Sunday, August 18, 2013

PHMSA Publishes Pipeline Reference Update NPRM

On Friday the Pipeline and Hazardous Material Safety Administration (PHMSA) published a notice of proposed rulemaking (NPRM) in the Federal Register (78 49996-50014). This NPRM is being used to update the pipeline safety regulations for miscellaneous changes to various materials incorporated by reference and make minor, non-substantive changes to the regulations.

Materials Incorporated by Reference

PHMSA is announcing that it has successfully negotiated with the below list of organizations to ensure that their publications that have been incorporated by reference are publicly available in accordance with requirements of Section 24 of the “Pipeline Safety, Regulatory Certainty, and Job Creation Act of 2011” (Pub. L. 112-90, January 3, 2012). While this NPRM was being drafted Congress lessened the impact of that legislation when it passed HR 2576 (PL 113-30, note this has not yet been published by the GPO) earlier this month. This will apparently not have a significant impact on operations at PHMSA.

• American Petroleum Institute (API).
• American Gas Association (AGA).Show citation box
• American Society for Testing and Materials (ASTM).
• Gas Technology Institute (GTI).
• Manufacturers Standardization Society of the Valve and Fittings Industry, Inc. (MSS).
• NACE International (NACE).
• National Fire Protection Association (NFPA).

This NPRM includes the adoption of a new reference; API Recommended Practice 5LT, “Recommended Practice for TruckTransportation of Line Pipe,” (First edition, March 1, 2012). This will be referenced in §192.65 and §195.207.

PHMSA is also including the incorporation of ASTM D2513-09a, “Standard Specification for Polyethylene (PE) Gas Pressure Pipe, Tubing, and Fittings,” (December 1, 2009). PHMSA is not including section 4.2 pertaining to rework material in that adoption. This ASTM will be referenced in §§ 192.59 (d); 192.63 (a); 192.123 (e); 192.191 (b); 192.281 (b); 192.283 (a); Item 1, Appendix B to Part 192.

PHMSA is not proposing to incorporate the following updated versions of reference documents:

API Recommended Practice 1162, “Public Awareness Programs for Pipeline Operators”; and
API Standard 653-2001, “Tank Inspection, Repair, Alteration, and Reconstruction” (3rd edition, 2001)

PHMSA is proposing to update the references to the following publications (new version listed):

API Recommended Practice 5L1, “Recommended Practice for Railroad Transportation of Line Pipe,” (7th Edition, September 2009);
API Recommended Practice 5LW, “Transportation of Line Pipe on Barges and Marine Vessels,” (3rd edition, September 2009);
ANSI/API Specification 5L/ISO 3183, “Specification for Line Pipe,” ANSI/API Specification 5L/ISO 3183 “Specification for Line Pipe” (45th edition, December 1, 2012);
ANSI/API Specification 6D, “Specification for Pipeline Valves,” (23rd edition, April 1, 2008, effective October 1, 2008), includes Errata 1, 2, 3, 4, 5, and 6 (2011) and Addenda 1 and 2 (2011);
API Specification 12F, “Specification for Shop Welded Tanks for Storage of Production Liquids,” (12th edition, October 2008, including errata 2008);
API Standard 620, “Design and Construction of Large, Welded, Low-Pressure Storage Tanks” (11th edition, February 2008, addendum 1, March 2009), and addendum 2 (2010);
API Standard 650, “Welded Steel Tanks for Oil Storage” (11th edition, June 2007), includes addendum 1 (November 2008), addendum 2 (November 2009), addendum 3 (August 2011), and errata (February 2012);
API Standard 2000, “Venting Atmospheric and Low-Pressure Storage Tanks Non-Refrigerated and Refrigerated,” (6th edition, November 2009);
ASTM A53/A53M-10, “Standard Specification for Pipe, Steel, Black and Hot-Dipped, Zinc-Coated, Welded and Seamless,” (October 2, 2010);
ASTM A106/A106M-10, “Standard Specification for Seamless Carbon Steel Pipe for High-Temperature Service,” (July 15, 2008);
ASTM A333/A333M-11 (2011), “Standard Specification for Seamless and Welded Steel Pipe for Low-Temperature Service,” (April 1, 2011);
ASTM A372/A372M-10, (reapproved 2005), “Standard Specification for Carbon and Alloy Steel Forgings for Thin-Walled Pressure Vessels,” (October 1, 2010);
ASTM A671/A671M-10, “Standard Specification for Electric-Fusion-Welded Steel Pipe for Atmospheric and Lower Temperatures,” (April 1, 2010);
ASTM A672-09, “Standard Specification for Electric-Fusion-Welded Steel Pipe for High-Pressure Service at Moderate Temperatures,” (October 1, 2009);
ASTM A691-09, “Standard Specification for Carbon and Alloy Steel Pipe, Electric-Fusion-• Welded for High-Pressure Service at High Temperatures,” (October 1, 2009);
MSS SP-44-2010, Standard Practice, “Steel Pipeline Flanges,” (2010 edition);
MSS SP-75-2008, “Specification for High Test Wrought Butt Welding Fittings,” (2009 edition);
NACE Standard SP0502-2010, Standard Practice, “Pipeline External Corrosion Direct Assessment Methodology,” (June 24, 2010);
NFPA-30 (Fire) (2012), “Flammable and Combustible Liquids Code,” includes Errata 1, Errata 2 (2012 edition, June 20, 2011); and
NFPA-70 (2011), “National Electrical Code,” includes Errata 1, Errata 2 (2011 edition, approved September 24, 2010);

