Wednesday, September 14, 2011

Rules Committee Hearing for HJ Res 79 – FY 2012 Continuing Resolution

Early this evening the House Rules Committee announced that it would be holding a hearing tomorrow morning for developing the rule for the consideration of HJ Res 79, the Continuing Appropriations Resolution, 2012. This bill would continue the current FY 2011 funding levels, with some exceptions, through November 11, 2012. This will provide some additional time for the Senate to complete their consideration of at least some of the FY 2012 spending bills (certainly including DHS) currently spending.

As expected, the CR would also extend the current CFATS authorization. Section 130 of the CR reads:

“Section 550(b) of the Department of Homeland Security Appropriations Act, 2007 (6 U.S.C. 121 note) shall be applied by substituting the date specified in section 106(3) [November 18th, 2011] of this joint resolution for ‘October 4, 2011’”.

DHS ICS-CERT Issues Multiple Alerts

This morning DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published alerts about reported vulnerabilities in six different industrial control systems:


The alerts don’t give much information beyond the fact that vulnerabilities have been reported and apparently exploit codes are available. Some of the systems have multiple vulnerabilities reported. ICS-CERT doesn’t give any information on the security researcher that published the vulnerability information.

I saw an entry on SCADASEC list yesterday that listed vulnerabilities in many of the same systems and that message noted that Luigi Auriemma had listed them on Bugtrac. That Bugtrac message included links to Luigi’s explanation of the vulnerabilities. Interestingly, Norton is providing “Malicious Web Site Blocked” notices for those notes. The Luigi note also lists vulnerabilities in Carel PlantVisor and BroadWin WebAccess.

In closing his Bugtrac note Luigi left the following comment: “If there will be enough interest in these sectors [control systems and financial trading software] I will release new vulnerabilities in the next weeks.” Luigi continues to make control system security interesting.

HR 963 Report Published – SAR Immunity

On Monday the House Judiciary Committee filed their report (H. Rept 112-204) on HR 963, the See Something, Say Something Act. The Committee had ordered the bill favorably reported at their markup hearing for the bill that was held back in July. The publication of this report now clears the bill for possible floor action by the whole House.

Since there were no amendments adopted in the markup of this bill there are no changes in the bill that we had to wait for this report to review. There are no surprises in the description the report makes about the provisions of the bill.

The most interesting part of the report is found at the end; the Dissenting Views section. Here the Committee Democrats outline their concerns that “H.R. 963 may end up promoting racial profiling, thereby violating the constitutional rights of those targeted individuals” (page 18). As I noted in my blog posting on the markup hearing, we will almost certainly see floor amendments to this bill addressing these concerns, but I doubt that any will be adopted by the House.

Tuesday, September 13, 2011

HR 2846 Introduced – Maritime SAR Immunity

Last week Rep. Rigell (R,VA) introduced HR 2846, the Suspected Maritime Activities Reporting of Terrorism (SMART) Immunity Act. The bill would extend the suspicious activity reporting immunity provisions currently found in 6 USC §1104 to non-passenger maritime vessels and facilities.

The current version of §1104 provides SAR immunity for reports about suspicious activity involving or directed against “a passenger transportation system or vehicle” {§1104(d)(2)}. This bill would revise that by keeping the current ‘transportation system’ language as subparagraph (A) and adding a subparagraph (B) that would address vessels, maritime facilities, ports and waterways “whether or not a passenger is threatened”.

Transportation Security Subcommittee to Markup TSA Authorization Bill

The House Homeland Security Committee announced yesterday that its Transportation Security Subcommittee will be holding a markup hearing this tomorrow on an as yet unpublished ‘TSA Authorization Act’. Since this is an ‘open markup’ it is expected that this will be a multiple day hearing.

Ranking Member Jackson-Lee has introduced a bill (HR 1900) that would specifically authorize ground transportation security measures for TSA. Provisions from that bill might be included in the bill being marked up in this hearing or may be added as amendments to Chairman Rogers’ (R,AL) bill.

More on New CSAT Registration Manual

As I noted last week DHS has published a new version of their CSAT User Registration User Guide. I’ve now had a chance to look at the new manual and compare it to the previous version. There have been some interesting changes.

New Version Number


As you would expect the latest version has a different version number; Version 5.0. The confusing thing is that the latest version that I had in my files was Version 2.0a. I would have thought that there should have been a ‘3.0’ and a ‘4.0’ before we got to this new ‘5.0’ version. Since there is no management of change documentation included in this new version I can’t tell for sure if I maybe missed a couple of versions.

The date for the ‘2.0a’ version that I am comparing this new version to is April 2008 which was apparently published on the CSAT web site on May 8th. The current CSAT web site notes that the ‘current’ version of the manual dates from July 2008. So, there may have been at least one other version that I have missed.

It would be nice if DHS published a notice when they update their various CFATS manuals.

Lead Preparer


When the SSP tool was introduced a couple of years ago it quickly became obvious that many facilities were going to be using multiple preparers to input the information into that very lengthy on-line questionnaire. In this Registration Manual it doesn’t specifically mention that multiple preparers are authorized, but it does include a separate position of ‘Lead Preparer’. This would be the individual that is designated to turn completed documents over to the ‘Submitter’ for final review before submission.

All facilities are required to designate a ‘Lead Preparer’. The Lead Preparer can be the same person as the Submitter or Authorizer for the facility. A consultant can be designated as the Lead Preparer for a facility.

Position Pre-requisites


The new manual no longer has a detailed listing of pre-requisites that personnel meeting the various roles must meet. In the old manual the Submitter, for instance, was required to be either an officer of the corporation or designated by an officer and had to be “domiciled in the United States” (pg 21). The only restriction on selection of a Submitter listed in the new manual is that consultants “hired by a Facility to assist with the CSAT data collection process may not act as Facility Submitters” (pg 4).

The new manual does note that the following questions will be asked about Submitters and Authorizers, but it doesn’t specifically note that these are pre-requisites.

• Is the individual a U.S. Citizen?

• Is the individual an Officer of the Corporation or designated by an Officer of the Corporation?

• Is the individual domiciled in the U.S.?

The first and last questions listed above will also be asked about Preparers and Reviewers.

Bulk Uploads


The new manual indicates that DHS has made provisions for organizations that have a large number of facilities that must be registered. DHS has developed a spread sheet that can be used for uploading registration data for organizations with “50 or more Facilities” (page 12). For further information on this program contact the CSAT Help Desk.

Other Changes


I don’t see any other substantive changes in the manual but there are numerous changes in format and layout of the manual.

Monday, September 12, 2011

HR 2871 Introduced – Pipeline Safety

Last week Rep. Speier (D,CA) introduced HR 2871, the Pipeline Modernization for Safety Act of 2011. This bill addresses two very specific pressure related issues for pipelines with segments without documented pressure tests.

The bill would modify 49 USC §60108 by adding a new paragraph dealing with ‘integrity verification requirements’; adding two requirements for pipelines with segments without documented pressure tests. The first {§ 60108(e)(2)} would direct the Secretary (DOT) to require pipeline operators to either hydro-test or replace those pipeline segments. The second {§ 60108(e)(3)} would direct the Secretary to establish regulations requiring the reporting of any pressure increase above the maximum allowable operating pressure (MOAP) designated for those untested line segments.

The regulations establishing these two new requirements would be required to be published in their final form within two years of this bill’s adoption.

Rep Jackie Speier became interested in pipeline safety issues after the San Bruno explosion and fire in her District. Last session she introduced HR 6295, the Pipeline Safety and Community Empowerment Act of 2010 which died in committees.
 
/* Use this with templates/template-twocol.html */