Showing posts with label Cybersecurity Executive Order. Show all posts
Showing posts with label Cybersecurity Executive Order. Show all posts

Four Key Take-Aways from the Sixth NIST Cybersecurity Framework Workshop


Last week, the National Institute of Standards and Technology (NIST) held in Tampa, FL its sixth workshop on the landmark critical infrastructure cybersecurity framework mandated by President Obama in February 2013 and issued by NIST in February 2014. As was true of the five previous workshops NIST held prior to the framework's release, hundreds of cybersecurity specialists gathered for two days to listen to government and industry experts and to hash out the framework's details across multiple, specialized working sessions.

While the event covered a lot of ground, tackling a range of technical and detailed topics from relatively specialized matters such as authentication issues in industrial control security to broader overviews of how various sectors are dealing with the framework, a few themes emerged from the sessions and conversations with the attendees. Here are the top four take-aways from the latest workshop:

1. Everyone Likes the Framework: Almost everyone said the framework is a good thing, although, as noted below, there are some issues that specialists still have with the framework's ongoing development. Not surprisingly, representatives from industry, UK and EU governments invited to speak on the plenary session panels offered almost uniformly positive views of the framework. "We began using the framework essentially the day it came out," Tim Casey, a senior information risk analyst at Intel said. "It gave us purpose and direction that we didn't have previously," Jefferson England, an executive at small telco Silverstar Communications, said.

Conversations with attendees yielded more of the same. "This is a good force multiplier. It's a common unified framework for managing security risks," Robert Brown, Manager of Assurance at PWC, said. "People have seemed to really embrace it," according to Phil Agcaoili, VP and Chief CISO at Evalon. "There are all sorts of ways this could have gone wrong and it didn't," Chris Blask, ‎Chair at Industrial Control System Information Sharing and Analysis Center (ICS-ISAC), said.

Much of the good vibes flowed from the sense of collegial community that has cropped up over the course of the multiple workshops among the many hundreds of cybersecurity specialists. (Frequent jokes were made about the T-shirts given to people who had attended every workshop). The framework process has really "put trust across the sectors," Jack Whitsitt, Senior Analyst of cybersecurity consortium EnergySec, said, highlighting the fact that cyber specialists in different industries now share information outside their sectors because of the relationships forged during the NIST framework process.

2. The Framework's Primary Value To Date Seems to Be as a Communications Tool:  The jury's out in terms of whether the framework has actually achieved its intended goal of reducing cybersecurity risks, but it's clear that the subject matter experts who were at the workshop think it's a good device for trying to communicate the arcane subject of cybersecurity to managers, regulators, vendors, partners and other audiences. "One of the largest benefits of the framework is that it provided a framework of discussion, as much as anything else," Silverstar's England said.

"We're using it as an engagement tool for our regulators," Karl Schimmeck of the Securities Industry and Financial Markets Association, said. "We're hoping that it becomes the common language when you're talking to suppliers, vendors, joint ventures," a senior oil and gas industry representative said. "I'm using it to inform my board and executives," Evalon's  Agcaoili said.

3. Otherwise the Framework Is Still Kind of Difficult to Use:  Despite being built on the notion of simplicity, the NIST framework is a 41-page document that features core sets of activities, multiple tiers and intricate mapping to hundreds of detailed cybersecurity standards developed by a welter of standards-setting bodies. Most of the practitioners in attendance at the workshop said that the framework, despite its communication value, can at times be quite a challenge to use. "These frameworks are alphabet soup," PWC's Brown said.

"The mapping process is nuts," Dorian Cougia, Compliance Scientist at Unified Compliance said. Part of the problem is that the intricate standards that are mapped to the framework can run dozens and even hundreds of pages long and it's not always clear which parts of the standards apply to what. "There were times when we did not exactly understand what the framework meant," one top energy cybersecurity specialist said.

"The content of the framework really doesn't matter," EnergySec's Whitsitt said. "Organizations that don’t know how to do security already will have a hard time with it."

The difficulty in using the framework can be greater for smaller and mid-sized organizations that don't have cybersecurity experts on staff, a topic much discussed during the framework's development. "The big guys do this already," one communications industry representative said. "They wouldn't be in business if they weren't protecting their networks for financial reasons." The smaller guys, however, are struggling to come up to speed with what the framework demands, she noted, because they may have at most only one IT person on staff assigned to implement security measures.

The right way to view the challenge of using the framework isn't big versus small, according to Adam Sedgewick, who spearheads the project for NIST, clarifying that it's more about how serious the company is about cybersecurity, regardless of size. "I think it's a mistake to think that small and medium companies do not have good cybersecurity practice as a rule.  I think it's more appropriate to say companies that do not have robust cybersecurity programs" face greater challenges.

4. There Won't Be a Framework 2.0 Any Time Soon:  Two mantras emerged from the government and NIST speakers at the workshop.  The first is that "it's still early days" for the framework and too soon to gauge its effectiveness.  The second, related concept is that no basic changes to the framework are in the offing anytime soon.

"We want to make sure that people understand we don't expect changes to the framework in the future," Ari Schwartz of the National Security Council said. "We are in no rush to make changes without knowing or understanding what effect those changes might have," Matt Scholl, Deputy Division Chief at NIST said.

Cybersecurity is already shaped by endless organizations, government agencies, schemas, frameworks and evolving standards, NIST's Sedgewick said. "We have to be careful when we think about the next phase of this effort to reduce that complexity and not increase it."

