Legislation calls for new security standards for government and critical infrastructure systems
By Jaikumar Vijayan
April 1, 2009 (Computerworld) Two U.S. senators are proposing legislation that would give federal officials significant new authority to create and enforce data security standards both for government agencies and key parts of the private sector.
The Cybersecurity Act of 2009, which was introduced by Sens. Olympia Snowe (R-Maine) and Jay Rockefeller (D-W.Va.), would empower the National Institute of Standards and Technology (NIST) to establish "measurable and auditable" security standards for all networks and systems run by federal agencies, government contractors and businesses that support critical infrastructure services. In addition, NIST would be charged with developing a standard for testing and accrediting software built by or for those groups.
The bill also calls for the creation of a national cybersecurity adviser's office within the Executive Office of the President. Under the proposal, the new operation would be modeled after the Office of the U.S. Trade Representative and have the power to compel federal agencies to comply with government security mandates.
According to a statement posted on Snowe's Web site Wednesday, the new legislation is aimed at reinforcing ongoing cybersecurity efforts within the government while also ensuring that proper safeguards are implemented for critical infrastructure targets within the private sector, such as banking and power systems. .. More >>
Saturday, April 11, 2009
Senate bill would give feds bigger cybersecurity role in private sector
Tuesday, November 20, 2007
Did NSA Put a Secret Backdoor in New Encryption Standard?
The standard is found in NIST Special Publication 800-90.
The article may be quite technical but is enough to raise concerns that backdoors may exist in a puportedly secure software component.
This leads to the conclusion and emphasis that it is imperative for nations to have their own indigeneous technologies inkey security areas in order to minimise exposure to shortcomings or backdoors that leave the system vulnerable to attacks or intrusions. >> More ..
Friday, October 12, 2007
Cyber Security Standards for Electric Power Systems
The North American Reliability Corporation or NERC has produced standards for Cyber Security for the power systems industry. Further details can be found here but a summary is described below. The standards are part of a full set of Reliability Standards including Emergency Preparedness and Operations and the full list of standards is listed and can be downloaded here.
NERC Cyber Security
The purpose of NERC's new cyber security standards is to ensure that all entities responsible for the reliability of the bulk electric systems of
NERC CIP-002 to CIP-009
NERC's new cyber security standard was originally called NERC 1300, but this has changed to 8 separate standards, CIP-002 to CIP-009. As summarized in the table below, these standards contain definitions, policies, reporting requirements, and issues related to personnel security, electronics (or network) security, and physical security (such as access).
| New Std # | Topic |
| CIP-002-1 | Critical Cyber Assets |
| CIP-003-1 | Security Management Controls |
| CIP-004-1 | Personnel and Training |
| CIP-005-1 | Electronic Security |
| CIP-006-1 | Physical Security |
| CIP-007-1 | Systems Security Management |
| CIP-008-1 | Incident Reporting and Response Planning |
| CIP-009-1 | Recovery Plans |
Tuesday, October 9, 2007
NIST Publications on ICT Security
The list of documents on ICT Security can be found and downloaded here but a more general introduction page on the publications category types is here.
The list is summarized also in the following documents which should be useful as a big picture reference:
1. Guide to NIST Information Security Documents
2. Roadmap to NIST Information Security Documents.
There are hundreds of documents in the whole set and a selection of the relevant topic clusters is listed below (each topic cluster has a list of relevant documents):
Audit & Accountability
Authentication
Awareness & Training
Certification & Accreditation (C&A)
Communications & Wireless
Contingency Planning
General IT Security
Incident Response
Maintenance
Planning
Risk Assessment
Viruses & Malware
On the topic of Critical Infrastructure Protection, the documents relevant to the Homeland Security Presidential Directive-7 (HSPD-7), Critical Infrastructure Identification, Prioritization, and Protection are:
FIPS 199 Standards for Security Categorization of Federal Information and Information Systems
FIPS 200 Security Controls for Federal Information Systems
SP 800-18 Guide for Developing Security Plans for Information Technology Systems
SP 800-30 Risk Management Guide for Information Technology Systems
SP 800-37 Guide for Security Certiication and Accreditation of Federal Information Systems
SP 800-53 Recommended Security Controls for Federal Information Systems
SP 800-60 Guide for Mapping Types of Information and Information Systems to Security Categories
SP 800-59 Guideline for Identifying an Information System as a National Security System
SP 800-82 Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control System Security
Monday, October 8, 2007
New security standards to strengthen SCADA
Sunday, October 7, 2007
ISA99 cyber security guidelines provide full user resources
There are two technical reports: ANSI/ISA-TR99.00.01-2004, ‘Security Technologies for Manufacturing and Control Systems’, and ANSI/ISA-TR99.00.02-2004, ‘Integrating Electronic Security into the Manufacturing and Control Systems Environment’.
The former provides an evaluation and assessment of current types of electronic security technologies and tools that apply to the manufacturing and control systems environment, including development, implementation, operations and maintenance.
The latter provides a framework for developing an electronic security programme and provides a recommended organisation and structure for the security plan. The information provides detailed information about the minimum elements to include.
The original article can be found here.
Control Systems, Instrumentation Systems and Automation Security
Amongst the relavant articles are:
1. Making Cyber Security Work in the Refinery
2. Uncovering Cyber Flaws
3. SP99 Counterattacks
4. Securing the Power Grid . This article also has a good chronological chart on the 2003 power blackout in OHIO that crippled a part of the nation.
5. ISA99, Manufacturing and Control Systems Security ISA99 is a new standard for Manufacturing and Control Systems Security. The current edition covers only security technologies and their strengths/weaknesses in the manufacturing environment. Eventually this would be expanded to include traditional strengths and weaknesses of the different types of control systems (DCS, PLC, SCADA, HMI, etc). The end of the article contain a list of materials in the development of ISA99 by the ISA SP-99 Committee.