Showing posts with label Water Facility Security. Show all posts
Showing posts with label Water Facility Security. Show all posts

Wednesday, November 7, 2018

S 3021 Changes Water Security Requirements


Thanks to Jake Brodsky for pointing me at an article about recent legislation affecting water treatment and waste water treatment cybersecurity. I did not cover S 3021, the America’s Water Infrastructure Act of 2018, when it was amended in the House (it was introduced as a courthouse name change bill in the Senate) as I did not see any cybersecurity or chemical security references in the long table of contents. Ooops, they slid in in as “SEC. 2013. COMMUNITY WATER SYSTEM RISK AND RESILIENCE”.

Cybersecurity Assessment


Section 2013 re-writes $1433 of the Safe Drinking Water Act (42 USC 300i–2) the current law regarding EPA’s regulation of security at water treatment facilities and waste water treatment facilities. The focus of §1433 is changed somewhat as reflected in the change of the title from “Terrorist and other intentional acts” to “Community water system risk and resilience”. Similar wording changes are found throughout the revised section.

The item that caught the author’s attention is found in the new §1433(a)(1)(A) risk assessment requirements:

“(A) shall include an assessment of—
‘‘(i) the risk to the system from malevolent acts and natural hazards;
‘‘(ii) the resilience of the pipes and constructed conveyances, physical barriers, source water, water collection and intake, pretreatment, treatment, storage and distribution facilities, electronic, computer, or other automated systems (including the security of such systems) [emphasis added] which are utilized by the system;

Interestingly, the new language in §1433(a) makes two other significant changes to the assessment requirements. First it removes the requirement for providing the EPA with a copy of the assessment; it only requires a brief certification statement to be submitted to the EPA. Secondly, it reduces the disclosure protections for the assessments; removing protection from disclosure requirements of 5 USC 522. Fortunately, no information of is being provided to the EPA that could be required to be disclosed under §522 beyond the certification statement.

Cybersecurity Emergency Response Plans


The emergency response plan requirements of §1433(b) have also been revised to include specific cybersecurity requirements. In addition to the formatting changes made to this paragraph, it now includes:

(1) strategies and resources to improve the resilience of the system, including the physical security and cybersecurity of the system; [emphasis added]

Again, the new language only requires covered entities to provide certification to the EPA that the emergency response plans have been prepared.

Alternative Programs


Paragraph (f) of the revised section allows facilities to meet the assessment and/or planning requirements by satisfying “technical standards that are developed or adopted by third-party organizations or voluntary consensus standards bodies that carry out the objectives or activities required by this section” {new §1433(f)(2)}.

Funding


Paragraph (g) establishes the Drinking Water Infrastructure Risk and Resilience Program which includes provisions for grants and technical assistance to support the assessment and response plan requirements of this section. It also authorizes $25 million for the Program for FY2020 and FY2021, with $5 million of that earmarked for ‘technical assistance’ and $10 million for grants to small (supporting less than 3,300 people; facilities that are not required to comply with §1433) facilities.

Commentary


This bill does very little to change the EPA’s oversight of security of water treatment or waste water treatment facilities. It does not require the EPA to review or approve the assessments or emergency response plans, nor even give them the authority to suggest changes to those activities. The additional cybersecurity language simply recognizes that the control systems at these facilities are potentially subject to attack or internal malfeasance and that their security should be addressed by facilities.

The ludicrously small amount of money remaining for grants to covered treatment facilities or works how little Congress appreciates the scope of the problem.

Thursday, March 30, 2017

HR 1579 Introduced – Drinking Water Security

Earlier this month Rep. Peters (D,CA) introduced HR 1579, the Secure and Resilient Water Systems Act. This bill would completely re-write the current drinking water security requirements of 42 USC 300i-2. It expands the current counter terrorism requirements to include protecting against climate change and source water degradation to enhance system security and resiliency.

Vulnerability Assessment


The new paragraph (a) would require community water systems to prepare new vulnerability assessments and submit them to the EPA within 24 months of enactment of the bill. The bill would require those assessments to identify threats to {§300i-2(a)(2)}:

• Source water from industrial activity, pipelines and storage tanks, contaminated sites, agricultural activity, and oil and gas exploration;
• Source water and distribution system from climate change, extreme weather, drought, and temperature changes; and
• Source water and distribution system from intentional acts, including intentional contamination, sabotage, and theft of any chemical of interest (as designated under Appendix A to 6 CFR 27).

The assessment would also be required to include “a comparison of the disinfection methods used by the community water system and reasonably available alternative disinfection methods, including a determination of whether reasonably available alternative disinfection methods could reduce the community water system’s vulnerability to the threats identified” {§300i-2(a)(2)}.

