Hiển thị các bài đăng có nhãn standards. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn standards. Hiển thị tất cả bài đăng

Heads-Up: The 2013 ICS Cybersecurity Summit is Closing In


We talked about this conference and many of its concerns a few weeks ago at the EnergySec Summit, and among things, got a great presentation showing how one utility has built and gotten great value from its OT security test-bed.

There's going to be a talk on test-beds plus a bunch of other great presentations at the annual "Joe Weiss" summit, so if you have interest, and the ability to get there,  I highly recommend you do.

Here are the basics:
Dates: 21-24 October 2013 
Venue: Conference location: GTRI Conference Center, 250 14th Street NW, Atlanta, GA 30318 
LINK for more info and to register 
LINK to register
Photo credit: Jomi Thomas Mani @ Flickr.com

RFP Alert: Security Advisor Sought for New England Utility Commissions

No sooner had I posted on the need for more state utility commissions to ensure access to quality cyber security guidance, when an RFP with this exact goal in mind came across my desk (figuratively speaking). So without further delay, your attention please:

The region of 6 northeastern US states collectively referred to as "New England" and boasting the highest per-capita concentration of Dunkin Donuts is seeking one very well qualified energy and cyber security professional to help guide them for a six month period commencing in mid September.

The New England Conference of Public Utilities Commissioners, Inc. (NECPUC) has issued an RFP for which responses are due NLT 5 pm August 8, 2013. I provide the URL to the RFP below but to save you an unnecessary trip, here are the qualifications required if you or your small firm want to even be considered for the job:
  • Background and knowledge of utility sector industrial control system and business operations
  • Knowledge and expertise in computer systems security and related physical security issues
  • Certified Information Systems Security Professional or similar computer security management certification preferred
  • U.S. Government security clearance of “Secret” or higher preferred
  • Engineering and/or information technology degree and training preferred
  • Knowledge of NERC CIP standards
  • Certified Information Systems Security Professional, Certified Information Security Manager or similar computer security management certification preferred
  • Ability to drive throughout New England visiting public utility commissions and utilities will be required (ab add: must be a confident driver in snow)
Does that sound like you?  If so, recommend you get started on your proposal. The New England state commissions are eager to get started!

(If not, but you think you know a qualified candidate, pleasure forward this on to them stat - thanks.)

------------------------------------

URL for NECPUC RFP:

http://www.aesp.org/associations/5980/files/RFP%20for%20Cyber%20Security%20Consultant%20FINAL.pdf

URL for previous SGSB post on PUCs and cyber security:

http://smartgridsecurity.blogspot.com/2013/07/to-secure-your-state-grid-first-know.html

NIST Thinking about Cyber Security for Critical Infrastructure Company Boards and CEOs


I just returned from the beautiful UC San Diego campus (hmmm, if only I could travel back in time and attend this school instead ...) where NIST assembled hundreds of cyber security (and other) professionals to advance the initiative known as the Critical Infrastructure Cybersecurity Framework, or CSF for short.

So far some are happy with progress made and some are quite the opposite. I think a little more time will have to pass and we'll have to see what comes out of the NIST oven ahead of the final workgroup session coming up in Dallas.


In San Diego, we spent a lot of time in groups fleshing out the categories and subcategories in various cyber security-related functional areas ... not sure how productive that activity will prove to have been. However, towards the end of the day on Thursday everyone had a chance to participate in one of several break out sessions.  I won't list them all here, but some were Privacy, Small Business, DHS, and  the one I worked in was the Senior Executive Cyber Security Support session facilitated by Kiersten Todt and attended by what looked like 40 or 50 folks.

So, our challenge was to generate strategies for engaging CEOs, Boards of Directors and other senior leaders to, once it's built, buy into the CSF triggered by Presidential Executive Order 13636: "Improving Critical Infrastructure Cybersecurity" earlier this year. Going in I was skeptical that a bunch of security folks would have any idea how to communicate effectively with, let alone persuade, senior business or Federal executives about anything.

Fortunately, there were at least a handful in the room who in their careers had regular and frequent exchanges with large company CEOs, other C-Suiters, and sometimes Board members. And their Federal and DoD counterparts as well.

