Showing posts with label critical infrastructure. Show all posts
Showing posts with label critical infrastructure. Show all posts

Tuesday, April 2, 2013

Why Reading Reports Is Clutch: GAO’s Important Report on the National Critical Infrastructure Prioritization, and the Underwhelming Press Release

By Keith Edmund White
Editor-in-Chief

GAO releases a report, which by a press release, seems like a simple 'turn in your homework' admonition regarding the U.S. federal program that prioritizes sites in the U.S. where we really don't want bad things to happen.  But, as Keith White shows, when the report it read, you might be a little worried about how well DHS is handling this list, and the resulting federal funds and programs that accompany it.  And yes, Canada factors in too.
  

GAO releases a report on the National Critical Infrastructure Prioritization Program (NCIPP).  This report lists places where the U.S. government would really not want bad things to happen.

I got the report through a third-party information gatherer I'll keep unnamed, who summarized it as such:

“In a new report, GAO finds that the Department of Homeland Security (DHS) has not sufficiently met statutory requirements to report annually to congressional committees. Specifically, DHS needs to work on how it identifies critical infrastructure such that it is consistent with the National Infrastructure Protection Plan (NIPP). GAO recommends the DHS commission an external peer review to develop an approach to verify the quality and timing of annual reports.”
Sounds like a not too consequential, and likely dull, report.

Then I read the report.

DHS has made several changes to its criteria for including assets on the NCIPP list. These changes initially focused on introducing criteria to make the lists entirely consequence based, with subsequent changes intended to introduce specialized criteria for some sectors and assets. DHS’s changes to the NCIPP criteria have changed the composition of the NCIPP list, which has had an impact on users of the list. However, DHS does not have a process to identify the impact of these changes on users nor has it validated its approach for developing the list.

And who are these affected users?

Oh, just FEMA when it’s doling out Urban Area Security Initiative grants. And the Protective Security Advisor Program, you know the department that conducts actual site visits and vulnerability assessments to owners of critical infrastructure.

Our analysis shows that changes to the NCIPP list can have an impact on users of the list, specifically, FEMA’s allocation of UASI grant funds and PSAs’ ability to prioritize outreach and conduct site visits for its protection programs. Our analysis of the FEMA risk formula shows that a change in the number of NCIPP-listed assets located in a city has an impact on a city’s relative risk score. Our analysis also shows that current UASI grant allocations are strongly associated with a city’s current relative risk score. Therefore, a change in the number of NCIPP-listed assets located in a city can have an impact on the level of grant funding it receives. For example, in fiscal year 2012, FEMA allocated approximately $490 million in UASI grant funds to the 31 cities with the highest relative risk scores out of 102 eligible cities nationwide. Our analysis of FEMA’s risk formula showed that, at the minimum, if the number of level 2 assets is increased or decreased by as few as two for each city, it would change the relative risk score for 5 of the 31 cities that received fiscal year 2012 UASI grant funding. Such a change could result in increased or decreased grant funding allocations for the affected cities. The changes in the relative risk scores tend to affect cities in the middle to the bottom of the top 31 list because there is generally a larger gap between the relative risk scores of those cities at the top of the list than those in the middle to bottom of the list. However, even a small change in grant funding could have an impact on a city, especially if that city does not traditionally receive other federal assistance as compared with cities with higher risk scores.
And yeah, this might have a significant impact:
While the change to an entirely consequence-based list created a common approach to identify infrastructure and align the program with the statute and NIPP, recent and planned criteria changes to accommodate certain sectors and assets represent a departure from this common approach, which could hinder DHS’s ability to compare infrastructure across sectors.
Go intra-agency coordination!  NCIPP, FEMA, and PSA are all housed in one federal department, the Dept. of Homeland Security, and information-sharing problems seem to linger.

But let's not get too snarky.  DHS is taking on the arduous task of changing the, at times politicized, NCIPP list.  Getting more Congressional oversight on this hot-bottom item will bring, whatever its numerous benefits, will bring increased political pressures on a program--especially in the lean (or not so lean) times of sequestration.

