Tuesday, August 16, 2011

NTSB Meeting – San Bruno Pipeline Fire


The National Transportation Safety Board (NTSB) announced in today’s Federal Register (76 FR 50759) that it would be holding a meeting on August 30, 2011 to review its report on the September 9, 2010 natural gas pipeline rupture and fire in San Bruno, CA. The meeting in Washington, DC will be open to the public and may be viewed on-line on the NTSB web site.

This incident is the poster child for pipeline safety that is driving provisions for many of the pipeline safety bills that are currently pending in Congress. Specific topics that might be expected to come up in this meeting include:

• Control system issues;
• Pipeline integrity management;
• Pipeline right-of-way management;
• Emergency response planning;
• Emergency response notification;
• Pipeline pressure management; and
• The use of automatic shut-off controls.

The first issue may be of significant interest to multiple communities that read this blog. Joe Weiss continues to identify this incident as a control system cyber incident that could have ICS security implications. Neither Joe nor anyone else I have read or talked to has even hinted that they thought that this was a result of a deliberate attack on a control system. Instead many people have expressed concerns that control system shortcomings identified in this incident could be exploited in a possible attack on pipelines. The expected call for the expanded use of automated shutoff valves would extend the range of the possible cyber-attacks on pipelines.

Monday, August 15, 2011

Reporting Cybersecurity Incidents


The Repository of Industrial Security Incidents (RISI) is an independent organization that collects and analyzes information about, and reports on, cybersecurity incidents involving industrial control systems. This weekend they announced a new online incident reporting form that allows for the anonymous reporting about industrial control system security incidents.

There is no other organization that (sorry ICS-CERT) that has a similar mandate. Since this is a non-governmental organization they have no way of requiring facilities to report these incidents. They rely on voluntary reporting and public news reports to maintain their data base of industrial control system security incidents.

RISI provides an incentive for reporting incidents; they provide one month of free access to reports and information to anyone reporting an ICS security incident. This will, of course, require some self-identification, but RISI maintains strict confidentiality. They note on their web site that:

“All reporting to RISI is strictly confidential. The security of all submitted information is of critical importance to RISI and all sensitive references are removed (and not masked) so there is no risk to the contributor or company. In addition, the investigative database is not available on line so identity data is not at risk from cyber theft.”

I would like to urge all readers working in chemical facilities (and any other facility that uses industrial control systems) to utilize this new reporting form to report any industrial control system security incidents. If the incident is an apparent attack, by all means report to law enforcement authorities first, but please follow-up with a report to RISI.

Sunday, August 14, 2011

Ammonium Nitrate Security Program NPRM – Record Keeping


On August 3rd DHS published their Ammonium Nitrate Security Program (ANSP) notice of proposed rulemaking (NPRM). This blog post is part of a continuing series that looks at provisions of that NPRM. This post looks at the requirements for reporting loss and/or theft of ammonium nitrate. Previous posts in this series included:







Who Reports


Subtitle J provides the legal requirement that any AN Facility Representative or Designated AN Facility POC with knowledge of a theft or unexplained loss must report that loss to Federal law enforcement authorities within 24 hours. Since it is unlikely that these individuals will have total first-hand knowledge of everything that goes on at the AN Facility, the facility management is required to have procedures in place to ensure that internal reports of theft or loss are forwarded to the AN Facility Representative or POC in a timely manner.

Subtitle J did not provide a requirement for AN Purchasers or agents acting on their behalf to report theft or loss of AN so DHS cannot require them to do so in this regulation. DHS does, however, take the opportunity in the preamble to encourage “them to do so using the same procedures that AN Facility personnel would use” (76 FR 46933).

Reporting to ATF


Since ISCD, which will administer the ANSP, does not have criminal investigative personnel on staff, it wouldn’t make much sense to have AN theft or loss reports go directly to them. This regulation would require the report to be made to the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). This reporting would follow standard ATF procedures; requiring an initial telephonic notification with follow-up reporting to be conducted by submitting a completed form via FAX or US Mail.

