Showing posts with label DHS SandT. Show all posts
Showing posts with label DHS SandT. Show all posts

Saturday, September 19, 2015

Bills Introduced – 09-18-15

Yesterday only the House was in session so there were only 31 bills introduced. Of those only two may be of specific interest to readers of this blog:

HR 3578 To amend the Homeland Security Act of 2002 to strengthen and make improvements to the Directorate of Science and Technology of the Department of Homeland Security, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

H Con Res 78 Expressing the sense of Congress that the President in consultation with the Department of the Treasury should apply economic sanctions against Chinese businesses and state-owned enterprises that can be linked to cyberattacks against United States entities. Rep. Wilson, Joe [R-SC-2] 

Okay, so I stretched the ‘may be of specific interest’ standards a bit today. Neither of these bills has a high potential for fitting in to my normal blog postings, but they may be covered any way because both could have significant impact on cybersecurity operations even though neither will specifically address control system security.

HR 3578 may increase the importance of cybersecurity in the Directorate’s focus on developing and supporting new homeland security related technology.


This resolution is interesting because instead of focusing on the Chinese government (as has been the target of many Republican congresscritters) it instead asks the President to specifically respond at Chinese businesses. Providing this, let’s face it, Republican backing for the President’s taking action under his recent cyber retaliation EO just might be the final push the President needs to take such action.

Monday, June 23, 2014

OMB Approves First Responder Communities of Practice ICR

Friday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had given a short term approval (1 year) to the DSH S&T’s information collection request renewal for their First Responder Communities of Practice (FRCoP) program. This covers the registration information collected by S&T for that program.

This is not in response to the 60-day ICR notice that I wrote about last week. Apparently S&T knew about the short term renewal that was going to be published and was trying to get an early start on that renewal.

This renewal contains the same ‘Terms of Clearance’ notice as did the previous approval from March of last year:

“If DHS submits a renewal of this collection, it should include a report with the following information: • How the First Responders Community of Practice is being used. Has the intended audience been reached? • An analysis by DHS of the practical utility of the collection. • An analysis by DHS of other similar platforms currently in use by first responders.”


So apparently S&T is being given a second chance to get this information right.

Wednesday, March 19, 2014

DHS Announces HSSTAC Meeting – 4-7-14

The DHS Science and Technology Directorate (DHS S&T) published a meeting notice in the Federal Register (79 FR 15354-15355) announcing a two-day meeting of the Homeland Security Science and Technology Advisory Committee (HSSTAC) starting April 7th in Washington, DC. Most of the meeting will be open to the public. (NOTE: As of 05:30 CDT, 3-19-14, the HSSTAC web site is not accessible.)

The first day of the meeting will focus on DHS S&T interactions with the U.S. Immigration and Customs Enforcement (ICE). The discussions on April 8th will include two topics of potential specific interest to readers of this blog:

• An update and discussion regarding the DHS S&T Cyber Security Division (CSD); and
• Project Responder, a project managed by the DHS S&T First Responder Group, which aims to systematically identify capability gaps for responding to catastrophic incidents. 

There will be a public comment period after these two presentations. Pre-registration for oral presentations is requested. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2014-0003). Comments should be submitted before April 4th.

The afternoon session on April 8th will be closed to the public while the Committee:

• Receives a classified brief regarding emerging and disruptive technologies and technology trends (including the use of Intelligence, Surveillance, and Reconnaissance (ISR)); and

• Hears an update from the Task Force on Third Party Pre-Screening regarding its progress on helping TSA to expedite physical screening by exploring private sector options; the results of private sector testing and evaluation.

Thursday, November 7, 2013

DHS Publishes CyberFETCH 30-day ICR Notice

Today the DHS S&T Directorate published another sloppy information collection request (ICR) notice in the Federal Register (78 FR 66949). This ICR renewal supports the relatively new (2011) CyberFETCH Program. CyberFETCH is a collaborative environment for cyber-forensics practitioners from law enforcement, private sector and academia.

Editorial Errors

Once again the S&T notice includes a wrong Docket #. The Docket # provided (DHS-2013-0021) is for a Customs and Border Patrol program (019 Air and Marine Operations Surveillance System (AMOSS) System of Records). The correct Docket # is DHS–2013–0047. The notice does not include the OMB Control # for the currently approved ICR (1640-0017), nor does it include a reference to the Federal Register page number for the 60-day ICR notice.

Oh, and this ICR renewal was already sent to OMB on September 30th. That submission says that the 30-day notice was published in the Federal Register on the same day as the 60-day notice.

Now none of these errors go to the substance of the ICR or the CyberFETCH program, but they do indicate a high degree of bureaucratic ineptitude. Some will argue that that is not necessarily a bad thing in a technology organization, but it certainly reflects poorly on the management skills in the Directorate.

