Tuesday, February 19, 2008

Critical Cyber Asset Identification

A key part of any vulnerability assessment is the identification of those parts of the facility that must be protected. In a perfect world everything within the perimeter fence would be protected against any potential attack. In the real world only the most critical parts of the facility can receive the high levels of protection necessary to prevent a successful terrorist attack. In this blog we will look at the electronic systems at chemical facilities to see what requires that protection.

 

FERC’s New Electronic Security Rules

 

Back in January the Federal Energy Regulatory Commission published the Final Rule on their “Mandatory Reliability Standards for Critical Infrastructure Protection” in the Federal Register. Any one that thinks that providing security for electronic control systems is simple needs to read this 185 page document. This document is a discussion of their proposed rule, industry comments on that rule and the commission’s final decisions on the issues covered. The eight Cyber Security Standards are not listed in the rule.

 

The requirements set forth in this rule were designed to protect the electrical power distribution systems of this country from terrorist attacks. As such the requirements are not necessarily directly translatable to security procedures for control systems at chemical facilities. This rule can, however, inform the discussion about how to protect chemical facilities from terrorist attack through their control systems.

 

Definitions

 

There are three definitions that are given in para 234 of the rule (page 7392) that help to set the background for the discussion of cyber security”

 

·        Cyber Assets – “programmable electronic devices and communication networks including hardware, software, and data”

·        Critical Cyber Assets – “cyber assets essential to the reliable operation of critical assets”

·        Critical Assets – “facilities, systems, and equipment which, if destroyed, degraded, or otherwise rendered unavailable, would affect the reliability or operability of the Bulk Electric System”

 

Only the last definition needs to be modified to make all three applicable to chemical facilities. Instead of reference back to the ‘Bulk Electric System’ we can make this apply to CFATS rules by substituting: “… would allow for the release, theft/diversion or contamination of a chemical of interest listed in Appendix A to 6 CFR part 27.”

 

There is one other term that crops up repeatedly in the FERC rule; “responsible entity” and it refers to “Bulk-Power System users, owners, and operators” (para 7, page 7369). Again we can modify that to refer to “owners and operators of high-risk chemical facilities” to translate the FERC rule discussion into terms more applicable to CFATS.

 

Define Risk-Based Assessment Methodology

 

The first thing that a responsible entity is required to do (para 237) under these new reliability standards is to establish a methodology for determining whatassets are critical assets. Much as DHS has recognized that there is no set of security protocols that apply to every chemical facility, FERC realizes that the wide variety of systems in the Bulk Electric System will require a variety of assessment methodologies.

 

One part of this standard lists the types of things that the methodology must look at in the assessment. Other than ‘control rooms’ the assets listed do not have direct counterparts in chemical facilities. Other things that probably should be considered would be servers, power supplies and stand alone safety systems.

 

Any device that controls an operation that could result in the release, theft/diversion or contamination of a listed chemical of interest should be reviewed in the assessment. This is not just limited to valves that control the movement of that chemical within the facility but such things as temperature and pressure controls that could cause the release through the failure of one or more containment systems.

 

There was also some considerable discussion about data as a cyber asset. In the end it depends on how that data fits into the definitions given above. The argument could certainly be made that safety limit data could certainly, if deleted or corrupted, “allow for a release” and thus be considered a critical asset.

 

Misuse of Control Systems

 

There was one item that FERC did not think received enough emphasis (para 274, pg 7396) in the original version of the standards on the assessment methodology. While they realized that most people would look at control systems they wanted to insure that the misuse of control systems was considered in the assessment. They wanted entities to take a hard look at the consequences of the deliberate misuse of control systems to damage the system.

 

A special case noted by commission was where a control system controlled multiple assets (para 281 page 7396). Where the individual assets under that control might not be critical in nature, the failure or loss of control for a combination of assets could be critical. During safety reviews in chemical facilities the simultaneous failure of multiple safety systems is usually ignored due to its low probability. When a single control system can affect multiple safety systems, that low probability is no longer a consideration in a security assessment.

 

Cyber Security and the SVA

 

The FERC document deals solely with cyber security. The SVA required under CFATS includes the cyber security assessment as just one part of the risk assessment process. But the identification of critical cyber assets is an important part of the SVA process, one that may be too easily overlooked.

Sunday, February 17, 2008

FBI Symposium on Agroterrorism

Last week there was an article on USAgNet.com about an upcoming symposium that the FBI is conducting on agroterrorism. Actually it is the Third International Agroterrorism Symposium and it is being held in Kansas City on April 21st thru 24th. The focus of this year’s symposium will be:

 

“….the importance of food defense and the need to closely communicate and coordinate among private industry, law enforcement, government agencies, science, academia, and the health and medical professions in order to protect the global food supply.”