While the underlying law does not require AN Facilities to report the theft or loss of ammonium nitrate to local authorities in addition to the required Federal notification, DHS does encourage facilities to make the local report as well. From a practical perspective, in most cases local law enforcement personnel will be able to respond to the crime scene quicker and may be able to intercept the perpetrators before the ATF personnel are even able to respond to the scene.

How Much to Report


In determining the quantity threshold that requires reporting, DHS looks at two different situations. The first situation is where there is a clearly defined theft of AN; any amount stolen would have to be reported. The second situation, where there is a known or suspected loss of AN due to an unidentified cause, the situation becomes more complicated.

That complication arises because AN is frequently shipped in bulk. Bulk shipping losses are a well-known problem in the industry and the amount that is routinely lost during these shipments varies on the type transportation used, the length of the transport, the weather and a number of other issues. So DHS will require loss reporting when “those losses deviate from the amount of loss that typically occurs during routine production, storage, transportation, or use of ammonium nitrate” (76 FR 46934).

Commentary


I understand the Department’s reasoning in selecting the ATF as the designated agency to handle the investigation of ammonium nitrate thefts and losses. They are typically the lead agency in matters relating to explosives. I do think, however, that DHS has missed an important intelligence gathering opportunity by the way they handle the reporting process.

The initial telephonic report to ATF is probably the way to go with that portion of the process. The follow-up written report would probably be better off submitted through the secure ANSP web site. The site will already be established and the AN Facility personnel will already be familiar with it. If the reporting format were established as tool on that web site (akin to the tools in the CSAT website used by the CFATS program) the information could be electronically sent directly to ATF. At the same time it could be sent to the intelligence folks at DHS for further analysis. Of course I would prefer to see it sent to a yet to be established Chemical Security Fusion Center, but that is fodder for another blog post.

A more fundamental problem exists with the loss reporting requirements. I fully understand the problem with ‘normal losses’ incident to transportation and handling. The problem is that without defining ‘normal losses’ DHS is setting up a situation where they will, in effect, be encouraging facilities to use the widest possible definition of that terminology to avoid the headaches associated with loss reporting.

The only way that I see around this problem is to add a requirement for a routine, periodic report on ‘normal losses’ at the facility. Again, a reporting tool on the ANSP secure web site would help to make this requirement as painless as possible. This would ensure that each facility was keeping the records necessary to be able to define what was a ‘normal loss’ that did not require reporting to the ATF.

ICS-CERT Updates Cybersecurity Evaluation Tool


Friday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an updated version of their Cyber Security Evaluation Tool (CSET, v 4.0). According to the ICS-CERT web site:

“This new release includes new standards such as NERC CIP Revision 3, NRC Regulatory Guide 5.71, a new key requirements set, and Version 7 of the DHS "Catalog of Security Requirements: Recommendations for Standards Developers." The new CSET also includes a fully revised set of reports with complete gap rankings, new diagramming functionality, and a new resource library as well as minor enhancements. This tool supports evaluations of both business and industrial control systems.”

CSET Description


CSET is a downloadable (also available on DVD; request by email to: CSET@dhs.gov) stand-alone desktop software tool that allows a facility to assess their network and ICS security practices. According to the CSET Fact Sheet CSET compares the facility answers to a lengthy list of questions “against recognized industry and government standards, guidelines, and practices” and it “provides a prioritized list of recommendations for increasing the cybersecurity posture of an organization’s ICS or enterprise network and identifies what is needed to achieve the desired level of security within the specific standard(s) selected”.

The standards available for evaluation include:

• DHS Catalog of Control Systems Security: Recommendations for Standards Developers, Revisions 6 and 7;

• NIST SP800-82;

• NIST SP800-53, revision 3;

• NRC Regulatory Guide 5.71;

• CFATS Risk Based Performance Standard (RBPS) 8;

• NERC CIP-002-009 revisions 2 and 3;

• ISO/IEC 15408 revision 3.1;

• DoDI 8500.2; and

• Consensus Audit Guidelines 2.3.

