Introduction to Enhancing Control Systems Security from the Department of Homeland Security, conducted by Jeffrey Hahn, Training & Education, DHS Control Systems Security Program, Idaho National Laboratory Mitigating Risk and Increasing Audit-ability of SCADA Systems with Best-in-Class Configuration and Change Management Strategies, conducted by Walter Sikora, VP Security Solutions, Industrial Defender Conducting Full-Risk Assessments and Identifying Critical System Assets to Fortify Security & Enable Process Control Redesign, conducted by Michael Toecker, Control Systems Security Designer, Compliance & Infrastructure Protection, Burns & McDonnell EngineeringThis conference is targeted at the corporate executive level. It will provide a high-level understanding of the SCADA threat and actions that companies can take to protect their systems from a variety of cyber threats. While no one will expect the attendees of this conference to write any code, they will be the ones to write the checks for the security efforts.
Tuesday, September 15, 2009
SCADA Security Summit
Early in September I got an email from the folks at scadasec@news.infracritical.com, a SCADA security discussion group about an upcoming SCADA security conference. Its taken me a couple of weeks to getting around to writing about the conference, but it will be held in December, so you still have plenty of time to register if you are interested.
The SCADA and Control System Security Summit will be held in Washington, D.C. on December 7th thru 9th. The actual conference will be held on the 8th and 9th with a number of pre-conference workshops held on the 7th. According to the Summit brochure those workshops will include:
Improving Transportation Security
Over at NationalJournal.com they have a feature where they conduct a week long discussion by a wide variety of transportation experts about a single question. This week the question is “How can we improve transportation security”. When I checked the site yesterday morning the first three commentors focused on what has been done for passenger security, but I would bet that there will be discussion of freight security issues.
I’ll be checking the site periodically during the week to see what the experts have to say about freight security issues. Needless to say I’ll comment here when appropriate.
I do urge anyone with any connection to transportation security to follow the discussion as well. While I expect that the greatest part of the discussion will cover passenger security issues, reflecting the current focus of the transportation security, the discussion will likely mirror what the focus of government regulatory efforts will be.
Monday, September 14, 2009
Greenpeace Presses Obama on CFATS
Last Friday, Greenpeace and a coalition of other environmental, labor and social activist organizations addressed a letter to President Obama encouraging him to get behind passage of HR 2868 and HR 3258, specifically urging him to “to support H.R. 2868 and H.R. 3258 (as introduced) along with any strengthening Amendments”.
The President and CFATS
As I noted last April when the White House web page dropped the promise to “work with all stakeholders to enact permanent federal chemical security regulations”, it does not seem that CFATS is currently a high priority for the Obama Administration. When they put a one-year extension of CFATS in their Homeland Security Budget, it should have convinced even the most ardent supporter of the expansion of CFATS that this was low on the President’s list of priorities.
To be perfectly fair, President Obama has a lot of problems that he and his administration have to deal with. The economy is still on fragile ground, and he has picked two controversial programs to be the hallmark of his first year in office, prevention of global warming and universal health care. It is understandable if he has decided to put the CFATS fight off for another year.
Misplaced Political Pressure
To be sure, Greenpeace and their associate organizations have spent little political capital in sending this letter to the President. But is this the way to really get anything done? I doubt it. This ranks right up there with the letter last summer to Senator Collins asking her to support HR 5577, a bill that had little chance (none in hind sight) of getting to the Senate.
As with last year, the bill needs to be broken out of the House Energy and Commerce Committee. Last year it was stalled there because of opposition to the bill by the Committee leadership. This year it looks more to be a workload issue; Energy and Commerce is a key committee in both the global warming and health care legislation. The committee staff is spending time on those two issues, not CFATS.
And this is the reason that it particularly counterproductive to ask the President to pressure Congress to get moving on CFATS. At this point CFATS is being held up by his two pet projects. It will take much more that a letter or two from supporters to get him to change his priorities. That effort is bound to fail.
Reader Comment 09-11-09 Aphorisms
Anonymous left a brief reply to Friday’s blog on the 9-11 anniversary. The comment was short, so I’ll post it in its entirety here. Anonymous wrote: “‘Those that try to defend everywhere, defend no where’”.
Aphorisms are nice, short sweet sayings that attempt to communicate a complex idea in a simple way. Unfortunately, they seldom achieve their objective because it is too easy to contradict the saying with a couple of counter examples.
In this case, any military man will be quick to see the error in this saying, you must defend everywhere or else the enemy will just go where you are not. A good defender will concentrate his forces in the areas most likely to be attacked, but will leave at least a thin screen of defenders across the entire front to detect an unconventional approach. If such an approach is detected, an appropriate response will be developed and implemented.