Hundreds of ideas were articulated rapid fire (I pitied the scribe but it looked like she was keeping up) and I'll leave it to NIST to select out and leverage the ones they think can be helpful. But I'll use this space to call out two I think had significant merit:

  • One person said government should do test runs of CSF on a handful of companies to demonstrate effectiveness and costs and that the results could then be used as evidence. Assuming benefit can be demonstrated, it could be packaged as a cost/benefit analysis to support discussions with senior management
  • Even if NIST and the crew constructing the CSF does a fine job and creates something potentially useful for the different industries it's designed to help, unless it's introduced via an outstanding marketing campaign targeting the right outlets (e.g., WSJ, Barrons, HBR, etc.) the CSF will never get the attention it needs to succeed.  Take-away for NIST and partners: be ready to focus nearly as much (or maybe more) on marketing, messaging and communications strategies as we are on building a good product
So, whether the CSF is ultimately judged a success or not, I think getting security folks to begin thinking and talking in terms that senior business folks can understand is not just helpful, but absolutely necessary if we're ever going to bridge the divide between the C-Suite and the increasingly strategic Cybersecurity function.

Photo credit: UCSD Math Dept.

NIST Critical Infrastructure Cyber Security Framework (#NISTCSF) Effort Steaming Ahead


Five hundred souls or so are expected in sunny San Diego this week for the 3rd round of meetings intended to produce new cyber security guidelines for operators of US critical infrastructure.

This article gives you the most recent update on status including cares and concerns related to privacy, business case, and getting senior management buy-in to even consider following this framework in the first place:

http://insidecybersecurity.com/Cyber-Daily-News/Daily-News/nist-meeting-poses-major-test-for-obama-cybersecurity-push/menu-id-1075.html

It references this DHS doc from earlier this year that attempts to pave the way for CEOs to become more engaged in their organization's cyber security efforts, called Cyber Security Questions for CEOs:

https://www.us-cert.gov/sites/default/files/publications/DHS-Cybersecurity-Questions-for-CEOs.pdf

Lastly, if you want to see more of the process without actually getting your feet weight (or getting on a west-bound plane) here are a few resources for you:

The emerging framework itself: http://www.nist.gov/itl/cyberframework.cfm

Details on the San Diego workshop: http://www.nist.gov/itl/csd/3rd-cybersecurity-framework-workshop-july-10-12-2013-san-diego-ca.cfm

Live webcasts of the proceedings can be viewed via these URLs:
Day 1 (Wednesday) Webcast: http://www.youtube.com/watch?v=3hJww5_BDSQ
Day 2 Webcast: http://www.youtube.com/watch?v=SLVW0vFw0gI
Day 3 Webcast: http://www.youtube.com/watch?v=-9hORcAcXNA
I'm flying out today, along with a few of my IBM colleagues. Looking forward to seeing some of you there.

Photo credit: The San Diego Union-Tribune



All the NIST Critical Infrastructure Security RFI Responses You Can Eat


Re: the many and various submissions from companies and individuals to NIST, someone who knows more than a few things about grid security recently tweeted twice thusly:
Reading - and in many cases laughing at - #NISTCSF responses
and ...
The responses? Mostly neutrally irrelevant, some nonsensical. I've marked only 14% so far for "real" read later
I just want you to set your expectations bar sufficiently low before you click HERE and read all of the responses.

By the way there were a few good and very good responses too.

If, after reading, you not only feel like you have something to suggest that hasn't yet been suggested, but you also want to physically transport and immerse yourself in this grand sausage making activity, then ...

For more information on the 2nd workshop coming up in late May in Pittsburgh, and a link where you can register, click on THIS.

Photo credit: @Doug88888 on Flickr.com

Helpful Clarifications Still Leave NERC CIP Version 4 Changes Feeling Overwhelming

If your job is to ensure your utility complies with new version 4, certainly you've been scouring info like this for a while now. But if you're a member of electric sector support or regulatory communities, including services providers and state commissioners, it'll behoove you to get a better feel for the massively numerous and often ambiguous compliance hoops through which these folks have to jump.


Thanks for my friend and super sharp energy sector security colleague Tim Deloach for prompting me on this. And if you're going to click through and read it at all, I want you to read this Q&A first for the motivation/urgency/anxiety/terror it produces:
Q: I thought there was an 18-month implementation plan under v4 for newly identified assets?
A: You have a lot of company; many others thought the same thing – but it’s wrong.... Briefly, you have a 12-24 month implementation period under V4 for assets that are newly commissioned. or newly identified after 4/1/2014. But for assets that were in operation as of June 25 of 2012 (the day that FERC Order 761 was published in the Federal
Registry), full compliance with CIP-002-4 through CIP-009-4 is due on 4/1/2014.
Nice job EnergySec and Honeywell, particularly CIP guru Tom Alrich, for the webcast and now for following up with this Q&A infosheet.

EnergySec Welcomes NERC CIP Virgin Utilities with Version 4 Briefing

Titled "Get Ready for Version 4" the deck linked at the end of my words has some great and helpful info in it, not just for utilities transitioning from version 3, but for brand new utilities who for the first time come under the tender embrace of the CIPs. To them, all of us in the community say, "Welcome aboard !!!"