Protection Plans


Each community water system would be required to submit to the EPA a source water and distribution system protection plan. The submitted plan would {§300i-2(b)}:

• Identify strategies and resources to mitigate the threats identified in assessments prepared; and
Include specific emergency response plans for the threats identified in assessments.

Grants


The bill would establish the Drinking Water Infrastructure Resiliency and Sustainability Program to provide grants “for the purpose of increasing the resiliency or adaptability of the community water systems to threats identified” {§300i-2(c)(1)}. The grants could be used to {§300i-2(c)(3)(B)}:

• Promoting more efficient water use, water conservation, water reuse, or water recycling;
• Using decentralized, low-impact development technologies and nonstructural approaches, including practices that use, enhance, or mimic the natural hydrological cycle or protect natural flows;
• Reducing stormwater runoff or flooding by protecting or enhancing natural ecosystem functions.
• Modifying, upgrading, enhancing, or replacing existing community water system infrastructure in response to changing hydrologic conditions;
• Improving water quality or quantity for agricultural and municipal uses, including through salinity reduction; or
• Providing multiple benefits, including to water supply enhancement or demand reduction, water quality protection or improvement, increased flood protection, and ecosystem protection or improvement.

The bill would authorize $50 Million for each year from 2018 through 2022 to support the bill.

Moving Forward


Peters is a senior member of the House Energy and Commerce Committee to which this bill was referred for consideration. This means that he may have enough influence to have the Committee consider the bill.

The inclusion of ‘climate change’ language and inherently safer technology reporting provisions will automatically raise the ire of many Republicans on the Committee. Their inclusion almost guarantees that the Committee will not favorably consider the bill without modifying those provisions. Peters will almost certainly have to agree to such changes prior to the Committee considering the bill.

Commentary


The bill greatly expands the security considerations that community water systems need to require in both the vulnerability assessment and response plans currently required. This expansion is more than a little justified, particularly after looking at the fiasco associated with the aftermath of the Freedom Industries chemical spill in West Virginia.

I covered a number of issues about water facility planning and response that probably should be taken when there are potential chemical contamination issues from industrial chemical sources in a series of blog posts about the lessons learned from the Freedom Fiasco. It would have been nice to see this bill address at least some of those issues in some more detail.

I am very happy to see the bill specifically address chemical security issues. Unfortunately, it only addresses the threat of theft of DHS chemicals of interest (COI). This would probably only be an issue for smaller water facilities that use 150-lb cylinders of chlorine gas; stealing chlorine gas from rail cars or even 1-ton storage cylinders is much less of a problem. What should have also been included was the threat of deliberate releases of COI; a much larger potential terrorist threat.

The major shortfall of this bill (and the original 2002 legislation) is that there is no provision for the EPA to review and approve either the vulnerability assessment, the response plans, or the implementation of those plans. The additional requirement to submit the response plans to the EPA was a step forward over the existing keep on file requirement, but there are no provisions for the facility to have adequately implemented the response plans.


Another system security problem that is virtually ignored by this bill is the problem of water control system cybersecurity. There are increasing amounts of automation being used by even smaller water treatment systems for increased efficiency and manpower reduction efforts. Failure to specifically address the protection of these automated systems from deliberate attacks is a major shortcoming of this bill.

Finally, the funding provided for the grant program is more than ludicrously small. The original, significantly more limited requirements, were supported by $160 million in funding for the first year. Interestingly, none of the grant monies could be used to protect facility physical, cyber or chemical security work.

Saturday, February 23, 2013

HR 654 and Water Facility Security


As I noted in an earlier blog, Rep Harper (R,MS) introduced HR 654, the  Grassroots Rural and Small Community Water Systems Assistance Act. This bill would amend the Safe Drinking Water Act (42 U.S.C. 300f et seq) to reauthorize and address funding priorities for technical assistance to small public water systems.

While the bill does not directly affect the language for the protection of water systems from terrorist attack of 42 USC 300i-2, it would, in passing, possibly provide some funding support for such activities. It would add §300j(1)(e)(8)(A):

“The Administrator may use amounts made available to carry out this subsection to provide technical assistance to nonprofit organizations that provide to small public water systems onsite technical assistance, circuit-rider technical assistance programs, onsite and regional training, assistance with implementing source water protection plans, and assistance with implementing monitoring plans, rules, regulations, and water security [emphasis added] enhancements.”

The congressional findings section of this bill implies that small water systems are those that “serve a population of less than 10,000 individuals” {§2(3)}. This is well above the 3,300 minimum used for the security requirements of public water treatment facilities. And the funding described in this bill is separate from the anti-terrorism program funding provided for small public water treatment facilities in 42 USC 300i-2(e).

