Hiển thị các bài đăng có nhãn critical infrastructure. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn critical infrastructure. Hiển thị tất cả bài đăng

Whitsitt on What's Up with the NIST CSF

Before you click through on the link provided below, I have to tell you that this write-up is not just about the NIST Critical Infrastructure Security Framework (CSF), but it's also a review of the current state of the security profession/practice/belief system, depending on your vantage point.

Penned by Jack Whitsitt of EnergySec, who among other things helped design the cyber security policies for the Transportation Security Agency (TSA) when it was just getting started. Be forewarned: Jack is no ordinary security guru. Because he's a practicing artist too, he brings both hemispheres to this challenge, and as a result, his perspectives and insights are unlike what you'll likely encounter anywhere else.


I particularly like that he begins with a 15 point description of the "problem space", something that might have helped the CSF initiative itself get off to a better start. Points 1-3 establish an overall tone of realism that includes references to money and outcomes:
  1. We are failing at cybersecurity
  2. We are investing heavily in cyber security
  3. Our organizations are getting breached at unacceptable rates
Doesn't sound like a status quo anyone interested in national security would want to maintain much longer. Or the CEO of large power company, for that matter.

I particularly like point 11, which I'll paraphrase below to suit our purposes:
A more likely way of getting at the cultural and business underpinnings of cyber security would be to start with business outcome objectives and then elicit a framework to meet those objectives. AB - now here's the magic part: Do this while assuming a lack of a dedicated security team and without making references to cyber security specific technologies. 
As Jack continues, this allows the discussions to remain in plain-English business language, which means the business folks, advocating for their business objectives, remain active participants in the conversation and the solution formulation process throughout.

There is a ton more to like in his comprehensive treatment of the subject matter.  You'll find the full piece, "My comments to NIST on the Preliminary Cybersecurity Framework" right HERE.

NERC CIPs Catching up to iPhone Version Numbers


OK, imagine an auction barker: "Bids opening at NERC version 3, do we have a version 3? ..."

"Yes! How about version 4?" Etc.

Well, according to Honeywell's NERC CIP guru Tom Alrich (of the famous, eponymous and quite helpful blog), it now appears that the next version of the CIPs to which utilities must comply will be neither version 4 nor  5 but rather version 6!

I was stunned as were many of the those in online attendance. Tom explains his reasoning on the EnergySec webcast and much more, which you can see HERE. There's a lot of helpful information for utilities of all sizes dispensed in this hour long piece, with some deep dives into the ramifications of high, medium, and low risk assets.

Now, depending on whether we get an iPhone 5s or 6 next month, it's clear that NERC will not allow the CIP versions to lag far behind.

----------------------------

Attended most of this webinar online, but hat tip to my former colleague and (hopefully) current friend, Nebraskan Dave Hemsath of IBM for sending me the replay.

Photo credit: KCRW.com

Motivation through Compensation: Paying Utilities to Upgrade Cyber Defenses

Now we're getting somewhere!  The long submerged topic of "who should pay" for electric utility cyber security improvements has just breached the surface and is now bobbing up and down in clear daylight.

A recent article in Bloomberg documents several large US utilities' efforts to recover current and future cyber security investments the same way they get paid for other infrastructure programs: by getting clearance from their state utility commissions to approve these expenses in their rate cases.

Actually rate payers (aka electricity customers) will pay one way or another, as they should, for the essential service that makes our modern lifestyles possible.  Possible methods of payment include:
  • Absorbing the costs to their businesses and their lives associated with brown outs or black outs or electricity quality issues stemming from successful attacks on control centers or systems
  • Paying more every month to cover some, most or all (TBD) of their utilities' cyber-protection expenses
  • Or, as Pepco CIO Doug Myers said, as cited in the Bloomberg article, allowing utilities to be reimbursed through federal grants
This concept was articulated more formally by Michael Daniel, special assistant to the President on Cybersecurity, when he included rate recovery as one of a number of cyber incentive strategies for critical infrastructure providers:
Rate Recovery for Price Regulated Industries — Agencies [DHS, Commerce, Treasury] recommended further dialogue with federal, state, and local regulators and sector specific agencies on whether the regulatory agencies that set utility rates should consider allowing utilities recovery for cybersecurity investments related to complying with the Framework and participation in the Program.
As this blog often reiterates, we have to acknowledge and accept the costs of living in a technology-enabled world, where the impulse to cyber secure important services must become every bit as natural as physically securing our more tangible valuables.

