Showing posts with label Cybersecurity Framework. Show all posts
Showing posts with label Cybersecurity Framework. Show all posts

Monday, January 11, 2016

CRS Insight - Electric Grid Physical Security: Recent Legislation (US)

(Another Hat Tip to our friends at the Federation of American Scientists for posting this CRS document!)

Last week a two-page summary of recent US government legislation focused on electric grid physical security was prepared by Paul W. Parfomak of the Congressional Research Service (CRS).

http://fas.us8.list-manage.com/track/click?u=33c6e6fc9f63792ebcbb7ef9d&id=9c0cfe0fff&e=d0dc8ca93c

The document is a quick read. Besides summarizing the Federal Energy Regulatory Commission (FERC)) / North American Electric Reliability corporation (NERC) efforts on the CIP-014, Physical Security Reliability Standard, the document summarizes some interesting electric grid physical security elements in the Fixing America's Surface Transportation (FAST) Act - P.L. 114-94 and the Energy Policy Modernization Act of 2015 - S. 2012.

Fixing America's Surface Transportation (FAST) Act - P.L. 114-94
  • Became law on December 4, 2015
  • Contains provisions in two sections to facilitate recovery during electric grid emergencies due to physical damage and other causes.
  • Critical Electric Infrastructure Security (§1104) -- This section provides the Secretary of Energy additional authority to order emergency measures to protect or restore the reliability of critical electric infrastructure or defense critical electric infrastructure during a grid security emergency.  The identification of such a grid emergency would be made by written notice from the President with a concurrent notification from Congress.  This section also allows a) grid owners to recover prudent costs incurred under such emergency measures through rates regulated by FERC, and b) increases protection of critical electrical infrastructure information.
  • Strategic Transformer Reserve (§1105) -- This section requires the Secretary of Energy -- in consultation with other agencies, the military, and the utility industry -- to submit to Congress within one year a plan for a Strategic Transformer Reserve.
  • Includes two sections primarily directed at electric grid cybersecurity but with potential impacts on physical asset protection or recovery.
  • Cybersecurity Threats (§2001) -- Would provide the Secretary of Energy additional authority to order emergency measures to avert or mitigate a cybersecurity threat upon receiving notice from the President that such a threat exists.  This section is also intended to increase protection of critical electrical infrastructure information.
  • Cybersecurity Threats (§2002) -- This section would designate the Department of Energy (DOE) as the lead Sector-Specific Agency under Presidential Policy Directive 21 for energy sector cybersecurity.  This bill would require a) DOE to develop a program for modeling and assessing energy infrastructure risks in the face of natural and human-made (physical and cyber) threats, b) DOE to explore alternative structures and funding mechanisms to expand industry participation in the Electricity Information Sharing and Analysis Center (E-ISAC).


Thanks again to Mr. Parfomak for this CRS Insight.

###





Thursday, March 6, 2014

New Policy Approaches to Address Cyber Threats Impacting the Electric Grid

In February the Bipartisan Policy Center released a report focused on cybersecurity and the North American Electric grid.  At first I was worried that this report would be another collection of the same ol' ideas of leaning on the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards as the panacea -- fortunately, this report is very good and really has some excellent ideas to help protect the electric grid from and during a cyber attack.


In a simple way I'd strongly suggest you skim this report if you are in any way/shape/form involved with electric grid cybersecurity defense, policy, funding or response.

The key areas of discussion in the report include:

  • The Existing Landscape for Electric Grid Cybersecurity Governance
  • Standards and Best Practices for Cybersecurity
  • Information Sharing
  • Responding to a Cyber Attack on the North American Electric Grid
  • Paying for Electric Grid Cybersecurity
The report is very refreshing and offers some new ideas on ways to defend the grid and respond to cyberattacks.  

One idea that has some merit is the concept of implementing an "Institute" similar to the Institute of Nuclear Power Operations (INPO) that would focus in continuous improvement of cybersecurity of the electric grid.  I sent the following email to one of the Advisory Board members supporting this idea.  In my email I observed:


The Institute of Nuclear Power Operations (INPO) was used as a model agency for oversight of the security of the grid.  I worked at INPO from 1986 to 1992 and when I left I was the Secretary of the Corporation and an evaluation Team Manager.  

