Thursday, March 23, 2023

Review – 6 Advisories Published – 3-23-23

Today, CISA’s NCCIC-ICS published six control system security advisories for products from ProPump and Controls, ABB, Schneider Electric, SAUTER, CP Plus and RoboDK.

Advisories

ProPump Advisory - This advisory describes nine vulnerabilities in the ProPump Osprey Pump Controller.

ABB Advisory - This advisory describes two vulnerabilities in the ABB NE843 Pulsar Plus Controller.

Schneider Advisory - This advisory describes eight vulnerabilities in the Schneider Interactive Graphical SCADA System (IGSS).

SAUTER Advisory - This advisory describes five vulnerabilities in the SAUTER EY-modulo 5 Building Automation Stations.

CP Plus Advisory - This advisory describes an insufficiently protected credentials vulnerability in the CP Plus KVMS Pro.

RoboDK Advisory - This advisory describes an incorrect permission assignment for critical resource in the RoboDK robot development kit.

NOTE: This was a relatively bad day for system owners as four of the six vendors had little or no response towards fixing the identified vulnerabilities.

 

For more details about these advisories, including links to researcher reports and exploits, as well as a description of vendor responses, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-3-23-23 - subscription required.

FDA Sends Medical Device Cybersecurity Notice to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had receive a notice from the Federal Drug Administration (FDA) on “Cybersecurity in Medical Devices: Refuse to Accept Policy for Cyber Devices and Related Systems Under Section 524B of the FD&C Act”. There is no listing for this action in the Fall 2022 Unified Agenda.

The new §524B was added to the Food, Drug, and Cosmetic Act by §3305 (pg 1374), Ensuring Cybersecurity of Medical Devices, of the Consolidated Appropriations Act, 2023 (PL 117-328, HR 2617). Subsection 3305(b) amended 21 USC 331(q) making it unlawful for medical device manufacturers to fail  to comply with any requirement under §524B(b)(2). That paragraph reads:

‘‘(2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—

‘‘(A) on a reasonably justified regular cycle, known unacceptable vulnerabilities; and

‘‘(B) as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks;”

It looks like this notice may be related to that section in relation to ‘§524B’.

Bills Introduced – 3-22-23

Yesterday, with both the House and Senate in Washington, there were 95 bills introduced. Two of those bills will receive additional attention in this blog:

S 914 A bill to establish an energy threat analysis center in the Department of Energy. Risch, James E. [Sen.-R-ID]

S 917 A bill to establish the duties of the Director of the Cybersecurity and Infrastructure Security Agency regarding open source software security, and for other purposes. Peters, Gary C. [Sen.-D-MI]

Wednesday, March 22, 2023

Short Takes – 3-22-23

State of ICS Cybersecurity and Critical Infrastructure: Half empty, Half full, or Stay Focused on the Quest? SCADAMag.Infracritical.com post. Pull quote: “If one looks back one cannot deny that we are not in the same state the community was in 2010.  We are no longer surprised, we know what is going on.  The problem has been recognized and informed measures are being taken and best practices are being made available.  The last bit of work left is to get the decision makers in the policy community to “get it”.  They cannot do it with the IT computer science bias they tend to have.  This gap can only be bridged if they start reaching out for help from the community (and vice versa).  I am not thinking of ICS security solution providers.  They are part of the community of course, but what is needed is for the engineering part to start leveraging their expertise about the physical process so we focus on things like protecting PLC’s and not baby monitors.  As I often say “…It is worrying when the engineering community that is running the power grid, petrochemical plants, and water systems is not represented.””

Emergency Escape Breathing Apparatus Standards. Federal Register FRA notice of proposed rulemaking. Summary: “FRA is proposing to amend its regulations related to occupational noise exposure in three ways. First, in response to a Congressional mandate, FRA is proposing to expand those regulations to require that railroads provide an appropriate atmosphere-supplying emergency escape breathing apparatus to every train crew member and certain other employees while they are occupying a locomotive cab of a freight train transporting a hazardous material that would pose an inhalation hazard in the event of release during an accident. Second, FRA is proposing to change the name of this part of its regulations from “Occupational Noise Exposure” to “Occupational Safety and Health in the Locomotive Cab” to reflect the additional subject matter of this SNPRM and to make other conforming amendments. Third, FRA is proposing to remove the provision stating the preemptive effect of this part of FRA's regulations because it is unnecessary.”  Comment due date – June 20th, 2023.

Hazardous Materials: Information Collection Activities. Federal Register PHMSA 60-day ICR Renewal Notice.

Hazardous Materials Incident Reports - OMB Control Number: 2137-0039,

Cargo Tank Motor Vehicles in Liquefied Compressed Gas Service - OMB Control Number: 2137-0595, and

Inspection and Testing of Meter Provers - OMB Control Number: 2137-0620

Comment due date – May 22nd, 2023.

Review - HR 1367 Introduced – Water System Threats

Earlier this month, Rep Schakowsky (D,IL) introduced HR 1367, the Water System Threat Preparedness and Resilience Act of 2023. The bill would require the EPA to carry out a program to support, and encourage participation in, the Water Information Sharing and Analysis Center (W-ISAC). The legislation would authorize $10-million for FY 2024 and FY 2025 to support this initiative.

