Showing posts with label ICR Comments. Show all posts
Showing posts with label ICR Comments. Show all posts

Saturday, April 10, 2021

Public Comments on CISA Vulnerability Discovery ICR Revision – 4-10-21

Last month DHS published [Link added 4-10-21 1422 EDT] a 60-day information collection request (ICR) notice to support the expansion of their Vulnerability Discovery program (VDP) to other agencies in the federal government. This post is (maybe?) part of a series of posts that looks at public comments submitted in response to that ICR. The end of the comment period is May 18th, 2021.

To date there are two public responses to that ICR notice. One, of course, is from my blog post [.PDF download link], the other is from Andrew Hunt. Along with a brief comment, Hunt provides a marked-up copy [.PDF download link] of the 60-day ICR notice, clarifying the changes that he suggests.

Hunt suggests:

“Overall, shift language from 'all agencies with their web forms' to 'DHS CISA centralized reporting'. They have the expertise to collect this sensitive information, secure it appropriately, disseminate appropriately, and engage agencies to remediate their exposures. Review 'lawful method to practice...discover new vulnerabilities' language if that is not intended to provide safe harbor protections to hackers. Remove references to 'Solarwinds Hack' and replace with codenames (e.g. SunBurst, SunShuttle) or descriptions to reduce liability of brand damage to the Solarwinds company as it is trying to recover from this truly terrible attack. Reword the definition of a 'vulnerability' as more to do with redirection of expected execution and behavior rather than controls bypass. A vulnerability can exist without a defined/intended control.”

He makes the following additional points in the marked-up document:

• Controls are not always defined before being vulnerable. A better definition: ‘coerces hardware/software to execute or behave in unintended ways from the design’.

• “… lawful method to practice and discover new cyber methods to discover the vulnerabilities….” CLARIFY: this sounds like a safe-harbor statement for hackers.

• If you do not guarantee confidentiality, then no one will play with you. Exempt this from FOIA.

• Use one site, done right, secured, and managed by those with the experience to do so. Remediation of vulnerabilities are notified, then managed by CISA. Agencies follow CISA direction to properly mitigate the vulnerability.

Commentary

While Hunt’s comments are brief he brings up some interesting points. First, his suggestion that DHS run a centralized VDP meshes well with my observations about the requirements of 44 USC 3509. The more interesting point, however, is his take on the definition of ‘security vulnerabilities’ used in the ICR notice. That definition comes from 6 USC 1501(17) and it reads:

“The term "security vulnerability" means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.”

Hunt makes the point that: “Controls are not always defined before being vulnerable. A better definition: ‘coerces hardware/software to execute or behave in unintended ways from the design’.” Playing with Hunt’s comments just a bit, I would like to offer this formal version of Hunt’s suggestion:

“The term “security vulnerability” means any attribute of hardware, software, process or procedure that would allow or cause that hardware, software, process or procedure to execute or perform in an unintended way from the design.”

Unfortunately, an ICR is not the appropriate vehicle for changing a regulatory definition. DHS is not, however, required to utilize the definition from §1501 in this ICR. They could instead use my formal definition above, substituting “Security vulnerabilities may be defined as” for the first five words of the revised definition.

His comment about removing the SolarWinds name from discussion in the ‘Supplementary Information’ portion of the Notice brings up an interesting point. While I personally do not care much about wounded corporate egos, DHS is not responding to the vulnerabilities in the SolarWind products (that is the sole responsibility of the company), they are responding to the effects of the attacks wrought by SunBurst, SunShuttle etc. Thus, naming them rather than SolarWinds is probably more appropriate.

Finally, I am not sure that I agree with his FOIA comment. Researchers have no need to ‘protect’ their discovery of vulnerabilities. Vendor and agency developers might, but their response is not the subject of the ICR. There would certainly be some justification for restricting access to the vulnerability information pending mitigation actions. Reported vulnerabilities should probably be protected as sensitive but unclassified information pending mitigation development.

Saturday, March 8, 2014

Public Comments on CFATS PSP 30-day ICR Notice

The public comment period closed this week on the 30-day ICR notice for the CFATS personnel surety program. Only 8 public comments were posted on the docket on the www.Regulations.gov web site. Those were almost certainly not all of the comments submitted as the notice provided instructions for direct submission to OMB’s Office of Information and Regulatory Affairs (OIRA). Comments submitted I that manner would be available via a Freedom Of Information Act request, but not generally in any other manner.

