Thursday, July 7, 2016

Rule for Consideration of S 2943 – FY 2017 NDAA

Last night the House Rules Committee adopted a rule for the consideration of S 2943, the FY 2017 National Defense Authorization Act. As part of the adoption of H Res 809 the language of HR 4909 will be substituted for the language of S 2943. The House would then vote on a motion to insist on its amendment and request a conference.

Since HR 4909 passed along generally party lines, it would be highly unlikely that the Senate would accept the ‘new’ House language for S 2943. The Senate would be expected to also insist on their own language and vote for a conference. It is very probable that the conference could complete its work and both houses accept the conference report before the end of the fiscal year.


The House is currently debating H Res 809. The vote should come later today or tomorrow.

Bills Introduced – 07-06-16

With both the House and Senate in session yesterday there were 38 bills introduced. Of those three may be of specific interest to readers of this blog:

HR 5634 Making appropriations for the Department of Homeland Security for the fiscal year ending September 30, 2017, and for other purposes. Rep. Carter, John R. [R-TX-31]

HR 5639 To update the National Institute of Standards and Technology Act, and for other purposes. Rep. Moolenaar, John R. [R-MI-4]

HR 5643 To amend the Homeland Security Act of 2002 to provide for active shooter and mass casualty incident response assistance, and for other purposes. Rep. Duckworth, Tammy [D-IL-8] 

The DHS spending bill is being introduced awfully late in the session, particularly for an election year. It is unlikely to receive consideration as a stand-alone bill. Still it will be interesting to see what is included in the Committee Report on this bill.

The NIST authorization bill will be covered only if it includes specific provisions related to cybersecurity, particularly control system security.


The active shooter bill will probably not be mentioned again, but I am hoping that it will have at least some sort of provision requiring the Department to address the unique aspects of active shooter situations at chemical storage/production facilities.

Wednesday, July 6, 2016

Top Screen Freeze

I have been receiving questions from folks in the field about the ‘Top Screen Freeze’ that is in effect at the DHS Infrastructure Security Compliance Division (ISCD). While I have written about the new Top Screen rollout, the recent questions have been about Top Screens being submitted now.

ISCD ‘Freeze’ Guidance


I have gone back to my contacts at ISCD and obtained a copy of the memorandum that DHS sent to CFATS facilities back on June 21st, 2016. There is nothing in that memorandum that contradicts what I said in my last post on this topic. It does, however, provide some additional information:

“In anticipation of publication of the Federal Register notice [see more below], and to minimize duplication for facilities, DHS is planning to slow down and in some cases suspend the review of some Top-Screens and SVAs [Security Vulnerability Assessments]. DHS will automatically extend due dates for facilities that have Top-Screens and SVAs due in the coming weeks. These extensions will release facilities from the requirement to submit a Top-Screen or SVA until the Federal Register notice is published announcing the formal suspension [emphasis added]. Facilities should contact their Chemical Security Inspector [CSI] or Compliance Case Manager [CCM] with any questions or for clarifications on next steps.”

This certainly makes sense, both for ISCD and covered facilities. No one is well served by duplicative work. Facility specific questions should be addressed to the facility CSI or CCM. Facilities without contact information for these individuals should contact the CFATS Help Desk {(866) 323-2957}.

Federal Register Notice


Before ISCD can proceed with the changes to the CSAT tool (now being referred to as CSAT 2.0) it must wait on the OMB’s Office of Information and Regulatory Affairs’ (OIRA) approval of the CSAT information collection request (ICR) revision that I talked about in the Top Screen Rollout blog post. There is no telling when that ICR approval will be given; the personnel surety program ICR took more than a year to get approved. The CSAT 2.0 ICR is certainly less controversial and everyone at ISCD expects the approval process to be much quicker.

Once OIRA approves the ICR revision ISCD will be publishing a notice in the Federal Register outlining the details of how CSAT 2.0 will be rolled out. As mentioned above, part of that notice will be an official suspension of the Top Screen and SVA submission requirements pending the actual start dates of the new CSAT tools. It is possible that ISCD will publish their Federal Register notice before the OIRA CSAT 2.0 ICR approval, but there are potential problems with such a move if OIRA drags out the ICR approval process.

