News: 1627535712

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

'Woefully insufficient': Biden administration's assessment of critical infrastructure infosec protection

(2021/07/29)


The Biden administration has issued a [1]National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems to address what it describes as a "woefully insufficient" security posture.

The Memorandum was accompanied by transcripts of remarks made by a "Senior administration official" who said the edicts are needed because "We have a patchwork of sector-specific statutes that have been adopted piecemeal, typically in response to discrete security threats in particular sectors that gained public attention.

"So, our current posture is woefully insufficient given the evolving threat we face today," the anonymous official added. "We really kicked the can down the road for a long time."

[2]

The Memo outlines plans to change that, with an "Industrial Control Systems Cybersecurity Initiative" that sees government and industry collaborate to define security baselines. The administration also wants security baselines to become consistent across all critical infrastructure sectors.

[3]Biden warns 'real shooting war' will be sparked by severe cyber attack

[4]Kaseya obtains REvil decryptor, starts sharing it with afflicted customers

[5]Wanted: State-backed bandits planning cyberattacks on US infrastructure. Reward: $10m

The Memo tasks the Secretary of the Department of Homeland Security with issuing preliminary goals for control systems across critical infrastructure sectors no later than September 22, 2021. Within a year, the administration expects "final cross-sector control system goals" will have been developed.

Despite the transcript repeatedly referring to a lack of statutes mandating certain security practices, and mentioning recent mandates introduced by the Transportation Security Administration to set security requirements for oil pipeline operators, the Memo doesn't discuss whether critical infrastructure operators need to be compelled to act.

[6]

Instead, the Memo pledges that US government risk management agencies will "work with critical infrastructure stakeholders and owners and operators to implement the principles and policy outlined in this memorandum." ®

Get our [7]Tech Resources



[1] https://www.whitehouse.gov/briefing-room/statements-releases/2021/07/28/national-security-memorandum-on-improving-cybersecurity-for-critical-infrastructure-control-systems/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQJ8NzmrCAp64oWaTBZW1wAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2021/07/28/biden_cyber_attack_real_war_prediction/

[4] https://www.theregister.com/2021/07/23/kaseya_obtains_revil_decryptor_starts/

[5] https://www.theregister.com/2021/07/16/us_10m_reward_cybercrime/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQJ8NzmrCAp64oWaTBZW1wAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://whitepapers.theregister.com/



"the Memo doesn't discuss whether critical infrastructure operators need to be compelled to act"

Mike 137

Actually, the briefing doesn't discuss very much at all. It's at best a kind of call to action. But we've had calls to action by the dozen over the last few decades, despite which the global cyber security position has got worse instead of improving. This seems to confirm that (as [1]was pointed out in 2016 in response to Obama's call to action) a new approach may be necessary - continuing to do what hasn't helped much for 40 years is unlikely to solve the problem.

[1] https://www.nist.gov/document/integratedinfosecrfiresponsepdf

Re: "the Memo doesn't discuss whether critical infrastructure operators need to be compelled to act"

Robert Grant

Right. "Woefully insufficient" I think is code for "lots of budget please".

It

Julz

Would seem to me that the normal capitalist race to the bottom on costs and the need to secure infrastructure are almost diametrically opposed. The only way to stop the cost cutting and improve the security would be if it were mandated by legal regulations. Tell me left pondians, are you up for bigger government and higher prices?

Microsoft Mandatory Survey (#9)

Customers who want to upgrade to Windows 98 Second Edition must now fill
out a Microsoft survey online before they can order the bugfix/upgrade.

Question 9: Which of the following do you prefer as a replacement for the
current Microsoft slogan?

A. "Over 20 Years of Innovation"
B. "Wintel Inside"
C. "Your Windows And Gates To The World"
D. "Because Anti-Trust Laws Are Obsolete"
E. "One Microsoft Way. It's Much More Than An Address!"
F. "This Motto Is Not Anti-Competitive. And Neither Is Microsoft."
G. "Fighting the Department of Injustice Since Day One"