Showing posts with label FFF. Show all posts
Showing posts with label FFF. Show all posts

Friday, January 11, 2019

House Passes Two FY 2019 Spending Bills


Yesterday the House passed two FY 2019 spending bills; HR 265, for Agriculture, Rural Development, Food and Drug Administration, and related agencies; and HR 267, for Department of Transportation, and Housing and Urban Development, and related agencies. Both bills passed by near party-line votes; HR 265 – 243 to 183 and HR 267 – 244 to 180.

The final spending bill in this series (HR 266, for Department of the Interior, environment, and related agencies) will be considered on the floor today. A similar result is expected.

NOTE: None bills contains cybersecurity or chemical security/transportation provisions that would lead to detailed coverage here.

None of these spending bills is likely to be considered in the Senate. Yesterday during an attempt to consider HR 21, the FY 2019 Consolidated Spending Bill, under the Senate’s unanimous consent process, Sen. McConnel (R,KY) objected to consideration of the bill (pg S 113). In his discussion leading up to the official objection to proceeding McConnel noted:

“We [McConnel and Sen. Schumer (D,NY)] agreed that we wouldn’t waste the Senate’s time on show votes related to government funding until a global agreement was reached that could pass the House, pass the Senate, and which the President could sign.”

Thus, until all five (McConnel, Schumer, Rep. Pelosi (D,CA), Rep. McCarthy (R,CA) and President Trump) reach an agreement on the termination of the Federal Funding Fiasco, the Senate is unlikely to consider any spending bill.

Saturday, December 29, 2018

Public ICS Disclosures – Week of 12-22-18


This week we have one vendor disclosure from Schneider Electric and there is of course the federal funding fiasco.

Schneider Advisory


Schneider published an advisory for a use after free vulnerability in their Zelio Soft software product. The vulnerability was reported by mdm and rgod, of the 9SG Security Team. Schneider has an update available to mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Federal Funding Fiasco


This is the first week of the FFF and it looks like it could last for a while. The NCCIC-ICS landing page does not include the FFF banner that is found on web sites for other Cybersecurity and Infrastructure Security Agency (CISA) organizations. I would like to think that that would mean that NCCIC-ICS is up and functioning like the main National Cybersecurity and Communications Integration Center (NCCIC) presumably is.

Unfortunately, the lack of publication of any advisories this week leads me to conclude that if NCCIC-ICS is functioning, it is doing so in a limited fashion. It would be helpful if NCCIC-ICS were to delineate which of its functions were deemed to be essential enough to continue during the FFF.

Monday, November 25, 2013

Slow SSP Approval Rate – Alternate Explanation

Last Thursday I took the folks at ISCD to task for the very small number of facility site security plans they had approved since the end of the Federal Funding Fiasco. I questioned whether it was due to a disconnect between HQ approvers and Chemical Security Inspectors (CSI; I still hate that acronym) on the ground. Well I had a very interesting discussion today with a DHS official that pointed out another very reasonable cause for the reported SSP approval numbers; fall-out from the FFF.

Rescheduling Visits

When Congress failed to pass an interim funding bill on September 30th the inspection staff at the Infrastructure Security Compliance Division (ISCD) had a full slate of SSP approval inspections (okay they are called ‘visits’ not inspections until the facility site security plan is approved) planned for the first half of October. Since everyone working at ISCD was sent home on October 1st for the duration, all of those visits had to be canceled.

On October 17th when ISCD and the rest of the federal government came back to work, all of those visits had to be rescheduled. Remember the purpose of these visits is not compliance assurance (that comes after the SSPs are approved), but a cooperative effort between the CSI and the covered facility. This means that the facility has to have a reasonable chance to make sure that everyone involved in the SSP development process is available when the CSI arrive.

So, instead of starting inspections (er visits) on October 21st, the teams were forced to look for other things to do. Well actually, headquarters had a better idea, they took the time to have some good communication time with the field folks to iron out all of those little nit-picking SSP problems that have been accumulating over the last six months of running around the country looking at chemical facilities. Hopefully, this took care of some of the issues that I discussed in other blog posts (here and here).

Contractors Were Not Furloughed

Now the above explanation certainly sound good, but I asked the DHS official why then did ISCD get so many SSP authorizations done in the same circumstances. Part of the reason, it was explained to me is that the bulk of the authorization process is now a paperwork review with more reliance on telephone calls instead of site visits to clear up questions about the submitted data.

Now ISCD employees could not make these telephone calls or review the data, they were prohibited from doing any work during the government shut down. Fortunately, it seems, the subject matter experts doing this work were not government employees, they were contractors. And apparently contractors could work during the FFF.

When the ISCD staff that is responsible for reviewing the contractor work and actually authorizing the SSPs came back to work on the 17th, they had large stacks of perused paperwork and analysis sitting waiting for action. And action was taken; the highest daily authorization rate since reporting started.

Next Month

Okay, what will happen with next month? Will it get better, get worse or stay the same? It looks like it will get some better, but it still won’t look as good as the October report for the period before the FFF. There are still some scheduling holes in the first part of the period, but more importantly the holiday period will seriously cut into the numbers. ISCD does not expect to be back up to full schedule until January.

But, I was assured by the DHS official that ISCD expected to approve at least twice as many SSPs as they did/do in 2013.


BTW: I suggested that ISCD should do a better job of explaining the ups and downs they encounter in the SSP authorization and approval process. Instead of including the boilerplate information in the November report, they would have been better served if they had included an explanation of their post-FFF activities.
 
/* Use this with templates/template-twocol.html */