Tuesday, February 8, 2011

HR 495 Introduced – SAR Immunity

Almost two weeks ago Rep. King (R, NY) and 12 fellow Republicans introduced HR 495, the See Something, Say Something Act of 2011. This bill provides immunity from civil action for people that make good faith reports of “any suspicious transaction, activity, or occurrence indicating that an individual may be engaging, or preparing to engage, in a violation of law relating to an act of terrorism” {§809(d)(2)}. It also extends similar immunity to law enforcement personnel.

As a means of enforcement mechanism, the bill provides for the collection from the plaintiff “all reasonable costs and attorney fees” {§809(c)} if the court finds that the individual is immune from civil liability under the provisions of this legislation.

This bill is obviously designed to protect individuals supporting the Department’s expanding “See something, say something” program. This would seem to be an important legal protection to support that program. Without this protection, once the first civil suit against a person making a report made it to public notice, the effectiveness would be reduced because of concerns against facing such law suits.

This is particularly important for corporate reporting of suspicious activity. Since corporations are seen as having deep pockets, they are much more likely to face such civil suits. This bill addresses this issue by using the legal term ‘person’ which includes corporate entities.

In my opinion, the owners and employees of high-risk chemical facilities should actively support this bill and urge Chairman Smith (R, Tx) to bring this before the House Judiciary Committee for immediate consideration. They should also urge their congress critter to support this bill when it comes up for a vote, both in Committee and on the floor.

DHS ICS-CERT Upgrades Access to CSET

Yesterday the DHS Industrial Control System Cyber Emergency Response Team web site upgraded the access for their Cyber Security Evaluation Tool. Readers might remember that I described this program in a blog post last fall. Well, yesterday, ICS-CERT made it possible to download a copy of the tool so that they could conduct the security evaluation of their ICS without the direct assistance of ICS-CERT.

One short warning; this is not a simple one-click download process, like getting a .PDF document. You will be downloading a piece of complex software in the .ISO format which requires saving to a CD or ‘mounting’ the program to your hard-drive. The instructions on the ‘Download’ page should be read carefully.

Unless you have a time-critical need to conduct the CSET, I would probably recommend taking the alternative course and request a copy of the CSET DVD from ICS-CERT. This is done by sending a relatively simple email to ICS-CERT (see the CSET web page for detailed instructions).

Facilities should probably only consider either of these two options if they have a high internal (or hired) level of control system expertise. If a facility has any doubts about the potential adequacy of their knowledge base, they should probably avail themselves of the free ICS-CERT on-site support for this tool. I think that it would provide a better outside look at the facility ICS security situation.

In any case, every CFATS covered facility with an industrial control system should absolutely take advantage of one of these CSET options to review their ICS security program. If I were a chemical facility security inspector (CFSI) the first cyber security question I would ask is to see the results of the CSET evaluation.

Monday, February 7, 2011

S 158 Introduction – STB Reauthorization

Almost two weeks ago, Sen. Rockefeller (D, WV) introduced S 158, the Surface Transportation Board Reauthorization Act of 2011. This weekend the GPO finally printed a copy of the bill. Looking over the bill I did find one provision that might be of interest to the chemical security community; the requirement for the STB to conduct and report to Congress on a rail interchange study.

Section 210 requires the STB to “initiate a study of rail interchange rules, including car service, interchange, and other operating rules adopted and administered by the Association of American Railroads and the effect of those rules on the national rail system”. This could be of interest because of the effects these interchange rules can have on the decisions made by rail roads concerning the routing of TIH chemical shipments.

Since the STB is not directly involved in the enforcement of the hazmat rail routing rule, they might not understand the potential importance of these interchange rules. As a result they might miss subtle nuances of these rules that would make it easy to justify not shipping TIH chemicals on routes outside of major urban areas. Rerouting of TIH rail shipments out of these urban areas was one of the objectives of Congress when they directed TSA and FRA (in Section 1551 of the Implementing Recommendations of the 9/11 Commission Act of 2007) to establish rules to require carriers to “select the safest and most secure route to be used in transporting” ‘security sensitive materials’ like TIH chemicals.

It will be interesting to see if this provision is changed in the legislative process to clearly include a requirement to analyze the affect of these interchange rules on the route selection process for security sensitive materials.

A Look at Cyber Defense in Depth

The National Science Foundation (NSF) has an interesting notice in Monday’s Federal Register (available on the internet on Saturday) for a March 22nd workshop that is intending to look at the basic assumption that a cyber ‘defense in depth’ strategy is the best way to protect information systems. This is intended to be the first in a series of ‘Assumption Buster’ workshops.

There are a number of things that set this Federal Register Notice apart from the mainstream notice. First this isn’t the normal meeting notice where some organization is publishing a required meeting notice. It reads like more of a solicitation to form an organization. NSF is asking people to apply to participate in the workshop; requiring a resume/CV and a one-page opinion paper on the topic of defense-in-depth.

