Showing posts with label Disaster Recovery. Show all posts
Showing posts with label Disaster Recovery. Show all posts

Sunday, January 12, 2014

Short Takes – 1-12-14

There was a lot of good information this week on the internet that I did not have a chance to write about in the blog.

Chemical Disaster Recovery

An article over at Manufacturing.Net describes what was done to bring a chemical plant back on line in Tallulah, LA after it was hit by an EF-3 tornado in 2010. Effective disaster recovery requires some for thought before the disaster. This is a good look at some of the issues that came up. This would be a good topic for a chemical facility business case study.

Al-Qaeda

This article from USAToday.com would be good pre-hearing reading for anyone that will be watching the House Homeland Security Committee hearing this week on the current status of al Quaeda. Far from dead, but certainly changing this group will continue to be a terrorist threat to our country and its interests.

Crude Oil Trains

While we were watching the water system train wreck in West Virginia, there was another crude oil train wreck in Canada. This brief article describes the out of the way that did much more damage than the leaking tank at Freedom Industries, but affected fewer people because of it’s isolated location in New Burnswick, Canada.

This brief article describes a recent letter from Senators Heitkamp (D,ND) and Hoeven (R,ND) asking the FRA to look at the quality of the rail lines near Casselton, ND, noting that the recent crude train derailment there was the fourth derailment in the general area in 9 years; a real impressive safety record (SARCASM Alert). A separate letter from Senators Rockefeller (D,WV) and Wyden (D,OR) to the FRA and the Department of Energy asked for ‘quick action’ on crude train safety.

Sen. Shumer added his voice to the mix encouraging PHMSA to move quickly on its DOT 111 car rulemaking effort. North Dakota Governor Dalyrmple also got involved in the discussion, meeting with BNSF CEO to discuss their latest train wreck.

Cyber Terror Threats

This is an odd note purportedly from a terrorist group that claims responsibility for a recent physical attack on an electrical sub-station in California. It describes the attack as part of a series of exercises using ‘cyber/kinetic vectors’. No proof, just claims, but it does add an odd name to the already long list of ‘odd names’ (from an American perspective any way) associated with jihadist groups, Parastoo.

No Chemicals

As a chemist I get unusually agitated when I hear the claim ‘chemical free’. I ran across this JPG file showing the chemicals in an organic, ‘chemical free’ banana. I love it. Unfortunately, I don’t know where it originated.


Cyber Attack Threat

The ICS-CERT web page has a section dedicated to informative articles that pertain to control system security issues. There are not many articles listed and there connection to control systems is frequently tenuous at best. The latest is a link to a DefenseOne.com article about a recent poll that listed the threat of cyber attack as the biggest threat to national security. It is rated as a higher threat than terrorism (#2 but trying harder). I guess that would make a terrorist cyber attack really bad.

Water Facility Cybersecurity

I ran across this old Automation.ISA.org  article (ancient stuff from November 2013) about cybersecurity at water treatment facilities while I was looking for information about the Freedom Chemical Leak situation. I missed it the first time around and this is just an excerpt from the longer article.

Flu Season

With the 2014 flu season in full swing in the United States it is always good to remember that natural disasters come in all sizes. This is a brief article from FocusTaiwan.tw about recent mutations in the H7N9 flu virus that allow it to attach to the upper respiratory tract, making it much more likely to be spreadable amongst human kind instead of just birds. Flu is always worth watching closely.

The last swine flu epidemic was made worse according to the HomeLandSecurityNewswire.com article that claimed over emphasis on bioterrorism took money away from critical research about the spread of the flu. That may be a bit of an exaggeration, but bioterrorism certainly got more political press.

The End of XP

The April 8th death of Windows XP (or at least the end of Windows support for the ancient operating system) will provide a whole slew of problems for many existing control systems based upon computers running that OS. This article outlines some of the risks of not migrating to a newer OS. Of course if you are just now considering your options you are a bit behind the curve, but better late than never.

Delay as Cybersecurity Measure

Everyone knows (or should) that any system can be broken into given enough time and resources. This article at SCMagazine.com looks at how much time most hackers are willing to spend breaking into a system. The data indicates that most hacks can be prevented if you put enough stuff in the way of the hacker. They just give up and move on to an easier target. Of course, if they really want you, they can own you.

Takes from TWITTER

Click on first link to see the TWEET; follow me at http://twitter.com/pjcoyle -



@pjcoyle RT @intel17h Are cars the ultimate mobile device? Auto tech at #CES2014 - http://intel.ly/1cxne2S  - PJC And nary a mention of security!

@PatrickCMiller Radware Predicts Critical Infrastructure Outages, Encryption as Mass Weapon and First-Ever SDN Attacks in 2014 | http://j.mp/1hqtK3K 

@pjcoyle @jwgoerlich Thanks for pointing to 10 Immutable Laws of Security - http://technet.microsoft.com/library/cc722487.aspx … - Good things to remember

@pjcoyle Oil and gas drilling pollutes well water, states confirm http://nbcnews.to/1eBx3jv  via PJC Headline exaggerates important data

@pjcoyle The benefits challenges of self-driving cars - http://tinyurl.com/lpzo5qt  - PJC - Interesting cost benefit analysis - Security ignored -

@pjcoyle @i_defender "platform that's already familiar to drivers and developers alike" and hackers too

@pjcoyle Ohio police: Man stopped for speeding had 48 bombs http://wapo.st/1lN1pCf  PJC - But terrorist have to get theirs from FBI informants???