At this point it is not clear to me how likely this bill will be to make it to the floor in the House. I don’t see anything in the bill that would interfere with a bipartisan vote in either the House or Senate. It is just a matter of how much of a priority the leadership would place on moving this to the floor for consideration. I would not be surprised to see this added to an EPA funding bill if one gets considered in the 113th Congress.

Tuesday, July 10, 2012

Reader Comment – 7-10-12 – DHS PSA and Water Systems


There was a very nice comment from hdk posted to my post from earlier today about the DHS water facility inspection.  It’s a lengthy and detailed alternative explanation that makes more sense than the newspaper account; it describes a little known DHS program, the Protective Security Advisor program in NPPD.

Protective Security Advisors


The PSA program is another undermanned and underfunded program that receives little attention. I’ve briefly mentioned them twice here in this blog (April 2010 and December 2010),  but they don’t receive much press (which is probably a good thing given the way government agencies usually get noticed).

The comment by hdk notes that PSA’s routinely work with water treatment facilities in their area of operations, doing vulnerability assessments, information sharing and just plain establishing contacts with operators.

A facility of this size is probably not one that the regional PSA team would initiate contact with, but if the facility had requested a vulnerability assessment, it almost certainly would have been worked into the schedule. While this facility hardly counts as critical infrastructure on the national scale, it is certainly important to their local community. If the regional PSA team could find the time to do the review, it was a good thing for the facility, the region and DHS.

ICS-CERT Involvement


There is only one thing that hdk points out that I take objection to. First off it is obvious that hdk knows a lot more about the PSA program than I do (not that hard, but I suspect that hdk is directly associated with the program). So I believe him when hdk says:

“While your comment on the size of the Athens facility would place it below the radar of DHS, it's not outside of the realm of possibility that the PSA may have offered up ICS CERT monitoring capabilities.”

ICS-CERT is even smaller than the PSA program and their expertise is even in shorter supply than the general security knowledge of the PSA team. Having them babysit a new control system implementation to verify that it is working properly is a misapplication of that resource. If there had been an attack on the system it would be a valuable deployment of ICS-CERT resources as it could be a potential trial run of later attacks on larger systems. But to just sit and watch a system to ensure that it is secure, no that would be a gross misuse of a scarce and valuable resource.

I’m not even sure that having a PSA member monitoring this deployment would be a legitimate use of limited resources. There could, of course, be some political reason why such a move might be an appropriate expenditure of time and personnel for the PSA Regional Commander.

Of course hdk doesn’t actually say that ICS-CERT did (or more appropriately will) take part in this cyber-system evaluation. It is much more likely, in my mind, that it would be a PSA follow-up operation.

DHS vs EPA and Water Systems


One final point; if the PSA teams from DHS are making it a routine point to help water systems with their security assessments it is only because the EPA water facility security program, as mandated by Congress, is a completely ineffective security program. That isn’t really the EPA’s fault; Congress made EPA responsible for the security program but did not give them any real authority to enforce any security measures.

That DHS has an underfunded program that is able to step up and actually help small water systems evaluate their security programs and make suggestions for improving that security is sufficient reason, in my mind, to encourage Congress to make the security of water treatment systems part of the responsibility of NPPD and DHS instead of the EPA. DHS has got to be more effective.

Friday, April 1, 2011

Lautenberg Introduces Chemical Security Legislation

Yesterday Sen. Lautenberg (D, NJ) introduced two chemical security bills; S 709, the Secure Chemical Facilities Act, and S 711, the Secure Water Facilities Act. Neither is yet available from the GPO, but Lautenberg’s press release on the two bills provides links to final draft versions of the bill. At first glance they appear to be re-submissions of bills that he introduced in the last session. These bills went no where last session and will receive less support in this session.

Thursday, January 20, 2011

House Energy and Commerce Committee on CFATS

Yesterday the website TheHill.com reported that “[c]hemical plant security standards” were on the agenda this session for consideration by the House Energy and Commerce Committee. That article also contained a link to a Committee document, “Backgrounders: Key Issues before the Committee on Energy and Commerce 112th Congress, First Session”.

On page 4 of that document under the ‘Environment and Economy Agenda’ the CFATS regulations are discussed. The document explains:

“Created in the Fiscal Year 2007 appropriations, CFATS sunsets in March 2011. Appropriations Acts have carried one year extensions for the past two years. Even though the program is not fully implemented, some in Congress and the Obama Administration support efforts to dramatically expand the CFATS program into non-security areas. We should highlight how the program has not yet been fully implemented and that expansion beyond security against terrorism could kill domestic investments and jobs. Any program extension should preserve the original focus on security against terrorism.”
The same section also addresses security issues at water facilities:

“As for the Bioterrorism Act, Title IV, enacted in 2002, we should only require water utilities to update and submit their vulnerability assessments and site security plans. Providing EPA regulatory authority could lead to a program that deviates greatly from the security mission authorized by Congress.”
Both of these policy statements are not much of a surprise given the Republican control of the House, and they appear to be fairly closely aligned with the opinions that Rep. King (R, NY), Chairman of the House Homeland Security Committee, has expressed on many occasions. I would expect that some sort of reauthorization legislation will pass relatively easy in the House as long as it doesn’t get lost behind other higher priority issues.

