Showing posts with label Pipeline Corporate Security Review. Show all posts
Showing posts with label Pipeline Corporate Security Review. Show all posts

Saturday, September 28, 2013

OMB Approves TSA Pipeline CSR ICR Extension – SCADA Included

Yesterday the Office of Management and Budget announced the approval of the TSA’s information collection request (ICR) renewal for the questionnaire used in their Pipeline Corporate Security Review (CSR) program. The 60-day request notice was published in February and the 30-day request notice in May.

The ICR

TSA and OMB both reported that the renewal request was made ‘without change’, but as I noted I my post on the 60-day request there were two changes; an increase in the number of annual reviews from 12 to 15 and a change in the annual cost burden from $11,076 to $0. The ICR request clearly identified the change in reviews but did not explain the cost change. The OMB notice explains the reason for the cost change:

“TSA's 2011 submission to OMB erroneously listed the cost of hour burden to industry in Question 13 of the supporting statement. That cost has been removed from the current submission resulting in a decrease of $11,076.48 in cost burden.”

Too bad we don’t get to see the ‘supporting statement’ to see exactly how question 13 is worded. It might explain why there are no costs to the public from most of these federal collection efforts. I’ll look into that.

Pipeline SCADA Security

One of the interesting things that we only get to see once the ICR is approved is a copy of the form that the agency provided to OMB for approval. It sure would be nice if that was publicly available during the comment process. In this case there appears to be some interesting differences between the previous form and the new form.

I don’t recall looking at the old form before today, but I took a good look at both and was both pleased and disappointed at the control system security coverage on the questionnaire. Keeping in mind that the TSA Ground Security Inspector is almost certainly not acquainted with ICS use, much less a cybersecurity expert, the questions in the SCADA section of the questionnaire provide a pretty good overview of the cybersecurity situation for the pipeline SCADA systems.

There are two questions that were added to the new questionnaire:

6. Does your corporation have a backup control center?
8. Do you restrict any remote operation of your SCADA system from portable electronic devices other than the pipeline control center?

Actually question 8 was re-worded to reflect that by definition SCADA systems are remotely operated. I guess the TSA folks got tired of the strange looks they got when they asked the old question; “Can your corporation’s SCADA system be controlled remotely?”

The most technical question is #15; “Which of the following features does your corporation use to secure your SCADA system(s)?” It then list the following possible security features:

• Locked facilities
• Strong passwords
• Communication gateways
• Access-control lists
• Authenticators
• Separation of duties
• Invocation of least privilege—only able to access information and resources that are necessary
• Keycards
• Access lists
• Entry logs
• Firewalls
• Demilitarized zone (DMZ)
• Intrusion-detection system
• Intrusion-prevention system
• Maintain patches

Admittedly it would take a cybersecurity specialist to review the actual implementation of these ‘features’ to ensure that they were effective, but I think most folks would agree that organizations that had all of these in place would be well on their way to having a fairly secure control system. And remember, there is no such thing as a ‘secure control system’ or a ‘secure’ anything for that matter. What one expert can secure another expert, given the time and resources, can bypass.

No Reference to ICS-CERT

The disturbing thing about this questionnaire is that there is no reference to ICS-CERT anywhere in the document. Now I understand that TSA and NPPD (the parent organization for CERT in general) are not in the same agency (Okay, if you call DHS an agency….) but there are a number of places where the questionnaire ask for other agencies that are contacted or coordinated with and even local law enforcement is included, but not ICS-CERT.

In my opinion ICS-CERT should have been included in the possible responses to the following questions:

• Does your corporation have an ongoing relationship with the following entities/departments/ agencies/organizations?
• From whom does your corporation receive threat information to assist in your SVA?
• Which of the following external agencies/organizations is on the corporation security incident, threat or suspicious activity notification list?
• Which organizations does your corporation work with during a security incident?


Oh well, maybe next time.

Tuesday, November 30, 2010

TSA Pipeline Corporate Security Review 30-Day ICR

Yesterday the Transportation Security Administration (TSA) published a 30-day information collection request (ICR) notice in the Federal Register for the proposed Pipeline Corporate Security Review (PCSR) program. This would be a follow-up to their 60-day notice that I discussed back in August. TSA proposes to conduct “likely 12” (75 FR 73117) of these PCSRs each year at selected facilities from up to 2,200 potential locations.

Public comments on this ICR are being solicited and should be submitted by December 29th, 2010. Comments should be submitted the Office of Management and Budget’s Office of Information and Regulatory Affairs. Those comment submissions should be addressed to Desk Officer, Department of Homeland Security/TSA, and sent via electronic mail to oira_submission@omb.eop.gov or faxed to (202) 395-6974.

ICR Description Revised

The information provided in this ICR notice is substantially less complete than that provided in the earlier 60-day notice (75 FR 42086-87). Since the reference to the earlier notice does not mention if comments were received, it is not clear if this constitutes a change in the ICR because of comments received on the original notice or if this is just due to a condensation of the description. To be fair the current notice lists the description as an ‘Abstract’ rather than a full listing of the ‘Purpose and Description of the Data Collection’.

There are, however, two apparent substantive differences in the descriptions of the information collection processes. The first difference involves the scope of the information collection. In the 60-day notice the on-site visit is specifically described as a two-phase visit. The first portion would be conducted at the corporate headquarters with follow-ups at “one or two of the owners/operators assets to further assess the implementation of the owner's/operator's security plan” (75 FR 42086). There is no such reference to assessing security plan implementation in the current notice.

To my mind the most important difference in the two ICR notices is that the current notice contains no mention of TSA’s responsibility to protect the information collected. The original submission contains the following language:

“TSA assures respondents that the portion of their responses that is deemed Sensitive Security Information (SSI) will be protected in accordance with procedures meeting the transmission, handling, and storage requirements of SSI set forth in 49 CFR parts 15 and 1520.” (75 FR 42087)
One would like to assume that this lack of SSI language is merely a bureaucratic oversight, but if I were a pipeline operator I would prefer to have this clearly documented since there is no specific regulatory mention of such protections, there being no current pipeline security regulations.
 
/* Use this with templates/template-twocol.html */