Yesterday the folks at ISCD updated the CFATS Request a Compliance Assistance Visit web page. The only change that I can see is that the email address for filing a request has changed to CFATS@dhs.gov.
Once again, ISCD is to be commended for not only making these compliance assistance visits available, but to make it so easy to request. The web page suggests just six items of very reasonable information that need to be included in the request and promise a response within two weeks. It goes without saying (and it is not mentioned on the site) that a facility should not propose a CAV date any sooner than two weeks from the date of the request; probably a month or so would be better.
Wednesday, March 16, 2011
Two ICS-CERT Advisories Published
Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published advisories for two SCADA systems; Progea’s Movicon 11 HMI and WellinTech’s KingView HMI. The vulnerabilities in both cases have been verified and patches are available.
Movicon 11 HMI
The vulnerability in this human machine interface (HMI) software may allow a remote attacker with moderate skill level to manipulate data or crash the server. There is no known exploit available for this vulnerability.
In addition to installing the available patch, ICS-CERT recommends consideration of the following mitigation measures:
A stack-based buffer overflow vulnerability in this HMI software may allow a remote attacker with moderate skill level to execute arbitrary code. An exploit is publicly available for this vulnerability. ICS-CERT has listed this vulnerability under a different number than their previous alert on the KingView system, so it is apparently a separate vulnerability.
ICS-CERT recommends replacing the vulnerable .DLL file with the updated version available from WellinTech.
Movicon 11 HMI
The vulnerability in this human machine interface (HMI) software may allow a remote attacker with moderate skill level to manipulate data or crash the server. There is no known exploit available for this vulnerability.
In addition to installing the available patch, ICS-CERT recommends consideration of the following mitigation measures:
• Implement firewall rules to limit network access to the Movicon system on Port 10651/TCP.KingView HMI
• Update Movicon to the latest Version 11.2.
• Minimize network exposure for all control system devices. Critical devices should not directly face the Internet.
A stack-based buffer overflow vulnerability in this HMI software may allow a remote attacker with moderate skill level to execute arbitrary code. An exploit is publicly available for this vulnerability. ICS-CERT has listed this vulnerability under a different number than their previous alert on the KingView system, so it is apparently a separate vulnerability.
ICS-CERT recommends replacing the vulnerable .DLL file with the updated version available from WellinTech.
Tuesday, March 15, 2011
HJ Res 48 Passes in House
This afternoon the House passed HJ Res 48, the latest short-term continuing resolution to keep the Federal government funded through April 8th. The vote of 271 to 158 was very bipartisan. The bulk of the Republicans were joined by 85 Democrats in voting for the measure while 54 Republicans joined the majority of the Democrats in voting against the bill. The bill now needs to be taken up and passed by the Senate before midnight Friday to avoid a now generally unexpected government shutdown.
CG Voluntary Use of TWIC Reader Notice
Today the Coast Guard published a notice in the Federal Register announcing that Policy Advisory Council (PAC) Decision 01-11, “Voluntary Use of TWIC Readers”, was now available for comment. This document “provides guidance for using Transportation Security Identification Credential (TWIC) readers as part of a Vessel Security Plan or Facility Security Plan” (76 FR 14038) pending the issuance of the TWIC Reader rule (the NPRM is expected late this year; no telling when the final rule will become effective). This would be the document that I have been talking about here since January.
This notice provides a general overview of the guidance document. It notes that it describes how the TWIC Reader is used to verify identification, card validity and card authentication in place of the current method of checking the card photograph against the personal appearance of the card’s presenter. This guidance applies to the use of TWIC Readers “that have passed the Initial Capability Evaluation Test” conducted by the TSA. The notice reminds the TWIC community that there is no guarantee that the Readers on that list will be on the approved list in the final rule.
This CG Notice reminds MTSA covered facilities and vessels that, if they intend to implement this voluntary use of TWIC Readers, “they must submit a Vessel Security Plan or Facility Security Plan amendment in accordance with applicable regulations” (76 FR 14039). Non-MTSA facilities intending to use TWIC readers as part of their personnel surety program would probably due well to download this guidance document and reference it in their program documentation.
There is no effective date for this guidance document provided in this Notice and I am not familiar enough with Coast Guard procedures to know if this document becomes effective policy upon release of this notice. The notice does make clear, however, that the Coast Guard is looking for public comments on the document and wants those comments submitted by May 16, 2011. Those comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2011-0129).
BTW: The Coast Guard web site is also providing a copy of a FEMA guidance document on how this affects grant applications under the Port Security Grant Program (PSGP) and the Transit Security Grant Program (TSGP).
This notice provides a general overview of the guidance document. It notes that it describes how the TWIC Reader is used to verify identification, card validity and card authentication in place of the current method of checking the card photograph against the personal appearance of the card’s presenter. This guidance applies to the use of TWIC Readers “that have passed the Initial Capability Evaluation Test” conducted by the TSA. The notice reminds the TWIC community that there is no guarantee that the Readers on that list will be on the approved list in the final rule.