The question, of course, will be similar to last session, can a House passed bill make it through the Senate. The dynamic will be different this year in that there with the number of Republicans and Democrats very close. Controversial legislation could be stymied by a failure of either side to garner enough votes to close debate. Further complicating the issue is the debate on filibuster rules that was interrupted by the Senates long delay in coming back into session (they are not scheduled to return until next Tuesday).

Tuesday, November 16, 2010

Water Facility Security in the Wiki Bill

One of the things that I did in my draft chemical facility security bill was to include water facilities in the chemical security program. I didn’t do this by modifying the current water facility security rules like Sen. Lautenberg did in S 3598 in the current session or the House did in the version of HR 2868 they passed last year. I just removed the language in the §550 authorizing language that exempted those facilities from coverage under the current CFATS program.

The reason for this is that the current water facility security program focuses mainly on the prevention of contamination of drinking water supplies. This is an important function in its own right and one that is probably better dealt with by water treatment experts. The processes that must be understood to deal with the security of the drinking water supply are significantly different than those processes affecting chemical facility security.

The protection of the chemicals at those facilities that would normally fall under the CFATS mandate (chlorine, anhydrous ammonia, and the like) will require the same types of security protocols, however, where ever they are located. So to me, it makes eminent sense to regulate the security of those chemicals under the CFATS program where ever they are found.

Chemical Security Sanctions

One of the main objections that the water treatment community has had with adding their facilities to the CFATS program is that those regulations give the DHS Secretary the authority to shut down non-complying facilities. Obviously no one expects water facilities to defy DHS, but the thought of the Secretary potentially shutting down a water facility that was fulfilling its water distribution function just does not make sense to the water treatment community.

I dealt with this by specifically exempting them from that sanction in the §550 authorization in §2(a)(4) of my proposed bill. I also realize that there must be provisions for some sort of sanctions against facilities that refuse to comply. I address this by having those sanctions applied through the Administrator of the EPA. Presumably the EPA would have a better understanding of the water treatment facility’s unique situation and would be better able to apply those sanctions.

Conflicts with Water Security Rules

Many water facility operators will undoubtedly be concerned that their coverage under the CFATS program will conflict with their security programs under the water system security programs. This is of course the same concern that many chemical facility operators had when CFATS was going to be applied to them in 2007. Existing security procedures are not invalidated by the CFATS program; they are incorporated in the CFATS process.

It is almost inevitable that additional security procedures will need to be implemented at these water facilities. Even facilities with extensive security measures will have holes in their program. This is a consequence of the fact that there has been no independent risk-based review of the security program. CFATS will certainly provide that.

Need for CFATS Coverage

Why shouldn’t we utilize the Lautenberg model of chemical security? The big problem is that there are no inspectors to insure that chemical security measures are adequate. I don’t understand how anyone expects that there will be adequate security measures put into place if there is no inspection program to ensure compliance, but that is how the water facility security program works.

Part of the reason for that is that the water security program is managed by each State. If the federal government mandated that the States added an inspection program to their current voluntary management of water treatment facilities there would have to be federal funding to support that requirement.

For EPA to have an effective security program that actually ensures that the chemicals used and stored at water facilities are adequately protected from potential terrorist attack they would have to establish an inspection program. To ensure that the inspection force (either federal or State) is adequately prepared to validate security measures, the EPA would have to initiate an inspector training program. If the chemical security program were designed in the way envisioned in S 3598, that training would have to be offered to each State’s inspection force.

Wiki Participation

I think that removing the current exemption of water facilities from CFATS coverage is the most reasonable way of ensuring that the extremely hazardous toxic inhalation hazard chemicals used at many of those facilities are adequately protected. I am also smart enough to know that I don’t have exclusive franchise on chemical security knowledge. Others may have other ideas on how to deal with these issues, and it is inevitable that adding some of those ideas to mine will result in a better legislative product.

That is one of the nice things about this project at WriteTheBillWiki. It allows for a collaborative approach to preparing legislation. Anyone can register with the system and take part in both the discussion surrounding the draft legislation, or even amend the actual language of the bill.

I would certainly like to invite all of my readers to actively participate in this project.

