As I mentioned in an earlier blog on the House Homeland Security Committee’s dual subcommittee hearing on weapons of mass destruction, Rep. Pascrell (D, NJ) introduced HR 2356, the WMD Prevention and Preparedness Act of 2011. The bill, which finally became available on the GPO web site late last week, was co-sponsored by a bipartisan group of Committee members including Chairman King (R, NY) and Ranking Member Thompson (D, MS).
I had expected that this would be a re-introduction of HR 5057 from last session, but it is not. It is a complete re-write of that earlier bill. As in the earlier bill, the primary focus of this legislation is preventing and responding to bio-attacks by terrorists, surely a high-consequence but low-probability event. There are, however, many more inclusions of the all-hazards terminology; “chemical, biological, radiological, and nuclear threats” (CBRN), potentially making provisions of this bill applicable to preventing and responding to the use of industrial chemicals in a terrorist attack.
Risk Assessment
One of the primary areas where this all-hazards approach is most evident is found in the proposed amendments to the Homeland Security Act, particularly the inclusion of proposed §2102, Risk Assessments. This would require the Secretary to produce a risk assessment of CBRN threats. It requires an “integrated risk assessment that assesses all of those threats and ranks them against one another according to their relative risk” {§2102(a)(2)}.
While the detonation of a nuclear device would certainly kill more people and a biological attack could affect a larger area of the country, any real assessment of attack probability would have to take into account the relative ease of conducting chemical attacks using industrial chemicals. An integrated risk assessment of the type required by this section should clarify that relative risk.
Individual and Community Preparedness
Another area that is not specifically directed at counter-bioweapons actions is the area of community response. Section 2106 calls for FEMA to “assist State, local, and tribal authorities in improving and promoting individual and community preparedness and collective response to terrorist attacks involving chemical, biological, radiological, and nuclear materials against the United States” {2106(a)}.
This is further expanded under §2131 where the Secretary is required to develop for “police, fire, emergency medical services, emergency management, medical and public health personnel, voluntary guidance for responding to a release of chemical, biological, radiological, or nuclear material” {§2131(a)(1)}. The guidance would also be required to be disseminated to “State, local, and tribal authorities, including primary and secondary school administrators, nongovernmental organizations, the private sector, and the public”{§2131(a)(2)}.
The guidance developed under this section is specifically required to be “voluntary, risk-based guidance”{§2131(b)} and is required to include “specific information regarding the effects of the chemical, biological, radiological, or nuclear material on those exposed to the agent”{§2131(b)(2)}. The latter is going to be a difficult mandate to meet due to the wide variety of effects of an even wider variety of materials of concern for anything but ‘nuclear material’.
I think that it would be appropriate to include language in this section requiring high-risk chemical facilities to work with local authorities and response organizations to develop and communicate this type of information for all release toxic chemicals of interest (COI) that the facility might have on hand.
Plume Modeling
A major concern in the emergency response planning for any of these WMD attacks is determining where the CBRN agent might be expected to spread once released. The tool used to predict this spread is plume modeling. Section 2132 of this proposed legislation would require the Secretary to “acquire, use, and disseminate the best available integrated plume models to enable rapid response activities following a chemical, biological, nuclear, or radiological attack or event”{§2132(a)(1)}.
It is interesting that this section includes the ‘attack or event’ language. This plume modeling software would certainly be beneficial to response planning and execution for accidental chemical releases as well as terrorist attacks.
I am a little concerned about the wording of the requirement for local officials to establish mechanisms for disseminating ‘integrated plume models’ to “nongovernmental organizations and the public to enable appropriate collective response activities”{§2132(a)(2)(B)}. There seems to be some confusion between the tool (the integrated plume model) and the information produced by the model once appropriate timely local information is fed into the tool. The information should certainly be shared with the public in the event of an incident and the tool should be shared with appropriate NGO’s involved in emergency response planning.
An important component that is missing from this section is the requirement to include the news media in the requirements for ensuring that “that guidance and training in how to appropriately use such models are provided” {§2132(a)(2)(C)}. The news media needs to clearly understand the information produced by these models as they will be the ones disseminating live information to the public during any emergency. Again, a clear distinction needs to be made between the operation of the model and understanding the output of the model.
