Friday, July 18, 2008

Reader Recommendation

I love the Internet. I write a blog about a video surveillance and bemoan the lack of introductory material (see: "Review: IP Surveillance 101"). Next thing I know, I am getting an email from the UK; from Mike, a consultant at cctvcrew.co.uk recommending a web site.

  • "I happened to notice your blog post about the lack of any interesting sites about CCTV. 
     
    "Our colleague Jon has a very useful website which may be of interest - http://www.doktorjon.co.uk"

He’s right. The DoktorJon site does have a lot of good information about video surveillance techniques and equipment. It is a well laid out site without a lot of flash, so the pages load quickly. This is helpful since it us a web site with stand alone articles explaining the various tools and techniques.

If you are looking for information about a specific topic without a lot of product hype this is a place to go. The explanations are well written and informative. All-in-all this is certainly a site that I would recommend to any security manager dealing with a video surveillance consultant.

This site is not, however, an introductory text on video surveillance. The individual articles could certainly be put together (with some transitional information) to form the backbone of such a text. In my opinion, Jon could do the video surveillance industry a huge favor and produce an e-book on the topic. It is obvious that he has both the technical and the writing skills to provide the reference text that would be very useful to security managers.

Control System Security

ChemicalProcessing.com has an excellent article in their on-line magazine about security of control systems. The article, "Protect Your Plant" provides a good overview of the real world problems that security managers are going to have to deal with in a chemical manufacturing environment. The article it is short on details of how to ‘protect your plant’, but it does provide enough information to help explain the problem to managers not intimately familiar with control systems.

Eric Byres, of Byres Security Inc, provides real world examples to illustrate the points that he makes. This goes a long way to make the problems real to the average reader. To many control systems engineers working with these systems on a daily basis these examples should cause some forehead slapping, ‘oh my’ moments. These problems could happen at most chemical manufacturing facilities.

There are many good points, but two strike me as being especially important. The first is that the IT department is not equipped to deal with security issues with control systems. Byres points out that different operating systems and design requirements are completely out-of-sync with the standard IT security protocols.

The second important point is that a successful control systems security program must be driven by a commitment from management. Without that top-down drive security managers and control systems engineers will not be given the authority and resources necessary to implement a proper security program.

Byres provides a useful list of the "The 10 most common plant cyber-security mistakes". The list will never make the David Letterman, but it should probably be read as a catechism for every security team meeting. All of them are good, but my two favorites are:

  • #1 Assuming that someone else (like the IT department) is looking after the security of control systems. It often turns out that everyone thinks it’s someone else’s job. (Upper management is especially prone to the mistake.)
  • #6 Forgetting the human aspects of security. Good security starts with ensuring that staff, management and contractors understand and follow appropriate practices.

This article is a timely read. The recent publication of the instructions forcompleting SVA’s at more than 7,000 high-risk chemical facilities means that many people are looking hard at cyber security (see: "SVA – Computer Systems Analysis"). Articles like this will help these facilities move forward as they start to develop their Site Security Plans in the coming months.

Thursday, July 17, 2008

DHS Web Page Updated

Earlier this week DHS updated the Identifying Facilities Covered by the Chemical Security Regulation page on its web site. DHS expanded the description of facilities that may be affected by CFATS and re-worded the description of how facilities can determine if they will be affected.

 

Facilities that Might Be Affected by CFATS

 

The old web page listed only three categories of facilities that might be affected by CFATS. The new page expands the list to include:

 

  • chemical manufacturing, storage and distribution;
  • energy and utilities;
  • agriculture and food;
  • paints and coatings;
  • explosives;
  • mining;
  • electronics;
  • plastics; and
  • healthcare.

 

This is still not an exhaustive list. We know from news reports that there were University labs that did make the list of 7,009 facilities labeled high-risk chemical facilities under the CFATS regulations.

 

Explanation Re-written

 

The explanatory text accompanying the list has been re-written, but there were no major changes in the information provided. The tone does change somewhat reflecting the fact that there is no single category of facilities that must complete a Top Screen. The main determinant is the possession of more than a screening threshold quantity (STQ) of a chemical of interest (COI) from Appendix A to 6 CFR part 27. The new explanation still reinforces the fact that DHS may require other facilities to complete a Top Screen either through direct communication or the publication of a notice in the Federal Register.

Call for SCADA Security Papers

With 7,009 facilities taking a new look at the cyber security questions in the CSAT Security Vulnerability Assessment (see: “SVA – Computer Systems Analysis”) SCADA Security is becoming a high visibility issue at high-risk chemical facilities. This means that a recent Call for Papers about SCADA Security by IDC Technologies comes at an opportune time.

