Tuesday, February 5, 2013

ICS-CERT Publishes Ecava Advisory


Today the DHS ICS-CERT published an advisory for a buffer overflow vulnerability in the Ecava IntegraXor application. The vulnerability was reported by Andrew Brooks in a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker utilizing a social engineering attack could remotely exploit this vulnerability to run arbitrary code on the system. Ecava has produced an updated version of the affected application that has been verified by Brooks to correct the vulnerability.

NSTAC Meeting Announced – 2-21-13


Today the DHS National Protection and Programs Directorate (NPPD) published a meeting notice in the Federal Register (78 FR 8160-8161) for a public meeting of the President’s National Security Telecommunications Advisory Committee (NSTAC). The meeting will be held via conference call on February 21st, 2013.

Agenda

The NSTAC will discuss the draft of a report for President Obama on the national security and emergency preparedness implications of the establishment of a nationwide public safety broadband network. The report will recommend that the President support the public safety broadband network project by suggesting:

• Organizational streamlining;
• Policy changes;
• Technical initiatives;
• Reporting requirements, and
• Funding measures.

The teleconference will also address the progress being made by the Secure Government Communications Subcommittee in examining the use of commercial-off-the-shelf technologies and commercial best practices to help secure between Federal civilian agencies.

Public Participation

Public participation is being solicited by the NPPD notice. Written comments on the topics listed above may be submitted by using the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2013-0002) by February 20th. Personnel wishing to make brief oral presentations on these topics may register to do so by contacting Sue Daage (sue.daage@hq.dhs.gov) by February 14th. Ms. Daage is also the person to contact to obtain access to the meeting’s phone bridge.

Monday, February 4, 2013

S 68 Introduced – Comprehensive CFATS Authorization


As I mentioned in an earlier blog post Sen. Lautenberg introduced S 68, the Secure Chemical Facilities Act. This bill would be the type of comprehensive chemical facility security legislation envisioned when Congress authorized the interim CFATS program in 2006. The language is nearly identical to S 709 in the 112th Congress and S 3599 in the 111th Congress; both authored by Lautenberg.

Overview

In many ways this bill mirrors the bill (HR 2868) that passed in the House in the 111th Congress. It does not specifically mention the current CFATS program, but much of the bill affirms what has been currently done and makes modifications to that program. It specifically amends the Homeland Security Act of 2002 adding Title XXI.

It adds a provision that addresses employee participation in the security vulnerability assessment process and the development of the site security plan. It requires that such activities must include at least:

• One supervisory employee {§2103(a)(1)(B)(iii)(I)}
• One non-supervisory employee {§2103(a)(1)(B)(iii)(II)}
• One employee representative from each bargaining agent {§2103(a)(1)(B)(iii)(III)}

It obliquely addresses the current delays in the SSP approval process by requiring that the Secretary must “review and approve or disapprove the security vulnerability assessment or site security plan” within 180 days of their submission {§2103(a)(1)(G)(i)}. It also specifically addresses the sharing of information on the assessment and security plans with the local emergency planning and response personnel requiring the provision of “appropriate information to any local emergency planning committee, State emergency response commission, local law enforcement officials, and emergency response providers to ensure an effective, collective response to terrorist incidents” §2103(c)(9).

It affirms the current risk based performance standards (RBPS) set forth in 6 CFR §27.230, including nearly identical language found in that section. It does add three new ‘security performance standards’:

• Assessing and, as appropriate, using methods to reduce the consequences of a terrorist attack; {§2103(c)(19)}
• Methods to recover or mitigate the release of a substance of concern in the event of a chemical facility terrorist incident; {§2103(c)(20)}
• Methods to mitigate the risks of exposure to chemical agents by maintaining an adequate supply of equipment and products to provide for decontamination procedures designed to neutralize the chemical agents; and {§2103(c)(21)}

The bill would expand the coverage of the CFATS program to include facilities regulated under the Maritime Transportation Security Act (MTSA){§2103(g)(1)} and those regulated by the Department of Justice under the Alcohol Tobacco and Firearms people {§2103(g)(2)}. Those resulting regulations would have to be coordinated with Commandant of the Coast Guard and the Attorney General to ensure that there is no unnecessary duplication or conflicts.

One of the more controversial parts of this legislation is the inclusion of inherently safer technology (IST) provisions under the heading of ‘methods to reduce the consequences of a terrorist attack’ {§2111}. This section deserves more detailed coverage, but it would establish a ‘best technology’ standard for determining what is feasible {§2111(a)}. It would also essentially exempt agricultural retailers and end users {§2111(d)} and small chemical facilities {§2111(e)} from the IST requirements by adding additional requirements before implementation of IST could be mandated.

