Thursday, January 6, 2022

Review - 4 Advisories Published – 1-6-22

Today, CISA’s NCCIC-ICS published three control system security advisories for products from IDEC, Fernhill and Omron. They also published a medical device security advisory for products from Philips.

IDEC Advisory - This advisory describes four vulnerabilities in the IDEC PLC’s.

NOTE 1: I briefly reported on these vulnerabilities on December 25th, 2021.

Fernhill Advisory - This advisory describes an uncontrolled resource consumption vulnerability in the Fernhill SCADA Server.

Omron Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Omron CX-One automation software.

Philips Advisory - This advisory describes an improper access control vulnerability in the Philips Engage customer support software platform.

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-1-6-22 - subscription required.

Review - 2021 Chemical Security Summit Presentations

Yesterday CISA updated the Chemical Security Summit (CSS) web page to provide links to some of the presentations that were made at last month’s virtual summit. The links go to copies of the slides used in the presentations, not videos of the actual presentations, so a lot of detail is missing. And they have not covered all of the presentations that were made. Still, there is a great deal of information here.

The presentation slides available include:

CFATS Risk-Based Performance Standards (RBPS) Deep Dive and Best Practices

CFATS Personnel Surety Program Overview and Demonstration

Cyber-Physical Security Convergence in the Private Sector

Cyber Threat Hunting: Industrial Control System Security

How to Conduct a Chemical Security Exercise

Jack Rabbit III Program Update

P4 – A Platform for Public-Private Emergency Management Collaboration

Voluntary Chemical Security Initiatives: CISA ChemLock

Case Study on Recent Disruptions in the Supply of Chlorine: Impacts and Responses

Missing Presentations

The following presentations that were made in the 3-day Summit did not make it to the list of published presentations:

• State of Chemical Security,

• Industry Perspective on the Threat Landscape,

• FBI Chemical Threat Briefing,

• FBI Case Study on Economic Espionage in the Chemical Sector, and

• Probabilistic Analysis for National Threats Hazards and Risks (PANTHR) Overview.

I have no idea why the first two presentations did not make the publication cut. The two FBI were restricted (no press allowed) presentations in the first place so, there is no surprise that the slides were not shared. I was surprised that the DHS S&T PANTHR presentation did not get published. The program web site coverage is extensive, so there should not have been any concerns about sensitive information.

For more details, including brief summaries, about the presentations, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2021-chemical-security-summit-presentations - subscription required.

Wednesday, January 5, 2022

Review - 1-5-22 Siemens Log4Shell Advisory

Siemens published an update for their original Log4Shell advisory that was originally published on December 12th, 2021 and most recently updated on December 28th, 2021.

It has been just over a week since Siemens published a new advisory or updated this one. This will probably be the last stand-alone report I do for updates for this advisory or the other advisories that Siemens has published on the Log4j problems. I added the Siemens advisories to the last weekly update Log4Shell list over on CFSN Detailed Analysis and that is where further reports on these advisories will be found. Unless, of course, Siemens turns up something that catches my fancy.

For more details about today’s update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-5-22-siemens-log4shell-advisory - subscription required.

Reader Comment – Decline in Covered Facilities: Good or Bad?

There was an interesting comment left on TWITTER yesterday about my post on latest CFATS update. Marc Ayala wrote: “Your right Pat, a decline in the number of covered facilities is actually a good thing. It looks good on paper that is.” This was in response to my reporting on the decline in the number of facilities covered under the Chemical Facility Anti-Terrorism Standards (CFATS) program. While there have only been two straight months of decline in the number of facilities regulated under the CFATS program, the number of facilities covered is at its lowest number since June 2020 when 3,341 facilities were covered.

I posited that: “Significant reduction or elimination of those risks at a facility (necessary for exit from the program) reduces the risk for the communities around those facilities and the country as a whole.” Marc’s comment raises the specter that this apparent reduction in risk is more about regulation avoidance than risk reduction. That is certainly an idea that should be addressed.

How Do Facilities Leave CFATS

Typically, a facility initiates the process of leaving the Program by submitting a Top Screen update showing a change in the inventory quantities of any of 300+ DHS chemicals of interest (COI). The folks at CISA’s Office of Chemical Security take the new inventory numbers and run them through the same risk assessment process that landed the facility in the program in the first place. As I understand it, if the assessment indicates that the risk is reduced below the threshold that would land a facility in the program, then a chemical security inspector (CSI) is dispatched to the facility to physically verify that the risk has been reduced.

Once the final determination is made about the change in status, the facility is notified that it is no longer covered by the program. Presumably, the facility then reduces its emphasis facility security in order to reduce the costs associated with its site security plan. That reduction would appear to be reasonable; with a reduced risk, the level of security does not need to be as high.

Incentives to Leave the Program

Facilities have a number of reasons to want to leave the program. Security measures are expensive to install and maintain. They also frequently lead to inefficiencies in internal processes and controls. Finally, any regulatory program has administrative compliance costs. Furthermore, the advantages of an effective security program are hard to quantify, especially since there have been no documented terrorist attacks (or attempted attacks) on chemical facilities in the US since the CFATS program was stood up in 2007.

To justify a removal from CFATS, a facility must reduce its inventory below the reporting levels set in Appendix A, 6 CFR Part 27. Facilities that manufacture or distribute COI, can get out of that business. Facilities that use COI as raw materials can either find replacement chemicals (not always possible), reduce the maximum amount of material that is held on hand, or get out of the business that utilizes the COI. Each of these options carries its own business costs and consequences. Or, of course, a facility could just lie. That is why OCS sends inspectors to verify the process changes.

