The Inner Circle

 View Only
Expand all | Collapse all

White House Asks CISA, NIST to Set Cybersecurity Performance Goals for Critical Infrastructure Operators

  • 1.  White House Asks CISA, NIST to Set Cybersecurity Performance Goals for Critical Infrastructure Operators

    Posted Jul 28, 2021 11:39:00 AM
    Technically cloud computing is not one on the 16 critical infrastructure sectors in the US Gov't definition, although there is some reference to it in the Information Technology Sector Plan of 2016. However, the reality is that all 16 sectors now use cloud extensively, so it is probably a moot point. The shared responsibility of cloud is such that I believe we focus on making sure that critical infrastructure sector entities are demonstrating strong cloud cybersecurity hygiene.  I realize this may seem self-serving, but I think the best out-of-the-box solution we have is for these entities to go through the CSA STAR program. It is here, it is trusted, over 1,000 entries and we don't have to debate about the mega IaaS provider role and create new laws as it is already baked into the controls framework. 

    Earlier this year, I lauded Saxo Bank for being the first financial institution I was aware of that added an entry into CSA STAR. It was Level 2 STAR Attestation, which is a third party assessment. I am hoping this is a trend.


    White House Asks CISA, NIST to Set Cybersecurity Performance Goals for Critical Infrastructure Operators
    Defense One remove preview
    White House Asks CISA, NIST to Set Cybersecurity Performance Goals for Critical Infrastructure Operators
    The White House will issue a national security memo Wednesday instructing the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology to establish cybersecurity performance goals for private-sector owners and operators of critical infrastructure.
    View this on Defense One >


    ------------------------------
    Jim Reavis CCSK
    Cloud Security Alliance
    Bellingham WA
    ------------------------------


  • 2.  RE: White House Asks CISA, NIST to Set Cybersecurity Performance Goals for Critical Infrastructure Operators

    Posted Jul 28, 2021 02:06:00 PM
    Here is the EO. It seems focused on Industrial Control Systems overall (which more and more have a cloud element), however Section 4 says:

    "Cybersecurity needs vary among critical infrastructure sectors, as do cybersecurity practices.  However, there is a need for baseline cybersecurity goals that are consistent across all critical infrastructure sectors, as well as a need for security controls for select critical infrastructure that is dependent on control systems." 

    https://www.whitehouse.gov/briefing-room/statements-releases/2021/07/28/national-security-memorandum-on-improving-cybersecurity-for-critical-infrastructure-control-systems/

    ------------------------------
    Jim Reavis CCSK
    Cloud Security Alliance
    Bellingham WA
    ------------------------------



  • 3.  RE: White House Asks CISA, NIST to Set Cybersecurity Performance Goals for Critical Infrastructure Operators

    Posted Jul 29, 2021 07:59:00 AM
    I worked on a big project while at BSI with large ICS organization regarding their industrial control systems and ISO/IEC 27019:2017 Information technology - Security techniques - Information security controls for the energy utility industry.

    ISO/IEC 27019:2017 provides guidance based on ISO/IEC 27002:2013 applied to process control systems used by the energy utility industry for controlling and monitoring the production or generation, transmission, storage and distribution of electric power, gas, oil and heat, and for the control of associated supporting processes. This includes in particular the following:

    - central and distributed process control, monitoring and automation technology as well as information systems used for their operation, such as programming and parameterization devices;

    This includes smart grid, all software, firmware and applications installed on above-mentioned systems, e.g. DMS (Distribution Management System) applications or OMS (Outage Management System);

    - any premises housing the above-mentioned equipment and systems;

    - remote maintenance systems for above-mentioned systems.

    Also the PLCs (Programmable logic controllers) and SCADA (Supervisory control and data acquisition) talk over the cloud these days. The operator interfaces which enable monitoring and the issuing of process commands, such as controller setpoint changes, are handled through the SCADA supervisory computer system.

    This is a sector that is listed in the DHS list of critical infrastructure. 
    John A DiMaria; CSSBB, AMBCI, HISP, MHISP, CERP
    Assurance Investigatory Fellow
    Cloud Security Alliance
    m:+1 314 374-9752






    This e-mail account is used only for work-related purposes; it is not guaranteed that any correspondence sent to this address will be read by the addressee only, as it may be necessary, under certain circumstances, for third parties appointed by the Cloud Security Alliance to access this e-mail account. Please do not send any messages of a personal nature to this address.