Today the Pipeline and Hazardous Materials Safety Administration (PHMSA) published a 60-day renewal notice in the Federal Register (76 FR 33808-33809) for continued authority to collect information on the public awareness programs required to be developed and implemented by operators of natural gas and hazardous liquid pipelines under 49 CFR 192.616 and 195.440. The current authority (OMB Control # 2137-0622) to collect this information expires on October 31st.
PHMSA expects 22,500 responses per year with an estimated annual burden of 517,480 hours or about 23 hours per response. PHMSA requests feedback from industry on the accuracy of that burden estimate.
Responses to this ICR can be filed on-line at the Federal eRulemaking Portal (http://www.regulations.gov/; Docket number PHMSA-2011-0136). Such comments should be submitted by August 8, 2011.
Thursday, June 9, 2011
HR 2096 Introduced – Cyber Security R&D
Last week Rep. McCaul (R, TX) introduced HR 2096, the Cybersecurity Enhancement Act of 2011. The bill would amend the existing provisions of High-Performance Computing Act of 1991 (15 U.S.C. 5511) and the Cyber Security Research and Development Act (15 U.S.C. 7401) to advance cybersecurity research, development, and technical standards.
While the findings section of this bill specifically mentions “critical infrastructures for electric power, natural gas and petroleum production and distribution, telecommunications, transportation, [and] water supply” {§102(1)} there is not a single mention of control systems in the bill. The clear focus of this bill’s studies, research programs and grant programs remains the conventional cyber security areas of information technology, information and identity assurance, and networking systems.
While the findings section of this bill specifically mentions “critical infrastructures for electric power, natural gas and petroleum production and distribution, telecommunications, transportation, [and] water supply” {§102(1)} there is not a single mention of control systems in the bill. The clear focus of this bill’s studies, research programs and grant programs remains the conventional cyber security areas of information technology, information and identity assurance, and networking systems.
NIST Publishes Guide to ICS Security
There is a new document out that address security for industrial control systems. The National Institute of Standards and Technology (NIST) published their “Guide to Industrial Control Systems (ICS) Security”. After a really quick ten-minute review of this lengthy (155 pages) document this morning, it looks like a valuable contribution to the discussion about ICS security issues.
As time permits I will do a more detailed review of the Guide and provide more information about its contents here in this blog. In the meantime, I would certainly recommend that anyone with responsibilities for ICS security should download a copy of this document.
As time permits I will do a more detailed review of the Guide and provide more information about its contents here in this blog. In the meantime, I would certainly recommend that anyone with responsibilities for ICS security should download a copy of this document.
Wednesday, June 8, 2011
Are We Having Top Screen Delays Too?
I had an interesting email exchange recently with a reader who is experiencing delays in getting a CFATS evaluation done by the folks at ISCD. No not a SSP delay; that would be old news by now. No this reader’s facility submitted their initial Top Screen about 90 days ago now and is still waiting on The Decision of whether or not their facility will be preliminarily declared a high-risk facility subject to the CFATS regulations. The reader wanted to know if a 90-day delay was unusual.
Back when the first large batch of Top Screens (almost 40,000) was being submitted within a single 60-day window a 90-day delay was not too unusual and was certainly understandable and defensible. Now, better than three years later, one would think that DHS would have all of the bugs worked out of the Top Screen evaluation system. Additionally, there should be a drastically reduced number of new Top Screen submissions (as opposed to updated Top Screens for currently covered facilities) for the system to handle.
Now, if all ISCD was doing was analyzing Top Screens, I would be very concerned about 90-day delays in getting information back from DHS on a new Top Screen submission. We all know, of course, that ISCD and the CFATS team have their attention focused on the site security plan portion of the CFATS process. I’m sure that that focus is the proximate cause of any delays in the Top Screen or SVA review process.
Now the Top Screen review process at DHS is probably the most highly automated of the reviews required by CFATS, but it is not completely automated. Some of the questions require more of a qualitative evaluation as opposed to a quantitative review. The final decision on whether a facility is covered or not has to be made by a real live person; one would assume a person with some minimum level of bureaucratic authority.
With the minimal staffing levels authorized for the headquarters element of ISCD (as opposed to the Chemical Facility Security Inspectors out in the field), the people making decisions on the Top Screen would be making similar decisions on site security plans. The site security plans being a higher current priority (politically speaking) and requiring many more high-level decisions of a higher degree of complexity (not to mention breaking new ground in almost every new plan being considered) means that the limited supply of decision makers is having more of their decision making time focused on the SSP with very little time left over for Top Screen and SVA evaluations.