Recovery from CBRN Attacks or Incidents
The final area of this legislation that is of potential importance to the chemical security community is §2142 that deals with the recovery from a CBRN attack or incident. Again, the importance of including ‘incidents’ is especially important for high-risk chemical facilities with large holdings of toxic release COI. Accidental releases are much more likely than a release as of a result of a terrorist attack and current emergency response rules totally ignore the recovery aspect of a release incident.
The Secretary is required to develop the appropriate guidance “for clean-up and restoration of indoor and outdoor areas, including subways and other mass transportation facilities, that have been exposed to chemical, biological, radiological, or nuclear materials”{§2142(a)}. The Secretary is required to consult with the appropriate authorities is almost every department of the Federal government in developing this guidance.
A significant part of this guidance includes the requirement to “clarify Federal roles and responsibilities for assisting State, local, and tribal authorities”{§2142(b)}. The same paragraph outlines risk-based recommendations for a wide variety of expected actions that will need to be taken.
Again, I have a concern about the specific wording for one of these recommendations. Section 2142(b)(5) requires recommendations for “maintenance of negative air pressure in buildings”. This level of detail should not be included in a piece of legislation because it could lead people to believe that ‘negative air pressure’ is needed in most incidents when it is only appropriate when the release is within the building in question. Positive air pressure is needed when the contamination is outside of the building.
Exercises
The final section of the bill is devoted to the planning of exercises. Unfortunately, the actual wording of this section is severely defective. The single sentence contains too many qualifying phrases and phrases expanding the requirement, but there is never a specific requirement for what the Secretary is supposed to do beyond the fact that the “Secretary shall develop exercises”. It reads as if the entire section was a last minute after thought.
Moving Forward
I am much happier with the wording of this bill than I was with the language in last sessions HR 5057. I still think that there is entirely too much concern with the extremely low probability biological attack by terrorists. But the general provisions for identifying, preventing, responding and recovery to and from general CBRN terrorist attacks makes up for that excessive concern.
I expect that the Homeland Security Committee in the House will formally take up this legislation fairly quickly. There is general support for this type of legislation in the Senate Homeland Security Committee, but there will need to be some coordination of efforts if this bill is to make it through the legislative process this session.
Monday, July 11, 2011
ICS-CERT Publishes Memory Corruption Advisory
Last Friday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an advisory on a memory corruption vulnerability in the 7-Technologies IGSS human machine interface (HMI) application.
The vulnerability in the Open Database Connectivity (OBDC) component could allow an attacker with advanced skills to remotely execute arbitrary code. There is no known publicly available exploit for this vulnerability. 7-Technologies has published a patch, but recommends upgrading to a more recent version that does not contain the vulnerability. Hmmm… did they know about the vulnerability and remove it in the newer version or was the removal as unintentional as the original insertion?
The interesting thing about this reported vulnerability is that it is an indication that security researchers are digging deeper into these systems to find newer types of vulnerabilities. Of course, finding this vulnerability in the IGSS HMI will ensure that other researchers look for the same type vulnerability in other SCADA HMI applications.
The vulnerability in the Open Database Connectivity (OBDC) component could allow an attacker with advanced skills to remotely execute arbitrary code. There is no known publicly available exploit for this vulnerability. 7-Technologies has published a patch, but recommends upgrading to a more recent version that does not contain the vulnerability. Hmmm… did they know about the vulnerability and remove it in the newer version or was the removal as unintentional as the original insertion?
The interesting thing about this reported vulnerability is that it is an indication that security researchers are digging deeper into these systems to find newer types of vulnerabilities. Of course, finding this vulnerability in the IGSS HMI will ensure that other researchers look for the same type vulnerability in other SCADA HMI applications.
Sunday, July 10, 2011
S 275 – Pipeline Safety Bill – Reported in Senate
Last week the Senate Committee on Commerce, Science, and Transportation published their report on S 275, the Pipeline Transportation Safety Improvement Act of 2011. Additionally, the revised version of the bill that was approved by that Committee was placed on the GPO web site. This is the first time that we have been able to see the ‘amendment in the form of a substitute’ that was adopted in the Committee mark-up of this bill that was held on May 5th, 2011.