 

Actually the Call for Papers includes much more than just SCADA Security. The SCADA & Industrial Automation Conference in Calgary, Alberta will be held on December 3rd and 4th of this year. It will cover a wide range of SCADA issues, but a major focus will deal with SCADA security. The security related issues will include:

 

  • Security and SCADA
  • Anti virus and firewall rules and configuration
  • Data Communications and Network security
  • Incident response plans
  • Intruder Detection Systems
  • Mobile & Wireless Computing security
  • Risk Management

 

IDC is looking for papers that provide practical responses to security related problems. According to the Call for Papers:

 

·           Now more than ever before, industrial enterprises and utilities rely on their control systems (SCADA, DCSs, PLCs, RTUs, and IEDs) to improve their reliability and efficiency. These new systems are proving even more vulnerable to security breaches and attacks. Today’s complex and dynamic security environment often requires difficult decisions to be made. You need to be armed with practical and competent advice in order to make the correct decisions. Tactical not theoretical solutions are the key to success here.”

 

Abstracts are due August 8th and full papers must be submitted by October 22nd. Contact Sarah Montgomery (sarah.montgomery@idc-online.com) for details.

Wednesday, July 16, 2008

DHS FAQ Update 07-15-08

DHS put five more questions on their FAQ site yesterday. None of the recent additions are SVA questions. They look more like questions asked by facilities that are looking at the CFAT regulations for the first time. The questions are:

  • 1538: How does a facility count the amount of a release-flammable Chemical of Interest (COI) in a mixture with a National Fire Protection Association (NFPA) rating of 4?
  • 1540: How does a facility count the amount of release flammable COI within a mixture that is not a fuel with an NFPA rating of 1, 2, or 3?
  • 1541: How does a facility count the amount of a release-flammable mixture that is a fuel with an NFPA rating of 1, 2, 3, or 4 if it is stored in an above ground tank farm (including farms that are part of pipeline systems)?
  • 1542: What is "CSAT"?
  • 1543: How will a facility know whether it is required to complete a CSAT Top Screen?

CSAT and the Top Screen

With the CFAT regulations over one year old, it might seem surprising that the last two questions are appearing on the FAQ page. I suspect that this is the result of a DHS outreach program to contact facilities that have not yet completed their Top Screen because they did not consider themselves ‘chemical facilities’.

The answers to both of these questions are concise and well written. They present no new information. Interestingly the Top Screen question does address the command requirement to complete a Top Screen along with the Appendix A driven requirement. Such directed Top Screens are one tool that DHS has to address the apparent lack of filing in facilities that might not think of themselves as chemical facilities.

Flammable Release COI Mixtures

DHS continues to have problems with facilities not understanding their complex rules for flammable mixtures. DHS was forced into this situation by their desire to limit the chemicals that would be included in the Top Screen to those that presented the highest risk for off-site consequences. Modest changes to these rules could have resulted in a huge increase in the number of facilities that were required to submit Top Screens.

These rules are complex. A large number of facilities that are not traditional chemical manufacturers use these flammable liquids in their processes. As a result DHS is going to continue to have facilities question these rules as they look at the Top Screen for the first time.

SVA – Finishing the Report

This is the last in a series of blogs concerning the Security Vulnerability Assessment (SVA) instructions recently published by DHS. This blog deals the final operations needed to complete the SVA. It also contains a commentary on the SVA procedure developed by DHS. The previous blogs in this series are listed below.

Once all of the questions have been completed for the SVA, finishing up the document it is very similar to the procedures used in completing the Top Screen. The Preparer will validate the data, print and check the data for accuracy and then electronically forward it to the Submitter. The Submitter will also review the SVA for completion and accuracy before printing a copy for the facility files (the completed SVA is CVI). The Submitter will then submit the SVA to DHS. The facility will no longer be able to access the SVA once it is submitted to DHS.

DHS will review the SVA. If they approve the document they will notify the facility of their final tier ranking. In some cases (probably a very small number of cases) DHS will notify the facility that they are no longer considered a high-risk facility. They will identify the date by which the facility will have to submit their Site Security Plan. They will also list the security issues that must be dealt with in that plan.

If the plan is not approved, the Department will notify the facility what deficiencies have to be corrected and provide a deadline for those corrections. The procedures for correcting those deficiencies have not been included in these CSAT Security Vulnerability Assessment Instructions.

