Vimarsana.com

Transcripts For CSPAN Biden 20240705

• Source: archive.org
Source. This is about an hour. Thank you for coming out today. The first u. S. Regulations were drafted more than a century ago. The one i remember was a steamboat explosion that led to safety regulations that we see now. 50 years ago we entered a time of deregulation. We found is a unique balance that looks at the burden on companies, the needs of safety and security. Also, it avoids Technology Specifics as much as possible. That would be an ideal system moving ahead. We are going to talk about the role that agencies and sectors play, the approach that tsa has put forward, one of the Success Stories of this administration and any other. Well talk about what dhs is doing. This is an exciting time for cybersecurity. On a final note, when we look at regulations that began in the 1820s, there is a series of automobiles and telephones. Somewhere between 20 and 40 years it takes to develop adequate regulations for a new technology. The one difference is that unlike some previous efforts, we have foreign opponents and they are eager to exploit things that we leave unlocked. Our speakers today are going to discuss this. I will read the titles. A few a full bio is available on the website. It is great to be here. Jim always has great insights on cybersecurity. When we are thinking about new ideas, he is one of the first people we call. As much sounds like an explosion in the 1830s, the Colonial Pipeline hack was a transformative moment in the United States. Oil and gas, pipelines across the entire east coast were disrupted. Cars were lined up at gas stations. We were confronted with the idea that a criminal group could disrupt major Critical Infrastructure in the United States. When the president asked the question of what are our cyber safety for infrastructure, the companies that promote hazardous materials, promote clean water and health care, Critical Services that americans rely on, the answer was that almost in all cases, we did not have minimum required cybersecurity practices. The president gave direction to say, take this on, address this. I will till the end of the Colonial Pipeline story in a moment. That work led to a review to say what executive authorities does the government have . We know there has been attempts at legislation over the decade prior. How can we put in place practices that we have heard so many times . The first authorities identified where the department of Homeland Security and a combination of what had occurred in colonial regarding threats to pipelines and other Critical Infrastructure. Both rob and dave will talk about that. The way that was done list to first bring in those companies, and engage with them. They will talk more about that process. First time visibility that it has provided, not only regarding specific threats but across a given sector. We know there is a threat and now there is a common visibility about the level of resilience and if it is appropriate for the threats that we face. That model was then used sector by sector. I want to show you this chart. I want to call out on the National Security council who has been driving this work. And the agencies who participated. It captures the Biden Administration efforts to drive for those Critical Services we rely on as american citizens. I will say that the beginning of the administration, there were minimum arm and since sectors like the nuclear sector. Rob will talk a bit more about what was in place for the chemical sector. The first column you see ahead of you is the set of sectors that were largely unused authorities that could be used to require minimum resilience practices. The middle area are areas where required some level of rulemaking. Looking at existing regulations for safety and applying them to cybersecurity. If we need safety for the amount of chlorine applied to a weather system, given that these are digital systems. The final column shows you the sectors where there is no ability to impose minimum requirements that we rely on. You will see clearly some of the sectors there. I wanted to show you this chart to highlight that cross picture across all of Critical Infrastructure. We will deep dive on the First Program where major progress has been made. Making those movements as well as the epa and Real Progress that has been made in the health care sector. With that, we will turn it over to that deeper dive and put in practice how this played out in those minimum cyber requirements. We will distribute the charter after the event. I could see people trying to take pictures of it. We will make it easier for you. If you look at that chart and think, oh my, there is a lot of information. Next up is david. Thank you. It is great to be here and see everybody in the audience. I appreciate your comments and the reference to the regulations. It is really apropos to what we are seeing today. We had the advantage in tsa of having really strong law that gave us authorities to require transportation entities to address threats that we saw, sometimes on emergency basis, other times with limited notice. We did when we saw colonial, i saw this occurring a little over two years ago. We have to think about that and think about all that has happened in a short amount of time. It is not just tsa, it is many Government Agencies involved in this. What we did, colonial had the report. Where the first questions asked was how common a Ransomware Attack in the pipeline, how common . The first thing we did in the same month was be issued a directive requiring critical cyber. We defined what the incident was. Really important thing we did was we decided that this reporting would be something we want to have across critical sectors. Lets make that go into one place. All reports went