Wednesday, March 27, 2013

More on DHS's New FY13 Budget

By Keith Edmund White
Editor-in-Chief

More resources on just what DHS's budget, which became official yesterday when President Obama's signed the Fiscal Year (FY) 2013 Continuing Resolution appropriations bill.

(Note:  Author appreciates readers bringing the documents cited below to his attention.)

Readers will find three primary documents below outlining the DHS budget for the remaining 6 months of Fiscal Year (YR) 2013.

Study Highlights Troubling Threats to Critical Infrastructure-Should We Fret Over Canada-U.S. Joint Infrastructure?

ZDNet.com reports on the recent release of Trend Micro Inc.'s 2013 research paper, Who's Really Attacking Your ICS Equipment? 

The report shows attackers didn't wait long to attack a dummy control site emulating an Industrial Control System, similar to systems that could control a water pump or monitor a power plant's output.  

The impact:  Computer system monitoring critical private and public infrastructure in the United States is most likely being attacked repeatedly and on a daily basis.

And it's as simple as having a computer and internet access.  With power system systems, dam networks, and international finance dependent on internet connectivity, all wired nations must grapple with protecting their critical infrastructure.


Monday, October 29, 2012

Canada, United States & Cyber-Security: With National Efforts Faltering, Will Cross-Border Cooperation Propel Both Nations Cyber-Security Strategies?

By Keith Edmund White
Editor-in-Chief

Has the Beyond the Border Initiative become the best hope for the United States and Canada to craft effective cyber-security strategies?

On Friday the U.S. Department of Homeland Security (DHS) and Public Safety Canada (PS) announced a Cyber Security Action Plan, a 4-page document that fleshes out the security-cyber objectives of the Beyond the Border Initiative, a bi-national effort to cooperate on security and border management.

Cyber-Security:  An Important, Cross-Border Issue


First, before delving into the Action Plan and cyber-security in Canada and the United States, it’s important to emphasize the importance of cyber-security to both Canada and the United States.  Whether it’s food supply systems, financial institutions, or energy distribution facilities, all these vital pieces of critical infrastructure are vulnerable to cyber attacks. And, whether through shared fiber optic cable networks or America's extensive use of Canadian-generated electricity, Canada and the United States can’t tackle cyber-security alone.

Cooperation Without Substance?


The Action Plan represents a still early, light-on-details step in DHS and PS coordination—but does show that the two agencies have, at least, identified the goals they wish to accomplish.  Perhaps the two most challenging goals can be found on page 3 of the Action Plan:
1.4 Align and standardize cyber incident management processes and escalation procedures; and

1.5 Enhance technical and operational information sharing in the area of industrial control systems security.
 Why are these goals unlikely to be met anytime soon?  Well, Canada and America seem MIA on even having a national approach to cyber-security.  As pointed out at CUSLI’s 2012 March Conference, the United States really doesn’t have a cyber-security strategy on the national level—with comprehensive cyber-security legislation unlikely to pass Congress this year.  And Canada’s Auditor General, while noting improvement, still hit the nation’s cyber security nerve centre for only running during daytime hours and not being kept in the loop with the most pressing cyber-security threats. 

Just to illustrate how much work still needs to be done, DHS’s National Cyber Security Division—which offers a link to a 2003 National Strategy Report—still, as of today, lists “build[ing] and maintain[ing] an effective national cyber response system” as one of its two objectives.  And, when it comes to Canada, a 2012 article by cyber-security expert Ron Deibert, published by Queen’s University Centre for International and Defence Policy, states “the Canadian government is late to the cyber-security arena…and only barely nods at the importance of a foreign policy for cyberspace.” 

Will Beyond the Border Propel Comprehensive Cyber-Security Strategies in Canada and the United States? 

So, how do two nations do cyber-security coordination when both have lackluster national cyber-security strategies?  Though, a fair counter-argument could be made—taking up a theme pushed in today’s Globe and Mail—that exactly because both nations are only beginning to hammer out their cyber-security strategies, there's greater likelihood that both nations will work together to tackle this pressing issue, unimpeded by entrenched institutional practices and regulations.

