Showing posts with label GAO. Show all posts
Showing posts with label GAO. Show all posts

Tuesday, September 8, 2026

GAO Publishes Report on Chemical Plant Personnel Screening

Today, the Government Accountability Office (GAO) announced the publication of their report on “Chemical Security: DHS Should Provide Options for Voluntary Vetting of Facility Personnel for Terrorist Ties”. GAO was asked to evaluate the effects of the end of the CFATS program in 2023 and the decline in CISA chemical security staffing since 2025 on chemical facility security.  

The report noted that (pg 5): 

According to CISA officials and representatives from the private sector coordinating council, the three selected chemical associations, and the six selected chemical companies we interviewed, losing the Personnel Surety Program is the most significant challenge high-risk chemical facility owners and operators have faced following the discontinuation of the CFATS program. CISA officials also stated that discontinuing the Personnel Surety Program left a gap in chemical facility security that poses significant risks. 

The Report made one recommendation (pg 16): 

Identify, evaluate, and implement voluntary options for chemical facility owners and operators to address insider terrorist security risks by vetting their personnel and unescorted visitors with access to restricted areas or critical assets, and, if necessary, seek the legislative authority to do so. 

The official CISA response to the recommendation (pg 16): 

The voluntary collection and handling of sensitive personal information necessary to conduct such vetting would raise significant legal, privacy, compliance, and resource considerations. These considerations include proper collection, use, maintenance, and protection of sensitive personal information necessary to support such activities, as well as requirements associated with safeguarding personal data and providing appropriate redress 

Saturday, April 20, 2024

GAO Reports – Week of 4-13-24 – Federal Cybersecurity EO Actions

This week, the Government Accountability Office (GAO) published a report on “Cybersecurity - Implementation of Executive Order Requirements Is Essential to Address Key Actions”. The report looks at the implementation of EO 14028 in CISA, NIST, and OMB.

The table below shows the GAO’s assessment of EO 14028 leadership and oversight requirements (see Appendix III of the report for description of the individual requirements):

Executive Order Section

Number of requirements that are:

Fully complete

Partially complete

Not complete

Not applicable

Removing Barriers to Sharing Threat Information

6

1

Modernizing Federal Government Cybersecurity

8

Enhancing Software Supply Chain Security

16

1

Establishing a Cyber Safety Review Board

6

1

Standardizing Playbook for Responding to Cybersecurity Vulnerabilities and Incidents

4

1

Improving Detection of Cybersecurity Vulnerabilities and Incidents

7

1

Improving the Federal Government's Investigative and Remediation Capabilities

2

1

Total

49

5

1

The report makes a total of five recommendations (pg 44), two for DHS and three for the OMB:

• The Secretary of Homeland Security should direct the Director of CISA to issue, in a timely manner, its list of software and software product categories that are considered critical software. (Recommendation 1)

• The Secretary of Homeland Security, through the Director of the CISA, should direct the Cyber Safety Review Board to document steps taken or planned to implement the recommendations provided to the President for improving the board’s operations. (Recommendation 2)

• The Director of OMB should demonstrate that the office has conducted, with pertinent federal agencies, cost analyses for the implementation of recommendations related to the sharing of threat information, as defined in the order. (Recommendation 3)

• The Director of OMB should demonstrate that the office has coordinated with pertinent federal agencies regarding resourcing needs for the implementation of an endpoint detection and response capability, as defined in the order. (Recommendation 4)

• The Director of OMB should demonstrate that the office has coordinated with pertinent federal agencies regarding resourcing needs for logging, log retention, and log management capabilities, as defined in the order. (Recommendation 5)

Saturday, April 6, 2024

GAO Reports – Week of 3-3-24 – Gas Pipeline Safety Regulatory Scheme

This week the Government Accountability Office (GAO) published a report on “Gas Pipeline Safety:

Better Data and Planning Would Improve Implementation of Regulatory Changes”. The report looks at two recent major changes to the pipeline safety regulations (2019 final rule and 2022 final rule) and PHMSA’s implementation efforts. Based upon their review of the problems that PHMSA and the gas pipeline industry had with the implementation of the 2019 rule, GAO is making the following recommendations for the 2022 rule implementation and for planned future rules.

• The Administrator of PHMSA should, as PHMSA considers possible changes to the potential impact radius calculation, evaluate what additional data are needed from operators to better understand the actual impact of pipeline incidents. (Recommendation 1)

• The Administrator of PHMSA should develop an implementation plan for the remaining activities for the 2022 final rule that includes clear objectives, timelines, and an outreach strategy. (Recommendation 2)

• The Administrator of PHMSA should update the 2019 and 2022 Gas Transmission Final Rule Implementation web pages to increase accessibility to rule implementation information. (Recommendation 3)

Saturday, September 30, 2023

GAO Reports – Week of 9-23-23 – Cybersecurity Audits

This week the Government Accounting Office (GAO) published a report on “Cybersecurity Program Audit Guide”. Rather than the normal GAO report on the results of an audit, this report outlines “the methodologies, techniques, and audit procedures they [auditors] need to evaluate the components of agencies' cybersecurity programs and systems.” It identifies six major components of a cybersecurity program audit:

• Asset and risk management: developing an understanding of the cyber risks to assets, systems, information, and operational capabilities.