Commentary

DHS has done a very good job in converting a complex process into a fairly straightforward data entry process. This does not make the process any simpler, but it does make the job of evaluating the data much easier. With 7,009 SVA’s to process over the next six months, DHS has used their time wisely in developing this tool. Presumably they have spent an equivalent amount of time developing the processing protocol to allow for an impartial tier assignment process.

This tool does not help facilities much in easing the complexity of the vulnerability assessment process. That cannot really be helped. Security at most high-risk chemical facilities is not going to be easy. The facilities were not designed with more than a modicum of security in mind. Trying to find all of the security holes that a determined terrorist might use is certainly a Herculean task.

Security professionals will certainly be able to find fault with this process. No one size fits all document can hope to identify all of the potential vulnerabilities. Even a trained security team will not be able to develop an exhaustive list of vulnerabilities. No sooner do you plug all of the holes that you can find, when an intelligent adversary looking for an unsecured way in finds the unsuspected Achilles’ heel.

What one can say is that the most common attack modes have been addressed. They are the most common because they are the easiest to plan and execute. They can all be executed with a relatively small team and a small team size makes it easier to avoid detection before the attack starts.

The one exception to this appears to be the inclusion of the Aircraft Attack Mode. For most facilities this attack mode is overkill on a scale unimaginable before September 11th, 2001. I am certain that DHS does not really consider this a viable attack option for most chemical facilities. There are a limited number of facilities, however, where this is the true nightmare scenario (e.g. a large LPG/LNG storage facility). DHS included this mode for those facilities and will probably discount this attack mode for facilities with smaller amounts of COI on site.

The only real complaint that I have about this SVA is the lack of questions dealing with the facility perimeter. For almost all facilities the fence line will be the first line of defense against a terrorist attack. For many facilities it will be the only line of defense. An analysis of that defense should be a valuable part of the vulnerability assessment. The questions for this hypothetical section could include:

  • What type of fence is used for the perimeter?
  • How many guarded gates in the perimeter?
  • How many unguarded gates in the perimeter?
  • What type of perimeter monitoring is used?
  • What percentage of the fence perimeter is lighted?
  • What percentage of the fence perimeter is under continuous observation?

I am watching the DHS FAQ page closely for indications of what types of problems facilities are having with their SVA’s. This will be a good way tracking problems with the SVA process.

Tuesday, July 15, 2008

DHS FAQ Page Update 7-11-08

Last Friday DHS added three new questions to their FAQ page. The first question deals with a Top Screen issue and the other two deal with Site Security Plan issues. The three questions are:

  • 1534: What is the Area of Highest Quantity (AHQ)?
  • 1536: What does "risk-based" mean?
  • 1537: Why is DHS using risk-based performance standards?

Area of Highest Quantity

The definition of AHQ is provided. It is a circle with a radius of 170 feet that contains the highest quantity of the COI in question. While this is a fairly straightforward definition, I have always wondered where the 170 ft radius came from. Well the SVA instructions provide the answer, it is the 9 psi overpressure line for a VBIED located at the center of the circle.

Definition of "Risk-Based"

The DHS answer never does actually define what ‘risk-based’ means though it does provide a description of their ‘risk-based tiering structure in its regulatory approach’. Let me take a swing at the definition.

Risk-Based – Adjective, describing a process where decisions are made based on relative levels of risk. Example: The CFATS process is risk-based; facilities are rated and regulated based on their relative risk for terrorist attack. The highest rated facilities are required to respond faster and adhere to higher standards of performance.

Risk-Based Performance Standards

I was happy to see that while the DHS answer started off with the ‘because Congress told us to’ explanation, a legally sufficient reason, they proceeded to give a justification for those standards. The first answer is the standard ‘each facility is unique’ and thus requires a unique response.

The second justification is one that has been appearing more frequently lately. This one points out that industry-wide security is increased because an adversary will not know what security procedures will be in place at any given facility.

  • "Security measures that differ from facility to facility mean that each facility presents a new and unique problem for potential adversaries."

I am not sure that I agree with that reasoning. This assumes that there is a central training department for terrorists that is teaching them how to attack chemical plants.

What I think is the best reason for this approach is not given in this answer. The alternative approach is the command method of regulation. That method assumes that the government is omniscient, and has the definitive answers to the problem. Since there is little actual experience in protecting chemical facilities from terrorist attacks, it would be hard to believe that anyone has ‘the answers’.

 
/* Use this with templates/template-twocol.html */