That view was embraced by most of the workshop attendees. However, some of the industry specialists who are implementing the framework think changes are needed sooner rather than later. "It is useful but it still needs more work," one big electric utility representative said. "If something is missing, they don't know something is missing.  They should not wait too long to update the core."

NIST's Cybersecurity Framework at the Six-Month Mark: Are We More Secure?


On February 12th the National Institute of Standards and Technology (NIST) released its comprehensive cybersecurity framework, the culmination of an intense 12-month drafting process ordered by President Obama in an effort to ward off what former Defense Secretary Leon Panetta feared would be an imminent "cyber Pearl Harbor." This framework of frameworks was intended to lay down some ground rules to improve the security and resilience of all industries, but particularly the critical ones upon which stable society depends, such as energy, communications, transportation and food and agriculture.

So, what's happened since the framework's release? Find out tomorrow when I will be moderating a webinar for the Industrial Control Information System Sharing and Analysis Center (ICS ISAC), one of the key groups assigned the all-important information-sharing task among industrial system control operators to ensure that cyber threats are identified and managed in a timely fashion.

Join ICS ISAC Chair Chris Blask and me to find out what top security specialists think about the framework six-months in and the benefits and challenges they've experienced in putting the framework into place. Among the experts we've lined up are:
  • Kevin Morley, Security and Preparedness Program Manager, American Water Works Association
  • Perry Pederson, Co-Founder and Managing Principal at The Langner Group, LLC
  • Greg Witte, Program Manager, Security Standards Team, G2, Inc.
Based on my conversations with some of the speakers, this webinar promises to be a lively one, complete with frank assessments of both the good and not-so-good aspects of the framework. I'll check back in here later with a write-up of the key points, but register for the webinar today so you can hear first-hand what they have to say and ask your own questions.

CrowdStrike CRO: NIST Framework, Vulnerability Mitigation Do Not Create Adequate Cybersecurity


On a day jam-packed with high-profile cybersecurity hearings and events in Washington, one expert witness strayed from the usual endorsements of government and corporate party lines to suggest that the cybersecurity strategies embraced by most organizations might actually harm security. Speaking at a hearing held today by the Senate Homeland Security and Government Affairs Committee, CrowdStrike Chief Risk Officer Steven Chabinsky (appearing in a personal capacity) said that the recent cybersecurity framework produced by the National Institute of Standards and Technology (NIST), while improving cybersecurity, "will not result in adequate security of our infrastructure and for our country."

Although praising the framework as a true public-private partnership, Chabinsky said that "improving our security posture requires that we reconsider our efforts rather than simply redouble them." Advocating that U.S. organizations align their cybersecurity efforts more with the strategies used in the physical world, Chabinsky said "we must ensure that our cybersecurity strategies focus on not preventing more intrusions but on more quickly detecting them and mitigating harm."

Specifically Chabinsky, previously a long-time FBI cyber intelligence leader, advocated a shift away from a "vulnerability mitigation" mindset, which he likened to protecting a building by constructing a twenty-foot brick wall around it (only to have the intruder buy a 30-foot ladder as a consequence), to one that focuses on instant detection, attribution, threat response, and recovery while in parallel locating and penalizing bad actors.  "We take reasonable precautions to lock our doors and windows, but we do not spend an endless amount of resources in hopes of becoming impervious to crime."

The growing focus on vulnerability mitigation can lead to decreasing economic returns, or worse, negative returns.  For example, using the analogy of the brick wall, stepped-up vulnerability mitigation might cause the intruder to use powerful explosives instead of buying a ladder. "Our current cyber strategy has had the unintended consequence of proliferating a greater quantity and quality of attack methods thereby escalating the problem and placing more of our infrastructure at greater risk," Chabinsky said.

Threat deterrence would improve if we blame the offenders rather than the victims for not having adequate vulnerability protection.  "It is my hope for the future that the blame for, and the costs of, cybercrime will fall more squarely on the offenders than on the victims, that in doing so we will achieve greater threat deterrence, and that businesses and consumers will benefit from improved, sustained cybersecurity at lower costs," he concluded in his written testimony.

Former Vice Admiral, NSA Director McConnell: 100% Certainty Cyber Attacks Will Occur



(Washington, DC)  Former Navy Vice Admiral, NSA Director and US Director of National Intelligence Mike McConnell said today that the probability of a destructive cyber attack is 100% and that without good information sharing between government and industry the loss of lives and damage to property could be high. "In my mind, there is 100% certainty that cyber attacks will occur," McConnell said at the EnergyBiz Forum on Securing Power here.

Repeating the growing mantra of current and former top government officials that Congress needs to pass a cybersecurity bill, McConnell said "we are a nation with a strategic vulnerability and we have the information to deal with the vulnerability and we must share information between the government and private sector.  [I]f we don't share [information] and share it frequently, we are going to have a major loss of life and damage of property.

"We need legislation that forces the government to provide classified information to the private sector," he stressed.  However, "it should be sanitized to make information of value available to you."

In terms of the most vulnerable critical infrastructure likely to experience a cyber attack, "I would probably choose banking or power and I would choose the hottest part of the summer or the coldest part of the winter," McConnell said. "Just imagine being in New York City in the middle of the summer with no power."

