Hiển thị các bài đăng có nhãn NIST. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn NIST. Hiển thị tất cả bài đăng

Whitsitt on What's Up with the NIST CSF

Before you click through on the link provided below, I have to tell you that this write-up is not just about the NIST Critical Infrastructure Security Framework (CSF), but it's also a review of the current state of the security profession/practice/belief system, depending on your vantage point.

Penned by Jack Whitsitt of EnergySec, who among other things helped design the cyber security policies for the Transportation Security Agency (TSA) when it was just getting started. Be forewarned: Jack is no ordinary security guru. Because he's a practicing artist too, he brings both hemispheres to this challenge, and as a result, his perspectives and insights are unlike what you'll likely encounter anywhere else.


I particularly like that he begins with a 15 point description of the "problem space", something that might have helped the CSF initiative itself get off to a better start. Points 1-3 establish an overall tone of realism that includes references to money and outcomes:
  1. We are failing at cybersecurity
  2. We are investing heavily in cyber security
  3. Our organizations are getting breached at unacceptable rates
Doesn't sound like a status quo anyone interested in national security would want to maintain much longer. Or the CEO of large power company, for that matter.

I particularly like point 11, which I'll paraphrase below to suit our purposes:
A more likely way of getting at the cultural and business underpinnings of cyber security would be to start with business outcome objectives and then elicit a framework to meet those objectives. AB - now here's the magic part: Do this while assuming a lack of a dedicated security team and without making references to cyber security specific technologies. 
As Jack continues, this allows the discussions to remain in plain-English business language, which means the business folks, advocating for their business objectives, remain active participants in the conversation and the solution formulation process throughout.

There is a ton more to like in his comprehensive treatment of the subject matter.  You'll find the full piece, "My comments to NIST on the Preliminary Cybersecurity Framework" right HERE.

First Look at Cyber Security Incentive Ideas, Companion to NIST's Framework Work

I'll oversimplify this to keep it short, but the President kicked all of this off earlier this year in wake of failed cyber security legislation efforts in 2010 (GRID Act) and 2012 (Cybersecurity Act of 2012).

The two primary vectors on this project have included:

  1. Having NIST lead the charge to develop a new cyber security framework (i.e., pattern, roadmap, guidance) made up of references to existing guidance that seem to work well. On twitter this effort is tagged #NISTCSF
  2. A parallel initiative to develop incentives that might improve the business case for being more proactive on cyber security.
The incentive categories were just made public, and so far include :
  • Cybersecurity Insurance
  • Grants
  • Process Preference
  • Liability Limitation
  • Streamline Regulations
  • Public Recognition
  • Rate Recovery
  • Cybersecurity Research
Liability and insurance are going to be the thorniest.  And rate recovery help, if workable, sounds promising.

You ran read The Hill's coverage and the original White House text via URLs below, as well as check out the current status and next activities related to the framework.

----

URLs

The Hill

http://thehill.com/blogs/hillicon-valley/technology/315795-white-house-publishes-preliminary-list-of-cybersecurity-incentives

White House

http://www.whitehouse.gov/blog/2013/08/06/incentives-support-adoption-cybersecurity-framework

NIST CSF

http://www.nist.gov/itl/cyberframework.cfm

NIST Critical Infrastructure Cyber Security Framework (#NISTCSF) Effort Steaming Ahead


Five hundred souls or so are expected in sunny San Diego this week for the 3rd round of meetings intended to produce new cyber security guidelines for operators of US critical infrastructure.

This article gives you the most recent update on status including cares and concerns related to privacy, business case, and getting senior management buy-in to even consider following this framework in the first place:

http://insidecybersecurity.com/Cyber-Daily-News/Daily-News/nist-meeting-poses-major-test-for-obama-cybersecurity-push/menu-id-1075.html

It references this DHS doc from earlier this year that attempts to pave the way for CEOs to become more engaged in their organization's cyber security efforts, called Cyber Security Questions for CEOs:

https://www.us-cert.gov/sites/default/files/publications/DHS-Cybersecurity-Questions-for-CEOs.pdf

Lastly, if you want to see more of the process without actually getting your feet weight (or getting on a west-bound plane) here are a few resources for you:

The emerging framework itself: http://www.nist.gov/itl/cyberframework.cfm

Details on the San Diego workshop: http://www.nist.gov/itl/csd/3rd-cybersecurity-framework-workshop-july-10-12-2013-san-diego-ca.cfm

Live webcasts of the proceedings can be viewed via these URLs:
Day 1 (Wednesday) Webcast: http://www.youtube.com/watch?v=3hJww5_BDSQ
Day 2 Webcast: http://www.youtube.com/watch?v=SLVW0vFw0gI
Day 3 Webcast: http://www.youtube.com/watch?v=-9hORcAcXNA
I'm flying out today, along with a few of my IBM colleagues. Looking forward to seeing some of you there.