An all-star energy and security team, including Steve Parker, new President of the Energy Sector Security Consortium (EnergySec), and Honeywellers Tom Alrich and Donovan Tindill, shared some sobering, cold, hard, urgent facts. Those from Tom Alrich were particularly rich:

  • Some have asked whether 4/1/2014 is the Compliant or Auditably Compliant date. These are CIP V1 terms – 4/1/2014 is the Compliant and Auditably Compliant date for Version 4. This means you have to have everything for compliance in place on that date, and includes all policies, procedures and technologies in CIP-003 through CIP-009
  • There are some who believe that assets identified by the V4 criteria are “newly identified” under V4 – thus they have 6-24 more months to comply after 4/1/2014. They are wrong: NERC and the Region Entities are in agreement on this
Donovan Tindill was no slouch either. Ensure you ingest a few of his lessons learned, like:
  • Cyber Assets not previously inventoried need budgeted >1 hour each!
  • Actual Site Inventory Labor: 11 sites, 1500 Cyber Assets = 2,200 hours
  • Site inventory can uncover >30% more assets than originally thought!
  • Existing network drawings >2 years old cannot be trusted, easier to start over with both logical and physical cable tracing
  • 50% of equipment is non-IT traditional infrastructure and is not easily recognized nor is information you need to collect and report easily collected
OK, I don't want to steal too much more of their thunder, so without further delay or obfuscation, you can see the whole deck by clicking HERE. You realize April 1st 2014 is less than 53 weeks away right? Good luck!

Metrics Mark the End of Faith-based Cybersecurity


Thanks to Dark Reading for covering the RSA 2013 metrics panel and for the article: "Governance Without Metrics Is Just Dogma."

To whom do we owe this powerful and provocative headline? Not the editors at Dark Reading, though they were smart enough to grab it and put it at the top. It was Alex Hutton, an Operations Risk and Governance director at Zions National Bank.

In case you're not used to seeing the word dogma in this context, let's refresh ourselves with a definition (thanks Wikipedia):
Dogma is an official system of belief or doctrine held by a religion, or a particular group or organization. It serves as part of the primary basis of an ideology or belief system. 

While there are appropriate places and good uses for dogma, the C-Suite and Board of Directors conference table is not one of them. (At this point I can imagine some long-term readers saying, "tell us how you really feel").

With both risk and governance in his title, clearly Hutton's been thinking this through, when he finishes with this zinger for the Security Governance ages:
You know what you call governance guided by metrics? Risk management.
I'll be submitting some business-oriented security metrics to the NIST Critical Infrastructure Cybersecurity Framework folks in a few days, and will follow up in person with them in Gaithersberg, MD on April 3.

People love to argue about metrics; that's one of the reasons they rarely come into being in our world.  Let's see if can agree on a few that work this time ... it's partly what NIST and others are looking for us to do this time.

The whole article is, HERE.

Photo credit: Still from Dogma film (1999) from Fanpix.net

DHS' CSET: a Remedy for Electric Sector Security Measurement and Reporting Complexity Pains?

Sorry about that ridiculously long title, but felt it couldn't be helped this time. Thanks to Dr. Les Cardwell of Central Lincoln PUD, a publicly owned utility serving communities on the coast of Oregon.

Les wrote in and shared some of what he recommended to NIST and DOE regarding the recent RFI on the "Framework for Reducing Cyber Risks to Critical Infrastructure."

I'm not going to reprint the entirety of his submission, but will share with you two things here. First, Les' articulation of the need for a way to keep complexity in check as we go about this search for a new/better security framework for our community:

I would like to address ... "the "elephant in the room" ... [that could hinder our achievement of] a Digital Systems Security (DSS) Cybersecurity standard across the US Utility spectrum. That issue is the "expanding redundant complexity" of the current approach to the problem domain. While one can appreciate the efforts [involved] in gathering more information from the industry ... for establishing and improving frameworks to raise the overall level of cybersecurity ..., the problem is that it does not address the inherent complexity of the problem. It only exacerbates it by creating yet more administrative requirements for decomposing and resolving the problem domain for each utility.
I think he's on to something. There's more text clarifying the challenge and then some words on what Les proposes could play a major role in the final solution: DHS' own Cyber Security Evaluation Tool (CSET). The department has put together a nice succinct info sheet on CSET, so rather than telling you more about it, I suggest you read it for yourself, which you can do HERE.

I've got some learning to do myself on this, but in the meantime, please let me know if you think CSET has a role to play in this grand challenge.

