena authority by limiting the use “for not more than 20 covered devices or systems”. A clever subpoena crafter could still gain valuable information from a Siemens or Rockwell about owners of vulnerable devices, but there would be some very real limits on that information as a result of this change. Those limits could deny CISA timely information that would prevent a cyberattack on critical facilities.

Does this make this a bill that should not pass? Of course not. No legislation is going to be perfect in a representative democracy. Compromises must be made to get bills passed and signed into law. The CISA subpoena authority is important, and if some limits have to be placed on that authority for it to become available, so be it.

Public ICS Disclosures – Week of 3-7-20 Part II


In addition to the vendor disclosures I discussed yesterday, we have four vendor disclosures from Schneider and three updated disclosures from Schneider and Siemens (2).

Schneider Advisories


Schneider published an advisory describing two vulnerabilities in the Schneider Interactive Graphical SCADA System (IGSS). The vulnerabilities were reported by an anonymous researcher via the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper limitation of a path name to a restricted directory - CVE-2020-7478; and
• Missing authentication for a critical function - CVE-2020-7479


Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability in the Schneider Modicon Quantum Ethernet Network module and Quantum / Premium COPRO. The vulnerability was reported by China Information Technology Security Evaluation Centre (CNITSEC). Schneider has a new version for the Quantum Ethernet Network module that mitigates the vulnerability. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing an untrusted search path vulnerability in the Schneider ZigBee Installation Toolkit. The vulnerability was reported by Yongjun Liu of nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Liu has been provided an opportunity to verify the efficacy of the fix.


Schneider published an advisory describing three vulnerabilities in the Schneider Andover Continuum Line of Controllers. The vulnerabilities were reported by Niv Levy. Schneider provided generic mitigation measures for this product that is no longer under service support.

Schneider Update


Schneider has published an update for their Urgent/11 advisory that was originally published on August 2nd, 2019 and most recently updated on February 11th, 2020. The new information includes mitigation measures for:

• HMIGXU;
• Easergy MiCOM P30;
• Tricon Communication Modules; and
• Trident Communication Integration Module

Siemens Updates


Siemens published an update for an advisory for Intel CPUs that was originally published on February 11th, 2020. The new information includes updated version and mitigation data for:

• SIMATIC IPC127El;
• SIMATIC IPC627E;
• SIMATIC IPC647E;
• SIMATIC IPC677E; and
• SIMATIC IPC847E


Siemens published an update for an advisory for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on February 11th, 2020. The new information includes updated version and mitigation data for:

• SIMATIC IPC127E; and
• SIMATIC IPC527G

Saturday, March 14, 2020

OMB Approves NHTSA Automated Driving System NPRM


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the DOT’s National Highway Transportation Safety Administration (NHTSA) concerning “Occupant Protection for Automated Driving Systems”.

The 2019 Fall Unified Agenda entry for this rulemaking notes:

“This action proposes to amend crashworthiness regulations that may be necessary to facilitate the certification of motor vehicles equipped without driver controls. The agency published a Federal Register notice on January 18, 2018, requesting comment on existing regulatory barriers that may block the introduction and certification of ADS-equipped vehicles, particularly those without human controls. In response to comments received from the January notice, the agency initiated this NPRM to begin the rulemaking process. NHTSA will consider comments received from this notice, agency research, stakeholder engagement, and internal agency analysis to remove crashworthiness-related regulatory barriers.”

I wrote about the 2018 request for comments.

House Passes HR 6160 – CFATS Extension


Yesterday (actually early this morning) the House took up HR 6160 under the unanimous consent process and passed the bill. There was no debate and no vote. The bill will extend the current CFATS program through October 18th, 2021. The program authority is currently set to expire on April 18th, 2020.

This early action by Rep. Thompson (D,MS) sends the bill to the Senate. The bill will almost certainly be taken up there under similar proceedings.

 
/* Use this with templates/template-twocol.html */