Tuesday, March 10, 2020

Bills Introduced – 03-09-20


With both the House and Senate in session there were 46 bills introduced. One of those bills will receive future coverage in this blog:

HR 6160 To extend the chemical facility anti-terrorism standards program of the Department of Homeland Security. Rep. Thompson, Bennie G. [D-MS-2]

This is almost certainly a short-term extension of the CFATS program. Disappointingly, there are currently no Republican cosponsors to the bill. This also probably indicates that the Senate bill, S 3416 (which I have not seen yet), is not acceptable to the Democrats in the House (or at least to Chairman Thompson). Nor is there a likely agreement to break HR 3256 out of the House Energy and Commerce Committee. The current authorization ends April 18th.

Monday, March 9, 2020

Committee Hearings – Week of 3-8-20


This week with both the House and Senate in Washington before a week back in their districts the big news in congressional hearings continues to be COVID-19 as well as more budget hearings. There is also a markup hearing in the Senate that will look at a CFATS reauthorization bill and the CISA subpoena bill.

Budget Hearings


Agency
House
DOD
3-10-20 Budget
Coast Guard
3-10-20 A-DHS
CG/TSA
3-11-20 HS-S
CISA/S&T
3-11-20 HS-S
ARPA-E
3-11-20 A-EWR

Budget – Budget Committee
A-DHS – Appropriations – DHS Subcommittee
HS-S – Homeland Security Subcommittee
A-EWR – Appropriations – EWR Subcommittee

The Senate will also be holding budget hearings, but the ones that are scheduled are not agencies that I closely follow in this blog.

Senate Markups


On Wednesday the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting that will include marking up 15 bills. Those will include:

S 3045, Cybersecurity Vulnerability Identification and Notification Act of 2019;
• S 3416, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020; and
S 3207, Cybersecurity State Coordinator Act of 2020;

The CFATS bill is still not available for review. Hopefully, I will see it before Wednesday.

On the Floor


As I noted yesterday the Senate will resume consideration of S 2657, the comprehensive energy bill. There is a vote on SA 1407, the substitute language, at 5:00 pm EDT. Further amendments will likely be considered tomorrow and Wednesday. We should see a final vote this week.

Sunday, March 8, 2020

S 2657 Considered in Senate – Comprehensive Energy Bill


On Thursday the Senate began consideration of S 2657, the Advanced Geothermal Innovation Leadership Act. This bill is being used as a vehicle for Sen Murkowski (R,AK) to bring to the floor of the Senate a comprehensive energy bill. On Teusday she offered SA 1407 (pg S1351 or pg 49 of document), the amendment that would serve as substitute language for S 2657. Then on Thursday she offered a modified version of that language that will be considered as SA 1407. The Senate is currently scheduled to vote on SA 1407 on Monday at 5:00 pm EDT.

Cybersecurity


There are a number of cybersecurity provisions included in the bill and most of them have come from previously introduced legislation. The list below shows the ones that I have identified (pg numbers are for Thursday’s Congressional Record pages):

§1005. Smart Building Acceleration. (S 2447) pg S 1526
§1808. ARPA–E reauthorization. (S 2714) pg S 1564
§2201. Incentives for advanced cybersecurity technology investment. (S 2256) pg S1570
§2202. Rural and municipal utility advanced cybersecurity grant and
technical assistance program. (S 2256) pg S1570
§2203. State energy security plans. pg S1571
§2204. Enhancing grid security through
public-private partnerships. (S 2095) pg S 1571
§2205. Enhanced grid security. (S 1241) pg S 1527

I have not had a chance to review these sections in detail to see if any changes had been made to the original language.