Another unusual aspect of this workshop is that NSF’s National Coordination Office (NCO) for the Networking and Information Technology Research and Development (NITRD) Program will be paying travel expenses for the selected participants. Most public meetings reported in the Federal Register expect public participants to pay their own expenses.

Of course, the most unusual aspect of this workshop is that it is intended to be an adversarial type of environment. The notice states that:

“The goal is to engage in robust debate of topics generally believed to be true to determine to what extent that claim is warranted. The adversarial nature of these debates is meant to ensure the threat environment is reflected in the discussion in order to elicit innovative research concepts that will have a greater chance of having a sustained positive impact on our cyber security posture.”
It’s nice to see that some people are interested in the competition of ideas. The confrontation of ideas is an important part of the scientific process. It is always a good idea to stop and question basic assumptions that we make about the use of technology from time to time.

This will be focusing on information systems, but I think it will be interesting for the control system community to take a look at the results from this workshop

House Homeland Security Committee Hearings

The House Homeland Security Committee will start holding hearings in earnest this week, with three separate hearings scheduled that might be of interest to the chemical security community. They will address: counter-terrorism intelligence, transportation security and chemical facility security.


Intelligence

The only hearing with any real details available currently is the planned full committee hearing to address “Understanding the Homeland Threat Landscape - Considerations for the 112th Congress”. There are two announced witnesses; Sec. Napolitano and Director Leiter, National Counterterrorism Center.

This hearing should provide a good, unclassified overview of the current intelligence landscape. More importantly it should give us the best indication of the relationship between the Department and the new Homeland Security Committee.

The hearing will be held at 10:00 a.m. EST on Wednesday.

Transportation Security

The Subcommittee on Transportation Security will conduct a hearing on “Terrorism and Transportation Security” on Thursday at 10:00 a.m. EST. No witnesses have yet been announced.

Chemical Facility Security

The Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies will conduct a hearing on “Preventing Chemical Terrorism: Building a Foundation of Security At Our Nation’s Chemical Facilities” on Friday at 10:00 a.m. EST. No witnesses have yet been announced.

Since we have not yet seen a chemical security bill introduced, this is probably not going to be a look forward to the permanent authorization of CFATS. I would suspect that ISCD will be accounting for the current state of the CFATS implementation. Since this subcommittee also looks at cyber security issues, it will be interesting to see if there is any mention of control system security issues, like maybe Stuxnet?

Bayer CropScience IST Study

Last months announcement that Bayer CropScience would be phasing out the use of MIC poses an interesting problem for the Chemical Safety Board and the National Research Council in regards to the congressionally mandated IST study of the use of methyl isocyanate at the Bayer CropScience facility outside Institute, WV. As I noted in an earlier blog, the tasking document specifically designed the purpose of the study to look at the potential alternatives to MIC production and use, not the broader issue of the employment of inherently safer technology.

Bayer IST Study Moving Forward

According to a recent article on the Chemical & Engineering News web site the study is moving forward with the first public meeting on February 9th in Washington, D.C. The study report is expected to be published in September.

The article quotes Dorothy Zolandz, director of the NRC panel that is conducting the study, as explaining that:

“Here we have an actual on-the-ground plant that we can use to enlighten us about how these assessments are carried out, what their capabilities and limitations are, and so forth. We have a real case study”
Since the recent CSB report on the 2008 fatal accident at the facility indicates that the owners took a number of safety measures to physically protect the MIC storage systems to prevent potential releases, it seems obvious that Bayer and its predecessors had a firm understanding of the safety issues they were dealing with. If that understanding was informed by a documented look at the potential alternatives to using MIC, then this NRC study may provide a valuable look at the IST process in a real world application.

An interesting look at the potential outcome of the study comes from Daniel Horowitz, CSB’s managing director of congressional, public, and board affairs; who is quoted as saying:

“Our interest has always been how inherently safer designs can benefit industry as they strive to make processes safer. We are hoping for advice from [NRC] on how we as an agency should look at these inherently safer technological issues in our accident investigations”
IST as a Political Issue

While the noise around the political debate about the use of IST procedures as part of the CFATS process has diminished because of the recent political changes in the House and Senate, anyone that really expects this issue to disappear underestimates the concerns of many people in organizations like Greenpeace and many union organizations. While their political influence is on the wane (and that is always a potentially temporary situation in this country, as closely divided as we continue to be), they will continue to make their voices heard.

I have always tried to maintain a middle ground on the IST issue. I think that the basic concept of taking a serious look at the potential alternative chemical processes to reduce safety and security risks is something that anyone should be able to agree is a worthwhile exercise. The problem of requiring such an exercise as part of a security process is defining how is should be done. And that is something that neither side in the debate has been willing to discuss.

