Tuesday, May 10, 2016

ISCD Updates Three CFATS FAQ Responses – 05-10-16

Today the DHS Infrastructure Security Compliance Division (ISCD) updated the responses for three Frequently Asked Questions (FAQ) on the CFATS Knowledge Center. All three FAQs deal with Chemical-Terrorism Vulnerability Information (CVI) issues.

The three FAQ are:


Recently, ISCD changed the URL for the actual CVI training web site. This is reflected in the change to FAQ #516. As has been the case for a couple of years now the printed link shown in the FAQ is not the actual URL for the training web site; that URL is https://cvi.dhs.gov/dana-na/auth/url_61/welcome.cgi. Unfortunately, the CVI Training web page (linked to in FAQ #1606) has yet to be updated with the correct URL to the actual training site.

Both FAQ #1606 and #1763 deal with the need for synchronizing ones CSAT login and CVI authorization number. This is needed to allow access to CVI information available on the CSAT tool. You can either do this when you finish the CVI training or when you sign into the CSAT web site.

FAQ #1763 includes the very important note (and it should probably have been included in the response to FAQ #1606):

“Note: The email address from the CVI Authorized User training record must match the email address associated with the CSAT User Account in order to complete synchronization between the CVI and CSAT accounts.”

For people that may have moved around since they completed their CVI training this may cause something of a problem. There are two ways to resolve this, re-take the CVI training using the newer email address, or contacting the CFATS Help Desk ((866) 323-2957) for assistance.


Bills Introduced – 05-09-16

With just the Senate in session, the House returns today, there were a dozen bills introduced yesterday. Of those one may be of specific interest to readers of this blog:

S 2905 A bill to require the President to develop a policy for determining when an action carried out in cyberspace constitutes an act of war against the United States, and for other purposes. Sen. Rounds, Mike [R-SD]


This bill is almost certainly political grandstanding, but it is does have potentially serious cybersecurity implications if it does move forward. It will be interesting to see how the bill is actually worded.

Monday, May 9, 2016

Committee Hearings – Week of 05-08-16

Both the Senate and House will be back in Washington this week, but it looks like the committee hearing schedule is fairly light. The National Defense Authorization Act is being looked at in both the House and Senate. That is the only hearing topic this week of potential specific interest to readers of this blog:

The Senate Armed Services Committee and its substituent subcommittees will be holding closed door meetings this week marking up the Senate version of the NDAA. The committee draft being marked up has not yet been released to the public.

The House Rules Committee has set a Wednesday deadline for the submission of proposed amendments to HR 4909, the House version of the NDAA that was reported last week. That deadline is Wednesday which may mean that the Committee will meet late this week to formulate the rule for the House floor consideration of the bill. That will probably take place next week.

Sunday, May 8, 2016

HR 5117 Introduced – DIGIT Act

Last month Rep. Paulsen (R,MN) introduced HR 5117, the Developing Innovation and Growing the Internet of Things (DIGIT) Act. There are many similarities between this bill and S 2607 as it was introduced, but it may serve as a companion bill to S 2607 as it was amended in the Senate Commerce, Science and Technology Committee on April 27th, but a full record of that hearing is not yet publicly available.

New Requirements


The main difference between this bill and the original version of S 2607 is that this bill would require the Department of Commerce Steering Committee to do a more detailed and widespread look at federal efforts that would support the wide spread deployment of the Internet of Things than just the specific requirement to look at spectrum availability concerns. The additional areas that the Steering Committee would be required to look at include {§4(e)}:

• The identification of any Federal regulations, statutes, grant practices, programs, budgetary or jurisdictional challenges, and other sector-specific policies that are inhibiting or could inhibit the development of the Internet of Things;
• Policies or programs that promote or are related to the privacy of individuals who use or are affected by the Internet of Things;
• Policies or programs that may enhance the security of the Internet of Things;
• Policies or programs that may protect users of the Internet of Things;
• Policies or programs that may encourage coordination among Federal agencies with jurisdiction over the Internet of Things; and
• Any international proceeding, international negotiation, or other international matter affecting the Internet of Things to which the United States is or should be a party.

Moving Forward


Paulsen is not a member of the House Energy and Commerce Committee to which the bill was assigned for consideration. His co-sponsor, Rep. Welch (D,VT), is a relatively junior member of that Committee, so there is an outside chance that this bill could receive consideration in that Committee.