Amendments


As with any major piece of legislation being considered by the Senate a large number of amendments have been offered over the last three legislative days and more are expected on Monday. Only a very small number of these amendments will be considered on the floor. A complete list of the offered amendment can be found here, here and here. Amendments that may be of interest include:

SA 1428 Whistleblower protection for employees responsible for ensuring the reliability, resilience, and security of the electric grid – pg S 1413;
SA 1455 Cyber Sense Program – pg S 1426;
SA 1480 Internet of Things (DIGIT Act) – pg S 1480;
            None

Moving Forward


S 2657 will probably pass with bipartisan support this coming week. What is not clear is how many Democrats will find enough ‘objectionable’ content to require a vote against the bill. If there is a large enough Nay vote the bill will not be taken up by the House. A strong bipartisan vote will ensure early consideration by the House. There is a good chance that if the Senate outcome falls somewhere in between the House will take up the bill and amend it into passable form.

CG Publishes TWIC Reader Delay Final Rule


The Coast Guard published a final rule in the Federal Register (85 FR 13493-13517) for “TWIC--Reader Requirements; Delay of Effective Date”. The rule will delay the implementation of the TWIC Reader rule for 3 years for 370 of the 525 affected Risk Group A facilities. The notice of proposed rulemaking (NPRM) for this rule was published in June of 2018. The rulemaking was initiated as a result of an industry petition [.PDF download].

Expansion of Covered Facilities


While the delay described in the NPRM would have only covered facilities that transferred or handled Certain Dangerous Cargoes (CDC) but did not transfer those CDC to or from vessels, the Coast Guard has expanded the delay coverage to all facilities that handle CDC. This leaves just larger passenger vessels and facilities that serve those vessels covered by the TWIC Reader Rule.

The length of the delay remains three years.

The Other Delay Rule


This final rule does not mention the other TWIC reader delay rule currently in effect. In August of 2018 the President signed HR 5729, the Transportation Worker Identification Credential Accountability Act of 2018 (PL 115-230). That bill prevented the Coast Guard from implementing the TWIC Reader Rule which was due to go into effect on August 23, 2018 until 60-days after Congress received the report on the efficacy of the TWIC program required by HR 710 from the 114th Congress, the Essential Transportation Worker Identification Credential Assessment Act (PL 114-278). That report was supposed to cover an assessment of the effectiveness of the TWIC program “at enhancing security and reducing security risks for facilities and vessels regulated” under the Maritime Transportation Security Act (MTSA).

While not specifically mentioning that other implementation delay, the final rule notice does mention (at the very end of the document) the required report:

“The U.S. Coast Guard requested that the Office of the Federal Register hold this document from publication until delivery to Congress of the assessment required by the Transportation Worker Identification Credential Security Card Program Act (Pub. L. 114-278).”

The report is included in the docket on this rulemaking. I cannot find a publication date on the report beyond “published in 2019”. Presumably it was delivered to DHS late last year and has undergone the required internal review necessary to develop the necessary corrective action plan.

While the final rule does not mention the other delay it effectively deals with it in the sole made to 33 CFR Part 105. It revises § 105.253(a) to read:

(a) For purposes of the Transportation Worker Identification Credential (TWIC) requirements of this subchapter, the following facilities subject to this part are in Risk Group A:

(1) Beginning June 8, 2020: Facilities that receive vessels certificated to carry more than 1,000 passengers.

(2) Beginning May 8, 2023: Facilities that handle Certain Dangerous Cargoes (CDC) in bulk and transfer such cargoes from or to a vessel.

(3) Beginning May 8, 2023: Facilities that handle CDC in bulk, but do not transfer it from or to a vessel.

(4) Beginning May 8, 2023: Facilities that receive vessels carrying CDC in bulk but, during the vessel-to-facility interface, do not transfer it from or to the vessel.

Thus, the TWIC reader rule now goes into effect on June 8th, 2020 and the implementation for the various types of facilities that handle CDC starts on May 8th, 2023. The breakout of the different types of CDC handling facilities indicates that the Coast Guard may treat these facilities differently after further review.

Saturday, March 7, 2020

CISA Risk Management for COVID-19


Yesterday the DHS Cybersecurity and Infrastructure Security Agency (CISA) published a new ‘insights’ document about “Risk Management for Novel Coronavirus (COVID-19)”. This is not a comprehensive planning document but rather it is designed “for executives to help them think through physical, supply chain, and cybersecurity issues that may arise from the spread of” COVID-19.

