Saturday, June 18, 2011

HR 901 Markup Scheduled

This week the House Homeland Security Committee will be conducting a full committee markup of HR 901, Chemical Facility Anti-Terrorism Security Authorization Act of 2011. The hearing will be held on Wednesday “subsequent days as may be necessary”. As currently written this bill is just a codification of the current CFATS authority as an amendment to the Homeland Security Act of 2002 with an extension of that authority until September 30th, 2018.

The Committee web site notes that an amendment in the form of a substitute will probably be offered by the bill’s sponsor, Rep. Lungren (R, CA). The only change that I can find in that amendment is in §2107 where the annual authorization rate is changed from $93 Million to $89.9 Million; the same figure that was included in the marked-up version of HR 908.

The comment on the web site that this might be a multiple day hearing may indicate that Chairman King (R, NY) is trying to craft a revision to this bill that might have a better chance of being considered and passed in the Senate. This might include provisions addressing one or more of the following issues:

• Inherently safer technology (IST)
• Employee participation
• Personnel-surety redress procedures
• Training/drills
• Whistleblower protections
• Emergency response planning
• Water/waste-water facility coverage
• MTSA facility coverage
• Public disclosure of CFATS status
Any of the above provisions would have to be carefully crafted to allow passage both in the House (where industry concerns about the provisions would have to be addressed) and in the Senate (where environmental and labor activists have substantially more influence). Industry desire for a long term extension of the CFATS authority may make a reasonable compromise on some of these issues possible.

Another factor that must be considered in the markup of this bill is the fact that there is an alternative bill (HR 908) reported by the Energy and Commerce Committee that also provides for a long term extension of the CFATS program. The House leadership will have to decide which bill to bring to the floor of the House for consideration. The chance of this bill being the one selected would probably be increased if a water treatment facility provision were added to the bill as this would ensure that the Energy and Commerce Committee would have some oversight responsibility for the CFATS program. This would be similar to the compromise reached last session on HR 2868.

The Senate bill extending the CFATS authorization (S 473) has not yet been brought up in Committee. This may be a case of the Senate waiting to see what the House approves before they consider their options. This is what happened in the last session.

Friday, June 17, 2011

Complex TIH Transportation Issues of Canexus v BNSF

This week both BNSF and UP have filed responses to the complaint Canexus Chemicals Canada initiated with the Surface Transportation Board (STB) about the transportation of chlorine from the Canexus facility in North Vancouver, BC to Kansas City, MO. As I noted in my initial blog on this issue, this is a TIH routing issue made complex by TIH routing regulations, PTC regulations and previous STB rules.

Background Information

Canexus produces chlorine gas at its chlor-alkali facility in North Vancouver, BC. It has customers for that chlorine in the Southeast United States. There is no single railroad that can provide delivery service of that chlorine from source to customer. Some of those customers receive delivery service from UP. Canexus had negotiated a delivery contract with UP for those customers with UP accepting the chlorine shipments at an interchange location in Kansas City, MO. BNSF has declined to provide service from the Northwest to Kansas City for that interchange; countering with a proposed interchange with UP in Washington or Oregon. Canexus maintains that BNSF has a common carrier obligation to provide that service to Kansas City.

Complexities

First issue, BNSF does not actually service the production facility in British Columbia. That initial rail service is provided by CN. BNSF does provide service from an interchange with CN in Canada, but CN also provides service directly to the Mid-Western United States where there is a potential interchange with UP at St. Paul, MN. Other non-BNSF interchange options include interline arrangements through CP. So, BNSF maintains that, with other options for the required service to customers in the Southeast United States, they should not be compelled to provide the requested service.

The second issue is the high-cost of TIH transport. BNSF notes that the liability issues associated with a potential chlorine release and the requirements for the installation of positive train control equipment on lines with TIH service both increase the costs of providing TIH service. BNSF notes that they are not currently able to charge TIH shippers rates that would cover these increased costs.

The third issue involved in this dispute is the regulatory requirement for railroads to conduct TIH route planning that minimizes the safety and security risks associated with such shipments.