@pjcoyle @i_defender @Deloitte Mitigation and recovery more difficult/costly in ICS

@pjcoyle Success! SpaceShipTwo hits new heights during rocket test http://www.nbcnews.com/science/liftoff-spaceshiptwo-celebrates-new-year-test-flight-2D11767010 … - PJC Another step to commercial space flight -


@pjcoyle @chemsafetyboard Good to see that CSB is taking a case without deaths or explosions, though they certainly have enough of those.

Monday, December 31, 2012

HR 1 Passes in Senate – Sandy Relief

On Friday the Senate passed HR 1 after renaming it an “Act making appropriations for disaster relief for the fiscal year ending September 30, 2013, and for other purposes”. Why they just couldn’t rename it the Sandy Relief Act, nobody knows. The vote was a mixed 62 – 32 in favor, hardly a ringing endorsement.

No CFATS Coverage


The bill did not address the effects of Sandy on the security of high-risk chemical facilities in the covered area as I suggested in an earlier blog posting. I am disappointed that the Senate was not interested in the continuing security of the CFATS covered facilities in the area, but I am not surprised. After all there were more important things like the agreement between the US and Palau for the response to the 2010 Super Typhoon Bopha (SA 3344; which failed by the way by a vote of 52 – 43, 60 being required to pass).

Well, maybe this will be taken up when the House considers the Senate action on HR1, though the bill did not make the long list of bills on today’s agenda for the House. So maybe we will have to start all over again in the 113th Congress.

In any case I have developed some suggested language to either be added to a comprehensive CFATS bill (yep, we’ll soon be talking about that again) or to a Sandy Relief bill lacking that. Actually, it will probably have a better chance of passing on a Sandy related bill than on a CFATS bill. The language below would be in the form of an amendment to the Homeland Security Act of 2002.

Suggested Language


§21XX; Natural Disasters Affecting CFATS Covered Facilities

(a) In the event that the President declares a natural disaster in any political subdivision of the United States (eg: county, borough, parish, or tribal area) that contains a facility covered by the Chemical Facility Anti-Terrorism Standards (CFATS), the Secretary, acting through the Director of the Infrastructure Security Compliance Division (the Director), will dispatch appropriate Chemical Facility Security Inspector (CFSI) teams to assess the effect of that natural disaster on the security of covered facilities in the declared disaster area. Those teams will:

(I) Visit each covered facility in the area as soon as safely practicable;

(II) For Tier 1 and Tier 2 facilities in the declared natural disaster area, the CFSI Commander will determine if there is an immediate need for additional security personnel to prevent unauthorized access to the covered facility. Any such needs will be immediately communicated to the Responsible Federal Official for that disaster area as well as to the Director;

(III) Conduct an assessment of the damage to existing site security measures resulting from the natural disaster;

(IV)For facilities without an approved site security plan:

(A) Meet with the owner/operator of the facility;

(B) Determine the damage to currently existing critical security infrastructure at the facility;

(C) Determine the repairs necessitated by that damage that would allow the facility to deter, detect and delay intruders to the standards required by existing risk based performance standards (RBPS) applicable to the tier level, or interim tier level assigned to that facility;

(D) In consultation with the owner/operator prepare a report on the expected costs to effect the repairs outlined in (C) above;

(V) For facilities with an approved site security plan:

(A)  Meet with the owner/operator of the facility;

(B) Determine the damage to the current security measures described in the approved site security plan;

(C) Determine the repairs necessitated by that damage to return those security measures to the standards required by existing risk based performance standards (RBPS) applicable for the tier level assigned to that facility;

(D) Of the repairs determined in (C) above determine which repairs would be required to allow the facility to deter, detect and delay intruders to the standards required by existing RBPS for the tier level assigned to that facility

(E) In consultation with the owner/operator prepare a report:

(i) On the expected costs required to effect repairs outlined in (D) above; and

(ii) On the expected costs required to effect repairs outlined in (C) above less the cost determined in (i);

(VI) All reports required (IV) and (V) will be submitted to the Director within 1 week of CFSI being allowed into the declared disaster area;

(b)  Within two weeks of CFSI being allowed into the declared disaster area the Director will compile and forward reports to:

(I) The Administrator of the Federal Emergency Management Agency recommending that disaster recovery grants be awarded to covered facilities for the costs reported in (a)(IV)(D) and (a)(V)(E)(i);

(II) The Administrator of the Small Business Administration recommending that no cost disaster recovery loans be provided to covered facilities for the costs reported in (a)(V)(E)(ii); and

(III) Copies of both reports will be forwarded to the Homeland Security Committees in the House and Senate along with a summary of any recommendations made in (a)(II);

(c) Within one year of CFSI being allowed into the declared disaster area the Director will:

(I) Ensure that each facility inspected in (a) has been re-inspected to ensure that the required repairs have been made; and

(II) Report to the Homeland Security Committees in the House and Senate on the status of the repairs at covered facilities in the declared disaster area.

Explanation


Basically the bill would require Chemical Facility Inspectors to check all covered facilities in the disaster area. The ISCD Director would recommend grants for fixing damaged security measures directly affecting Deter, Detect, and Delay to the appropriate tier level standards set forth in the RBPS Guidance document. Facilities with approved site security plans would have their other security related repairs recommended for no cost loans from the Small Business Administration. The actual awarding of those grants or loans would be determined by the appropriate Administrators.

Remember, the whole purpose of the CFATS program it to protect the communities surrounding these high-risk chemical facilities. The companies have had to pay the cost of getting their facility security measures up to the minimum standards established. They shouldn’t have to pay for the costs of re-establishing those security measures after a natural disaster. And it is in the best interests of the Nation that the necessary repairs are done in a timely manner.
 
/* Use this with templates/template-twocol.html */