• Configuration management: identifying and managing security features for system hardware and software and controlling changes to the configuration.

• Identity and access management: protecting computer resources from modification, loss, and disclosure by limiting authorized access.

• Continuous monitoring and logging: maintaining ongoing awareness of cybersecurity vulnerabilities and threats to an organization's systems.

• Incident response: taking action when security incidents occur.

• Contingency planning and recovery: developing contingency plans and executing successful restoration of capabilities.

Saturday, July 1, 2023

GAO Reports – Week of 6-24-23 – Cybersecurity Strategy

This week the Government Accountability Office published a report on “Cybersecurity: Launching

and Implementing the National Cybersecurity Strategy”. This short (2 page) report provides an overview of the recently published National Cybersecurity Strategy with an emphasis on how well the document meets the GAO ‘desirable characteristics of a national strategy’ criteria. Major topics addressed in the report include:

• Threats highlight the importance of establishing leadership in cybersecurity,

• The Administration needs to fully develop and implement the National Cybersecurity Strategy,

• Opportunities, and

• Challenges


Saturday, June 17, 2023

GAO Reports – Week of 6-10-23 – Nuclear Weapon Cybersecurity

This week, the Government Accountability Office (GAO) published a report on “Nuclear Weapons Cybersecurity: Status of NNSA's Inventory and Risk Assessment Efforts for Certain Systems”. The report provides an overview of actions the National Nuclear Security Administration (NNSA) has taken in response to recommendations made an earlier (GAO-22-104195) GAO report.

While NNSA and GAO have an odd definition of the term ‘nuclear weapons IT’ (it includes the ‘weapon control unit inside the B61-12 gravity bomb’ for instance), the definition of operational technology is only lightly focused on manufacturing related technology. “NNSA uses operational technologies (OT) in the processes, equipment, materials, and products employed in the production of nuclear weapons. Examples of OT systems include building safety systems (e.g., fire suppression systems) or an additive manufacturing system used to print polymer components.” (pg 1)

To give one an idea of where NNSA is in its cybersecurity voyage, the report notes that (pg 3):

“NNSA’s efforts to address cybersecurity at the system level in the OT environment remain in the early stages of development and implementation. In our September 2022 report, we noted that NNSA has made limited progress—after several years of effort—to implement risk management practices that would help it inventory OT systems and assess and mitigate the risks to such systems. NNSA has estimated that there could be hundreds of thousands of OT systems at sites across the nuclear security enterprise.”

 

There are no new cybersecurity recommendations made in this report.

Saturday, March 25, 2023

GAO Reports – Week of 3-18-23 – Critical Infrastructure Protection

This week the Government Accountability Office (GAO) published a report on “Critical Infrastructure Protection: Time Frames to Complete CISA Efforts Would Help Sector Risk Management Agencies Implement Statutory Responsibilities”. This report was presented as the prepared testimony of Tina Won Sherman, GAO, before a hearing of the Subcommittee on Cybersecurity and Infrastructure Protection of the House Homeland Security Committee on March 23rd, 2023. This is essentially a follow-up to a February GAO report on the same topic.

Section 9002 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (PL 116-238, 134 STAT. 4768) changed many of the duties of the Sector Risk Management Agencies (SRMAs) when it added §2215 to the Homeland Security Act of 2002 (6 USC 665d). This report looks at actions that CISA could be (and is planning on) taking to support those additional SRMA duties.

Saturday, January 21, 2023

GAO Reports – Cybersecurity – Week of 1-14-23

This week the Government Accountability Office (GAO) published a report on “Challenges in Establishing a Comprehensive Cybersecurity Strategy and Performing Effective Oversight”. The report summarizes previous GAO reports on the topic and looks at the recommendations that have not yet been implemented to date.

The ‘Overview’ section of the report notes that:

“This is the first in a series of four reports that lay out the main cybersecurity areas the federal government should urgently address, beginning with the need for a comprehensive strategy and effective oversight.1 We have made about 335 recommendations in public reports since 2010 with respect to this area. About 190 of these recommendations were not implemented as of December 2022. Until these are fully implemented, federal agencies will be more limited in their ability to protect private and sensitive data entrusted to them.””

Saturday, October 1, 2022

GAO Reports – Cybercorps Scholarships

This week the Government Accountability Office (GAO) published a report on Cybersecurity Workforce:

Actions Needed to Improve CyberCorps Scholarship for Service Program. The program was started in 2000. Since that time the program has awarded about $621 million in scholarships to over 4,707 recipients.

According to the Highlights section of the actual report:

“GAO was asked to review the Scholarship for Service Program. GAO determined the extent to which (1) NSF and OPM are complying with program legal requirements, and (2) NSF has identified, analyzed, mitigated, and reported on program risks.”

The report includes three recommendations for the National Science Foundation:

• NSF should periodically evaluate and make public, information on how long CyberCorps® Scholarship for Service Program scholarship recipients stay in the positions they enter upon graduation.

• NSF should provide Congress with all required information in a timely manner for the CyberCorps® Scholarship for Service Program so Congress can use this information to make informed decisions regarding the SFS Program.

• NSF should develop and implement a risk management strategy that includes a process to effectively identify, analyze, mitigate, and report CyberCorps® Scholarship for Service Program risks and challenges.