into the agency by design. There was the responsibility to transmit to other agencies that had an interest, that would have been tsa and hazardous Safety Agencies in transportation. The department of Homeland Security had a keen interest in the department had an interest as well as the department of defense. Singler reporting was very important. As we have gone from the pipeline sector to the rail line and announcing in aviation. I think it has proven its work. Reporting goes in, everyone gets the same reports. Information can be different enough to cause some confusion. The second thing we did, we required that the companies assign a cyber point of contract that was available. We got the report, we had someone that we could call for Additional Information if that was necessary. Even if it was two or three people, it was helpful overall. In may and incident occurred and we issued the report. There were specific measures that we required companies in the pipeline sector to implement as quickly as possible. It is important to note that when we issued this directive, we intentionally did not issue to every pipeline in the country. We looked at is how Distant Department define the critical elements of a critical structure. Which owners and operators are more critical to that sector . It was those that we chose to cover by our security directive. We issued that to fewer than 100 pipeline countries. With very specific requirements. The reaction was, are you asking us to stop doing some of the things we are currently doing which we think are good . This will require significant investment and probably change some of our core business practices. We looked at that and had a lot of back and forth with industry representatives. We had a series of roundtable discussions with them and in the span of a year they did a lot of work on the requirements we had in place. This was from a Cyber Security directive. Within one years time, we did a direct pivot with the help of the industry and came up with performancebased regulation. Rather than saying to them to do specific activities, we outlined four key outcomes for them to achieve. Then we said, here are the outcomes. We want you to come back to us and give us an input pit give us an Implementation Plan to tell us what works for your business to achieve the outcomes we have required. Those were network segmentation. It was the lack of that because the major disruption that we saw in may of 2021. The first was, we need to ensure network segmentation. The second was to put measures in place to achieve Access Control of the critical cyber systems. The third was to do continuous detection and monitoring. Is one thing to put measures in place, but if you are not monitoring constantly, that is not as helpful. The last was, particularly in pipeline, there are literally thousands in a pipeline. Going across vast distances. Mainly they are controlled through electronics. Some are not. One of the things we set was, you need to give us a prioritized plan using the system established for patching systems. Give us that plan. The industry, i would say did an incredible job on this. We saw from an Agency Perspective has been an enormous help to us in designing a Regulatory Framework that i think works really well. Secondly, they invested a lot of money and time to be able to put measures in place and pivot to this performancebased model. The second thing i required was a Cyber Security assessment program. The stance for the proposition that we have the outcomes, we need to see objectively how you are achieving those outcomes. That will feed back into the revisions of your Implementation Plan. As you offer up measures and we approve of those, are we seeing the improvement of the achievement that we require to see it and if not, what do we need to change . This builds in a constant revision process into the entire system. The other thing i think is really important is that we also require them to do vulnerability assessments and have a response plan. It is one thing to be able to prevent, it is another thing to build resiliency. If the attack is even partially successful, you can be as resilient as possible is a critical operator in the system to be able to respond. We are going to do them issue our directive coming up this summer, is to add an additional requirement which we have already exercised with one of the companies. Tabletop exercises. We found learning from not to be incredible. It was important to understand how youre going to receive information, when a cyber attack occurs secondly, how do pivot from responding to the cyber incident to responding to what would be a crisis in many cases, depending on the extent of the intrusion and the level of interest from the republic. Att x found a significant value in that. Is one thing to have a plan, it is another to execute off the framework. It is unlikely that it will have the exact scenario in place the other thing that we have worked really hard on is, how do we bring all of the federal agencies in alignment to be able to make an incident in the response to the incident as effective as possible. When the Colonial Pipeline incident occurred, the ceo was fielding calls from all agencies. Often times asking the same question and sometimes in a slightly different way. We were able to do here was bring the federal agencies into the exercise so that the company could see that we have got all the agencies here. That for them i think was reassuring. That there would be some level of that. It would not be perfect but there is an effort to coordinate forward. In closing, we have done since then is gone from the pipeline sector to a rail line sector and use the exact same framework, which allows for the tailoring of the specific measures to the business model. Some are