Else, I have a nice cave I'd like to show you. And no, it doesn't have wifi.

NIST Thinking about Cyber Security for Critical Infrastructure Company Boards and CEOs


I just returned from the beautiful UC San Diego campus (hmmm, if only I could travel back in time and attend this school instead ...) where NIST assembled hundreds of cyber security (and other) professionals to advance the initiative known as the Critical Infrastructure Cybersecurity Framework, or CSF for short.

So far some are happy with progress made and some are quite the opposite. I think a little more time will have to pass and we'll have to see what comes out of the NIST oven ahead of the final workgroup session coming up in Dallas.


In San Diego, we spent a lot of time in groups fleshing out the categories and subcategories in various cyber security-related functional areas ... not sure how productive that activity will prove to have been. However, towards the end of the day on Thursday everyone had a chance to participate in one of several break out sessions.  I won't list them all here, but some were Privacy, Small Business, DHS, and  the one I worked in was the Senior Executive Cyber Security Support session facilitated by Kiersten Todt and attended by what looked like 40 or 50 folks.

So, our challenge was to generate strategies for engaging CEOs, Boards of Directors and other senior leaders to, once it's built, buy into the CSF triggered by Presidential Executive Order 13636: "Improving Critical Infrastructure Cybersecurity" earlier this year. Going in I was skeptical that a bunch of security folks would have any idea how to communicate effectively with, let alone persuade, senior business or Federal executives about anything.

Fortunately, there were at least a handful in the room who in their careers had regular and frequent exchanges with large company CEOs, other C-Suiters, and sometimes Board members. And their Federal and DoD counterparts as well.

Hundreds of ideas were articulated rapid fire (I pitied the scribe but it looked like she was keeping up) and I'll leave it to NIST to select out and leverage the ones they think can be helpful. But I'll use this space to call out two I think had significant merit:

  • One person said government should do test runs of CSF on a handful of companies to demonstrate effectiveness and costs and that the results could then be used as evidence. Assuming benefit can be demonstrated, it could be packaged as a cost/benefit analysis to support discussions with senior management
  • Even if NIST and the crew constructing the CSF does a fine job and creates something potentially useful for the different industries it's designed to help, unless it's introduced via an outstanding marketing campaign targeting the right outlets (e.g., WSJ, Barrons, HBR, etc.) the CSF will never get the attention it needs to succeed.  Take-away for NIST and partners: be ready to focus nearly as much (or maybe more) on marketing, messaging and communications strategies as we are on building a good product
So, whether the CSF is ultimately judged a success or not, I think getting security folks to begin thinking and talking in terms that senior business folks can understand is not just helpful, but absolutely necessary if we're ever going to bridge the divide between the C-Suite and the increasingly strategic Cybersecurity function.

Photo credit: UCSD Math Dept.

NIST Critical Infrastructure Cyber Security Framework (#NISTCSF) Effort Steaming Ahead


Five hundred souls or so are expected in sunny San Diego this week for the 3rd round of meetings intended to produce new cyber security guidelines for operators of US critical infrastructure.