Tuesday, November 9, 2010

Water Security and HR 2868

Bridget O’Grady over on the Security Notes blog at ASDWA.org has an interesting post about Sen. Lieberman wanting to see a floor amendment adding water facility coverage under CFATS to the HR 2868 debate if it comes up in the Lame Duck session. She doesn’t provide a source for his comments, but he did make similar comments during the last hearing his committee had on HR 2868.

He also noted in that hearing that he expected to see the IST provisions brought out as a possible floor amendment if/when HR 2868 came up for debate. If the IST provisions are added, I don’t see a cloture vote passing on the final bill. Without IST requirements, the inclusion of water facilities (water treatment and waste water treatment) might not be a killer amendment to the final consideration of HR 2868.

Any water amendment that wanted even a modicum of support (more likely the lack of vociferous opposition) from the water treatment industry would have to include provisions that would prohibit the Secretary from closing down non-complying water treatment facilities. Adding a water facility security grant program would quiet opposition to this even more. Making this just a chemical security issue with these two provisions might be passable in the Lame Duck session.

I have heard that DHS figures that such an elimination of the water facility exemption from CFATS would probably double the number of facilities covered under the program. I would expect that it would also significantly increase the number of Tier 1 and Tier 2 facilities. This would be a fairly large increase in the work load for chemical facility security inspectors, but that could be addressed in adding authorization for some more much needed inspectors in the amendment.

On the other hand the delay involved in the rule making process might mitigate that work load increase. It might also provide more time for more facilities to reconsider their decision to continue to use toxic inhalation chemicals instead of less hazardous alternatives and provide a positive inducement to make that change. That would further reduce the increased work load.

Wednesday, October 13, 2010

Water Security Congress

On Monday, the ASDWA Security Notes Blog posted information on last month’s 2010 Water Security Congress conducted by the American Water Works Association (AWWA). While most of this meeting was focused on security issues that did not specifically deal with chemical issues at water facilities, there were a couple of presentations that might be of interest to the general chemical security community. For readers from the water community may want to look at the general AWWA page on the meeting.

Water ISAC

There was an interesting presentation made by Aaron Levy discussing the Water Sector Information Sharing and Analysis Center (WaterISAC) that he heads. This is an organization run by the Water Sector Coordinating Council, part of the National Infrastructure Protection Program. It provides an information sharing environment for all sorts of water sector protection activities including a secure portal for sharing intelligence information. I have not seen a comparable organization coming out of the Chemical Sector Coordinating Council.

One of the interesting issues raised in Levy’s presentation is the problem of financially-motivated vandalism. Water facilities have a security issue that is much more prevalent than terrorist attacks, the theft of metal (pipe and wire) from their extended facilities; a problem aggravated by the poor economy.

Stuxnet was briefly addressed in the presentation both as a threat to water system control systems, but also as a threat to the electrical power supply critical to the operations of these systems. This is an issue that should also be of concern to chemical facility operators.

I want to take an opportunity to commend Mr. Levy for the format of his presentation file. Most presenters provide copies of the presentation slides for these type files. The WaterISAC presentation not only includes the slides, but the notes that he used in his presentation. This provides a lot more information and provides more of a flavor of the actual presentation. Still not as good as a video file, but Levy is to be commended for taking this innovative step.

Utility Security

This presentation by John W. McLaughlin, from Jacobs-JJG (engineering firm), looks at the switch from security being a counter-terrorism matter to a more inclusive ‘all-hazards’ approach. He notes that many utilities do not see themselves as a terrorist target and may see counter-terrorism measures as a diversion of funds that could be better spent elsewhere.

He notes the enlarged focus of security at the national level is now looking beyond just the possibility of terrorist attacks and is addressing all sorts of security issues. A major new focus at the national level is ‘resiliency’, the ability to get the water system up and running after an attack, vandalism, systems failures, or natural disaster.

This discussion about the need for resiliency is certainly an increasingly important focus at DHS. Prevention of production disruptions from all causes is important, but resilient facilities recognize that all disruptions cannot be prevented. I’ve noted for some time in this blog that recognition of the practical inability to prevent all terrorist attacks requires planning for emergency response to deal with resulting chemical releases, fires and explosions. Resiliency looks even beyond that, at what happens after the emergency response is done.

While chemical facility management certainly has an interest in getting their facility back on line, they don’t have the same urgency in this matter that public utilities have. An off-line chemical facility will not typically cause life changing problems for all of their neighbors and customers. A shutdown water plant, on the other hand, adversely affects the entire community until it gets back on-line.

Water and CFATS

Bryon O. Elwell, from ABS Consulting, provided an overview of both the current CFATS regulations and the pending legislation in Congress that might affect security operations at water and waste-water treatment facilities. The information in the slides was well put together, especially the summary data on S 3598, the Secure Water Facilities Act.