The provisions of the bill that I wrote about in my post on the introduction of the bill remain essentially unchanged. The only change I’ve noted in the revised bill is that the emergency response plan reporting requirements are spelled out in more detail in {§8(a)(2)}.
New Sections Added to the Bill
The revised bill includes two completely new sections and replaces a section in the original version with a section covering a new topic.
The revised section is §9; it has a new title; “Cast Iron Pipelines.” It replaces the section requiring a GAO report. The Committee report summarizes the new section:
The first requirement of §27 would be for the Secretary to “require pipeline operators to conduct a verification of records for all interstate and intrastate gas transmission lines in class 3 and class 4 locations and class 1 and class 2 high consequence areas that accurately reflect the pipeline’s physical and operational characteristics and confirm the established maximum allowable operating pressure of those pipelines.” {§27(a)(1)}
This first requirement is important and is fully outlined in the Committee ‘Section-by-Section’ summary of the bill. From an emergency response perspective the more important requirement is spelled out in §27(b)(2). That section requires pipeline operators to “report any exceedance of the maximum allowable operating pressure for gas transmission pipelines that exceed the build-up allowed for operation of pressure limiting or control devices to the Secretary not later than 5 working days after the exceedance occurs.”
The five day requirement is kind of bizarre; this type of ‘exceedance’ was an immediate precursor to the San Bruno catastrophe. Not all such ‘exceedances’ would presage a catastrophic release or explosion, but some would. Since minutes count in the response to these type incidents, immediate notification of State and local responders should be the standard with a follow-up report to PHMSA within 5 days that would include a root-cause analysis and corrective action plan.
The provisions of the bill that I wrote about in my post on the introduction of the bill remain essentially unchanged. The only change I’ve noted in the revised bill is that the emergency response plan reporting requirements are spelled out in more detail in {§8(a)(2)}.
New Sections Added to the Bill
The revised bill includes two completely new sections and replaces a section in the original version with a section covering a new topic.
The revised section is §9; it has a new title; “Cast Iron Pipelines.” It replaces the section requiring a GAO report. The Committee report summarizes the new section:
“This section would require the Secretary to conduct a follow-on survey of that required in 49 U.S.C. 60108(d) to determine progress that has been made on the extent to which each operator has adopted a plan to safely manage and replace cast iron pipelines in its system. This section would require that the Secretary perform this survey biannually.”The two new sections are inserted before the last section in the bill; the old §27 now becomes § 29. The new §27 is titled: “Maximum Allowable Operating Pressure”. The new §28 is titled: “Administrative enforcement process”. The §28 provisions are legally significant, but are not important in a safety context.
The first requirement of §27 would be for the Secretary to “require pipeline operators to conduct a verification of records for all interstate and intrastate gas transmission lines in class 3 and class 4 locations and class 1 and class 2 high consequence areas that accurately reflect the pipeline’s physical and operational characteristics and confirm the established maximum allowable operating pressure of those pipelines.” {§27(a)(1)}
This first requirement is important and is fully outlined in the Committee ‘Section-by-Section’ summary of the bill. From an emergency response perspective the more important requirement is spelled out in §27(b)(2). That section requires pipeline operators to “report any exceedance of the maximum allowable operating pressure for gas transmission pipelines that exceed the build-up allowed for operation of pressure limiting or control devices to the Secretary not later than 5 working days after the exceedance occurs.”
The five day requirement is kind of bizarre; this type of ‘exceedance’ was an immediate precursor to the San Bruno catastrophe. Not all such ‘exceedances’ would presage a catastrophic release or explosion, but some would. Since minutes count in the response to these type incidents, immediate notification of State and local responders should be the standard with a follow-up report to PHMSA within 5 days that would include a root-cause analysis and corrective action plan.
EPA Submits 2012 Methyl Bromide NPRM to OMB
On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) published a notice on their web site that the Environmental Protection Agency had submitted a notice of proposed rule making setting out the “2012 Critical Use Exemption from the Phaseout of Methyl Bromide”. As I have noted in many previous posts, the use of methyl bromide is being phased out under the Montreal Protocol as it is considered to be an ozone destroying chemical. This rule will set forth the authorized uses of this fumigant for 2012, including specifying how much may be produced or imported for those uses.
