Cybersecurity Update – How Are You Impacted?

by Mitchell Silberberg & Knupp LLP
Contact

On February 12, 2014, the Obama Administration released the long-awaited Cybersecurity Framework: “a voluntary how-to guide for organizations in the critical infrastructure community to enhance their cybersecurity” (the “Framework”). A year earlier, Executive Order 13636, regarding Improving Critical Infrastructure Cybersecurity, was issued. See Executive Order 13636. In that Executive Order, the Administration established the need for a governmental partnership with the owners and operators of critical infrastructure to collaboratively develop and implement risk-based standards. Although “voluntary” in nature, it is easily foreseeable that the Framework will become industry standard, raising the specter of how companies, even those who do not deal with government contracting or critical infrastructure, will be expected to meet those standards.

Whether you are securing your supply chain or are, for example, a retailer worried about being hacked, the Framework proposes a unified process by which to evaluate your cybersecurity program: 1) Describe your current cybersecurity posture; 2) Describe your target state for cybersecurity; 3) Identify and prioritize opportunities for improvement within the context of a continuous and repeatable process; 4) Assess progress toward your target state; and 5) Communicate among internal and external stakeholders about cybersecurity risk. If you have an intrusion, it seems reasonable that authorities (and your insurance company) will be checking to see how you have implemented this process, even if you are not a government contractor.

The 2013 Executive Order was directed at critical infrastructure and called for the Attorney General, the Secretary of Homeland Security (Secretary), and the Director of National Intelligence (Director) to issue instructions to ensure the timely production of unclassified reports of cyber threats that identify specific targeted entities and to enhance information sharing through an expanded “Enhanced Cybersecurity Services” program.

The Framework was described as intended to “provide a prioritized, flexible, repeatable, performance-based, and cost-effective approach, including information security measures and controls, to help owners and operators of critical infrastructure identify, assess, and manage cyber risk” and “shall focus on identifying cross-sector security standards and guidelines applicable to critical infrastructure.” It was also to “identify areas for improvement” to be addressed through future collaboration with various parts of the private sector, including standards-developing organizations. To enable technical innovation and account for organizational differences, the Framework was expected to provide guidance that is “technology neutral” and enables “critical infrastructure sectors to benefit from a competitive market for products and services” that meet the “standards, methodologies, procedures, and processes” developed to address cyber risks. The Framework was to include guidance for measuring the performance of an entity in implementing it and was also to include methodologies to identify and mitigate its impacts and associated information security measures or controls on business confidentiality and to protect individual privacy and civil liberties.

The Secretary of Defense and the Administrator of General Services were to make recommendations to the President on the “feasibility, security benefits, and relative merits of incorporating security standards into acquisition planning and contract administration” and were also to deal with steps that could be taken to “harmonize and make consistent existing procurement requirements related to cybersecurity,” and this is the area where the private sector has the most interest. Once there are standards in place for government procurement purposes, the affected companies will be mandated to meet those standards and will require their business partners to meet those standards, and, shortly thereafter, it is easily foreseeable that most other companies, whether or not dealing in defense or other government contracting disciplines, will be expected to meet those same standards. For any company that does not, significant issues can be expected, including intrusions, along with class action and shareholder derivative lawsuits.

The Executive Order was far-reaching, but so is the Framework, which represents a year’s worth of collaboration between the government and the private sector gathering “thoughts on the kinds of standards, best practices, and guidelines that would meaningfully improve critical infrastructure cybersecurity.” At heart, the Framework is an attempt to set forth a common language with respect to five cybersecurity activity core functions and to provide a common set of tools for building and analyzing an organization’s activities and responses within each core function. To that end, the Framework is implemented on three levels: the Framework Core, the Framework Profile, and the Framework Implementation Tiers.

The Framework Core (Core) is a set of cybersecurity activities, desired outcomes, and references that are common across “critical infrastructure sectors.” The Core covers five concurrent and continuous functions — Identify, Protect, Detect, Respond, Recover — designed to provide a 100-foot view of the lifecycle of an organization’s management of cybersecurity risk. For each of these lifecycle functions, the Core then identifies underlying key categories, and subcategories, and matches them with exemplar references, such as existing standards, guidelines, and practices. For instance, under Detection, a key category is detection of anomalies and events. One of the subcategories is establishing and managing a baseline of network operations and expected data flows for users and systems. There are then several potential standards and guidelines listed to assist with that functionality, including COBIT 5 DSS03.01, ISA 62443-2-1:2009 4.4.3.3, and NIST SP 800-53 Rev. 4 AC-4, CA-3, CM-2, SI-4.

The second level of the Core is the Framework Implementation Tiers, which essentially provide a numerical representation of how advanced an organization’s risk-mitigation procedures are, given the threat environment, legal and regulatory requirements, business/mission objectives, and organizational constraints. The Tiers range from Partial (Tier 1) to Adaptive (Tier 4). Because an individual organization’s cybersecurity risk is taken into account, not every organization needs to be Tier 4, as doing so would not be cost effective, given a lower level of cybersecurity risk. The Framework notes that, “[w]hile organizations identified as Tier 1 (Partial) are encouraged to consider moving toward Tier 2 or greater, Tiers do not represent maturity levels. Progression to higher Tiers is encouraged when such a change would reduce cybersecurity risk and be cost effective.”