You Can’t Protect Everything Equally
Now if Anonymous meant that you can’t protect everything equally I would have to agree. If you spread limited resources too thinly then nothing will be adequately protected. This is why there has been a continuing emphasis on risk-based security. This means that one takes a detailed look at what the risk is for a particular site or activity and then plan the security accordingly.
Of course the problem lies with how to calculate risk. Risk is a product of likelihood of occurrence and the consequence of the event. Event consequences are relatively easy to define for the most part. It is the frequency or likelihood of occurrence that is more difficult to establish.
In process chemistry we assumed that failures, equipment failures or personnel mistakes, were essentially random events and that we could thus predict the number of occurrences in a given period of time from past history. We would then establish a risk matrix based the severity of the result and predicted frequency of occurrence. This would allow us to establish the number safety procedures required and prioritize their implementation.
For example a high frequency event (once every five years for example) that had a serious consequence (on-site personnel injury or serious equipment damage) might require two preventive actions, at least one of which would be required before unit start-up. A low frequency event (once every 20 years) and low consequence (out of spec product) would require a single preventive action within six months of unit start-up.
It is more difficult to establish a risk response matrix for non-random events like potential terrorist attacks. For chemical facilities DHS has established a formal evaluation technique to establish such a matrix; it is known as the Chemical Security Assessment Tool. While DHS has not revealed the details of exactly how it determines which of four risk tiers a facility will be assigned to, those tiers are the risk response matrix for high-risk facilities. Tier 1 facilities will be required to implement more security than a Tier 4 facility because their risk is higher.
Does Low Risk Mean No Risk ?
DHS initially looked at over 30,000 chemical facilities to determine which facilities in the United States would be classified as high-risk facilities. These facilities were selected from a much larger number of chemical facilities using the presence of one of 300+ chemicals as the screening criteria. Now that we know which are the high-risk facilities that will have their security regulated by DHS, what does that mean for the remaining chemical facilities in this country?
Not ‘high-risk’ does not mean ‘no’ risk. There is a continuum of risk that extends from those facilities that just missed the cut of being labeled high-risk through the lowest-risk facility in the country. There is no such thing as a no risk facility.
DHS was given the job of regulating only high-risk companies because Congress realized that they had limited resources and could only spread them so thin. That does not mean that the remaining facilities need not worry about their facility security. It just means that the lower risk facilities will have to look after their own security without the assistance and oversight of the Infrastructure Security Compliance Division of DHS.
There is another DHS program that will provide some assistance for those facilities in evaluating their security program. I’ll look at that program later this week.
Friday, September 11, 2009
S 1649 WMD Security
Earlier this week Senators Lieberman and Collins introduced S1649, a bill to “prevent the proliferation of weapons of mass destruction, to prepare for attacks using weapons of mass destruction, and for other purposes”. While news reports have concentrated on the bill’s effects on biological laboratories that house dangerous microorganisms, there are provisions in the bill that deal with the two other ‘common’ types of WMD, chemical and radiological weapons. Here we will specifically look at those provisions of potential interest to the chemical security community.
Communications Planning
Section 221 of the legislation would amend the Homeland Security Act of 2002 by adding §525, Communications Planning. This would require FEMA to “a communications plan for providing information to the public related to preventing, preparing for, protecting against, and responding to imminent natural disasters, acts of terrorism, and other man-made disasters [emphasis added], including incidents involving the use of weapons of mass destruction and other potentially catastrophic events" {§525(a)(1)}. This would certainly include terrorist attacks on high-risk chemical facilities as well as industrial accidents at those facilities that have significant off-site affects.
Those communications plans would include provisions for the development of pre-scripted messages or message templates that would “be designed to provide accurate, essential, and appropriate information and instructions to the population directly affected by a disaster or incident, including information related to evacuation, sheltering in place, and issues of immediate health and safety” {§525(b)(2)(B)}.
These pre-scripted messages would be developed in multiple formats to allow for failure of different communications media. Additionally formats for these messages would be developed to allow for communication with “individuals with disabilities or other special needs and individuals with limited English proficiency in accordance with section 616 of the Post-Katrina Emergency Management Reform Act of 2006” (PKEMR) {§525(c)(2)}.
To ensure appropriate evaluation of the effectiveness of these pre-scripted messages, FEMA would be required to incorporate the use of these messages in any exercises conducted under the National Exercise program required by PKEMR. Additionally, FEMA would be required to report to Congress on the development and effectiveness of these messages.
