Tuesday, November 2, 2010

Reader Comment SOCMA Podcasts

An anonymous reader posted a comment to last weeks posting about the 2011 Chemical Sector Security Summit. Anonymous was responding to my suggestion that DHS provide video coverage of presentations at next year’s Summit, writing:

“Though it's far removed from video coverage, SOCMA posts podcasts on its website conducted with key DHS officials during the summit. You may have to register for access (can't recall) but there is no fee to download it.”
Anonymous is correct, SOCMA (who co-funded the 2010 Summit) provided a link to their Summit Podcast in their post-Summit review. The podcast includes comments from some of the presenters and Summit participants. I thought that I had covered this in one of my post-Summit blogs, but I can’t find any mention in my records.

SOCMA was one of the providers of information from the Summit this year and I hope they do the same next. Tweets and blog posts helped those of us who could not attend follow what was going on. Since this is supposed to be another method for DHS to keep the chemical security community updated on the CFATS process and other chemical security programs managed by DHS, I think it is important that the information be shared in as wide a variety of means as possible. SOCMA certainly helped this year, but it is really DHS’s job to make sure that this happens.

Again, I realize that there may be issues in providing video coverage of some of the industry presentations (though I think that most PR departments would look at it as free advertising), but that would not apply to the presentations made by Federal employees. I also understand that there might be concerns about inadvertent disclosure of security sensitive materials, but I’m not asking for live broadcasts. I would be happy if DHS just posted edited videos of the presentations on the Internet after the Summit is over, much the same way that they post the slides used in those presentations.

A major reason for DHS to sponsor this Summit is to ensure that the regulated community gets the information that they need to comply with the CFATS regulations. Since it is not possible for all covered facilities to have security team members attend this Summit, DHS has a responsibility to ensure that the information provided here has the widest possible dissemination. Providing copies of the slide presentations on their web site was a good move, but those slides are only a very minor component of the presentations. We need to hear the words, the voices of the presenters.

Chemical Security Awareness Training Program ICR to OMB

Yesterday the Office of Management and Budget (OMB) reported that the DHS /Sector-Specific Agency Executive Management Office (SSA EMO) had submitted an Information Collection Request (ICR) renewal application for their Chemical Security Awareness Training program last Friday. According to that report the submission coincided with the publication of the required 30-day notice in the Federal Register, unfortunately the cited notice (75 FR 52768) was actually the 60-day notice that I previously reported. I have yet to see a 30-Day Notice on this ICR in the Federal Register.


This sounds like one of those administrative snafus that occur from time to time. OMB cannot complete their review of ICR application until they look at any public comments filed on the 30-day notice and that time clock cannot start until the notice is actually published in the Federal Register. Based on the history of this (and most) ICR there won’t be any public comments to review.

The current ICR for this program (1607-0009) expired on Sunday so DHS cannot require anyone to submit the personal information needed to complete the training program. Since this is a voluntary program and the user’s employer gains the potential benefit from the user completing this information (not DHS) this ICR is not much more than a legal formality.

More USB Problems

As if Stuxnet hadn’t produced enough concerns about using USB jump drives with industrial control systems, yesterday US-CERT posted a warning about reports of “newly purchased removable media devices [that] are infected with malicious code”. If the system autorun is enabled (the default setting for most systems) the worm will infect the system when the device is connected.

There is no information in this report about what types of ‘removable media devices’ have been reported to be infected. This is not really a new issue; I recall reports of digital picture frames becoming infected at the manufacturer’s location when the quality control checks were done with an unprotected computer. Whether the devices being reported to US-CERT were deliberately or accidentally infected is not explained in this warning.

US-CERT recommends the implementing the following security practices:

• Disable autorun in Windows [see Microsoft knowledgebase article 967715].
• Maintain up-to-date antivirus software.
• Maintain up-to-date hardware, operating systems, and software by applying security patches, fixes, and updates.
• Perform virus scanning of the removable media devices prior to each use.
Please note that this warning did not come from DHS ICS-CERT so it did not include the caveat included in most ICS-CERT mitigation recommendations that administrators need to evaluate the potential impacts of the recommended mitigation measures on their particular systems prior to implementation.

Monday, November 1, 2010

Another Moxa Device Issue

DHS ICS-CERT published an Advisory on their Control Systems Security Program page today concerning a buffer overflow issue that has been indentified on the MOXA Device Manager (MDM, Version 2.1). ICS-CERT reports that they are working with Moxa to develop a new version of the software without this vulnerability.

The Advisory notes that this vulnerability appears that it would be difficult to exploit because “control of the MDM Gateway is necessary since the vulnerable function is exposed during communication between the MDM Tool and MDM Gateway”.