S 2607 is apparently moving forward in the Senate, but it is too early to tell if that bill will make it to the floor of the Senate. And it is way too early to tell if this bill is moving forward. Having said that, neither version of the bill has anything that would alarm businesses. This new version of the bill addresses privacy and security concerns so those objections to the bill appear to have been assuaged. If the bill did make it to the floor of either body, it would probably be adopted with little or no debate, no amendments and probably a voice vote in the House and not even that level of formality in the Senate.

Commentary


While this bill addresses many of the concerns that I expressed earlier about S 2607, it looks like the crafters of the bill were making a conscious effort to short out any concerns about the security issues associated with IOT deployments. The failure to include DHS in the Federal Working Group cuts out the one agency that is responsible for tracking cybersecurity issues and is responsible for regulating cybersecurity issues in many critical infrastructure organizations.

Interestingly, the two committees with DHS oversight and shared concerns about cybersecurity have also been shut out of consideration of these bills. The lack of inclusion of DHS in the Federal Working Group may have been designed to keep the two DHS oversight committees out of the picture. In any case it looks like there may be some inter-committee competition here that could further confuse the issue.

Having said all of that the issue of available bandwidth addressed in both bills is important and deserves consideration. The whole basis for the utility of IOT is the communication with millions of standalone processors with other processors and networks. While some of these connections will be wired, most will be wireless connections over a limited amount of available bandwidth.

Reliable wireless communication requires either time or frequency separation of signals. As more and more devices are sending more and more signals over the limited available bandwidth there are going to be communications issues that arise. Of course, IOT is not the only new technology where this bandwidth issue raises its ugly head. The railroads had a similar issue when they were designing their Positive Train Control (PTC) systems. And bandwidth is going to be an issue with vehicle-to-vehicle communications and vehicle-to-infrastructure communications.

Some bandwidth can be made available when new digital communications technologies replace older analog communications. We saw this with the rise of digital TV; there old broadcast frequencies were able to carry three or more TV signals when converted to digital broadcast. That will help, but it will not be the solution to this problem as the increase in the number of broadcast nodes is rising much faster than the available bandwidth can handle.

What we are probably going to have to see is the establishment of some sort of local mesh networks that includes of communications switching capabilities that allow for time separation of signals. I’m not sure that this is going to be something that the government is going to be able to regulate; just look at the political issues related to broad-band regulations.


In any case, a federal working group looking at the communications issues associated with the IOT should be a good thing. I’m not sure that there is any real need for federal agencies to do anything else to ‘promote’ the use of IOT; it appears that IOT is spreading quite well on its own.

HR 4909 Reported in the House – NDAA

Yesterday the House Armed Services Committee published their report on HR 4909. While the original bill did not contain any specific cybersecurity language, the bill revised in numerous subcommittee and Committee hearings did add a number of cybersecurity related provisions and the Committee Report adds additional cybersecurity discussions and requirements.

Added Cybersecurity Provisions


A number of new cybersecurity provisions were added to this bill. They include:

Sec. 231. Strategy for assured access to trusted microelectronics
Sec. 232. Pilot program on evaluation of commercial information technology.
Sec. 911. Establishment of unified combatant command for cyber operations.
Sec. 1631. Special emergency procurement authority to facilitate the defense against or recovery from a cyber-attack.
Sec. 1632. Change in name of National Defense University’s Information Resources Management College to College of Information and Cyberspace.
Sec. 1633. Requirement to enter into agreements relating to use of cyber opposition forces.
Sec. 1634. Limitation on availability of funds for cryptographic systems and key management infrastructure.

None of these cybersecurity requirements is going to have a significant direct impact on civilian cybersecurity activities and none of them directly address control system security issues. The only one that comes close is §231, which continues and expands the DOD reporting requirements on the issue of supply chain security for microelectronics. This will only directly affect DOD contractors, but ultimately could have an effect on the whole supply chain security environment down the road.

Section 231 would require DOD, after conducting studies and issuing reports to Congress, to issue a directive by September 30th, 2020 that would describe how DOD entities would “access assured and trusted microelectronics supply chains for Department of Defense systems” {§231(d)}. The key word here is ‘trusted’ which is defined as “the ability of the Department of Defense to have confidence that the microelectronics function as intended and are free of exploitable vulnerabilities, either intentionally or unintentionally designed or inserted as part of the system at any time during its life cycle” {§231(f)}.

