Thursday, February 16, 2023

Call for Trusted CI Framework Cohort Participation - Response due 24 March 2023

 

The Framework Cohort is a six month, group engagement aimed at facilitating adoption and implementation of the Trusted CI Framework among NSF Major Facilities, Mid-scales, and research cyberinfrastructure (CI) providers. During the engagement, members of the cohort will work closely with Trusted CI toward implementing the Trusted CI Framework at their facility, emerging with a validated assessment of their cybersecurity program and a strategic plan detailing their path to fully implement each Framework Must. Cohort members will participate in six monthly workshops (lasting three hours each) and spend no more than eight hours each month outside of the workshops on cohort assignments. The fourth cohort will meet from July 2023 through December 2023.

 Since January 2022, almost 70 percent of NSF’s Major Facilities (MFs) have completed a cohort engagement or are currently participating in a cohort. These MFs include ARF, GAGE, IceCube, LIGO, NEON, NOIRLab, NRAO, NSO, OOI, SAGE and USAP. Additionally, NSF’s Mid-scales FABRIC, Network for Advanced NMR (NAN) and Deep Soil Ecotron (DSE); and the Corporation for Educational Network Initiatives in California (CENIC) and Giant Magellan Telescope (GMTO) are cohort participants. 

NSF Major Facilities and Mid-scales  providers wishing to participate in the next Framework cohort engagement should respond to the call by completing the form at the bottom of this page: https://www.trustedci.org/call-for-trusted-ci-framework-cohort  Your response is appreciated by Friday, March 24, 2023.

Wednesday, February 15, 2023

Advancing the Cybersecurity of NSF Major Facilities and National Research Cyberinfrastructure: Trusted CI’s Framework Cohort Achievements in 2022


Trusted CI’s second Framework Cohort, “Bravo”, successfully completed the six-month program of training and workshop engagement focused on learning and applying the Trusted CI Framework. Cohort members entered the engagement with a commitment to adopting the Framework at their sites. They then worked closely with Trusted CI to gather site information and create validated self-assessments of their facility’s cybersecurity programs based on the Framework. In addition, each site emerged with a draft Cybersecurity Program Strategic Plan (CPSP) identifying priorities and directions for further refining their cybersecurity programs. Bravo cohort included the following NSF Major Facilities (MFs) and research cyberinfrastructure providers:

The foundation of the cohort program is the Trusted CI Framework. The Framework was created as a minimum standard for cybersecurity programs. In contrast to cybersecurity guidance focused narrowly on cybersecurity controls, the Trusted CI Framework provides a more holistic and mission-focused standard for managing cybersecurity. For these organizations, the cohort was their first formal training in the Trusted CI Framework “Pillars” and “Musts” and how to apply these fundamental principles to assess their cybersecurity programs.

Concurrent with leading Bravo, Trusted CI continued engagement with the inaugural “Alpha” cohort through the end of 2022. Alpha cohort followed up on the success of the first half of the year by focusing on implementation challenges each cohort member was currently facing. Each of the monthly workshops was led by a different cohort member, with the workshop focused on addressing a specific cybersecurity challenge that the facility was facing. The Trusted CI Framework team is exploring ideas to continue the productive engagement with the cohort alumni.

In January 2023 Trusted CI began a third Framework cohort engagement (“Charlie”). Charlie cohort includes the following organizations:

Trusted CI is excited to be working with these new sites to advance their understanding and implementation of cybersecurity programs and best practices!

For more information, please contact us at info@trustedci.org.


Thursday, February 9, 2023

Trusted CI Webinar: Using the Trusted CI Framework to Create the CFDE Cybersecurity Program, Feb 27th @11am EST

Rick Wagner is presenting the talk, Using the Trusted CI Framework to Create the CFDE Cybersecurity Program, February 27th at 11am (Eastern).

Please register here.