Comments were received from:


Comment Analysis

NOTE: The numbers in parentheses indicates how many commenters addressed that particular issue.

Not surprisingly there are continued industry opposition (4) to the requirement to submit personally identifiable information (PII) on personnel with existing TSDB vetted credentials. No comments addressed how industry expected to ensure that an individual has shown up on the TSDB since being vetted for the alternate credential.

There were also comments (1) about the PSP being introduced through an information collection request process rather than a rule making. The objection being that the ICR notice sets forth detailed procedures and requirements for the PSP. This ignores the fact that all of the on-line tools for CFATS were accompanied by manuals that outlined detailed procedures and requirements and did not go even through the ICR process since they did not collect PII.

Industry continues to object (2) to the lack of an absolute commitment by DHS to notify facilities when a submitted individuals PII turns up a positive match on the TSDB. They continue to either ignore or not be swayed by the argument that a criminal investigation of the individual may prevent, by law, DHS from notifying facilities of such a match.

Objections were also raised (2) about the requirement to notify ISCD when an individual no longer had access to the covered facility. Commentors ignored the ISCD explanation that it needed to know when to stop the recurrent vetting of individuals against the TSDB.

An industry proposal for DHS to establish a method of allowing personnel to directly submit their own PII to DHS was mentioned (3). Such a system would place the onus of ensuring that the individual submitting the information was who they claimed to be on DHS when facilities already have that responsibility in their other RBSP #12 mandates. Additionally, no one has explained how the individual would be able to prove their PII submission to a facility.

There is an interesting discussion about 3rd party PSP services in Industrial Safety Training Council submission. It is a bit of an advertisement, but an interesting discussion if you read past that.

An interesting comment is provided by the AAR about the cost benefit calculation. The extenisvie calculation provided in the ICR does not address the costs associated with outside agencies, like the railroads, having to vet their personnel against the PSP. Technically, DHS does not have to consider that since the railroads are specifically not regulated under CFATS and it is the covered facility’s responsibility to ensure that all personnel given unescorted access to the facility are properly vetted. In practice, however, many non-chemical facility organizations will end up being affected by this rule.

Yeah or Nay?

Final Tally: 3 for; 5 against. Two of the three commenters supporting the ICR are providers of 3rd party background checks; such support is certainly in their best business interest. The third supporter is the American Chemistry Council. They support the proposed PSP with some suggested changes, but it is support from an influential chemical organization.

Normally, I would suggest that the lack of comments from some previously vociferous detractors would be a positive sign. With the ability to submit comments directly to OIRA, however, the lack of objection does not necessarily signify grudging support or even inactive opposition.

Moving Forward

The Personnel Surety Program ICR is now in the hands of OIRA. There is no telling how quickly (okay not very quickly is mostly expected) OIRA will take to provide their approval or disapproval of the ICR. They never did approve/disapprove the first PSP submission made in 2010; it was finally withdrawn by ISCD in 2012.


Given the President’s Executive Order on Improving Chemical Facility Safety and Security, one would like to think that the consideration of this ICR would be expedited, but this is an inherently political decision and this Administration has repeatedly shown how slow it is to make a decision with political ramifications.

Monday, June 10, 2013

CFATS PSP Comments – 06-08-13

This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


This last week of the comment period saw 17 submissions, almost exclusively from corporate sources or industry groups.

Third-Party Submissions

There is continued expressions of support for the provisions for allowing third-party submissions of personally identifiable information (PII). Air Liquide asks for additional details about how the third-party submitters would be identified to CSAT. GIS, a background-check provider, requests that ISCD provide a method for bulk-data submissions for third-party information providers.

48-Hour Advance Submissions

Air Liquide joins the chorus of complainers about the requirement to submit PII data on individuals 48 hour prior to their being granted unaccompanied access to critical or restricted areas of the CFATS facility. The National Association of Chemical Distributors (NACD) makes the point that there is no justification for the 48 hour submission rule if ISCD continues to refuse to notify facilities of the identification of personnel with terrorist ties. This point is clearly echoed by Rep. Thompson (D,MS) and the American Petroleum Institute (API). Allied Universal Corp. states it more bluntly: “As such, the PSP provides facilities no security value.”