Finally, the third level of the Core, the Framework Profile (Profile), represents the outcomes the organization selected from the Framework Categories and Subcategories. A Profile enables the organization to establish a road map for reducing cybersecurity risk in a manner aligned with organizational and sector goals, considers legal/regulatory requirements and industry best practices, and reflects appropriate risk-management priorities. Armed with the profile, and target profiles, the Framework allows the organization to evaluate risk vulnerabilities and create a prioritized action plan to address those gaps.

The question for all companies now is how best to adapt to these new recommendations and do so in a cost-effective and meaningful manner.

For those interested, the final report can be found at here.


 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Mitchell Silberberg & Knupp LLP | Attorney Advertising

Written by:

Mitchell Silberberg & Knupp LLP
Contact
more
less

Mitchell Silberberg & Knupp LLP on:

Readers' Choice 2017
Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
Sign up using*

Already signed up? Log in here

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Privacy Policy (Updated: October 8, 2015):
hide

JD Supra provides users with access to its legal industry publishing services (the "Service") through its website (the "Website") as well as through other sources. Our policies with regard to data collection and use of personal information of users of the Service, regardless of the manner in which users access the Service, and visitors to the Website are set forth in this statement ("Policy"). By using the Service, you signify your acceptance of this Policy.

Information Collection and Use by JD Supra

JD Supra collects users' names, companies, titles, e-mail address and industry. JD Supra also tracks the pages that users visit, logs IP addresses and aggregates non-personally identifiable user data and browser type. This data is gathered using cookies and other technologies.

The information and data collected is used to authenticate users and to send notifications relating to the Service, including email alerts to which users have subscribed; to manage the Service and Website, to improve the Service and to customize the user's experience. This information is also provided to the authors of the content to give them insight into their readership and help them to improve their content, so that it is most useful for our users.

JD Supra does not sell, rent or otherwise provide your details to third parties, other than to the authors of the content on JD Supra.

If you prefer not to enable cookies, you may change your browser settings to disable cookies; however, please note that rejecting cookies while visiting the Website may result in certain parts of the Website not operating correctly or as efficiently as if cookies were allowed.

Email Choice/Opt-out

Users who opt in to receive emails may choose to no longer receive e-mail updates and newsletters by selecting the "opt-out of future email" option in the email they receive from JD Supra or in their JD Supra account management screen.

Security

JD Supra takes reasonable precautions to insure that user information is kept private. We restrict access to user information to those individuals who reasonably need access to perform their job functions, such as our third party email service, customer service personnel and technical staff. However, please note that no method of transmitting or storing data is completely secure and we cannot guarantee the security of user information. Unauthorized entry or use, hardware or software failure, and other factors may compromise the security of user information at any time.

If you have reason to believe that your interaction with us is no longer secure, you must immediately notify us of the problem by contacting us at info@jdsupra.com. In the unlikely event that we believe that the security of your user information in our possession or control may have been compromised, we may seek to notify you of that development and, if so, will endeavor to do so as promptly as practicable under the circumstances.

Sharing and Disclosure of Information JD Supra Collects

Except as otherwise described in this privacy statement, JD Supra will not disclose personal information to any third party unless we believe that disclosure is necessary to: (1) comply with applicable laws; (2) respond to governmental inquiries or requests; (3) comply with valid legal process; (4) protect the rights, privacy, safety or property of JD Supra, users of the Service, Website visitors or the public; (5) permit us to pursue available remedies or limit the damages that we may sustain; and (6) enforce our Terms & Conditions of Use.

In the event there is a change in the corporate structure of JD Supra such as, but not limited to, merger, consolidation, sale, liquidation or transfer of substantial assets, JD Supra may, in its sole discretion, transfer, sell or assign information collected on and through the Service to one or more affiliated or unaffiliated third parties.

Links to Other Websites

This Website and the Service may contain links to other websites. The operator of such other websites may collect information about you, including through cookies or other technologies. If you are using the Service through the Website and link to another site, you will leave the Website and this Policy will not apply to your use of and activity on those other sites. We encourage you to read the legal notices posted on those sites, including their privacy policies. We shall have no responsibility or liability for your visitation to, and the data collection and use practices of, such other sites. This Policy applies solely to the information collected in connection with your use of this Website and does not apply to any practices conducted offline or in connection with any other websites.

Changes in Our Privacy Policy

We reserve the right to change this Policy at any time. Please refer to the date at the top of this page to determine when this Policy was last revised. Any changes to our privacy policy will become effective upon posting of the revised policy on the Website. By continuing to use the Service or Website following such changes, you will be deemed to have agreed to such changes. If you do not agree with the terms of this Policy, as it may be amended from time to time, in whole or part, please do not continue using the Service or the Website.

Contacting JD Supra

If you have any questions about this privacy statement, the practices of this site, your dealings with this Web site, or if you would like to change any of the information you have provided to us, please contact us at: info@jdsupra.com.

- hide
*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.