Heralding the Dawn of Critical Infrastructure Security Metrics


You may like this blog because of its emphasis on business-oriented security metrics and measurement. Or you may loathe it for the same reason (though if you do, you shouldn't still be visiting much).

Can't measure, can't manage. On this we agree, right?

So ... we're two weeks past the Presidential executive order (EO) that kicked off a new round of meetings that will ultimately produce a new NIST framework for grid security. You can read about the goals for this thing, including the RFI process HERE.

Thanks for EnergySec's Patrick Miller who tweeted yesterday that this round of work is designed, among other things, to produce metrics that can be used to assess the current security posture of your organization.

To whit, "The Framework should include flexible, extensible, scalable, and technology-independent standards, guidelines, and best practices, that provide:
Metrics, methods, and procedures that can be used to assess and monitor, on an
ongoing or continuous basis, the effectiveness of security controls that are
selected and deployed in organizational information systems and environments in
which those systems operate and available processes that can be used to facilitate
continuous improvement in such controls."

Bravo. Also I note and you'll see, in a section called Current Risk Management Practices, these highly metrics-suggestive questions:.
  • How do organizations define and assess risk generally and cybersecurity risk specifically?
  • To what extent is cybersecurity risk incorporated into organizations’ overarching enterprise risk management?
  • What standards, guidelines, best practices, and tools are organizations using to understand, measure, and manage risk at the management, operational, and technical levels?
You can see where this is leading, can't you? I'll plan to be at the first framework development meeting that's open to industry, and will be including my 2 cents in the RFI process as well. Recommend you do same. 

Heard that meeting might be on April 3 and will confirm or revise accordingly.

Photo credit: Wikimedia.org

So Far, it Seems WAMPAC Systems are Insecure by (Lack of) Design


Thanks to colleague Jeff K for pointer to recent NESCOR reports.

First things first: in IBM and elsewhere the phrase "secure by design" is used to describe a project or a system where security requirements are considered at the earliest stages, right along with all the functional requirements.

Now for new initiates, WAMPAC = Wide Area Monitoring, Protection and Control, and the term refers to a group of new technologies and capabilities that will put the Smart in Smart Grid much more than the more attention grabbing Smart Meter.


This IEEE abstract does a better job defining WAMPAC than I could, so here you go:
Market driven grid management, increased number of renewable/distributed generation sources, complexities to address reactive support, and a progressively more stressed transmission network have increased the complexity of operation, monitoring, control and protection of large interconnected electric power systems considerably. Power-grid congestion issues and disturbances worldwide have emphasized the need to enhance power grids with WAMPAC systems as a cost-effective solution to improve grid planning, operation, maintenance, and energy trading. WAMPAC systems take advantage of the latest advances in sensing, communication, computing, visualization, and algorithmic techniques.
Sounds like one could become rather dependent on systems like this, no?  So you would want to ensure that the P in WAMPAC includes protection of the system itself so the system can do its job helping to protect the grid. Alas, it seems, that's not how it's gone down so far.

Please allow me to pause for a brief, somewhat alarmist thought. Let your mind wander for a moment and imagine the importance of data integrity in such a system, and what could befall large chunks of the grid should the data that drives WAMPACs be modified surreptitiously by an uninvited 3rd party.

From the most recent draft of the Annabelle Lee and EPRI-led security review of WAMPAC initiatives underway, we get the following findings up front:

  • Several WAMPAC standards were developed on a fast track, and several new standards are either in the final approval or development stage. During this standards development organization (SDO) process, guidelines for a consistent approach to cyber security requirements across the standards were not developed
  • Most of the WAMPAC standards do not mention any cyber security requirements. Some that do mention cyber security but at a very generic level, suggesting that such issues should be addressed by separate standards focused on cyber security.
Long suffering security pro's will hardly be surprised by the lack of inclusion of security requirements, even for projects as important as WAMPAC. Others may be be surprised. Whichever camp you fall in, you can read the full report HERE. Lots of good recommendations included, though you can't help but wish we weren't in bolt-on security mode again.

Photo credit: ISO New England

Perhaps Better Fettered: 2nd Thoughts on ENISA's Cybersecurity Report from this Side of the Pond

Had a number of reader responses to this week's post on the European information security organization's proclamation of intent and recommendations for the electric sector and Smart Grid. 

My post welcomed the attention to the issue by the EU, but expressed, hopefully in a mainly professional way, that this feels, to invoke a common American idiom, a day late and a dollar short.

