Sunday, May 19, 2013

Comments for TWIC Reader NPRM – 5-18-13


This is part of a continuing series of blog posts on the public comments filed in the previous week for the Coast Guard’s TWIC Reader NPRM. The previous posts in the series are listed below.


This week we have 14 submissions, two of which come from the same person and one from a previous commentor. There is no indication that any of these commenters were affected by the recent congressional hearing on the TWIC Reader Pilot, but it may be just too soon to expect responses to reflect that hearing.

Flash Pass for Each Entry

The requirement for a TWIC holder to present the TWIC for visual inspection upon each entry to secure spaces on board vessels continues to be identified as a concern by many commenters, particularly passenger vessel operators.

TWIC Readers on Vessels

An individual commenter made an interesting observation about requiring TWIC Readers on Vessels. He noted that all vessel entries are via facilities thus entry onto a vessel is already covered by a TWIC Reader at the facility. This does not take into account the entry of personnel at foreign ports or access to vessels underway (pilots for instance).

TWIC Reader Pilot Participant

A commenter that was a participant in the TWIC Reader Pilot noted that they experienced “failed readers, failed hot-list, excessive time burden (and) lost data”. They note that: “As a TWIC Pilot Program (sic) participant, we strongly believe the pilot has not adequately demonstrated the justification of the cost of the program.”

Vessel vs Facility Reader Requirements

A commenter noted that they were told at a regional public meeting that passenger facilities handling vessels certified to carry over 1,000 passengers would be required to utilize TWIC Readers even if the vessels serving the facility were not because of the 14-person provisions. The commenter argues that facility reader requirements should be more closely linked to the reader requirements of the vessels that serve the facility.

Comment Period Extension

The original comment period for this NPRM would have ended this coming Tuesday. We would have expected to see a surge in comments being submitted on Monday and Tuesday. With the one month extension already having been announced, it will be interesting to see if this has any significant effect on those expected submissions.

NRC Publishes Transportation Security Rule


The Nuclear Regulatory Agency (NRC) published a final rule in Monday’s Federal Register (78 FR 29519-29557; available on-line yesterday) regarding the Physical Protection of Irradiated Reactor Fuel in Transit. This is the first major revision of the provisions of 10 CFR 73.37 since it was established in 1980. Section 73.37, Requirements for physical protection of irradiated reactor fuel in transit, is being revised and §73.38 is being added.

I certainly don’t intend to expand the general coverage of this blog to nuclear security matters, but I do think that a brief look at the security measures required for transportation of nuclear fuel provides a look at how involved transportation security measures can be. I’ll leave for another day the discussion of the relative security risks associated with a small (101 gram) shipment of nuclear fuel and a 40,000 lb tank wagon shipment of a toxic inhalation hazard (TIH) chemical.

Purpose of Regulations

Section 73.37(a) sets forth the security performance objectives that each licensee that transports or causes to be transported more than 100 grams of irradiated reactor fuel will achieve. These objectives are twofold:

• Minimize the potential for theft, diversion, or radiological sabotage of spent nuclear fuel shipments; and
• Facilitate the location and recovery of spent nuclear fuel shipments that may have come under the control of unauthorized persons.

To achieve these objectives requires the use of physical protective systems that:

• Provide for early detection and assessment of attempts to gain unauthorized access to, or control over, spent nuclear fuel shipments;
• Delay and impede attempts at theft, diversion, or radiological sabotage of spent nuclear fuel shipments; and
• Provide for notification to the appropriate response forces of any attempts at theft, diversion, or radiological sabotage of a spent nuclear fuel shipment.

Required Security Measures

Security measures required by this final rule include:

• Preplan and coordinate spent nuclear fuel shipments;
• Advance notifications;
• Transportation physical protection program; and
• Contingency and response procedures.

The NRC requires the submission of detailed preplan; including route, safe havens, and local law enforcement coordination; which must be approved by the NRC before it can be implemented. These requirements apply to all shipments by road, rail, or US waterways.

Additional specific requirements are provided for shipments by road. These include:

• Provisions for armed escorts;
• Redundant 2-way communications capabilities;
• Vehicle immobilization devices;
• Continuous and active telemetric position monitoring;

Background Checks

The final rule adds a new §73.38, Personnel access authorization requirements for irradiated reactor fuel in transit. This requires the establishment of an access authorization program. The program will apply not only to personnel with unaccompanied access to spent nuclear fuel in transit but also personnel who:

• Could adversely impact the safety, security, or emergency response to spent nuclear fuel in transit;
• Are responsible for implementing a licensee's physical protection program;
• Have access to spent nuclear fuel shipment information; or
• Is the access authorization program reviewing official.

As one would expect the access authorization program must include provisions for completing background checks on covered individuals. The checks will include:

• Personal history disclosure;
• Criminal history;
• Verification of true identity;
• Employment history;
• Credit history;
• Character and reputation; and
• Determination of trustworthiness and reliability.

