Wednesday, February 4, 2015

ISCD Updates CFATS Fact Sheet

This morning the folks at DHS Infrastructure Security Compliance Division (ISCD) published the latest CFATS update covering data from January. The number of approved and authorized site security plans at CFATS facilities continues to increase.
  



The number of covered facilities continues to decline and ISCD still fails to provide any composite data on the reasons for facilities being removed from program coverage.



The only part of this fact sheet that actually changes from month to month is the sidebar that includes the statistics. The bulk of the sheet is verbiage that describes the program basics. Until December the lack of change in that verbiage was not a real issue. But with the passage of HR 4007 last December there are a number of impending changes to the CFATS program. It would be nice if ISCD were to use this update to explain some of those changes, particularly those that effect whether or not the currently approve SSPs will have to be re-approved.

Tuesday, February 3, 2015

ICS-CERT Published Two Siemens Advisories

Today the DHS ICS-CERT published two control system advisories from products from Siemens. Both advisories are related to system communications services. The affected products are Ruggedcom WIN devices and SCALANCE-X switches.


This advisory describes multiple vulnerabilities in Ruggedcom WIN devices. The vulnerabilities were reported by IOActive in a coordinated disclosure. Siemens has produced firmware updates that mitigate these vulnerabilities but there is no indication that IOActive has confirmed the efficacy of those updates.

The vulnerabilities are:

● Improper authentication - CVE- 2015-1448;
● Buffer overflow - CVE- 2015-1449; and
● Storing passwords in a recoverable format - CVE- 2015-1357

ICS-CERT reports that a relatively unskilled attacker with network access to the devices could exploit these vulnerabilities to perform administrative actions over the network or execute arbitrary code. The Siemens advisory notes that an attacker must be able to access the log files to exploit the third vulnerability.

SCALANCE Advisory

This advisory describes an apparently self-reported user impersonation vulnerability in the SCALANCE X-200IRT Switch Family. Siemens has developed a firmware  update that mitigates the vulnerability.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to impersonate a legitimate user on the system. The Siemens advisory notes that a successful exploit requires network access while a legitimate user is signed into the switches’ web interface.


NOTE: It is taking much less time for the CVE links in the ICS-CERT advisories to point to active pages. It used to take a day or two (business days). The CVE’s in both advisories were active this evening. That may be because they were originated yesterday. Still it is nice to see live links being provided instead of early links.

Monday, February 2, 2015

Two Homeland Security Bills Pass in House

As expected the House passed two homeland security related bills that I discussed yesterday; HR 361, the Medical Preparedness Allowable Use Act, and HR 623, the Social Media Working Group Act of 2015. Both bills passed with substantially bipartisan votes; HR 361 – 377 to 2, and HR 623 – 328 to 51. The no votes were predominantly (all but one) Republican.

As I mentioned in the earlier posts these two bills should also pass in the Senate if they get to the floor. During the last session Sen Reid (D,NV) made little effort to bring bipartisan bills like this to floor of the Senate. In many ways this contributed to the ‘do nothing’ label that was laid upon the 113th Congress. The bulk of the number of bills that any Congress passes is made up of this type of bill.


While major legislation also languished because the two houses were controlled by different parties with different agendas, the numerical analysis of the number of bills passed was seriously affected by the leadership’s failure to bring bipartisan bills to a vote. It will be interesting to see if the leadership of the 114th Congress takes the same tack.

Hazardous Materials Information Advisory Committee

As I previously noted Rep Lipinski (D,IL) introduced HR 505, the Developing Standards for Electronic Shipping Papers Act of 2015. This bill would require the Secretary of Transportation to form a Hazardous Materials Information Advisory Committee (HMIAC) to develop interim voluntary standards for hazardous materials electronic shipping papers while DOT is going through the rule development process outlined in MAP 21 (49 USC 5121 Note).

The Congressional findings section of the bill (§2) notes that §33005 of the MAP 21 legislation (PL 112-141) passed in 2012 required DOT to undertake a number of pilots of possible electronic shipping papers and then to develop appropriate rulemakings to institute national standards. According to the bill the pilots are not scheduled to be completed until October of this year meaning that it will be a while (years?) before a national standard is developed.

The HMIAC described in this bill would be tasked with developing an interim voluntary standard. It would be given 120 days to publish this standard. This development would include {§4(c)}:

● Development of a voluntary standard for the use of electronic shipping papers until a rulemaking has been completed;
● Establishment of a standardized curriculum for training first responders and enforcement officials in the use of electronic shipping papers and other alternative means of communicating hazardous materials information;
● Providing recommendations and best practices for the use of electronic shipping papers by first responders in varying circumstances and locations;
● Providing recommendations and best practices to assist persons transporting hazardous materials in commerce in implementing electronic shipping papers; and
● Assessing potential issues during deployment phases, including first responder training, technology procurement issues and budget limitations, and biometrics.


Congressman Lipinski is a fairly senior Democrat on the House Transportation Committee so this bill cannot be completely discounted, but it will be an uphill fight to get this bill considered by the Committee. There is nothing that I see in the bill that would necessarily cause any anguish for the Republican leadership so this bill would stand a good chance of passing in both the House and Senate if it were brought to the floor.