NIST Official: B2B Use of Cybersecurity Framework is the ‘Moonshot’



The real benefit of the cybersecurity framework released last week by the National Institute of Standards and Technology (NIST) will come when businesses and organizations use it with their partners and suppliers, Adam Sedgewick, principal organizer of the framework effort at NIST said yesterday. Speaking at our webinar (replay available) on the NIST framework, held jointly with the  Industrial Control System Information Sharing and Analysis Center (ICS-ISAC), Sedgewick said “ I think people have realized more and more that this is a pretty broad ecosystem.”

“What I hope we will see is that it will be used in business to business conversations.  That’s where this approach can really scale, where it is not tied to one or two government agencies.  That’s kind of the moonshot here and what we’re really hoping for.”

Even though the water sector has developed its own cybersecurity guidance, the NIST framework should prove to be a useful “anchor” on key cybersecurity issues, Kevin Morley, Security & Preparedness Program Manager, American Water Works Association said.  “We believe that it provides a very useful anchor on some principles” even if at “an applied level it may be a little abstract.”

The electric sector, which has its own mandatory cybersecurity standards in the form of NERC-CIP (National Electricity Reliability Corporation Critical Infrastructure Protection) requirements, was pleased to see that NIST made efforts to map the framework to those requirements during the development process, Laura Brown, Manager of CIP Policy and Coordination for NERC said.  “We’re happy…that the White House and NIST acknowledge that we have these standards.”

Involving top management in use of the framework is critical to its success, Kent Landfield, Director, Content Strategy, Architecture and Standards, McAfee Labs, said.  “It’s not something you want to do with a bunch of techies off to the side.”

Getting a realistic grip on the level of the organization’s cybersecurity maturity is likewise crucial to the framework’s success.  “Honest evaluation is critical,” Landfield said.  “You need to be accurate with where you stand today.  If you’re a one [in terms of the framework’s implementation tiers], put it as a one.  If you are not using the tool correctly, you’re not getting the most out of it.”

The implementation tiers in the framework, which “rate” an organization on how highly evolved its cybersecurity protection schemes are, could prove to be a disincentive to smaller organizations, Morley said. “We have concerns a little bit with the tiering structure.  From our perspective this may be a disincentive for action” because people are afraid their organizations will look bad if they rate lower on the scale.

From an industrial control sector perspective, the framework “is good for a number of reasons because it furthers the motion of the machinery in the U.S. public sector,” Chris Blask, chair of the ICS-ISAC said.
“For our purposes it’s helping our membership and by extension the people they are in contact with.”

NIST's Gallagher: Framework Implementation Falls to Companies, Not DHS


The implementation responsibilities for the cybersecurity framework developed and released last week by the National Institute of Standards and Technology (NIST) now fall into the hands of the critical infrastructure companies and operators, Patrick Gallagher, the head of NIST said today at a Brookings Institution event.  Despite the fact that many activities surrounding the framework now shift from NIST to the Department of Homeland Security (DHS) under the cybersecurity executive order issued by President Obama last year, "I actually don’t view the implementation responsiblities passing to DHS," Gallagher said.

"I think it’s important to keep in mind that there are three things happening here.  One is that the framework process continues and NIST continues to act as a convener so nothing has changed on that front at all."

"What DHS is doing is establishing a voluntary program that is there to support and promote adoption," he said.  "The most powerful force driving adoption are the companies themselves. This is not just about what you do internally. [I]t’s about your relationship with your vendors, your suppliers, your supply chain, the other companies you work with in your sector.  Those are actually more powerful than anything we've been discussing" [on the government side].

But the federal government, and NIST itself, will continue to play a key role in shaping further changes to the framework, although NIST has not yet announced a revision schedule for the framework.  "What we've done is deliberately create a bit of a pause…for the very reason that we don’t want to get in the way of the adoption piece. We really want companies to use this and we want the [revision] process to be informed by companies that are using the framework," Gallagher said.

And Gallagher hinted that NIST might continue to play a major role in the framework's application and development by pointing to the Smart Grid Interoperability Panel (SGIP), a non-profit organization which facilitates the use of  NIST-developed smart grid standards, as a potential model for the cybersecurity framework's governance.   "How do we set up a governance scheme where all these different companies can get work together and turn this into a ongoing routine process?," he asked.

"In smart grid, the SGIP was put together because the stakeholders felt there wasn't an existing organization that could facilitate the process," Gallagher said, inferring that perhaps such an organization could be developed for the cybersecurity framework.  NIST is extensively involved in the management and activities of the SGIP.

NIST Cybersecurity Framework Webinar Speakers Announced - Register Now for Thursday's Event


As I mentioned late last month, DCT Associates has teamed with the Industrial Control System Information Sharing and Analysis Center (ICS-ISAC), the private/public center for knowledge sharing regarding industrial control system (ICS) cybersecurity, to host a webinar on what cybersecurity practitioners need to know now about the cybersecurity framework developed by the National Institute of Standards and Technology.

The webinar is slated to begin at 1 pm EST on Thursday, February 20th and so far well over 100 people have signed up to find out what they need to know now about this unprecedented cybersecurity blueprint.

We've got a great line-up of speakers for this event, including:

  • Adam Sedgewick, Senior Information Technology Policy Advisor, NIST
  • Matthew Light, Cybersecurity Specialist, ES-ISAC at North American Electric Reliability Corporation
  • Kevin M. Morley, Ph.D., Security & Preparedness Program Manager, American Water Works Association
  • Kent Landfield, Director, Content Strategy, Architecture and Standards, McAfee Labs
Find out more about the event or just register today.  It's free and it's a chance to get a leg up on what promises to become the foundation for cyber protection initiatives across all industries and throughout the government.