Mitigation Recommendations

DHS ICS-CERT recommends:

• Update version 2.1 to the new MDM version when it is released.
• Ensure network protection for the MDM Tool, Gateway, and Agents to protect communications between these systems.
• Encourage asset owners to minimize network exposure for all control system devices. Critical devices should not directly face the Internet. Control system networks and remote devices should be located behind firewalls, and be separate from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be utilized.
• Refer to the Control System Security Program Recommended Practices section for control systems on the US-CERT website. Several recommended practices are available for reading or download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies [note the printed URL in the Advisory is incorrect, though clicking on the link works].

DHS CSAT Webinars

Today DHS updated their CFATS Knowledge Center page by adding a small, but potentially very important item to the ‘Latest News’ section of the main page. That note reads:

“Weekly CSAT-SSP Webinars will soon be open to any CFATS facility with an outstanding SSP, please refer to this site for an update to this announcement. Webinars are currently held each Wednesday from 11:00 AM to 1:00 PM EST and 2:00 to 4:00 PM EST.”
I’ll be watching for the details when they become available. In the mean time, if I were having problems getting my head around my SSP, I would contact the CFATS Helpline (866-323-2957, Monday-Friday 7:00 a.m. – 7:00 p.m., Eastern Time) to see if you could get signed up for the next Wednesday webinar.

Ideally you want to get your CSAT team together in one place to observe and participate in the webinar. Get a conference room with a big screen or a digital projector, a conference phone and sign on to the webinar. Make sure you have one person asking the questions for the group at the end of the seminar, it will make things go smoother and ensure that the most important questions get asked and answered.

Without a doubt the question answer period at the end of these webinars is the most valuable portion of the presentation (though in my experience DHS puts out good information in their presentations).

If you don’t have an approved SSP then you need to take DHS up on this very valuable resource.

Update DHS Chemical Security Landing Page 11-01-10

Today DHS updated two of their web pages that are designed to provide links to information used to help protect chemical facilities. The first was the Chemical Security landing page, the page that provides the first step to finding DHS info on chemical security. They added a link to the Chemical Sector Training and Resources page. The only previous link to the page was on the Critical Infrastructure Protection landing page.

In turn the Training and Resources page was updated. The changes include:

● Added a link to sign-up for notification for changes to this page;
● Removed a list of out-dated training sessions under the Security Seminar & Exercise Series;
● Reworded the section on the Chemical Sector Security Summit to reflect the links to presentations from the last Summit and note registration for next Summit will be published next Spring; and
● Added a description for The Roadmap to Secure Control Systems in the Chemical Sector (to be requested by email).
I have requested a copy of the Roadmap. As soon as I receive it I plan to review it here in this blog.

Election Tomorrow

I haven’t talked much about the mid-term elections to this point because I have not expected them to have much effect on chemical security matters. I don’t know of a single election where this is determinant issue, or even an issue that is even discussed much on the campaign trail. Even Greenpeace seems to have backed off on their chemical security campaign. None of the major players in Congress with any kind of focus on chemical security issues appears to be in any danger of not being re-elected.

So what will happen when the votes are counted tomorrow (or the next day). Well, I hate to waffle, but I’m not sure anyone has a good prediction at this point of what the final numbers will be in Congress. As we would expect for the first mid-term elections for a new Administration, the party in power is expected to loose seats, the question is how many. Again, as with any mid-term elections it depends in large part in which party does a better job in getting their supporters to the polls. So here are the three scenarios that have a reasonable chance of coming to pass:

Democrats Maintain ‘Control’: Republicans make gains in both the House and the Senate, but Democrats retain a majority in both. The Republicans would have an easier time for blocking legislation in the Senate; more of their votes would be necessary for closing off debate on controversial subjects. In the House the power of the Blue Dog Democrats would increase as their votes would be absolutely necessary to pass Administration measures. In short, a lot more yelling and screaming and less controversial legislation getting to the President for signature.

Democrats Maintain ‘Control’ of Senate: Republicans gain a majority of the House, but don’t make enough gains in the Senate to gain the majority. Moderate Republicans will have some measure of power to moderate the House agenda, but the main moderating influence will be the inability to get a radical conservative legislation considered in the Senate.

Republicans Gain ‘Control: Republicans gain a majority in both the Senate and the House but this won’t give them real control. There won’t be enough votes to force a cloture vote in the Senate. The gains in the House will not be enough to over-ride a Presidential veto which Obama can be expected to wield to stop major changes to his agenda.
What this means for chemical security issues is that there will not be any major changes to CFATS. We will probably continue to see 1 to 2 year extensions of the current §550 authorization. We are likely to see, however, some sort of cyber security legislation that will have additional affects on chemical security requirements; this will be separate from CFATS and will be administered by another office in DHS.

One caveat to those predictions; if there is an actual attack on a chemical facility (successful or otherwise), there is no telling what kind of over-reaction we will get from any Congress. For example, just watch the Congressional reaction during the upcoming lame-duck session to the attempted attacks last week via explosives in aircraft. If any of these devices spent any time on commercial airliners you can expect to see a great hew and cry because TSA has not instituted 100% screening of packages on inbound commercial airlines. There will almost certainly be new legislation mandating such screening.
 
/* Use this with templates/template-twocol.html */