This article gives you the most recent update on status including cares and concerns related to privacy, business case, and getting senior management buy-in to even consider following this framework in the first place:

http://insidecybersecurity.com/Cyber-Daily-News/Daily-News/nist-meeting-poses-major-test-for-obama-cybersecurity-push/menu-id-1075.html

It references this DHS doc from earlier this year that attempts to pave the way for CEOs to become more engaged in their organization's cyber security efforts, called Cyber Security Questions for CEOs:

https://www.us-cert.gov/sites/default/files/publications/DHS-Cybersecurity-Questions-for-CEOs.pdf

Lastly, if you want to see more of the process without actually getting your feet weight (or getting on a west-bound plane) here are a few resources for you:

The emerging framework itself: http://www.nist.gov/itl/cyberframework.cfm

Details on the San Diego workshop: http://www.nist.gov/itl/csd/3rd-cybersecurity-framework-workshop-july-10-12-2013-san-diego-ca.cfm

Live webcasts of the proceedings can be viewed via these URLs:
Day 1 (Wednesday) Webcast: http://www.youtube.com/watch?v=3hJww5_BDSQ
Day 2 Webcast: http://www.youtube.com/watch?v=SLVW0vFw0gI
Day 3 Webcast: http://www.youtube.com/watch?v=-9hORcAcXNA
I'm flying out today, along with a few of my IBM colleagues. Looking forward to seeing some of you there.

Photo credit: The San Diego Union-Tribune



Super Cyber Security Reading: 2Q ICS-CERT Monitor

Unfortunately, the Energy Sector wins this competition over last 12 months

There are few publications you can read that will tell you more about the current state of cyber awareness and attacks on critical infrastructure orgs and systems than this than the Monitor.


Before we go much further, laypersons, get ready for some advanced acronym unpacking.

Published quarterly by the US Department of Homeland Security (DHS), the Industrial Control Systems (ICS) Computer Emergency Response Team (CERT), this 15 page document gives you the latest findings and trends.

There's a lot of goodness is the 2Q issues, but I'm going to show you just a couple paragraphs and call out some key words in bold that'll give you a feel for the overall messages it contains.  Let's see how this works:
Most recently, ICS-CERT has assisted critical infrastructure entities in the energy and critical manufacturing sectors with response to cyber intrusion attempts and compromises related to an emerging cyber threat actor. These incidents have involved common exploitation techniques and readily available tools that have been deployed successfully against many companies to compromise networks.
OK, so far so good. You can see that attackers are succeeding without having to work too hard. Now this with a bit more in bold:
In the first half of fiscal year 2013, ICS-CERT has deployed five (5) onsite teams compared to six (6) in all of fiscal year 2012. Three of the onsites were in the energy sector and two were in the critical manufacturing sector. All of the onsite incident response engagements involved sophisticated threat actors who had successfully compromised and gained access to business networks
While onsite, ICS-CERT analysts examined networks and artifacts to determine if ICS networks were also compromised. Unfortunately, in many cases that analysis was inconclusive because of limited or non-existent logging and forensics data from the ICS network
While cyber security threats to ICS and other systems can feel overwhelming at times, it's important to note that utilities and other user organizations can do a lot to improve their posture, without either breaking the bank or having to hire dozens of Einsteins. ICS-CERT is a great resource, one that I'd hope you can use as much as possible, proactively vs. reactively.

--------------------------

URL for Monitor report

http://ics-cert.us-cert.gov/sites/default/files/ICS-CERT_Monitor_April-June2013.pdf

All the NIST Critical Infrastructure Security RFI Responses You Can Eat


Re: the many and various submissions from companies and individuals to NIST, someone who knows more than a few things about grid security recently tweeted twice thusly:
Reading - and in many cases laughing at - #NISTCSF responses
and ...
The responses? Mostly neutrally irrelevant, some nonsensical. I've marked only 14% so far for "real" read later
I just want you to set your expectations bar sufficiently low before you click HERE and read all of the responses.

By the way there were a few good and very good responses too.

If, after reading, you not only feel like you have something to suggest that hasn't yet been suggested, but you also want to physically transport and immerse yourself in this grand sausage making activity, then ...

For more information on the 2nd workshop coming up in late May in Pittsburgh, and a link where you can register, click on THIS.

