Showing posts with label Counterterrorism. Show all posts
Showing posts with label Counterterrorism. Show all posts

Wednesday, February 22, 2017

HR 940 Introduced – Securing Communications

Earlier this month Rep. Jackson-Lee (D,TX) introduced HR 940, the Securing Communications of Utilities from Terrorist Threats (SCOUTS) Act. The bill addresses the relationships between DHS and critical infrastructure in planning for, and responding to, terrorist attacks.

Policy


Section 2 of the bill sets some pretty broad policy guidelines for DHS. First it allows DHS to work with “critical infrastructure owners and operators and State, local, tribal, and territorial
entities” {§2(a)} to determine how DHS “can best serve the sector-specific cybersecurity needs to manage risk and strengthen the security and resilience of the Nation’s critical infrastructure against terrorist attacks”.

In fulfilling this policy DHS is specifically directed to “seek to reduce vulnerabilities, minimize consequences, identify and disrupt terrorism threats, and hasten response and recovery efforts related to impacted critical infrastructures” {§2(b)}. Additionally, the Secretary is allowed to “investigate the best means for engaging sector-specific agencies in participation in a voluntary cybersecurity information sharing, emergency support, and emerging threat awareness program” {§2(c)}.

Strategic Imperatives


Section 3 of the bill requires DHS to “implement an integration and analysis function for critical infrastructure that includes operational and strategic analysis on terrorism incidents, threats, and emerging risks” {§3(b)}. That ‘function’ will include data sharing with Fusion Centers to accomplish the following:

• Determine the appropriate role that Fusion Centers may fill in reporting data related to cybersecurity threat or incident information regarding individuals or service providers with access to or ongoing business relationships with critical infrastructure.
• Determine whether or how the National Protection and Programs Directorate and the National Cybersecurity and Communications Integration Center may work with Fusion Centers to report possible cybersecurity incidents.
• Determine a means for Fusion Centers to report availability of critical infrastructure to support local, State, Federal, tribal, and territorial law enforcement and the provision of basic public services after disruption events such as electric power brownouts and blackouts, accidents that disrupt service, and vandalism to or near facilities.
• Categorize and prioritize cybersecurity intake risk information based on relevance to critical infrastructure owners or operators in the area served by the Fusion Center.
• Establish an emerging threat hotline and secure online sector-specific cybersecurity incident reporting portal by which information may be disseminated through Fusion Centers.
• Develop, keep up to date, and make available a Federal agency directory of designated offices or individuals tasked with responding to, mitigating, or assisting in recovery from cybersecurity incidents involving critical infrastructure and make the directory available on a voluntary basis to critical infrastructure owners and operators.
• Establish a voluntary incident access portal with the ability to allow users to determine the means, methods, and level of incident reporting that is sector-specific and relevant to the recipient as defined and controlled by the recipient.
• Gather voluntary feedback from critical infrastructure owners and operators on the value, relevance, and timeliness of the information received, which shall include how they believe information and the means used to disseminate that information might be improved.
• Report to Congress every 2 years on the voluntary participation of critical infrastructure owners and operators in the programs established under this title.
• Implement a capability to collate, assess, and integrate vulnerability and consequence information with threat streams and hazard information
• Support the Department of Homeland Security’s ability to maintain and share, as a common Federal service, a near real-time situational awareness capability for critical infrastructure.

In evaluating vulnerability and consequence information the bill specifies the following cybersecurity related considerations {§3(b)(10)}:

• Evaluate the impact of cybersecurity and cyberphysical impacts of critical physical assets;
• Determine, through the voluntary cooperation of critical infrastructure owners and operators, the staffing and professional need for cybersecurity critical infrastructure protection with Fusion Centers;
• Determine, through coordination with the sector-specific agencies, the agency staffing needed to support cybersecurity critical infrastructure protection and report the findings to Congress;
• Anticipate interdependencies and cascading impacts related to cyber telecommunications failures;
• Recommend security and resilience measures for critical infrastructure prior to, during, and after a terrorism event or incident;
• Evaluate interdependencies and cascading impacts related to electric grid failures; and
• Make recommendations on preventing the collapse or serious degrading of the telecommunication capability in an area impacted by a terrorism event.

