Tuesday, April 20, 2021

CISA Integrated Operations Division

This last weekend I received an interesting direct message on one of my social media accounts asking if I had ever taken a look at CISA’s Integrated Operations Division. I had not, but before I do, I need to take a brief side step and look at a piece of my governmental history.

Chain of Command

Every soldier, sailor, airman and marine learn one basic lesson quickly in their initial training; the chain-of-command. The chain-of-command is the legal fiction that there exists a direct line of authority from the President down to the lowest enlisted members of the Armed Forces. Each and every recruit is required to memorize the title and name of every person in their chain-of-command.

While such a direct linear chain-of-command may have existed at some point in our nation’s history, the structure of a modern military is no longer so clearly defined. I had this fact driven home for me when I served in the G3 Emergency Operations Center in Berlin in the late 70’s and early 80’s. That time was a very warm period of the Cold War and Berlin was, as usual, smack in the middle of things. In the EOC we served two masters; the Brigadier General commanding the Berlin Brigade and the US Commander of Berlin, a Major General. For the BG we were a tactical operations center that typically went ‘to the field’ once a year for a tri-partite war game with our British and French allies.

For the USCOB, however, we were the EOC for a politically responsive military command. The Major General reported directly to the US Ambassador for Germany and we routinely communicated directly with the Pentagon and the National Command Authority as incidents evolved in our area of operations. As political tensions escalated, we frequently operated as both the EOC and the TOC. As operations NCO’s we had to carefully be fully aware of in which role we operated, in each communication in which we took part.

Our chain-of-command in each role was different and would frequently shift in the middle of an operation as the political realities changed around us. Fortunately, we had a great operations officer and an experienced Senior Operations NCO that were aware of the potential problems. They kept us aware of the organizational status of our operations, especially when that status changed in the middle of an operation. This helped us ensure that we did not make any serious reporting or coordination mistakes.

Integrated Operations Division

CISA is the Cybersecurity and Infrastructure Security Agency. They make most of their news recently in their cybersecurity role. The infrastructure security portion of the Agency is, however, a fully functioning and important part of CISA. A major functional part of that other-than-cyber part of CISA operations is found in the Integrated Operations Division. They provide “a national capability to deliver CISA services to our stakeholders and partners across state and local governments and the critical infrastructure community.”

Operating offices out of each of ten CISA Regions (patterned after the FEMA regional organization) the IOD provides local logistical support for CISA personnel in the realms of:

• Chemical Security Inspectors (CFATS program),

Protective Security Advisors,

• Cybersecurity Advisors, and

Emergency Communications Coordinators

These regional offices also serve as a point-of-contact for State, local and tribal governments for coordination and support from CISA.

IOD and CFATS

Here is where stuff starts to get complicated. First off, the Chemical Facility Anti-Terrorism Standards (CFATS) program is run by the Office of Chemical Security (OCS) out of the CISA Infrastructure Security Division. OCS is responsible for:

• Developing and maintaining the Chemical Security Assessment Tools (CSAT) used by facilities to provide information to DHS about their chemical security processes,

• All of the back-end operations of the risk assessment process which is used to determine which reporting facilities are considered to be at high-risk of terrorist attack and thus covered by the CFATS program,

• First authorizing and then approving each facility site security plan, and

• Ensuring that covered facilities remain compliant with their approved site security plan responsibilities.

The on-site eyes and ears of OCS are the Chemical Security Inspectors. These are the valued members of the CFATS teams that work directly with the covered facilities in helping them develop effective site security plans and then ensure that they comply with the approved plans and remain in compliance with them over time. The CSI work out of the CISA Regional offices.

Each Regional Office has a Chief of Chemical Security. This is the ranking Chemical Security Inspector in the region who is responsible for the operations of the CSI in that Region. In addition to ensuring that all chemical security inspections, audits and assistance visits are accomplished in a timely and effective manner, the Chief is also responsible for providing response to State, local and Tribal governments in the region in matters related to chemical security, providing outreach to chemical facilities within the region about their reporting responsibilities under the CFATS program, and supporting chemical facilities not covered under the CFATS program is assessing their facility security.

The thing that is not clear to me is to whom does the Chief of Chemical Security report? Certainly, in many of the day-to-day activities of the CSI is responsive to the local official running the Regional Office. But for the purposes of ensuring that the requirements of the CFATS program are met, the Chief should be directly responsible to OCS. One would like to think that there should be no conflicts between the competing requirements of the Regional Office and OCS, but anyone that has ever worked with bureaucracies knows that they seldom work as planned.

Now I have heard nothing about any specific conflicts between regional offices and OCS, but professionals would have to acknowledge that there was the potential for conflict. When organizations are set up in ways that make for potential conflict, controls have to be put into place to identify such conflict early on and resolve that conflict before it gets too far out of hand. In the federal government, the agency responsible for identifying and resolving these types of internal conflicts is the Inspector General. The DHS IG should set up a periodic review of the situation in the CISA Regional Offices to ensure that conflicts between IOD and OCS priorities to not hinder the efficient oversight of the CFATS program.