brandnew, they recognized from the threat that they need to do more. It also allows us to account for technology changes. We dont need to change the Regulatory Framework. That provides for a great deal of flexibility. I would like to exercise how important the partnerships were to our collective success. We would not be where we were today without the partnerships in the pipeline sector, the real sector. The rail line sector. To the extent that we can bring some standardized asian standardization is really important. It reinforces that we are really trying to partner very closely with them because we view this as, we are all in this together and we all need to Work Together to be able to increase our cybersecurity resiliency and improve on the protections that we have. Thank you. Thank you. That is interesting, we will come back to those points. What Companies Might expect moving forward. Rob come over to you. Rob, over to you. Thank you. People expect us to protect them when they cannot protect themselves. Food safety, national defense. American people are in a position to be in those lines of work themselves. The same goes for this modern area of digital threats. Whether it be very sophisticated in ransomware or, the most sophisticated. We saw with Colonial Pipeline and when you see gas lines in North Carolina and virginia, the American People asked, what can be done to protect me from that as well . That is why we have gone into action. Our work to protect the American People is a mix of voluntary programs and mandatory programs with companies. I would say the vast majority of our work is under voluntary. It has been growing in success and sophistication. Theres also the realization that there needs to be a standard that any Company Delivering essential services to people needs to adhere to. That is not a new concept. There has been regulations over the financial sector, the nuclear sector, the energy grid and others for a long time across administrations. What youre seeing from this administration is a thoughtful and to systemic approach. We are doing this to say, lets make your there is coverage where there ought to be and it is rational. So that the industry knows what they are stepping into. In that regard, we have put a lot of focus in insuring that in those cases where every other approach has failed and some regulatory approaches required, we are doing it in a surgical and tailored riskbased and thoughtful way together with industry. That means we are doing things like setting common frameworks from which regulations can springs. They are not mandatory, prescriptive controls saying you need to have that on your i. T. Or other, but rather are outcomebased. Once that companies should drive toward. They can pick the way and have flexibility within the context of their business and how to get there. That is a more efficient, less costly less burdensome way that can allow for experimentation from companies that can figure out what are the best kinds of expectations. We are also taking steps to make sure that only does entities that need to be regulated are regulated. That goes to daves point about selecting only the highest risk tears or have multitier systems where they have to meet higher thresholds and lower tiered or smaller may have smaller businesses. They dont have to undertake such a great burden. We are also looking at harmonization opportunities. It is really imperative upon us as we take the steps to make sure that we are doing it in a way that makes sense when you look across the different actions that we are taking. For example, Congress Last year passed landmark legislation that called to issue regulations to mandate Incident Reporting for very significant cyber incidents. That mandate from congress falls into a sea of other Incident Reporting mandates, from fake federal regulators, International Regulators that can be overwhelming for eight company that already has a lot going on in the 48 hours after falling victim to a cyber attack that it is incumbent upon us to make sure we are minimizing paperwork requirements. One thing that we are doing and we expect to report to congress in the next month or two is through the cyber Incident Reporting council, all of key federal agencies including federal regulators is, we are closing in on proposed model definitions, timing triggers, ways to structure a regime so that a Victim Company has to have the minimum amount of destruction as he gets to the information that the government needs to protect the nation, but not more. We are undertaking all of these mitigating approaches as we deliver the kinds of protections that the American People expect us to protect, when it comes to things like their drinking water, their power supply, their ability to transport themselves by air or rail or otherwise. That is our strategy. Great. You covered a lot of ground and that was hopeful. Rob hit at least three of my questions. Let me start with one that is a nice think take discussion. You said you select companies in the highest risk tears, how do you do that . How do determine who is highest risk . When we started doing this i said, i would pick the 10 biggest and forget everyone else. That did not fly. How did you do it . I will start. I will use the real sector as an example. To the example you gave, if you just look at the biggest freight railroads, you would not get all of the ones that are critically important. Sometimes the last mile are important to get something onto the freight system. As part of what we look like. What are the largest systems, what cargo do they typically carry, and are there any last mile operators that need to include . That is where a lot of the great work with the transportation and department of defense came into play. Were trying to get everybody