Perhaps Canada and America’s individual difficulties on cyber-security will make the Beyond the Border framework the main hub for both nations emerging cyber-security strategies.  Not only is this good news for protecting both nations critical infrastructure, it could also show the value of bilateral approaches to more effectively--and efficiently--solve pressing public policy issues in Canada and the United States.

Friday, March 23, 2012

CUSLI 2012 Conference: Afternoon Panel 2 -- Cyber Security and Infrastructure

by Keith Edmund White


This panel discussed Canada and the United States’ plans to reform cybersecurity and critical infrastructure and some of the secondary impacts that will have on privacy rights and trade.  Critical discussion resolved around (1) what role the government should play in these areas (and can it keep up with breakneck changes in cybersecurity) and (2) the risk that even if like-minded countries come together for critical infrastructure and cyber-security, will this just push the leading industries to put them serves in non-member countries?  In any case, one thing is clear:  while nations have seen first hand, re: the 2003 power grid failure that rocked both nations, little--if anything--has happened when it comes to Canada and the United States to adopting a joint risk assessment approach and response plan.

Chaired by Eric Miller, Canadian Embassy
Paul Rosenzweig, Private Practitioner focusing in Cyber Security Law
Michael McDaniel, Professor of Law at Cooley
William de Laat, de Laat Global

Paul Rosenzweig:  What Cyber-Security Law Applied When Servers Are All World?  Short Answer—No One Knows.

Paul Rosenzweig opened his remarks pointing out that viruses can do physical damage—just look at the Stutnet virus that set back the Iranian program back.  So, this means America has to make sure other Stutnet’s don’t disable our transportation grids, agricultural grids, and manufacturing grids are run on a cyber-infrastructure on both sides of the border.  And what does this mean?  No matter what America does, Rosenzweig continued, that Canada has to work en tandem.

What’s next?  We need to get the basic level of risk.  But in discussing this, we need to have a joint services approach to cyber security.  But are we moving forward the right way?  Rosenzweig pointed out two bills moving through Congress now that are now written “with a complete U.S.-centric viewpoint because no one has looked at and said” that a vulnerability in Niagara power facility will want to know what’s happening on the other side.  If we don’t do this, the U.S. efforts will be “substantially diminished.”

And the Canadian side?  Just like with day-light saving time, Canada has raised its hand and said “hey, what about us?”  And this is particularly important since it involved important civil liberalities, and Canada shouldn’t just avoid this discussion by following wherever America may lead it regarding cyber security.

But Rosenzweig is “deeply skeptical” of the government leading the way on cyber-security.  The National Energy Regulatory Commission) to set standards for standards for energy grids.  But the average time for the production of rules like those is about 24 months, Rosenzweig.  But in that time, Rosenzweig, the mutation in threats is vast and the processing power doubled every 18 months.  So, Rosenzweig concluded, government can’t keep up with this in terms of specific rules.  But government can create a web to enable private industry to address these concerns in the private sector.

The U.S. and Canadian government cannot respond to these cyber security threats comes at our own peril.  In short, it “can’t be the be all and end all.”  He need “as close to a joint operating model as we can come given the limits of legal and policy models.”  One such example is that the NSA has a wide swath of cyber security information that only select individuals are aware of, but it is “essential” that it is shared with CSIS and the Five Eyes Organization, and from that those groups share that as much as possible with U.S. and Canadian private actors who may be subject to the attack, Paul Rosenzweig stated.  Also, we have Lockheed Martin plants in Canada and the United States, there’s no reason to make it harder for one of them to get information.

And countering against McDaniel’s push for greater government involvement, while there are areas that the government must take the lead, this can’t be the model.  In one study, the NSA only identified 5% of the risk that the private industry did regarding cyber-security.  Also, 82% of government alerts on cyber-security come after the private sector alerts occurred.  So the government needs to play a role and bring players together, “the structure is moving too fast” when it comes to cyber-security.  Thus, what is right for a Ford factory will not be a cure-all for cyber security.