This rule, when it is approved by OMB, will be very similar to the 2011 regulation that I discussed back in March. The main difference is that there will almost certainly be a slight reduction from the 1500 MT production authorized in the previous rule. The big reductions won’t start taking effect until 2014 when more of the current authorized uses are phased out.
The EPA seems to be getting this rule finished earlier this cycle. Publication of the 2011 rule took place in March forcing the EPA to unofficially notify producers and users of the numbers that could be used in the 2011 planting season. Given any kind of reasonable attention to this rule in OMB and then again in the EPA process should allow to them to meet the December 2011 target date set forth in the Unified Agenda for this rule.
I’ll forgo my typical rant about the need for methyl bromide to be included in the DHS list of chemicals of interest (COI) used by the CFATS regulations. Anyone that hasn’t seen it too often can go back and read the section “Methyl Bromide COI Status” section of my blog post on the previous annual exemption rule.
This rule, when it is approved by OMB, will be very similar to the 2011 regulation that I discussed back in March. The main difference is that there will almost certainly be a slight reduction from the 1500 MT production authorized in the previous rule. The big reductions won’t start taking effect until 2014 when more of the current authorized uses are phased out.
The EPA seems to be getting this rule finished earlier this cycle. Publication of the 2011 rule took place in March forcing the EPA to unofficially notify producers and users of the numbers that could be used in the 2011 planting season. Given any kind of reasonable attention to this rule in OMB and then again in the EPA process should allow to them to meet the December 2011 target date set forth in the Unified Agenda for this rule.
I’ll forgo my typical rant about the need for methyl bromide to be included in the DHS list of chemicals of interest (COI) used by the CFATS regulations. Anyone that hasn’t seen it too often can go back and read the section “Methyl Bromide COI Status” section of my blog post on the previous annual exemption rule.
House Passes HR 2219, the FY 2012 DOD Appropriations Bill
On Friday, the full House, after three days of floor amendments, passed the FY 2012 DOD appropriations bill in a decidedly bipartisan manner; 336 to 87. Over half of the Democrats in the House voted for the bill (112-75) and there were 12 Republicans voting against the bill
No further homeland security or cyber security measures were brought to the floor. The two amendments that I discussed in the previous blog on this bill were not submitted for actual consideration.
This means that, for homeland security or cyber security purposes, this bill remains essentially the same as I described in my post on the Appropriations Committee report on the bill.
Senate Inaction
This bill will move to the Senate for consideration, hopefully before the start of the 2012 fiscal year on October 1st. Typically the Senate would substitute language from their own version of the bill to start the consideration process. The Senate Appropriations Committee has not yet published even a draft sub-committee version of their bill yet.
I suspect that the main reason for the delay is the continuing discussions on the debt limit extension. Since there will apparently be some sort of spending cuts included in the final deal, it probably makes sense for the Senate to hold off. This is especially true since the cuts in their version of the bill will probably be significantly different than those found in the House passed bill.
No further homeland security or cyber security measures were brought to the floor. The two amendments that I discussed in the previous blog on this bill were not submitted for actual consideration.
This means that, for homeland security or cyber security purposes, this bill remains essentially the same as I described in my post on the Appropriations Committee report on the bill.
Senate Inaction
This bill will move to the Senate for consideration, hopefully before the start of the 2012 fiscal year on October 1st. Typically the Senate would substitute language from their own version of the bill to start the consideration process. The Senate Appropriations Committee has not yet published even a draft sub-committee version of their bill yet.
I suspect that the main reason for the delay is the continuing discussions on the debt limit extension. Since there will apparently be some sort of spending cuts included in the final deal, it probably makes sense for the Senate to hold off. This is especially true since the cuts in their version of the bill will probably be significantly different than those found in the House passed bill.
Friday, July 8, 2011
OMB Approves Ammonium Nitrate NPRM
The Office of Information and Regulatory Affairs (OIRA) at OMB published a notice yesterday on its web site that they had approved the notice of proposed rulemaking submitted by the DHS Office of Infrastructure Protection for the establishment of the Secure Handling of Ammonium Nitrate Program (RIN: 1601-AA52). The approval was given ‘consistent with change’, indicating that OMB required some relatively minor changes to the NPRM.