Sunday, February 1, 2015

Committee Hearings – Week of 2-1-15

The number of hearings being conducted this week is on the increase, especially on the Senate side of the building. There are three hearings that may be of specific interest to the readers of this blog; one physical security and one cybersecurity.

Facility Access

The Transportation Security  Subcommittee of the House Homeland Security Committee will be holding a hearing on Tuesday on “A Review of Access Control Measures at Our Nation’s Airports.” The current witness list includes:

Mr. Mark Hatfield  - TSA, DHS
Mr. Gary D. Perdue - FBI
Ms. Sharon Pinkerton – Airlines for America
Mr. Miguel Southwell – Hartsfield-Jackson Atlanta International Airport

Airports share a common problem with large chemical facilities, how to control access through multiple gates in a very long perimeter. There will not be a lot of specifics about security measures discussed here, but the questioning may give some insight on how the new Congress will be looking at security issues.

Cybersecurity Issues

The Senate Commerce, Science and Transportation Committee will be holding two hearings this week on cybersecurity issues. The first hearing will be on Wednesday and it will look at “Building a More Secure Cyber Future: Examining Private Sector Experience with the NIST Framework”. The second hearing will be on Thursday on “Getting it Right on Data Breach and Notification Legislation in the 114th Congress”. There are no witness lists currently published for either hearing.

It will be interesting to see how the conflict between the Commerce Committee and the Senate Homeland Security and Governmental Affairs Committee will play out in the Republican controlled Senate. One of the problems in the last couple of sessions in the Senate that lead to very little actual action on cybersecurity issues was the differing outlooks of the two committees.

Neither of these hearings will specifically address control system issues. The big picture in Congress (for the immediate future at least) will be focused on IT issues and specifically those dealing with the compromise of personal information. Any legislative proposals will reflect that focus, though there may be minor, after-thought language expanding coverage to control systems. This may cause more problems than it solves for the control system security community, we will just have to wait and see.

On the Floor

As I mentioned in two earlier posts today, there are two bills coming to the floor of the House that may be of specific interest to readers of this blog: HR 361 and HR 623. Both will be considered on Monday under the suspension of the rules provisions. This means that the House leadership expects these bills to gain enough bipartisan support to sustain a 60% vote required for passage under these rules. I expect that the votes will be much closer to 90% in favor of these two bills.


The Senate is beginning to look at HR 240, the FY 2015 DHS spending bill that passed in the House last month. There will be a first cloture vote on Monday that could lead to the actual debate on the bill. Watching the recent action on S1, the Keystone pipeline bill, I expect that we will see vigorous debate with a number of amendments offered and voted upon. There is a February 27th deadline to get a bill to the President and we may see a short term continuing resolution while the Senate works on amending HR 240 and the two houses of Congress work out their differences on that bill.

HR 623 Introduced – Social Media Group

On Friday, during a proforma session of the House, Rep. Brooks (R,IN) introduced HR 623, the Social Media Working Group Act of 2015. This bill would require the Secretary of DHS to establish a working group to advise on the use of social media. This is nearly identical to HR 4263 that was passed in the House last year, but was not taken up by the Senate.

The bill would add §318 to Title III of the Homeland Security Act of 2002 (6 USC Subchapter III). It would require the Secretary to establish the working group under the direction of the Under Secretary of Science and Technology. The group would “provide guidance and best practices to the emergency preparedness and response community on the use of social media technologies before, during, and after a terrorist attack or other emergency” {§318(b)}.

There is an important difference between this bill and the one introduced in the last session. It corrects a problem that I identified in my post about that bill in that it adds the words “or other emergency” in the description of the purpose of the use of social media. Whether or not this would have any practical effect on the guidance produced by the working group is probably a moot point, but it may have an effect on the dissemination of the guidance.

The one short coming of this bill is that there is no specific mechanism described for sharing this information with the emergency response community. The working group is required to report annually to Congress {§318(g)}, but those reports are typically hard for the public to access and are seldom pushed out to the affected communities.


This bill is already scheduled for a vote on the floor of the House on Monday. I expect that it will pass with a largely bipartisan vote. The chances of it being taken up in the Senate are much better this session. It will almost certainly be taken up there under their ‘unanimous consent’ process.

HR 361 Introduced – Medical Preparedness Grants

HR 361, the Medical Preparedness Allowable Use Act, was introduced by Rep. Bilirakis (R­FL). It would add medical preparedness as one of the areas that various homeland security grant programs could be used to fund.  I missed this bill when it was first introduced on January 14th because of the wording of the title that was initially used.

The bill amends 6 USC 609 by adding §609(a)(10). It adds to the list of allowable uses of Urban Area Security Initiative (§604) and State Homeland Security Grants (§605). It specifically allows for the use of these funds for the purpose of “enhancing medical preparedness, medical surge capacity, and mass prophylaxis capabilities, including the development and maintenance of an initial pharmaceutical stockpile, including medical kits, and diagnostics sufficient to protect first responders, their families, immediate victims, and vulnerable populations from a chemical or biological event”.


No additional funding is provided for grants under this addition. That means that this is a motherhood and apple pie bill that will almost certainly pass if it makes it to the floor of the House and Senate. It is currently scheduled for a House floor vote on Monday under suspension of the rules.
 
/* Use this with templates/template-twocol.html */