The NIST Framework is Out the Door. So What's Next?



Industry and government alike have praised the cybersecurity framework developed by the National Institute of Standards and Technology (NIST). So, what happens next?

As I describe in my latest piece for CSO Magazine, the ball is now in the court of the Department of Homeland Security (DHS), which promises it will carry on in the spirit of openness which served NIST so well. NIST, however, won't ride off into the sunset anytime soon - it will act as a "convener" until DHS and the sector specific agencies take over the framework's implementation.

For more, check out the article.

And mark your calendars for a webinar on the cybersecurity framework that DCT Associates is hosting with the ICS-ISAC on February 20 at 1pm EST.  It's free and will hit the high points of what you need to know about the framework.

Government, Industry Embrace NIST Cybersecurity Framework


One year to the date since it was first assigned the challenge, the National Institute of Standards and Technology (NIST) today released its final version of a framework for improving critical infrastructure cybersecurity.  President Obama, whose February 2013 executive order mandated that NIST formulate the framework, praised the collaboration that went into the effort, citing all the work by public and industry participants as "a great example of how the private sector and government can, and should, work together to meet this shared challenge."

Although the framework itself consists of multiple and complex parts, and references hundreds of existing standards and practices, Lisa Monaco, Assistant to the President for Homeland Security and Counterterrorism boiled it down to its basic elements at a White House-organized event with top government and industry executives. "It provides for lack of a better phrase a common language to discuss cybersecurity. The framework core is really a set of common cybersecurity activities that [e]very organization should carry out in order to minimize cyber risks."

Another element of the framework, its profiles feature, helps "organizations to align what they’re doing with their own business requirements."  The final essential element, the tiers of implementation, "will allow companies to identify how well they’re doing to develop their own risk management practices," Monaco said.

Department of Homeland Security (DHS) Secretary Jeh Johnson officially unveiled the name for the DHS program that will continue refining the framework and promote its use among critical infrastructure asset owners.  The Critical Infrastructure Cyber Community (C3 or C-Cubed) Voluntary Program will give asset owners direct access to cybersecurity experts in DHS for advice and assistance in the event of a cyber attack or simply to provide guidance to organizations as they evaluate their cybersecurity strengths and weaknesses.

Joe Rigby, CEO of electric utility Pepco, praised the framework for providing a blueprint for his industry, which still is grappling with the challenges of cybersecurity.  "Our industry is actually pretty good at restoring power," he said.  But "we haven’t built the muscle yet for responding to cybersecurity.  We’ve been thinking about this for ten years but we’ve been acting on it for four or five years."

Telecom companies, on the other hand, have been forced by the market to stay apace with cyber developments.  "We unfortunately live, eat and breathe this," AT&T CEO Randall Stephenson said.  "It’s obviously just central to what we do.  Nobody has got this thing licked.  We think we’re pretty good at it but you’re only as strong as your weakest link."

The real benefit for AT&T will be in extending this "minimal" level of cybersecurity efforts to the company's supply chain and service providers.  "When you have all this interconnectedness [t]he weakest connection to your network is obviously an exposure point to your network. We look at this as a good piece of work but we view it as a minimum level."

As DHS continues to work on developing incentives for companies to use the framework, the focus should be on small companies that don't devote the effort to cybersecurity that large, well-financed players do, Marilyn Hewson, CEO of Lockheed Martin said.  "To the extent that we can look for incentives for the smaller and medium sized companies, that’s what we should do."

President Obama and virtually all of the government and industry officials stressed the need for congressional legislation to clear away the legal impediments that currently discourage cybersecurity information-sharing.  "I again urge Congress to move forward on cybersecurity legislation that both protects our nation and our privacy and civil liberties," he said in his statement.

One of the key elements that makes this [framework] viable in the long run is information sharing," AT&T's Stephenson said.  "There needs to be very robust protect and indemnification in place.  If you don’t have those in place, it’s all for naught."

Note: I will write a more in-depth piece on the framework's release as part of my series for CSO Magazine. Stay tuned.

NIST Official: Won’t Be Many Surprises in Cybersecurity Framework Release on Wednesday


(Washington, DC)  The National Institute of Standards and Technology (NIST) will release on Wednesday its final version of a comprehensive cybersecurity framework mandated by President Obama’s February 2013 cybersecurity executive order, with the final version containing few surprises, a NIST official said yesterday.  “Hopefully there won’t be many surprises,” Adam Sedgewick, NIST’s chief organizer of the framework process told attendees at the winter meeting of the National Association of Regulatory Utility Commissioners (NARUC) held here.

Since its fifth workshop on the framework in early November, NIST has fielded 2,500 separate comments on a preliminary version of the framework and posted a mid-January update on the changes the agency will incorporate as a consequence of the feedback.  The release of the framework at a White House event on Wednesday (with publication in the Federal Register on the 13th) comes exactly a year to the date following the executive order, an intensely compressed time frame given the magnitude of the topic.

“We went in without a net without thinking about what the framework would look like at the end of the day,” Sedgewick said.  Although the framework is “final,” NIST and government officials refer to it as the 'framework 1.0,' signifying the need for continued evolution as the framework is used by critical infrastructure owners. "From my perspective, there will always be more work to do on this issue.”