 

Now fighting agroterrorism and protecting chemical facilities against terrorist attacks are not one and the same thing. There are overlaps, however. Commercial or industrial agriculture as practiced in the United States is very much a chemical intensive operation. Many of the chemical used down on the farm are the same ones that DHS has identified as potential terrorist targets. The food processing industry also uses a number of chemicals that are found in Appendix A to 6 CFR part 27.

 

Unfortunately, looking at the published program for this symposium I see nothing about farm chemicals or food processing chemicals as potential targets of terrorist attacks. I would have thought that this would be a perfect opportunity for DHS to reach out to agriculture industry to explain what it was trying to accomplish with their CFATS program. Especially since agriculture has been the most potent political foe DHS has had to deal with in implementing these regulations.

 

In fact, there are two specific issues that DHS has with the agricultural production industry that need to be dealt with in the coming months and this might be an ideal venue to publicly bring that industry into the fold. The first, of course is the temporary agricultural exemption to the Top Screen (see: “Agriculture does not understand even the revised rules”). The second is the upcoming regulations on the sale of ammonium nitrate (see: “DHS and the Omnibus Spending Bill”).

 

Agriculture Top Screen Exemption

 

By the time that the end of April comes around DHS should have decided what they want to do about the various chemicals of interest from Appendix A that are wide spread on farms, ranches, etc. It would seem that some sort of abbreviated Top Screen would be the easiest way to get the required information into the CSAT system and eliminate 99% of the farmers and ranchers from the list of potential high-risk chemical facilities.

 

DHS needs to get these people to complete the Top Screen so that the CFATS system appears to be a fair and equitable attempt to identify all high-risk facilities. A careful explanation of that reality and an assurance to these farmers that DHS does not want to send their chemical facility inspectors out traipsing through barns and fields will go along way to ease the confrontation that has become such a political nightmare for DHS.

 

Ammonium Nitrate Sales/Transfer Rules

 

The new ammonium nitrate rules that DHS was directed to implement by Congress in the latest spending bill have the potential for being an even worse headache for farmers and DHS. These regulations are aimed directly at farmers and farm supply companies. They will certainly put a paperwork burden on a large number of farmers and small business people. DHS needs to reach out to the agriculture community early in this process if they are going to have any hope of avoiding a number of bruising political fights over these regulations.

 

DHS has a June 26th deadline to get a proposed regulation into the Federal Register. This April date would give DHS adequate time to get a general idea of what they want to do (and Congress was a little more specific this time than they were in the Section 550 instructions for CFATS). A good one-day round-table discussion at a forum like this would let DHS get their most vocal feedback on the table with time to make adjustments before the June deadline.

 

I hope that the lack of announced DHS participation at this FBI organized symposium is just one of those inevitable over sights on the part of both agencies. It would be a shame if parochial conflicts were the real reason that DHS is not on the program. Agriculture and the American people deserve better.

Saturday, February 16, 2008

Budget Testimony from DHS Intelligence and Analysis Under Secretary

As part of the on-going parade of Executive Branch officers going to Capital Hill to explain the President’s budget for 2009, Charles E. Allen, DHS Under Secretary Intelligence and Analysis (I&A), was supposed to have appeared before the House Subcommittee on Intelligence, Information Sharing, and Terrorism Risk Assessment yesterday. While that hearing was postponed, the prepared testimony for Mr. Allen was posted on the DHS web site.

 

As with most testimony of this sort, Secretary Allen’s presentation highlighted the things that his agency has done well with the people’s money. For most of us this is the most detail that we will see in one place about the operations of an intelligence agency. We can look at Mr. Allen’s presentation to see if we can tell what the Department has been doing to develop and share intelligence information about potential terrorist attacks against high-risk chemical facilities.

 

Intelligence Shared with Critical Infrastructure Protection Community

 

Actually he never mentioned chemical facilities, nor did he mention any of the other 16 critical infrastructure categories by name. He did, however, refer to critical infrastructure intelligence support a number of times. One of the most important dealt with I&As work with the DHS Office of Infrastructure Protection:

 

“We are enhancing our existing analytic efforts in partnership with the DHS Office of Infrastructure Protection in a center – the Homeland Infrastructure Threat and Risk Assessment Center, or HITRAC – to assess terrorist threats to and vulnerabilities in the 17 critical infrastructures identified in HSPD-7.”

