I just received an interesting email from a reader with an important question. He writes that his chemical facility does security inspections of inbound vehicles and tractor-trailers. He wants to know if anyone knows of a training program (preferably in or near the Houston, TX area) that teaches security personnel how to conduct such an inspection.
Please post replies as comments on this blog post.
Thursday, January 13, 2011
HR 225 Introduced – CFATS
On January 7, 2011 Rep. Jackson-Lee (D, TX) introduced HR 225, the Chemical Facility Security Improvement Act of 2011. Almost exactly two years earlier she introduced a nearly identical bill {‘2009’ vs ‘2011’ and the earlier bill was co-sponsored by Rep. Thompson (D, MS) while this bill has no co-sponsors}, HR 261.
As I noted in my comments about the original bill, there are two separate parts of this bill. The first part {§2(a)}limits the use of federal funds in approving site security plans at CFATS facilities, and the second (much larger) part {§2(b)} fulfills the “other purposes” portion of the long title of this bill. As I noted in my posting about these ‘other purposes’ in the earlier bill, I think that this particular attempted abuse of legislative power, hiding potentially extensive and significant changes in an existing regulatory program behind the words ‘other purposes’, deserves to be dismissed out of hand, regardless of the merits of the suggested changes. See that earlier post for a detailed discussion of those proposed regulatory changes.
Limitation on the Use of Funds
As I explained in my discussion of §2(a) of the earlier bill, this bill would effectively prohibit DHS from approving a CFATS facility Site Security Plan unless it already knew that the facility met any existing State or local chemical facility security regulations. It would change the relationship between Federal, State, and local regulations, making DHS an enforcer of State and local chemical security regulations.
The wording of the bill would certainly not allow DHS to send chemical facility inspectors to a facility to do the post-SSP submission inspection until the Department had determined that it was in compliance with all State and local laws designed to prevent any kind of terrorist attack on the facility. Given the patchwork nature of such regulations, it is not clear how DHS would make this determination and who would be responsible for reporting such compliance.
The phrase ‘No Federal funds may be used’ could even be extended to mean that facilities could not even be allowed to submit an SSP since the operation of the CSAT tool certainly requires the expenditure of ‘Federal funds’. Thus, HR 225 has the potential capability to paralyze the CFATS program.
I certainly understand the desire of communities to establish and enforce higher chemical security or chemical safety standards than those set by the Federal government. This provision, however, goes far beyond the issue of Federal pre-emption; it effectively makes DHS the enforcement arm of potentially 50 States and uncounted regional, county, city and district governments.
This bill saw no committee hearings or other legislative work in the 111th Congress. I suspect it will receive even less consideration in the 112th.
As I noted in my comments about the original bill, there are two separate parts of this bill. The first part {§2(a)}limits the use of federal funds in approving site security plans at CFATS facilities, and the second (much larger) part {§2(b)} fulfills the “other purposes” portion of the long title of this bill. As I noted in my posting about these ‘other purposes’ in the earlier bill, I think that this particular attempted abuse of legislative power, hiding potentially extensive and significant changes in an existing regulatory program behind the words ‘other purposes’, deserves to be dismissed out of hand, regardless of the merits of the suggested changes. See that earlier post for a detailed discussion of those proposed regulatory changes.
Limitation on the Use of Funds
As I explained in my discussion of §2(a) of the earlier bill, this bill would effectively prohibit DHS from approving a CFATS facility Site Security Plan unless it already knew that the facility met any existing State or local chemical facility security regulations. It would change the relationship between Federal, State, and local regulations, making DHS an enforcer of State and local chemical security regulations.
The wording of the bill would certainly not allow DHS to send chemical facility inspectors to a facility to do the post-SSP submission inspection until the Department had determined that it was in compliance with all State and local laws designed to prevent any kind of terrorist attack on the facility. Given the patchwork nature of such regulations, it is not clear how DHS would make this determination and who would be responsible for reporting such compliance.
The phrase ‘No Federal funds may be used’ could even be extended to mean that facilities could not even be allowed to submit an SSP since the operation of the CSAT tool certainly requires the expenditure of ‘Federal funds’. Thus, HR 225 has the potential capability to paralyze the CFATS program.
I certainly understand the desire of communities to establish and enforce higher chemical security or chemical safety standards than those set by the Federal government. This provision, however, goes far beyond the issue of Federal pre-emption; it effectively makes DHS the enforcement arm of potentially 50 States and uncounted regional, county, city and district governments.
This bill saw no committee hearings or other legislative work in the 111th Congress. I suspect it will receive even less consideration in the 112th.
USCG TWIC Reader NPRM to OMB
The Office of Management and Budget posted a notice yesterday on their web site that it had received a draft NPRM from the Coast Guard for the TWIC Reader Rule (RIN: 1625-AB21) for review. Typically this would mean (unless OMB finds major issues with the NPRM as submitted) that the NPRM could be expected to appear in the Federal Register in a matter of months.
Readers of this blog might remember that I briefly mentioned that this was listed in the Fall 2010 Unified Agenda. There OMB predicted that the NPRM would be published in November of this year. To me this looks like a potential acceleration of that publishing date. We’ll just have to wait and see.
Readers of this blog might remember that I briefly mentioned that this was listed in the Fall 2010 Unified Agenda. There OMB predicted that the NPRM would be published in November of this year. To me this looks like a potential acceleration of that publishing date. We’ll just have to wait and see.
IED Threat Information
The web site that publishes restricted access information from governments around the world, PublicIntelligence.net, recently posted a copy of a set of DHS TRIPwire briefing slides providing an overview of the use of improvised explosive devices by terrorists; “Domestic Improvised Explosive Device (IED) Threat Overview”. As is usual with the publications of the slides from a presentation, much of the detailed explanation that makes up such briefings is missing from this document, but even so it is a valuable compilation of information about Terrorist IED Tactics, Techniques, and Procedures (TTP).
In addition to information about explosives and devices (lacking any details that would allow the uninformed to produce them) there is an interesting section on ‘Domestic Radicalization’. There will be some that object to the inclusion of ‘radical Christian movements’ in the discussion, but the example of Eric Rudolph demonstrates that they are referring to the violent radical fringe, not the just less-mainstream religious groups. They conclude that slide with a very important point;
SECURITY WARNING: Government contractors and members of the federal government should be aware that the document is marked ‘For Official Use Only’ (FOUO) and the fact that you download this from an open source will not exempt you from applying appropriate safeguards for the storage of this document. The last time I looked at FOUO regulations (20+ years ago in the Army) this required the use of an ‘FOUO’ cover sheet and storing in a locked desk drawer or file cabinet.
In addition to information about explosives and devices (lacking any details that would allow the uninformed to produce them) there is an interesting section on ‘Domestic Radicalization’. There will be some that object to the inclusion of ‘radical Christian movements’ in the discussion, but the example of Eric Rudolph demonstrates that they are referring to the violent radical fringe, not the just less-mainstream religious groups. They conclude that slide with a very important point;
“To date, most of the perpetrators of terrorist attacks in the United States have been radicalized by non-Islamic movements.”The slide presentation would almost certainly be more informative if it included the information provided by the presenter, but this is still a good, short reference document on IEDs and their associated tactics.
SECURITY WARNING: Government contractors and members of the federal government should be aware that the document is marked ‘For Official Use Only’ (FOUO) and the fact that you download this from an open source will not exempt you from applying appropriate safeguards for the storage of this document. The last time I looked at FOUO regulations (20+ years ago in the Army) this required the use of an ‘FOUO’ cover sheet and storing in a locked desk drawer or file cabinet.
HR 22 Introduced – Pipeline Safety
Back on January 5th Rep. Spier (D, CA) introduced HR 22, the Pipeline Safety and Community Empowerment Act of 2011 and it was finally made publicly available by the GPO last night. This bill is a duplicate of HR 6295 introduced last September in response to the natural gas pipeline explosion and fire in San Bruno, CA earlier last year.
Communications
As I mentioned in an earlier blog posting, one of the problems identified in that incident was that there was inadequate emergency response planning by both the pipeline operator and the local response agencies. The only thing that this bill does to address this issue is to require that operators provide State and local governments as well as local response agencies with copies of their inadequate emergency response plans. It’s better than nothing, I suppose.
Another thing that this bill does do is to require that pipeline operators periodically inform property owners within 2000 feet of their pipelines of the location of the pipeline. It seems that many of the affected property owners in the San Bruno disaster did not even know that their homes were built almost on top of a large natural gas pipeline.
There has been some concern expressed about the security problems associated with publicly disclosing the location of natural gas and hazmat pipelines. Since it is practically impossible to protect every foot of a pipeline from attack, the disclosure of the actual location of the pipeline could provide a terrorist with vulnerable target information. This provisions in this bill avoid some of this concern by requiring direct communication between the pipeline operator and the property owner rather than a more general public disclosure.
Safety Assurance
There are a couple of provisions that address the issue of safety assurance. Pipeline inspection requirement are enhanced. There are also provisions for requirements for automated or remote shutoff valves to mitigate the effects of a pipeline failure. Leak detection requirements are more clearly spelled out and the definition of ‘high consequence areas’ is expanded.
Incorporated by Reference
A relatively minor provision in this bill may raise the most controversy. Section 7 of the bill requires the Transportation Secretary to ensure that any of the industry standards or procedures ‘incorporated by reference’ in the ‘Federal pipeline regulatory program’ is available to the public free of charge.
It is a fairly standard procedure for regulatory agencies to take technical standards produced by industry groups and engineering societies and refer to them in regulations, effectively making those standards federal law. They do this because there is no way that the Federal government has the personnel resources to develop these standards on their own.
The problem is that many of these standards, particularly those developed by professional associations, have a fairly high cost associated with access to the standards. The reason is that these organizations spend a great deal of money assembling the experts necessary to develop these consensus technical standards. The experts are not typically directly compensated, but there are meetings to hold and documents to produce and print. The market for these documents is very small so the price has to be high to recoup those costs.
The simple language involved in §7 of this bill provides an apparently simplistic solution to a complex problem. It clearly needs to be addressed, but this section will complicate the approval process for this bill since it raises copyright issues and funding for standards development.
Communications
As I mentioned in an earlier blog posting, one of the problems identified in that incident was that there was inadequate emergency response planning by both the pipeline operator and the local response agencies. The only thing that this bill does to address this issue is to require that operators provide State and local governments as well as local response agencies with copies of their inadequate emergency response plans. It’s better than nothing, I suppose.
Another thing that this bill does do is to require that pipeline operators periodically inform property owners within 2000 feet of their pipelines of the location of the pipeline. It seems that many of the affected property owners in the San Bruno disaster did not even know that their homes were built almost on top of a large natural gas pipeline.
There has been some concern expressed about the security problems associated with publicly disclosing the location of natural gas and hazmat pipelines. Since it is practically impossible to protect every foot of a pipeline from attack, the disclosure of the actual location of the pipeline could provide a terrorist with vulnerable target information. This provisions in this bill avoid some of this concern by requiring direct communication between the pipeline operator and the property owner rather than a more general public disclosure.
Safety Assurance
There are a couple of provisions that address the issue of safety assurance. Pipeline inspection requirement are enhanced. There are also provisions for requirements for automated or remote shutoff valves to mitigate the effects of a pipeline failure. Leak detection requirements are more clearly spelled out and the definition of ‘high consequence areas’ is expanded.
Incorporated by Reference
A relatively minor provision in this bill may raise the most controversy. Section 7 of the bill requires the Transportation Secretary to ensure that any of the industry standards or procedures ‘incorporated by reference’ in the ‘Federal pipeline regulatory program’ is available to the public free of charge.
It is a fairly standard procedure for regulatory agencies to take technical standards produced by industry groups and engineering societies and refer to them in regulations, effectively making those standards federal law. They do this because there is no way that the Federal government has the personnel resources to develop these standards on their own.
The problem is that many of these standards, particularly those developed by professional associations, have a fairly high cost associated with access to the standards. The reason is that these organizations spend a great deal of money assembling the experts necessary to develop these consensus technical standards. The experts are not typically directly compensated, but there are meetings to hold and documents to produce and print. The market for these documents is very small so the price has to be high to recoup those costs.
The simple language involved in §7 of this bill provides an apparently simplistic solution to a complex problem. It clearly needs to be addressed, but this section will complicate the approval process for this bill since it raises copyright issues and funding for standards development.
Wednesday, January 12, 2011
HR 174 Introduced – Cyber Security
On the January 5, 2011, the first day of the 112th Session of Congress, Rep. Thompson (D, MS) introduced HR 174, the Homeland Security Cyber and Physical Infrastructure Protection Act of 2011. A copy of the bill is finally available on the GPO web site for public review.
This bill is virtually identical (the only changes other than ‘2011’ for ‘2010’ are the correction of two very minor typographical errors) to HR 6423 from the 111th Congress. The only other difference is that HR 174 has no cosponsors while HR 6423 was cosponsored by Jane Harman (D-CA) and Yvette D. Clarke (D-NY). The earlier bill was introduced during the Lame Duck Session and there was no action taken beyond referring the bill to the Homeland Security Committee and the Committee on Oversight and Government Reform.
As I noted in my blog post on that earlier bill, HR 174 will primarily provide for regulation of government IT networks through an Office of Cybersecurity and Communications (OCSC) at DHS. There is significant language in the bill (§224), however, that would allow for the establishment of CFATS like rules to regulate cyber security activities at critical infrastructure facilities, including the security of industrial control systems. The wording of this authority is broadly written and would allow wide latitude for regulation writers.
Private Sector Regulation
The interesting part of this is that the regulation of private networks and systems would be regulated by the general regulating agency for that industry (first party regulatory agency) or the current sector-specific agency that is responsible for that industry under Homeland Security Presidential Directive 7. For chemical facilities that would be under NPPD at DHS; for electrical facilities, that would be under the appropriate agency at DOE; and for water facilities it would be the appropriate agency at EPA. The actual regulations would be written by the Director of the OCSC, but would effectively be administered by the “first party regulatory agency or sector-specific agency” {§224(a)(5)}.
Information Protection
Section 4 of HR 174 would extend the sensitive security information protections to the information required to be collected, reported and shared in under this new cyber security program. This will set up some interesting security information conflicts if/when a CFATS covered facility comes under these cyber security rules. Identical information could be covered under the SSI rules and the Chemical-Terrorism Vulnerability Information (CVI) provisions of the CFATS regulations. Both are unclassified but sensitive information programs but with significantly different rules, particularly with regard to disclosure in court cases. This conflict needs to be resolved, giving one program or the other primacy.
Cybersecurity R&D
Section 5 of the bill would provide for an extensive cybersecurity R&D effort. It outlines a wide variety of areas that those efforts would address, including attack detection, mitigation and forensics capabilities. Section 5(b)(5) specifically addresses industrial control system (ICS) issues, requiring efforts to “assist the development and support of technologies to reduce vulnerabilities in process control systems”.
Committee Referral
This bill was referred to the Committees on Homeland Security and on Oversight and Government Reform. This early in a new Congress it is hard to forecast how well bills like this will fair in committee. I suspect that it will get a hearing in the Homeland Security Committee and don’t see anything that would draw any particular objections there (though there are a bunch of new players involved so something might strike a cord on someone’s pet peave).
I have no idea how this will be received in the Oversight and Government Reform Committee; it’s not a committee that I have paid much attention to. Their focus would be on the government IT security requirements in §223, not the regulation of industrial systems. Of course, it the bury the bill, it is unlikely to advance to floor consideration.
This is a cyber security bill that we will watch closely.
This bill is virtually identical (the only changes other than ‘2011’ for ‘2010’ are the correction of two very minor typographical errors) to HR 6423 from the 111th Congress. The only other difference is that HR 174 has no cosponsors while HR 6423 was cosponsored by Jane Harman (D-CA) and Yvette D. Clarke (D-NY). The earlier bill was introduced during the Lame Duck Session and there was no action taken beyond referring the bill to the Homeland Security Committee and the Committee on Oversight and Government Reform.
As I noted in my blog post on that earlier bill, HR 174 will primarily provide for regulation of government IT networks through an Office of Cybersecurity and Communications (OCSC) at DHS. There is significant language in the bill (§224), however, that would allow for the establishment of CFATS like rules to regulate cyber security activities at critical infrastructure facilities, including the security of industrial control systems. The wording of this authority is broadly written and would allow wide latitude for regulation writers.