The report includes two recommendations for the Office of Personnel Management:

• OMB should establish a time frame for implementing a process to ensure that all CyberCorps® Scholarship for Service Program scholarship recipients provide their institutions of higher education and the Office of Personnel Management (in coordination with the National Science Foundation) with annual verifiable documentation of post-award employment and up-to-date contact information for a period of at least through the end of their work service obligation.

• OMB should ensure the collection of complete and consistent data that relate to the fulfillment of all post-award obligations or requirements pursuant to the CyberCorps® Scholarship for Service Program.

NOTE: GAO actually published two very nearly identical reports (GAO-22-105187 and GAO-22-106146.pdf), both on October 29th, 2022. Most of the changes are very minor formatting changes, the biggest change that I have found in a quick look is that the later report refers to the ‘Office of Personnel Management’ in a number of locations where the earlier report refers to it in the same places as the ‘U.S. Office of Personnel Management’.


Saturday, September 24, 2022

Review - GAO Reports NNSA Cybersecurity Concerns

This week the Government Accountability Office published a report on the cybersecurity efforts at the National Nuclear Security Administration. According to the web site for this report: “The National Nuclear Security Administration (NNSA) and its contractors have not fully implemented six foundational cybersecurity risk practices in its traditional IT environment. NNSA also has not fully implemented these practices in its operational technology and nuclear weapons IT environments.”

The GAO report recommends (pgs 42-3) that NNSA should:

• Promptly finalize its planned revision of Supplemental Directive 205.1, Baseline Cybersecurity Program, to include the most relevant federal cybersecurity requirements and review the directive at least every 3 years.

• Direct NNSA’s Office of Information Management, and the site contractors that have not done so, to develop and maintain cybersecurity continuous monitoring strategies that address all elements from NIST guidance.

• Direct NNSA’s Office of Information Management, and the site contractors that have not done so, to identify and assign all risk management roles and responsibilities called for in NIST guidance.

• Direct that the site contractors that have not done so maintain a site-wide cybersecurity risk management strategy that addresses all elements from NIST guidance and perform periodic reviews at least annually.

• Direct the Office of Information Management to identify the needed resources to implement foundational practices for the OT environment, such as by developing an OT activity business case for consideration in NNSA’s planning, programming, budgeting, and evaluation process.

• Establish a cybersecurity risk management strategy for nuclear weapons information technology that includes all elements from NIST guidance.

• Clarify and reinforce to the M&O contractors, such as by a policy flash or other communication, that they are required to monitor subcontractor’s cybersecurity measures.

Include performance criteria evaluating contractor oversight of subcontractor cybersecurity measures in the annual M&O contractor performance evaluation process.

• Direct Information Management and the Office of Acquisition and Project Management to ensure that Supplemental Directive 205.1 contains language requiring third-party validation of contractor and subcontractor cybersecurity measures.

 

For a more detailed look at the GAO Report, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/gao-reports-nnsa-cybersecurity-concerns - subscription required.


GAO Publishes Federal Building Security Report

This week, the Government Accountability Office published a report looking at the effectiveness of the Federal Protective Services in providing physical security oversight over, and federal law enforcement support to federally owned and leased offices. The GAO reports that, while Agencies are generally satisfied with the assessments, they do not implement many of the resulting recommendations.

The report notes:

“FPS conducts facility security assessments and recommends security measures—such as security cameras, physical access control systems, and x-ray screening equipment. These measures are aimed at preventing security incidents.”

Interestingly, there is no discussion about the assessment of, and recommendations for, the cybersecurity of the electronic systems being suggested by the FPS. This would be especially problematic where these systems are networked to centralized security stations or where remote access to the systems are allowed.


Saturday, June 18, 2022

GAO Reports – DOD Cybersecurity Management

This week the Government Accountability Office published a report on DOD’s management of cybersecurity and supply chain risks. While this report is a look at the business management of unclassified information technology systems, it does look at some cybersecurity risk management issues at DOD. Like a note on the report’s landing page that seven of the 25 major DOD business IT programs reported “not having a system security plan that addresses [information and communications technology] ICT supply chain risk management and did not plan to develop one”.

No problems here, keep moving, nothing to see…

Saturday, March 5, 2022

GAO Reports – Cybersecurity - 3-5-22

This week the Government Accountability Office (GAO) published a cybersecurity related report on: “Internet Architecture is Considered Resilient, but Federal Agencies Continue to Address Risks” (GAO-22-104560). The report was requested by the House Armed Services Committee. The report consists of two parts; the abbreviated Highlights and the Full Report.

According to the summary provided in the Highlights, the report:

• Identifies security risks related to the internet architecture and (2)

• Determines the extent to which U.S. federal agencies have taken actions to address security risks to the internet architecture.

The report does not include a concluding list recommendations.

Saturday, November 13, 2021

GAO Reports – K-12 Cybersecurity

This week the Government Accountability Office published a report on their audit of federal programs to ensure the safety and security of K-12 educational institutions. They found that the most recent guidance from the Department of Education dates back to 2010 and that guidance minimizes the importance of cybersecurity in the protection of K-12 education facilities. The report makes two recommendations:

• The Secretary of Education should initiate a meeting with the Director of CISA to determine how to update its sector-specific plan (SSP) for the Education subsector. The plan should assess and prioritize federal actions to assist K-12 schools in protecting themselves from cyberattacks.