Elwell presented some facts that I haven’t seen pulled together before. He noted (slide 18) that there were 1,200 waste water treatment plants that had more than 2,500 lbs (CFATS SQT for Chlorine) of Chlorine gas on-site and 1,700 water treatment plants that were covered by EPA’s risk management plan rules (and presumably would be covered by CFATS rules). He also provided (slides 19 and 20) a more complete listing of water treatment chemicals that are DHS chemicals of interest (COI) than I have seen to date.

Water Cyber Security

I was pleased to see that there were three separate presentations on control system cyber security (CSCS) matters; all of them should be reviewed by any organization with an automated industrial control system. The first was by Candace Chan-Sands, from EMA, Inc. who’s presentation looked at the DHS ICS-CERT Cyber Security Evaluation Tool (CSET). This is a service provided by DHS ICS-CERT to evaluate the security environment for a facility’s control system. Some how I have overlooked this service listed on the ICS-CERT web site; I’ll cover this in more detail in a separate blog post.

The second presentation was by W. Michael Sutton, an engineer with Malcolm Pirnie Inc. He looked at both the development of the ISA-99 cyber security standards under development. He pointed the audience at ANSI/ISA-99.02.01-2009, the Security for Industrial Automation and Control Systems: Establishing an Industrial Automation and Control Systems Security Program, published in 2009. He did not provide a link to the ANSI site for obtaining the document; here it is. He also provided a brief look at control system design and technologies available to help secure cyber assets.

The third cyber-security presentation was made by Jeff Mills, from Coalfire, an IT Audit and Compliance Management firm. This is a pretty good, if high-level, review of the control system security problem, but it does not address the peculiar ICS issues with implementing many IT security measures. There is, however, a very good description (slide 25) of general control system security measures that would apply to any facility using ICS systems.

Posting Presentations

I always appreciate it when organizations like the AWWA post their presentations on-line. I don’t have the travel budget to get to these meetings and there is a wealth of good information presented at meetings like this. Most people in the public water supply industry have similar budget constraints making the posting of these presentations a valuable service to the industry. I would like to make my standard presentation recommendation to AWWA; next year, how about providing videos of the presentations on-line.

Personal Complaint Warning: I am always upset when an organization posts .PDF documents with excessive security settings. Why would anyone be concerned about someone copying and pasting from the document. It makes the job of reviewers like myself that much more difficult. This is especially true when the document includes URL’s, its bad enough that the listed URL’s were not live links, but then they were protected against copying. What a PAIN! Please re-think your document security policy.

Friday, August 13, 2010

Water Security Congress

Today the ASDWA Security Notes blog announced that registration is now open for the AWWA’s 2010 Water Security Congress. As I have mentioned before, water security is not chemical facility security (water treatment facilities are currently exempted from CFATS by specific language in the §550 authorizing legislation) but chemical security is an important component of water facility security for many water systems. Looking at the WSC10 technical program web page we can certainly see that the organizers of this annual get together certainly realized it this year. There are a number of presentations and one workshop that address chemical security related issues. On Sunday (09-19-10) there will be a workshop on the new voluntary consensus security standard (AWWA/ASME-ITC) for water facilities, J100-10 Risk And Resilience Management Of Water and Wastewater Systems, based on the RAMCAP – Plus methodology. This is one of the justifications that I mentioned in a previous blog that the AWWA is using to support their opposition to CFATS coverage for water treatment facilities. A Tuesday afternoon session on chlorine and cyber security will include a presentation on the legislative changes that are being proposed for the CFATS program. Of course the two of interest to this community is the removal of the water facility exemption and then the IST proposals. A second presentation in that session will look at IST evaluations in detail; specifically addressing drivers for chlorine substitutes. The remainder of that session will look at cyber security issues for industrial control systems.

Wednesday, August 11, 2010

Water System Lobbying

I ran into an interesting blog post at ISAQQA-WUC.Blogspot.com about efforts of member utilities of the American Water Works Association to oppose passage of legislation that could allow the imposition of changes in disinfectant chemicals on water treatment and waste water treatment facilities.

The AWWA has opposed bills like the House passed version of HR 2868 and the recently introduced S 3598. They are now calling for members to contact their Senators to ask them to support the version of HR 2868 ordered to be reported by the Senate Homeland Security Committee. This very long blog post provides an interesting and detailed discussion of how utilities, which have access to little money for lobbying efforts, can best conduct a campaign to influence their legislators. Anyone intending to conduct a low-cost campaign to influence legislation should review this blog post before they seriously start to plan their own campaign.

Chemical Security Situation 

Of more interest to readers of this blog is the background information on chemical security issues at water treatment facilities. There is a very good summary of the current requirements for security and the types of chemical security responses that many facilities have taken. Careful reading of this section of the blog shows why there really does need to be some sort of water treatment facility language in any comprehensive chemical security language that would extend current CFATS rules.