Moving Forward


Jackson-Lee is an influential member of the House Homeland Security Committee, the committee to which this bill was assigned for consideration. She certainly has the political influence to see this bill considered in committee.

Since the bill requires no new regulations or spending, there is little to attract the ire of the Republican leadership. It is very likely that if this bill is considered that it would attract bipartisan support. I suspect that if it would make it to the floor of the House for consideration, that it would be considered under the House suspension of the rules process. This means there would be limited debate, no floor amendments and it would require a super-majority for passage.

Commentary


The title of this bill is more misleading than most. The bill has only very limited influence on ‘securing communications of utilities’. It is a much more generalized counter-terrorism support of critical infrastructure bill that would probably have minimal impact on operations of DHS, fusion centers or critical infrastructure.

The term ‘cybersecurity’ is thrown into various places in the bill in a haphazard manner. We see it combined frequently with ‘critical infrastructure’ in a way that makes it unclear whether the bill is calling out a new, undefined, type of critical infrastructure or whether it is referring to cybersecurity for each of the current critical infrastructure categories.

The closest the bill comes to defining its use of cybersecurity is the definition of the term ‘security’. That is defined as “reducing the risk to critical infrastructure by physical means or defense cyber measures to intrusions, attacks, or the effects of terrorist intrusions or attacks” {§4(4)}. This is about as useless a definition as I have seen in proposed legislation.


I suspect that this bill will make it to the President’s desk as a feel-good measure for congress critters to be able to claim that they have done something about counterterrorism and cybersecurity. At least it will not cost anything; except perhaps the preemption of attempts at actually doing something.

Friday, September 20, 2013

Bills Introduced – 9-19-13

There were 34 bills introduced in the House and Senate yesterday, but only two might be of specific interest to the readers of this blog, but it is hard to tell for sure due to the relatively vague title given to the two bills.

HR 3143 : To deter terrorism, provide justice for victims, and for other purposes.
Sponsor: Rep King, Peter T. (R,NY)

S 1535 : A bill to deter terrorism, provide justice for victims, and for other purposes.
Sponsor: Sen Schumer, Charles E. (D,NY)


I would assume that these are companion bills which should make them very interesting due to the political differences between the two sponsers.

Monday, June 10, 2013

Congressional Hearings – Week of 6-9-13

The summer recess gets a week closer and more attention gets turned to passing money bills. Both the Defense Authorization and Appropriations bills will be the topic of hearings this week. There will also be a counterterrorism hearing, a discussion about DHS communications with the public and a high level cybersecurity hearing.

Defense Department Money

As I mentioned earlier today the House Rules Committee will be holding two hearings on HR 1960. Tuesday there will be a rules hearing and Wednesday there will be the second hearing to consider what amendments will make it to the floor.

Also on Wednesday the House Appropriations Committee will be holding a markup of the FY 2014 DOD spending bill. There are currently no specific cybersecurity provisions in the bill, but we may see some added to the bill or the accompanying committee report.

Counterterrorism

The Subcommittee on Counterterrorism and Intelligence of the House Homeland Security Committee will be holding a hearing on Wednesday to look at "Protecting the Homeland Against Mumbai-Style Attacks and the Threat from Lashkar-e-Taiba”. The witness list includes:

• Dr. C. Christine Fair, Georgetown University;
• Mr. Joseph W. Pfeifer, New York City Fire Department
• Dr. Stephen Tankel, American University

DHS Communications

The Subcommittee on Oversight and Management Efficiency of the House Homeland Security Committee will be holding a hearing on Friday about “Why Can’t DHS Better Communicate with the American People?” The witness list includes:

• Mr. Robert Jensen, U.S. Department of Homeland Security
• Mr. Douglas Pinkham, Public Affairs Council

Cybersecurity

The Senate Appropriations Committee will be holding a public hearing (followed by a classified session) on Wednesday about “Cybersecurity: Preparing for and responding to the enduring threat”. The witness list includes:

• General Keith B. Alexander, U.S. Cyber Command and National Security Agency
• Rand Beers, Department of Homeland Security
• Patrick Gallagher, National Institute of Standards and Technology
• Richard McFeely, Federal Bureau of Investigation


There will certainly be questions asked about the development of the Cybersecurity Framework and its implementation.