Minor Clarifications and Edits

PHMSA is making minor, non-substantive modification or edits to the below listed sections.


Public Comments


PHMSA is soliciting public comments on this NPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2011-0337). Comments need to be submitted by October 15th, 2013.

Saturday, August 17, 2013

Why We Always React to White Powder Incidents

The internet is a wonderful tool; it allows me wide access to a lot of information. It also allows people to contact me with strange and peculiar questions. I had an interesting one today from someone who stumbled across my blog while researching improvised chemical munitions. It seems that the writer is trying to help a doctor identify a chemical that a postal worker was exposed to a year and a half ago.

Before I go any further, I want to warn readers that I have no way of verifying any of this information, nor do I intend to try. The story has enough verisimilitude that it serves an illistratative purpose. I have added some details to the story that was relayed to me; I did so to make some points and I don’t believe that they detract from the background information. And apparently the proper authorities have already been approached with the story, so this will not affect any official investigation that may or may not be under way.

The Story

Back in February 2011 at a postal facility in Orlando, Florida a package fell off one of the processing lines at the facility and was damaged. The package contained two bottles that were apparently wired together and at least one was damaged enough to leak. A dark noxious liquid leaked from the package. A postal worker donned a pair of gloves, cleaned up the mess, made the appropriate reports and the liquid container was placed in a Hazmat receptacle. The employee washed up and went home with a headache. The employee is now under the care of a physician who is trying to figure out what the chemical was so that he can properly treat the employee’s symptoms.

We have all seen enough news reports and have laughed often enough at the over reaction of people to know what should have happened.  The fire department and police should have been notified that there was a suspicious chemical exposure incident. The employees should have been evacuated and people in chemical suits should have been expected to go into the building to secure the suspect chemical to test it to see whether or not it was dangerous. The exposed employee should have been decontaminated at the scene and taken to the local emergency room for appropriate diagnostics and treatment.

That apparently did not happen in this instance, I suspect because too many postal employees have been made fun of by the late night comedians because they over reacted to flour or powdered sugar. There may have been a report made, but my email writer can find no organization that has any record of conducting an investigation.

Now the reason that I was contacted was that the return address on the package was apparently from Yemen. My correspondent has a military background and a suspicious nature (some law enforcement training I think) and began to think that the chemicals may have been an improvised chemical munition. I mean, why else would someone be sending bottles of chemicals from Yemen? Okay, a home remedy from mom; a special sauce for a native dish; chemical samples for some sort of applications testing (this is more common than one might think); there are all sorts of legitimate reasons. But the possibility of chemical weapons led them to me.

The Problem

Now, there are innumerable incidents where people in the shipping industry are exposed to chemicals that were improperly packed and too carelessly handled. When the chemicals are properly marked, appropriate actions can be taken to protect the workers involved. The need for decontamination and/or medical treatment can be properly assessed and responded to.

When there are no markings, one can only assume the worst and over react. Of course that gets old fast. Most chemicals are not immediately dangerous or even dangerous over the longer term from a brief exposure. So just from the random nature of things most over reactions become fodder for jokes and poking fun at people. And people begin to ignore the potential hazard until the dangerous situation arrives and smacks someone in the face; then it is too late.

To be truthful, a package from Yemen containing improperly packaged and undeclared chemicals should have raised a lot more attention that it apparently did. Of course, two years ago Yemen wasn’t in the news as much as today, but even then  there was enough talk about terrorists and Yemen, that someone should have made that potential connection very quickly. Additional precautions should have been taken, a formal investigation should have been initiated and the chemical positively identified.

But, even ignoring the possible terrorist connection here, any time someone is exposed to an unidentified chemical, there should be reason to be concerned. There are dangerous chemicals out there and people can be seriously hurt and not always in the short term. We have a person here who is still struggling to get proper medical treatment because there was not an adequate effort made to identify the chemical in question. And now it may be too late, the damage may be irreversible.