Photo credit: @Doug88888 on Flickr.com

NatGas Cybersecurity getting a lot more Visibility


Thanks to colleague H. Chantz for spotting this article and sending this way.

As has been the case quite a bit this year, once again we are in the realm of SCADA/Control System security. William Rush of the Gas Technology Institute states it plainly, if somewhat dramatically:
Anyone can blow up a gas pipeline with dynamite. But with this stolen information, if I wanted to blow up not one, but 1,000 compressor stations, I could,” he adds. “I could put the attack vectors in place, let them sit there for years, and set them all off at the same time. I don’t have to worry about getting people physically in place to do the job, I just pull the trigger with one mouse click.
There are no NERC CIPs for the gas industry, but with 25-30% of US electric power and a whole lot of home heating coming from gas, it's time to get moving on better securing this infrastructure.

Pipeline operators, now alerted to the fact that sensitive access control information to important subsystems is in the hands of folks outside the industry (and outside the country it seems), need to get moving. And I'm sure they will, but it's a BIG job.

The whole Christian Science Monitor article is HERE.

Photo credit: War News Updates

NIST Critical Infrastructure Cybersecurity Framework RFI and Workshop Details

We're about a month away from the first NIST workshop to help create the new framework described in the recent Executive Order, as well as from the 5 pm, USA ET, April 8 deadline to submit responses to the RFI.

To refresh, here's what they/we are trying to do:
The goals of the Framework development process will be: (i) To identify existing cybersecurity standards, guidelines, frameworks, and best practices that are applicable to increase the security of critical infrastructure sectors and other interested entities; (ii) to specify high-priority gaps for which new or revised standards are needed; and (iii) to collaboratively develop action plans by which these gaps can be addressed. It is contemplated that the development process will have requisite stages to allow for continuing engagement with the owners and operators of critical infrastructure, and other industry, academic, and government stakeholders.
If you are so moved and have something to say (and NIST and I hope you do), here's how to submit your ideas and recommendations:

Old School
For those who prefer to communicate longhand by dipping your peacock feather quill into the inkwell on your vintage desk, "Written comments may be submitted by mail to Diane Honeycutt, National Institute of Standards and Technology, 100 Bureau Drive, Stop 8930, Gaithersburg, MD 20899."

New School
"Electronic submissions may be in any of the following formats: HTML, ASCII, Word, RTF, or PDF. Online submissions in electronic form may be sent to cyberframework@nist.gov."

Do this in Either Case
"Please submit comments only and include your name, company name (if any), and cite“Developing a Framework to Improve Critical Infrastructure Cybersecurity” in all correspondence."

'Know this in Either Case: Your Written Comments will be Public
"All comments received by the deadline will be posted at http://csrc.nist.gov without change or redaction, so commenters should not include information they do not wish to be posted (e.g., personal or confidential business information)."

In Person
Sometimes there's no substitute for being there in person, so if that's your desire, you can click HERE to register for the April 3 workshop in beautiful Gaithersburg. Hope you can make it and fair warning if you do: I'll be there too!

DHS' CSET: a Remedy for Electric Sector Security Measurement and Reporting Complexity Pains?

Sorry about that ridiculously long title, but felt it couldn't be helped this time. Thanks to Dr. Les Cardwell of Central Lincoln PUD, a publicly owned utility serving communities on the coast of Oregon.

Les wrote in and shared some of what he recommended to NIST and DOE regarding the recent RFI on the "Framework for Reducing Cyber Risks to Critical Infrastructure."