So, no, I don’t suppose that it is surprising that there are lengthy delays in anything being done by ISCD these days. The problems caused by the underestimation of the complexity of the site security plan review process are going to have an adverse impact on every operation of this organization; it is inevitable.
And it is only going to get worse. Sooner or later, the personnel surety program will be put together and implemented (and the act of getting there is yet another manpower drain). That will require some level of review by the staff at ISCD. Then there will be the new ammonium nitrate rule that DHS has promised will be in place by November. That will add a whole new level of confusion and implementations issues.
Oh. And let’s not forget that we have to tighten up the purse strings of the Federal government. That will have to have an adverse impact on the personnel situation within DHS.
So, to anyone making any sort of CSAT submissions for CFATS covered facilities, expect delays in getting the necessary responses from DHS. For my Top Screen reader, if you think that it is likely that your facility will be designated a high-risk facility, go ahead and start working on the development of your SVA. There is lot’s of information to collect and organize. Getting it started before the regulatory clock starts to tick will make life easier in the long run.
Back when the first large batch of Top Screens (almost 40,000) was being submitted within a single 60-day window a 90-day delay was not too unusual and was certainly understandable and defensible. Now, better than three years later, one would think that DHS would have all of the bugs worked out of the Top Screen evaluation system. Additionally, there should be a drastically reduced number of new Top Screen submissions (as opposed to updated Top Screens for currently covered facilities) for the system to handle.
Now, if all ISCD was doing was analyzing Top Screens, I would be very concerned about 90-day delays in getting information back from DHS on a new Top Screen submission. We all know, of course, that ISCD and the CFATS team have their attention focused on the site security plan portion of the CFATS process. I’m sure that that focus is the proximate cause of any delays in the Top Screen or SVA review process.
Now the Top Screen review process at DHS is probably the most highly automated of the reviews required by CFATS, but it is not completely automated. Some of the questions require more of a qualitative evaluation as opposed to a quantitative review. The final decision on whether a facility is covered or not has to be made by a real live person; one would assume a person with some minimum level of bureaucratic authority.
With the minimal staffing levels authorized for the headquarters element of ISCD (as opposed to the Chemical Facility Security Inspectors out in the field), the people making decisions on the Top Screen would be making similar decisions on site security plans. The site security plans being a higher current priority (politically speaking) and requiring many more high-level decisions of a higher degree of complexity (not to mention breaking new ground in almost every new plan being considered) means that the limited supply of decision makers is having more of their decision making time focused on the SSP with very little time left over for Top Screen and SVA evaluations.
So, no, I don’t suppose that it is surprising that there are lengthy delays in anything being done by ISCD these days. The problems caused by the underestimation of the complexity of the site security plan review process are going to have an adverse impact on every operation of this organization; it is inevitable.
And it is only going to get worse. Sooner or later, the personnel surety program will be put together and implemented (and the act of getting there is yet another manpower drain). That will require some level of review by the staff at ISCD. Then there will be the new ammonium nitrate rule that DHS has promised will be in place by November. That will add a whole new level of confusion and implementations issues.
Oh. And let’s not forget that we have to tighten up the purse strings of the Federal government. That will have to have an adverse impact on the personnel situation within DHS.
So, to anyone making any sort of CSAT submissions for CFATS covered facilities, expect delays in getting the necessary responses from DHS. For my Top Screen reader, if you think that it is likely that your facility will be designated a high-risk facility, go ahead and start working on the development of your SVA. There is lot’s of information to collect and organize. Getting it started before the regulatory clock starts to tick will make life easier in the long run.
DHS ICS-CERT Updates Samsung Advisory
This morning the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) updated the advisory that they issued on May 26th for an SQL injection vulnerability in the Samsung Data Management Server (DMS). The update changes the method that owners/users should follow to update their system to mitigate this vulnerability.
The new instructions state:
BTW: This is the 'B' version of the advisory but I cannot find a copy of the 'A' version on the ICS-CERT site. The original version had no letters.
The new instructions state:
“1. Contact Samsung via the e-mail address that is posted at the following Internet address: http://wwwdvmcare.com/SRM/dms/download.html.So much for air-gapped control systems. CFATS facilities that have a Samsung DMS as part of their critical areas list need to remember that remote access to computers is unaccompanied access and is thus governed by personnel surety rules. Have fun assuring that the person who is actually doing this update is properly vetted and cleared.
“2. Samsung will then either update the DMS installation remotely or dispatch a Samsung service engineer directly to the installation site to apply the patch, depending on customer preference.”