• The Secretary of Education should make a determination, in consultation with the Director of CISA and based on current cybersecurity risks, on whether subsector-specific guidance is needed for the Education subsector.

Saturday, September 25, 2021

GAO Publishes Grid Resiliency Overview

This week the Government Accountability Office published a report on “Electricity Grid Resilience”. This is a brief, 2-page, overview of recent GAO reports on the topic. It does highlight previous GAO recommendations that have not yet been implemented. Includes discussion of cybersecurity and physical security risks.

Tuesday, May 19, 2020

GAO CFATS Cybersecurity Report – Outdated Guidance


Last week the Government Accountability Office published their latest report on the Chemical Facility Anti-Terrorism Standards (CFATS) program. This report specifically addresses the cybersecurity component of the CFATS program. It provides six recommendations to address cybersecurity guidance for covered facilities and cybersecurity training for chemical security inspectors (CSI).

The Recommendations


The GAO report recommended (and DHS concurred) that DHS should:

• Implement a documented process for reviewing and, if deemed necessary, revising its guidance for implementing cybersecurity measures at regularly defined intervals.
• Incorporate measures to assess the contribution that its cybersecurity training is making to program goals, such as inspector- or program specific performance improvement goals.
• Track delivery and performance data for its cybersecurity training, such as the completion of courses, webinars, and refresher trainings.
• Develop a plan to evaluate the effectiveness of its cybersecurity training, such as collecting and analyzing course evaluation forms.
• Develop a workforce plan that addresses the program’s cybersecurity related needs, which should include an analysis of any gaps in the program’s capacity and capability to perform its cybersecurity-related functions, and human capital strategies to address them.
• Maintain reliable, readily available information about the cyber integration levels of covered chemical facilities and inspector cybersecurity expertise. This could include updating the program’s inspection database system to better track facilities’ cyber integration levels.

Cybersecurity Guidance


The main complaint the GAO had with the cybersecurity guidance provided by the Cybersecurity and Infrastructure Security Agency’s (CISA) Infrastructure Security Compliance Division (ISCD) is that it is over ten years old. That guidance is found in the CFATS Risk Based Performance Standards (RBPS) Guidance document that was published in May 2009. Cybersecurity it addressed in RBPS number 8. The seven pages of ‘guidance’ is a broadly written overview of general cybersecurity provisions that might be appropriate to a high-risk chemical facility. It includes paragraphs addressing various topics in the areas of:

Security Policy,
Access Control,
Personnel Security,
Awareness and Training,
Cyber Security Controls, Monitoring, Response, and Reporting,
Disaster Recovery and Business Continuity,
System Development and Acquisition,
Configuration Management, and
Audits.

The RBPS Guidance then goes on to discuss (similarly briefly) security considerations associated with:

Potential Off-site Aspect of Cyber Security,
Interconnectivity of Critical and Seemingly Non-Critical Systems,
Impact of Risk Drivers,
Physical Security for Cyber Assets, and
Layered Security,

Finally, the RBPS Guidance cybersecurity section provides a series of metrics that ISCD would use in assessing whether or not a facility’s site security plan adequately addresses the cyber RBPS. Those metrics are keyed to the risk rating of each facility; generally speaking, higher risk facilities have to take more actions to protect the facility from potential terrorist cyber threats. The threat metrics address:

Cyber Security Policies,
Access Control
Personnel Security,
Awareness and Training,
Cyber Security Controls, Monitoring, Response, and Reporting,
Disaster Recovery and Business Continuity,
System Development and Acquisition,
Configuration Management, and
Audits

Guidance Problems


Beyond the age of the document, the biggest problem with the RBPS Guidance was not addressed by the GAO report and that is that the writers had to be careful not to be ‘too prescriptive’ in their discussions about security issues. I discussed this problem in some depth when the document was published, but in short DHS was dealing with a congressional restriction on providing any sort of one-size-fits-all facilities regulation. In my opinion, they bent over backwards in the RBPS Guidance document to avoid any sort of appearance of dictating security measures and the document is weak as a result.

Proposals for Additional Guidance


While the issues discussed in the RPBS Guidance are still appropriate cybersecurity considerations, they fail to address any of the emerging cybersecurity threats that face high-risk chemical facilities. An updated discussion would have to include discussions about:

Phishing,
Ransomware,
Advanced persistent threats,
Security Operations Centers,
Patching and vulnerability risk assessments, and
Vulnerability reporting.

An additional topic for inclusion would be the ISCD’s cybersecurity integration level program. This is an internal ISCD assessment of the level of integration of cyber systems into the protection and utilization of chemicals of interest. This program was described on pages 15-17 of the GAO report. ISCD uses this assessment to assign CSI with varying levels of cybersecurity expertise to the appropriate facilities. In many ways this integration assessment would more sense than just risk levels in determining which sorts of cybersecurity controls should be in place for facilities.

Problems with Changes


ISCD has a long history of being very responsive to industry concerns with the CFATS programs. They have to be to ensure continued congressional support for the program. That support, in turn, is necessary because of the continued short-term reauthorization process for the program. This does cause some problems for the CFATS program.

