• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Cybersecurity Power
April 19 2018 3:28 pm

Alarming Increase in Cybersecurity Threats Prompts Spate of Government Action

S

Sonal Patel

Lawmakers, industry, and government entities, including the Department of Energy (DOE) and the National Institute of Standards and Technology (NIST), this week released a string of measures responding to mounting cybersecurity attacks by state-sponsored actors.

A Revised Cybersecurity Framework

On April 16, the Commerce Department's NIST, a federal standards laboratory, released an updated version of the "Cybersecurity Framework." A living document, the framework is a risk-based approach to cybersecurity that is applicable to organizations relying on technology, whether IT, industrial control systems (ICS), or cyber-physical systems and connected devices–including the Internet of Things (IoT). While it is not a one-size-fits-all approach to managing critical infrastructure risks, organizations typically use it to determine activities that are important to critical service delivery, as well as to prioritize investments.

According to NIST, numerous industry surveys indicate sustained and increasing use of the framework over time. All federal agencies must use the framework, as required by a May 2017 executive order signed by President Trump. NIST noted that the framework has also been adopted by many companies and countries across the world, including Italy, Israel, and Uruguay.

Version 1.0 was issued in February 2014 as required by the Cybersecurity Enhancement Act of 2014. Version 1.1, released on Monday following a period for public comment and workshops held over 2016 and 2017, is "intended to be implemented by first-time and current Framework users," the document says. "Current users should be able to implement Version 1.1 with minimal or no disruption; compatibility with Version 1.0 has been an explicit objective."

Key changes to the framework in the new version include:

  • A new section on self-assessment, which explains how the framework can be used to understand and assess risks, including use of measurements;
  • An expansion of a section to explain in more detail how stakeholders can better understand cyber supply chain risk management;
  • Refinements to better account for authentication, authorization, and identity proofing;
  • A better explanation of the relationship between implementation tiers and profiles;
  • Updates on vulnerability disclosure;
  • A clarification of terms like "compliance."

Later this year, NIST plans to release an updated companion document, the "Roadmap for Improving Critical Infrastructure Cybersecurity," which will describe key areas of development, alignment, and collaboration. NIST will host a free public Webcast explaining Version 1.1 in detail on April 27, 2018, at 1 p.m. Eastern time. NIST is also planning a Cybersecurity Risk Management Conference–which will include a major focus on the framework–to be held November 6–8, 2018, in Baltimore, Maryland.

More Funding for Cybersecurity Research

The DOE on April 16 also made a $25 million funding opportunity announcement (FOA), seeking applications to conduct research, development, and demonstration (RD&D) in five areas:

  • Redesign for cyber-resilient architecture–electric, and oil and natural gas (ONG) subsectors;
  • Cybersecurity for the ONG environment;
  • Cybersecure communications;
  • Cybersecure cloud-based technologies in the operation technology (OT) environment;
  • Innovative technologies that enhance cybersecurity in the energy sector.

The DOE said applicant submissions, due on June 18, 2018, "must conclude in a demonstration of the developed technology at a relevant end-user site to validate a clear path to industry acceptance." Selected applications will involve advanced tools technologies that are interoperable, scalable, and readily manageable. They will also include a strategy for transitioning solutions into practice throughout the energy sector through commercialization or by making the solution available through open source.

Cybersecurity Gets a Boost on the Hill

Lawmakers in the U.S. House are, meanwhile, scrambling to respond to disclosure by the Department of Homeland Security last month that Russian state-sponsored actors are targeting energy-related ICS.

Cyber Deterrence Bill. On April 18, Rep. Ted S. Yoho (R-Florida) introduced the Cyber Deterrence and Response Act of 2018 (H.R. 5576), a bipartisan bill that would create a three-step process for identifying, deterring, and responding to malicious, state-sponsored cyberattacks.

The bill hasn't been published yet for public viewing, but according to Politico, the measure would require the White House to "name and shame" state-sponsored attackers, label them as "critical cyber threats," and impose sanctions on them for carrying out attacks against the U.S.

The bill has been referred to the Committees on Foreign Affairs, Financial Services, Oversight and Government Reform, and the Judiciary.

Energy Security Bills Clear Energy Subcommittee. On April 18, the Subcommittee on Energy advanced a spate of bills to the full Energy and Commerce Committee to give the DOE "tools it needs to execute its core energy security missions and to promote domestic energy infrastructure and capitalize on the nation's energy abundance," a press release says.

Four bills could directly affect power sector dealings.

H.R. 5239, Cyber Sense Act, authored by Digital Commerce Subcommittee Chairman Bob Latta (R-Ohio) and committee member Rep. Jerry McNerney (D-California), would establish a voluntary DOE program that tests product cybersecurity and technologies intended for use in the bulk-power system, including products related to ICS. It would also authorize the DOE to provide technical assistance to electric utilities, product manufacturers, and other electricity sector stakeholders to help mitigate cybersecurity vulnerabilities. It passed the subcommittee unanimously by voice vote.

H.R. 5240, Enhancing Grid Security through Public-Private Partnerships Act, also authored by Reps. McNerney and Latta, requires the DOE to establish a program to encourage public-private partnerships to promote and advance physical and cybersecurity at smaller electric utilities, which may have fewer resources. It also directs the DOE to assess policies and actions to enhance physical and cybersecurity of distribution systems. It passed the subcommittee unanimously by voice vote.

H.R. 5175, Pipeline and LNG Facility Cybersecurity Preparedness Act, authored by Energy Subcommittee Chairman Rep. Fred Upton (R-Michigan) and committee member Rep. Dave Loebsack (D-Iowa), would require the DOE secretary to carry out a program coordinating federal agencies, states, and the energy sector to ensure security, resiliency, and "survivability" of natural gas pipelines, hazardous liquid pipelines, and liquefied natural gas facilities. It also passed the subcommittee unanimously by voice vote.

H.R. 5174, Energy Emergency Leadership Act, authored by committee members Rep. Tim Walberg (R-Michigan) and subcommittee Ranking Member Bobby Rush (D-Illinois.), updates the DOE's Organization Act to include energy emergency and energy security functions, which the secretary shall assign to an assistant secretary. The measure passed unanimously by voice vote.

 

–Sonal Patel is a POWER associate editor (@sonalcpatel, @POWERmagazine)

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles