Sunday, September 9, 2018

S 3405 CFATS Reauthorization – EAP


This is the third in a series of blog posts about S 3405, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2018, which would reauthorize the Chemical Facility Anti-Terrorism Standards (CFATS) program for five years. The other blog posts in the series include:


Expedited Approval Program (EAP)


Section 4 of the bill makes a large number of changes to 6 USC 622(c)(4), the Expedited Approval Program. This subparagraph was added by the 2014 bill as a method to allow Tier 3 and Tier 4 facilities a smoother path to having a site security plan approved by DHS. There are almost three pages of changes made to the EAP language by §4 and they are difficult to understand without looking at how the language of §622(c)(4) will actually look once these changes are put into place. So here goes; stricken language is lined through, added language is highlighted and the ‘ ’ indicates where extended portions of the language have not been changed.

(4) Expedited approval program
(A) In general  
A covered chemical facility assigned to tier 3 or 4 may meet the requirement to develop and submit a site security plan under subsection (a)(2)(D) by developing and submitting to the Secretary—
(i) a site security plan and the certification described in subparagraph (C)(i); or
(ii) a site security plan in conformance with a template authorized under subparagraph (H).
(B) Guidance for expedited approval facilities
(i) In general Not later than 180 days after December 18, 2014, the Secretary shall issue The Secretary shall maintain guidance for expedited approval facilities that identifies specific security measures that are sufficient to meet the risk-based performance standards.
(ii) Material deviation from guidance If a security measure in the site security plan of an expedited approval facility materially deviates from a security measure in the guidance for expedited approval facilities, the site security plan shall include an explanation of how such security measure meets the risk-based performance standards.
(iii) Applicability of other laws to development and issuance of initial guidance During the period before the Secretary has met the deadline under clause (i), in developing and issuing, or amending, the guidance for expedited approval facilities under this subparagraph and in collecting information from expedited approval facilities, the Secretary shall not be subject to—
(I) section 553 of title 5;
(II) subchapter I of chapter 35 of title 44; or
(III) section 627(b) of this title.
(C) Certification The owner (i) In general the owner operator of an expedited approval facility shall submit to the Secretary a certification, signed under penalty of perjury, that—
(i) (I) The owner or operator is familiar with the requirements of this subchapter and part 27 of title 6, Code of Federal Regulations, or any successor thereto, and the site security plan being submitted;
(ii) (II) the site security plan includes the security measures required by subsection (b);
(iii) (III) (I) (aa) the security measures in the site security plan do not materially deviate from the guidance for expedited approval facilities except where indicated in the site security plan;
(II) (bb) any deviations from the guidance for expedited approval facilities in the site security plan meet the risk-based performance standards for the tier to which the facility is assigned; and
(III) (cc) the owner or operator has provided an explanation of how the site security plan meets the risk-based performance standards for any material deviation;
(iv) (IV) the owner or operator has visited, examined, documented, and verified that the expedited approval facility meets the criteria set forth in the site security plan;
(v) (V) the expedited approval facility has implemented all of the required performance measures outlined in the site security plan or set out planned measures that will be implemented within a reasonable time period stated in the site security plan;
(vi) (VI) each individual responsible for implementing the site security plan has been made aware of the requirements relevant to the individual’s responsibility contained in the site security plan and has demonstrated competency to carry out those requirements;
(vii) (VII) the owner or operator has committed, or, in the case of planned measures will commit, the necessary resources to fully implement the site security plan; and
(viii) (VIII) the planned measures include an adequate procedure for addressing events beyond the control of the owner or operator in implementing any planned measures.
(ii) RISK-BASED PERFORMANCE STANDARDS.—In submitting a site security plan and certification under subparagraph (A)(i), an owner or operator of an expedited approval facility should consider using the guidance for expedited approval facilities to determine appropriate measures for the site security plan of the expedited approval facility.