The personnel surety mandate {§2115} would be expanded by requiring the Secretary to clearly identify the offenses {§2115(b)(2)(A)(i)} and the elapsed time from those offenses {§2115(b)(2)(A)(ii)} that would disqualify a person from working in critical areas of covered chemical facilities; the process would be similar to the TWIC procedures. It would also require the establishment of a redress procedure {§2115(d)} and an appeals process {§2115(e)} for a determination of security risk.

Two other controversial topics address the involvement of non-facility personnel in the chemical facility security processes. Section 2116 would allow private citizens to sue the Secretary to ensure compliance with the provisions of this act and §2117 would allow citizen petitions to raise issues of compliance at individual facilities.

The current Infrastructure Security Compliance Division would get revamped under this bill. It would be upgraded to the Office of Chemical Facility Security, presumably still in the National Protection and Programs Directorate in DHS. It sets some pretty stiff requirements for the Director; a demonstrated knowledge of {§2114(b)(1)}:

• Physical infrastructure protection;
• Cybersecurity;
• Chemical facility security;
• Hazard analysis;
• Chemical process engineering;
• Chemical process safety reviews; or

That ‘or’ at the end is the erasure of those requirements as it sets the alternative as “other such qualifications that the Secretary determines to be necessary” {§2114(b)(1)}.

There are two provisions for the obligatory reports to Congress. Section 2120 provides for an annual report on the status of the chemical facility security program under this legislation with specific details about what that report would entail. It would also include a one-time report on a study of emergency response capabilities for responding to a catastrophic release from terrorist attacks on covered facilities.

As is to be expected from a bill authorizing a comprehensive program like this it does include appropriations authorization. It provides for $300M for 2013 & 2014 and $275M through 2017. Of that $150M is for grants to support the IST program with $3M earmarked for grants supporting that program in the agricultural community.

Moving Forward

In the past I have dismissed the earlier incarnations of this bill as dead upon introduction. Since the bills were of necessity referred to the Senate Homeland Security and Governmental Affairs Committee for action, these bills never stood a chance of being considered because the bills sponsored by then Sen. Collins (R,ME) would take priority in consideration. Without the Collins and Lieberman team present, it is not clear that there will necessarily be an in-committee bill that would pre-empt the consideration of this bill. If Sen. Levin (D,MI) had, for instance, been a co-sponsor of this bill I would have been nearly certain that it would have been considered by the Committee. As it is, we’ll just have to wait and see.

In any case, I doubt that this bill would make it to the floor of the Senate because of the opposition to the IST and citizen action provisions. It will certainly not get considered in the House.

Sunday, February 3, 2013

Congressional Hearings – Week of 02-03-13


This week both the House and Senate will be in town. There are no hearings of particular interest on the Senate side of the building and only two on the House side. Both of those are organizational hearings with both Committees (Energy and Commerce and Oversight and Reform) adopting their oversight plans for the 113th Congress. Those plans will address chemical security issues as well as cybersecurity issues.

Energy and Commerce

The Committee will meet on Tuesday and Wednesday. Their draft Oversight Plan specifically addresses chemical-security and cybersecurity topics. Not too much detail on either topic in this plan (as would be expected) but what is available does provide some insight into what philosophy the Chairman and his staff expect to advocate in this session.

Cybersecurity – “The Committee will exercise its jurisdiction over cybersecurity to ensure the country is well protected  while at the same time avoiding one-size-fits all approaches [emphasis added] that hinder the flexibility  of commercial and governmental actors need to combat the rapidly evolving threats.”

CFATS – “The Committee will continue to examine whether taxpayer funds are spent prudently and the extent to which the Department is advancing the purpose of securing chemical facilities against terrorist threats.”

This committee is expected to craft legislation this session for renewal of the CFATS program and on cybersecurity issues. There will be conflicting (to one degree or another) legislation from the Homeland Security Committee on both topics and it will interesting to see which version of the bills make it to a floor vote (if any do).

Oversight and Governmental Reform

I don’t normally follow this committee very closely, but their draft Oversight Plan does contain a section on Homeland Security that does address security areas of potential interest to readers so their hearing on Tuesday may be interesting.

The Homeland Security section of their plan contains the following paragraph:

“The Committee will evaluate efficiency and effectiveness of homeland security strategy, laws, initiatives, and technology.  In particular, the Committee will focus on aviation, rail and transit, chemical, nuclear, port, our northern and southwestern borders, and other facilities or critical infrastructure at risk, federal funding interaction with local responders and efforts to strengthen the U.S. public health system.” [emphasis added]

Cybersecurity is addressed under Technology Policy and focuses primarily on Federal Information Security Management Act (FISMA) and thus is primarily interested in government IT security, not control systems.

Saturday, February 2, 2013

OMB Approves TSA Exercise Information System ICR


On Friday the Office of Management and Budget (OMB) announced that it had approved the information collection request (ICR) from the Transportation Security Administration (TSA) for their new Exercise Information System (EXIS). I discussed this new program in some detail last year when TSA initiated this ICR.