Moving Forward

As long a CISA’s OCS adequately vets facilities leaving the program, the risk of facilities cheating to avoid regulatory oversight remains relatively low. And OCS has a bureaucratic incentive to keep the covered facility number high; if the number drops too low, Congress will reduce funding and headcount for the Office.

It would be nice if OCS were able to share more details about how and why facilities continue to leave the CFATS program, but there are legitimate security and business confidentiality reasons that limit the information that CISA can share with the public. I suspect, however, that with the program facing renewal next year (after the Democrats potentially loose “control” of Congress) that we are going to start to see Committee interest in all sorts of issues within CFATS. I would not be surprised to see one or more Committee Chairs asking the GAO to report on the number and process of facilities dropping out of the CFATS program.

Tuesday, January 4, 2022

Review - OCS Updates Monthly Statistics – 1-3-22

Yesterday, CISA’s Office of Chemical Security(OCS) updated the statistics on their Chemical Facility Anti-Terrorism Standards (CFATS) Monthly Statistics page. This provides a snapshot look at the activities of the chemical security inspectors (CSI) and the status of the covered facilities at the end of December 2021. At this time, OCS is not including CSI activities in support of the ChemLock program. There was a slight decrease, month-to-month, in CSI activity levels and a net loss in the number of covered facilities in December.

CSI Activities

The table below provides a look at the reported figures for CSI activities over the last four months.

Inspection Data

Sep-21

Oct-21

Nov-21

Dec-21

Authorization Inspections

22

8

10

11

Compliance Inspections

154

126

182

116

Compliance Assistance

73

65

44

62

Compliance Audit

0

0

0

0

Facility Status

The table below provides a look at the facility status information provided by OCS over the last four months.

Facility Status

Sep-21

Oct-21

Nov-21

Dec-21

Tiered

83

80

57

57

Authorized

110

112

125

115

Approved

3078

3082

3073

3074

Total

3271

3274

3255

3246

From a chemical security perspective, a decline in the number of covered facilities is actually a good thing. The CFATS program is built on the premise that the possession of certain DHS chemicals of interest above a threshold quantity make (with some other risk assessment concerns that are hidden in the OCS black box) place a facility at risk of a terrorist attack. Significant reduction or elimination of those risks at a facility (necessary for exit from the program) reduces the risk for the communities around those facilities and the country as a whole.

But that risk is not eliminated (except where facilities close) just reduced. With the advent of the ChemLock program, facilities leaving the CFATS program have a mechanism to continue to receive support from CISA in protecting their facilities.

For more details about what these numbers mean, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ocs-updates-monthly-statistics-1 - subscription required.

Monday, January 3, 2022

Review - ChemLock Exercises – An Overview

Developing a chemical facility security plan is just a time-consuming, compliance exercise until it has been tested. Instead of waiting for a real-world security incident to be the first test of a facility security plan, a smart security team will conduct a variety of exercises to evaluate the efficacy of the plan and the assumptions which drove its development. CISA’s new ChemLock program, a voluntary off-shoot of the successful Chemical Facility Anti-Terrorism Standards (CFATS) program, provides a number of exercise tools that facility security managers can use to plan, execute and evaluate a series of exercises to see how well their facility security plan stands up to a variety of security scenarios.

ChemLock Exercise Web Page

This page is the starting point for exercise planning and development. Most of (okay maybe all, but I am not sure about that) the information here was not specifically developed by the CISA Office of Chemical Security (the folks that manage the CFATS program), but rather by the wider range of offices within CISA and DHS.

There are two general options provided on this page. The first (and easiest) is a series of canned CISA Tabletop Exercises Package (CTEP). The CTEPs are no-cost to download and include the scenario-specific situation manual, planner handbook, facilitator/evaluator handbook, and assorted forms and templates. The second option is to contact the ChemLock folks to ask for assistance in planning and executing an exercise. That option is initiated by the use of the same  ChemLock Services Request Form that I have mentioned in a number of earlier posts.

Which Exercise?

In a perfect world, every facility would run every exercise as routine part of operations. Obviously, that is not going to happen in the real world. If a facility has never run an exercise of this sort, it is probably best to concentrate on one exercise and run it through a couple of iterations before trying to determine what sort of ‘exercise schedule’ will be appropriate for the facility.

I will be looking at individual exercise packages in future posts, but each facility is going to have to determine which exercise would be the most appropriate to start with. Facilities are going to want to start with something simple, but something that is a real potential threat at that facility. For example, a vehicle borne explosive device is probably not a serious threat at a facility that does not have significant inventories of toxic inhalation hazard chemicals on site unless an attacker has a particular issue with the facility.

Remember, though, the whole purpose of the ChemLock program is to help chemical facilities solve their security issues. The folks at OCS have offered to provide that assistance. So, facilities should contact the ChemLock folks with their questions about these exercise programs. Questions should be addressed via email to ChemLock@cisa.dhs.gov.

For more details about these exercise offerings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-exercises-an-overview - subscription required.

Sunday, January 2, 2022

Review - Public ICS Disclosures - Log4Shell Advisories – Week of 12-25-21

 

This is effectively Part 2 of my weekly public ICS disclosure post. It is a follow-up to last week’s post. There are now 91 vendor notifications listed. As I did last week, I am making the article on my CFSN Detailed Analysis site - https://patrickcoyle.substack.com/p/public-ics-disclosure-log4shell-week-eef - a free-access article so as to avoid a lengthy duplication here.

 
/* Use this with templates/template-twocol.html */