Friday, July 16, 2021

Review - OMB Approves Another Emergency TSA Pipeline Security ICR

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) published an approval for another TSA emergency information collection request supporting increased security oversight of gas and liquid pipelines. This emergency ICR update addresses changes to the Pipeline Corporate Security Review (1652-0056) which was most recently updated on April 15th, 2021. According to the supporting document [.PDF download link] provided to OIRA, this emergency ICR approval is needed to support a new TSA Security Directive for pipeline cybersecurity security operations.

As with most emergency ICR requests, OIRA gave rapid approval of the ICR request. Its approval was, however, only for 6-months. OIRA did required that TSA publish a 60-day ICR notice for this change within 90-days.

For more details about the ICR coverage and the upcoming Security Directive, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-another-emergency-tsa - subscription required.

Bills Introduced – 7-15-21

Yesterday with just the Senate in session, there were 33 bills introduced. Two of those bills will receive additional coverage in this blog:

HR 4431 Making appropriations for the Department of Homeland Security for the fiscal year ending September 30, 2022, and for other purposes. Rep. Roybal-Allard, Lucille [D-CA-40]

HR 4432 Making appropriations for the Department of Defense for the fiscal year ending September 30, 2022, and for other purposes. Rep. McCollum, Betty [D-MN-4]

Both of these bills are being reported by the House Appropriations Committee. The text of the bills is already available, but we are waiting on the actual publication of the Committee Report for each bill. While the bills do provide spending totals and limited guidance (at this point, the floor amendment process will change that) most of the meat of committee requirements will be found in the Committee Report for each bill.

That being the case, I will hold off on conducting my reviews until the Committee Reports are actually published by the GPO in the next day or two.

Thursday, July 15, 2021

Review - HR 3691 Introduced - Wastewater Infrastructure Modernization Act

Last month, Rep Bourdeaux (D,GA) introduced HR 3691, the Wastewater Infrastructure Modernization Act. The bill would establish a smart wastewater infrastructure technology grant program. It amends the Federal Water Pollution Control Act by adding a new §222 (note: that will probably be 33 USC §1302). The bill authorizes $500 million for the grant program.

Very similar language to that found in this bill was included in the version of HR 3684, the INVEST in America Act, that passed in the House. It was included as §12011 in Division H (pg 1661). That Division was added to the bill by the House Rules Committee. That means that there will be no committee action taken on this bill until the final status of HR 3684 is resolved. If the language remains in a version of the bill that makes it to the President’s desk, this bill will die a silent death. If that does not happen this bill may resume the legislative process.

For a more detailed review of the provisions of the bill and ways to clarify the coverage of cybersecurity measures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3691-introduced - subscription required.

Review - 1 Advisory Published – 7-15-21

Today CISA’s NCCIC-ICS published on medical device security advisory for products from Ypsomed. Additionally, I am reporting on an odd security warning about the CISA Industrial Control System web page.

Ypsomed Advisory - This advisory describes four vulnerabilities in the Ypsomed mylife diabetes management platform.

CISA Web Site Security Warning - Microsoft returns the following warning when an attempt is made to copy and paste data from the CISA Industrial Control Systems web site into a Word® document:

“This document contains fields that can share data with external files and websites. It is important that this file is from a trustworthy source.”

For a more detailed look at the advisory and warning, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-published - subscription required.

Review - HR 3608 Introduced - Improving Contractor Cybersecurity Act

Back in May, Rep Lieu introduced HR 3608, the Improving Contractor Cybersecurity Act. The bill amends 41 USC by adding a new §4715, Vulnerability disclosure policy and program required. It would require all federal  information technology contractors to maintain a vulnerability disclosure policy and program.

Lieu is not a member of the House Oversight and Reform Committee to which this bill was assigned for consideration. This means that the Committee is unlikely to take up this bill. I suspect that there would be substantial opposition to this bill from business interests supported by Republican members of the House, and frankly many Democratic members as well. If the bill were considered in Committee, I would not be surprised if there were insufficient votes to see it adopted as introduced.

For a more detailed analysis of the bill requirements and my observations on the problems with the language, see my analysis at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3608-introduced - subscription required.

Wednesday, July 14, 2021

Review - 4 Updates Published – 7-13-21

 

Yesterday CISA’s NCCIC-ICS published updates for four control system security advisories for products from Siemens. Siemens published an additional update yesterday that was not covered by NCCIC-ICS. Schneider published six updates yesterday that were not addressed by NCCIC-ICS. I will be reviewing all of those updates this weekend.

Industrial Products Update - This update provides additional information on an advisory that was originally published on September 10th, 2019 and most recently updated on May 11th, 2021.

UMC Stack Update - This update provides additional information on an advisory that was originally published on July 14th, 2020 and most recently updated on April 13th, 2021.

SIPROTEC Update - This update provides additional information on an advisory that originally published on March 8th, 2018 and most recently updated on March 12th, 2019.

Linux Based Products Update - This update provides additional information on an advisory that was originally published on May 11th, 2021 and most recently updated on June 8th, 2021.

For a more detailed look at these updates, and a commentary on what little effect the delays in mitigating these vulnerabilities have had on security actually means, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-updates-published - subscription required.

Bills Introduced – 7-13-21

Yesterday with the Senate actually in Washington and the House meeting in pro forma session, there were 53 bills introduced. Two of those bills may receive additional coverage in this blog:

HR 4430 To provide for the establishment of security standards for international research in key technology focus areas. Rep. Wild, Susan [D-PA-7]

S 2317 A bill to provide for the establishment of security standards for international research in key technology focus areas. Sen. King, Angus [I-ME] 

These are probably companion measures. I will be watching for any language and definitions that indicate that cybersecurity coverage under these bills applies to industrial control systems.

 
/* Use this with templates/template-twocol.html */