CSET and CFATS


Alert readers will notice that the above list of standards (taken directly from the CSET Fact Sheet) includes a listing of CFATS. In a post about an earlier version of CSET I wrote that:

“Will this help facilities with their CFATS cyber security requirements? Since there are no specifically delineated requirements for a cybersecurity system under CFATS, that is a hard question to answer. I think that a tool like this will help facilities identify current security issues and provide suggestions on how to deal with them. Having used this system to identify and correct system shortcomings certainly would provide a good basis for justifying a facility’s program to inspectors.”

It would appear that the newest version of CSET would allow an evaluation of a covered facility’s cybersecurity against the performance standards in RBPS #8 and that is a good thing and should provide a valuable tool for facilities to use to prepare their cyber security portion of their SSP. But, it should be clear that while ICS-CERT and ISCD are both parts of DHS, they don’t talk for one another.

I have not seen a memorandum of understanding between ICS-CERT and ISCD that would establish the CSET as an official evaluation tool for RBPS #8 (and the same thing would apply even more so to NERC CIP-002). It might be a good idea for ISCD to consider such a move, it would ease the evaluation burden on their Chemical Facility Security Inspectors and provide a level of cybersecurity expertise that is almost certainly lacking (through no fault of their own) in the inspection teams.

ICS-CERT Assistance


One last point needs to be made about the CSET tool. It was designed to be used by the facility to conduct a self-evaluation. ICS-CERT believes that a facility with enough control system expertise to manage an ICS should be able to conduct the evaluation. But they realize that that may not be the case at all facilities and ICS-CERT has made provisions for that; “the Control Systems Security Program also offers onsite training and guidance to asset owners in using CSET during onsite assessments. These assessments are conducted at no cost to the asset owners [emphasis included in original]”. This assessment assistance can be requested by email to: CSET@dhs.gov.

Social Engineering Attacks and LinkedIn


I’ve mentioned social engineering attacks as a method that attackers may use to get access to relatively secured networks. While many social engineering attacks are bulk type attacks, targeted at anyone in an organization, we have been hearing more and more about targeted attacks. These attacks are targeted at specific people in an organization, control systems engineers or technicians for instance.

The question often arises how do attackers select the targets of the spear phishing attacks? Well one way is through the perusal of social networking sites; particularly the professional sites liked Linkedin.com. In the modern networked society in which we operate it would be a waste of time to recommend that personnel in security sensitive positions for go the use of these sites; too much valuable information is exchanged via this medium.

No, what every security expert that I have heard over the last couple of years say is that everyone should be careful about the information that they share on these sites and who they share it with. Frequently this is easier said than done as the managers of these sites are not really concerned about secondary security issues like providing information that could be used in developing a targeted social engineering attack to gain access to an industrial control system.

I had an interesting bit of information shared with me by a long time reader. It seems that LinkedIn has learned a new marketing trick from Facebook. Linked in describes it this way:

LinkedIn may sometimes pair an advertiser's message with social content from LinkedIn's network in order to make the ad more relevant. When LinkedIn members recommend people and services, follow companies, or take other actions, their name/photo may show up in related ads shown to you. Conversely, when you take these actions on LinkedIn, your name/photo may show up in related ads shown to LinkedIn members. By providing social context, we make it easy for our members to learn about products and services that the LinkedIn network is interacting with.

So if you follow an automation company like Siemens or any of a hundred other vendors your name and picture could show up on one of their LinkedIn ads. Someone interested in attacking one of their installations could follow you back to your profile and learn who you work for. From there most people can guess your corporate email address and you are now a target.

Linked in has provided a way for people to opt out of this program so they are not totally clueless; though it does seem odd that they haven’t publicized this option. Anyway, thanks to one of my cybersecurity readers here is the simple technique for protecting yourself against this source of potential social engineering attack targeting:

• Log into your LinkedIn account;

• In the upper right corner of the screen, select 'Settings' under your name;

• Go to 'Account' on the bottom left side of the screen and select 'Manage Social Advertising' under ‘Privacy Controls’;

• Disable the box which states 'LinkedIn may use my name & photo in social advertising'; and

• Click on ‘Save’

This is a simple enough process. It took me literally seconds to complete. I recommend that if you occupy any type of security sensitive position, you should do the same.