The Society of Chemical Manufacturers and Affiliates (SOCMA) maintains that the possible requirement to shut down a facility because of the inability to comply with the 48-hour rule should have been addressed in the burden estimates.

PII Protection Rules

The American Coatings Association (ACA) questions whether the PSP ICR adequately addresses the various federal, state and local requirements to protect PII that will impact how facilities will collect and submit that data to DHS. The American Fuels and Petrochemical Manufacturers (AFPM) notes that this is an added burden because they are not currently required to maintain PII on contractors and visitors.

Other DHS Vetted Credentials

The ACA complains that the requirement for providing ISCD data on individuals with other TSA vetted individuals (holders of TWIC or HME for instance) defeats the purpose of using these credentials as alternatives to ISCD data submission for vetting. The Agricultural Retailers Association (ARA) maintains that “DHS should not require any further submission of information for those individuals holding federally issued credentials”.

SOCMA notes that it does not believe that DHS has the authority to compel facilities to provide information on personnel with other TSDB vetted identifications. AFPM agrees that “DHS is not authorized to impose prescriptive measures in order to comply with the performance-based rulemaking”.

Limited Implementation

The ARA supports the initial limited application of the PSP submission requirements to Tier 1 and Tier 2 facilities, noting that any future expansion to lower tiered facilities would benefit from the experiences obtained from this initial implementation.

PSP Coverage

The Edison Electric Institute complains that the ICR notice does not make it clear what employees would be covered by the PSP data submission requirement.

Inaccurate Burden Data

The API notes that the Burden Data estimates in the ICR notice are flawed because they do not rely on information already provided to ISCD via the submitted site security plans provided by all of the currently covered facilities. The American Chemistry Council estimates that the actual annualized burden costs of the PSP would be $5.22 million.

Moving Forward

This should be the last comments on the 60-day notice. DHS-ISCD will massage these comments, make changes as they deem appropriate and then issue a 30-day notice (if they ignore the suggestions to go to a rule making instead of an ICR) sometime in the next couple of months.


I’ll be looking at a couple of the issues raised in these comments in some detail in future blog posts.

Sunday, June 2, 2013

CFATS PSP Comments – 06-01-13

This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


This week there are comments from two industry organizations representing, hardly a well spring of comments as the fourteen day comment extension comes to a close. Effectively, there are just two days left in the comment period.

ISCD PSP Authority

The commentor representing terminal interests again objects to the ‘prescriptive’ nature of the PSP program proposed by ISCD and notes that this violates the §550 prohibition against the Secretary specifying any particular security measure as a prerequisite to site security plan approval. They even went so far as to include a 2012 letter they sent to the OMB after the previous attempted PSP ICR was forwarded to OMB for approval.

Alternative to PSP


The commentor representing the gas industry proposed an alternative proposal for a PSP program where individuals wishing to enter CFATS facilities submit information to a secure website for the purpose of being vetted against the Terrorist Screening Database. Once cleared, they would be given a personal identification number that they would provide to CFATS facilities to verify that they had been properly vetted against the TSDB. This is the same procedure that was proposed the week before by the chemical manufacturer.

Sunday, May 26, 2013

CFATS PSP Comments – 05-25-13

This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


We finally have some comments from the corporate sector, three from trade associations, one from a large chemical manufacturer and one from a background check provider.

Personnel Information

The background check provider calls out ISCD on a couple of paperwork issues, including:

• Maintaining PII files of information submitted to ISCD;
• PRA Notice signature requirements; and
• PII collection and storage for non-employees.

The major chemical manufacturer raises the same issues in their submission.

CSAT Requirements

The background check provider also wants to know some of the details about how the CSAT requirements for third-party submitters. They ask an interesting question, will lists of information (PII) submitted for the PSP have to be protected as Chemical-Terrorism Vulnerability Information (CVI) like the rest of the information submitted thru CSAT?

Lack of Authority to Require PSP Submissions

The chemical manufacturer and a trucking industry group question the authority of DHS to require data submissions to ISCD for local PSP. They cite the §550 stipulation that the Secretary may not require any specific security measure. They miss the loophole that was published in the 60-ICR Notice stating that facilities could propose alternative PSP measures in their Site Security Plan.

An explosives industry group agrees with the above comment and goes on to question the use of an information collection request as the vehicle for imposing essentially regulatory requirements on industry.