This CG Notice reminds MTSA covered facilities and vessels that, if they intend to implement this voluntary use of TWIC Readers, “they must submit a Vessel Security Plan or Facility Security Plan amendment in accordance with applicable regulations” (76 FR 14039). Non-MTSA facilities intending to use TWIC readers as part of their personnel surety program would probably due well to download this guidance document and reference it in their program documentation.
There is no effective date for this guidance document provided in this Notice and I am not familiar enough with Coast Guard procedures to know if this document becomes effective policy upon release of this notice. The notice does make clear, however, that the Coast Guard is looking for public comments on the document and wants those comments submitted by May 16, 2011. Those comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2011-0129).
BTW: The Coast Guard web site is also providing a copy of a FEMA guidance document on how this affects grant applications under the Port Security Grant Program (PSGP) and the Transit Security Grant Program (TSGP).
HJ Res 48 Reported by Rules Committee
Last night the House Rules Committee finished developing the rule for the consideration of HJ Res 48, Additional Continuing Appropriations Amendments, 2011. This will be considered under a closed rule (no floor amendments will be allowed) and only one hour of debate will be allowed. This is pretty much the same as the rule for the previous short-term CR. This resolution will likely be considered by the House today.
A number of news organizations are reporting that some conservative Republicans are planning on voting against this resolution because they feel that it doesn’t go far enough and that a final resolution needs to be worked out, not another short term deal. That being said, there are almost certainly enough Democrats that will vote in favor of this legislation to allow it to pass in the House, and probably do so in the Senate.
A number of news organizations are reporting that some conservative Republicans are planning on voting against this resolution because they feel that it doesn’t go far enough and that a final resolution needs to be worked out, not another short term deal. That being said, there are almost certainly enough Democrats that will vote in favor of this legislation to allow it to pass in the House, and probably do so in the Senate.
HR 1007 Introduced – Terrorist Watchlist Redress
Last week Rep. Clarke (D, NY) introduced HR 1007, the Fair, Accurate, Secure, and Timely (FAST) Redress Act of 2011. The legislation is designed to put into place a formal appeal mechanism for air line passengers who are incorrectly identified as a potential security risk base upon their name being found on the terrorist watch list.
While the main focus of the legislation is to assist improperly targeted air line passengers, Rep. Clarke took care to ensure that it would apply to anyone adversely affected by being matched with a suspect name on the watchlist. In describing the establishment of the redress procedure it is described as a “process for individuals who believe they were wrongly delayed or prohibited from boarding a commercial aircraft or denied a right, benefit, or privilege by the Department because they were wrongly identified as a threat when screened against the terrorist watchlist used by the Transportation Security Administration” {§890A(a)}.
This could potentially affect two separate programs of interest to the chemical security community; the TWIC program and the CFATS personnel surety program that will sooner or later be announced by ISCD. In fact, one of the provisions that was included in last session’s HR 2868 (as passed by the House) was a requirement for the establishment of a similar redress process for the personnel surety program spelled out in that legislation.
Redress Process
The bill would establish the Office of Appeals and Redress. The Director of that office would report directly to the Secretary, probably because the use of the watchlist cuts across so many of the agencies within the Department. The Director would establish a redress process (specifically including an information technology system) that would address “case management, workflow, document management, recordkeeping, and interoperability issues” {§890A(c)(1)}.
The program would be designed to generally allow the redress process to be completed within 30 days. Additionally, to ensure that the problem remains resolved, the Director would be responsible for maintaining a ‘Comprehensive Cleared List’ of individuals whom have provided adequate identification to allow the system to determine that they were misidentified by the use of the terrorist watchlist. That ‘Cleared List’ would be specifically incorporated into the screening process used by TSA and US Customs and Border Protection (CBP) and other Federal, State and local agencies using the terrorist watchlist as a security screening tool.
Privacy Protection
As one would expect in legislation introduced by Rep. Clarke, there are fairly extensive provisions provided for the protection of personal information. These include privacy and security training, requirements for data encryption and provisions for sharing the personally identifiable information (PII) via an encrypted network.
While the bill would require individuals handling PII in accordance with 552a of title 5, United States Code, the Federal Information Security Management Act of 2002 (Public Law 107–296), the bill specifically exempts one type of PII from those requirements, legal name changes. Section 890A(e)(7) specifically states that “section 552a of title 5, United States Code, shall not prohibit the sharing of legal name changes among Federal agencies and entities for the purposes of this section”.
Redress Initiation
The legislation requires that TSA and CBP provide clear and unambiguous notice at air ports and ports of entry on the existence of the appeals process and guidance on how to initiate the process. Interestingly there are no other requirements for public acknowledgement of the process, no requirement to tell someone denied a TWIC or the ability to work at a high-risk chemical facility that there is an applicable appeals process to correct the misidentification of being a potential terrorist risk.
While the main focus of the legislation is to assist improperly targeted air line passengers, Rep. Clarke took care to ensure that it would apply to anyone adversely affected by being matched with a suspect name on the watchlist. In describing the establishment of the redress procedure it is described as a “process for individuals who believe they were wrongly delayed or prohibited from boarding a commercial aircraft or denied a right, benefit, or privilege by the Department because they were wrongly identified as a threat when screened against the terrorist watchlist used by the Transportation Security Administration” {§890A(a)}.