 

Since intelligence information is worthless unless it gets into the hands of the people that will have to plan for and deal with the identified threats, DHS has, according to Mr. Allen, worked hard to get that information into the appropriate hands. They have “delivered tailored briefings to a wide range of State, local, and private sector customers to enhance their awareness and understanding of the threats.” One tool I&A has used for such delivery has been the publication of Infrastructure Intelligence Notes.

 

I&A is attempting to make intelligence more responsive to the operational components of the DHS team by forming Shared Mission Communities (SMC). The law enforcement agencies of DHS were brought “together to address information sharing opportunities and to build a coordinated approach to information sharing.” The success of that effort has served as a proof of concept and the Department will form additional SMC’s; to include one for Critical Infrastructure Protection.

 

Need to Share Intelligence with High-Risk Chemical Facilities

 

What was not addressed in this presentation is how any of this threat analysis work will be getting down to those high-risk chemical facilities identified in the CSAT process last month. These facilities, the actual number of which is still only known to DHS, are beginning their vulnerability analyses. To do that effectively they need access to up to date intelligence information on the threats they face.

 

DHS has a tool that they could use to communicate with these facilities. Due to the CSAT registration process, they have the name and email addresses of two people for each facility that have been designated by their corporate leadership as the action officers for CFATS implementation. I&A should establish an intelligence mailing list for unclassified information about identified and potential threats against chemical facilities.

 

I&A also needs to establish a security data collection protocol from these high-risk chemical facilities. As a part of their site security plans each of these facilities is expected to report security incidents to DHS. The faster those reports are gotten into the analysis process the faster the information can be developed into intelligence reports useful to other such facilities.

 

Intelligence Training for Facility Security Officers

 

Another area that Mr. Allen takes pride in is the training and development efforts that I&A has worked on. He points out that without “appropriate training and education, the DHS Intelligence Enterprise will operate neither as a culture nor as a unified work force.” That training needs to be extended down to the high-risk chemical facility community.

 

Most of the high-risk chemical facilities do not have staffs to review and analyze intelligence information. Very few of them even have anyone with intelligence training of any sort on staff. I&A should develop a basic, on-line, intelligence analysis course for Security Officers at these facilities. That training should concentrate on understanding the limits of intelligence information and the importance of situational awareness of what is going on around their facilities.

 

If there is any one thing that people in the operations side of the anti-terrorism business will agree on, that is that having timely and accurate intelligence information about the threat is an essential element in planning for and reacting to the terrorist threat. Secretary Allen’s presentation seems to indicate that he understands that as well.


Tags: , ,

Friday, February 15, 2008

Senate Committee looks at DOD’s Homeland Security Role

Yesterday the Senate Committee on Homeland Security and Governmental Affairs held a hearing on the Defense Department’s Homeland Security Role. According to opening remarks by Sen. Lieberman, the committee chairman, this will be the first of a series of hearing about how the country will deal with the results of terrorist attacks using weapons of mass destruction (WMD).

 

The three generals testifying at this hearing, MG Punaro (USMCR-Ret), LTG Sherrard (AFR-Ret), and MG Stump (ANG-Ret), all served on the recent Commission on the National Guard and Reserves that just completed its final report to Congress: Transforming the National Guard and Reserves into a 21st-Century Operational Force. MG Punaro was the chairman of that commission. Their prepared testimony dealt with portions of that report that dealt with Homeland Security.

 

Early on in their testimony they made the same point I made in a blog earlier this month (see “Chemical Plant Incident Response”) that the military will have to be involved in the response to a large scale terrorist attack (page 6);

 

“A terrorist’s use of a weapon of mass destruction (WMD) in a major metropolitan area would cause a catastrophe to which only the Department of Defense could respond: no other organization has the necessary capacity, capability, command and control, communications equipment, and mass casualty response personnel and equipment.”

 

Chemical Facilities as WMD

 

While chemical weapons are clearly included in the term WMD, they are not normally thought of, in a terrorist context, as a large-scale attack. The typical military chemical weapon contains only a limited amount of a toxic agent. While they may be lethal, they affect only a relatively small area. The military delivers a large number of such weapons to have a major effect. A terrorist would only be able to employ one or two such weapons.

 

An attack on a chemical facility where there is a large-scale release of a toxic chemical, on the other hand, could have a large area affect normally associated with WMD. In that case, I believe we should consider a terrorist attack on a chemical facility where there is a large release of a toxic chemical as the use of a weapon of mass destruction. With that in mind the discussions in this hearing do affect chemical facility security planning considerations.