Of note, the recently published Cybersecurity Framework (CSF) has an approach very similar to INPO's.  That is the CSF is "performance-based" rather than "compliance-based" which is an approach that INPO pursued.  INPO published a document entitled Performance Objectives and Criteria for Operating and Near-Term Operating Nuclear Plants that really focused on what would be viewed as optimal performance in particular areas (e.g., management, administration, operations, maintenance, etc.) with a collection of criteria that supported the performance objectives (similar to the CSF).  However, the process was not focused on compliance to the performance objectives but instead to how the plant truly performed.

An example to demonstrate this approach would be relative to CIP-008, incident response.  The NERC approach to reviewing CIP-008 is to actually sight the utility's incident response procedure; however, they do not check to see that it actually is a workable, accurate document (i.e., are the phone numbers/email addresses accurate, can it truly be used as written, is it practiced, etc.).  On the other hand the INPO approach would be to view the document but with emphasis on watching the utility perform the incident response process and observe strengths, weaknesses, etc. and highlight areas needing improvement.

In other words the assessment was based on the true performance of the utility; not a simple view of its paperwork -- a serious flaw with the NERC approach (in my opinion).

I am very pleased with the tone, content and ideas put forth in this report and I look forward to the "new" dialogue that surfaces in this domain different from the old, stale ideas that really don't solve the problem for the entire electric grid from generator to transmission line to distribution system to the toaster in your home.

Again, compliments to the authors and advisory group on this report!

###

Friday, February 14, 2014

Focus on Information Sharing for Cybersecurity

At the end of 2013 I was invited by the NATO Energy Security Centre of Excellence to submit an article regarding the barriers to information sharing and their impact on critical energy infrastructure protection.



The actual e-zine was posted today and contains seven well-written articles by some global thought-leaders relative to information sharing, cooperation and security of the energy supply.  The e-zine can be downloaded at: this LINK.  A picture of the Table of Contents is shown below.



This is probably one of the first publications exclusively focused on the subject of information sharing for critical infrastructure protection. I'm very honored to have been invited to participate.  Of note, the conversations in this publication will be especially germane to the dialogue raised by the new release of the NIST Cybersecurity Framework this week -- especially since one of President Obama's objectives in his Executive Order was to improve and increase two-way information exchange to better protect critical assets.

Thanks for reading!

###







Thursday, January 2, 2014

2014 -- And What It Brings...

Happy New Year!  Welcome to 2014 and all the opportunities it brings!

Wow, 2013 has flown by!  For this year I will continue to focus this Blog on Critical Infrastructure issues and augment it with some discussions focused on some of the key questions and topics I think will affect all of us this year.

So, for a “bulletized” recap of the topical areas I’ll ponder please consider the following:

·         Critical Infrastructure Protection
o   What will happen with the NIST Cybersecurity Framework?
o   What news and events will surface for the 16 critical infrastructure areas designated by PDD-21?

o   How will the electric industry react to the new NERC CIP Version 5 mandates? And the NIST Cybersecurity Framework?

·         Industrial Controls Systems Security
o   This is a continuation of the areas reviewed last year including the SANS Global Industrial Cyber Security Professional (GICSP) certification activities and new ICS-security emphasis from other cyber-security agencies outside of the US ICS-CERT and even overseas with ENISA, etc.

·         Supply Chain Security
o   I find this a fascinating topic that is finally getting to the front pages of many business journals
o   Again, I will be examining ideas for both physical and cyber protection as well as new legislation impacting cyber defense and threat mitigation

·         Cyberwar
o   This area is particularly intriguing with continued stories about nation-state attacks and defenses
o   Added discussions about “hack-back” and “Active Defense” will be included

·         Cyber Risk Issues and Psychology of Security/Risk
o   The annual meeting in Davos for the WorldEconomic Forum surfaces some very interesting discussions about threats to the digital economy that are not part of the mainstream IT press

So, this should be an interesting year and one that keeps us all busy.  Overall, though, my objectives for this Blog are to a) educate, b) entertain and c) make you think about today’s new challenges to our security and critical infrastructure resilience.

Lastly, I’ll also be busy with Twitter forwarding news items that follow the themes above.  Feel free to follow me @ErnieHayden

I look forward to your comments, ideas and feedback and if you hear of some news items that fit into my list above, I’d love to hear about it at enhayden1321@gmail.com

Happy New Year and all the best!