that had an interest from the federal level to have this discussion to make sure we identified the right critical operators. The beauty of that is that it is a fluid list. If somebody becomes critical because of what they do take an air carrier, depending on what cargo they might be caring, they might fit into a critical category where they did not before. You do not have to rewrite everything they have done. It just covers the definition when you include them. There was one point that dave referenced in an interesting way. He mentioned trans,. Several individuals may have seen the products they came out last week. Across the national and fbi that talked about chinese targeting of Critical Infrastructure in the United States. Clearly, the u. S. Military uses the same rail and Aviation Systems to deploy troops and move material as you, i or Large Companies do. There is an overlay to this work that we call defense Critical Infrastructure in the United States that our Defense Department relies on to mobilize troops, move material that that Critical Infrastructure also makes our National Security more secure and resilient. That partnership has been key to this work. Nothing to add. I will go to the next. I was having lunch with a friend who is in the audience who said, in Cyber Response incidents, a lot of the work has to deal with state governments and regulations. Tell us how you deal with the states. Rob, i will pick on you first. In many instances, state regulations come into play because a company may find that in the course of a cyber incident, personal data has been compromised and every state has rules that if there is personal data, you have to tell those residents and tell the attorney general of that state, it is relatively rare that from their state authorities, they will get very involved in the actual incident response. They may have a Law Enforcement regulation in the attorney general office. It is really the federal authorities that can offer medial support to a victim entity to really help them understand what has happened to them and offer them tools and support to get back on their feet or engage in a Law Enforcement investigation into the perpetrators. From that perspective, from a National Protection perspective, the action is really at the federal level when it comes to ensuring the reliability and continue to cash contin tutti the reliability and continuity in the protection of protection will data, whether companies have engaged in what we call unfair trade practices and how they handled that personal data. There are some exceptions, state regulators that do come in more from that protection angle but i would say that is the exception, rather than the rule of practice. Thank you. David, your clients run across multiple state. They do. Multiple countries sometimes. I would say the state governance is for us and municipal governments. Many are owned by municipalities or by authorities that are by state organizations or by the states themselves. In addition, where the state comes in often is in setting rates like in the national gas industry. The owners and operators need to go to the states for the ability to change the rates and one of the things they have done is providing directives to those regulators so they can see that when a Company Comes to them based on an assessment, that they see that directive before hand and to know that it is a federal requirement. Maybe now would be a good time to start handing out cards for questions. If you want to add a question, go ahead. One of the tasks was to bring federal agencies into alignment. Im not quite sure what to ask. How do you do that, how is it going, any outliers . Traditionally, when the National Security council hosts we call our National Security deputies and principals meeting, those are our traditional agencies that you would think about. Department of defense, state, department of justice. Was different we think about Critical Infrastructure and defense of Critical Infrastructure is that the agencies who are really on the frontline are those sector let agencies like tsa, epa, hhs. As we have been working to achieve President Bidens calling to say, we need Relentless Improvement in cybersecurity, we need to improve digital infrastructure. That group has meant to bridge those communities. Briefing individuals who may not have gotten an intelligence briefing before. Learning about, what elements of a water system are most important to secure that water system . Actually improving cybersecurity on the ground where the rubber meets the road. How do we ensure that leadership is brought in . A big part is to say, what is common across . What is sector specific . Like the particular elements of risk that we want to secure because that is what adversaries will want to focus on . In many cases, if you look at an industry sector, there are comanagement agencies. The faa is a sector of Risk Management. Same with pipelines. When you think about it, for me it is really embellished by my coast guard career. Safety and security in the same agency. We saw was the things that we did for a safety purpose oftentimes had a security impact. Orca it could have an intentional impact. What we have done is we have worked really closely with our Risk Management agencies to the point where we developed our frameWork Together. We socked their input in advance. When we did the industry roundtables, we did them together because we wanted the industry to see that we were working together and we were both willing to learn from this. I dont operate a pipeline or rail system. But i really want to learn from the operators and how they would do things in a smart way but still achieve the minimum baseline that we want to achieve. Putting the agencies together is critical and important. I think