Alternative Visitor Process

The manufacturer notes that they had previously proposed an alternative method for submitting PII for visitors and contractors. They had proposed to NPPD that DHS could establish a secure web portal for individuals to submit the PII necessary for a Terrorist Screening Database (TSDB) search if they were going to be desiring to gain access to a covered facility. The manufacturer expresses concern that DHS has not followed up on the suggestion as promised.

TWIC, etc Procedures

The chemical manufacturer continues to complain about having to submit PII information on personnel who have a TSDB-based security identification. The explosives organization makes the same point, but further complains that ISCD is not accepting the ATF background check process that uses the same TSDB vetting.

The trucking group goes even further noting that requiring a HME holder to undergo additional security checks under federal programs is prohibited by 49 USC §5103a(g)(1)(B)(i)(I)-(II).

A training industry group supports the ISCD requirement for submitting PII for vetting personnel with other TSA supported identification, noting that a brief visual examination of the credential cannot determine if it is “expired, revoked or fraudulent”.  They additionally point to the problems with the TWIC Reader identified by GAO.

TSDB Positives

The manufacturer and the explosives group re-iterates their concern about DHS not notifying the facility if an individual is identified as having terrorist ties during the TSDB vetting.

48-Hour Submission Requirement

The chemical manufacturer objects to the 48-hour PII submission requirement for the TSDB vetting. They argue that since DHS will not routinely be informing facilities of positive TSDB matches, what difference does submitting the information 48-hours in advance of providing unescorted access make?


The trucking group notes that the 48-hour notice requirement could unnecessarily limit the availability of commercial deliveries.

Tuesday, May 21, 2013

NPPD Extends Comment Period on CFATS Personnel Surety Program ICR


Today the DHS National Protection and Programs Directorate (NPPD) published and ICR Comment extension notice in the Federal Register (78 FR 29759) extending the comment period on the CFATS Personnel Surety Program (PSP) information collection request. The fourteen day extension moves the end of the comment period to June 4, 2013.

The extension notice does not mention any specific request for additional time. It justifies the move by saying:

“The Department believes that the public would benefit from additional time to provide comments on the March 22, 2013 CFATS Personnel Surety Program Notice and Request for Comments.”

Today was supposed to have been the closing day for comments so it is uncertain if the extension will practically provide any additional time for comments. Typically corporate comments come in at the end of the comment period, so the management decision to comment or not will have already been made.

To date only three comments have been posted and only one of those made any substantive suggestions. After the firestorm of comments received on the previous ICR, I expect that ISCD is waiting for the other shoe to drop, but it looks like they may have addressed the major concerns of industry with the previous PSP proposal. Oh well, another 14 day delay in fielding the PSP won't make much difference, I hope.

Public comments on the PSP may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0061).

Monday, April 29, 2013

CFATS PSP Comments – 04-27-13


This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


We are more than half way through the comment period on this ICR notice and we only added one comment in the last week bringing the total to three. I am surprised that there have been no comments to date from any chemical companies, though I do expect that will change as we get closer to the May 21st deadline for comments. We do have our first corporate comment this week, however, from AGL Resources, a natural gas distribution company.

AGL has three specific suggestions for improving the PSP dealing with:

• Vendor PSP certification;
• Bulk data submissions to the PSP; and
• Exemption from PII data sharing rules.

The issue of dealing with vetting vendor employees will be the area that will give high-risk chemical facilities the most problem with the PSP. While facility security managers are certainly going want to restrict vendor access to critical areas of the facility to the largest extent possible, there is still going to be some unaccompanied access required for selected vendors.

I don’t expect ISCD to get too specific about how this should be handled; the §550 rule about specifying security measures hangs heavy over their heads. Generally speaking, I would expect them to address this issue in the ICR by stating that each facility will have to address the issue in their site security plans which will be reviewed on an individual basis.

I really believe that the most effective way to handle this issue for most facilities is that they would require such vendors to have a TWIC that would be verified by a TWIC reader at some centralized location (security company most likely) and then checked against an approved list at the facility entrance. Larger facilities would be able to afford a TWIC reader at the gate.

Which brings up an interesting question; how long before we have a Tablet Application that scans IDs and compares them to a facility access list?