Bills Introduced – 4-19-21

Yesterday, with both the House and Senate in session, there were 55 bills introduced. One of those bills may receive additional coverage in this blog:

HR 2659 To establish a grant program at the Department of Homeland Security to promote cooperative research and development between the United States and Israel on cybersecurity. Rep. Langevin, James R. [D-RI-2] 

This is likely a companion bill to S 1193 that was introduced last week. I will also be watching this bill for language and definitions that specifically include control system cybersecurity coverage.

NOTE: A companion bill is a piece of legislation that is introduced in both the House and Senate to allow for the legislative process to begin in both houses of Congress at the same time. Theoretically, this is done to speed the process by which the bill gets to the President’s desk, but it is typically done as a way to garner more attention in the press.

Monday, April 19, 2021

Committee Hearings – Week of 4-18-21

This week, with both the House and Senate in session, there is a full slate of committee hearings. Budget hearings continue and there is one cyber workforce hearing scheduled. The House will take-up one chemical security bill and one piece of cyber related legislation this week.

FY 2022 Budget Hearings

4-21-21 Environmental Protection Agency House IER Subcommittee

Cyber Work Forces

On Wednesday the Senate Armed Services Committee will hold a hearing on “To receive testimony on the current and future cyber workforce of the Department of Defense and the military services.” The witness list includes:

• Lieutenant General Dennis Crall, DOD Joint Staff,

• Leonard Litton, Acting Deputy Assistant Secretary for Defense for Military Personnel,

• Veronica Hinton, Acting Deputy Assistant Secretary for Defense for Civilian Personnel Policy,

• John Sherman, Acting Department of Defense Chief Information Officer

Since a major portion of the DOD cyber workforce is on the civilian side of the House, this hearing should provide insights into some of  the problems facing the private sector cybersecurity workforce.

On the Floor

The House is scheduled to take up 23 bills this week under their suspension of the rules process. That means that there will be limited debate, no floor amendments, and the bills will require a supermajority to pass. The House leadership expects that all of the scheduled bills will receive significant bipartisan support.

Included in this week’s consideration are:

HR 397 – CBRN Intelligence and Information Sharing Act of 2021, and

HR 1251 – Cyber Diplomacy Act of 2021

I have not reviewed HR 1251 here as the bill contains no language or definitions that specifically address control system security concerns.

Sunday, April 18, 2021

Public ICS Disclosures – Week of 4-10-21 – Part 2

Today we look at three vendor disclosures from Siemens (2) and Schneider. There are also six vendor updates from Siemens (5) and Schneider.

Siemens Advisories

This advisory describes four vulnerabilities in the DNS modules of their Nucleus products. These are the NAME:WRECK DNS vulnerabilities. Siemens has updates that mitigate the vulnerabilities in some of the affected products.

The four reported vulnerabilities are:

• Improper null termination - CVE-2020-27736,

• Out-of-bounds read - CVE-2020-27737,

• Access of memory location after end of buffer - CVE-2020-27738, and

• Use of insufficiently random variables - CVE-2021-25677

 

This advisory describes a use of hard-coded cryptographic key vulnerability in their Smartclient installer. Siemens has provides workarounds to mitigate the vulnerability.

Schneider Advisory

This advisory discusses two Windows® vulnerabilities in their s NTZ Mekhanotronika Rus. LLC control panels. Schneider provides links to two Microsoft updates that mitigate the vulnerabilities.

The two reported vulnerabilities are:

• Windows NTLM tampering vulnerability - CVE-2019-1040, and

• Win32k elevation of privilege vulnerability - : CVE-2019-0803

Siemens Updates

This update provides additional details on their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on March 9th, 2021. The new information includes adding:

• CVE-2017-12424,

• CVE-2017-20002,

• CVE-2020-14871 (exploit),

• CVE-2021-3428,

• CVE-2021-3450,

• CVE-2021-27219, and

• CVE-2021-28153

NOTE: NCCIC-ICS does not cover this advisory.

 

This update provides additional details on their CodeMeter advisory that was originally published in 2018 and most recently updated on March 9th, 2021.  The new information includes updating the solution for:

• PSS CAPE, and

• SIMIT

NOTE: NCCIC-ICS does not update their CodeMeter advisory for changes in vendor advisories since the NCCIC-ICS advisory links to the latest version of the vendor advisory.

 

This update provides additional details on their  DNSpooq advisory that was originally published on January 19th, 2021 and most recently updated on March 9th, 2021. The new information includes adding solutions for:

• SCALANCE M-800/S615, and

• RUGGEDCOM RM1224

NOTE: NCCIC-ICS does not update their DNSSpooq advisory for changes in vendor advisories since the NCCIC-ICS advisory links to the latest version of the vendor advisory.

 

This update provides additional details on the Solid Edge advisory that was originally published on March 9th, 2021. The new information includes:

• Adding fix information for two of the vulnerabilities, and

• Adding a reference to SSA-574442.