Moving Forward

Schakowsky is not a member of the House Transportation and Infrastructure Committee to which this bill was assigned for primary consideration, but she is a member of the House Energy and Commerce Committee to which this bill was assigned for secondary consideration. This means that she may have sufficient influence to see the bill considered in that Committee. Unfortunately, without influence in the T&I Committee, this bill has little chance of moving forward.

I see nothing in this bill that would engender any organized opposition beyond the $10-million authorized. I would expect that there would be some Republican opposition to the additional spending, but support for local water treatment facilities will frequently overcome such philosophical opposition. This bill would probably receive some level of bipartisan support.

Commentary

While the undefined term ‘malevolent acts’ used in §2(b)(4)(B) would certainly seem to include cyber incursions or attacks, I would prefer to see cybersecurity specifically addressed. To that end, I would suggest changing subparagraph (B) to read:

“(B) enhancing the preparedness of community water systems and publicly owned treatment works to identify, protect against, detect, respond to, and recover from cybersecurity threats (as defined in 6 USC 1501), malevolent acts (within the meaning of section 1433 of the Safe Drinking Water Act (42 U.S.C. 300i–2)) or natural hazards.”


For more details about the provision of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-1367-introduced - subscription required.

Bills Introduced – 3-21-23

Yesterday, with the Senate in Washington and the House meeting in pro forma session, there were 60 bills introduced. Five of those bills will receive additional coverage in this blog:

HR 1674 To enhance safety requirements for trains transporting hazardous materials, and for other purposes. Deluzio, Christopher R. [Rep.-D-PA-17]

S 885 A bill to establish a Civilian Cybersecurity Reserve in the Department of Homeland Security as a pilot project to address the cybersecurity needs of the United States with respect to national security, and for other purposes. Rosen, Jacky [Sen.-D-NV]

S 896 A bill to authorize Counter-UAS activities on and off commercial service airport property, and for other purposes. Lee, Mike [Sen.-R-UT] 

S 903 A bill to require the Secretary of the Army to carry out a pilot project to establish a Civilian Cybersecurity Reserve, and for other purposes. Rosen, Jacky [Sen.-D-NV]

S 905 A bill to prescribe zoning authority with respect to commercial unmanned aircraft systems and to preserve State, local, and Tribal authorities and private property with respect to unmanned aircraft systems, and for other purposes. Lee, Mike [Sen.-R-UT] 

Tuesday, March 21, 2023

Short Takes – 3-21-23

Lots of cyber security companies are going to fail this year. Twitversation. Don’t know a lot about Andrew, but this sounds prescient. Pull quote: “All of those companies at the RSA and Blackhat vendor hall with gigantic booths that claim to solve problems that you as a security person ask constantly yourself: "is this really a problem???" have the largest targets on them and will represent the majority of companies that fail. The failures will start in earnest approximately 12 months after it became clear that money was expensive again (12 months from summer of 2022, which puts the crunch time at this summer). The failures will likely continue for at least one full year and slow down around summer of '24.”

Director Easterly Announces New Members to Join CISA's Cybersecurity Advisory Committee. CISA.gov press release. Pull quote: ““I am thrilled to welcome our newest members, who bring a wealth of experience from across government and industry,” said CISA Director Jen Easterly. “Chosen for their deep expertise in critical infrastructure, cybersecurity, and governance, these members will add important new perspectives to the CSAC’s work, particularly given this year’s additional focus on corporate cyber responsibility, technology product safety, and efforts to raise the cyber hygiene baseline of ‘target rich-cyber poor’ entities like hospitals, K-12 school districts, and water utilities. The insight and counsel to date from our existing members have been instrumental in our evolution as America’s Cyber Defense Agency, and I couldn’t be more excited for tomorrow’s meeting with our new members.””

Journalist opens USB letter bomb in newsroom. BBC.com article. Which would be worse in an USB attack, a small bomb or a worm/trojan? Pull quote: “He [Lenin Artieda] said the explosive device looked like a USB drive. He plugged it into his computer and it detonated.”

A Different Kind of Pipeline Project Scrambles Midwest Politics. NYTimes.com article. Pull quote: “But opponents are concerned about property rights and safety, and are not convinced of the projects’ claimed environmental benefits. They have forged unlikely alliances that have blurred the region’s political lines, uniting conservative farmers with liberal urbanites, white people with Native Americans, small-government Republicans with climate-conscious Democrats.”

Guidance for Implementing Federal Rotational Cyber Workforce Program. CHCOC.gov guidance document. Summary: “The Program allows for 6-month to 1-year interagency details of cyber employees to cyber rotations where they can improve and develop knowledge and skills to not only support their own professional growth but also bring new skills back to their home agency. The Program will help Federal agencies continue to enhance their cyber workforce by developing critical cyber skills and creating environments where employees have ongoing learning and development opportunities. Such rotational opportunities align with an objective in the White House National Cybersecurity Strategy to strengthen the Federal cyber workforce by developing and retaining talent. Cyber rotations help advance career opportunities and support employee engagement, satisfaction, and retention.”

Railroads pilot AskRail data to increase first responder information access. ProgressiveRailroading.com article. Pull quote: “After the Feb. 3 Norfolk Southern Railway train derailment in East Palestine, Ohio, AAR learned that lack of cell phone service and other challenges made using AskRail difficult in the early hours of the response, said AAR President and CEO Ian Jefferies in a press release.”

 
/* Use this with templates/template-twocol.html */