First the posting explains that current rules require these facilities to conduct a security vulnerability assessment (SVA) and emergency response planning (ERP). There is no standard for the SVA or ERP and there is no real requirement to establish and execute a security plan to protect the vulnerabilities identified. Finally there is no authority for state or federal regulators to review the SVA or ERP or allow them to require correction of deficiencies.

Like various chemical industry organizations the AWWA also likes to brag on the efforts that have been made at member facilities to protect chemicals like chlorine gas. The main difference here is that there is no mandatory security program that member facilities have to adhere to. All of the programs that the AWWA describes here are completely voluntary and this is reflected in the following statement made in the blog post: “Most [emphasis added] have restricted access and enacted other measures to secure critical assets, including chemical supplies.”

One last time I would like to point out that no outside agency has the authority to determine if the ‘restricted access’ and ‘other measures’ provides an adequate degree of security for the facilities that have taken such measures. And no government agency can require the facilities that have not take such measures to do so.

Remove CFATS Exemption 

If the AWWA really wants to preempt efforts in the Senate to require consideration, and a possible mandate to implement, disinfectant substitution they may want to consider finding some Senator to submit a proactive floor amendment to HR 2868 that would remove the current CFATS exemption for water treatment and waste water treatment facilities. If the AWWA were to craft such language to include provisions for denying the Secretary the authority to shut down water facilities and included a grant program for security measures at public treatment facilities, there would be little reason for water facilities to object to CFATS inclusion.

Facilities that have actually addressed security issues would get credit for those efforts in implementing CFATS SSP requirements. Only facilities that have done little to protect the public from the consequences of a potential terrorist attack would expect to have to take extensive actions to get up to CFATS standards.

The benefit to the AWWA and its members would be that they could then point at the CFATS coverage as a reasonable alternative to S 3598 and its included IST measures. While the activists that would like to see chlorine gas removed from all of these facilities would not accept that argument, it is likely that many Senators would accept the increased security provided by CFATS requirements as an adequate first step to protecting the adjacent communities.

Friday, May 28, 2010

Water Facility Security Training

I ran across an interesting training notice on Facebook for a training class for water facility personnel to prepare utilities for the security and safety requirements under House of Representative’s Bill HR 3258, the “Drinking Water System Security Act of 2009.” The class will be held the week after next in Murfreesboro, TN. According to the notice:
“Utility operators will become familiar with the requirements of this Bill and how to comply with the Bill. Free RAMCAP compliant software is available to help systems prepare risk-based security plans, and alternative chemicals and processes to replace compressed gases.”
Now HR 3258 was incorporated in HR 2868 as Title II of that bill and was subsequently passed in the House. Readers of this blog will know that I do not believe that this bill will come to a vote in the Senate this year. Having said that I am nearly certain that a similar bill will come up next year and there will be some sort of provisions for water facility security in that bill. I’m not sure what ‘RAMCAP compliant software’ Taud Training Station is using, but the RAMCAP program was one of the bases for the development of the current CFATS tools. Additionally, addressing the issue of ‘alternative chemicals and processes’ (I like that better than IST) should certainly be of benefit to water system operators even if there is no IST mandate in future legislation. A six hour training program will not provide in depth coverage of any of these topics, much less all of them, but it is certainly enough time to give a good overview and point participants in the proper direction for further training. I don’t know anything about the Taud Training Station or any of the specifics of their proposed training, but the info provided on the Facebook page certainly would be enough to get me to make a call to John Shadwick for further information if I was a small water system operator.

Tuesday, March 30, 2010

Water Facility Security Lacking

Last week there was an interesting water facility security breach out in Oregon. According to news reports an intruder broke into a local water treatment facility and stole the computer that operated the automated water treatment equipment at the facility, including the valves that control the addition of chlorine to the water. The article reports that “the burglar gained access to the plant by driving around a fenced and gated area through an adjacent tree farm”. The local residents can rest assured that local officials are taking action to ‘harden’ both the water treatment and waste water treatment facilities against future intrusions; too little, too late. Now current water security rules require all facilities that serve over 3,500 customers (and I am making the perhaps unwarranted assumption that this facility meets that requirement) have completed security vulnerability assessments. Unfortunately there are no provisions to allow the EPA (the water facility security enforcement agency) to require that facilities take action to correct security shortcomings. In this case the only thing that happened with the break-in was the loss of about $1,000 worth of computer equipment and significant amounts of overtime pay to cover having someone on site executing manual control of the system. What if this had been something more than vandalism or theft? What if this had been a terrorist attack on the water system? Or an attack on the chlorine used at the water system? Can anyone believe that the security system would have had any better result? This is a perfect example of why I am concerned about the lack of water facility security regulations that really mean anything. Requiring that facilities ‘conduct an SVA’ is a toothless requirement if there is no check of the adequacy of that evaluation. And an SVA does not provide any security, it just identifies the security needs. It should lead to the development and execution of a security plan and there are no current requirement for that to be done. Legislation like HR 2868 needs to be passed to give DHS or EPA the authority to provide proper regulatory oversight of the security of water treatment and wastewater treatment facilities. Sooner or later terrorists are going to see stories like this one in the Oregon newspaper and realize exactly how vulnerable our water treatment facilities actually are.

