Cyberscoop

Here’s how experts think CISA should tell agencies to protect OT


A coalition of cyber firms and critical infrastructure operators on Tuesday spelled out its views on the tasks that the Cybersecurity and Infrastructure Security Agency should assign federal agencies to protect operational technology systems after this summer’s attacks on water utilities.

The Operational Technology Cybersecurity Coalition said a CISA binding operational directive (BOD) for OT should specify who is responsible for protecting these systems at each agency,, draw on existing federal guidelines and set minimum cybersecurity practices.

The coalition said the BOD would address a need to act based on CISA’s lack of visibility into the spectrum of OT devices in federal agencies, a lack of consistent across-the-board OT security policies and the severity of the consequences that an attack on federal OT could produce.

Just last month, the Government Accountability Office published a report which concluded that most federal civilian executive branch agencies (FCEBs) haven’t enacted Office of Management and Budget requirements released in 2023 for networked Internet of Things and OT devices.

Putting forward recommendations for a CISA directive has two goals, said Michael Garcia, policy director of the coalition.

“One, it does make sure that the government is taking its own medicine,” said Garcia, who until recently worked at the agency. “You should practice what you preach. … Second, it sends a very strong signal to the private sector that, ‘This is what we think is important: As an OT partner, owner or operator or critical infrastructure owner or operator, [this is what] you should ask other providers to do.’”

There are 8,000 General Services Administration-owned and -leased properties, many of which would have OT involved in everything from power supply to heating, ventilation and air conditioning systems. Some of those OT systems might be “trivial,” Garcia acknowledged, but the coalition paper notes that CISA “does not currently have a holistic view of the assets managed by the FCEB and the potential risks, such as connected programmable logic controllers, to which the government may be exposed.”

With OT falling into a “government gray zone” between chief information officers and facilities managers, CISA should tell agencies to formally designate an officer in charge of cybersecurity for OT, the coalition recommends.

The directive should examine past OT guidelines the National Security Agency issued to see if they should apply to federal civilian agencies, and align any requirements in the hypothetical BOD with cybersecurity performance goals that CISA first issued in 2022, according to the coalition.

The coalition doesn’t assert that such a BOD would have headed off the attacks this summer on the water sector, and is focused on federal OT, something where CISA has done some work.

“To be fair, CISA has incorporated OT security requirements into prior directives (such as BODs 23-01, 23-02, and 26-04) alongside a host of technical guidance,” the paper reads. “But as AI reduces the technical barriers to sophisticated cyber operations, enabling adversaries to identify weaknesses, accelerate reconnaissance, and move laterally through poorly segmented operational environments with greater speed and scale, it is time for an encompassing BOD solely focused on OT security.”

CISA didn’t respond to a request for comment Monday in advance of the coalition publishing its paper.

But Garcia said that in discussions with CISA, “increasingly, I think they understand that there might be a need” for an OT BOD.

Written by Tim Starks

Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he’s covered cybersecurity since 2003. Email Tim here: tim.starks@cyberscoop.com.



Source link