Plume Models
While WMD attacks may have devastating local effects at the site of attack, one of their disturbing characteristics is the spread of the toxic after affects of such attacks in a down-wind plume. It thus becomes important to forecast where that plume will spread to alert personnel located downwind of what appropriate defensive actions to take to avoid or mitigate those toxic affects.
While the military has long had very simplistic tools to determine the size and location of the toxic plume and to calculate the concentrations of the toxic agents within the plume, §222 of this legislation requires the Secretary to develop an integrated plume model “that integrates protective action guidance and other information as the Secretary of Homeland Security determines appropriate” {§222(a)(3)}.
The wording makes it clear that the Secretary, presumably through FEMA, would be required to develop and disseminate an integrated plume model for every “nuclear, radiological, chemical, or biological explosion or release” {§222(b)(1)}. It does not limit that development/dissemination to releases that are the result of a deliberate attack.
These integrated plume models would be distributed to Federal Government and State, local, and tribal governments and through such officials to “nongovernmental organizations and the public to enable appropriate response activities by individuals” {§222(b)(2)(B)}. This requirement to enable an ‘appropriate response’ would require either significant training of the public in the interpretation of the output of the plume model, or the very clear explication of the hazard zones and their appropriate responses on the distributed output of the model.
Intelligence on WMD
Section 401 deals with improving the nation’s intelligence on issues related to weapons of mass destruction. The section starts with a series of definitions, including a three part definition of WMD. The first part of that definition deals with chemical WMD which it describes as “any weapon that is designed, intended, or has the capability to cause death, illness, or serious bodily injury to a significant number of persons through the release, dissemination, or impact of toxic or poisonous chemicals or their precursors” {§401(a)(4)(A)}. This would certainly seem to include attacks on high-risk chemical facilities.
The section then goes on to require the Director of National Intelligence to develop within 120 days of the passage of the legislation a “strategy for improving the capabilities of the United States for the collection, analysis, and dissemination of intelligence related to weapons of mass destruction, including intelligence related to the relationship between weapons of mass destruction and terrorism” {§401(b)(1)}. The Director would then have to report to Congress on the effectiveness of that plan every 180 days for the next three years.
WMD Response Guidelines
Within a year of passage of this bill, the Secretary of DHS would be required to develop guidelines “for responding to an explosion or release of nuclear, biological, radiological, or chemical material” {§502(a)(1)}. These guidelines would be disseminated through State and local governments to the private sector, police, fire, emergency medical services, emergency management, and public health personnel.
The guidelines would include at a minimum {§502(b)}:
“(1) protective action guidelines for ensuring the health and safety of emergency response providers; “(2) information regarding the effects of the biological, chemical, or radiological agent on those exposed to the agent; and “(3) information regarding how emergency response providers and mass care facilities may most effectively deal with individuals affected by an incident involving a nuclear, biological, radiological, or chemical material.”Bipartisan Legislation This legislation was developed to respond to the recommendations included in last year’s report from the Commission for the Prevention of Weapons of Mass Destruction Proliferation and Terrorism. Not only was that a politically balanced commission, but this legislation was co-sponsored by the Chairman and the Ranking Member of the Senate Homeland Security and Governmental Affairs Committee. This bipartisan effort stands a decent chance of being passed even in the current acrimonious Congress. Whether it passes this year or next will depend in a large part on how hard Sen. Lieberman presses it through the Senate.
Fusion Center and EOC Coordination
Fusion Centers provide for the coordination and dissemination of information that might allow for the prevention of terrorist attacks. Emergency Operations Centers provide for the coordination of law enforcement and emergency response personnel for a wide array of emergency situations including potential terrorist attacks. FEMA recently released a draft Comprehensive Preparedness Guide (CPG) outlining how these two organizations can cooperate to more effectively work together to protect the public.
Thanks to HSDL.org I learned about the existence of this draft CPG. It can apparently only be accessed through the International Association of Emergency Managers (IAEM) web site. I have not been able to find the document on either the FEMA web site or the DOJ web site; these being the two agencies that collaborated on producing the document.
The IAEM is asking for feedback on the document. I haven’t had a chance to review the 81 page document yet, but I wanted to let everyone know about this since the IAEM is asking for that feedback to be submitted by next Thursday, 9-17-09. I’ll take a more detailed look at the draft of CPG 502, Considerations for Fusion Center and Emergency Operations Center Coordination, over the weekend and comment back if there is anything of specific interest to the chemical security community.
9-11-2009
Today is the 8th anniversary of the 9/11 attacks on the United States. While there have been no successful terrorist attacks on the US since that fateful day, we continue to work at preventing the next attack. Today is a good day to take a look at those efforts and determine if they are necessary, or whether we should be expending that time and those resources on other endeavors.