Monday, November 16, 2009

Reader Comment – 11-15-09 Water Tiering

An anonymous engineer from New Zealand had a question about the potential tier ranking of a water treatment facility that he is working on the design for. He posted the question to one my blogs about HR 3258. Its an interesting question and one that will have to be asked in a lot of facility design operations. So let’s take a stab at giving some sort of answer. Disclaimers We need to start this theoretical discussion with lots of disclaimers. First off, DHS (and likely EPA will follow suit) has been very reluctant to talk about the methodology it uses to rank the security risk for chemical facilities. Without filing an actual Top Screen for the facility, your not going to get a firm answer from anyone. I’m not sure that DHS has developed an internal procedure for dealing with facilities in development. More importantly for water facilities there will be additional complicating factors. First, HR 2868 has not yet been signed into law so numbers of changes can still be made to that legislation. Next EPA will have two years to write their regulations implementing the law. As currently written the EPA is required to ‘consult with’ DHS in establishing their chemical security rules, but that leaves a lot of leeway. Finally, since our NZ Engineer specifically asked about Tier 1 and 2 rankings, I’m going to guess that he was concerned about IST complications. Since that decision, as the bill is currently written, will be made by State agencies, that will be tougher still. I would bet that states like California and New Jersey may be more likely to require IST implementation, but that is a somewhat educated guess, not a prediction. Disinfectant Decisions One of the first decisions that must be made for a water treatment facility is the determination of the disinfection technique that will be used at the facility. I am not qualified to weigh in on the actual decision, but I can offer this; do a detailed assessment of all of the alternatives and do a formal documentation of that assessment. That assessment will form an invaluable starting point for future assessments, Remember to include the costs of security and safety in the assessment. All drinking Water facilities that serve more than 3300 will come under the new federal security rules regardless of what chemicals they use for disinfection. This means that some of the security costs will be there regardless of the chemicals used. Chlorine Gas To get an idea of the tiering for a chlorine gas facility you are going to have to identify the number of people affected by a terrorist related release of chlorine gas. DHS would require you to use the total amount of chlorine on-site for making this determination. The EPA RMP would use the amount in the largest container, but I would guess that for security the EPA will go with the DHS technique. DHS does use the EPA RMP*Comp online tool to calculate the ‘distance of concern’ for a toxic chemical release. Select chlorine gas and enter the maximum on-site inventory to get that distance. Then draw a circle with that radius centered on the facility. Then determine the maximum number of people in that circle during a normal work day. DHS uses both residents and people working in the area in this calculation. The larger the number the more likely the facility is to be a Tier 1 or Tier 2 facility. Security Costs There are two types of security costs that you are going to face when you employ a toxic chemical like chlorine gas. First you need to isolate the storage from the attacker, and then you need to provide mitigation measures to deal with a successful attack. First you are going to have to have a perimeter that looks impressive and will allow for early detection of a penetration. Next, since only the largest facilities will be able to afford having a security force on site to respond to an attack, most facilities will use local law enforcement responding to an incident. That means that there needs to be additional security layers to delay an attacker until the police arrive. If you are using chlorine cylinders like our friend from New Zealand, then keep them in a secure room in a secure building. I would keep my stored cylinders in a separate secured room from the cylinders in use. The more you can isolate the cylinders, one from another, the more difficult it will be to release the total on-site inventory in a single attack. Mitigation costs can be divided into active and passive measures. Active measures work to reduce the off-site movement of the toxic cloud while passive measures alert the potentially affected population to take appropriate action. Active measures can include water deluge systems or scrubbers protecting the tank storage rooms. Passive measures would include a reverse 911 system or sirens to warn of the release and an education program to teach neighbors how to respond to the warning. In Closing… This is, of course, just a brief over view. The American Water Works Association is supposed to be developing a computerized assessment tool. They won’t release it to outsiders like me, but it will probably help in the assessment process. The Metropolitan Water District in Southern California seems to have a pretty good handle on this situation; you might want to talk to them. I hope I have been of some small measure of help.
 
/* Use this with templates/template-twocol.html */