Private Sector Regulation
The interesting part of this is that the regulation of private networks and systems would be regulated by the general regulating agency for that industry (first party regulatory agency) or the current sector-specific agency that is responsible for that industry under Homeland Security Presidential Directive 7. For chemical facilities that would be under NPPD at DHS; for electrical facilities, that would be under the appropriate agency at DOE; and for water facilities it would be the appropriate agency at EPA. The actual regulations would be written by the Director of the OCSC, but would effectively be administered by the “first party regulatory agency or sector-specific agency” {§224(a)(5)}.
Information Protection
Section 4 of HR 174 would extend the sensitive security information protections to the information required to be collected, reported and shared in under this new cyber security program. This will set up some interesting security information conflicts if/when a CFATS covered facility comes under these cyber security rules. Identical information could be covered under the SSI rules and the Chemical-Terrorism Vulnerability Information (CVI) provisions of the CFATS regulations. Both are unclassified but sensitive information programs but with significantly different rules, particularly with regard to disclosure in court cases. This conflict needs to be resolved, giving one program or the other primacy.
Cybersecurity R&D
Section 5 of the bill would provide for an extensive cybersecurity R&D effort. It outlines a wide variety of areas that those efforts would address, including attack detection, mitigation and forensics capabilities. Section 5(b)(5) specifically addresses industrial control system (ICS) issues, requiring efforts to “assist the development and support of technologies to reduce vulnerabilities in process control systems”.
Committee Referral
This bill was referred to the Committees on Homeland Security and on Oversight and Government Reform. This early in a new Congress it is hard to forecast how well bills like this will fair in committee. I suspect that it will get a hearing in the Homeland Security Committee and don’t see anything that would draw any particular objections there (though there are a bunch of new players involved so something might strike a cord on someone’s pet peave).
I have no idea how this will be received in the Oversight and Government Reform Committee; it’s not a committee that I have paid much attention to. Their focus would be on the government IT security requirements in §223, not the regulation of industrial systems. Of course, it the bury the bill, it is unlikely to advance to floor consideration.
This is a cyber security bill that we will watch closely.
TSA Pipeline Guideline Upgrade
Yesterday I discussed the recently issued TSA Pipeline Security Guidelines. I explained that it is a pretty generic document that is internally described as being risk based. To some extent it is since there is a discussion of baseline and enhanced security measures and the risk differentiation is based upon the criticality of the facility. There is no discussion of different levels of security based upon the risk the pipeline facility poses to neighbors as does the CFATS program.
The only real discussion of risk-based security measures is found in the last chapter of the Guidelines. This chapter provides a very (VERY) brief description of the Homeland Security Advisory System (HSAS) and then it states:
I would like to provide my readers with additional information and a discussion of the measures described, but this document is clearly marked as ‘Sensitive Security Information’ and I don’t need to run afoul of the folks at DHS over such a discussion. I will recommend that anyone with any responsibility for pipeline security should contact the folks at Pipeline Security at TSA for a copy of the document.
Misuse of SSI Markings
I think that TSA has little justification for marking this document as ‘Security Sensitive Information’. First the security measures listed are not associated with any facility. Since the Pipeline Security Guidelines that this document supplements is a purely voluntary program there is no requirement for any particular facility to implement these particular security measures.
Furthermore, all of the security measures discussed are generic enough that the general availability of the information would provide little useable information for a terrorist planning an attack on a facility implementing these measures.
Finally, I don’t understand how the security measures described in a similar level of detail in the unmarked Pipeline Security Guidelines are substantially less sensitive than the measures described in this document. Those initial security measures are not considered by TSA to be SSI, why should these?
Overly restricting access to important security information is counter productive. People have a natural tendency to share information and when it is obviously over classified as is this document it allows people to self-justify ignoring the security markings. Once that happens is becomes easier for that individual to ignore those markings on other documents.
The other thing that it does is to stifle legitimate discussion of marked information. There are many items in this document that I would normally specifically address in this blog. That discussion would include pointing out some measures that are in my opinion less than adequate with suggestions for improving upon the measures. Because of the markings on this document I am prohibited from initiating that discussion.
Inadequate Markings
I spent a great deal of time in my Army career handling classified documents. There were extensive rules for handling and marking those documents. One of those rules required the marking of individual paragraphs in a classified document with the security classification of the information in that paragraph when there was information in the document with varying levels of security classification. This made it clear what information could be disclosed in varying security environments.