Sunday, April 14, 2013

CFATS PSP Comments – 04-13-13


This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


There has been only a single comment filed in the last two weeks, another comment by an individual with no identified connection to a covered chemical facility. It includes discussions about the relative benefits of Options 1 and 3. Unfortunately the opening and closing paragraphs that bracket that discussion demonstrate a significant misunderstanding of the proposal (noting that there is nothing that describes what will be done with people identified with terrorist ties) and the CFATS program (noting that there is nothing in §550 or the ‘proposed rule’ that defines ‘high-risk chemical facility). Those misunderstandings severely detract from the discussion of the two options in the notice.

Monday, April 1, 2013

CFATS PSP Comments – 03-30-31


A little over a week into the comment period on the CFATS Personnel Surety Program (PSP) ICR and there is a single comment in the docket on the Federal eRulemaking Portal. There are six unusual supporting documents also to be found in the docket.

Supporting Documents

After the previous version of the PSP ICR was submitted to OMB (ultimately fated to be withdrawn last summer) there were a number of comments filed on the 30-day notice that had not been previously addressed by ISCD. David Wulf, Director of ISCD, took the unusual step of replying to those comments just about 11 days before the new ICR was published in the Federal Register in letters to the commenting parties. Those letters were addressed to:


Alternative Vetting Options

In each of the letters Wulf addresses the issue of supplying information on individuals that have already been vetted by the Department in one of the other TSA executed reviews of the TSDB. He makes the point that ISCD needs a limited amount of information on these personnel to:

• Verify that the affected individuals are currently enrolled in the Department program; and
• Enable the Department to access both the original enrollment data and the results of the vetting against TSDB information already in the possession of the Department, when necessary.

In responses to similar questions in the previous ICR ISCD repeatedly made the comment that they would also use the data to periodically recheck personnel against the TSDB to see if new information had been added. That point was re-made in the letter to Dr. Constantinides when Wulf states: “Facilities must notify the Department when individuals no longer have access, so that the Department knows when to stop performing recurrent vetting on them.” (page 2) This point was reinforced in the same letter when Wulf said that the Department would not grant reciprocity to the ATF vetting because the ATF “schedule for re-processing names against information in the TSDB as part of the ATF’s licensing/permitting regime is not equivalent to the recurrent vetting for terrorist ties that the Department plans to perform as part of the CFATS Personnel Surety Program” (page 3; also seen in the IMF letter).

This raises an interesting question in regards to the use of a TWIC Reader to validate an individual’s identity and the currency and validity of the TWIC in lieu of providing vetting or vetting verification information to ISCD. There is nothing in the wording of the ICR that would indicate that the facility would have to periodically have to require TWIC holders to re-use a TWIC Reader. In fact, it seemed to me that facilities using a third party (or consolidated corporate submission) to conduct PSP screening and data submission could use the TWIC Reader to validate a person’s TWIC to fulfill the PSP terrorist screening requirements and the facility would never have to acquire a TWIC Reader. I plan on submitting a question about this to ISCD as part of a comment on the ICR.

Computer System Access and PSP

The letter to the Chamber of Commerce addressed another interesting issue with regards to computer networks that are designated as critical assets in the SSP. The Chamber had addressed the issue in their comment noting that the facility’s cyber personnel could be located any where in the United States and even in other countries. Wulf’s response noted that PSP coverage included “facility personnel and as appropriate, for unescorted visitors with access to restricted areas or critical assets” (page 3) and then added the somewhat cryptic comment: “CFATS may include individuals with access to certain networked computer systems.”

I have always maintained that anyone with remote access to a critical computer systems (like an ICS) must be covered by the facility PSP. Admittedly this would cause some problems with vendors providing system service via remote access. The latest version of the ICR seems to make this somewhat easier in that vendors have the capability to submit PSP information to ISCD for the vetting process. There is still the question of how the facility can be assured that whomever is accessing their system has been properly vetted.

This is an issue that will have to be addressed in the SSP and it would be helpful if ISCD could offer some guidelines on the types of methodology that would be acceptable (always keeping in mind that ISCD is prohibited from requiring a specific method). I would suspect that a memorandum of understanding between the facility and the vendor that all personnel accessing a particular system will be vetted by the vendor would be a minimum requirement.

Comment Filed

The one public comment on the current ICR posted to the docket was, as expected this early in the game, from an individual. It appears that the commentor was unfamiliar with the purpose of the ISCD vetting program. It was not designed, as apparently assumed, to search for the most qualified people to access restricted areas but to just ensure that people with known terrorist ties were not allowed access.
 
/* Use this with templates/template-twocol.html */