Showing posts with label Exercise. Show all posts
Showing posts with label Exercise. Show all posts

Tuesday, January 25, 2022

Review - ChemLock Exercises – Vehicle-Borne IED

 

NOTE: This is part of a series of blog posts looking at various CISA Tabletop Exercises Packages (CTEP) offered to chemical facility managers by the new CISA ChemLock program, a voluntary chemical security program run by the Office of Chemical Security (the CFATS folks). CTEP administrative documents can be found here. The scenario manuals can be found here. Earlier posts in the series include:

Overview,

Chemical Sector IED (short version), and

Chemical Sector Active Shooter (short version)

The Situation Manual for this vehicle-borne improvised-explosive (VBIED) exercise bills it as a review of “emergency preparedness plans and response procedures for an attack at a chemical sector facility.” It follows the same format as the two earlier exercises that I have discussed in some detail in the IED exercise post. Using the same format will make it easier for facilities to run subsequent exercises as they will already be familiar with the exercise processes.

The scenario for this module starts with a missing vehicle on the day before the exercise. On the day of the exercise a truck approaching the loading dock at the facility crashes into the dock and explodes. The provided discussion questions address:

• Plans that are in place to prevent or deter an attack at your facility,

• How security and personnel are trained,

• Standard operating procedures (SOPs) for incident response roles and responsibilities for staff,

• Assets onsite to immediately respond to an incident,

• Evacuation procedures for an incident of this type,

• Notification methods facility uses to send alert information,

• Incident command processes,

• Mutual aid agreements in place with other organizations,

• Notification of state or federal agencies of the incident,

• Law enforcement conduct of the response and address the threat,

• Medical response,

Commentary

While this is billed as a ‘Chemical Sector’ exercise, there is nothing in the scenario or discussion questions that would apply specifically to a chemical facility. The scenario could be applied to any manufacturing facility or warehouse in the country. There are no mentions of chemicals or chemical consequences in any of the discussion questions. This does not reduce the usefulness of the exercise, as the response discussion questions do identify areas of concern at chemical facilities, they just do not address the unique problems associated with a VBIED attack on a chemical facility.

For more details about the exercise, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-exercises-ca9 - subscription required.

Monday, January 17, 2022

Review - ChemLock Exercises – Chemical Sector Active Shooter

NOTE: This is part of a series of blog posts looking at various CISA Tabletop Exercises Packages (CTEP) offered to chemical facility managers by the new CISA ChemLock program, a voluntary chemical security program run by the Office of Chemical Security (the CFATS folks). It is a follow-up to my earlier Overview post. CTEP administrative documents can be found here. The scenario manuals can be found here. Earlier posts in the series include:

Chemical Sector IED (short version)

The Situation Manual for this exercise bills it as a review of “emergency preparedness plans and response procedures to an active shooter incident at a chemical sector facility.” It follows the same format as the IED exercise I previously discussed. Using the same format will make it easier for facilities to run subsequent exercises as they will already be familiar with the exercise processes.

The first Module is slightly more complex than that seen in the IED exercise. It provides two separate starting points for the exercise, a stolen vehicle and a disgruntled employee. Both starting points lead to an unidentified shooter arriving at the loading dock who is quickly killed by responding officers before the shooter can progress into the facility.

The exercise proceeds with the same question discussion format used int eh IED exercise. The second and third modules are nearly identical to the IED exercise in that they look at the short term and long term response to the incident. The same discussion questions are used in the second and third module as were used in the IED exercise.

Commentary

Active shooter situations are becoming much more common in the United States. With that in mind, facilities certainly need to consider running exercises such as this. This scenario, as presented, could be run at any manufacturing facility. Unfortunately, it is billed as a “Chemical Sector Active Shooter” exercise, but it does not take into account any of the unique problems that chemical facilities could face in an active shooter situation. This exercise assumes that the shooter, their bullets and the bullets of the responders that take him down never enter an area of the facility that contain chemicals. While such a limited event could occur, that is not what a “Chemical Sector Active Shooter” exercise should address.

For more details about the exercise, including my suggested additional discussion questions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-exercises-804 - subscription required.

Wednesday, October 17, 2012

ICS-CERT Updates Shamoon JSAR


Yesterday DHS ICS-CERT, in conjunction with US-CERT, issued an update of the Joint Security Awareness Report on the Shamoon malware. While this information stealing tool is suspected as being responsible for shutting down the Saudi oil company IT network, there has been no mention of it being used, or being specifically capable of being used, against control systems.

New Information


The new information included in the Update (on page 2) are three new entries in the ‘Tactical Mitigations’ section of the JSAR. The first is a ‘no duh’ entry, the second is somewhat useful, and the third is somewhat confusing. In general these three additions hardly make issuing an update worthwhile, particularly for the ICS community.

Drill Your Recovery Plan


I did say that this was a ‘no duh’ mitigation strategy, but to be fair ‘drill your recovery plan’ is one of those common sense strategies that probably doesn’t get done much. I’m not sure that simply listing it in a JSAR will help that. Perhaps an explanation of why any plan must be practiced (drilled) to be effective will help.

The military probably has the best experience in developing, perfecting and executing contingency plans. They know from bitter and painful experience that plans inevitably have short comings due to assumptions made in the planning process. Most often these assumptions are not clearly understood and frequently not even identified.

Practicing a plan will usually point out some of the shortcomings in the plan that are a result of inaccurate or incomplete assumptions. This does require, however, that after the plan has been exercised, that a clear and complete analysis has to be made of the areas where the plan did or did not work. And then the plan has to be modified to correct the deficiencies and build on what was done right.
 
Finding these mistakes during an exercise is much less painful and makes them easier to correct than if they are discovered for the first time while responding to the real thing.
 
/* Use this with templates/template-twocol.html */