(D) Deadline (i) In general Not later than 120 days after the date described in clause (ii), the owner or operator of an expedited approval facility shall submit to the Secretary the site security plan and the certification described in subparagraph (C) subparagraph (C)(i).
(ii) Date The date described in this clause is—
(I) for an expedited approval facility that was assigned to tier 3 or 4 under existing CFATS regulations before December 18, 2014, the date that is 210 days after December 18, 2014; and
(II) for any expedited approval facility not described in subclause (I), the later of—
(aa) the date on which the expedited approval facility is assigned to tier 3 or 4 under subsection (e)(2)(A); or
(bb) the date that is 210 days after December 18, 2014.
(iii) Notice An owner or operator of an expedited approval facility shall notify the Secretary of the intent of the owner or operator to certify the site security plan for the expedited approval facility not later than 30 7 days before the date on which the owner or operator submits the site security plan and certification described in subparagraph (C) subparagraph (C)(i).
(E) • • • (no change)
(F) Amendments to site security plan (i) Requirement (I) In general If the owner or operator of an expedited approval facility amends a site security plan submitted under subparagraph (A), the owner or operator shall submit the amended site security plan and a certification relating to the amended site security plan that contains the information described in subparagraph (C) subparagraph (C)(i). • • •
(G) • • • (no change)
(H) • • • (no change)
(I) Evaluation
(i) In general Not later than 18 months after December 18, 2014, the Secretary shall take any appropriate action necessary for a full evaluation of the expedited approval program authorized under this paragraph, including conducting an appropriate number of inspections, as authorized under subsection (d), of expedited approval facilities.
(ii) Report Not later than 18 months after December 18, 2014, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Energy and Commerce of the House of Representatives a report that contains—
(I)(aa) the number of eligible facilities using the expedited approval program authorized under this paragraph; and
(bb) the number of facilities that are eligible for the expedited approval program but are using the standard process for developing and submitting a site security plan under subsection (a)(2)(D); (II) any costs and efficiencies associated with the expedited approval program;
(III) the impact of the expedited approval program on the backlog for site security plan approval and authorization inspections;
(IV) an assessment of the ability of expedited approval facilities to submit facially sufficient site security plans;
(V) an assessment of any impact of the expedited approval program on the security of chemical facilities; and
(VI) a recommendation by the Secretary on the frequency of compliance inspections that may be required for expedited approval facilities.
(I) NOTICE BY THE SECRETARY.—The Secretary shall provide notice to each covered chemical facility of the expedited approval program under this paragraph.’’.

Commentary


The basic outline of the EAP remains the same. The DHS ISCD is to maintain the current guidance document. Tier 3 and Tier 4 facilities would continue to have the option to use the EAP instead of going through the normal site security plan submission process. And ISCD would enforce the EAP in the same manner as is currently in use.

There are two administrative changes to the EAP that affect actions by ISCD. First, any revisions to be made to the guidance document will no longer be exempt from the publish, comment and response process normally used in regulatory affairs. The original EAP was exempted from that processes because facilities could choose to participate or not and Congress wanted DHS to get the EAP process up and running quickly. This change protects the small handful of facilities that are operating under the EAP from DHS making ad hoc changes to the security requirements for the program.

The second administrative requirement is that DHS would be required to notify ‘each covered chemical facility’ about the EAP process. Typically, the term ‘covered facility’ means a facility that has submitted a Top Screen and has been notified by ISCD that they are required to submit a site security plan. The EAP process remains available to only Tier 3 and Tier 4 facilities, so I do not see why Johnson would want the Tier 1 and Tier 2 facilities notified, but the provision is easy enough to comply with and could arguably already be considered completed because of the current EAP web page.

There is one change to the existing EAP process for submitting facilities that would be made by §4 of the bill. Instead of notifying ISCD 30 days before they submit an EAP security plan and certification, the bill would now only require that notification 7 days before the submission. This notification requirement was a provision that never really made much sense. As long as the facility submitted the EAP documents prior to the required date for submitting a site security plan I cannot fathom why DHS would need any additional prior notification.

There is one oddity in the §4 changes to the EAP language. The new §622(c)(4)(C)(ii) statement does not make much legislative sense. It looks like Johnson was trying to provide facilities with some wiggle room on what security measures that they could select from the EAP guidance, but the way the sub-paragraph was added it does not do that. In fact, Johnsons changing all reference to ‘subparagraph (C)’ to read ‘subparagraph (C)(i)’ specifically removes the new subparagraph (C)(ii) from having any impact on facilities or in any way modifying how ISCD enforces the program.

The one thing that I am surprised not to see in the language of §4 is a revocation of the subparagraph (H)(ii). This is the nearly identical to the language in (B)(iii) which was deleted. Since this clause is found in the section on ‘Templates’ it could be argued that it only provides DHS with an exemption to the publish comment and revise process for changes made to templates. Since DHS has not yet really published any templates (other than the ‘example’ in
Attachment 2 to the EAP guidance document), perhaps Johnson wanted to preserve the ability of DHS to formulate a formal template without having to go through the full administrative process. If that were the case, he should have revised the language in (H)(ii) because it relies on a date in (B)(iii) which would be removed by this bill.