Discussions in the Report


As we see with any authorization or spending bill report, there are a number of discussions in the report where the Committee provides additional guidance and directives to the Department of Defense. The discussion that may be of interest to readers of this blog include:

• Cellular and broadband signals exploitation (pg 79);
• Counter-unmanned aerial systems roadmap (pg 80):
• Non-destructive counterfeit parts detection tools (pg 89);
• Social media analysis cell (pg 91);
• National Guard Cyber Protection Teams (pg 135):
• Cyber Science Education at the Service Academies (pg 147);
• Wassenaar Arrangement Impacts to the Department of Defense (pg 221); and
• Facility Industrial Control Systems (pg 374)

The Committee encourages SOCOM to continue their efforts to “efforts to utilize commercial technology to conduct cellular and broadband survey, active interrogation, and directional finding capabilities from unmanned aerial systems”. While this technology certainly has ongoing military application in counter-terrorism operations, the potential use of the same technology in civilian law enforcement operations raises all sorts of interesting controversies.

The threat to forces from adversaries employing small unmanned aerial systems continues to grow. While the Army is conducting some anti-UAS research, the Committee is directing “the
Secretary of Defense to develop a technology roadmap for addressing gaps to counter the potential threats from terrorist or state actor uses of small UAS technology, with an emphasis on technology to support tactical level units, and fixed, high-value defense assets”. The value of such technology to protect critical infrastructure facilities in the homeland should also be studied.

The concern with counterfeit parts is apparently high on the Committee’s task list. They have encouraged the Department to “evaluate the need to identify or develop best-of-breed, non-destructive counterfeit parts detection tools that it can use, or that could be made available to defense industrial base suppliers, to support the overall mission of ensuring the integrity of electronic components of defense weapon systems”. Again, this type technology would have widespread applications throughout the electronics sector.

The Committee has increased the budget of the Joint Concept Technology Demonstration program by $10 Million to look into the “application of new technologies or concepts in this space, especially in the use of ever-increasing data from social media sources that can be leveraged to amplify and inform other warning, force protection and battlespace awareness activities of the Department of Defense”. Again, a potentially valuable military tool with uncomfortable applications in the civilian sector.

The brief discussion of the National Guard cyber protection teams (CPT) looks at funding issues and questions why the Army teams have not been integrated into the Cyber Command operational planning. They direct the DOD to provide additional information in the FY 2018 funding request.

In a very short discussion about cybersecurity training the Committee concludes by encouraging
“the Department to recognize the importance of cyber education within each of the U.S. military service academies and actively promote cyber sciences education and training within the service’s respective curriculum”.

Another Wassenaar report and briefing; the Committee “believes restricting export of these technologies may negatively impact use of such products for national security purposes”.

Military Industrial Control Systems


For the first time that I can remember, this Committee Report specifically address the security of industrial control systems in the military realm. It is a rather limited look, to be sure, in that it only addresses “industrial control systems integrated into systems and equipment such as air conditioners, utility meters, and other programmable controllers”.

The report applauds current efforts “to implement and promote secure procedures, adopt best government practices, and revise Department of Defense Unified Facility Criteria and Unified Facility Guide Specifications to address the cybersecurity vulnerabilities of industrial control systems”. The Committee would like to see these efforts expanded; encouraging “the Department’s cybersecurity community to look more closely at these classes of vulnerabilities and how to modify tactics, techniques, and procedures to better position the cyber mission forces to deal with new and emerging threats proactively”.

Moving Forward



This is one of those ‘must pass’ bills that needs to be passed every year. It is likely that this bill will be considered by the House in a full-blown debate and amend process later this month. The Senate will take up their own version of the bill (not yet introduced) and a conference committee will meet to iron out the differences. If past years are any indicator, final consideration of the bill will not take place until after the election in November.

Friday, May 6, 2016

NIST Announces Cybersecurity Commission Meeting – 5-16-16

Today the National Institute of Standards and Technology published a meeting notice in the Federal Register (81 FR 27414-27415) for a public meeting of the Commission on Enhancing National Cybersecurity. The meeting will take place in New York City on May 16th, 2016. The Commission was established by Executive Order 131718.

The agenda for this meeting of the Commission includes:

• Panel discussion on the cybersecurity challenges and opportunities in the finance sector;
• Panel discussion on the cybersecurity challenges and opportunities in the insurance sector; and
• Panel discussion on cybersecurity research and development in the finance sector.