Saturday, August 13, 2011

PHMSA Pipeline Public Awareness Program ICR – 30-day Notice


On Monday the Pipeline and Hazardous Material Safety Administration (PHMSA) (will) published in the Federal Register (76 FR 50539) [sorry about the tense confusion, it was published today on-line but it will appear Monday in the print edition and that is the official date of publication] a 30-day Information Collection Request (ICR) renewal notice for their Public Awareness Program for operators of natural gas and hazardous liquid pipelines.

According to the notice abstract:

“The Federal Pipeline Safety Regulations require each operator to develop and implement a written continuing public education program that follows the guidance provided in the American Petroleum Institute's Recommended Practice RP 1162. Upon request, operators must submit their completed programs to PHMSA or, in the case of an intrastate pipeline facility operator, the appropriate state agency. The operator's program documentation and evaluation results must also be available for periodic review by appropriate regulatory agencies (49 CFR 192.616 and 195.440).”

Cut and Paste Problems


It’s interesting that this is the second renewal of the ICR and the response and burden information is the same as was published in the original ICR. This would typically mean one of three things:

• This is an annual requirement with a fixed respondent community;

• Every year there is a near-constant number of new entrants into the community; or

• The regulators have no idea what the actual burden is and are just cutting and pasting the information from the original submission.

I can find nothing in §192.616 or §194.440 that describes this as other than a one-time requirement to establish the program and ‘implement’ it. That implementation may require periodic educational and communications actions to be taken by the operator, but that has no practical effect on the ‘information collection’ described in this ICR. That information collection is the submission of the program for PHMSA and/or State and local review upon request.

I doubt that there are 22,500 new pipeline operators entering the business each year. That leaves just the last possibility and I really suspect that that is just what is happening in this request. I’m not trying to blame PHMSA for being lazy, it is just that the way OMB has structured their approval process it appears that cut and paste ICR’s have an easier time making it through the approval process in a timely manner.

The regulated community has not complained (And why should they?  The ICR is a meaningless process for the most part for the private sector.). Without their objection there is no incentive for PHMSA to make a real effort to complete this request in a detailed and factual manner if that will lead to delays in the OMB approval process.

Public Comments


PHMSA is soliciting public comments (as required by 5 USC §1320.8(d)) on this ICR submission. Public comments should be sent to:

Office of Management and Budget
Office of Information and Regulatory Affairs
Attn: Desk Officer for the U.S. Department of Transportation
725 17th Street, NW.
Washington, DC 20503

Public comments should be submitted by September 14, 2011.

Friday, August 12, 2011

Explosive Threat Awareness Training Canceled


Readers will remember that earlier this week, in my post about the updated Chemical Sector Training and Resources page, I noted that the Chemical Sector Explosive Threat Awareness Training Program (CSETATP) had been removed from the list of available training programs listed on that page. At the time of that post I wasn’t sure if the program had in fact been canceled or if there were just no sessions scheduled for the near future. I contacted the Chemical Sector Specific Agency to see what was going on.

Here is the explanation that I received:

“Unfortunately, the CSETAT program description was removed because the contract that funded the training has ended. We are currently assessing what our options might be in the future. If alternative or additional explosive threat awareness training options are identified, we will post them on the Web site – so keep checking.”

It sounds to me that if someone had a program ready to go and could reach an agreement with Chemical SAA then we could have continued training in this area. It really is an important area for every security manager to be knowledgeable in and most civilians are woefully mis-informed about matters explosive; too much Hollywood information out there.

I’m sure that there are official vendor channels to go through, but if you’re interested in talking to the Chemical SAA folks you can probably start the discussion with an email to them at Chemicalsector@dhs.gov.
 
/* Use this with templates/template-twocol.html */