This could potentially affect two separate programs of interest to the chemical security community; the TWIC program and the CFATS personnel surety program that will sooner or later be announced by ISCD. In fact, one of the provisions that was included in last session’s HR 2868 (as passed by the House) was a requirement for the establishment of a similar redress process for the personnel surety program spelled out in that legislation.
Redress Process
The bill would establish the Office of Appeals and Redress. The Director of that office would report directly to the Secretary, probably because the use of the watchlist cuts across so many of the agencies within the Department. The Director would establish a redress process (specifically including an information technology system) that would address “case management, workflow, document management, recordkeeping, and interoperability issues” {§890A(c)(1)}.
The program would be designed to generally allow the redress process to be completed within 30 days. Additionally, to ensure that the problem remains resolved, the Director would be responsible for maintaining a ‘Comprehensive Cleared List’ of individuals whom have provided adequate identification to allow the system to determine that they were misidentified by the use of the terrorist watchlist. That ‘Cleared List’ would be specifically incorporated into the screening process used by TSA and US Customs and Border Protection (CBP) and other Federal, State and local agencies using the terrorist watchlist as a security screening tool.
Privacy Protection
As one would expect in legislation introduced by Rep. Clarke, there are fairly extensive provisions provided for the protection of personal information. These include privacy and security training, requirements for data encryption and provisions for sharing the personally identifiable information (PII) via an encrypted network.
While the bill would require individuals handling PII in accordance with 552a of title 5, United States Code, the Federal Information Security Management Act of 2002 (Public Law 107–296), the bill specifically exempts one type of PII from those requirements, legal name changes. Section 890A(e)(7) specifically states that “section 552a of title 5, United States Code, shall not prohibit the sharing of legal name changes among Federal agencies and entities for the purposes of this section”.
Redress Initiation
The legislation requires that TSA and CBP provide clear and unambiguous notice at air ports and ports of entry on the existence of the appeals process and guidance on how to initiate the process. Interestingly there are no other requirements for public acknowledgement of the process, no requirement to tell someone denied a TWIC or the ability to work at a high-risk chemical facility that there is an applicable appeals process to correct the misidentification of being a potential terrorist risk.
Monday, March 14, 2011
HR 963 Introduced – SARS Immunity
Last week Rep. Smith (R, TX), the Chairman of the House Judiciary Committee, introduced HR 963, the See Something, Say Something Act of 2011. Now if you think that this sounds familiar it is because I wrote last week about S 505 which had the same title. In fact, the observant reader might remember that I wrote that the earlier bill was a companion measure to HR 495.
I explained in the blog about S 505 that a companion bill is an identical bill introduced into the second house of Congress to make it easier to get the bill through committees in an expeditious manner. The language in S 505 and HR 495 are identical.
HR 963 is not technically a companion bill to S 505 and it can’t be a companion bill to HR 495, having been introduced into the same house of Congress. I say that it cannot ‘technically’ be considered a companion bill because it is not identical; it differs in just one word from the other two bills. In §890A(b)(1) S 963 says, in part; “authorized official as defined by section (d)(1)(A)”. The other two bills say; “as defined by sub-section”. As you can clearly see this is a substantial difference (SARCASM ALERT).
The earlier bill, authored by Rep. King (R, NY) was assigned to the House Judiciary Committee for consideration, the Committee chaired by Rep. Smith (R, TX). It is obvious that Chairman Smith and his committee staff are extremely diligent in reviewing legislation referred to their committee (I know there was already one sarcasm alert in this post). Anyone want to bet which bill gets reported out of Committee?
BTW: In my listing of legislation, I am going to tack HR 963 to the listing for HR 495 to which I have already tacked S 505. Sorry about that Rep. Smith, but here I try to go first come, first serve.
I explained in the blog about S 505 that a companion bill is an identical bill introduced into the second house of Congress to make it easier to get the bill through committees in an expeditious manner. The language in S 505 and HR 495 are identical.
HR 963 is not technically a companion bill to S 505 and it can’t be a companion bill to HR 495, having been introduced into the same house of Congress. I say that it cannot ‘technically’ be considered a companion bill because it is not identical; it differs in just one word from the other two bills. In §890A(b)(1) S 963 says, in part; “authorized official as defined by section (d)(1)(A)”. The other two bills say; “as defined by sub-section”. As you can clearly see this is a substantial difference (SARCASM ALERT).
The earlier bill, authored by Rep. King (R, NY) was assigned to the House Judiciary Committee for consideration, the Committee chaired by Rep. Smith (R, TX). It is obvious that Chairman Smith and his committee staff are extremely diligent in reviewing legislation referred to their committee (I know there was already one sarcasm alert in this post). Anyone want to bet which bill gets reported out of Committee?
BTW: In my listing of legislation, I am going to tack HR 963 to the listing for HR 495 to which I have already tacked S 505. Sorry about that Rep. Smith, but here I try to go first come, first serve.
Subscribe to:
Posts (Atom)