ISCD would almost certainly have to go through the comment and response process that it used in the original publication of the RBPS Guidance in any revision of the document. Industry would be leery of any substantive changes to that document that might cause facilities to change their existing security procedures. This is almost certainly been one of the reasons why ISCD has been reluctant to undertake a review and update of that document. On the flip side of that, is of course, if no changes in security programs would be required, why should ISCD take the effort to update the document.

Congress needs to provide cover to ISCD in this matter. As part of the impending CFATS reauthorization, Congress should include a mandate for review and update of the RBPS Guidance. To avoid additional wrangling over what to include in the bill, specifics on what to include in the update should not be provided by congress. That should be left to the review process. Congress should, however, require ISCD to include examples of what sorts of controls could be included in a site security plan to meet the metrics provided in the Guidance.

Thursday, August 9, 2018

GAO Publishes CFATS Report – 08-08-18


Yesterday the Government Accountability Office (GAO) published their latest report on the Chemical Facility Anti-Terrorism Standards (CFATS) program. This report was requested by Congress as part of the efforts leading up to the re-authorization of the CFATS program. Generally, the GAO was satisfied with the progress that the DHS Infrastructure Security Compliance Division (ISCD) has made with improvements to the CFATS program and issued two Recommendations. GAO provides both a copy of the report and one-page summary on their web site.

Measuring Program Performance


While the GAO report is generally positive in its reporting on improvements made to the CFATS program (and specifically to responses to previous GAO recommendations) they do note one on-going problem that ISCD has only partially addressed. That reflects on the ability of ISCD and DHS to measure the success of the CFATS program in reducing the risk of terrorist attack on high-risk chemical facilities.

Specifically, they recommend that ISCD “should incorporate vulnerability into the CFATS site security scoring methodology to help measure the reduction in the vulnerability of high-risk facilities to a terrorist attack, and use that data in assessing the CFATS program's performance in lowering risk and enhancing national security.” (pg 33)

DHS has concurred with this recommendation (pg 39) and notes on-going activities to improve the calculation of the change in ‘security score’ that the Department uses to measure and report the program performance in ‘lowering risk and improving national security’. To more fully comply with the recommendation DHS reports that (pgs 39-40):

“To develop a system that could numerically evaluate vulnerabilities likely would require revising the regulatory language describing CFATS vulnerability assessments, modifying CFATS processes, and updating tools used to gather vulnerability assessments. This would be a significant burden on both industry and government and NPPD does not believe this would result in a better measure for evaluating the security enhancing effectiveness of the CFATS program, compared to the new performance measure the Department intends to implement.”

Information Sharing


While the GAO report recognizes that ISCD has taken positive steps to share information about CFATS covered facilities with first responders and emergency planners through the establishment of their IP Gateway, their investigation showed that the information available is not effectively reaching the targeted audience (see the lengthy discussion on pages 29-32.

The GAO recommends that DHS “should take actions to encourage access to and wider use of the IP Gateway and explore other opportunities to improve information-sharing with first responders and emergency planners.” (pg 33-4).

The DHS response to this recommendation includes a discussion (pgs 40-1) of efforts that it has taken to date (mostly identified in the GAO report) including a program requirement (Risk Based Performance Standard 9) that requires facilities to “have regular and recurring contact with their local first responders” (pg 41). DHS then goes on to explain that this last “is the most effective way to get information to first responders as it involves direct communication between the high-risk chemical facilities and their local responders. DHS then notes that they “cannot require first responders to access the IP Gateway or respond to facility requests for visits”. They do report that they “will ensure contact is made with LEPCs representing the top 25 percent of the CFATS high-risk chemical facilities no later than the end of the second quarter FY 2019” (pg 41).

Commentary


The first issue is a program measurement issue that needs to be resolved between DHS and Congress. Congress rightly wants to know that the programs that it authorizes and funds are having a beneficial effect. How to measure that performance in a meaningful way in this particular instance, is going to be difficult to establish. DHS has an important point in that the measures of program performance should not unduly increase the burden on the regulated community.

The second issue is much more problematic and important to the ultimate success of the CFATS program. All CFATS covered facilities have to rely to some extent on the resources of the local community to respond to a successful attack on the facility. Even facilities with dedicated on-site emergency response personnel are going to have to rely on off-site responders to deal with effects of an attack on the local community. Sharing information with local response agencies (including police, ambulance and hospitals serving the area around CFATS facilities) is an important pre-requisite to having an effective response a successful terrorist attack.

I was disappointed in this portion of the GAO report in that the investigators did not apparently dig deeper into why “officials representing 13 of the 15 LEPCs stated that they do not have access to CFATS information within the IP Gateway” (pg 31). While seven of those officials reportedly were not aware of the IP Gateway, it is disconcerting that GAO did not attempt to ascertain why the other 8 could not accesses the available information.

I suspect that the reason has to do with the provisions that require that before an individual can access the most detailed (and important) information they have to be cleared for access to Chemical-Terrorism Vulnerability Information (CVI). This clearance requires completing an on-line training program, establishing a need-to-know (should be a priori established for LEPC members), and maintaining the information security requirements (a post access requirement) of the CVI program {which have yet to be upgraded to comply with Federal controlled unclassified information (CUI) standards}. Gaining the CVI access is not terribly difficult, but it does require some investigation and action by the LEPC officials desiring access to the information.