Ernie

Tuesday, December 17, 2013

Neuroscience, Risk and Security

For years I have been a student and practitioner of security – both cyber and physical.  My initial years focused on the “Security 101” elements with a “castle and moat” approach for both physical assets and cyber (i.e., the “walls” were “firewalls”).  Over time, however, I’ve realized that there is more to security than wondering about the bits and bytes or the sizes of chain link fence mesh.  Instead, I’ve begun to recognize more and more that the human element – that is the attacker and defender – needs to be studied and recognized as a key element.

(Artwork from Microsoft Open Source)

I’ve realized – with some considerable influence from Bruce Schneier in his seminal essay “The Psychology of Security,” and from other thought leaders in the security space such as Kirk Bailey at the University of Washington or Robert Coles at GlaxoSmithKlein -- that you need to understand what motivates the attacker and what helps the defender recognize new ways and means of defending against the wiley aggressor.

In other words, I came to realize that neuroscience should play a key role in helping security professionals understand the attacker’s “brain” so to speak and thus their motivations.

Samad Aidane PMP

Last night I had a fascinating discussion on this very subject with my friend and colleague Mr. Samad Aidane.  Samad and I first met in 2004 or so when I was the information security manager/CISO at the Port of Seattle.  Samad was a newly hired project manager.  Since then we have both expanded our horizons and Samad has evolved his expertise in the realm of neuroscience and project management as well as risk.

Anyway, our conversation tonight revolved around Samad’s new research and focus on the neuroscience behind effective project management and risk.  In fact, Samad has even begun a blog at Neurofrontier.com to expand his and his reader’s awareness of neuroscience and leadership.  I’d like to suggest you take a look at his blog and get a sense of his perspectives on this new science.

A key take-away from my conversation with Samad was that how the brain functions when analyzing risk may be excellent knowledge for security and risk professionals to leverage when dealing with risk analysis decisions.  Similarly, understanding how the brain functions when establishing attack and defense concepts may be very useful to the cyber and physical security defender.  And, of course, if you lean on the concept of “Assumption of Breach[1] for your enterprise cyber and physical defense, perhaps knowing how the brain functions and reacts could be very useful.

I am excited about the new ideas raised by Samad last evening and I look forward to our next meeting and discussions.  In the meantime, take a moment to look at Samad’s website and review some of his ideas.  You may see a sliver of some new concepts for the security profession to lean on as we try to stop the bad guys!




[1] For my past articles on this subject please go to my article in Asian Power at http://asian-power.com/node/11144 or my article in SearchSecurity at http://searchsecurity.techtarget.com/tip/Assumption-of-breach-How-a-new-mindset-can-help-protect-critical-data

Saturday, December 7, 2013

NIST CYBERSECURITY FRAMEWORK - COMMENTS DUE FRIDAY 12/13!

A few weeks ago I prepared a blog for Tofino Security summarizing the key aspects of the DRAFT NIST Cybersecurity Framework.  I guess I hit the target because the blog has been posted on a few other sites and referred to in some Tweets.

(From Cover of National Infrastructure Protection Plan - http://www.dhs.gov/xlibrary/assets/NIPP_Plan.pdf)

Anyway, as one of my readers, my original submittal for the Tofino blog is posted below.

But, don't forget, NIST has requested comments on the Cybersecurity Framework by Friday, December 13th.

Take care, have a great and safe week, and here is the blog.................Ernie

########################################


You may have heard a bit of buzz in the US national and even international press about the release of the Cybersecurity Framework Draft from the US National Institute of Standards and Technology (NIST).  However, you may not know about its background or what it may mean to you as a control systems manager.  As such, this is intended to give you a high level overview of the genesis of this document and give you some points of reference.

Background
As we realize more and more everyday our national infrastructure – in Canada, the US or any country for that matter – is very important to our economies as well as our own national defense.  Because of concerns over continued cyber attacks on US national infrastructure – such as the electric grid, water systems, transportation networks, banks/financial institutions, critical manufacturing, etc. – President Obama issued Executive Order 13636, “Improving Critical Infrastructure Cybersecurity,” on February 12, 2013. 
This document is fondly referred to as the “EO.”