As with the earlier meeting of the Commission, there will be a brief period reserved for public comments. Written comments on the topics listed may be submitted to the Commission. The meeting notice only provides a snail mail address for submitting comments, but there is an email address (cybercommission@nist.gov) provided on the Commission web site.


That web site also provides a list of the Commissioners, something that was missing the last time that I mentioned the Commission. As I suspected, they are all Very Important People. I hope that they have hired a good staff to actually get the work done in time for their December report.

HR 5069 Introduced – Cybersecurity Reporting

Last week Rep. McDermott (D,WA) introduced HR 5069, the Cybersecurity Systems and Risks Reporting Act. The bill would modify the Sarbanes-Oxley (SOX) Act of 2002 (15 USC Chapter 98) adding cybersecurity reporting requirements to the financial reporting requirements of that Act.

Definitions


Section 2 of the bill starts out by modifying some existing definitions in the SOX Act. The definition of audit {15 USC 7201(a)(2)} is modified by adding ‘and information systems’ after the words ‘financial statements’. In the term ‘audit committee’ {§7201(a)(3)} the bill would replace ‘financial reporting processes’ with ‘financial, and cybersecurity systems reporting processes’. Finally, in §7201(a)(3), the definition of ‘professional standards’ would be modified by adding ‘cybersecurity systems standards and practices,’ after the ‘quality control policies and procedures,’.

Three new definitions would then be added to the SOX Act list of definitions. The new terms would be:

• Information System;
• Cybersecurity System; and
• Cybersecurity Risk

The key definition here is ‘information system’. It is defined this way {new §7201(a)(18)}:

“The term ‘information system’ means a set of activities, involving people, processes, data, or technology, which enable the issuer to obtain, generate, use, and communicate transactions and information to maintain accountability and measure and review the issuer’s performance or progress towards achievement of objectives.”

Cybersecurity Requirements


The bill goes on to modify three additional sections of the SOX Act where it conflates cybersecurity with financial systems. For example, it changes the title of §7241 to “Corporate responsibility for financial reports and information systems” [added verbiage] and makes internal changes adding requirements for the newly listed ‘principal cybersecurity systems officer’.

Again in §7262, the new title is “Management assessment of internal controls and information systems” [added verbiage] with added instructions for “adequate internal control and cybersecurity systems structures and procedures for financial and information systems reporting”. The bill would essentially duplicate current financial reporting requirements for information systems.

Finally, in §7265, the new title is “Disclosure of audit committee financial and cybersecurity systems experts” [added verbiage]. The new language would require the Securities and Exchange Commission (SEC) to consult with the Secretaries of Homeland Security and Commerce to come up with an appropriate definition of ‘cybersecurity systems expert’.

Moving Forward


McDermott is not a member of the House Financial Services Committee; the committee to which this bill was assigned for consideration. This makes it unlikely that this bill will receive consideration in that Committee. There is an outside chance that this bill could be offered as a floor amendment to the Financial Services spending bill, but it is unlikely that it would survive a vote on the floor. Corporate opposition to the huge expansion of the SOX Act requirements proposed in this bill would be fierce.

Commentary


Ignoring for the moment the question of just how effective the SOX Act has been in preventing financial irregularities in corporate finances, conflating cybersecurity issues with financial governance seems to be counter-productive. Adding corporate cybersecurity governance requirements to the SOX Act makes a certain amount of sense, but they would probably have been more effective if they had been added as a new and separate section of the Act.

Of course, the bigger issue here (as elsewhere in cybersecurity regulation) is where would the SEC come up with the trained personnel to properly evaluate (and ultimately investigate) cybersecurity governance. Not only would these people need a background in cybersecurity (of which there is already an ever-growing mismatch between positions and trained personnel), but they would also have to have a background (or training) in managing corporate cybersecurity programs. It will be a long time coming for there to be many folks with that background available for government service.


Finally, it absolutely astounds me that this bill would so specifically restrict cybersecurity governance to IT and financial systems. While there are certainly more companies that are at risk for financial harm to attacks on these systems, there are still a very large number of companies (and that includes some very large companies) whose financial stability relies on the consistent operation of their industrial control systems. Ignoring that set of cybersecurity risks in a cybersecurity governance regulation system just makes no sense.
 
/* Use this with templates/template-twocol.html */