In its response to the Boards requirement to respond to the Canexus complaint BNSF states:

“Normally, the originating carrier exercises that preference by selecting the long haul in order to maximize its revenue division and contribution. But in the case of TIH/PIH, the normal commercial incentive to maximize contribution is not always controlling. The risk of liability, and the increased capital and operating costs from transporting TIH/PIH traffic far outweigh the potential revenue contribution and therefore BNSF logically seeks to minimize its potential exposure by minimizing its length of haul.”
While not as clearly stated in the UP response to the same order, UP has attempted to shorten its segment of the chlorine transport by accepting an interchange at Kansas City instead of in Washington or Oregon by directly negotiating a delivery contract with Canexus.

BNSF has filed a motion with the Board to refer this dispute to a mediation panel as is typically used in disputes about selecting interchange locations. They note that if the Board so orders, it will voluntarily extend its current arrangements for chlorine shipments to Kansas City until the end of July.

Oral Arguments Ordered

Yesterday the STB issued a conditional decision calling for oral arguments to be presented on June 23rd. It will not hold those arguments if both UP and Canexus agree to the mediation proposed by BNSF. UP and Canexus have been ordered to respond to the mediation proposal by June 20th.

Thursday, June 16, 2011

Another HMI SCADA Advisory from ICS-CERT

Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published yet another advisory about a vulnerability in a SCADA Human Machine Interface system, this time from a vendor in China, Sunway. The heap-based buffer overflow vulnerability affects two Sunway systems, the ForceControl and pNetPower applications.

There are no published exploits for the vulnerabilities and ICS-CERT estimates that it would take an attacker with an intermediate skill level to exploit them. Sunway has published separate patches for each system.

The interesting thing about this particular set of vulnerabilities is that the security researcher who reported them is Dillon Beresford of recent Siemens vulnerability fame. Obviously Dillon is no one-hit-wonder.

ICS-Monthly Monitor Published

ICS-CERT also published the second issue of their Monthly Monitor today. There is a very interesting description of the vulnerability disclosure procedures used by ICS-CERT; an appropriate topic given recent complaints about their apparent inaction on Dillon’s Siemens disclosure.

The interesting bit of disclosure here that was new to me was that, in the coordinated disclosure process, ICS-CERT publishes a limited edition advisory to be released the day that the vendor publishes the patch/mitigation-strategy. This is published, according to the Monitor, on a ‘secure portal library’, “which is available only to a limited vetted membership— primarily CIKR asset owners, federal, state, local, and tribal agencies”. No word on how one gains membership in this elite group.

As a blogger/reporter on chemical security issues I would not expect to be invited/allowed to join such a group. Even if I could, I don’t think that I would accept because of the undoubted limitations on disclosure that would accompany such membership.

I would suspect that any cyber security manager at a high-risk chemical facility, or any facility on the Critical Infrastructure Key Resources (CIKR) list should be interested in joining this group. I’m not sure how you would go about requesting membership, but I suspect that an email to ICS-CERT@dhs.gov would be a good place to start asking the questions.

PHMSA Pipeline Control Room Management Final Rule

Today the Pipeline and Hazardous Material Safety Administration published their final rule on pipeline control room management in the Federal Register (76 FR 35130-35136). As I noted in a blog post this weekend, this rule changes the effective dates of the previous rule on this topic published on December 9th, 2009 (74 FR 63301) and corrected on February 3rd, 2010 (75 FR 5536).

Revised Effective Dates

The following new dates apply:

October 1st, 2011 (Establish procedures by August 1st, implement October 1st):

• §192.631(b) Roles and responsibilities
• §192.631(c)(5) Shift change
• §192.631(d)((2)-(3) Fatigue mitigation education and training
• §192.631(f) Change management
• §192.631(g) Operating experience
August 1, 2012:

• §192.631 (c)(1)-(4) Adequate information
• §192.631 (d)(1) Shift length
• §192.631 (d)(4) Maximum hours-of-service
• §192.631 (e) Alarm management
Rule Status Confusion

I noted in my earlier blog that, based on the OMB web site data, there was some confusion about if this would be an NPRM or a direct final rule. Well, it turns out that there was even more reason for the confusion. The OMB’s regulatory agenda web page noted that the NPRM for this rule had been scheduled for December 2010, but had not yet been published. According to the preamble to this rule the NPRM had actually been published on September 17th, 2010 (75 FR 56972). So, there is no ‘direct final rule’ involved here.