NOTE: NCCIC-ICS should have updated their advisory.

 

This update provides additional details on their SiNVR/SiVMS Video Server advisory that was originally published on March 10th, 2020. The new information includes:

• Adding a partial solution for SiNVR/SiVMS Video Server, and

• Removing information for Control Center Server (CCS), which is now addressed in SSA-761844

NOTE: NCCIC-ICS should have updated their advisory.

Schneider Update

This update provides additional information on their Ripple20 advisory that was originally published on June 23, 2020 and most recently updated on March 9th, 2021. The new information includes adding remediation for Acti9 PowerTag Link C.

Saturday, April 17, 2021

S 808 Introduced - Cybersecurity Disclosure Act of 2021

Last month Sen Reed (D,RI) introduced S 808, the Cybersecurity Disclosure Act of 2021. The bill would require the Securities and Exchange Commission to establish rules requiring the reporting of whether there was cybersecurity expertise on the board of directors or other governing body of each company required to file annual reports. The bill is nearly identical to S 592 that was introduced last session. No action was taken on the earlier bill.

Moving Forward

Reed is a member of the Senate Banking, Housing, and Urban Affairs Committee to which this bill was assigned for consideration as are three of his cosponsors {Cortez-Masto (D,NV), Cramer (R,ND), and Warner (D,VA)}. This means that there should be enough influence to see the bill considered in Committee. I would expect there to be some resistance to this bill from business supporters in the Republican conference. With the increasing concern, however, in Congress about cybersecurity issues, there should be somewhat reduced opposition to this bill. That means that the bill could pass in Committee with some bipartisan support.

This bill will not make it directly to the floor of the Senate. The bill is not important enough to take the time required for the normal debate and amendment process. That would leave just the unanimous consent process as the means for this bill to make it to the floor; there will be at least one Republican Senator that would object to the consideration of the bill. The bill could make it to the floor as an amendment to a must pass spending or authorization bill.

Commentary

I would like to reiterate a point I made in my discussion of S 592 back in 2019, is this realistic? Does every corporation in the United States (no matter the size) need to have a cybersecurity expert on their Board? According to Scott A Hodge, at the TaxFoundation.org, in 2014 there were 1.7 million C corporations and 7.4 million partnerships and S Corporations in the United States. Where are all of the cybersecurity experts going to come from?

Public ICS Disclosures – Week of 4-10-21 – Part 1

This week we have six vendor disclosures from Philips, QNAP (4), and Ruckus. We also have a researcher report for products from Siemens. Part 2 will discuss advisories and updates from Siemens and Schneider published earlier this week.

Philips Advisory

Philips published an advisory discussing the NAME:WRECK DNS vulnerabilities in their products. They report that they are evaluating potentially affected products.

QNAP Advisories

QNAP published an advisory describing an SQL injection vulnerability in their Multimedia Console and the Media Streaming Add-On. The vulnerability was reported by Yaniv Puyeski. QNAP has a new version that mitigates the vulnerability. There is no indication that Puyeski has been provided an opportunity to verify the efficacy of the fix.

QNAP published an advisory describing a command injection vulnerability in their QTS and QuTS hero. The vulnerability was reported by Omri Mallis and Yaniv Puyeski. QNAP has new versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

QNAP published an advisory describing a cross-site scripting vulnerability in their File Station. The vulnerability was reported by Independent Security Evaluators. QNAP has newer versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

QNAP published an advisory describing two vulnerabilities in their TWONKY server products. This is a third-party (Lynx Technology) vulnerability. A Lynx update is pending.

The two reported vulnerabilities are:

• Improper access restriction, and

• Weak password obfuscation

Ruckus Advisory

Ruckus published an advisory describing an information disclosure vulnerability in their SmartZone products. Ruckus has new versions available that mitigate the vulnerability.

Siemens Report

The Zero Day Initiative published a report describing an unrestricted pointer dereference vulnerability in the Siemens Sold Edge Viewer. ZDI coordinated this disclosure with ICS-CERT (NCCIC-ICS), but no fix is yet available from Siemens.

Friday, April 16, 2021

S 914 Reported in Senate – Water Systems Reauthorization

Earlier this week the Senate Environment and Public Works Committee adopted substitute language for S 914, the Drinking Water and Wastewater Infrastructure Act of 2021, and ordered the bill reported favorably without a written report. The reported version of this bill is now available.

The only major change made to the bill was the insertion of a new §109, Rural and low-income drinking water assistance pilot program. A number of word and editorial changes were made in the language of the bill. Of interest here is the replacement of the term ‘cybersecurity threat’ with ‘cybersecurity vulnerabilities’. That change was made everywhere the original term was used. Neither term was defined in the bill.

This bill received strong bipartisan support in Committee and I expect that it will move quickly to the floor of the Senate. It will be interesting to see if it is considered under the Senate’s unanimous consent process or if it will be brought up under the ‘normal’ debate and amend process.

 
/* Use this with templates/template-twocol.html */