Friday, August 16, 2013

TSA Publishes SSI Threat Assessment 60-day ICR Notice

Today the Transportation Security Administration (TSA) published a 60-day ICR renewal notice (78 FR 50076-50077) for their threat assessment program for allowing the use of Sensitive Security Information (SSI; 49 CFR Part 1520) during court proceedings. Section 525 of the Department of Homeland Security Appropriations Act of 2007 (Public Law 109-295) required DHS to establish procedures for the use of SSI during Federal civil court proceedings, including {§525(d)} the conduct of a threat assessment of court personnel (including lawyers and expert witnesses) who might need to have access to the SSI information.

The procedures established require TSA to conduct a threat assessment that includes:

• A fingerprint-based criminal history records check (CHRC);
• A name-based check to determine whether the individual poses or is suspected of posing a threat to transportation or national security, including checks against terrorism, immigration, or other databases TSA maintains or uses; and
• A professional responsibility check (for attorneys and court reporters)

Burden Estimate

The table below shows the current estimated burden estimate for the renewal of this ICR along with the previously approved burden estimate. The time estimate is the time necessary for individuals to provide the required information necessary for TSA to conduct the various background checks.


This Notice
Previous Notice
Responses
120
180
Burden Hours
120
480
Cost Burden
0
0

[Corrected typo in the 'this notice' column changing '100' to '120' in both response and burden hour lines, 1-15-14 5:00 am CST]
There is no explanation for the decreased number of annual responses required, but presumably it is based upon recent history. Nor is there an explanation for why there is a drastic reduction in the amount of time necessary to provide the information (from 2 hours and 20 minutes to one hour). Looking at the previously approved TSA Form 2211, I don’t see how anyone would have taken an hour to complete the form, much less 2 and 2/3rds hours. Perhaps the additional time included the time to get fingerprinted.

Public Comments

The TSA is soliciting public comments on this ICR renewal notice. Such comments need to be sent to TSA PRA Officer (TSAPRA@dhs.gov). Again as I noted this morning, there are no provisions explained in this notice for using the Federal eRulemaking Portal for submission of comments. Interestingly, there is a docket for this ICR at www.Regulations.gov; Docket # TSA-2013-0001-0012 and there are already two comments posted there.

TSA ICR Renewal 60-Day Notice – Pipeline Operator Security Information

Today the Transportation Security Administration published a 60-day information collection request (ICR) renewal notice in the Federal Register (78 FR 50077-50078) supporting the information reporting guidelines outlined in the Pipeline Security Guidelines. The information collections supported here are all voluntary in nature.

There are two specific types of information requests covered in this ICR renewal; security manager contact information and incident reporting information. TSA is requesting the contact information so that they might be able to contact the security manager in a timely manner if they develop security information that might be of interest to the pipeline owner/operator. The ICR notice does not explain why TSA wants to be notified of pipeline security incidents, but it is presumably so that they  may share incident information with other owner/operators as necessary to prevent attacks on other pipelines.

Incident Reporting

The types of incident information that TSA suggest should be reported to the Transportation Security Operation Center (TSOC; 866-615-5150 or TSOC.ST@dhs.govincludes:

• Explosions or fires of a suspicious nature affecting pipeline systems, facilities, or assets;
• Actual or suspected attacks on pipeline systems, facilities, or assets;
• Bomb threats or weapons of mass destruction (WMD) threats to pipeline systems, facilities, or assets;
• Theft of pipeline company vehicles, uniforms, or employee credentials;
• Suspicious persons or vehicles around pipeline systems, facilities, assets, or right-of-way;
• Suspicious photography or possible surveillance of pipeline systems, facilities, or assets;
• Suspicious phone calls from people asking about the vulnerabilities or security practices of a pipeline system, facility, or asset operation;
• Suspicious individuals applying for security-sensitive positions in the pipeline company;
• Theft or loss of Sensitive Security Information (SSI) (detailed pipeline maps, security plans, etc.); andShow citation box
• Actual or suspected cyber-attacks that could impact pipeline Supervisory Control and Data Acquisition (SCADA) or enterprise associated IT systems.

Burden Estimate

The table below shows the burden estimate for this renewal notice and the previously approved ICR.


This Notice
Previous
Reports
3,340
3,440
Burden Hours
845
895
Burden Cost
0
0

The changes in burden reporting reflects a change in the number of estimated incidents, 140 incidents were estimated in the earlier ICR Notice  but only 40 incidents in this notice. I would assume that the change is based on the actual number of incidents reported to date to TSA, but that is not specifically stated in this notice.

Public Comments


The TSA is soliciting public comments on this ICR renewal. They request that such comments be sent to the TSA PRA Officer (TSAPRA@dhs.gov). There is no explanation given as to why TSA is not using the Federal eRulemaking Portal for taking these comment submissions. It will certainly make it more difficult to determine if the TSA has responded to any such comments when they submit the 30-day notice sometime in the indeterminate future.