Once NIST puts the framework out, the Department of Homeland Security (DHS) will be primarily responsible for promoting its use, mostly through a public-private working group known as the voluntary program.  “The voluntary program will be our primary vehicle for promoting the framework,” Bob Kolasky, Director of Strategy and Policy, Office of Infrastructure Protection at DHS said.  “It is our key next step for how we're going to work with folks like you on how to use the framework.”

One critical infrastructure player, electric utility Pepco, already plans to change its procedures as a result of the framework, Susan Mora, Director of Federal Regulatory affairs at the utility said.  Specifically Pepco will reorganize its core cybersecurity functions to match those contained in the framework (which are Identify, Protect, Detect, Respond, and Recover).  Pepco has also volunteered to become one of the first utilities to which the framework will be applied.

Although the framework and the rest of the executive order are positive steps, a major stumbling block to better cyber protection is Congressional inability to pass a cybersecurity bill which would enhance information sharing among government entities and critical infrastructure owners, Mora said.  “I think the executive order is a great piece.  It checks box one which is standards and practices.  [But] there are other boxes that need work.  I can't tell you how disappointed I am on the information sharing front.”

State regulators play a key role in how the framework is used by utilities, primarily through the approval of cybersecurity expenses in public utility rate-making proceedings.  But “rate cases appear to be a dysfunctional pathway for appropriate cybersecurity,” industry consultant Andy Bochman told the utility commissioners in a presentation.  The adversarial culture surrounding the approval of rate increases can derail the reality of better cybersecurity, which both utilities and regulators seek as a shared goal.

Save the Date for Important Webinar - What You Need to Know About the Cybersecurity Framework


On February 13, the National Institute of Standards and Technology (NIST) will release the much-anticipated cybersecurity framework for critical infrastructure as mandated under President Obama's February 2013 executive order.  This framework (which I've followed extensively over the past year) is coming at a propitious time, with cyber breaches and digital vulnerabilities increasingly dominating the headlines and reshaping government and corporate policies.

The goal of the framework is to offer critical infrastructure providers a road map for managing cybersecurity challenges and to help organizations of all shapes and sizes to elevate cybersecurity risks to the level  that financial, safety, and operational risks currently occupy today.  These things are tall orders and NIST has consulted with thousands of cybersecurity technical and policy specialists through nationwide workshops, briefings and two rounds of public comments to come up with something that works.

Despite NIST's goal of keeping the framework high-level and flexible, it won't be that simple for even skilled cybersecurity practitioners to know what to do with it, when, how or why.  Therefore, my firm has teamed with the Industrial Control System Information Sharing and Analysis Center (ICS-ISAC), the private/public center for knowledge sharing regarding industrial control system (ICS) cybersecurity, to host a webinar on what you need to know now about the cybersecurity framework.

Scheduled for February 20 starting at 1 pm EST, this event will feature the top government and industry experts to explain it all.  Representatives from the relevant government agencies will walk through the framework and offer insight into how agencies and the administration view the importance and impact of adopting and following the framework.  Top experts from the electricity, petroleum, technology supply, water utility and other sectors will discuss the impact of the framework on their cybersecurity practices and procedures.

Best of all, it's FREE.  (If you're interested in sponsoring this webinar to gain greater exposure to the top cybersecurity specialists who will attend that event, drop me an email.)  Sign up today and put it on your calendar.  Stay tuned as we publish the full list of speakers.

White House Cybersecurity Official: We Need A Public Health Model for Cybersecurity


(Baltimore, MD)  Amid growing cybersecurity threats which are becoming increasingly difficult to detect and more dangerous at the same time, the U.S. should develop a public health model for cybersecurity, a White House official said today.  Speaking at the 2014 Cybersecurity Innovation Forum here, Michael Daniel, Cybersecurity Coordinator at the White House, said that the existing cybersecurity thought models, which cast cyber threats in military terms such as "attack" or "war," are useful but that it's time to "think of the cybersystem as an immune system."

To achieve better cyber health, several steps are necessary.  The basic steps are:  widespread adoption of best standards and practices, expanded information sharing and the sharing of actionable information.  The need for better cyber health practices becomes more urgent each day because “now we are going [into] a world where the coffee maker, your refrigerator and car are threat vectors,” he said.

“A single [poorly crafted] exploit can yield immense value for its creator.  For years you can keep deploying that same crappy attack.  To better defend our networks we need to decrease the value of these exploits by better cyber public health.”

The importance of effectively communicating good cybersecurity practices is key to maintaining that thought model. “We as a community could do better ways of preparing information in a way that the community can use it,” Donna Dodson, Division Chief of the Computer Security Division at the National Institute of Standards and Technology (NIST), said.  “One of the big points of  [President Obama’s February 2013 executive order] was the need to have a conversation between the bits and bytes and the CEOs. We have to think about how to give people good information and how they can digest it.”

In terms of adapting to innovation, securing the increasing number of mobile devices requires rapid action. “The biggest challenge is for us to move from devices today to mobile devices,” Curt Dukes, Deputy Director, Information Assurance of the National Security Agency (NSA) said.