BTW: This is the 'B' version of the advisory but I cannot find a copy of the 'A' version on the ICS-CERT site. The original version had no letters.
Sen. Lieberman’s DHS Budget Guidance
Recently Sen. Lieberman, Chairman of the Senate Homeland Security and Governmental Operations Committee sent a letter to the Senate Appropriations Committee outlining what he believes should be included in a DHS spending bill. As you would expect he addressed both chemical security and cyber security issues.
Chemical Facility Security
He expressed his hope that a CFATS authorization bill would be passed this session, but that he wanted to see a one-year extension included in the DHS spending bill. He noted that; “the most important thing is that the existing program continues without any lapse”.
Cyber Security
Lieberman came out firmly supporting the increased spending for cyber security efforts that was included in the President’s budget request. Unfortunately this support included some apparent confusion about the difference between federal networks and industrial control systems. He noted:
Surface Transportation Security
Sen. Lieberman does not even address spending for surface transportation security spending in TSA. The closest he gets to addressing this issue is his support for the President’s budget requests for the Port Security and Transit Security Grant programs. This lack of attention to freight rail and truck security issues, is endemic to Congress in general not just Sen. Lieberman. Fortunately, it appears to extend to terrorist planners as well.
Chemical Facility Security
He expressed his hope that a CFATS authorization bill would be passed this session, but that he wanted to see a one-year extension included in the DHS spending bill. He noted that; “the most important thing is that the existing program continues without any lapse”.
Cyber Security
Lieberman came out firmly supporting the increased spending for cyber security efforts that was included in the President’s budget request. Unfortunately this support included some apparent confusion about the difference between federal networks and industrial control systems. He noted:
“The [President’s] request includes an increase of $78.3 million for efforts to secure federal networks, which includes increased funding for technical support, oversight duties pursuant to the Federal Information Security Management Act, and deployment of EINSTEIN sensors. The need for this funding is underscored by the discovery of both the Stuxnet worm during the summer of 2010 and, just last week, of significant vulnerabilities in a software package common to many major industrial control systems.”This confusion in the Chairman of one of the main Senate committees that will have to sign off on any significant cyber security legislation bodes ill for the effectiveness of Committee efforts to craft legislation that would adequately address control system security issues.
Surface Transportation Security
Sen. Lieberman does not even address spending for surface transportation security spending in TSA. The closest he gets to addressing this issue is his support for the President’s budget requests for the Port Security and Transit Security Grant programs. This lack of attention to freight rail and truck security issues, is endemic to Congress in general not just Sen. Lieberman. Fortunately, it appears to extend to terrorist planners as well.
Tuesday, June 7, 2011
GPO Publishes House Version of HR 2017
Yesterday the final version of HR 2017 passed last week by the House became available on the GPO web site. This allows us to better understand the effects of the large number of amendments that were adopted during the floor debate on this bill. For readers of this blog probably the most important item is the confirmation that the CFATS extension did remain in the bill, though it is now found at §535.
Budget Numbers
None of the gross budget numbers that I discussed in my earlier blog on the introduction of HR 2017 have changed. There are no indications of changes to any of the program budget numbers identified in that blog as coming from the Committee Report on the bill.
TWIC Amendment
As I noted on the first day of the debate there was an amendment to the bill passed that would affect the operation of the TWIC program. That amendment is now §704 of the bill. It reads:
I discussed this issue in more detail in my blog on the GAO report on potential requirements to mail TWIC to approved applicants.
Budget Numbers
None of the gross budget numbers that I discussed in my earlier blog on the introduction of HR 2017 have changed. There are no indications of changes to any of the program budget numbers identified in that blog as coming from the Committee Report on the bill.
TWIC Amendment
As I noted on the first day of the debate there was an amendment to the bill passed that would affect the operation of the TWIC program. That amendment is now §704 of the bill. It reads:
“None of the funds made available under this Act may be used to require an approved Transportation Worker Identification Credential (TWIC) applicant to personally appear at a designated enrollment center for the purpose of TWIC issuance, renewal, or activation.”If this provision remains in the final version of the budget, this could have a significant on the operation of the TWIC program. The whole point of the TWIC program is that there has been a biometric confirmation of the identity of the holder of the card. This is going to be difficult to achieve when the applicant for the TWIC cannot be required to show up at the issuing facility at some point in the issuing process. This will certainly require changes in the TWIC procedures and probably the TWIC regulations.
I discussed this issue in more detail in my blog on the GAO report on potential requirements to mail TWIC to approved applicants.
Subscribe to:
Posts (Atom)