The NIH Common Fund Data Ecosystem (CFDE) aims to enable the broad use of Common Fund (CF) data sets to accelerate discovery. CF programs generate a wide range of diverse and valuable data sets designed to be used by the research community. However, these data sets reside in different locations, and it is challenging or even impossible to work with multiple data sets in an accessible and user-friendly way. To help remedy this problem, the CFDE has created an online discovery portal that helps make CF data sets FAIR (Findable, Accessible, Interoperable, and Reusable) and enables researchers to search across CF data sets to ask scientific and clinical questions from a single access point. The CFDE Coordinating Center oversees CFDE activities and works closely with participating data coordinating centers from other CF programs on an initial subset of data sets, with plans to expand to additional CF data sets. As the security officer for the CFDE Coordinating Center, Rick used the Trusted CI Framework to focus cybersecurity efforts on protecting the trust amongst the CFDE participants. This mission-driven approach significantly clarified the CFDE's cybersecurity planning.

Speaker Bio:

Rick Wagner is a Principal Research Systems Integration Engineer at UCSD. Rick began his career using cyberinfrastructure as a tool for research in astrophysics, working on problems in cosmology and supersonic turbulence. His research was largely done on campus, NSF, and DOE computing resources, the same kinds of systems he later managed for SDSC. Rick took a break from UCSD to work for Globus at the University of Chicago, helping researchers with data management solutions. Now Rick is part of the Research IT team, helping to design solution for projects that cut across the campus and beyond it. He is also trying to smooth the boundary between cybersecurity and research, and was a 2021 Trusted CI Fellow.

---

Join Trusted CI's announcements mailing list for information about upcoming events. To submit topics or requests to present, see our call for presentations. Archived presentations are available on our site under "Past Events."

Friday, February 3, 2023

Registration Open for 3rd HPC Security Workshop at NIST NCCoE

Trusted CI is participating in the 3rd HPC Security Workshop, hosted by NIST’s National Cybersecurity Center of Excellence (NCCoE). The goal of the workshop is to gather community feedback, share the work of the HPC security working group, and to plan future tasks.

The in-person workshop will be held Wednesday through Thursday, March 15th - 16th in Rockville, MD. Registration is currently open.

The workshop will begin Wednesday morning with a keynote from NSF Program Officer Rob Beverly. Next, members of NCSA, PSC, and NCAR will present on their experiences as HPC operators. Later in the afternoon Trusted CI Director, Jim Basney will be presenting with colleagues on cybersecurity framework development, implementation, and assessment.

On Thursday, Erik Deumens, member of Trusted CI partner Regulated Research Community of Practice (RRCoP), will be participating in a presentation on HPC security research. Later, Trusted CI Deputy Director Sean Peisert will present the final keynote on secure data sharing in HPC environments.

The full agenda is available on NIST’s website.

Join Trusted CI's announcements mailing list for information about upcoming events.

Wednesday, January 25, 2023

Announcing the 2023 Trusted CI Annual Challenge: Building Security Into NSF Major Facilities By Design

The Trusted CI Annual Challenge is a year-long project focusing on a cybersecurity topic of importance for scientific computing environments.  In its first year, the Trusted CI Annual Challenge focused on improving trustworthy data for open science.  In its second year, the Annual Challenge focused on software assurance in scientific computing.  In its third year, 2022, the Annual Challenge focused on the security of operational technology in science.  

The 2022 Annual Challenge on the Security of Operational Technology in NSF Scientific Research reinforced the notion that NSF Major Facilities, once constructed, can deploy operational technology that can have an operational lifetime of 15-30 years.  However, there are typically no cybersecurity requirements during acquisition and design.  In the 2023 Annual Challenge, Trusted CI staff will engage with NSF Major Facilities undergoing construction or refreshes in a hands-on way to build security into those Facilities from the outset.  Trusted CI will directly support the planning for facility refreshes and construction with respect to operational technology and will particularly focus on the academic maritime domain, including supporting the acceptance testing of the NSF-funded Research Class Research Vessels (RCRVs) at Oregon State University, supporting the U.S. Antarctic Program (USAP)’s design of the Antarctic Research Vessel (ARV), and Scripps Institution of Oceanography’s design of the California Coastal Research Vessel (CCRV).

This year’s Annual Challenge is supported by a stellar team of Trusted CI staff, including Andrew Adams (Pittsburgh Supercomputing Center), Daniel Gunter (Berkeley Lab), Ryan Kiser (Indiana University), Mark Krenz (Indiana University), Michael Simpson (Indiana University), John Zage (University of Illinois, Urbana-Champaign), and Sean Peisert (Berkeley Lab; 2023 Annual Challenge Project Lead).