that has been one of our real strengths. We have not had a situation where something we have done has been a surprise to our agencies, we do everything very close and in close consort with dod and the department of energy so that none of us are surprised. When we decide to issue regulation four, the industry knows we have recorded that ourselves. There may be some issues that come up and we would be happy to look at the issues that may cross. The other thing is that internationally it is very important as well. If you look at the civil organization, they are reps there. Coordinating domestically reflects the work we do internationally. In the top in the context of the incident, i think there is a brass tacks need for the federal government to half inch agencies have its agencies talk on the backend so that we are not burdening a Victim Company with multiple knocks on the door asking questions. That is our duty. I think we have gotten better as a federal government in that regard. What Victim Companies often dont see is that behind the scene, they are exchanging notes so there is a common factual picture. Without all those parties having to go and get the information in a burdensome way. I think you will see when the reporting Council Issues its report to congress, we are going to reaffirm the commitment to having that kind of federal coordination. Particularly in broad and systemic regulations and also the heat of an incidence level as well. I will build on that. The heat of the incident is really important. That is where you will gain and hopefully hold public confidence. We are not the owner and operator of the system but we are the federal government which is held accountable to make sure there are safe regulations. That first News Conference needs to be with the most senior person and a senior official that can speak to the other agencies so there is not a question asked that someone answers in a slightly different way or disagrees with because that means that everybody goes oh no, we do not have the coronation, we need to get through this incident. We are trying to build resiliency here. The key to resilience is, when you get impacted, how quickly can you get act on your feet . That cannot happen if it cannot be done right away. One question i have asked previous administrations is, it is in the third column on the chart. What authorities do you need, what authorities do you want . There are some authorities, i think the first column is impressive with how many there are, but where do you see the shortfalls . This is a congressional question to some extent. Where do you need more authority, where would you Like Congress to take action . I dont know who wants to go first. One area we are really fork us we are really focused is implementing the Authority Congress gave us. The new mandate for Critical Infrastructure to report specific cyber incidents. We are engaged in a major lawmaking process to meet that mandate and we also are working from a resourcing perspective to make sure we have the resources needed to bring that mandate into fruition. I would echo that last comment. It is the resourcing something that we need . Budgets are constrained, it is a challenging situation. With respect to the authorities, i would say and we are on the lefthand column. We are in very good shape. I would offer the authorities that we have as a good model. I hold my personal responsibility to exercise those authorities when needed and appropriately, with the fruit with the full cognizance. That is how you keep the great authorities that you have. I think we are in really good shape from a priorities perspective. I would say a twopart answer. I think the major move is to use every authority that we have. Whether under emergency authorities, interpreting safety authorities, to ensure that we can make Critical Services as secure and resilient as possible or the American People. One other effort President Biden has addressed on is using our procurements to lift all of those saying that the u. S. Government will only by secure software that meets a given standard. Also using Government Procurement to drive more. Another is tech providers. We are watching kids and students data being used. Looking at tsas model in looking at the sectors. What sectors to be filled that voluntary efforts are inadequate . For those we will approach congress at the same time and discuss those authorities. We have some great questions. Some of them on espionage. We might save them for the end. There are a couple, several good ones on what the topic of discussion is. How do think about regulating across sectors like i. T. . How do you regulate cross sectors . Particularly in Critical Infrastructure. Really harmonizing with the requirements are. We find that in many sectors, we have those authorities. The data shared, you will achieve that objective. We have learned so much in lamenting in these first two years. What additional remains . I would echo that. Framework is an important word. We are not telling you specifically how to do it, were giving you a framework. We have tried to link things that we do to framework and cybersecurity. It cuts across sectors. The key area of interest is to understand where those cross sector risks are. I am cognizant of risks in sectors that my sector relies on their own perspectives and response ability. Responsibility. There are other sectors that we look to to address risk in the system were might not otherwise be obvious how to do it. For example, the committee on foreign investment, which covers deals and transactions that involve foreign capital, it is now routine to impose cybersecurity requirements to allow the deal to proceed. That does not cover the whole landscape but is away for risk concern context. We have the power of the