That cybersecurity has risen to a level of national policy importance in less than a decade is a testament to how important maintaining digital security is to national welfare. “I didn't ever expect the President to say [the word] cybersecurity” in a State of the Union address as he did last night and during last year’s address, Bobbie Stempfley, Deputy Assistant Secretary, Office of Cybersecurity and Communications at the Department of Homeland Security said.

Adoption and Privacy Issues Get Aired at NIST's Fifth Cybersecurity Framework Workshop


Last week in Raleigh, North Carolina, the National Institute of Standards and Technology (NIST) hosted a fifth and final workshop on the development of a comprehensive critical infrastructure cybersecurity framework as the February 2014 deadline for finalizing the ambitious effort draws near.  After an intensive amount of work on a complex and thorny subject, many of the participants, particularly those who participated in all five of the workshops, were in awe over how far NIST has come since it received its marching orders via President Obama's executive order last February.

But as could be expected, there are a lot of issues that have yet to be resolved.  As my latest piece for CSO Magazine spells out, one major question remains unanswered despite the prodigious work by NIST and industry collaborators:  what constitutes adoption of the framework?  Without really good answers to this question, the framework itself could become a hollow exercise that, while representing good thinking and practices, does very little in reality to raise the cybersecurity bar.  The definition of adoption as well as related issues (such as the incentives needed to adopt the framework) got a lot of airtime among the attendees in North Carolina.

A well-organized effort to get NIST to overhaul its latest attempt to incorporate privacy and civil liberty considerations into the framework was one of the more surprising aspects of the workshop.  The framework's privacy appendix is too broad and should be pared down to deal only with privacy matters as they relate to cybersecurity, a number of top infrastructure industry reps said.

NIST has some, but not much, time left to tinker further with the framework before it becomes final.  And the group is still fielding feedback during an open comment period that ends in December.

For more information on the latest workshop, check out my article in CSO.

Public-Private Partnership, Information Sharing Key to NIST Cybersecurity Framework Success


(Washington, DC)  Improving private sector relations with the government, particularly in the area of threat information, will be central to the future success of the cybersecurity framework issued last week by the National Institute of Standards and Technology (NIST), according to a panel of industry representatives speaking at a Bloomberg Government cybersecurity conference here today.  That framework was developed pursuant to an executive order signed by President Obama last February and is slated to be final under the order by February 2014.

When asked to rate the still-preliminary framework on a scale of one to ten in terms of how well the public-private partnership has worked so far in developing the framework, Dean Garfield, President and CEO of the Information Technology Industry Council, rate the effort an 8.5.  "What was surprising to me is that there is broad consensus on policy issues," he said.

"It's improving, it's moving toward the higher end" of the scale, Robert Mayer, Vice President of Industry and State Affairs at telecom trade association USTelecom said.  "The grade is obviously incomplete [but] I'm encouraged by the direction we're moving in," Internet Security Alliance CEO Larry Clinton said.

Jeremy Bash, Managing Director of  policy consulting firm Beacon Global Strategies, however, rated the effort as merely a three "because there is a huge disconnect with industries.  For the vast majority of enterprises, this issue is not yet on the radar screen." Most industries "fundamentally want one thing - they want the government to share sensitively derived threat [information], Bash said.

Incentives, which are also addressed separately in the executive order, are also key determinants of how well the framework will be adopted.  One important incentive is to improve information sharing between the government and private sector, Garfield said.  "Making sure we have the capacity and communication internally within the administration and the government to share and make use of the information that has been shared," is crucial.

The problem is going to be that many incentives, including some of the liability protections needed for effective information sharing, will require statutory authority, necessitating an act of Congress, Mayer said., a very difficult feat given the current legislative environment.  One big problem with threat information sharing is that "the government doesn't want to share data because they are afraid the source of the data will come out," Clinton said.  "The thing is industry doesn't care about the source.  So take the source data out."

NIST Cybersecurity Framework Is Improved But Best Part Is the Community It Has Created


The National Institutes of Standards and Technology (NIST) released on Tuesday its "official" preliminary comprehensive critical infrastructure cybersecurity framework as required under President Obama's February executive order, and most people involved say it's an improvement over previous versions.

After talking to a number of the key participants in the framework process, I noticed that despite the varied and widespread critiquing of the framework from a diverse and often fractious bunch of cybersecurity specialists, lawyers and engineers, one thing stood out:  the framework has created a community of people willing to collaborate on cybersecurity for the common good.

As one participant noted, "what we've developed is a framework for people working together." Unfortunately the framework itself still falls short in terms of actually improving cybersecurity in the eyes of many participants.  But there's still time for more changes before the framework is finalized in February...and will probably continue changing well after that.

Here's my latest take in my ongoing series on the framework for CSO Magazine.  Check it out.

Cybersecurity Leader Offers Alternative Version to NIST Framework



Phil Agcaoili (pronounced "Agg-Ca-Willy") is doing his best to push things forward with the cybersecurity framework process underway at the National Institute of Standards and Technology (NIST). The much-lauded cybersecurity leader, who sold his first cybersecurity company to Verisign for $70 million in 1998, making him a comfortable man in his mid-20s, has made a public shot across the bow of NIST's effort to craft a comprehensive cybersecurity framework for critical infrastructure as mandated under President Obama's February 2013 cybersecurity executive order (EO).

At midnight last night, Agcaoili posted on the Internet his own draft cybersecurity framework (download spreadsheets here) that he contends is a simpler, better version of the one that NIST has been working on since February.  He said that his framework, which he has vetted with the top cybersecurity professionals and standards-setting bodies in the world, actually meets the EO's goal, which is to produce a "prioritized, flexible, repeatable, performance based, and cost effective" scheme.