Much of the information currently protected by the CVI designation in the IP Gateways probably should not be protected as it should be available to LEPCs under the EPA reporting requirements of the Emergency Planning and Community Right-to-Know Act of 1986 (EPCRA). Interestingly, the GAO reports note that 200 of the 300+ chemicals covered under the CFATS program {DHS chemicals of interest (COI)} are not covered under the reporting requirements of EPCRA. Not mentioned in the report is the fact that (presumably most of) these 200 chemicals are covered under the CFATS program because of their potential use in manufacturing improvised chemical munitions or improvised chemical weapons, not because they are an air-pollution release-risk covered under the EPCRA requirements.

Adequately addressing this information sharing problem is not one that ISCD is going to be able to resolve on its own. It will require congressional action as part of the CFATS reauthorization process. I will address this issue more completely in a future blog post.

Monday, July 27, 2015

New GAO Report on CFATS Program

Last Friday the Government Accountability Office (GAO) published their latest report on the Chemical Facility Anti-Terrorism Standards (CFATS) program. While the report did identify some areas where the DHS Infrastructure Security Compliance Division (ISCD) needed to improve the CFATS program it generally noted that significant improvements had been made and previously identified problems had generally been corrected.

The GAO Report identifies four areas of concern:

DHS has not taken steps to mitigate errors in some facility-reported data;
DHS does not have reasonable assurance that it has identified all of the nation’s highest-risk chemical facilities;
DHS cannot ensure consistency in how it addresses noncompliance in the CFATS program because it does not have documented processes and procedures; and
DHS’s CFATS performance measure does not reflect security measures that facilities have implemented and that ISCD has verified.

Top Screen Data Reporting

The GAO identifies a problem with the reporting of Distance of Concern DOC for the release of toxic chemicals in the Top Screen. The CFATS Top Screen requires the facility to calculate the down wind distance that a worse case discharge of a toxic release chemical of interest (COI) will cause a significant problem. The tool that facilities are required to use is the EPA’s RMP*Comp.

The user inputs the maximum amount of a Toxic COI that they have on site, enters some other basic information (see pages 42 and 43 of the Top Screen User’s Manual) and the tool calculates DOC which is then reported in the Top Screen. DHS then uses this information as part of its determination of whether or not a facility may be covered under the CFATS program as a facility at high-risk of terrorist attack.

The GAO used available Top Screen data to verify the DOC reported for a ‘a generalizable sample of facilities’. Using that data the GAO report indicates that 44% of the facilities (2,700 facilities) had errors in the reported DOC and about 43% under-reported the DOC. It goes on to note that a common potential reason for the under-reporting may be due to one difference in the way the tool is used to calculate EPA and CFATS DOC information, the CFATS program does not allow facilities to take credit for passive mitigation measures such as dikes around tank farms.

The Report provides an example of a facility with more than 200,000 lbs of anhydrous ammonia  (AA) reported in its Top Screen that reported a DOC of 0.9 miles and GAO found a minimum possible distance of 2.4 miles when they calculated the DOC using R*Comp. I have replicated that work and found that there was no way to come up with a DOC of 0.9 miles regardless of whether or not mitigation measures were used. I suspect that the facility used their largest storage tank data (as they would for EPA reporting) instead of the total amount of AA on site as required by DHS. It is remotely possible that GAO’s figure of 0.9 miles came from the DOC value reported for the Area of Highest Quantity (AHQ) instead of the total COI.

The GAO report notes that ISCD has all of the information in its Top Screen Database necessary to verify the DOC data, but does not choose to do so. The first part is not necessarily true. The RMP*Comp tool, when calculating the DOC for materials that are gasses at 25°C, asks if the material is liquefied, and if liquefied whether it is liquefied by refrigeration or by pressure. That information is not included in the Top Screen and makes a big difference in the DOC. This is not important for most toxic release COI, but it is for AA. Using the Report’s example with AA you could get DOC’s of 2.4 miles (unliquified) 6.5 miles (liquefied under refrigeration) vs 8.0 miles for liquefied by pressure (all in an urban setting).

The thing that the GAO failed to take into account in pointing out this deficiency is that ISCD does not verify any of the information provided in the Top Screen. It is true that they could generally check the DOC value (using the ‘unliquified’ data from RMP*Comp), but that might not give a true picture for all COI. But given the fact that ISCD is accepting all other reported information, it would be unusual for them to pick out this one item that could be partially verified in a portion of the instances where it is reported.

Given the fact that the Report notes that only 43% of the discrepancies that it noted were under-reports, it seems to me that their data would tend to indicate that there were systemic problems with the use of the RMP*Comp tool. As ISCD moves forward with implementing the results of the outside evaluation of their risk ranking methodology, they should consider taking this calculation out of the hands of the facility and do the calculations in-house.

The GAO has two recommendations for this area:


Provide milestone dates and a timeline for implementation of the new Top-Screen and ensure that changes to this Top-Screen mitigate errors in the Distance of Concern submitted by facilities, and
In the interim, identify potentially miscategorized facilities with the potential to cause the greatest harm and verify the Distance of Concern these facilities report is accurate.