Friday, January 13, 2023

Cyberinfrastructure Vulnerabilities 2022 Annual Report

The Cyberinfrastructure Vulnerabilities team provides concise announcements on critical vulnerabilities that affect science cyberinfrastructure (CI) of research and education centers, including those threats which may impact scientific instruments. This service is freely available by subscribing to Trusted CI's mailing list (see below).

We monitor a number of sources for vulnerabilities, then determine which ones are of critical interest to the CI community. While there are many cybersecurity issues reported in the news, we strive to alert on issues that affect the CI community in particular. These issues are identified using the following criteria:

  • the affected technology's or software's pervasiveness in the CI community
  • the technology's or software's importance to the CI community
  • the type and severity of a potential threat, e.g., remote code execution (RCE)
  • the threat's ability to be triggered remotely
  • the threat's ability to affect critical core functions
  • the availability of mitigations

For issues that warrant alerts to the Trusted CI mailing list, we also provide guidance on how operators and developers can reduce risks and mitigate threats. We coordinate with ACCESS, Open Science Grid (OSG), the NSF supercomputing centers, and the ResearchSOC on drafting and distributing alerts to minimize duplication of effort and maximize benefit from community expertise. Sources we monitor for possible threats to CI include the following:

In 2022 the Cyberinfrastructure Vulnerabilities team discussed 41 vulnerabilities and issued 29 alerts to 192 subscribers.

You can subscribe to Trusted CI's Cyberinfrastructure Vulnerability Alerts mailing list by sending email to cv-announce+subscribe@trustedci.org . This mailing list is public and its archives are available at https://groups.google.com/a/trustedci.org/g/cv-announce .

If you have information on a cyberinfrastructure vulnerability, let us know by sending email to alerts@trustedci.org .

Monday, January 9, 2023

Trusted CI Webinar: Improving the Security of Open-Source Software Infrastructure, January 23rd @11am EST

Gedare Bloom is presenting the talk, Improving the Security of Open-Source Software Infrastructure, January 23rd at 11am (Eastern).

Please register here.

Remote monitoring and control of industrial control systems are protected using firewalls and user passwords. Cyberattacks that get past firewalls have unfettered access to command industrial control systems with potential to harm digital assets, environmental resources, and humans in proximity to the compromised system. In this talk, I will discuss our approach to prevent and mitigate such harms in scientific industrial control systems by enhancing the security of open-source cyberinfrastructure: the open-source Real-Time Executive for Multiprocessor Systems (RTEMS) real-time operating system and the Experimental Physics and Industrial Control System (EPICS) software and networks. The RTEMS and EPICS software projects are widely used cyberinfrastructure for controlling scientific instruments. This talk will discuss security problems that we have explored with these communities, and examine the salient challenges and opportunities presented by working with open-source communities on their cybersecurity needs.

Speaker Bio:

Gedare Bloom received his Ph.D. in computer science from The George Washington University in 2013. He joined the University of Colorado Colorado Springs as an Assistant Professor of Computer Science in 2019 and Associate Professor in 2022. He was an Assistant Professor of Computer Science at Howard University from 2015-2019. His research expertise is computer system security with emphasis on real-time embedded systems. He has published over sixty peer reviewed articles, serves as a program committee member and technical referee for flagship conferences and journals, and is an associate editor for the IEEE Transactions on Vehicular Technology.

Since 2011 Dr. Bloom has been a maintainer for the RTEMS open-source hard real-time operating system, which is used in robotics frameworks, unmanned vehicles, satellites and space probes, automotive, defense, building automation, medical devices, industrial controllers, and more. Some of his key contributions to RTEMS include the first 64-bit architectural port of RTEMS, design and implementation of a modern thread scheduling infrastructure, support for running RTEMS as a paravirtualized guest for avionics hypervisors, and implementation of POSIX services required to be compliant with the FACE avionics standard. Additionally, he mentors and guides students around the world through learning about and developing with RTEMS. He co-authored the textbook “Real-Time Systems Development with RTEMS and Multicore Processors” published by CRC Press in 2020.

---

Join Trusted CI's announcements mailing list for information about upcoming events. To submit topics or requests to present, see our call for presentations. Archived presentations are available on our site under "Past Events."