Interestingly, there is no specific requirement to vet an individual for terrorist ties through the Terrorism Screening Database (TSDB) or any other specific terrorism related list.

Regulatory Detail

All of the above requirements are spelled out in great regulatory detail.

Clearly the NRC and its regulated community take security much more seriously than does PHMSA and/or TSA. Certainly the security of nuclear materials is a serious matter, but these rules apply to shipments as small as 101 grams, or about a ¼ of a pound. How much of this is based upon a realistic threat assessment and how much of this is based upon a knee-jerk fear of radioactive materials is not clear.

Saturday, May 18, 2013

NPPD Publishes 30-Day ICR for PCII Officers Questionnaire


The DHS National Protection and Programs Directorate’s Infrastructure Information Collection Division (IICD) published a 60-Day information collection request (ICR) notice in Monday’s Federal Register (78 FR 29375-29376; available on-line today) supporting a questionnaire targeted at State and local Protected Critical Infrastructure Information (PCII) Officers. The questionnaire would help the Department “to gather information from PCII Officers that can be used to assess their programs, their compliance with PCII rules and requirements, and the specific needs of their accredited programs”.

The Importance of PCII Programs

The Department posted a 60-day ICR notice in the Federal Register back in November, 2012. In a post about that notice I expressed some concerns about the Department’s just now getting around to assessing these State and local programs with which DHS shares selected PCII information. Since the promise of limited disclosure is the only incentive that DHS can provide critical infrastructure organizations to share security information with DHS, any questions about the efficacy of State and local PCII programs will act as a disincentive to information sharing.

The new Cybersecurity Framework under development will depend on PCII programs to protect the information about critical infrastructure computer systems and networks provided to the government. This means that the PCII protections are going to have to be a critical part of the Framework. Again, this makes assessment of State and local PCII programs all that more important.

Earlier Comments

The current notice states that “DHS received no comments”. A review of the Docket (DHS-2012-0046) at www.Regulations.gov shows that there was a comment submitted on November 28th. Terry Frank from Shell Oil Company noted that it would be difficult to assess the accuracy of the collection effort since a copy of the questionnaire is not made available. This is a point I also made in my earlier blog post. This is particularly aggravating since NPPD is required to include the questionnaire when it files this ICR with OMB. It could easily be placed in the current docket.

Mr. Frank also notes a discrepancy in the description of information disclosure protections provided by the PCII program. Since that comment is not really germane to the ICR in question, I suppose that DHS was justified in ignoring that portion of the comment. Still the comment should have been noted in this ICR notice.

Public Comments

NPPD is soliciting public comments on this 30-day ICR notice. Comments may be filed via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0046). The notice does not contain the customary ‘submit comments by’ information, but this is a 30-day notice so comments should be filed within 30 days of the publishing of the notice on Monday; so June 18th, 2013.

NOTE: With the failure to acknowledge the comment filed on the 60-day notice and the failure to include a comment closure date in this notice, perhaps NPPD should consider re-submitting this 30-day ICR notice in proper form.


EPA Submits 2013 Methyl Bromide Final Rule to OMB


Yesterday the Environmental Protection Agency (EPA) submitted their final rule for the 2013 Critical Use Exemption from the Phaseout of Methyl Bromide to OMB. This rule will authorize the use of methyl bromide for critical agricultural uses that are exempted from the provisions of the Montreal Protocol on Substances that Deplete the Ozone Layer. The production and use of methyl bromide was supposed to have been phased out in 2005, but there are protected agricultural uses of the material that are re-authorized every year because there are no effective substitutes.

As is typical for the EPA in this annual exercise, this final rule will not be published until well after the 2013 production and use of methyl bromide has already started. Back in December, recognizing that they would not fulfill their regulatory obligation in time for the spring application of methyl bromide, the EPA published a letter notifying the manufacturers and users of methyl bromide that the EPA would “exercise its enforcement discretion not to pursue enforcement for violations of 40 CFR §82.4 against companies” identified in the NPRM published in December 2012.

Long time readers of this blog will undoubtedly remember (I’ve reminded them enough times) that the DHS chemicals of interest (COI) list for the CFATS program had methyl bromide removed from the proposed list because they believed EPA when it said that methyl bromide was being phased out. This toxic inhalation hazard (TIH) chemical would normally have been included on the COI list because of its toxic characteristics. This means that three of the four manufacturer/importers of methyl bromide and an indeterminate number of distributors are not required to report their inventories in excess of 10,000 lbs of the material to DHS under the CFATS program.

Once again I would like to suggest that DHS, as part of their on-going review of the COI list in Appendix A to 6 CFR Part 27, actively consider adding methyl bromide back to the list.