Here are two additional observations I got:
1. One US respondent says "It contains no call for cooperation with US-CERT, FERC or equivalent body on problems that are clearly of interest to both sides. Compare with various DHS initiatives (such as DHS ICSJWG) which have included foreign participants."
Concur. References to SANS, NIST and DHS in the bibliography notwithstanding, it does appear that explicit calls for trans Atlantic, interagency cooperation are missing, and that this should be rectified in a next version.
2. Another true blue American notes "ENISA reports do not adequately address control systems."
While the bibliography is littered with entries for SCADA and Control Systems-related texts, it doesn't seem like much of that research made it into the final document. Still, while most of the 10 recommendations involve getting ready to get ready to do something, and control system security seems to be largely glossed over, there is, in requirement 6, language that might point to operational systems at some point:
Recommendation 6. Both the EC and the MS competent authorities should promote the development of security certification schemes for components, products and organisational security.
So I'll leave it at that for now. Would welcome an ENISA response. I always try to not be too hard on 1.0 documents because there's always the chance, if not the likelihood, that we'll see them improve in subsequent versions.

I know it doesn't want to be a fetterer, but my sense is that Europe will come to see the wisdom of getting a bit more explicit and comprehensive in these matters.  I know from experience that some of its utilities are looking for more guidance. OK? Back to the Olympics!

Unfettered: ENISA Announces European Smart Grid Security Intentions


Here's how the European Network and Information Security Agency put it a few weeks ago:
We are happy to inform you that ENISA has recently published a new study on smart grids’ security. This study makes 10 recommendations to the public and private sector involved in the definition and implementation of smart grids. These recommendations intend to provide useful and practical advice aimed at improving current initiatives, enhancing co-operation, raising awareness, developing new measures and good practices, and reducing barriers to information sharing. This guidance is based on the results of a thorough analysis of the opinions of the experts who participated in the study.
Couldn't possibly be softer, gentler, or less threatening, I'd say. Sort of like what some of the North America utilities wish they had to deal with instead of the teethy and time consuming NERC CIPs. Certainly this ENISA stuff is much higher level, earlier stage guidance than the NISTIR 7628 which has now been available in some form for over 2 years.

But I note that we're hearing of no more significant cybersecurity breaches in the European electric sector than we are at utilities in the US. Maybe what some say, that expensive and time consuming compliance burdens and activities cut into the utilities' own cybersecurity efforts. The argument goes that if it weren't for the NERC CIPs, utilities might be able to better secure themselves.

At this point, it's hard to discern a difference in effectiveness between the European laissez faire approach to setting electric sector security rules and the more prescriptive North American one. Maybe the pluses and minuses of each roughly cancel out and for the moment, both are in reasonably good shape.

Although I bet that's a message you're not going to hear at the ICS CyberSecurity Conference coming up in October.

You can download the ENISA document HERE.

Europa Image credit: Wikipedia Commons

The State of the States and Smart Grid Security

Readers, working your way through this comprehensive yet non alarmist EPIC PIECE of Smart Grid security journalism will take some time, because author and former NH PUC commissioner Nancy Brockway has done her homework and then some.

And unlike some unschooled energy security bloggers I know, she knows all the business angles. To whit:
Utilities might argue that they need pre-approval and current recovery of cybersecurity costs. Utilities and their smart grid industry partners sometimes claim that without such cost recovery, a utility will lack the ability and resources to pursue cybersecurity with vigor, presumably because in and of themselves, cybersecurity investments don’t generate revenue. However, the industry has it backwards.
See what I mean? OK, here's the cybersecurity funding smackdown:
If a utility executive says the firm won’t vigorously pursue cybersecurity absent a tracker to recover its costs outside the normal ratemaking treatment, the utility is signalling that it might not have fully embraced the goal of such security. And a utility that tries to reassure the commission that such guaranteed revenues can be clawed back on a later finding of imprudence might be hoping the commissioners are naive about how prudence reviews work.
Hold on; one more volley and it's over:
There’s a huge difference between pre-approving and providing extra-rate-case recovery of utility investments in cybersecurity, and making it clear that the commission understands the need to change out obsolete equipment and technology, beef up staff, and make investments to protect the grid. But if a utility cares so little about cybersecurity that it won’t pursue the smart grid or the cybersecurity component of the smart grid absent guaranteed, dollar-for-dollar, few-questions-asked revenues awarded outside of normal cost recovery, this should be a red flag to the commission about letting that utility install the connectivity inherent in the smart grid.
About the only point Ms. Brockway seems to have missed re: State actions is the recent publication of a pretty decent and helpful guide by NARUC, which we posted on earlier and you can view HERE. Didn't seem like you could comment on the article, but I'll be very interested to hear what folks make of her positions on these matters, particularly the funding aspects.