The EO also called for development of a voluntary Cybersecurity Framework to provide a “…prioritized, flexible, repeatable, performance-based, and cost-effective approach” for assisting organizations responsible for critical infrastructure services to thus manage cybersecurity risk.

Critical infrastructure is defined in the EO as “…systems and assets – whether physical or virtual – so vital to the US that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”  Example industry sectors – and the corresponding Federal oversight agency -- considered as “critical infrastructure” include[1]



As a follow up to the EO and PPD, NIST was assigned responsibility for development of the Framework in collaboration with industry feedback.  The Framework is intended to provide guidance to an organization on managing cybersecurity risk.  A key objective of the Framework is to encourage organizations to consider cyber security risk as a priority similar to financial, safety and operational risk while factoring in larger systemic risks inherent to critical infrastructure.

In other words, cybersecurity risk and considerations need to be included in the day-to-day discussions at your company or organization as you expand your business, build new facilities, install new equipment and hire new people.

Let’s Talk About the Framework
First, the EO instructed NIST to be the lead in developing the Framework.  As such you can find the Framework DRAFT document and supporting information at www.nist.gov.

And, what does the Framework contain?  The Cybersecurity Framework shall:
  • include a set of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks.
  • shall incorporate voluntary consensus standards and industry best practices to the fullest extent possible.
  • shall be consistent with voluntary international standards when such international standards will advance the objectives of this order.

And, what is the Framework supposed to do?  The Framework:
  • shall provide a prioritized, flexible, repeatable, performance-based, and cost-effective approach, including information security measures and controls, to help owners and operators of critical infrastructure identify, assess, and manage cyber risk.
  • shall focus on identifying cross-sector security standards and guidelines applicable to critical infrastructure.
  • will also identify areas for improvement that should be addressed through future collaboration with particular sectors and standards-developing organizations.
  • should provide guidance that is technology neutral and enables critical infrastructure sectors to benefit from a competitive market for products and services that meet the standards, methodologies, procedures and processed developed to address cyber risks.  And,
  • shall include guidance for measuring the performance of an entity in implementing the Cybersecurity Framework.

So, with the guidance above – and with input from industry – the draft of the Framework is intended to provide a common language and mechanism for organizations to:

  • Describe their current cybersecurity posture (and a semblance of maturity level)
  •  Describe their target state for cybersecurity
  •  Identify and prioritize opportunities for cybersecurity improvement within the context of risk management
  • Assess progress toward the target state, and
  •  Foster communications among internal and external stakeholders.

A key aspect of the Framework is that it is not intended to replace an organization’s existing business or cybersecurity risk management process and cybersecurity program.  Instead, the organization can use its current processes and leverage the Framework to identify areas to improve its cybersecurity risk management.  Also, the Framework can be helpful to a company that does not have a currently existing cybersecurity program so they can build in key elements raised by the Framework.

So, What Should You Do with the Framework?
First of all, take a look at the list of the critical infrastructures listed above.  Does your company fall into any of those categories?  If not, is your company substantially reliant on any of those key infrastructures for your success and even existence?  If the answer to either is YES then I’d suggest you take time to read the Framework as it stands and figure out how you can apply it to your current cybersecurity risk management.

Secondly, acquaint your Executive Management and Board Members with the Framework.  Give them a sense of how your company stands today relative to the Framework Implementation Tiers listed.  Use this as a means of highlighting your organization’s “…cybersecurity maturity level…” and if you aren’t at the top, use it to highlight the resources (i.e., people, time and money) you need to raise your game.

Thirdly, take a hard look at the Framework and even “test drive” it as it stands.  Be sure to provide comments back to NIST as described at their page “Request for Comments on the Preliminary Cybersecurity Framework.”  Comments are requested before December 13, 2013.

Final Thoughts
When you read the draft Framework, recognize that it is not a “checklist” or a simple “compliance” item to be fulfilled.  Instead it provides a set of performance objectives for your cybersecurity risk program to achieve for your prioritized list of key assets.  But also, it is not a “how-to” on building a security program.

So, even for our Canadian friends, be sure to take time to look the Framework over. 


[1] From the corresponding President Policy Directive (PPD) 21 “Critical Infrastructure Security and Resilience” that was issued at the same time as the EO. Link: http://www.whitehouse.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infrastructure-security-and-resil