The EXIS web page is up and functioning, but there is little on it yet. This is another site that will go on my list of sites to periodically check. The EXIS Links page does provide a good list of web sites that emergency planners and exercise planners might find useful. There is also a brief overview of the Intermodal Security Training and Exercise Program (I-STEP) that is supported by the EXIS program.

Everything sounds good here. It will be interesting to see how well it is executed and used by the transportation and emergency response communities.

DHS Announces HSIN Advisory Committee Meeting – 2-27-13


DHS published a notice (78 FR 7797-7798) in Monday’s Federal Register (available on-line today) announcing that the Homeland Security Information Network (HSIN) Advisory Committee would be holding a two-day meeting on February 27th.

The Agenda

The agenda includes:

• HSIN update including OMB TechStat review;
• HSIN Release 3 update; and
• HSIN and the National Information Sharing and Safeguarding Strategy.

Additionally, the HSIN Program Management Office has requested that the HSINAC look at communication messaging and training guidance on the suggested topics of:

• Identity proofing;
• Migration;
• Two-factor authentication;
• Federated users; and
• Community of interest (COI) charter implementation.

Public Participation

The meeting is open to the public and the meeting will be available by teleconference. You may register by contacting David Steigman (david.steigman@hq.dhs.gov) by February 25th. Written comments may be submitted on the agenda topics via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2013-0005). A short period for public oral comments will be made available at the end of the meeting; register with David Steigman.

Interestingly the notice provides some details for how the HSINAC will deal with inclement weather should that arise for the scheduled meeting time. I can’t imagine why anyone would possibly expect weather to affect Washington, DC in February (minor sarcasm alert).

BTW: I can see some acronym confusion in the future. The use of ‘COI’ in this context could be confused with the CFATS use of ‘COI’ and both could be expected to come up in HSIN communications.

Friday, February 1, 2013

Coast Guard Publishes Request for Comments Notice


Today the Coast Guard published a notice in the Federal Register (78 FR 7334-7336) requesting comments on how to best proceed with the implementation of §822 of the Coast Guard Authorization Act of 2010 (Pub. L. 111-281). While the words ‘advanced notice of proposed rulemaking’ are nowhere to be found in this notice, this is certainly what it appears to be.
In passing the Coast Guard Authorization Act of 2010 Congress added two new mandates in §822:
• Make a current copy of the vulnerability assessment conducted under subsection (b) available to the port authority with jurisdiction of the facility and appropriate State or local law enforcement agencies; and
• Integrate, to the maximum extent practical, any security system for the facility with compatible systems operated or maintained by the appropriate State, law enforcement agencies, and the Coast Guard.

Facility Vulnerability Assessment

The Coast Guard is considering four possible options for the requirement to share vulnerability assessments:
• Require each MTSA-regulated facility owner or operator to make a copy of the current FVA available to the cognizant Coast Guard Captain of the Port, port authority, and State and local law enforcement agencies, upon request.
• Require each MTSA-regulated facility owner or operator to proactively provide a copy of the current FVA to the port authority and State and local law enforcement agencies at a prescribed time interval (as opposed to making copies of FVAs available to the port authorities and law enforcement upon request).
• Require each MTSA-regulated facility owner or operator to share the current FVA with the port authority and State and local law enforcement agencies annually at the annual exercise required under 33 CFR 105.220 or at a newly required annual FVA sharing meeting.
• Require each MTSA-regulated facility owner or operator to share the current FVA with the port authority and State and local law enforcement agencies during the regularly scheduled 5-year re-submission process of the Facility Security Plan (FSP).

Security System Integration

The Coast Guard is considering four options for fulfilling the security system integration requirements of the mandate:
• Require each MTSA-regulated facility owner or operator to have and demonstrate via annual exercises the ability to provide manual alerts regarding a transportation security incident (TSI) to appropriate State and local law enforcement agencies and the Coast Guard.
• Require each MTSA-regulated facility owner or operator to have and demonstrate via annual exercises the ability to provide automated alerts regarding a TSI to appropriate State and local law enforcement agencies and the Coast Guard.
• Require each MTSA-regulated facility owner or operator to make security data feeds regarding a TSI (e.g., alerts, video feeds, alarms, etc.) available to appropriate State and local law enforcement agencies and the Coast Guard.
• Require each MTSA-regulated facility owner or operator to incorporate a technological solution that integrates their electronic surveillance and communications systems with compatible systems operated or maintained by the appropriate State and local law enforcement agencies and the Coast Guard.

Request for Comments

The Coast Guard is actively looking for input on these potential methods of meeting the Congressional mandate. The notice provides a series of specific questions that they are specifically looking to have answered. Additionally they are looking for comments on the feasibility, costs, and benefits of each of the preliminary alternatives described above.
Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2012-0907). Comments should be submitted by May 2, 2013.
 
/* Use this with templates/template-twocol.html */