 

Chemical WMD Response

 

According to the Generals’ prepared testimony (page 14), “Congress authorized the creation of chemical, biological, radiological, nuclear, and high-yield explosives consequence management (CBRNE-CM) response forces…” Currently DOD staffs the following such forces:

 

·        NORTHCOM’s Joint Task Force Civil Support (JTF-CS)

 

·        National Guard Weapons of Mass Destruction Civil Support Teams (WMD-CSTs)

 

·        National Guard CBRNE Enhanced Response Force Packages (CERFPs)

 

·        CBRNE Consequence Management Response Forces (CCMRFs)

 

·        U.S. Marine Corps Chemical-Biological Incident Response Force (CBIRF)

 

Lack of Current Planning

 

While DOD does have some units designated to deal with CBRNE incidents, according to the Generals’, there has been only a limited amount of planning and coordination on how to respond to such incidents. Part of the problem is that DHS, the designated response agency for domestic terror attacks, and DOD have not done the coordination that would be required for DOD to properly support DHS operations. As a result (page 17):

 

Because the nation has neither adequately identified the requirements related to nor adequately resourced its forces designated for response to weapons of mass destruction, it does not have sufficient trained, ready forces available for that mission. In our report, we call this an appalling gap, though we are certainly not claiming to be the first to recognize it.”

 

The other main point that the Generals’ made in their testimony (page 9) was that “…the National Guard and Reserves should play the lead role within DOD in supporting the Department of Homeland Security”. This is because, in their words (page 6), it is “‘forward deployed’ in 3,000 communities across the country, is readily accessible to state authorities, routinely exercises with law enforcement and first responders, and is ‘experienced in supporting [local] communities in times of crisis.’”

 

Needless to say that there was a lot more information provided in the 36 pages of testimony provided by the Generals. Much of it is only of interest to military planners, but there was enough other material that would be of interest to chemical facility security planners to justify a couple of future blogs.

Thursday, February 14, 2008

Chertoff’s Appearance before House Homeland Security Committee

The first round of hearings on the DHS 2009 budget started yesterday in the House Homeland Security Committee. Secretary Chertoff was the only witness in yesterday’s hearing. Today he will appear before the Senate committee.

 

Secretary Chertoff’s testimony highlighted the departments achievements to date. These include two areas specifically related to the chemical industry:

 

·         Setting Chemical Security Standards: NPPD established national guidelines for chemical facility security in a comprehensive set of regulations to protect chemical facilities from attack and prevent theft of chemicals that could be used as weapons.

 

·        Assessed Impacts of Chemical Attacks: S&T conducted the first comprehensive chemical threat risk assessment across a broad range of toxic chemicals that better focuses interagency priorities accordinglyto risk.

 

As I mentioned in an earlier blog (see “DHS 2009 Budget Released” there is only one item in the budget that directly pertains to security at chemical facilities, the Chemical Security Compliance Project (what we know as CFATS). The President’s budget requests $13 million more for this project than requested in the 2008 Budget.

 

In Chairman Thompson’s Opening Statement and in the Committees Budget Shortfalls Analysis much attention was made of how much the budget cut funding for a wide variety of programs (none related to chemical security programs). The Secretary’s testimony noted increases of hold steady on almost all of those programs.

 

The difference between the two was due to what baseline was used. Chertoff increases were referenced back to last year’s budget request. The Chairman’s figures were referenced back to last year’s appropriated figures. It is likely that this year will also see congress increase funding for the many grant programs; after all it is an election year.

Wednesday, February 13, 2008

Chemical Incident Review – 2-13-08

Once again, since there have been no reported terrorist incidents at chemical facilities reported in the press, we will look at chemical accidents and incidents that have been reported. This is not being done to review safety, but rather to look at such incidents to see what they can teach us about security and mitigation.

 

Mountaire Farms Ammonia Leak, Selbyville, DE

 

A faulty valve on a rooftop refrigeration unit resulted in the leakage of an unreported amount of anhydrous ammonia into the Mountaire Farms poultry processing plant. Thirty-one people needed medical attention and seventeen were transported to local hospitals for additional treatment. No lasting injuries were reported. The ammonia fumes entered the facility through the HVAC system and response personnel measured concentrations at 100 ppm. The facility has a history of reported ammonia leaks.

 

Food processing facilities are frequent users of anhydrous ammonia refrigeration units. They are also good targets for terrorist attack because of the perception of danger to the food supply. Facilities that have a published history of ammonia leaks and resulting injuries to their workers are also likely to draw the attention of home grown terrorists in search of easy targets. It would take a very small explosive device to remove a valve on a roof top system.

 

Ammonia sensors in the HVAC system could have prevented most of these injuries. Such a sensor could be tied into an emergency stop for the blowers and an alarm in the facility. Stopping the blowers would have reduced the amount of ammonia taken into the facility and the alarm would have started the evacuation process.