The Collection Burden

This notice and the earlier 60-day notice report no changes in the burden estimates for the program. This seems a little bit odd since the currently approved ICR was prepared before the site was established and was a reasonable attempt to estimate the level of participation. Additionally, since this ICR is for the Registration Form, I would think that the rate of new registrations would start to fall off unless there was a new push to get people to participate.

In any case S&T estimates that there will be 1000 new registrants to the program every year for the next three years. It will take 15 minutes to fill out the registration form (it isn’t that complicated) for an estimated annual burden of 250 hours. This is certainly not an unreasonable burden for the potential information sharing and expansion that this program may engender.

The CyberFETCH Potential


I generally think that having a semi-secure environment were cybersecurity professionals can share information on cyber-forensics is certainly a good idea. Since the CyberFETCH activities go on behind semi-closed doors and I am not a member (since I am certainly not a cyber forensics practitioner) I am not able to report on how well this site is serving its intended purpose. I do hope that it includes some active discussions and information sharing on control system forensics as this is an area that needs whatever help it can get.

Wednesday, March 20, 2013

DHS Cancels HSSTAC Meeting


DHS S&T published a notice in today’s Federal Register (78 FR 17219-17220) that they were canceling tomorrow’s meeting of the Homeland Security Science and Technology Advisory Committee (HSSTAC). No reason for the cancellation is provided in the notice and the meeting is still listed on the Committees web site.

Readers might recall that one of the agenda items for the meeting was an update on the evolution of the Cyber Security Division of S&T.

Thursday, September 13, 2012

HSSTAC Meeting Announced


Today DHS announced in the Federal Register (77 FR 56662-56663) that the newly reconstituted Homeland Security Science and Technology Advisory Committee (HSSTAC) will be holding its first meeting on September 27th and 28th in Washington, DC. This public meeting will allow the Committee to establish its working priorities and organizational structure.

HSSTAC Purpose


This advisory committee was established to advise the DHS Under Secretary for Science and Technology on areas including:

• Systems engineering;

• Cybersecurity;

• Knowledge management; and

• How best to leverage related technologies funded by other federal agencies and by the private sector.

Agenda


The first day of the meeting will consist of briefings of the new committee by various organizations within the Department. On the second day the Committee will focus on:

• How technology can address homeland security challenges;

• Accelerating innovation through systems analysis; and

• Leveraging industry for impact

Based upon the briefings received, public input and Committee discussions Department officials will provide direction to the HSSTAC on their priorities and the establishment of sub-committees to address identified issues.

Public Participation


The public is invited to participate in these deliberations. Pre-registration to attend the meeting is required and may be accomplished on-line. There will be a public comment period on the second day of the meeting. Comments should be limited to 3 minutes and pre-registration of the intent to make a public comment is required; contact Mary Hanson, HSSTAC Executive Director. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0053).

Tuesday, March 1, 2011

DHS S&T First Responders Community of Practice ICR

The DHS Science and Technology Directorate (S&T) published their initial 60-day information collection request (ICR) in today’s Federal Register for a new program they plan to establish, the First Responders Community of Practice. This program is being designed to provide “a collaborative environment for the first responder community to share information, best practices, and lessons learned” (76 FR 11254).

OMB approval of the ICR would allow S&T to collect registration information to allow them to limit participation in the program to first responders and selected non-first responders. Participating on-line members of this community would be able to “create wikis, discussion threads, blogs, documents, etc., allowing them to enter and upload content in accordance with the site’s Rules of Behavior”.

Public comments on this ICR are being solicited. They should be submitted by May 2nd, 2011. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov) using docket number DHS-2011-0008.

Thursday, December 3, 2009

Studying Chemical Attacks

There has only been one semi-successful chemical attack in a subway system. Given the high number of riders in urban systems, the limited nature of emergency exit routes, and the somewhat restricted air flow, it would seem to be a natural terrorist target for employing chemical weapons. It is with this in mind that Secretary Napolitano announced yesterday that DHS and the Massachusetts Bay Transportation Authority (MBTA) announced that they would be conducting a chemical dispersion study in MBTA subways this month.

According to the announcement the DHS Science & Technology Directorate-led study “will examine the behavior of airborne contaminants if they were to be released into the subway”. The study will involve the release of non-toxic chemicals representing gasses, small particulates, and simulated biological agents. Detectors will be placed in tunnels, subway stations, and subway cars to study the dispersion patterns of these trace chemicals.

Information gained from this study will allow scientists to more accurately predict the way that chemical and biological agents would move throughout the subway system in the event of a deliberate attack or even an accidental spill. This will allow subway systems to more accurately develop emergency response plans for such incidents.