Thursday, August 15, 2013

S 1462 Introduced – PTC Delay

As I noted earlier Sen. Thune (R,SD) introduced S 1462 the  Railroad Safety and Positive Train Control Extension Act. This bill would amend 49 USC 20157 by extending various deadlines for the implementation of positive train control (PTC) technology.

Five Year Statutory Extension

Section 2b of the bill would amend §20157 to change the requirements for submitting plans for PTC implementation. The deadline for submitting plans (already passed) is removed. The date by which plans would be implanted would be changed to December 31st, 2020. Finally the date used for determination of which sections of track must be covered by PTC equipment is changed to December 31st, 2015.

Additional Extensions Authorized

Section 3(a) would give the DOT Secretary authority to provide additional extensions if requested by the railroads. Section 20157 is amended by adding paragraph (i) that establishes the limits of that authority. The Secretary is allowed to authorize one-year extensions if it is found that the railroad has made a good faith attempt to implement its PTC plan, and has submitted a new plan.

The Secretary must determine that the reason for the inability to complete the PTC implementation is due to circumstances beyond the control of the railroad. The new language provides some examples of such circumstance {§20157(i)(1)(A)} including:

• Funding availability;
• Spectrum acquisition;
• Resource and technology availability;
• Software development and testing;
• Availability of alternate risk reduction strategies; and
• Interoperability standards.

Presumably this would also include the problems with FCC antenna licensing identified by various House Committee Chairs.

The authority for these incremental one-year extensions would not allow for delaying the implementation of the PTC plan beyond December 31st, 2022 {§20157(i)(1)(D)}. There is an additional fig-leaf restriction on this extension authority. The Secretary must take into consideration “whether the affected areas of track have been identified as areas of greater risk to the public and railroad employees in the applicant’s positive train control implementation plan under section 236.1011(a)(4) [Link Added] of title 49, Code of Federal Regulations” {§20157(i)(2)(A)}.

CFR Revision Required

The Secretary is given 180 days by §4 of this bill to make specific (and limited) changes to PTC regulations. The deadlines in 49 CFR 236.1006(b)(4)(iii)(B) would have to be extended by 5 years. Those deadlines deal with the requirements for Class II and Class III railroads to have locomotives equipped with PTC equipment if they will be moving more than 20 miles on a PTC controlled section of track.

Normally 180 days is way too short of a time to make substantive changes to Federal Regulations. Given the limited nature of the changes required by this section and the fact that the Secretary is given no regulatory discretion in this particular change, there should be no real problem in complying with this section. A direct final rule without the need for a public comment period is all that is required.

Moving Forward

It is becoming painfully apparent that Congress was a tad bit aggressive in establishing the time limits for the implementation of these PTC requirement and that the railroads will not be able to fully implement their PTC plans by the currently required date of December 31st, 2015. This is a fairly straight forward extension plan that should be able to be accepted by a clear bipartisan majority in both houses of Congress.


The only question will be when this bill could actually be considered. The main (and contentious) issue facing Congress on their return from the Summer Recess will be the various spending bills that must be passed by October 1st. The political gamesmanship that will be involved in that controversy will almost certainly impede congressional work on less disruptive legislation through the end of the year. This bill may languish until 2014.

Wednesday, August 14, 2013

ICS-CERT Publishes Kepware DNP Advisory

Today the DHS ICS-CERT published an advisory for an improper input validation vulnerability in the Kepware Technologies DNP Master Driver. The vulnerability was reported by Adam Crain and Chris Sistrunk in a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker could exploit this vulnerability to conduct a denial of service attack or possibly execute arbitrary code on the system. Kepware has produced an updated version of the software that has been validated by Crain and Sistrunk.


The Project Robus page now shows four DNP3 related ICS-CERT advisories published that were based upon work by Adam and Chris with 15 advisories ‘pending’. Based upon Adam’s work on the open source implementation of DNP3 that I discussed yesterday, I would bet that a number of the ‘pending’ advisories will also deal with DNP3 vulnerabilities. It might behoove vendors that utilize the DNP protocol to start taking a hard look at their potential vulnerabilities. 

ICS-CERT Closes Advantech Alert

Late yesterday the DHS ICS-CERT closed out a January 2013 alert for a cross-site scripting vulnerability in Advantech WebAccess by publishing an advisory outlining the mitigation efforts of Advantech to address the vulnerability. The original disclosure was made by Sanadi Antu of SecPod Technologies. ICS-CERT credits this as an uncoordinated disclosure but the SecPod Technologies site claims to have notified Advantech of the vulnerability on December 12, 2012.

ICS-CERT notes that a relatively skilled attacker would be able to use the publicly available exploit to remotely execute arbitrary HTML code on the affected systems. The Advantech security page notes that all versions of WebAccess are vulnerable and that a new patch is available.


BTW: This seems to be the last publicly released vulnerability reported by SecPod Technologies.
 
/* Use this with templates/template-twocol.html */