Saturday, September 8, 2018

Bills Introduced – 09-07-18


Yesterday with just the House in session (the Senate took an early break for the long Rosh Hashanah weekend) there were 27 bills introduced. Of these one may be of specific interest to readers of this blog:

HR 6735 To direct the Secretary of Homeland Security to establish a vulnerability disclosure policy for Department of Homeland Security internet websites, and for other purposes. Rep. McCarthy, Kevin [R-CA-23]


Okay, I’m really going to follow this one to see how one sets up a vulnerability disclosure policy for a web site…. Something seems to be lost in translation.

ISCD Publishes CFATS Update – 09-07-18


On Friday the DHS Infrastructure Security Compliance Division (ISCD) published their latest update of statistics on the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS) program. This month the figures indicate that more facilities were added to the program than left and there was a significant increase in the number of facilities with an approved site security plan.

ISCD Activities


The table below summarizes the activities that ISCD undertook to support the CFATS program.

CFATS Activities
Jun-18
Jul-18
Aug-18
Authorization Inspections to Date
3713
3768
3822
Authorization Inspections Month
66
44
68
Compliance Inspections to Date
3684
3752
3819
Compliance Inspections Month
131
59
78
Compliance Assistance Visits to Date
4463
4598
4749
Compliance Assistance Visits Month
113
103
158

We see a significant increase in activities over the low of the previous month. This would tend to indicate that last month’s lower than normal numbers were probably related to vacations and the 4th of July holiday.

Facility Status


The table below shows the status of facilities in the CFATS program at the end of the month (my best guess of the effective date of the data).

CFATS Facility Status
Jun-18
Jul-18
Aug-18
Tiered
216
213
218
Authorized
623
618
562
Approved
2528
2531
2586
Total
3367
3362
3366

The data shows the first net increase in the number of covered facilities since February. From the data presented it is not clear if that increase is due to an unusual number of new facilities submitting Top Screens (probably mainly in July) or if there were fewer facilities exiting the program due to changes in their COI or security posture.

ISCD Updates PSP Manual – 08-30-18


This week the DHS Infrastructure Security Compliance Division (ISCD) published a new version of their Personnel Surety Program (PSP) Instructions manual dated 8-30-18. This replaces the version printed 9-18-17. As we have seen with most of the recent rewrites of the Chemical Facility Anti-Terrorism Standards (CFATS) program manuals, most of the changes in this manual only minor changes have been made to clarify requirements.

There is some new information about the Transportation Workers Identification Credential (TWIC). The TSA began issuing a new and improved version of the TWIC to make it more difficult to counterfeit or alter. Laurie Thomas did a blog post on this TWIC change back in July. The new information in this manual is found on page 29 in the Note below the new photos.

If you are navigating the CFATS web site to find this new manual (instead of using the link above), you have to look on the Chemical Security Assessment Tool (CSAT) page under ‘Additional Resources’. Do not use the link on the CFATS Knowledge Center; that still takes you to the earlier version of the manual. NOTE: There is no notice on either page about the change in manual versions.

Public ICS Disclosure – Week of 09-01-18


This week we have a vendor vulnerability disclosure (with related exploit) for products from KONE, two medical device exploits (possible 0-day) for products from Softneta, and an ICS communications exploit (possible 0-day) for products from Endress+Hauser.

KONE Advisory and Exploit


KONE published an advisory for their Group Controller (KGC) computer for elevators. The advisory describes four vulnerabilities. The vulnerabilities were reported by Sebastian Neuner who has published proof of concept exploits for the vulnerabilities. KONE has a new software version that mitigates the vulnerabilities. There is no indication that Neuner has been provided an opportunity to verify the efficacy of the fixes.

The four reported vulnerabilities are:

• Unauthenticated remote code execution - CVE-2018-15484;
• Unauthenticated local file inclusion/modification - CVE-2018-15486;
• FTP without authentication and authorization- CVE-2018-15485; and
Denial of service - CVE-2018-15483

KONE reports that successful exploits of these vulnerabilities will not affect the safe operation of the connected elevators but may result in a denial of service.