Photo credit: The San Diego Union-Tribune



All the NIST Critical Infrastructure Security RFI Responses You Can Eat


Re: the many and various submissions from companies and individuals to NIST, someone who knows more than a few things about grid security recently tweeted twice thusly:
Reading - and in many cases laughing at - #NISTCSF responses
and ...
The responses? Mostly neutrally irrelevant, some nonsensical. I've marked only 14% so far for "real" read later
I just want you to set your expectations bar sufficiently low before you click HERE and read all of the responses.

By the way there were a few good and very good responses too.

If, after reading, you not only feel like you have something to suggest that hasn't yet been suggested, but you also want to physically transport and immerse yourself in this grand sausage making activity, then ...

For more information on the 2nd workshop coming up in late May in Pittsburgh, and a link where you can register, click on THIS.

Photo credit: @Doug88888 on Flickr.com

SGSB notes from NIST's Critical Infrastructure Cybersecurity Framework Workshop


Long title, eh?  Cranking this out just before heading back to Beantown from DC/Reagan airport so please be more tolerant than usual of typo's, lack of narrative, lack of clarity, weak grammar, lack of a point, etc. ...

ICS-ISAC Chair Chris Blask, pictured above (long hair on right), waited very patiently at a microphone that seemed like it was for audience use, and ultimately got his turn, in which he asked a long question phrased like a long statement.

Today was a good day. There was lots of Tweeting was going on, even though the wireless service in the Dept of Commerce was highly sub-optimal. As one fellow attendee observed, "it's not bad because of security, it's just bad." You can find those tweets, many happy, some helpful, a couple cheeky and a few angry for some reason, using the #NISTCSF hashtag.

As the format didn't encourage much audience participation, I might have been just as happy if not slightly happier if I had "attended remotely" via Webcast  I was able to oversize my modest social skills with friends and acquaintances from FERC, NIST, DOE, DHS, UTC, and more than a few companies. 

Anyway, my 2 centavos:

While public-private partnerships sound good on paper, and can produce good results, they can also produce nothing, disguised as activity. Nevertheless, this work may produce results for the electric sector, and if it does, I think you'll see them in some or all of the following categories:

1) Incentives

Tax relief, liability limits, making it easier for crit infra co's to generate the money to fund newer/bigger security investments. I think we're all pulling for this, but the devil will be in the sausage making.

2) Sourcing & Acquisition

Crafting minimum security requirements for systems and software purchases going forward. Won't secure what's in the field, but will drive improvement over time. Super thorny issue, though, right? IBM practices "secure by design" processes in its software products. And recommend it to others. Also see IEC 62443 2-4 where a very large US utility and security boutique Wurldtech collaborated to make security maturity guidelines for sourcing grid products. That could be one helpful precedent.

3) Security Metrics

One of my favorite topics of course. Can't show improvement if we can't describe current state. Once you can baseline then you can find gaps and roadmap to an improved future state. 

4) Cyber Hygiene

Repeated throughout was how 80-90 % of data breaches are from the most primitive/basic types of phishing attacks. Users clicking on links in emails, as NERC's Tim Roxey, who was far and away the brightest star in a very high caliber group of panelists, said, "like rats on crack." So this is about user awareness and basic cybersecurity 101 stuff. Not high tech. But if it could be implemented broadly, would eliminate majority of breaches.

5) Info Sharing

Making it easier for crit info co's to collaborate by giving certain privacy and other protections.

Please note that after RFI responses are in (deadline: April 8) and digested, another workshop (there will be 3) leading up to the October milestone will be at CMU in Pittsburgh right after the Memorial Day weekend in late May. I'll endeavor to be there, either in person and via the marvel of the Internet, will make my contributions, and report back out to you here.  Now got to go ... they're boarding !!!

Boxing the Fundamental Assumptions of Cybersecurity Risk Management


Here's something to wrap your head around (or more literally, put in your head) as you head to NIST on April 3rd to make your contribution to the Critical Infrastructure Cybersecurity framework development processes, an effort begat by the recent Presidential Executive Order.

Many in our community love to talk about risk management as the common sense, business oriented antidote to the mandatory and therefore inflexible and slow moving instructions in the NERC CIPs.

You could certainly put me at least half in that camp.  Well, after reading THIS sharp Brookings paper from Ralph Langer and Perry Pederson, that half of me is feeling a little wobbly.