“This is a problem of diplomacy, not technology,” Rosenzweig stated.  Like-minded countries have to come together and set standards and then grade ourselves.  And once we do that, those countries can then call out other countries, whether its China or Russia, for failing these standards that liberal, western anti-criminality norms regarding cyber-security and critical infrastructure can then call-out those nations who are failing to meet the board.

And when it comes to dealing with choice of law disputes when it comes to cyber-security standards:  no one knows what the answer to choice of law disputes yet.  And what about privacy standards?  When it comes to Canada’s efforts for privacy in cyberspace, the efforts are based on out-dated 1970s notions of privacy.  The answer?  We need a new conception of privacy.

Michael McDaniel:  We need to have a joint approach to responding to threats to critical infrastructure, and we get there by building on regional agreements.

While an optimist, McDaniel cast a critical eye on the one recommendation relating to critical infrastructure that says cyber security will be brought together and working through RRAP (Regional Resilience Assessment Program).  But, he cautioned, RWRAP is just a pilot program,  that may or may not actually happen.

“The plan doesn’t even talk about planning for a response at all.”

 When recommending what to do over the next year, McDaniel stated that we need something like the Emergency Management Assessment Compact (EMAC) —which involved Ontario and the Great Lakes States.  Second, we have to have that down at the county level as well for dealing with the effects of a damage to America’s critical infrastructure.  Third, we need to “define our taxonomy” when it comes to how we assess risk to our critical infrastructure.  And this requires information sharing among governments, different sizes businesses, and within agencies that connect the regulators to the operators to the first-responders. 

Is it underwhelming because of lack of internet or its just “too big to get our arms around at this point.”  But there are other agreements that show that we can move forward on this topic. 

When you look at Michigan, with the just in time automobile system, businesses and States are ready to take on the problem themselves. 

McDaniel pointed out that USNORTHCOM should have authority over the countries responses to cybersecurity and critical infrastructure challenges.  But we don’t have agreement on that.  And the chief hold-out, McDaniel argued, is at the state-level.  He stressed that this shows the value of taking an EMAC approach to coordinating Canada and America’s critical infrastructure.

William de Laat:  “..the specifics aren’t there.”

DE Laat focused on the link on physical infrastructure, trade, and cyber security in the Action Plan.  He emphasized that the BTB Action Plan’s comprehensive view of these matters is critical, whether its power, stock trading, or transportation.  But what the plan doesn’t do, and this is not different from past efforts, is “to link cyber security and critical infrastructure.”  Both Canada and America divide critical infrastructure and cyber-security, and while de Laat admitted these groups say they talk to each other all the time, but we need formal ties to protect critical infrastructure.  But “I’m underwhelmed” by the results we have so far…the specifics aren’t there.”  We need a comprehensive plan that “combines the really good, high value information sharing that really…allows us to come up with a clear protocol…and joint operational capacity that says in a crisis or non-crisis this is how we [Canada and the United States] will work together.

And why is this important?  Because, de Laat pointed out, one prominent Canadian expert has stated that “the interconnection of CI [critical infrastructure] systems is developing an overlay of what might be called the meta-CI system…”  If we don’t protect this emerging meta-system, it appears from this author’s quick read on the topic, it seems that America and Canada are leaving themselves open to natural disasters or computer attacks reaping havoc on their economic and trading relationship.

 A number of regional groups are “working really effectively.”  But these are treaty level agreements if taken on the bilateral level, and getting these through the national level are much more difficult.

De Laat sees the the path forward on critical infrastructure is working with a few countries who share the same values.  But this brings up a difference between Canada and the United States:  Canada tends to push more for multinational engagement.

Addressing if industry can take care of itself, he pointed out that industries may not take a strategic view.  “Governments will not save the day, but if governments do not make this a priority we will have problems on our hands…they have to work with the private sector.  Unfortunately, “we’re all sitting on our hands right now.”