 

Ethanol Storage Tank Explosion, Harristown, IL

 

An apparent lighting strike resulted in the explosion of a 30,000-gallon ethanol storage tank. The lightning apparently ignited vapors in the tank headspace. The force of the explosion blew the top of the tank over 350 feet away. No injuries were reported and the only damage reported was to the storage tank. There is nothing in the news report to indicate how much liquid was in the tank.

 

Storage tanks of flammable liquids are only threats for fire or explosion if the headspace in the tank contains oxygen (air) and the flammable vapors. Inerting the headspace with a non-combustion supporting gas such as nitrogen or carbon dioxide will prevent a fire or explosion in the headspace. If this is done, the only hazard from fire or explosion would arise if the tank were to rupture or leak.

 

Chlorine Leak at Water Treatment Plant, Medford

 

A chlorine leak at the Big Butte Springs water treatment plant resulted in the evacuation of the plant and some nearby homes. No injuries were reported and people were allowed to return to their homes that afternoon. Investigation showed that the leak was small enough that the evacuation of nearby homes was not actually needed.

 

The facility did have an airborne chlorine detection unit in the area of the chlorinating operation. The sensor sounded the alarm and shut off the supply from the chlorine tank. This was almost certainly responsible for the lack of injuries and the small size of the leak.

 

Interestingly the local paper reported that the plant is preparing two switch from chlorine gas to the use of hypochlorite for their water treatment. While the switch over is costing $1.29 million the plant was facing upgrade costs (presumably for security) of  $0.8 million so the net cost of the switch was just under $0.5 million. The switch over to hypochlorite does not do away with the risk of chlorine exposure, but does eliminate the security costs associated with using chlorine gas. There are no security regulations covering the use of hypochlorite.

Tuesday, February 12, 2008

SVA Definitions – Vulnerability, Target Attractiveness, Likelihood of Success

Continuing yesterday’s blog (“SVA Definitions – Risk, Consequences and Threat”) we continue to look at some definitions that need to be understood by SVA team members at high-risk chemical facilities. As before the definitions come from the CCPS SVA Guideline Book,  "Guidelines for Analyzing and Managing the Security Vulnerabilities of Fixed Chemical Sites."

 

Definition of Vulnerability 

 

In an SVA vulnerability is “any weakness that can be exploited by an adversary to gain unauthorized access to an asset.” Vulnerability could be due to a hole in the security precautions protecting the asset, plant operating procedures that allow access, or even management procedures that make unauthorized access easier to achieve.

 

There are two general methods for assessing vulnerability in the CCPS approach to conducting an SVA. The asset-based approach looks at the threat and hazards associated with assets at the facility. For example a facility with a 60,000-pound chlorine tank and no other COI would look at how that particular asset could be attacked to achieve a catastrophic release, working from the result back to the probable method of attack.

 

The scenario-based approach focuses more on the potential attackers. The vulnerability assessment looks at various attack scenarios that could be employed against the facility. Looking at, for example, what damage an armed assault team, a vehicle bomber and a cyber attack could do to determine the vulnerability points of the facility.

 

Which approach to take depends on a number of factors. A team with a strong understanding of terrorist tactics and capabilities would probably favor the scenario-based approach. A team with more of a process background would probably use the asset-based approach.

 

Definition of Target Attractiveness

 

Target Attractiveness is a measure of the value of the facility to an adversary when viewed as a target. In large part this depends on the objective of the adversary planning the attack. Thus an accurate assessment of the Target Attractiveness depends on the intelligence available on adversary. This means that in almost all instances only a broad outline of Target Attractiveness can be obtained.

 

Target Attractiveness can be best used to determine the necessity of doing an SVA. For the purposes of CFATS DHS has determined the Target Attractiveness of all facilities that have completed the Top Screen. Thus the Tier ranking of the facility can serve as a relative measure of Target Attractiveness.

 

Definition of Likelihood of Adversary Success

 

The Likelihood of Adversary Success is a measure of the probable success of a security measure to prevent a catastrophic result from a terrorist attack. Once again a quantitative measure is not likely to be determined from available information. There is simply not enough available data.

 

Once again the judgement of the SVA team will be used to evaluate the various security measures and their effectiveness at reducing the Likelihood of Adversary Success. This is one of the reasons that it is necessary to have a wide variety of skills on the SVA team. Two skill sets that it is imperative for the team to have to make this particular evaluation are a strong understanding of security procedures and devices as well as knowledge of terrorist tactics and capabilities.
 
/* Use this with templates/template-twocol.html */