TSA Publishes Pipeline Security ICR Renewal Notice

Today the Transportation Security Administration (TSA) published a 60-day notice in the Federal Register (76 FR 35229-35230) of their intention to request OMB approval for the renewal and expansion of their information collection request (ICR) for continued authority to collect ‘critical facility’ information on the top 100 ‘most critical’ pipelines.

That ‘top 100’ description is a misnomer. It comes from the requirement in the Implementing the Recommendations of the 9/11 Commission Act of 2007 {§1557(b)} for TSA to “develop and implement a plan for inspecting critical facilities of the 100 most critical pipeline systems”. What TSA has actually done is to identify the top 125 critical pipeline systems and have them identify their ‘critical facilities’. This has resulted in about 600 facilities that TSA is including in their pipeline inspection program.

According to the discussion in this notice, TSA expects to conduct follow-up visits to up to 125 critical pipeline facilities per year after reviewing the updated information collected under this ICR renewal. During these visits TSA will collect additional information under this ICR using the Critical Facility Security Review form. This new form will be different than the Corporate Security Review (which will remain in use) that is described in the current ICR in that it looks at facility specific information rather than corporate policy data.

This new form, and the intended follow-up data on implementing recommended security measures, have resulted in a change in the burden hours associated with the renewal of this ICR. TSA expects pipeline operators to spend 4 hours providing updated critical facility information. The new Critical Facility Security Review will take 4 hours at each facility and TSA expects facilities to spend five hours responding to TSA follow-up requests about the status of their security recommendations implementation. This results in an expected industry burden of 2,730 hours in the first year and 1,080 hours in each of the following years.

Public comments on this notice are solicited by TSA. Comments may be submitted by email to TSAPRA@dhs.gov. (TSA does not appear to be using the Federal eRulemaking Portal for these comments). Comments must be submitted by August 15, 2011.

Wednesday, June 15, 2011

S 1152 Introduced – Cybersecurity R&D

Last week Sen. Menendez (D, NJ) introduced S 1152, the Cybersecurity Enhancement Act of 2011. This is a companion bill to HR 2096 that I discussed in an earlier blog. This means that it identical to HR 2096 and theoretically allows for simultaneous consideration of the bill in both the Senate and the House, allowing for earlier passage of one of the two bills.

NOTE: The delay in this post is due to the fact that the GPO just published a copy of S 1152 today.

Reader Comment – NIST ICS Security Guide

A reader of this blog, Ragnar Schierholz, added a comment to my recent post about the publication of the NIST ICS Security Guide. He noted, as have some bloggers, that the recently published version of the Guide is little different from the draft of the document that was published about three years ago. He then asked if I had noted the very close similarity in the two versions.

I’m sorry Ragnar, I didn’t. The reason is that I never saw the draft document. Three years ago my understanding of ICS security issues was much narrower than it is today. Like much of the user community, I was essentially unaware of the multitude of cybersecurity issues that we recognize as being important today. Three years ago readers of this blog would have read about physical security measures for control rooms and vague suggestions that complete isolation of control systems was ‘becoming difficult’.

My appreciation for the complexities of control system security issues has changed over time and this has led to increased coverage of those issues in this blog. Hopefully, this has helped to increase awareness in the user community on these issues.

As a number of bloggers have noted, if the user community does not demand increased security in their systems, vendors will likely remain reactive to security vulnerabilities rather than proactively designing more secure systems (I almost wrote ‘secure systems’ there, a misnomer if ever there was one). That demand can only be made if there is an increased understanding of the problem.

So, while the newly released security guide may be little changed from the draft, it is a new document to many of us in the chemical security community. That makes it a valuable addition to any chemical security library.

On a personal note, questions like this one posed by Ragnar make me wonder what security issue I’m overlooking today due to the limits of my knowledge. Hopefully my readers are standing by to help identify those issues for me.
 
/* Use this with templates/template-twocol.html */