Chemical-Terrorism Vulnerability Information (CVI) authorized users will recognize this requirement as it is included in the rules for handling and marking that information. CVI and SSI are similar in their general scope and requirements, but agencies and individuals applying SSI markings do not have access to the same level of document handling guidance that the CFATS community does in its CVI Procedures Manual. So there is no particular requirement to include paragraph markings in SSI documents.
Having said that I would like to propose that, once again, the failure to mark uncontrolled information within a document makes it easier for individuals to self-justify ignoring the markings in general. This subverts the intent of the SSI markings. For example, since the title of this TSA document is on an SSI marked page and there are no markings on the title noting that it is not SSI, I am prohibited from publishing the name of the document. This is patently silly, and it sorely tempts my rebellious side to publish the title in spite, but I will refrain. How many others won’t?
The only real discussion of risk-based security measures is found in the last chapter of the Guidelines. This chapter provides a very (VERY) brief description of the Homeland Security Advisory System (HSAS) and then it states:
“TSA has developed a supplement to this document containing a series of progressive security measures to reduce vulnerabilities to pipeline systems and facilities during periods of heightened threat conditions and to establish a consistent security posture within the pipeline industry. This supplement is unclassified but sensitive and is marked as Sensitive Security Information (SSI). The password-protected document may be obtained by email request to pipelinesecurity@dhs.gov.”I have reviewed a copy of this supplemental document and it is an interesting series of security recommendations for each of the five levels of heightened threat conditions. The way it was written it theoretically assumes that security measures were adopted at a threat condition below blue and provides a brief description of the escalation of those security measures as the threat level increases.
I would like to provide my readers with additional information and a discussion of the measures described, but this document is clearly marked as ‘Sensitive Security Information’ and I don’t need to run afoul of the folks at DHS over such a discussion. I will recommend that anyone with any responsibility for pipeline security should contact the folks at Pipeline Security at TSA for a copy of the document.
Misuse of SSI Markings
I think that TSA has little justification for marking this document as ‘Security Sensitive Information’. First the security measures listed are not associated with any facility. Since the Pipeline Security Guidelines that this document supplements is a purely voluntary program there is no requirement for any particular facility to implement these particular security measures.
Furthermore, all of the security measures discussed are generic enough that the general availability of the information would provide little useable information for a terrorist planning an attack on a facility implementing these measures.
Finally, I don’t understand how the security measures described in a similar level of detail in the unmarked Pipeline Security Guidelines are substantially less sensitive than the measures described in this document. Those initial security measures are not considered by TSA to be SSI, why should these?
Overly restricting access to important security information is counter productive. People have a natural tendency to share information and when it is obviously over classified as is this document it allows people to self-justify ignoring the security markings. Once that happens is becomes easier for that individual to ignore those markings on other documents.
The other thing that it does is to stifle legitimate discussion of marked information. There are many items in this document that I would normally specifically address in this blog. That discussion would include pointing out some measures that are in my opinion less than adequate with suggestions for improving upon the measures. Because of the markings on this document I am prohibited from initiating that discussion.
Inadequate Markings
I spent a great deal of time in my Army career handling classified documents. There were extensive rules for handling and marking those documents. One of those rules required the marking of individual paragraphs in a classified document with the security classification of the information in that paragraph when there was information in the document with varying levels of security classification. This made it clear what information could be disclosed in varying security environments.
Chemical-Terrorism Vulnerability Information (CVI) authorized users will recognize this requirement as it is included in the rules for handling and marking that information. CVI and SSI are similar in their general scope and requirements, but agencies and individuals applying SSI markings do not have access to the same level of document handling guidance that the CFATS community does in its CVI Procedures Manual. So there is no particular requirement to include paragraph markings in SSI documents.
Having said that I would like to propose that, once again, the failure to mark uncontrolled information within a document makes it easier for individuals to self-justify ignoring the markings in general. This subverts the intent of the SSI markings. For example, since the title of this TSA document is on an SSI marked page and there are no markings on the title noting that it is not SSI, I am prohibited from publishing the name of the document. This is patently silly, and it sorely tempts my rebellious side to publish the title in spite, but I will refrain. How many others won’t?
Subscribe to:
Posts (Atom)