Tuesday, May 14, 2013

Fuel Trucks and Terrorists


It has been a while since I looked at a simple chemical accident through the eyes of a potential terrorist plotter, but there was an interesting vehicle accident in Harrisburg, PA last week that pointed out how easy it would be for a terrorist organization (or even a serious lone wolf) to utilize something as ubiquitous as a fuel tanker as a terrorist weapon. The CumberLink.com web site has excellent coverage of the accident.

The Accident

The accident was routine enough. A diesel fuel tanker overturned on a freeway off-ramp, leaked and the fuel caught fire. The first part is common enough, the second not so much and the third relatively rare. The driver escaped with minor burns and no one else was hurt. But, the fire kept burning.

Think back to the 9/11 tower collapses in New York City. The actual attack was simple enough fly an airliner into a building. Presumably the passengers were killed instantly as were many people in the impacted areas of the buildings. But what captured the horrified imagination of the world was the subsequent collapse of the twin towers because the heat of the fire weakened the metal structure of the buildings.

The same type thing occurred here. The heat from the fire was hot enough to cause steam ‘explosions’ in the concrete and weaken steel beams to the point where engineers fear that the overpass could collapse under its own weight. The overpass is closed as are the freeway lanes underneath pending demolition.

Fortunately the accident happened at 6:10 a.m.; well before the morning traffic jam would have put thousands of people in harm’s way.

A Terrorist Attack

So, imagine a terrorist with a hijacked fuel tanker, in rush hour traffic in a major metropolitan area. Stop the truck with the trailer on a busy overpass and detonate an IED under the trailer, causing the trailer to rupture and the spilling fuel to catch fire. Not only would you have the infrastructure damage seen in Harrisburg, but multiple vehicle fires and explosions with the resulting chaos, death toll, and visible destruction that shows so well on the evening news.

That would be well within the skill set of a lone wolf, but it could be even worse with a terrorist cell. Multiple trucks used to isolate a section of elevated freeway packed with rush hour traffic. Hundreds of people trapped between two fireballs and subsequent explosions as car fuel tanks rupture and add to the destruction, chaos and panic; thousands of YouTube videos replaying the scene.

Response or Prevention

We live in a dangerous world and it could get worse. We have been fortunate that terrorists have not seriously targeted this country. We are vulnerable at every turn and just because the attacks have not yet happened does not mean that they cannot. We are not going to be able to prevent all (or even most) determined attacks so we must begin to consider how we are going to respond to them.