Softneta Exploits


Carlos Avila published exploits for two vulnerabilities (here and here) for the Softneta MedDream picture archiving and communication system (PACS) server. No CVE has been provided and there are no security advisories on the MedDream web site so these may be 0-day vulnerabilities.

The two vulnerabilities are:

• Directory traversal; and
• SQL injection

Endress+Hauser Exploit


Hamit CİBO published an exploit for a directory traversal vulnerability in the Endress+Hauser WirelessHART Fieldgate SWG70. There is no CVE listed and there are no security advisories on the Endress+Hauser web site so this could be a 0-day vulnerability. It does appear that CİBO previously published a similar exploit in June of this year.

Friday, September 7, 2018

S 3405 Introduced – CFATS Authorization


On Tuesday Sen. Johnson (R,WI) introduced S 3405, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2018. The bill will reauthorize the current Chemical Facility Anti-Terrorism Standards (CFATS) program for regulating the security at selected high-risk chemical facilities for a period of 5 years.

In general, the bill continues the current CFATS program, but it does make some changes to the program. Those changes will affect the current:

• Risk-based performance standards (see earlier post);
• Expedited approval program;
• Frequency of inspections and audits;
• Personnel surety program;
• Coverage of facilities with explosive chemicals of interest (COI); and
Small covered chemical facilities.

Additionally, the bill would add a new CFATS recognition program and new congressional reporting requirements on the CFATS program.

Moving Forward


The current CFATS program expires in January and there appears to be a consensus in DHS, Congress and the regulated community that the program should be extended for a significant period of time. Johnson is the Chair of the Senate Homeland Security and Governmental Affairs Committee which obviously means that this bill will receive consideration by that Committee. It is too early to tell how much support there will be for this specific language, but I suspect that there will be substantial attempts to amend this bill when it is considered in Committee.

This bill (or a House version yet to be introduced) will not make it to the floor of the Senate before the November elections. Depending on how the election goes and what other pressures arise a reauthorization bill will be very likely be considered before the end of the year; whether it is this bill, a House bill, or some sort of amendment in the DHS spending bill has yet to be determined.

Commentary


I am already getting a lot of questions about provisions in this bill and many of those provisions deserve a detailed explanation and analysis. As I have already demonstrated by my first blog post on this bill, I have some strongly held views about the reauthorization process, the provisions of this bill and the CFATS program in general. With that in mind, I can see now that I will be doing a number of posts about a number of provisions of this bill. That is why this post is so short. More will be coming….

S 2836 Reported in Senate – UAS Protection


Earlier this week the Senate Homeland Security and Governmental Affairs Committee published their report on S 2836, the Preventing Emerging Threats Act of 2018. Additionally, the amended version of the bill was also published. The changes to the bill were made during a mark-up hearing conducted by the Committee on June 13th, 2018.

Additional Protections


The changes made to the bill by the Committee did not make any major changes to the counter-UAS activities that DHS and DOJ are authorized to undertake. There were, however, three new constraints that would have to be considered before conducting counter-UAS activities. DHS and DOJ would be required to {new §210G(a)(2)}:

• Avoid infringement of the privacy and civil liberties of the people of the United States and the freedom of the press consistent with Federal law and the Constitution of the United States, including with regard to the testing of any equipment and the interception or acquisition of unmanned aircraft or systems;
• Limit the geographic reach and duration of the actions to only those areas and time frames that are reasonably necessary to address a reasonable threat; and
Use reasonable care not to interfere with authorized or non-threatening manned or unmanned aircraft, communications, equipment, facilities or services

Moving Forward


It is unlikely that this bill could be brought to the floor of the Senate using any of the abbreviated consideration options found in the Senate rules. This means that there would almost certainly have to be significant floor debate and provisions for the consideration of amendments. With the constraints of time facing the body prior to the upcoming elections, it is unlikely that this bill will be considered until Congress returns from the battle royale in November. Even then, the chances of this bill making to the floor for a vote are probably low.

Commentary


Some of the ‘changes’ that I reported on in HR 6401 actually come from the revised language in this bill. Actually, the only significant change in the House bill is the language limiting the ‘notwithstanding’ clause in §210G(a)(1). While both bills would provide rather blanket authorization to avoid a wide variety of federal law regarding protections of aircraft and communications, the House language provides more targeted exemptions for specific activities rather than the blanket exemption from KK US criminal statutes found in the Senate bill. I really think that the Senate bill should adopt the House language for that clause.

 
/* Use this with templates/template-twocol.html */