This study by the NRC may give us a good look at how an actual IST process has been conducted by industry. With the issue of the continued use of MIC at Bayer CropScience now a settled, we can hope that the study will spend more time looking at how the IST study process was conducted at the Institute, WV facility over the years. An NRC recommendation of how to conduct such a study would be a valuable contribution to the IST debate.

There is another contribution to this debate that ought to be studied. Many opponents of an IST mandate in CFATS have argued that the chemical industry already looks at IST as part of their business model. They point to the number of facilities that have changed their processes as a result of the CFATS regulations as how the current business model achieves IST results.

It would be interesting for someone to take a detailed look at how many of the facilities that have dropped out of the CFATS process (there were over 6,000 covered facilities in the original Top Screen evaluation and fewer than 5,000 facilities currently in the process) did so because of IST type process changes and how many were due to the current economic situation. This is a study that the Rep. King and his Republican fellows on the House Homeland Security Committee should have no problems supporting. It would be relatively cheap to conduct and would provide valuable information for the debate. And it could be inserted in the final FY 2011 budget.

Saturday, February 5, 2011

DHS Control System Security Program Page Update

The DHS Control System Security Program web page was updated yesterday to include links to news about the upcoming Industrial Control System Joint Working Group (ICSJWG) 2011 Spring Meeting in Dallas, Tx and a new ICS-CERT recommended practices document.

ICSJWG Spring Meeting

The 2011 Spring Meeting will be held on May 2nd thru 5th at the Dallas/Addison Marriott Quorum hotel. According to the meeting web page

“The ICSJWG Conference will consist of panel discussions, presentations, training, and working group meetings on various topics such as emerging technologies, standards development, threat and incident reporting, analysis tools and techniques, roadmap development initiatives, workforce development and certification, vulnerability management, research and development, information sharing, and international coordination.”
The page also includes a Call for Papers for this meeting. It provides a non-exclusive list of potential topics, a link to an electronic submission form for sending an abstract for a proposed presentation and a submission deadline of February 18th.

The last day of the Spring Meeting will be the typical ICSJWG all-day training course. For this meeting it will be the Intermediate Industrial Control Systems Cybersecurity training. Prior control system security experience or attendance at the basic-level course is the recommended prerequisite for this class. The training will include:

• The importance of protecting control systems from cyber attacks and why they are susceptible

• Understanding the risks and potential consequences of attacks

• Understanding common vulnerabilities in industrial control systems

• Discussion of system exposures to attacks, various attack scenarios, and associate mitigation strategies

• Control Systems Security Program products and services that are available to asset owners.
Both the Spring Meeting and the all-day training are free. Well, that’s not completely true; no charge for attending, but you do have to pay for travel and accommodations. As I expect that most travel budgets remain tight (I know mine is) I will make my standard recommendation that the organizers of this conference consider providing on-line access to at least some of the presentations. It would certainly expand the potential audience for this valuable information.

Remote Access for ICS

The DHS Control System Security Program and the Center for the Protection of Critical Infrastructure have produced a new best practices document; Configuring and Managing Remote Access for Industrial Control Systems. In a modern industrial setting there are many legitimate reasons to provide remote access to control systems this lengthy and dense document provide a detailed look at how that access can be provided in a secure manner.

This is not a how-to manual, but more of a policy discussion. As is typical for many policy discussion documents this means that the writing can get fairly intense. For example, here is the opening paragraph in the discussion of on ‘password policy’:

“In an ideal deployment, authentication mechanisms should be chosen based on the criticality of the system being accessed and should include not only passwords, but other mechanisms as well (see the section on ‘Two form factor authentication’). When using passwords, a secure remote access system should enforce complex passwords of 8 to 25 characters that are a mixture of upper and lower case letters, numbers and symbols.k In addition, corporate policy should demand that these passwords be changed at a rate that is commensurate with the value of the system being protected and regular audits of the strength of these passwords should be done as part of the organisational [sic] cyber security program. The corporate cyber security policy should dictate that these passwords are never shared and that each user ID is unique across the entire system.”
This seems fairly straightforward until you get down to the footnote referred to in the middle of the paragraph. That footnote (k) reminds the reader that:

“This guideline is a recommended best practice for general ICT security and the authors recognise [sic] that the creation and use of a 25-character complex password (although ideal) for day-to-day human machine interface operations may be inappropriate. The recollection and usage of such a password under duress may create circumstances that are unacceptable from a safety perspective.”
I think that this is a valuable manual to have and review, but I do have on major complaint about the mechanics of the document. There are a large number of high-density graphics included that make navigation through the 66-page document difficult and time consuming if you are using an older system. I had page load times of almost two minutes using my old Windows 2000 based lap top.
 
/* Use this with templates/template-twocol.html */