Friday, March 19, 2010

Counterterrorism Info to Private Sector

There is an interesting article over on FCW.com (Federal Computer Week web site) about a new program being planned by DHS to share classified anti-terrorism information with private industry (thanks to DHS CERT Control Systems web page for the link). The Cybersecurity Partners Local Access Program (CPLAP) will provide security clearances for select cybersecurity professionals in industry so that they can be informed about cybersecurity threat information. The distribution of information would be through local fusion centers that are already set up to provide such classified information to local law enforcement personnel. The CPLAP would also, according to the article, “allow industry officials to build relationships with their local fusion centers”. The cybersecurity officials would be from a variety of critical infrastructure sectors, presumably including the Chemical Sector. ChemPLAP Needed for CFATS I have been advocating for a while now that DHS should establish this type of information sharing as part of the CFATS program. I don’t know that DHS (or any other part of the intelligence community) has any particular intelligence related specifically to chemical facility security, but the time to establish this type of program is actually before actionable intelligence becomes available. The Infrastructure Security Compliance Division (ISCD) really does need to get started on establishing a ChemPLAP (Chemical Partners Local Access Program) for the CFATS community. With the inevitable funding and time constraints involved, they should probably concentrate first on Tier 1 facilities. Expansion to the other Tiers would proceed after the bugs were worked out of the program. InfoSec Problems The biggest obstacle to this type of information security (InfoSec) program is getting the appropriate security clearances for the civilians involved in the program. Having dealt with the security clearance program in the Army (and running it at the Company and Battalion level), I know how difficult it is to keep up with the bureaucratic requirements of the process. Throw in the background check requirements (though these are not too extensive for Secret level clearances) and you have a time consuming process on both ends of the system. There are other potential problems in establishing this type of program. Participants need some training about handling and disseminating classified information. Secure communications and storage need to be addressed. Proper classified document destruction procedures need to be established and followed. Finally there needs to be an audit process established to ensure that classified information is actually being protected in accordance with the proper laws and regulations. The article says that the industry professionals will have to go to their local fusion center to get the information. Presumably this is because of the need for secure communications links that are already available at these locations. If there is a prohibition against taking classified documents out of these centers, then many of the previously mentioned problems will be greatly reduced. Open Source Intelligence Of course, most of the InfoSec problems can be avoided if DHS were to establish an active open-source intelligence collection, processing and reporting program. Now, just because the information comes from open sources, doesn’t mean that the resulting intelligence products will be uncontrolled products. The process of analyzing and reporting makes the resulting information sensitive at the very least. Fortunately ISCD already has a methodology for handling and disseminating sensitive, but unclassified material. The Chemical Vulnerability Information (CVI) program is already in place at all CFATS covered facilities. This program should be adequate to protect intelligence products from open source information. The Chemical Security Assessment Tool (CSAT) could be adapted for the dissemination of CVI protected intelligence reports, with each facility designating one or more Intelligence Officers for access to an Intelligence Tool. I am glad to see that DHS is starting the move to making classified counterterrorism information available to industry professionals. Limiting that information sharing to the cybersecurity community is less helpful. Every sector needs this type of capability, but the CFATS community is probably the best organized to implement and successfully use such a program.

Tuesday, September 8, 2009

QHSR – Chemical Disasters

This last weekend I had a chance to look over the Disasters section of the Quadrennial Homeland Security Review (QHSR) Dialogue. I was surprised to find no mention of the potentially catastrophic disasters that could result from a toxic chemical release from any of a large number of chemical facilities. Such releases could be the result of industrial accidents, adverse weather events, or terrorist attacks. To be fair one of the objectives of the 2nd Goal in the Disasters section would probably include such an event. That objective reads:
“Prepare for Catastrophic Incidents: Recognize the unique characteristics of catastrophic disasters, the requirements those characteristics place on emergency management systems, and the gaps between requirements and capacity.”
Current Ideas There were two ideas that did touch concepts that would be required to support emergency response activities for such an incident. They were:
Educate Communities on Actions to be taken during Catastrophic Events” “Supporting locals, securing national infrastructure, and information stewardship
While neither of these ‘ideas’ specifically addresses chemical facilities, anyone in the chemical security community would do well to look at these two ideas. My New Idea As my readers can probably guess, I came up with and submitted an idea that specifically deals with emergency response planning for high-risk chemical facilities. I won’t go into details of it here as that is the whole point of the Dialogue; an on-site discussion. You can find it at: “Catastrophic Chemical Incidents”. My Other Ideas There was some additional discussion on my “Controlling Access to Chemical Agents at Water Treatment Plants” idea that I submitted earlier. I also had two interesting initial comments on my “Interdict Threats to Chemical Facilities” idea from the weekend. Look forward to more input from the readers of this Blog.
 
/* Use this with templates/template-twocol.html */