The main topic areas include:

• Actions for Infrastructure Protection;
• Actions for your Supply Chain;
• Cybersecurity for Organizations;
• Cybersecurity Actions for your Workforce and Consumers

The first two sections mainly address business continuity issues. The organization cybersecurity section deals with considerations for enabling or expanding telework or remote access. And the final section deals with looking out for cyber-scams related to COVID-19.

While there are a number of links to more detailed information on many of these topics, conspicuously lacking are references to CDC guidance on disease prevention in the workplace or the COVID-19 outbreak in general. Also lacking is any discussion about physical security impacts of guard force sickouts.

Public ICS Disclosure – Week of 2-29-20


This week we have lots of new ‘information’ on SweynTooth vulnerabilities and three vendor disclosures for products from Rockwell, Phoenix Contact and Moxa.

SweynTooth


In addition to the CISA alert for the SweynTooth  Bluetooth vulnerabilities published this week there was an advisory from the FDA and brief disclosures from the following medical device vendors:

Medtronic;
BD; and
Drager

Rockwell Advisory


Rockwell published an advisory describing four vulnerabilities in their MicroLogix Controllers and RSLogix 500 Software. The vulnerabilities were reported by Ilya Karpov, Evgeny Druzhinin from ScadaX Security and Dmitry Sklyarov from Positive Technologies. Rockwell has new versions for some products that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Use of hard-coded cryptographic key - CVE-2020-6990;
• Use of broken or risky algorithm for password protection - CVE-2020-6984;
• Use of client-side authentication - CVE-2020-6988; and
• Unsecured SMTP data storage - CVE-2020-6980

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing three vulnerabilities in their  TC ROUTER & TC CLOUD CLIENT devices. The vulnerabilities were reported by Thomas Weber, SEC Consult Vulnerability Lab. Phoenix Contact has new firmware that mitigates the vulnerability. There is no indication that Weber was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Improper control of generation of code - CVE-2017-16544;
• Command injection - CVE-2020-9436; and
• Hard-coded certificate - CVE-2020-9435

NOTE: the first vulnerability is an old library problem that has lots of exploits available.

Moxa Advisory


Moxa published an advisory describing an improper authentication vulnerability in their MGate MB3180/MB3280/MB3480/MB3170/MB3270 Series Protocol Gateways. This is a self-reported vulnerability. Moxa has new firmware versions available that mitigate the vulnerability.

Friday, March 6, 2020

Bills Introduced – 3-5-20


Yesterday with the House and Senate preparing to head home for the weekend there were 67 bills introduced. Three of those bills may receive additional coverage in this blog:

HR 6096 To improve oversight by the Federal Communications Commission of the wireless and broadcast emergency alert systems. Rep. McNerney, Jerry [D-CA-9]

HR 6113 To establish an Advanced Research Projects Agency-Water, and for other purposes. Rep. Katko, John [R-NY-24]

S 3416 A bill to reauthorize the Chemical Facility Anti-Terrorism Standards Program of the Department of Homeland Security. Sen. Johnson, Ron [R-WI]

I will be watching both House bills for cybersecurity language and definitions; not holding my breath.

Looking forward to seeing what Johnson has come up with this session for the CFATS program. Nothing on his web site about this bill, but that is not too unusual. Earlier this week, Johnson did make a comment about CFATS program in a hearing on the DHS 2021 Budget proposal:

“Additionally, CISA provides security assessments and advisory services to the sixteen critical infrastructure sectors of our economy. For all but one sector in which CISA has oversight, CISA employs a common approach by using voluntary Protective Security Advisors. In 2006, Congress authorized a specific regulatory program for the Chemical sector — the Chemical Facility Anti-Terrorism Standards program (CFATS). CFATS is set to expire in the coming weeks, and the administration proposes to transfer CFATS Chemical Security Inspectors into the same voluntary system used for the other critical infrastructure sectors. I support this common sense approach, but am willing to work with industry, the administration, and congressional colleagues on a path forward we can hopefully all agree on.”

This bill is currently scheduled to be considered in the Senate Homeland Security and Governmental Affairs Committee next week.

 
/* Use this with templates/template-twocol.html */