Facility Identification

The report outlines the measures that DHS has taken to identify facilities that have not submitted Top Screens, but should have done so. While they had conducted earlier out-reach activities, the effort was expanded after the West Fertilizer incident and the issuance of the President’s Executive Order on Increasing Chemical Facility Safety and Security. As a result of these latest efforts just over 3,000 potentially non-compliant facilities were identified and contacted by DHS.

More than 1500 had already submitted Top Screens; the ‘new’ identification was apparently based on differing naming or location information. Over three hundred were exempted from CFATS regulations. Of the remaining just over 1,000 have now submitted Top Screens and just 24 of those have been designated as high-risk facilities covered under the CFATS program with 44 still pending. ISCD is continuing to investigate other means of identifying potentially non-compliant facilities.

The report indicates an interesting problem. ISCD has asked States for information on the chemical facilities that they regulate as part of this program. California recently complied, identifying over 46,000 facilities (ISCD has only processed 50,000 Top Screens since the program started) which ISCD is now going through. Only 13 other States have supplied similar lists.

The GPO did not provide any recommendations for DHS on this issue.

Compliance Inspection Issues

The Report starts of the discussion of this issue with a review of actions that ISCD has taken to increase their rate of site security plan approvals and notes that ISCD has made substantial improvements in that approval rate. Interestingly, even though the GAO calculated that ISCD would have the approval backlog eliminated next year, they did not mention that the EAP process will almost certainly further accelerate the SSP approval process.

The Report then notes that ISCD has completed 83 compliance inspections of facilities with approved site security plans. There is no discussion of how well that reflects the requirement for ISCD to inspect facilities within one year of their site security plan being approved. The number seems low, but it will almost certainly increase as ISCD has fewer authorization inspections to complete.

The GAO reports that nearly half of the facilities inspected have not completely implemented all of the security measures outlined in their site security plans, which of course means that the facilities are out of compliance. The Report notes that ISCD is working with the facilities to get them into compliance.

The GAO notes that none of the non-compliance sanctions available to the Department (including Compliance Orders, Civil fines and even Cease Operations Orders) have been used by the Department to-date. While ISCD is ‘working with’ the facilities, the GAO reports that they do not have any written processes or procedures in place to document the progress that is being made at those facilities. Nor, apparently, does ISCD have any written processes or procedures in place on how they determine whether or not a facility is in compliance.

The GAO had one recommendation for this area:


Develop documented processes and procedures to track noncompliant facilities and ensure they implement planned measures as outlined in their approved site security plans.


CFATS Performance

The last area of concern identified in the Report concerns the program reporting done by ISCD to DHS. This annual reporting requirement is used by DHS and the GAO to assess program performance and efficacy. One of the pieces of information included in that report is the number of security measures implemented by facilities. The GAO notes that ISCD does not distinguish between those measures implemented before the facility site security plans were approved, which measures have been reported as planned, or which of the planned measures have been implemented. Thus, the GAO reports that the numbers do not reflect changes brought about by the CFATS program and ISCD actions in support of that program.

The GAO had one recommendation for this area:

Improve the measurement and reporting of the CFATS program performance by developing a performance measure that includes only planned measures that have been implemented and verified.

Moving Forward


DHS has acknowledged the four recommendations in the GAO report and has reported their intended actions to be taken in response to those recommendations. GAO confirms that if those actions are taken as reported, the recommendations would be considered as completed.

Sunday, May 12, 2013

TWIC Reader Hearing


Well, I finally had a chance to go back and watch the web cast of last Thursday’s hearing of the
Government Operations Subcommittee of the House Oversight and Government Affairs Committee on the GAO’s report on the TWIC Reader Pilot. Well, it was supposed to be about Federal Government Approaches to Issuing Biometric IDs, but no other agencies could show up and there was this GAO report, so it was essentially about the report.

Now I described the report in an earlier post, but in summary the GAO found all sorts of methodological problems with the way the TWIC Reader Pilot was run by TSA. As a result of those problems GAO questions whether the conclusions drawn from the pilot report can be used to justify the use of TWIC Readers. GAO did not question the utility or performance of the Readers, just whether or not the TWIC Reader Pilot results could be used to justify the use of the Readers.

Politics

The hearing was very poorly attended on both sides of the Committee Room. There were only four congressmen present, the Chair and Vice-Chair, the Ranking Members of both the Committee and Sub-Committee. The Rep. Mica (R,FL) noted that there were only three people in the press gallery. Even with the advanced notice of the results of the GAO report, there was little interest in the hearing.

The hearing was, however, a model of bipartisan agreement; TSA was in deep trouble and had a great deal of explaining to do. With only four congresscritters asking questions there was a great deal of follow-up questioning and when one congressman’s turn was done the next took up the same line of questioning as if it were rehearsed.

For the most part the questioners did listen to the responses and modify their subsequent questions appropriately. The only major exception to this was Chairman Mica’s continuing reference to the susceptibility of the TWIC to forgery, even after Mr. Lord explained that the GAO’s forged cards did not pass muster in the TWIC Reader. Lord explained that the holders were allowed facility entrance despite the lack of TWIC Reader approval; certainly not the fault of TSA.

To TWIC or Not To TWIC

Every one of the Subcommittee members present questioned whether or not DHS should consider replacing the TWIC with something more effective. Committee Ranking Member Cummings (D,MD) made the comment in his opening remarks that there is no “reliable data proving that the TWIC card” is part of an effective port security program. Mr. Sadler from TSA disagreed, of course, but even Mr. Lord from GSA admitted that there was no proof that the TWIC wasn’t effective.