Since al Qaeda has proven their interest in attacking public transportation facilities by their attacks on such systems in London and Madrid, it is only fitting that this study would have international support. Participating in the study will be scientists from Defence Science and Technology Laboratory of the United Kingdom; and Chemistry Centre of Australia, as well as such domestic organizations as Argonne National Laboratory (ANL) of Argonne, Ill.; Lawrence Berkeley National Laboratory (LBNL) of Berkeley, Calif.; and ICx Technologies of Arlington, Va.

While this study will not directly affect the chemical security community, it is clearly understood that there are a number of theft/diversion chemicals of interest produced in this country that could conceivably be used in conducting a chemical attack on such transit facilities. Anything that can be done to reduce the likelihood of such an attack will help to reduce the threat terrorist attacks to steal or divert such chemicals from CFATS covered facilities.

Wednesday, February 25, 2009

S&T Communications Development

More about the DHS ‘table top’ exercise that is being “designed to facilitate and accelerate the delivery of critical infrastructure protection technologies”. In my earlier blog I finished with a discussion of how we used a what-if review to analyze the things that can go wrong with a new or revised chemical process. And I promised to explain how that ties into this DHS ‘table top’ exercise. Well, here goes, with a little side trip through the US Army Berlin in the ‘70s. War Story Back many years ago when I was a young sergeant in a mortar platoon we got a new company commander in our unit. Shortly after his arrival we had one of those periodic games that a peace-time Army likes to play, a load-out alert. It really was nothing more than an emergency response drill with weapons and camouflage. The call came in and we loaded up all of our combat equipment and parked the vehicles outside the gate, ready for inspection. The new commander did not like how well his new company performed on this alert. He thought we were confused, disorganized and above all, too slow. He was sure that ‘his’ company should be able to get the vehicles rolling out the gate in 30 minutes instead of the almost two-hours it actually took us. All it would take would be a little training. The first thing he did was hold a training session with the leaders of each platoon; the platoon leader, platoon sergeant and each squad leader. We went over in detail what needed to happen to get our platoon loaded out and in the assembly area. At each step along the way he would explain a requirement and we would work out how to make it happen in the most efficient way possible. For example, getting vehicles to the platoon bay to load them up. Assigned drivers need to pick up the vehicles from the motor pool. Oops, all of the assigned drivers lived off post and it would take them twenty minutes to get there. Okay, assign a person who lived in the barracks to get the vehicle. Oops, the vehicle keys were locked in the Platoon Sergeant’s desk and it took him 15 minutes to get there (he lived closer). Okay, give a key to the desk to one of the sergeants (me) who lived in the barracks; no better make that a copy to each of the sergeants who lived in the barracks. After doing that for each of the tasks involved in loading out the platoon, we did a walk through with whole platoon, explaining what each person was supposed to do along the way. After we went through it a couple of times and everyone understood we went back to the barracks and pretended it was early in the morning and did a slow run through. And then repeated that a couple more times. Two weeks later when they called the next load-out alert we made it out the gate in 20 minutes. Table Top Exercises So we have two completely different types of process development that used many of the same techniques. The most important was the sit down in a room and talk about the process in a step-by-step sequence. This allowed a variety of people who would look at the process from their separate perspectives to point out the things that would work and would not work. The input from these collective viewpoints would allow most of the real time problems to be avoided. This is the purpose of any table top exercise. It is used to familiarize personnel with the procedure and work out the kinks in the procedure in an atmosphere where there is no time pressure or safety considerations distracting people from finding an effective way to get things done. Science and Technology (S&T) Division The S&T Division of DHS has the responsibility for developing tools and techniques to protect the homeland. They are there to help solve the problems that crop up in trying to protect the critical infrastructure and key resources (CIKR) that have been identified as being important in maintaining the ‘American Way of Life’. They cannot, however, be everywhere and see everything needed to identify those problems. They must rely on a wide variety of stakeholder in the Federal, State and local governments and the private sector to identify those problems. Anyone that has ever done any serious problems solving knows that the hardest part is defining the problem. It gets even more complicated when someone else is defining the problem; communications issues cause additional complications. This is the primary challenge that S&T faces in developing procedures for taking problems from other agencies, levels of government and the private sector and converting those problems into innovative tools and techniques to solve those problems. This is the Game According to Leslie Sibick, Chief, Research and Development Project Office at the DHS Infrastructure Information Collection Division this is the process that the ‘table-top’ exercise is supposed to help develop. Their ‘little game’ will put potential consumers of S&T Division services around a table and provide them with a game ‘scenario’. They will then work through the situation, trying to identify problems where the S&T Division can provide assistance. Then they will work through the S&T procedures for submitting that problem. Both the Infrastructure Information Collection and the S&T Divisions hope that this will help their private sector customers understand the areas where the S&T Division can provide assistance and how to request that assistance. S&T should also get at least a couple of issues on which they can start to work. But, more importantly, it will allow S&T to refine their problem identification and information collection process. That is what this game is all about. Anyone in the Nuclear, Chemical, and Dams Sectors that may be interested in participating in this exercise should contact Amy Graydon at amy.graydon@hq.dhs.gov.