The timing of Agcaoili's is no coincidence - under the EO NIST was required to publish a draft of its framework in 240 days, or on October 10th, yesterday.  Due to the government shutdown, NIST has ceased all work on the framework, which must be finalized by February, and has shuttered its framework website (see image above).  If NIST aims to meet the February deadline despite the delay, as some reports indicate, there is little time to make effective changes in the framework, which, while currently voluntary, could ultimately become mandatory for many critical infrastructure industries through regulatory machinations.

"We're not shutting down on the Internet," Agcaoili said, referencing the fact that interested commenters no longer have access to the materials that NIST has developed and on which NIST is seeking public comment. Agcaoili said he released his alternative framework as a private citizen.

"I was making a statement on many levels on what a private citizen can do, what the government doesn't have to do," he said.

Agcaoili is echoing the view held by many cybersecurity practitioners inside critical infrastructure entities (as opposed to Washington representatives or Beltway consultants or government officials) that the NIST framework is simply "reinventing the wheel" and will make cybersecurity more, not less, difficult.  He said his framework consists of nothing more than well-honed cybersecurity components that already "exist in the wild" and for which most critical infrastructure entities already seek certification.

Specifically, Agcaoili's framework hinges on six core schemes:  ISO/IEC 27001-2005, COBIT 4.1, NIST SP800-53 R3, CCS CSC, NERC CIP and ISA 99.  In addition, he has factored in three key privacy standards -- GAPP (August 2009), AICPA TS Map, AICPA Trust Service Criteria (SOC 2SM Report). The latest version of the NIST framework is generic when it comes to privacy, despite the EO's requirement that NIST ensure privacy requirements are built into the framework.

"If you’re already following SANS, if you’re already following ISO, if you’re already following NERC-CIP you’re following the framework," he said.  "We've done it in the industry all along."

Much of Agcaoili's framework is based on technical "mapping" work performed by the Cloud Security Alliance (CSA), which has attempted to pull together the sometimes incoherent mass of cybersecurity standards into a comprehensible whole so that cybersecurity professionals can more easily know how to secure their networks and systems.  Agcaoili began to vociferously promote a CSA-type approach in San Diego in July at one of the four workshops NIST has held since the EO was signed.

He said he does have the support and backing from a host of cybersecurity luminaries and standards group. Agcaoili named these individuals and groups--and they are impressive--with the same rapid-fire and encyclopedic knowledge he uses to discuss the vast, arcane and complex world of cybersecurity standards and practices.

Asked why he has taken this bold step, Agcaoili said "so that people can pick it up and use it.  So we can actually defend our country and stop all the fracturing that’s going on."

Note:  This headline and some of the article text has been modified since its original publication.

Alexander, Rogers Appeal for Cybersecurity Legislation While Lute Says It's a Sure Thing


(Washington, DC) National Cybersecurity Awareness Month is not even upon us yet but the DC hype meter tilted into the red today with three dueling cybersecurity events, each populated by prominent panelists who propounded on their pet topics and theories surrounding the state of systems security.  Some attendees moved from event to event throughout the day, catching one set of speakers and then moving on to the next venue.

The speakers across all three events ranged from the highly technical to the highly political, with most emphasizing the need for better cybersecurity policy and practices.  If one common theme emerged across the two dozen-plus speakers and panelists it is the need for a cyber bill which, at the minimum, facilitates information sharing and encourages better conformance to good cyber schemes.

One day-long event was hosted at the National Press Club (keynote videos here) and generated the most buzz due to its opening keynote speaker, embattled National Security Agency (NSA) Director Keith Alexander.  Alexander first castigated what he considered the media leaks flowing from former contractor Edward Snowden and then shifted into a plaintive plea for help from the public and private industry in maintaining the vast electronic intelligence apparatus his agency has built.

"We first have to address media leaks," Alexander said.  Speaking of the call records collection authorized by the Foreign Intelligence Surveillance Court, Alexander attempted again to explain, as he has many times over the past several months, that media coverage has distorted the kinds of information NSA collects, reiterating that the bulk of the collection focuses on metadata, comprising call details such as date, time, length of call, and not on the content of the calls.  "It’s been sensationalized and inflamed in much of the reporting that we’re listening to people’s calls and reading their emails.  That’s flat wrong."

Alexander frequently asked for help and support in maintaining NSA's activities, saying that the security of the nation depends on the efforts of his and other intelligence groups.  "Our mission is to have to defend this country," he said.  "We can’t do it without your help and without the tools that the nation needs."

He also appealed on behalf of those Internet and technology companies that supply data to NSA, stressing that they only do so under court order.  "Industry isn't driving up to NSA, dumping off U.S. persons' or foreign person's data to us," he said.  "What they’re doing is they’re providing what the courts have directed for them to provide."

He walked through a series of statistics about the "incidents" or "violations" that have occurred with the data NSA collects, saying that only 5% involve U.S. persons, and even then mostly involve typos and not deliberate privacy invasions.  Most of the NSA personnel engaged in the violations either retired, resigned or were appropriately admonished.  "What that means for you and the American people is that you are guaranteed that we will do everything we can to protect your civil liberties and your privacy and defend this country," he said.

