Wednesday, January 11, 2017

OMB Approves PHMSA Oil Volatility ANPRM

On Monday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved for publication an advanced notice of proposed rulemaking (ANPRM) submitted by DOT’s Pipeline and Hazardous Material Safety Administration. PHMSA is considering this rulemaking in response to a petition for rulemaking from the Attorney General of the State of New York.

The ANPRM that will probably be published in the Federal Register in the coming weeks will see information from the public and the regulated community on a variety of questions related to the appropriateness and use of Reid Vapor Pressure (RVP) testing and establishing a maximum RVP standard for shipping crude oil by rail.

The timing of this rulemaking may make for an interesting look at how the Trump Administration will look at the regulatory process for chemical transportation safety. It is generally assumed that the new administration will be very limited in its use of the regulatory process, rather letting ‘market forces’ control how businesses conduct their operations.

This ANPRM is likely to be published before the upcoming inauguration of Donald Trump as President. The public comment period will thus be started under the Obama Administration, but it will be Trump’s DOT Secretary (probably Elaine Cho) who makes the determination of whether to proceed with this rulemaking process or deny the petition for rulemaking.


Those political questions aside, there is still the technical question of the appropriateness of RVP sampling and testing. As I pointed out in an earlier blog post the results of RVP testing can  be extremely variable based upon differences in the sampling regime. If a vapor pressure standard is needed for crude oil shipments (and that is a political question), it would seem to be important that the method used to obtain that information should be the most reliable and replicable method. Hopefully, PHMSA will address this in their request for information in the ANPRM.

Monday, January 9, 2017

Committee Hearings – Week of 1-8-17

This week both the House and Senate will be in Washington, but there will only be a limited number of hearings being held, mainly focusing in the Senate on confirmation hearings. Two of those this week may be of specific interest to readers of this blog; confirmation hearings of DHS and DOT Secretaries.

DHS Secretary


On Tuesday, the Senate Homeland Security and Governmental Affairs Committee will be holding a hearing on the confirmation of General John F. Kelly, USMC (Ret.) to be the Secretary of the Department of Homeland Security. I suspect that we will be hearing some talk about cybersecurity matters, but it will be short on details.

DOT Secretary



On Wednesday, the Senate Commerce, Science and Transportation Committee will be holding a hearing on the confirmation of Elaine Chao to be the Secretary of the Department of Transportation. I suspect that there will be some mention of vehicle automation and chemical transportation safety issues, but again no details.

Thursday, January 5, 2017

ICS-CERT Published Two Rockwell Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Rockwell Automation. Both advisories were previously published on the NCCIC Portal library (formerly US-CERT Secure Portal) to provide critical infrastructure owners time to implement mitigation measures before the vulnerabilities were publicly reported.

MicroLogix Advisory


This advisory describes two vulnerabilities in the Rockwell Allen-Bradley MicroLogix 1100 and 1400 programmable logic controller (PLC) systems. The vulnerabilities were reported by Alexey Osipov and Ilya Karpov of Positive Technologies. Rockwell has developed new firmware versions to mitigate the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Clear-text transmission of sensitive information - CVE-2016-9334; and
• Incorrect permission assignment for critical resource - CVE-2016-9338;

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to gain unauthorized access to affected devices, as well as impact the availability of affected devices.

Logix Advisory


This advisory describes a buffer overflow vulnerability in the Rockwell Automation Logix5000 Programmable Automation Controller product line. The vulnerability is apparently self-reported. Rockwell has developed new firmware versions to mitigate the vulnerability.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to cause a denial of service at a controller or execute code on a target controller.

BIS Extends Russian Cyber Sanctions

Yesterday the DOC’s Bureau of Industry and Security (BIS) published a final rule in the Federal Register (82 FR 722-725) adding the five organizations identified in the President’s recent amendment of EO 13694 to the Entity List of the Export Administration Regulations (EAR). This rule “imposes on these entities a license requirement for exports, reexports, or transfers (in-country) of all items subject to the EAR and a license review policy of presumption of denial”.


There were some comments made about the EO 13694 actions having little impact on the identified personnel and organizations because they were unlikely to have any assets in the US that could be frozen. This action by the BIS could potentially have more practical effects because it would affect third party vendors dealing with the organizations if they were attempting to sell US sourced items covered by the EAR to those organizations.

Wednesday, January 4, 2017

ICS-CERT Updates Advisory and Links to FDA Guidance

Today the DHS ICS-CERT published an update for a control system security advisory initially published and quickly updated in November, 2016 for products from CA Technologies. They also provided a link to a new FDA medical-device cybersecurity guidance document.

CA Technologies Update


The update provides new information about the affected versions and the version to which the system must be updated to mitigate the reported vulnerability. The newest version of the CA Technologies security notice reports that the previously reported upgrade did not adequately address the vulnerability reported in the ICS-CERT Advisory; the latest version does mitigate the vulnerability.