NIST Publishes Initial Analysis of Framework Responses


In just over a month since the last comment was posted on the Cybersecurity Framework RFI web site NIST has published an initial review of the over 200 comments received. As one would expect from an technology oriented organization like NIST, this review was based upon an automated identification, correlation and review of specific search terms. NIST notes that:

“This initial analysis will serve as the basis for additional discussion and study at the Cybersecurity Framework Workshop #2 to be hosted at Carnegie Mellon University in Pittsburgh on May 29-31, 2013. In preparation for this workshop, we ask that all participants review the RFI submissions and this initial analysis.”

Categorizing Common Themes

The automated review/search techniques used by NIST allowed the identification of common themes within the submitted comments and the abstraction of comments related to those themes so that those comments could be grouped together for future review and analysis. (NOTE: The methodology used here should be adapted into a standard package that could be used by any federal regulatory agency for the initial analysis of large volumes of comments received in regulatory actions; 30-days to conduct this level of analysis is remarkable.)

The NIST review document breaks these comment components into three categories with a number of themes identified within each category. Those categories and themes are (note ‘X%’ refers to the percentage of comments that addressed the specific theme):

Framework Principles - Characteristics and considerations the Framework must encompass:

• Flexibility (35.8%)
• Impact on Global Operations (64.6%)
• Risk Management Approaches (81.1%)
• Leverage Existing Approaches, Standards, and Best Practices (33.3%)

Common Points - Practices identified as having wide utility and adoption:

• Senior Management Engagement (67.0%)
• Baseline Security (20.9%)
• Understanding Threat Environment (75.3%)
• Business Risk/ Risk Assessment (68.7%)
• Separation of Business and Operational Systems (60.0%)
• Models / Levels of Maturity (19.7%)
• Incident Response (27.9%)
• Cybersecurity Workforce (61.7%)

Initial Gaps - initial gaps are those areas where RFI responses were not sufficient to meet the goal of the Executive Order:

• Metrics (59.2%)
• Privacy / Civil Liberties (52.2%)
• Tools (55.9%)
• Dependencies (57.2%)
• Industry Best Practices (65.4%)
• Resiliency (46.5%)
• Critical Infrastructure Cybersecurity Nomenclature (27.1%)

Discussion of Themes

Each of the themes identified above has its own associated high-level discussion provided in this analysis document. The discussion includes:

• A brief description;
• Associated key terms and phrases;
• A brief statistical analysis;
• Examples of specific supporting comments in RFI’s; and
• A list of the associated RFI questions.

I’m not exactly sure why NIST did this, but each of the examples of supporting comments has been sanitized so that it is not possible to identify the commentor. This information is available if one were to read each of the 200+ comments, so it is not done to protect the reputation of the commentor. I suppose that if the comments were not sanitized that some people might not be able to generalize the comments to the larger universe of potentially affected organizations.

Further Discussion

If NIST really wants these comments to be a basis for the discussion at the next cybersecurity framework workshop (and the draft agenda certainly seems to indicate that) then it would be helpful if they were to make their database of extracted comments available on-line. That way all of the specific comments on a particular theme could be accessed without having to read the totality of each of the submitted comments.

Control System Themes

Of the total of 19 themes identified in this analysis, only one specifically refers to industrial control system security issues; Separation of Business and Operational Systems. The fact that this was actually identified in 60% of the comments submitted is absolutely amazing because of the small number of manufacturing organizations submitting comments. To be fair, NIST actively solicited comments on this topic with three separate questions addressing the issue.

The four abstracted comments that are included in this theme discussion are motherhood and apple pie comments supporting the separation of ICS and IT systems. I have not seen anything that addresses the very real problem of de-linking enterprise and control systems. This is certainly an area that I would like to see the complete listing of the specific comments (in 60% of the responses????) posted on this theme.

I am severely disappointed that the topics raised by Chris Blask, Chair of the Industrial Control System Information Sharing and Analysis Center (ICS-ISAC), do not fall into any of the neat categories or themes identified in this analysis. His comments on vulnerability reduction should be an important part of any framework discussion about control systems.

Not All Comments Considered

There is an interesting footnote on page one of this report; it states:

“Responses identified as spam or marketing and sales materials were not posted or reviewed by NIST.”

I certainly sympathize with the folks at NIST. Over the years writing this blog I have read a number of comments submitted to various rules that were, objectively, a complete waste of time. The reasons varied from being completely off topic, to being so poorly written as to be incomprehensible or their being political diatribes. But, these were all included in the political record of the rulemaking process.

I am particularly concerned about the exclusion of ‘marketing and sales material’. There are a number of organizations, particularly in the control system security community, that have cutting edge ideas and approaches to securing cyber-systems. While I certainly do not expect (nor would I condone) NIST to specify a specific security system or device, I think that this discussion needs to take into account the state of the art in security systems and devices. It seems to me that the exclusion of these from the public record is short sighted at best and probably legally indefensible.