At one other big cybersecurity event, hosted by the U.S. Chamber of Commerce, House Intelligence Committee Chairman Mike Rogers (R-MI), bemoaned how much more difficult it now is to pass cybersecurity legislation due to the controversy triggered by the Snowden leaks.  Rogers, like Alexander, hopes that Congress can move past the drama and enact effective cybersecurity legislation.

He was specifically referring to a bill he co-sponsored, the Cyber Intelligence Sharing and Protection Act (CISPA), which would facilitate cyber threat information sharing.  "I haven't given up on CISPA," Rogers said.

At the third cybersecurity event of the day, hosted by DC lobbying and law firm Venable, Jane Holl Lute, CEO of the Council on CyberSecurity and former Deputy Secretary of the Department of Homeland Security (DHS), said that cybersecurity legislation is practically a sure thing.  "I think it's a near certainty that there will be legislation regarding cybersecurity," she said.

A big factor that will drive Congress is the failure of the marketplace to provide adequate security in the cyber realm.  "Of those who say they want to keep government out, government will step in...because frankly we're at an unacceptable level of vulnerability and the market is not taking care of that," Lute said.

NIST Cybersecurity Framework Subject to Major Work Ahead of Public Comment


The National Institute of Standards and Technology (NIST) is racing the clock to whip into shape the comprehensive cybersecurity framework mandated by President Obama's February executive order.  As my most recent piece for CSO Magazine highlights, critical infrastructure providers say there is a lot of work to get done before the framework, a first-time government effort to bolster better cybersecurity across all critical infrastructure, is published in the Federal Register on October 10 and put out for public comment.

The final framework is due in February, but when it comes to the constantly changing world of cybersecurity, the framework could keep evolving indefinitely.  As Patrick Gallagher, the head of NIST, saiid, "in my view the framework is never finished."

Check out the full article here.

NIST's Latest Draft Cybersecurity Framework: Not Yet Ready for Primetime


The National Institute of Standards and Technology (NIST) released the latest version of its draft cybersecurity framework on August 28 and the reviews are...mixed.  The voluntary framework, mandated under President Obama's February executive order and intended to help critical infrastructure providers establish better cybersecurity programs, needs a lot more work, experts say, despite the greater detail NIST provided between versions one and two of the document.

But little time remains between a final workshop on the framework that NIST will host in Dallas next week and the October 10th deadline for publishing the preliminary framework in the Federal Register.  Read my latest take on the framework in this article commissioned by CSO Magazine.

Image from the August 28th document released by NIST.

China Not Out to Destroy the Electric Grid or Other Networks, Former NSA, CIA Director Hayden Says


U.S. networks, including the electric grid, are less threatened by cyber attacks from nation-states than from damage inflicted by rogue entities such as web activists, former CIA and NSA Director Michael Hayden said today.  And although China is a major cyber threat from an economic perspective, it does not seem a likely source of destruction to U.S. networks.

"Without question the country that is out there stealing most of our stuff is China," Hayden said at a Bipartisan Policy Center conference on protecting the electric grid from cyber threats.  "There is evidence that they are out there on SCADA networks as well as just penetrating networks just to steal our stuff."

But, Hayden said, "frankly I find it hard to imagine circumstances where China would want to do something incredibly destructive to any American network, the grid, absent a far more problematic international environment in which the cyber attack itself is part of a larger package of really, really bad things."

The real threat to the grid and other networks may not be nation-states such as China or criminals out to make a buck but unpredictable rogue players, including terrorist groups and web transparency activists. "Sooner or later governments can be held to account.  Fundamentally criminals want to make money and they enter into a symbiotic relation with the host," Hayden said.

Those loosely defined players, though, are "beginning to acquire capacities that a year or two or three ago we equated with the more competent groups" and their "demands may be unsatisfiable," according to Hayden. "This is going to get worse before it gets better."

The philosophy embedded in the U.S. Constitution makes it hard to create adequate cyber defenses because "we have not yet created a consensus as to what we want our government to do..or what we will let our government do," Hayden said.  "I’m willing to accept the proposition that forever the United States will have one of the least well-defended networks on this planet because of James Madison and Alexander Hamilton and all of those good folks who wrote the Federalist papers."

Addressing the revelations flowing from the leaks of former NSA contractor Edward Snowden, Hayden said that the ensuing fears of an overly aggressive government will "freeze" the government's ability to protect private industry and that private industry must learn to protect itself.  "The next sound you hear will not be a bugle and the sound of pounding hoofs as the federal cavalry comes over the ridge line to your rescue," he said. "To the degree that you never expected it down here in the physical domain, you are responsible for your safety in the digital domain personally and corporately."

The federal government, though, needs to step up its cybersecurity efforts, particularly in the arena of information sharing, electric industry representatives speaking at the same event said.  Speaking of state regulator capabilities for addressing cybersecurity issues, Doug Myers, CIO of Pepco Holdings, said "if the conversation at the state level could be informed by a clear and compelling federal vision…I think would be very helpful."

"The issue has to be addressed at the federal level," Ed Goetz, VP of Corporate and Information Security at Exelon said. "I think the president’s executive order opened the door to this possibility."

However, information sharing works best as a two-way street, Scott Saunders, Information Security Officer at Sacramento Municipal Utility District said.  "if we pull together in a more cohesive manner we can provide information back to the government about what is happening to us."

Twitter Delicious Facebook Digg Stumbleupon Favorites More