Questions Raised in QHSR
This is one of the questions that was raised in response to a number of different Ideas discussed in the recent Quadrennial Homeland Security Review Dialogue. A number of different commentors noted that it is impossible to protect everything. Besides as we prevent one threat, our opponents develop another.
Even as we stopped passengers from taking any potential edged/pointed weapons onto airline, the terrorists developed explosive shoes. We required passengers to take off their shoes for inspection and the terrorists turned to liquid explosives. As TSA continues to enforce the 3-1-1 Rule we hear reports of terrorists using explosives hidden in ‘anal cavities’ in a non-airline attack. Every new security measure results in a new technique.
What the security measure critics fail to recognize is that none of the newly developed attack techniques has been successfully used in an attack on airlines in this country. A combination of robust intelligence work and ineptly executed attacks has resulted in the detection of these new techniques before they were successfully executed. Responses have been put into place to prevent future efforts.
So why are we expending the time and effort to defend against the last attack technique? Actually the answer is quite simple; we prevent the terrorist organizations from perfecting those techniques. The 9/11 attacks succeeded in large measure because we stopped looking for hijackers because it was a discredited, no longer successful, terrorist attack technique. The terrorists realized that we had stopped looking, so they dusted off an old technique and successfully used it in a new way.
We continue to defend against the simpler attack techniques because to do so raises the bar for participation in attacks. The simpler attack modes could be used by just about any wannabe; preventing those modes reduces the number of potential adversaries that can attack us. As new attack modes are developed and implemented, we will develop and implement defenses. Hopefully we will continue to detect the new attack modes before they are successfully used.
No Attacks, Why Defend?
The question is even more acute when it comes to defending chemical facilities against terrorist attacks. There have been no credible reports of attempted or planned attacks on high-risk chemical facilities in this country, so why are we requiring almost 7,000 facilities to expend a great deal of time, effort and money on defending these facilities against potential attacks?
Actually we are using a standard process safety tool known as the “What if Technique”. In safety reviews we look at a variety of potential scenarios to see if something ‘bad’ can happen. If it is determined that there is a potential issue we then ask how likely it is that the scenario can occur. The worse the potential consequence the less likely the occurrence has to be required to take preventive action.
The potential consequences of successful attacks on the high-risk chemical facilities covered under the CFATS program are so high that there only needs to be a relatively low probability of such an attack to make it worth while to take the required safety/security measures. Additionally, the tier ranking system used to evaluate the risk requires more security measures for the higher risk facilities.
What Cost Security?
Security measures cost money; who then pays for that security? This is one of the fundamental questions that needs to asked whenever the federal government requires actions by State and local governments or private individuals and companies. It is clear that under current rules the management of high-risk chemical facilities will pay for the planning, implementation and upkeep of security measures at their facility. They will, of course, pass those costs on to their customers so that the cost eventually gets spread through out the economy.
If competitors can produce equivalent products without using the chemicals that trigger the regulatory requirement, or produce the products in locations where the risks are less, or can in some other way reduce their risk below the CFATS threshold, they will not have the security cost to recover in their pricing. Whether this will be enough to give them a significant competitive advantage in the market place will determine if the high-risk facility is able to remain in business using the chemicals of interest that make them high-risk facilities.
While CFATS does not specifically require action by State and local governments, it is an inescapable fact that local law enforcement, emergency management and other governmental response agencies will be required to support security plans at these high-risk chemical facilities. Who pays for that support? While there may be grants that help in some limited situations, it is clear that the local population will pay for these security-support measures. In some ways that is appropriate since the neighbors will be receiving the direct benefits of that support in the event of an attack on the facility.
The final cost that has not been addressed in the discussion of protection against potential terrorist attacks is who will pay for the damage that results from a successful terrorist attack. Will the facility and their insurance company bear the bulk of the financial responsibility for making whole the neighbors of the facility? Or will the facility be responsible for a ‘reasonable’ amount of the damage with the government picking up the rest? In either case, what is an adequate level of insurance coverage or bonding required for a high-risk chemical facility?
Continued Evaluation
Today, the anniversary of the fateful date reminds us that there are many enemies of this country in the world, some of whom will attack us where we live. We need to periodically look at the consequences of that fact and reaffirm that we will take the necessary actions to protect our way of life. We need to periodically re-evaluate the threat and the potential consequences to determine what measures are appropriate.
Requiring high-risk chemical facilities to implement security measures is just one of those types of actions we need to take to protect ourselves and our society.
Subscribe to:
Posts (Atom)