Hiển thị các bài đăng có nhãn press coverage. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn press coverage. Hiển thị tất cả bài đăng

Supply Chain Security Awareness on Upswing for Energy and Comm Sectors

10/25/12 Update: Huawei just said it is ready to have all its source code tested for security. Would other vendors be so bold?

------------------

If you don't subscribe to the online version of the Wall Street Journal, you probably don't get its daily CIO feed, which provides a nice topical tapas-sized taste of what's on folk's minds every morning.

One of those folks is me, and I've been stirred up lately by all the press (The Economist, 60 Minutes, etc.) and Capitol Hill attention Chinese communications equipment maker Huawei has been getting. Personally, I haven't have any direct contact with Huawei or its products, but I have a gut-level response when a company gets pilloried solely on where it's headquartered or the nationality of the owner(s).

This comes from my prior experience in application security and some vetting procedures that give credit to applications built by companies with US ownership. The distance between owners, whose reputation and integrity may be stellar, and the products themselves, is vast. In the the software world, rule #1 is re-use. Components written all over the world are easy to find, buy or borrow these days. And security is often not in the decision tree of the developers on either side of the equation.

Of course, owners' reputations may be less or far less than stellar, but still, the distance remains and they have  little impact on the ultimate security characteristics of their wares. All that to say, Huawai's products need to be scrutinized carefully prior to purchase and deployment. But the same level of attention needs to be paid to ALL 3rd party products, IT and OT, hardware and software, regardless of country of  origin.

Take it away Michael Hickins (from The Morning Download: Beware Your IT Supply Chain):
Good morning. A White House report leaked Thursday exonerated Huawei of spying on behalf of the Chinese government. But that doesn't mean you can rest easy. The same report found vulnerabilities in the company’s networking equipment, which put customer data at risk.
Customers are unwittingly installing computing and networking equipment and software rife with back doors created by vendors who outsource parts of their production to partners in “politically hostile” areas of the world, according to Gartner analyst Neil McDonald, who just published a study on the topic. “Attackers use weaknesses in a supply chain to get a foothold on a system rather than attack a system in production, which is hard on a well-defended system,” McDonald told CIO Journal.
CIOs can reduce the risk of introducing trap-door-riddled IT by demanding proof of an explicit chain of custody from IT suppliers covering all third-party hardware and software they use in their products. They also should require their IT system providers to periodically sample and test their products; and they should procure the same equipment used by government agencies, which in some cases employ electron microscopes and chemicals to test IT components. McDonald says the spotlight on Huawei put IT supply chain risks “on the radar screen of every CIO.” Now it’s up to every CIO to act on this information.
Nicely said Neil McDonald.

Mid 2012 GAO Update on Grid Security ... and a Mea Culpa

Before teeing up the most recent GAO report on electric sector cybersecurity, I'd like to use this pixelated platform to speak back to a quote attributed to me last week that raised the hackles of some utility professionals (and it should have).

First, I'm neither a security-focused PR flack for the electricity industry, nor a gotcha journalist trying to capture eyeballs by vilifying utilities and scaring readers. Rather, I'm a member, supporter, advocate, and hopefully, sometimes, a constructive critic of the enterprise of keeping the grid safe and secure while updating it for the 21st century.

So here's the thing: a recent interviewer quoted me as saying senior management doesn't have a very good understanding of their security posture. While I'm sure I've said something like this a hundred different ways on the blog, it's never been intended as an insult or attack, but rather as observation of the current state of affairs at many but not all utilities. The way  this was captured and framed in the article, however, losing nuance and a few other qualifying words along the way, it definitely came off as a blunt attack ... and I'm not the only one who noticed. Sorry about that ... wasn't my intent.

However, support for this type of generic observation comes from things everyone in the industry already knows, and that the GAO lists on the highlights page of its July 2012 report. Here are the last 4 challenges, partially addressing utilities, partially the larger industry ecosystem:
  • A focus by utilities on regulatory compliance instead of comprehensive security
  • A lack of security features consistently built into smart grid systems
  • The electricity industry did not have an effective mechanism for sharing information on cybersecurity and other issues
  • The electricity industry did not have metrics for evaluating cybersecurity (AB: of course I'll come back to this one before the post is over!)
All of these things make sense to folks who've either been in a utility or have worked with utilities and/or regulators for some time. There's a logical history to each of them that explains where they came from and why they remain challenges to be solved. 

And you'll note (and it angers some of the more concerned security pundits when I say this), that whatever US utilities have done so far has apparently been enough to keep cyber attackers from having major successes to date.

As this post is now getting too long and trying to do too many things, let's end with another invocation on the benefits of business-oriented metrics, this time courtesy of the GAO itself:
... Having metrics would help utilities develop a business case for cybersecurity by helping to show the return on a particular investment. Until such metrics are developed, there is increased risk that utilities will not invest in security in a cost-effective manner, or have the information needed to make informed decisions on their cybersecurity investments.
The GAO, I think, comes from a similar position, in some ways anyway, as this blog. The cited report mentions not just shortcomings but positive actions taken so far. The GAO, the SGSB (this blog) and plenty of other groups and individuals simply want to see utilities and the industry be safe and successful while they modernize to meet the demands of our times. Neither are interested in criticism for criticism's sake, but only to suggest better possible methods. I'll leave it at that for now.