Moving Forward

I think that this document produced by NIST is a valuable initial analysis of the lengthy and varied comments submitted to the agency is a very short period of time. The speed with which NIST accomplished this high-level review should be a bench mark for other regulatory actions. Actually, the mere publication of this review at this stage of the development of the framework should serve as a model for developers of regulations.

It will be interesting to see how the discussions based upon these comments at the Pittsburg workshop will turn out.

Friday, May 17, 2013

NPPD Updated NSTAC Meeting Notice


Today the DHS National Protection and Programs Directorate published an update to their recent National Security Telecommunications Advisory Committee (NSTAC) meeting notice in the Federal Register (78 FR 29145). The update changes the date by which written comments on the agenda items must be submitted from the previously reported May 13th, 2013 to May 21st, 2013.

Consequences of CFATS Authorization Renewals


I had an interesting communication yesterday with a reader who has a personal connection to the CFATS program (and thus needs to remain anonymous). After reading my post about the draft DHS spending bill that was marked up yesterday this connected reader was struck by the program consequences of this annual (well, ‘randomly periodic’ might be better terminology than ‘annual’) reauthorization. This connected reader had a question and an observation that I think are worth sharing; first the observation and then the question.

Top Screen Submission Failures

Connected notes that “one reason there has been so many places reluctant to submit a top screen (sic) is due to this temporary authorization process through the history of the program”. I think that this may be a classic case of assuming facts not in evidence. We do have a recent history of a very public facility that had not filed a Top Screen, but I have not seen or heard any definitive statement as to why that Top Screen was not filed.

Having said that, I do think that it is safe to assume that there are a number of facilities that have not completed a required Top Screen submission. How many is anyone’s guess, but I would suspect that a realistic range would be somewhere between 1% and 10% of the facilities that are required to submit a Top Screen. I would be surprised (but not amazed) if it were over 10%. I would almost bet money that it was not less than 1%.

The reasons why such a large number of facilities (as many as 4,000 at the upper end) will be as varied as the types of facilities involved. I would bet, however, that the major categories of reasons would include (in no particular order):

• General mistrust of the Federal Government;
• Lack of knowledge of the CFATS program;
• Misunderstanding of the term chemical facility;
• Avoidance of the cost of compliance; and
• Fear of getting involved in a costly compliance regime that is doomed to be canceled.

While we don’t have any firm numbers for any of these categories, I think everyone can agree with Connected that at least some portion of non-compliant facilities wants to avoid getting caught-up in an expensive security program that will inevitably fail to be reauthorized in the not too distant future.

Why the Periodic Reauthorization

Connected asks an interesting question; have any of the other existing chemical safety/security programs “such as MSHA, OSHA, MTSA, or EPA had to endure a litany of successive temporary authorizations before getting their permanent authorizations”? The short answer is ‘No’, but that doesn’t provide any useful information unless we also examine the corollary question; why does CFATS have to undergo this periodic renewal? Again a short answer is ‘Politics; and it requires some explication.

There are two general strains of political thought in the United States that have been with us essentially since the beginning. The first is the belief that government is inherently coercive and thus something to be avoided assiduously. This inherently anarchic belief in the United States is moderated by a grudging admission that there are some things that only a government can do and a less than enthusiastic willingness to accept government regulations in those areas.

The other strain of political thought that has been prevalent throughout our history is based upon the belief that people want and need order imposed upon their lives. This leads to the inevitable conclusion that the government is the only organization that can fulfill that need.

What is probably unique about this country is that a large portion of the population is able to accept both of these concepts as controlling factors in different parts of their personal political lives. This helps to explain, for example, the social conservatives both decrying regulatory involvement in personal lives and the desire for strong laws prohibiting abortion.

This dichotomy is clearly evident in governmental relations with the chemical industry in general and chemical security regulations specifically. Neither side in this debate really believes that there is a terrorist threat against chemical facilities. One side, generally embodied by the Democrats, mistrusts the chemical industry because of a long history of mishandling hazardous chemicals and wants to regulate the industry at every turn. The other side, generally Republicans, believes that bureaucrats are intellectually incapable of understanding chemical processes and thus have no business being involved in the regulation of chemical facilities.

Thus neither side is really willing to listen to the political overtures of the other in this debate, particularly since neither side really believes in the terrorist threat. As long as neither side sees a realistic threat, they will not be able to come together to pass a ‘permanent’ chemical facility security bill; their mistrust of each other’s intentions will continue to prevent them from working together.

I’m afraid that the only thing that would allow the two sides to get together and work out a consensus set of chemical security regulations would be a successful terrorist attack on a chemical facility; and that is something no one wants to see happen.

So, it looks like for at least the near term, one-year reauthorizations in the DHS spending bill is what we have to look forward to.
 
/* Use this with templates/template-twocol.html */