Monday, February 23, 2009

DHS Exercise of SandT Communications

Last month I read a short little piece on the ACC website about a ‘table-top’ exercise that DHS was going to be putting on in early March. Now DHS sponsors all sorts of exercises and drills, but this one sounded a little bit different because of the purpose. This exercise would be “designed to facilitate and accelerate the delivery of critical infrastructure protection technologies”. Needless to say, my interest was peaked. Since that piece came out, I have been trying, in fits and starts, to get some more information, some details about how this ‘table-top exercise’ was going to fulfill its designed goal. Well on Friday, I finally had a chance to talk to one of the people that is responsible for this ‘little game’, Leslie Sibick, Chief, Research and Development Project Office, and it was an interesting telephone conversation, well worth the wait. Drills and Exercises Before I get to the details of what I learned in that conversation, I think that it would be appropriate to take a look at why we use drills and exercises. Most readers of this blog will have at least a passing familiarity with emergency response drills. A typical emergency response exercise will physically simulate an incident that could happen at a facility. Then the people involved will exercise their pre-planned response to that simulated emergency. A variety of people and response agencies can take part in the drill, but essentially everyone is going to do in the drill what they would do in the actual situation. Generally we think of these drills as training or evaluation exercises. The people involved will have some level of familiarity with the tasks involved; they know what they are supposed to do; they just need practice so that they can do it effectively in the event the incident ever really happens. Before these emergency response drills can take place, however, some one must determine what everyone is supposed to do. Some one must decide that if this happens, this should be done; it should be done by this person or group, it should be done using this equipment and using these procedures. Due consideration must be made for missing people and equipment and for responses for a whole host of things that can go wrong. The more detailed this planning is done in advance, the smoother the training goes, and the smoother the drill or exercise goes. Process Development Essentially what we are talking about here is process development, developing the process for responding to an emergency incident. Now process development is something that I know a lot about, it is what I did for most of my career in the chemical industry. I developed refined and improved chemical manufacturing processes. I became quite good at it and I understand the process of process development. Developing a process, any process, starts out with an idea of how to accomplish a task. That initial idea usually comes from the mind of a single individual. Now one thing that I have learned in my life is that no successful process comes from the mind of just one person. The reason for that is simple, life is too complex for any one person to conceive of all of the things that can happen to make a process go wrong. Now, the next most important thing about process development that I have learned I learned before I ever set foot in a chemical production facility. I learned this, had it pounded into my head, in my first career as an Infantry NCO. The military has a rule that is familiar to every successful general and sergeant; no plan survives contact with the enemy. It means that no matter how well you plan, no matter how well you train, when it comes time to actually put that plan into action something over which you have no control will cause you to change your plan. Experimental Development Now in the chemical industry we dealt with that problem by conducting a series of experiments. The experiments would start out small in the laboratory. We would look at all of the things that we though could go wrong; temperature too high or too low, too much of one ingredient or another. The more complex the process, or the more unique the process the more experiments were done. As we successfully found all the things that could go wrong, and how to prevent or correct them, we would scale up the experiments to a larger size container. We started with small scale glassware experiments and then moved into 1-liter reaction vessels that more closely simulated the process equipment that we would use in production. Then we would scale-up to 20-liter vessels and then 2000-liter vessels. Then we would move into production scale equipment. At each step along the way there was a formal review of what had been done, what had been learned in the previous experiments. As the scale increased the number of people involved in the review process increased as did the formality of the review. This was because the number of people involved in conducting the experiments would increase, but also because the risk and the cost of the experiments would increase. Process Reviews The most intense and practical reviews were the process safety reviews. A team of experienced individuals from a variety of different disciplines in the facility would get together and review each individual step of the process and ask a series of what if questions; what if the temperature got too high, what if the wrong material were added. If the answer was some negative consequence, ranging from a bad product to a vessel exploding, a control or preventive action had to be developed to stop that from happening. DHS’ Little Game Well, what does that have to do with this little game that DHS has developed to “to facilitate and accelerate the delivery of critical infrastructure protection technologies”? To find that out, you are going to have to tune in to the next installment: S&T Communications Development.
 
/* Use this with templates/template-twocol.html */