I'm not going to reprint the entirety of his submission, but will share with you two things here. First, Les' articulation of the need for a way to keep complexity in check as we go about this search for a new/better security framework for our community:

I would like to address ... "the "elephant in the room" ... [that could hinder our achievement of] a Digital Systems Security (DSS) Cybersecurity standard across the US Utility spectrum. That issue is the "expanding redundant complexity" of the current approach to the problem domain. While one can appreciate the efforts [involved] in gathering more information from the industry ... for establishing and improving frameworks to raise the overall level of cybersecurity ..., the problem is that it does not address the inherent complexity of the problem. It only exacerbates it by creating yet more administrative requirements for decomposing and resolving the problem domain for each utility.
I think he's on to something. There's more text clarifying the challenge and then some words on what Les proposes could play a major role in the final solution: DHS' own Cyber Security Evaluation Tool (CSET). The department has put together a nice succinct info sheet on CSET, so rather than telling you more about it, I suggest you read it for yourself, which you can do HERE.

I've got some learning to do myself on this, but in the meantime, please let me know if you think CSET has a role to play in this grand challenge.

Heralding the Dawn of Critical Infrastructure Security Metrics


You may like this blog because of its emphasis on business-oriented security metrics and measurement. Or you may loathe it for the same reason (though if you do, you shouldn't still be visiting much).

Can't measure, can't manage. On this we agree, right?

So ... we're two weeks past the Presidential executive order (EO) that kicked off a new round of meetings that will ultimately produce a new NIST framework for grid security. You can read about the goals for this thing, including the RFI process HERE.

Thanks for EnergySec's Patrick Miller who tweeted yesterday that this round of work is designed, among other things, to produce metrics that can be used to assess the current security posture of your organization.

To whit, "The Framework should include flexible, extensible, scalable, and technology-independent standards, guidelines, and best practices, that provide:
Metrics, methods, and procedures that can be used to assess and monitor, on an
ongoing or continuous basis, the effectiveness of security controls that are
selected and deployed in organizational information systems and environments in
which those systems operate and available processes that can be used to facilitate
continuous improvement in such controls."

Bravo. Also I note and you'll see, in a section called Current Risk Management Practices, these highly metrics-suggestive questions:.
  • How do organizations define and assess risk generally and cybersecurity risk specifically?
  • To what extent is cybersecurity risk incorporated into organizations’ overarching enterprise risk management?
  • What standards, guidelines, best practices, and tools are organizations using to understand, measure, and manage risk at the management, operational, and technical levels?
You can see where this is leading, can't you? I'll plan to be at the first framework development meeting that's open to industry, and will be including my 2 cents in the RFI process as well. Recommend you do same. 

Heard that meeting might be on April 3 and will confirm or revise accordingly.

Photo credit: Wikimedia.org

CNAS Provides a Good Way to Grok the Executive Order

First of all, Happy Valentines Day, SGSB readers.  Hope you are finding as much success in your love lives as you are in your careers securing (or caring about securing) the most critical of critical infrastructures.

Yesterday found me walking down the street in Washington DC a little before noon, when suddenly I ran into some friends, old and new, who had just popped out of the US Department of Commerce. They witnessed directly, and gave me a  first-hand account, of the birth of the administration's Executive Order (EO) on better securing the nation's critical infrastructures.

We've been waiting for this, or something like this, for quite a while. The most recent legislative pushes were the GRID Act of 2010 which almost made it, and the Cybersecurity Act of 2012, which came similarly close but failed to pass both houses. The narrative goes: since Congress couldn't do it, the President did what he could.

Anyway, let's get to the EO while we're young. Of the torrent of analysis I came across yesterday, this one, by Irving Lachow and Jacob Stokes of the Center for New American Security (CNAS) stood out as the best and most comprehensible.

I'll highlight one section before giving you a link to their work. It's on the part many of us are wondering about ... that is, what is the likelihood that the EO will have a marked and observable impact on security posture. Nothing in the EO is mandatory; therefore, as some have suggested, it may turn out to be much ado about nothing.