This long overdue NPRM (required to be published by 5-26-2008) should be published in the Federal Register in the next two or three weeks even though the recent Unified Agenda projected it to be published last month.
This long overdue NPRM (required to be published by 5-26-2008) should be published in the Federal Register in the next two or three weeks even though the recent Unified Agenda projected it to be published last month.
HR 2219 Floor Consideration – Wednesday 7-6-11
Over the last two days the House has been spending considerable time working on the DOD spending bill, HR 2219. The late hours that the House has been keeping on this bill have been delaying the publication of the Congressional Record so I’m about a day behind looking at the progress of the bill for effects on homeland security issues.
Wednesday – Action on Amendments
In Wednesday’s session only one amendment concerning homeland security issues was considered. The amendment by Rep. Clarke (D, MI) that I discussed in an earlier blog transferring DOD funds to DHS was brought up on the floor by Mr. Clarke. As I predicted a point of order was raised against this amendment because of the rule against transferring money to or from the funds designated as being for spending on the Global War on Terrorism (GWOT). No effort was made to overturn the Chair’s upholding of the point of order.
Wednesday – New Homeland Security Amendments
House members are encouraged to publish their intended amendments to this bill in the Congressional Record, allowing advanced review of the amendments by staff so that Members can make a more informed vote when the amendment is actually submitted on the floor. Wednesday’s Congressional Record contained a number of new amendments; two of which may be of interest of to the homeland security community and one of those is actually cyber security related.
First the cyber security amendment; Rep. Lipinski (D, IL) published amendment #91 that adds a new section to the bill that would read:
The other homeland security related amendment was amendment #76 submitted by Rep. Shuler (D, NC) which would also add a new section to HR 2219 that would read:
If or when these amendments are actually offered on the floor we may get additional information when the member uses their allotted 5 minutes of discussion to urge a positive vote on the amendment.
Wednesday – Action on Amendments
In Wednesday’s session only one amendment concerning homeland security issues was considered. The amendment by Rep. Clarke (D, MI) that I discussed in an earlier blog transferring DOD funds to DHS was brought up on the floor by Mr. Clarke. As I predicted a point of order was raised against this amendment because of the rule against transferring money to or from the funds designated as being for spending on the Global War on Terrorism (GWOT). No effort was made to overturn the Chair’s upholding of the point of order.
Wednesday – New Homeland Security Amendments
House members are encouraged to publish their intended amendments to this bill in the Congressional Record, allowing advanced review of the amendments by staff so that Members can make a more informed vote when the amendment is actually submitted on the floor. Wednesday’s Congressional Record contained a number of new amendments; two of which may be of interest of to the homeland security community and one of those is actually cyber security related.
First the cyber security amendment; Rep. Lipinski (D, IL) published amendment #91 that adds a new section to the bill that would read:
“None of the funds made available by this Act may be used by the Department of Defense to replace an information technology system that stores classified information in the United States with an information technology system that stores such classified information outside the United States.”I’m not sure what this means unless there is some plan currently under consideration that would use a server farm outside of the US to replace an aging facility in the United States (one would expect in Illinois). From a security perspective the physical location of a server farm is really only of concern because of physical security issues. One would assume that DOD would do as good a job of providing physical security for facilities overseas as they would here in the States. I would expect that the most likely location for an overseas server farm would be at the US facility in Diego Garcia and I doubt that you could get a more secure physical location; not much in the way of commercial travel to that island facility.
The other homeland security related amendment was amendment #76 submitted by Rep. Shuler (D, NC) which would also add a new section to HR 2219 that would read:
“None of the funds made available in this Act may be used to restrict cooperation between employees of the Department of Defense and employees of the Department of Homeland Security.”This is another one of those vague amendments that makes little or no sense on first reading; in this case on second and third reading as well. How could one vote against such a ‘motherhood and apple pie’ amendment?
If or when these amendments are actually offered on the floor we may get additional information when the member uses their allotted 5 minutes of discussion to urge a positive vote on the amendment.
Subscribe to:
Posts (Atom)