Want to see if you can handle it?  Let's see you go for a round with them.  They begin with a jab -- the DHS definition itself:
The following is a definition of risk-based decision making from appendix C of the Department of Homeland Security’s risk Lexicon: “risk-based decision making is defined as the determination of a course of action predicated primarily on the assessment of risk and the expected impact of that course of action on that risk.”
And then counter with a flurry of lefts to some assumptions, a series of rights to some more, and finish with a big left to the whole foundation upon which cyber risk management normally rests:
The basic assumption embedded in this and all risk formulae is that unknown future events of an unknown frequency, unknown duration, unknown intensity, from an unknown assailant, with unknown motivations, and unknown consequences are quantifiable. Consequently, if one thinks s/he can measure the risk, the mistaken conclusion is that one can manage the risk.
I'm trying to not be overly swayed by this one article, but certainly it's going to be something I try to keep in main memory while at the workshop.  Hope it helps inform your thinking too.

BTW (late addition): I just realized this post ends on a bit of a down note and I don't want to leave you there.  If you can make it to page 8 you'll find Pederson and Langer pivoting towards their recommended solutions to replace risk management-based decision making.  You'll see these fall into 3 P's: Politics, 2) Practicality and Pervasiveness.  I myself haven't made it there yet but intend to before nightfall ... tomorrow.

---------------
P.S. have you ever tried boxing? I have a little, and it's a blast, and super hard, and exhausting.  But you know one thing it's easier than?  That's right, you've got it.

Photo credit: Wikimedia Commons

NIST Critical Infrastructure Cybersecurity Framework RFI and Workshop Details

We're about a month away from the first NIST workshop to help create the new framework described in the recent Executive Order, as well as from the 5 pm, USA ET, April 8 deadline to submit responses to the RFI.

To refresh, here's what they/we are trying to do:
The goals of the Framework development process will be: (i) To identify existing cybersecurity standards, guidelines, frameworks, and best practices that are applicable to increase the security of critical infrastructure sectors and other interested entities; (ii) to specify high-priority gaps for which new or revised standards are needed; and (iii) to collaboratively develop action plans by which these gaps can be addressed. It is contemplated that the development process will have requisite stages to allow for continuing engagement with the owners and operators of critical infrastructure, and other industry, academic, and government stakeholders.
If you are so moved and have something to say (and NIST and I hope you do), here's how to submit your ideas and recommendations:

Old School
For those who prefer to communicate longhand by dipping your peacock feather quill into the inkwell on your vintage desk, "Written comments may be submitted by mail to Diane Honeycutt, National Institute of Standards and Technology, 100 Bureau Drive, Stop 8930, Gaithersburg, MD 20899."

New School
"Electronic submissions may be in any of the following formats: HTML, ASCII, Word, RTF, or PDF. Online submissions in electronic form may be sent to cyberframework@nist.gov."

Do this in Either Case
"Please submit comments only and include your name, company name (if any), and cite“Developing a Framework to Improve Critical Infrastructure Cybersecurity” in all correspondence."

'Know this in Either Case: Your Written Comments will be Public
"All comments received by the deadline will be posted at http://csrc.nist.gov without change or redaction, so commenters should not include information they do not wish to be posted (e.g., personal or confidential business information)."

In Person
Sometimes there's no substitute for being there in person, so if that's your desire, you can click HERE to register for the April 3 workshop in beautiful Gaithersburg. Hope you can make it and fair warning if you do: I'll be there too!

DHS' CSET: a Remedy for Electric Sector Security Measurement and Reporting Complexity Pains?

Sorry about that ridiculously long title, but felt it couldn't be helped this time. Thanks to Dr. Les Cardwell of Central Lincoln PUD, a publicly owned utility serving communities on the coast of Oregon.

Les wrote in and shared some of what he recommended to NIST and DOE regarding the recent RFI on the "Framework for Reducing Cyber Risks to Critical Infrastructure."

I'm not going to reprint the entirety of his submission, but will share with you two things here. First, Les' articulation of the need for a way to keep complexity in check as we go about this search for a new/better security framework for our community:

I would like to address ... "the "elephant in the room" ... [that could hinder our achievement of] a Digital Systems Security (DSS) Cybersecurity standard across the US Utility spectrum. That issue is the "expanding redundant complexity" of the current approach to the problem domain. While one can appreciate the efforts [involved] in gathering more information from the industry ... for establishing and improving frameworks to raise the overall level of cybersecurity ..., the problem is that it does not address the inherent complexity of the problem. It only exacerbates it by creating yet more administrative requirements for decomposing and resolving the problem domain for each utility.
I think he's on to something. There's more text clarifying the challenge and then some words on what Les proposes could play a major role in the final solution: DHS' own Cyber Security Evaluation Tool (CSET). The department has put together a nice succinct info sheet on CSET, so rather than telling you more about it, I suggest you read it for yourself, which you can do HERE.

I've got some learning to do myself on this, but in the meantime, please let me know if you think CSET has a role to play in this grand challenge.