Here's the CNASers' take:
The provisions within the EO may not, by themselves, change the fundamental incentives driving the behavior of critical infrastructure operators. As important as it is to identify possible incentives for changing the behavior of critical infrastructures, the government will need to experiment with these incentives to see which ones work. Conducting such experimentation will require the establishment of a well-structured and rigorous evaluation program. Congressional action may be needed to implement some incentives and to enable the proper evaluation of different options.
But I and many others hope it's much ado about something. Here's a LINK to the full CNAS write-up, and here's a LINK to the EO itself. We'll have to see how it plays out, and play our respective parts too. NIST is going to need your input and I'll share notices on how and when you can do that when I get the info. 

Meanwhile, have a great and potentially romantic day please.

Security Double Dutch: Shodan Points out Critical Infrastructure Gaps in the Netherlands


Hat tip to friend and colleague Steve D for shooting this my way.
Security researcher Oscar Koeroo, working for the Dutch nuclear physics institute NIKHEF, found out that national infrastructural systems were listed on Shodan, (a database of cyber security vulnerabilities) and could be easily accessed remotely. Those systems, controlling pumping stations and sluices, are vital for the water management of a large part of the Netherlands. Because a large part of the country lies below sea-level, those systems keep the Dutch feet dry!
I've been to the Netherlands several times and saw the country in the news a lot recently when UberStorm Sandy raised concerns that New York City should perhaps get similar types of protective systems. I can assure you that this is about much more than a preference for dry feet.

Read on to find out how control system search engine Shodan once again reveals what systems are directly connected to the Internet. Warning, it paints a full picture, but it's not a pretty picture, and hopefully you won't find systems in your charge popping up in the findings window!

Here's the complete article from Tofino, replete with lurid details of password mismanagement, accusations, denials and counter-accusations, and that sort of thing. Best keep a Heineken or two handy.

Photo credit: nrc.nl

So Far, it Seems WAMPAC Systems are Insecure by (Lack of) Design


Thanks to colleague Jeff K for pointer to recent NESCOR reports.

First things first: in IBM and elsewhere the phrase "secure by design" is used to describe a project or a system where security requirements are considered at the earliest stages, right along with all the functional requirements.

Now for new initiates, WAMPAC = Wide Area Monitoring, Protection and Control, and the term refers to a group of new technologies and capabilities that will put the Smart in Smart Grid much more than the more attention grabbing Smart Meter.


This IEEE abstract does a better job defining WAMPAC than I could, so here you go:
Market driven grid management, increased number of renewable/distributed generation sources, complexities to address reactive support, and a progressively more stressed transmission network have increased the complexity of operation, monitoring, control and protection of large interconnected electric power systems considerably. Power-grid congestion issues and disturbances worldwide have emphasized the need to enhance power grids with WAMPAC systems as a cost-effective solution to improve grid planning, operation, maintenance, and energy trading. WAMPAC systems take advantage of the latest advances in sensing, communication, computing, visualization, and algorithmic techniques.
Sounds like one could become rather dependent on systems like this, no?  So you would want to ensure that the P in WAMPAC includes protection of the system itself so the system can do its job helping to protect the grid. Alas, it seems, that's not how it's gone down so far.

Please allow me to pause for a brief, somewhat alarmist thought. Let your mind wander for a moment and imagine the importance of data integrity in such a system, and what could befall large chunks of the grid should the data that drives WAMPACs be modified surreptitiously by an uninvited 3rd party.

From the most recent draft of the Annabelle Lee and EPRI-led security review of WAMPAC initiatives underway, we get the following findings up front:

  • Several WAMPAC standards were developed on a fast track, and several new standards are either in the final approval or development stage. During this standards development organization (SDO) process, guidelines for a consistent approach to cyber security requirements across the standards were not developed
  • Most of the WAMPAC standards do not mention any cyber security requirements. Some that do mention cyber security but at a very generic level, suggesting that such issues should be addressed by separate standards focused on cyber security.
Long suffering security pro's will hardly be surprised by the lack of inclusion of security requirements, even for projects as important as WAMPAC. Others may be be surprised. Whichever camp you fall in, you can read the full report HERE. Lots of good recommendations included, though you can't help but wish we weren't in bolt-on security mode again.

Photo credit: ISO New England