News: 1621350193

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

The UK loves cybersecurity so much, it's going to regulate managed service providers' infosec practices in law

(2021/05/18)


+Comment The British government has vowed to create a legally binding cybersecurity framework for managed service providers (MSPs) – and if you want to tell gov.UK what you think, you've only got a few weeks to act.

The supply chain review comes in the wake of high-profile events like the SolarWinds compromise and [1]a 2018 APT campaign linked by the FBI to China that may have breached HPE, IBM, and some of their clients.

Targeted at managed service providers and firms outsourcing their digital infrastructure services alike, the review is described by the government as helping build evidence for "additional government intervention" to force businesses into formally assessing cyber risks to their supply chains. It also looks like MSPs will be subject to a legally binding security framework as a result of the review.

[2]

[3]

[4]

Matt Warman MP, whose Department for Digital, Culture, Media and Sport job title this week is "digital infrastructure minister", said in a canned statement: "There is a long history of outsourcing of critical services. We have seen attacks such as 'CloudHopper' where organisations were compromised through their managed service provider. It's essential that organisations take steps to secure their mission-critical supply chains – and remember they cannot outsource risk."

MSPs are obvious targets for criminals: if you pwn one MSP, you can potentially gain illicit access to all of its customers – or simply threaten to DoS them unless a ransom is paid.

'This could be time consuming and a difficult process'

Chris Waynforth, AVP Northern Europe at Imperva, mused: "It's interesting to see the onus the government is placing on providers of digital services, in particular those providing managed services – suggesting they may be subject to some sort of regulation for the first time.

"Depending on the level of maturity, this may be music to the ears of some, allowing them to distinguish their services and show they are equipped to protect customers from supply chain attacks. For others, this could be time consuming and a difficult process."

Formal responses to the call for views [5]can be found on GOV.UK .

+Comment: Computer Misuse Act review

The Department for Digital, Culture, Media and Sport's review of supply chain security comes on the heels of last week's [6]announcement of a review of the Computer Misuse Act (CMA). A formal document has now been published on GOV.UK.

While the review might have been initially welcomed, it is wise to look at it cautiously. The Society for Computers and Law summarised the purpose of the exercise as being "to identify whether there is activity causing harm in the area covered by the CMA that is not adequately covered by the offences. This includes whether law enforcement agencies have the necessary powers to investigate and take action against those attacking computer systems."

[7]

Put another way, the consultation's main target is creating new criminal offences and expanding the CMA's remit; while there's a token nod in there to protecting researchers from the threat of prosecution for legitimate infosec activities, the bulk of the call is aimed at creating new crimes.

The consultation document itself says the Home Office, owner of the CMA, is looking at "whether the legislation is fit for use following the technological advances since the CMA was introduced" and adds "we would welcome any other suggestions on how the response to cyber-dependent crime could be strengthened within the legislative context."

Individual infosec researchers El Reg has spoken to are cautious. Away from the corporate context, it seems the biggest priority for sole traders and small operators is providing concrete clarity in law about what is, or is not, a CMA crime.

[8]

It may be that individual perception of the CMA being wielded like a giant sword hanging over the necks of innocent infosec bods is wrong, but so far most public uses of the CMA in the courts has been [9]against things that looked and smelled very much like deliberate criminal offences .

Later this month, the government will be publishing new stats on the use of the CMA over the past couple of years and The Register will be reporting on these. ®

Get our [10]Tech Resources



[1] https://www.theregister.com/2018/12/20/two_alleged_chinese_hackers/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YKPkmdfdOseGuoj2V6gP4QAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKPkmdfdOseGuoj2V6gP4QAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKPkmdfdOseGuoj2V6gP4QAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.gov.uk/government/publications/call-for-views-on-supply-chain-cyber-security/call-for-views-on-cyber-security-in-supply-chains-and-managed-service-providers

[6] https://www.gov.uk/government/consultations/computer-misuse-act-1990-call-for-information

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKPkmdfdOseGuoj2V6gP4QAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKPkmdfdOseGuoj2V6gP4QAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/Tag/computer%20misuse%20act

[10] https://whitepapers.theregister.com/

Back doors?

Mishak

Any bets that back doors* "for your own good" / "to protect the children" will come up at some point?

* You know, just so the security services can make sure the provider is complying. Never, never to be used for interception.

Digital Defence Officer

2+2=5

I wonder if the legislation will propose the introduction of a Digital Defence Officer in the same way that GDPR legislation required the appointment of a Data Protection Officer?

The Digital Defence Officer ( or DiDO ) would be responsible for persuing the sophisticated international criminal gang 15-year old Welsh schoolboy responsible for the intrusions at your organisation.

Some internetworking cybersecurity providers be blissfully ignorant of .gov concerns, therefore ..

amanfromMars 1

Targeted at managed service providers and firms outsourcing their digital infrastructure services alike, ....

Until and unless there be an onus on governments to also inform and directly contact and engage with such managed cybersecurity services as may be of myriad particular and peculiar interests and/or concern to them, will any worries they may have in the field be likely to exist and persist. I suggest that a provision be allocated to mitigate and/or negate that certain risk.

And don't forget that there may be cases which require the payment of significant compensation for loss of earnings because of other parties concerns regarding ones service provision to A.N.Others.

Insider attacks

Eclectic Man

Currently the Met Police is investigating possibly unjustified access to details of the murder investigation of Sarah Everard:

https://www.bbc.co.uk/news/uk-england-london-57146622

"Dozens of officers and staff are being investigated for looking up details of the Sarah Everard case on the police computer system, the Met has said.

The 33-year-old marketing executive vanished as she walked home in Clapham, south London, on 3 March. Her body was found a week later in Kent woodland.

The Met's Directorate of Professional Standards is set to question staff who accessed files on the case.

Doing so "without a purpose" could be a criminal offence, the force said."

It will be interesting to see what comes of the consultation, and any attempts to change the current law.

Drop in any mailbox.