Showing posts with label National Infrastructure Protection Plan. Show all posts
Showing posts with label National Infrastructure Protection Plan. Show all posts

Sunday, June 23, 2013

Comments on Proposed Revisions to NIPP – 6-22-13

This is the first in a series of blog posts about the public comments posted to the DHS proposed revisions to the National Infrastructure Protection Plan (NIPP).

We are now a little over a week into the one month comment period and four comments, all from individuals, have been posted to the Federal eRulemaking Portal for this docket. None of them is particularly responsive to the proposed revisions to the NIPP. We do have suggestions for:

• Building sea water canals into the interior of Western Africa to help prevent hurricanes along the East Coast and Gulf Coast of the United States;
• Providing more public availability of severe weather warnings;
• Placing educational institutions in their own Critical Infrastructure Sector (okay this comes close to what the NIPP is all about); and
• Making it a federal criminal offense to undertake a variety of criminal actions on, at or against Critical Infrastructure facilities (it takes Congress to enact criminal statutes).

The main problem with these suggestions is that they actually propose specific actions to be taken by the Federal Government. Anyone that has managed to stay awake long enough to read the current NIPP (and I am not one of that very limited number) would understand that this is a bureaucratic statement of general policy that is flexible enough to cover just about any action the Federal Government takes or doesn’t take with regards to Homeland Security.


I suspect that in the coming weeks we will see comments from a number of NGOs and contractors suggesting additions that would favor their pet projects. That is what we saw during the comment period for the last update in 2008.

Tuesday, December 9, 2008

National Infrastructure Protection Plan Comments – 12-05-08

As I noted in a blog last month (see: “Draft 2009 National Infrastructure Protection Plan”) DHS is doing its required revision of the National Infrastructure Protection Plan (NIPP). With the comment period having closed this last week (12-01-08) we finally see comments posted to the Regulations.Gov web site. Not very many comments I must say.

The comments were received from:
Becatech
National Association of State Energy Officials
National Association of State Chief Information Officers
Digital Sandbox, Inc
Security Analysis and Risk Management Association

Becatech Comments Becatech disagrees with the apparent focus on resilience and recovery as opposed to protective security. Becatech is concerned that the potential scale of terrorist attacks on critical infrastructure and key resources (CIKR) will quickly overwhelm the ability of that infrastructure to quickly and adequately recover. Becatech would like to see “DHS revise the NIPP to include the establishment of a framework, timeline, and funding for the mandated deployment of systems of protective security for CIKR”.

National Association of State Energy Officials Comments NASEO believes that the document contains too many abbreviations and acronyms which makes it difficult to read and understand. They also find that the draft is more focused on prescriptive measures than previous versions of the NIPP. NASEO would like to see the NIPP take a more ‘All Hazards’ approach, addressing issues beyond just terrorism.They are concerned that the criteria based Tier1/Tier2 program does not address dynamic systems like the electric power grid and the national pipeline system. NASEO believes that the inclusion of Appendix 1A (Cross-Sector Cyber Security) is too detailed for this document and that other cross-sector security issues like energy could also be included. NASEO would like to see their organization and the National Association of Regulatory Utility Commissioners (NARUC) added to the list state-level professional associations mentioned in the NIPP.

National Association of State Chief Information Officers Comments NASCIO would like to see provisions included in the NIPP for clear requirements and procedures for state and local government partners to receive TS and TS-SCI clearances. This would allow for more threat information sharing. NASCIO would also like to see Section 4.2 expanded to include state and local government security personnel to be included in developing the information sharing requirements for a Common Operating Picture.

Digital Sandbox, Inc Digital Sandbox provides some very technical comments on risk model development and valuing risk components. They express their disappointment that the Terrorist Target Selection Matrix from page 42 of the original NIPP is not included in the draft document.

Security Analysis and Risk Management Association SARMA provides a number of detailed editorial comments on sections that need clarification or expansion. SARMA notes that section 1.4.2 should include a reference to the DHS/FBI Joint Special Assessment on Potential Terrorist Attack Methods and describe the frequency with which it will be updated. They also recommend that a similar document be prepared describing potential natural or man-made hazards.

My Comments on Comments I have to admit that I have been unable to get through reading the NIPP draft. I am well used to reading government documents and regulations, but this particular document is boring beyond belief. The words are strung together in the worst example of bureaucratic writing that I have ever seen. I commend the commenters for being able to get through the document, much less comment intelligently on it.

Friday, November 14, 2008

Draft 2009 National Infrastructure Protection Plan

DHS published a request for public comment on the draft revision to the National Infrastructure Protection Plan (NIPP). This draft document is based on a DHS triennial review of the NIPP and the public comments that it had requested earlier this year (see: “Triennial Review of National Infrastructure Protection Plan”). Comments need to be submitted (Docket # DHS-2008-0112) by December 1st, 2008.

What is the NIPP? The preface to the draft describes the NIPP and its 18 supporting Sector-Specific Plans (SSPs) as: “an integrated network of Federal departments, State and local government agencies, private sector entities, and a growing number of regional consortia—all operating together with a largely voluntary CIKR (critical infrastructure and key resources) protection framework”. The preface goes on to describe the updated draft NIPP this way:
“The current document was developed collaboratively with CIKR partners at all evels of government and the private sector. Participation in the implementation of the NIPP provides the government and the private sector the opportunity to use collective expertise and experience to more clearly define CIKR protection issues and practical solutions and to ensure that existing CIKR protection planning efforts, including business continuity and resiliency planning, are recognized.”
Public Comments I’ll be taking some time to read the 200+ page document. Then I’ll take a couple of blogs to discuss the parts that have a potential to have an impact on the high-risk chemical facility community.
 
/* Use this with templates/template-twocol.html */