Mr. Sadler said time and again (in very repetitive language, obviously rehearsed to emphasize the limitations) that, when properly installed and maintained, and the operators and card holders were properly trained, the TWIC Readers in the study properly performed their scanning and verification function. No one disputed this oft repeated statement.

What wasn’t directly mentioned here was the fact that neither TSA or GAO have any control over whether or not the TWIC program continues, is cancelled or is significantly modified. All of that rests with the Congress. Of course, scrapping the program and starting anew will cost a great deal of money, something that will be politically impossible to do. Even making significant changes to the TWIC program will be costly and politically difficult to achieve in the current political and economic environment.

Interestingly, the GAO does not recommend making changes to either the TWIC or the TWIC Readers. The conclusion of this report states:

“Given that the results of the pilot are unreliable for informing the TWIC card reader rule on the technology and operational impacts of using TWIC cards with readers, we recommended that Congress should consider repealing the requirement that the Secretary of Homeland Security promulgate final regulations that require the deployment of card readers that are consistent with the findings of the pilot program; and that Congress should consider requiring that the Secretary of Homeland Security complete an assessment that evaluates the effectiveness of using TWIC with readers for enhancing port security. This would be consistent with the recommendation that we made in our May 2011 report. These results could then be used to promulgate a final regulation as appropriate.” (pg 10)

In other words, Congress should remove their mandate to use the TWIC Reader Pilot as the justification for requiring the use of TWIC Readers and put the burden back on DHS to justify the use of TWIC Readers on the basis of improved security. The reason for requiring the TWIC Reader shouldn’t be that it works, but rather that it is needed.

TWIC Antennas

There was an important technical issue that was only peripherally addressed in this hearing and in the GAO report. The GAO report noted that there was insufficient information provided in the TWIC Reader pilot to identify how many cards were not read due to broken antennas. Since the TWIC is an RFID device that can be remotely queried by the TWIC Reader a broken antenna makes it useless as a contactless identification.

Mr. Sadler noted in response to questioning that the contactless mode of operation is what distinguishes the TWIC from the Common Access Card (CAC) readers used by the military. He used this to explain why the Subcommittee members {particularly Ranking Member Connolly (D,VA)} should not try to compare the ruggedness of the CAC to the less robust TWIC.

He then claimed that only a contactless reader could be used at port facility truck gates. This does not appear to be factually correct. There are hand-held TWIC Readers that could be used, allowing the more robust antenna available on such devices to be used to contact a local base station rather than using the embedded antennas to allow the TWIC to communicate with the Reader.

IRIS Biometric

A topic near and dear to the heart of Chairman Mica is the lack of an iris scan biometric encoded in the TWIC. Each time he brings this up, apparently, he has been told that NIST does not yet established a standard for encoding the iris biometric, but is coming in the next couple of months. TSA rightly maintains that it is not up to them to establish the standard, just to implement one if it is feasibly available.

Mica requested both witnesses and the committee staff to contact NIST to see if they could get a consistent answer as to when such a standard might become available.

TWIC NPRM Reader Extension

Mr. Lord did note in response to some question about the timetable for the implementation of the TWIC Reader NPRM (a concept that Chairman Mica appeared to be completely unfamiliar with) that the Coast Guard had recently extended the comment period on the NPRM to 90 days. Then, almost in passing, he suggested that they might want to make another 90 day extension to allow comments to be formulated about the results of the GAO report on the TWIC Reader Pilot.

Since there have been no comments to date on the TWIC Reader Pilot, I would not be surprised to hear that someone in industry doesn’t request another extension to review their initial acceptance of the NPRM in light of the reported inconsistencies in the pilot report. With just a little over a month remaining on the revised comment period, the Coast Guard would certainly be justified in approving such a request.

Video Timeline

A long time reader, Donald Bruce of the Houston/Galveston, TX Area Maritime Security Committee, was kind enough to send me an annotated timeline of the important parts (in his estimation) of the web cast of the hearing. I have not checked every listing, but it was helpful to me in following the video so I thought that I would pass it along. Note: Everything up to about the 39 minute mark was essentially opening statements.

Min 39 - Iris Scan issues
Min 42 – Use of Fake Cards
Min 43 – Questions from Rep. Connolly – Was the Pilot Successful?
Min 57 – What if we cancel the program?
Min 58 – We should recommend readers
Min 110 – Answer to benefit of TWIC Pilot – Definition of a Successful Reader Project
Min 111 – We will go forward
Min 113 – The TWIC Pilot is very useful for the USCG in the NPRM
Min 114 – CAC described use in Afghanistan – a success story
Min 119 –Contact biometric will not work in a maritime environment
Min 120 – TSA Given 60 days to review over Biometric Card success (CAC)
Min 122 – Look NIST Iris standard (Alternate Biometric)

Moving Forward

Chairman Mica said that the Subcommittee will be holding additional hearings looking at other forms of Federal identification that include encoded biometrics. He also gave Mr. Sadler 60 days to look at the CAC and get back to the Committee with an explanation of why the TWIC and the CAC should/should not be compared.
 
/* Use this with templates/template-twocol.html */