Reader Comment – ICS Cybersecurity Initiative
Yesterday I published a brief piece on Chemical Facility Security News on President Biden’s “National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems”. A long time reader of my blog, Jake Brodsky, posted a comment to that post that should be read by anyone interested in the ongoing move of the Administration to improve cybersecurity in critical infrastructure. One point that Jake made is worth discussing here:
“I have a lot of respect for what CISA does. However, they cannot be the ones to enforce security on industries that they are not responsible for in any other capacity. That should come from the EPA in water, FERC in Energy, and so on. I would vastly prefer to see CISA become a research, integration, and intelligence distribution agency --much as they're doing now.”
Background Material
Today, I came across a press briefing from Tuesday evening by an unnamed “Senior Administration Offical” on the White House web site that gives additional information on the ICS cybersecurity initiative. That ‘Official’ started the briefing with the following observation:
“So, those of you who have reported on critical infrastructure know that federal cybersecurity regulation in the U.S. is sectoral. We have a patchwork of sector-specific statutes that have been adopted piecemeal, typically in response to discrete security threats in particular sectors that gained public attention.
“So, our current posture is woefully insufficient given the evolving threat we face today. We really kicked the can down the road for a long time. The administration is committed to leveraging every authority we have, though limited, and we’re also open to new approaches, both voluntary and mandatory.”
The ”Official” then goes on to make the point that
“So the first piece it says is: We are going to do our part by outlining performance controls that cover all critical infrastructure, that say these are the thresholds that we expect responsible owners and operators to go, and start moving there voluntarily, because that is the threshold that we as a government expect our private-sector owners and operators to meet.”
CISA as Regulator
Jake makes a good point, CISA is not really set up to be a regulator. With the exception of the Chemical Facility Anti-Terrorism Standards (CFATS) program that does fall under CISA, CISA does not have the personnel, or background to be a regulatory agency. Regulating cybersecurity takes more than just writing regulations or Security Directives. Without the people to go out into the field and check that the regulated entities are doing, or even can do, what is written in the CFR, writing regulations is an empty effort.
I worked in the chemical industry for over 25 years. In that time, I worked for one company that actively ignored chemical safety regulations and, but more often, my employers made a good faith effort to proactively follow safety regulations and best practices. Even at the later facilities, there were numerous times when regulations were violated through misunderstanding, or just lost sight of during responding to the vagaries of specialty chemical manufacturing.
And for the most part, all of those companies understood the concepts of safe chemical operation. We had process engineers and process chemists, chemical engineers and chemists with manufacturing backgrounds in management roles. They employed and listened to industrial hygiene and industrial safety professionals. But still, we had shortcoming, regulatory violations and some fairly serious chemical safety incidents.
And over all of that we had two regulatory agencies that had ‘active’ regulatory programs that affected our facilities, OSHA and EPA. We had annual reporting requirements and emergency reporting requirements and every-once-in-a-long-while, we had an inspector that came out and looked at what we were doing to ensure that we understood what our responsibilities were and that the I’s were dotted and the T’s crossed.
CISA does not have the organizations in place to assume that kind of oversight role. Jake is absolutely right. That should not be CISA’s role.
Cybersecurity and Safety
In process industries, cybersecurity of control systems should be intimately tied to process safety. I do not care how many security controls you have in place, someone, if they are determined enough, will find a way around those controls. What should be more important for operational cybersecurity is ensuring that there are process safety controls in place that will make cyber systems fail in a safe mode.
That and ensuring that for the most critical manufacturing processes, the facility can continue critical manufacturing (at a reduce rate, naturally) when the control systems fail. The ransomware attack on Colonial Pipeline did not affect the safe operation of the pipeline control systems. It has become apparent that the pipeline control system was shutdown for business reasons dealing with the inability to bill customers without the direct connection between the operations systems and the business systems. That was arguably a legitimate business response, but it could have been obviated if processes were put into place to allow the operations without that direct connection.
Biden May not be Asking CISA to Regulate
In a closer reading of yesterday’s security memorandum, I do not think that the President or his advisors are currently envisioning CISA as the regulating agency for industrial control system security. Section 4 of the Memorandum makes it clear that while security controls will almost certainly vary by industry (and realistically, by facility) the Administration feels that CISA can establish some baseline cybersecurity ‘goals’ that could be applied to a broad swath of critical infrastructure.
That is certainly a worthwhile goal, and one that any group of process control cyber experts could probably come up with over a couple of beers. Here would be my first pass:
A concise listing of all the electronic devices connected to the industrial control system and the links between those devices and with outside systems of any type,
A process for identifying vulnerabilities in each of those devices and making risk-based decisions about how and when to respond to those vulnerabilities,
A process for limiting access (most especially remote access) to those devices to those with an operational need for that access along with appropriate risk-based controls to implement that limited access,
A process for detecting anomalous activity in the system along with a risk-defined process for responding to that activity, and
A process in place for the safe shutdown of critical operations and the risk-based restart or continued operations of affected systems.
If we try to get too detailed in our ‘cybersecurity goals’ we will make them too expensive and too complex for them to be applied to all of the facilities where they are needed. Each facility is going to have to determine what tools are most appropriate for their operations to achieve the general cybersecurity goals. But we must keep in mind that cybersecurity must be tied back into the safety and business case of each individual facility. If we fail to do that, cybersecurity will continue to take a back seat to getting product out the front door.