Thursday, July 21, 2022

Review – 5 Advisories and 1 Update Published – 7-21-22

Today, CISA’s NCCIC-ICS published five control system security advisories for products from AutomationDirect, Mitsubishi Electric, Rockwell Automation, Johnson Controls, and ABB. They also published an update for products from Rockwell.

AutomationDirect Advisory - This advisory describes a cleartext transmission of sensitive information vulnerability in the AutomationDirect Stride Field I/O product.

Mitsubishi Advisory - This advisory describes seven vulnerabilities in the ICONICS Product Suite, and Mitsubishi MC Works64.

Rockwell Advisory - This advisory describes three vulnerabilities in the Rockwell ISaGRAF Workbench.

Johnson Controls - This advisory describes a missing authentication for critical function vulnerability in the Johnson Controls Metasys ADS, ADX, OAS with MUI server.

ABB Advisory - This advisory describes five different improper privilege management vulnerabilities in the ABB Drive Composer, Automation Builder, Mint Workbench products.

Rockwell Update - This update provides additional details on an advisory that was originally published on March 29th, 2022.

NOTE: Rockwell has not updated their advisory, and the new information is not reflected in the original Rockwell advisory.

 

For more details on these advisories and update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-0f2 - subscription required.

HR 8294 Passed in House – FY 2023 Minibus Spending Bill

Yesterday, the House completed consideration of HR 8294, the Transportation, Housing and Urban Development, Agriculture, Rural Development, Energy and Water Development, Financial Services and General Government, Interior, Environment, Military Construction, and Veterans Affairs Appropriations Act, 2023. This minibus spending bill includes six spending bills (HR 8294-THUD, HR 8239-ARD, HR 8255-EWR, HR 8254-FSGG, HR 8262-IER, and HR 8238-MC&VA). The bill passed on a party line vote of 220 to 207.

A large number of the 190 proposed amendments were adopted, mostly in en bloc votes. There were no cybersecurity, chemical transportation or UAS amendments proposed.

The bill now goes to the Senate for consideration. With no spending bills published by the Senate Appropriations Committee, there are no substitute languages currently available to begin Senate consideration. With the party-line vote, the Senate is unlikely to take up the House language for consideration. This bill is unlikely to be considered in the Senate.

Review - S 3511 Reported in Senate – Satellite Cybersecurity

Last month, the Senate Homeland Security and Governmental Affairs Committee published their Report for S 3511, Satellite Cybersecurity Act. The Committee met on March 30th, 2022 and adopted substitute language and one additional amendment before ordering the bill reported favorably. The new version of the bill modifies some of the reporting requirements and makes changes to the satellite cybersecurity recommendations process. Subsequent technical changes were made to the bill “by mutual agreement of the Chairman and Ranking Member” (Committee Report, pg 4).

Moving Forward

While there was (not unexpectedly) strong bipartisan support for this bill in Committee for this bill, the bill is not likely to be considered by the Senate leadership to be important enough to be considered under regular order on the floor of the Senate. The time and effort to go through the debate and amendment process would interfere with the agenda of the Senate as we go into the last four months of the session. There is a remote chance that the bill could be considered under the unanimous consent process, but that has a high potential for being blocked for political reasons having nothing to do with the bill. This bill is much more likely to be added to a major bill (such as the upcoming NDAA) as part of the substitute language or as a floor amendment.

For more details about the changes made to the language of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3511-reported-in-senate - subscription required. 

Wednesday, July 20, 2022

Review - Senate Considering HR 4346 – CHIPS Act

Yesterday, the Senate took up the House amendment, to the Senate Amendment to HR 4346, the FY 2022 Legislative Branch Appropriations Act, as the vehicle for the CHIPS Act. The Senate action will start with the SA 5135 as substitute language. It looks like Schumer is trying to limit the amendment process, filling the ‘amendment tree’ with inconsequential amendments. Action on the bill is continuing today.

This is a new try at passing a technology spending bill to break the impasse between the Senate and House on S 1260 and HR 4521. The new attempt is slightly more focused on chip manufacturing, with lots of extraneous (but not nearly all) matter stripped out. It does include some cybersecurity language, but not as much as was in either of the earlier bills. The cybersecurity provisions include:

Sec. 10223. NIST authority for cybersecurity and privacy activities.

Sec. 10228. Protecting research from cybersecurity theft.

Sec. 10235. Dr. David Satcher Cybersecurity Education Grant Program.  [S 2305]

Sec. 10315. Cyber workforce development research and development.

Sec. 10316. Federal cyber scholarship-for service program.

Sec. 10317. Cybersecurity workforce data initiative.

Moving Forward

There has not yet been a cloture vote on this revised bill, so it is hard to assess if there will be enough Republican support for the bill to move it forward in the House. We are starting to get into that period in the calendar where election considerations play an even higher than normal role in legislative actions. To me, however, the bigger question is has Schumer finally worked out language on a technology bill that will pass in the Democratically controlled House? The Democrats need a legislative win in a measure that will have a visible impact on improving the economy without looking like it is throwing money at people.

For a more detailed look at the cybersecurity provisions of the substitute language, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/senate-considering-hr-4346-chips - subscription required.

CISA Announces NSTAC Meeting – 8-23-22

Today, CISA published a meeting notice in the Federal Register (87 FR 43281) for a conference call meeting of the President's National Security Telecommunications Advisory Committee (NSTAC). The meeting is open to the public. The agenda includes a deliberation and vote on the NSTAC Report to the President on Information Technology and Operational Technology Convergence.

Personnel wishing to participate in the conference call (listen only) need to register via NSTAC@cisa.dhs.gov no later than August 16th, 2020. Those wishing to speak at the meeting need to register via the same route. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # CISA-2022-0006).

Bills Introduced – 7-19-22

Yesterday, with both the House and Senate in Washington, there were 36 bills introduced. One of those bills may see additional coverage in this blog:

S 4553 A bill to extend other transaction authority for the Department of Homeland Security. Sen. Peters, Gary C. [D-MI]

Okay, this may be a bit too government geeky even for me, but I will be watching this bill for definitions and language that would specifically include cybersecurity services within the scope of the OTA.

OTA - other transaction authority - A legal instrument (award) issued by the federal government that is not a contract, cooperative agreement or grant. There is no standard set of regulations or template for this award.

Tuesday, July 19, 2022

Review – 1 Advisory and 1 Update Published – 7-19-22

Today, CISA’s NCCIC-ICS published a control system security advisory for products from MiCODUS and updated an advisory for products from Dahua.

MiCODUS Advisory - This advisory describes five vulnerabilities in the MiCODUS MV720 GPS tracker.

Dahua Update - This update provides additional information on an advisory that was originally published on July 12th, 2022.

 

For more details on the advisory and update, including a link to a researcher report and a down the rabbit hole look at the changes in the update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-1-update-published-824 - subscription required.

 
/* Use this with templates/template-twocol.html */