The ICS-CERT advisory continues to ignore the two medium rated vulnerabilities (CVE-2016-9164 and CVE-2016-9165) that were reported by CA Technologies.

FDA Guidance


The ICS-CERT landing page provides click-through links to the FDA Voice blog-post on the publication of the final guidance document for the postmarket management of medical device cybersecurity.

The guidance document includes an interesting discussion (pgs 15-17) of risk management for cybersecurity risk with examples of how a manufacturer would use the recommended techniques in some well-defined situations. A similar discussion (pgs 18-21) addresses mitigating and reporting vulnerabilities.

The big shortcoming in the guidance is the lack of a vulnerability coordinating mechanism to ensure effective communication between cybersecurity researchers and manufacturers. While the document does recommend that manufacturers should adopt “a coordinated vulnerability disclosure policy and practice that includes acknowledging receipt of the initial vulnerability report to the vulnerability submitter” (pg 18), the FDA does not attempt to establish an organizational office to mediate disagreements between researchers and manufacturers about the existence, seriousness, or mitigation of reported vulnerabilities.

Having said that the FDA has set a pretty rigorous reporting requirement under the existing requirements of 21 CFR 806. An exception to those requirements is made when the following four criteria are met (pg 22):

• There are no known serious adverse events or deaths associated with the vulnerability;
• As soon as possible but no later than 30 days after learning of the vulnerability, the
manufacturer communicates with its customers and user community regarding the
vulnerability, identifies interim compensating controls, and develops a remediation
plan to bring the residual risk to an acceptable level;
• As soon as possible but no later than 60 days after learning of the vulnerability, the
manufacturer fixes the vulnerability, validates the change, and distributes the
deployable fix to its customers and user community such that the residual risk is
brought down to an acceptable level; and
• The manufacturer actively participates as a member of an ISAO that shares vulnerabilities and threats that impact medical devices, such as NH-ISAC (see section IX) and provides the ISAO with any customer communications upon notification of its customers.

The only problem with the reporting requirements under §806 is that they only apply when ‘corrections’ or ‘removals’ of a device are required. Neither the definition of ‘correction’ {§806.2(d)} or ‘removal’ {§806.2(j)} specifically apply to software updates or revisions. The FDA continues to assume that the undefined terms ‘repair’, ‘modification’, or
‘adjustment’ cover changes to software. That might not stand up in court.


Oh, and by the way, each page of the document includes a header that states “Contains Nonbinding Recommendations”. This is just a guidance document, not a regulation. Remember that when they hook you up to a device connected to the wall by a network cable.

Bills Introduced – 1-3-17

Yesterday was the first day of the 115th Congress. As expected there were a large number of bills (274) introduced in the House and a few (20) in the Senate. Many of these bills are repeats from previous sessions of congress and will continue to see little or no action. Of those introduced yesterday, three may be of specific interest to readers of this blog:

HR 54 To require the Secretary of Homeland Security to conduct a study on the feasibility of establishing a Civilian Cyber Defense National Resource in the Department of Homeland Security. Rep. Jackson Lee, Sheila [D-TX-18]

HR 59 To enhance the security of chemical facilities and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 150 To direct the Attorney General to create a special reward program for individuals providing information leading to the apprehension and conviction of persons committing offenses under section 1030 of title 18, United States Code, and for other purposes. Rep. Green, Al [D-TX-9]

I suspect that HR 54 will bear some semblance to HR 60 introduced (and died) in the 114th Congress. Since the current title contains no reference to ‘National Guard’, it would seem that Ms. Lee may have changed her mind about the military nature of the organization.

HR 59 will also probably bear some resemblance to HR 54 from the last session in that it will be an essential re-write of the current CFATS program. It will be interesting to see if it includes a cleaned-up version of the hacking provisions of the earlier bill.

HR 150 is almost certainly not a control system security bill, but any bill that ‘enhances’ enforcement of the cyber fraud provisions of the US Code (§ 1030)is certain to effect (unintentionally if nothing else) anyone in the cybersecurity research community, especially those that are not meticulous supporters of coordinated disclosure.


As always future coverage of these bills in this blog will depend on what the actual wording of the bill includes.

Tuesday, January 3, 2017

Committee Hearings – Week of 1-1-17

The 114th Congress will meet for the last time this morning and then adjourn sine die. The 115th Congress will then meet at noon. The first week is mainly procedural matters. There are a couple of hearings currently scheduled, but only one of potential interest to readers of this blog; a cybersecurity threat hearing by Sen. McCain’s (R,AZ) Armed Services Committee.

That hearing will be held on Thursday and will address foreign cyber threats to the United States.

The witness list includes:

• James R. Clapper, Jr. – DNI;
• Marcel J. Lettre II - DOD; and
• Michael S. Rogers – Cyber Command/NSA


While the press has made much of the focus of the hearing being on the impact of Russian hacks of the DNC and Clinton campaign staff the testimony could end up being fairly wide ranging. Very little chance that control system security will be mentioned though.
 
/* Use this with templates/template-twocol.html */