2016 CSSS


This is a topic that will certainly be discussed at the upcoming 2016 Chemical Sector Security Summit CSSS. The Agenda shows that there will be two workshops on July 19th demonstrating the CSAT tools; presumably these will be the CSAT 2.0 tools. Unfortunately, none of the workshops are currently planned to be web cast. I certainly hope that ISCD reconsiders this, especially given the number of questions from the field about these new tools.

On the 20th there will be a session on “Infrastructure Security Compliance Division Regulatory Update”. I expect that Director Wulf will be discussing the CSAT 2.0 implementation in some detail during this hour long presentation. This will be web cast.


If you have not yet registered to attend the CSSS in person or via the web cast there is still time to register.

ISCD Publishes CFATS Update – 07-06-16

The DHS Infrastructure Security Compliance Division (ISCD) published their latest update on the status of the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS) program today. We continue to see an improvement (at a much reduced rate) in the number of authorized and approved site security plans; there are now just under 400 facilities without approved site security plans.


May 2016
June 2016
July 2016
Covered Facilities
3,018
2,999
2,991
Authorized SSPs
3,356
3,370
3,390
Approved SSPs
2,525
2,562
2,595
Compliance Inspections
854
958
1,079

There have been some subtle changes in the wording of the ‘Program Statistics’ section of the Update, but the numbers continue to have the same problems that we have been seeing for some time now:

• No tally of why the number of covered facilities continues to fall;
• The number of authorized site security plans is still greater than the number of covered facilities, the number of currently authorized SSPs would be better;
• No information on the outcomes of the compliance inspections conducted;

• And no data about the number enforcement actions.

HR 5459 Introduced – Cybersecurity Information Sharing

Last month Rep. Donovan (R,NY) introduced HR 5459, the Cyber Preparedness Act of 2016 [Note: there is currently something wrong with this link at the GPO, alternative text of bill here]. The bill makes minor revisions to the Homeland Security Act of 2002 to enhance cybersecurity information sharing.

Fusion Centers and NCCIC


Section 2(1) of the bill would add ‘cybersecurity risk information’ to the list of types of information designated in 6 USC 124h(b)(6) and (b)(8) to be shared with fusion centers by DHS. Additionally, the same ‘cybersecurity risk information’ would be added to the list of types of information in §124h(d)(1) for which DHS would be required to “assist law enforcement agencies and other emergency response providers of State, local, and tribal governments and fusion center personnel in using information within the scope of the information sharing environment”.

Section 2(2) of the bill would amend 6 USC 148 addressing the information sharing responsibilities of the National Cybersecurity and Communications Integration Center (NCCIC). It would add fusion centers to the information sharing requirements of §148(c)(5)(B).

Grants


Section 3 of the bill would amend 6 USC 609 by adding “enhancing cybersecurity, including preparing for and responding to cybersecurity risks and incidents” to the list of permitted uses at §609(a) for which grants under the Urban Area Security Initiative or State Homeland Security Grant Program can be used.

As is fairly typical no additional funding is provided for either grant program.

Moving Forward


Donovan and all three of his cosponsors {McCaul (R,TX), Ratcliffe (R,TX), and Payne (D,NJ)} are influential members of the House Homeland Security Committee. That means that this bill has a good chance of moving forward through the committee review process. In fact, shortly after the bill was introduced, it was approved without amendments by the Emergency Preparedness, Response, and Communications Subcommittee.

There is nothing in this bill that would draw any sort or organized opposition. If the bill makes it to the floor of the House it would almost certainly be approved under the suspension of the rules procedure. The only question is if there is enough interest in the bill to get it to the floor of the House for consideration in the limited time remaining in the session.

Commentary


This is the type of ‘i-dotting and t-crossing’ legislative work that needs to take place to ensure that everyone has the appropriate authority to carry out legislative mandates that have been previously passed. Unfortunately, in this case, problems with the underlying definitions that are critical to the intent of the legislation are not addressed.

In this case we go back to the problem of the definition of ‘cybersecurity risk’. There is no definition of the term in §124h, so we are still left with the lack of any real authority to share cybersecurity risk information within the fusion center environment. In §148 we do have a definition {§148(a)(1)}, but it is one of those definitions that narrowly defines the term just with respect to IT systems. So again, we technically have no authority for the NCCIC to share information about cybersecurity risks that apply uniquely to industrial control systems.