purse. Many of the major global i. T. Providers are significant vendors to the u. S. Government. We spend a lot of money on technology and we are a meaningful customer that they want to cater to. If they want to meet our business, they have to meet a whole host of cybersecurity requirements that they would not have the authority to impose on them by regulation. We are looking at the tools and levers that we have. I do like to identify outcomes and let them identify how to do it. It is much easier for everyone. This question kinda falls on what we have been talking about. As tsa has developed its framework, how will it address or incorporate third already thirdparty . Incorporate third party . Some dont have the resources to develop the protections that we need. You would look at the Larger Service providers and infrastructure operators to put the requirements at their level. The other thing we are doing provides grant funding. We are putting important into those grant applications based on, if you want the grant, here is the framework they need. Taylor it to what the debt might be. That is a key part of the National Strategy as well. Great. Cybersecurity is typical overall. Vendor cybersecurity is one of the most typical of the landscape. To start understanding first second or third tier down the line is difficult, to say the medium. A lot of leaving regimes now are thirdparty security components. Dod, the pentagon has rolled the maturity schema and there are plenty others as well. There are also technologies and the commercial sector is coming up with Solutions Like thirdparty risk ratings. Others that are happening helping Companies Come to grips with it. We know it is a hard task. Most federal regulators endeavor to be reasonable when they work with their regulated entities and understand the challenges that there are. There are many things that can be done. We are Encouraging Companies to do those things. May be, building on that. One of the highlights of the National Security strategy is its emphasis on cloud. Some people are recommending that we treat cloud as an infrastructure as well. I would not be surprised if that appears in some drafts of the nda. What are some approaches to these outside providers, particularly to small and medium it will be dependent . What is the burdened or expectation for them . I would say three things quickly. One is for small and medium , they have trouble recruiting people. It should be the expectation that if you are buying cloud, it comes from the baseline. I get in the car, the airbags are there. It goes that way. The traditional challenge is, who will be responsible for it. Theres one entity providing those services. Our excitations should be, when you are buying cloud, you are buying secure. The final pieces that as procurement we have issued, here is how it is configured. That is the model we are thinking through at this moment. This is a fun one. It is one i think about. How are you going to do with the independent agencies. When you think about the agencies, particularly infrastructure. They are independent. How does that fit into this general approach . I think the answer is, we bring to them we bring them to the table as appropriate. There are meetings where independent agencies are present. Not because anyone is directing them what to do, but because they should be part of that conversation as part of the council. They want to know what we are doing and we want to know what they are doing. That is a good thing. They make those independent decisions. Theres also a form hosted by the fcc called the independent regulators forum. Most regulators in the federal space come together to discuss these kinds of issues, including harmonization issues. Are the right people talking to each other . Absolutely. And, they should be. May be relating to that is the question i know we are running out of time how will digital manufacturing be . As we look at software, it is increasingly in the center of the economy. It is not a traditional category. There is risk, if you know what the letters sdk down for. What are we going to do about it . What is the approach going to be to digital manufacturing . I can kick that off. The first part, the Critical Software build requirements, part of the executive order two years ago. This is the way Software Needs to be built, managed and deployed. I would note that the speed at which the cybersecurity industry identifies that shows that we have made progress. One effort is the labeling program. To have a government standard and label applied to companies that me the particular standards. More on that is coming. It is important and has a lot of corners to it. We also saw in the log, vulnerability that came out a year and a half ago that there are unique security vulnerabilities in opensource Source Software as well. The cyber safety review board did a deep dive on that issue. Whether it be the very big tech consumers, pitching in resources and evaluating for opensource libraries to recommendations to the community to improve their focus on secure coding in terms of programs. A lot of really good schools, you can get a comp to agree without ever having taken a secure coding component course. That is not good. That needs to change. We need to not just develop more coders, we need to develop coders that know how to code securely. The cyber review board recommended that there is every component Curriculum Program or degree. There are a number of things. The programs are going to increase transparency into the components so that consumers can understand what is in there. I think with artificial intelligence, there are a lot of benefits to run ai with potential vulnerabilities or suggestions or otherwise. One quick, last question. The term keeps changing. I might go to first