Finally, as I have mentioned numerous times, expanding the allowable uses of federal grant monies is all well and good as long as the amount of available funding is already increased. In cases like the one here in this bill where that money pool is not enlarged, the expansion of the allowable uses has the direct effect of decreasing the money available to the existing list of potential grant uses. This means that grants will either be smaller (and less useful) or fewer grants for exiting programs will be approved. Either may be a perfectly legitimate outcome, but there is no discussion of those consequences when bills like this are discussed.

Tuesday, July 5, 2016

ICS-CERT Publishes New Advisory and an Update – Rockwell Ransomware -

This afternoon the DHS ICS-CERT published a new control system security for a Rexroth Bosch product and updated an advisory for a Siemens product.

Rexroth Bosch Advisory


This advisory describes two vulnerabilities in the Rexroth Bosch BLADEcontrol-WebVIS. The vulnerabilities were reported by Maxim Rupp. Rexroth Bosch has produced a new version. There is no indication that Rupp was provided an opportunity to verify the efficacy of the fix.

The reported vulnerabilities are:

• SQL injection - CVE-2016-4507; and
• Cross-site scripting - CVE-2016-4508

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to compromise of the database server or lead to remote code execution.

Siemens Update


This update provides new information on a Siemens Advisory that was reported by ICS-CERT on May 19th, 2016 for the Siemens SIPROTEC 4 and SIPROTEC Compact. The update removes a previously reported version of SIPROTEC Compact (7SK80) from the advisory. It also adds update information for another version of SIPROTEC Compact.

As I reported on Friday, Siemens CERT reported this update on TWITTER® last week.

ICS Ransomware Issue


As I mentioned on TWITTER on Saturday there is an interesting article over on ISSSource.com about a report from Rockwell Automation about a ransomware attack from a file being made available on the internet (no source given) called ‘Allenbradleyupdate.zip’. Apparently this file is not on the Rockwell web site and there is no information about any kind of social engineering attack associated with the file.

A copy of the Industrial Security Advisory from Rockwell is available here. It is presumably available on the Rockwell Automation web site, but access to that site is restricted to customers and Rockwell employees, so I cannot verify that.

Rockwell learned about the file from the Electricity Information Sharing and Analysis Center (E-ISAC). This is a good example of how information sharing should work to get information back to responsible folks to evaluate and spread the word. Unfortunately, it appears that the attempt by Rockwell to share this information via ICS-CERT was rebuffed.

While no one would like to think that any responsible control system engineer would apply an update to an industrial control system that was obtained from anywhere but from a vendor web site, I think that we have to admit that with a properly crafted social engineering attack it is almost inevitable that someone would load this ransomware masquerading as and ICS update. Spreading the word about this as widely as possible would certainly be in the best interest of everyone (except the ransomware author, of course). It is inconceivable to me that ICS-CERT would not use its information sharing capabilities to spread the word.


It is just a matter of time before a ransomware attack like this finds its way onto a hacked vendor or integrator web site. This is a good time to begin a discussion about what vendors are doing to prevent such site hacks and how vendors and users can ensure that only legitimate system updates are applied to live systems. This is another good reason to first apply updates to test systems before they are applied to real control systems.

Committee Hearings – Week of 7-3-16

This week the House is in town, back from their extended 4th of July holiday. The Senate is taking their ‘week’ off this week and will only be meeting in pro forma sessions. Currently there is only one hearing of interest scheduled for this week; a Rules Committee hearing on the 2017 NDAA.

Hearing


The Rules Committee will be meeting on Wednesday to prepare their rule for the consideration of S 2943, the FY 2017 National Defense Authorization Act (NDAA). The House already passed their version of the bill (HR 4909) which has some important differences from the Senate bill.

It is too early to tell if the House is just going to substitute the HR 4909 language or actually amend the Senate bill. That should be more obvious as we get closer to the hearing.

On the Floor



The House will take up S 2943 sometime later this week. They will also be considering HR 4361, a federal information security bill; not one that I have been following.
 
/* Use this with templates/template-twocol.html */