Monday, February 11, 2013

Reader Comment – 02-11-13 – Sharing with Medical Community


This morning Stu Fischbeck left a comment on my blog post from Friday about the introduction of S 242. This was the bill that reauthorized some public health and medical emergency response programs. I suggested that the bill ought to include language requiring facilities with significant amounts of toxic inhalation hazard (TIH) chemicals to provide MSDS to local medical facilities so that they could make appropriate plans for mass casualty operations in the event of a catastrophic leak. Stu asked:

“Do you have any data on how many in industry already coordinate with hospitals, FDs, local EMAs, etc.?”

Notifications are required to be made to local fire departments and local emergency planning committees (LEPC) for certain facilities under CERCLA. This should certainly cover the significant holders of TIH chemicals. Unfortunately LEPCs don’t exist everywhere and the ones that do vary widely in their efficacy.

As best I can tell there is no requirement for anyone to talk to the medical community about the potential treatment requirements for a mass casualty event due to a catastrophic event at a chemical facility.

Different toxic chemicals are going to require different treatment regimes. It seems to me that knowledge of the potential toxic agent in advance would allow the local medical community to do some advance preparation for the required treatment. At the very least the triage personnel are going to have to know what symptoms to look for to separate the chemical casualties from the other related injuries.

Stu makes a valid point. There are almost certainly folks that are already doing this, but from the limited number of conversations that I have had and the news reports that I have seen related to actual incidents there seems to be little to indicate that this is anything but a minority. This isn’t out of any evil intent; too many people think that doctors can recognize the source of all ailments and treat them appropriately with the material on hand. If they can’t we simply sue them for malpractice.

Most doctors have little or no experience dealing with gross exposures to toxic chemicals. Even if they do have some specific experience it is not likely to be on the chemical in question for a particular release; those releases come too far and in between for much of an experience base to have been acquired. That combined with the special equipment and drugs that may be necessary to treat the casualties means that prior planning is an absolute requirement for an effective response to this type of situation.

While this probably should have been included in the CERCLA regulations, it is certainly time to correct the oversight. I think this legislation is a good point to go back and add it to the EPA regulations as it directly effects public health measures and planning that should be done prior to a terrorist attack or a terrible accident that results in a large release of toxic chemicals.

Sunday, February 10, 2013

Privacy and the WWW


There is an interesting piece by Simon Sharwood over on TheRegister.CO.UK about the fufrah about social media tracking software being marketed by Raytheon. It seems that people are becoming afraid that the Gubmint is listening to what we say on the internet and keeping track of it all. Golly gosh, who’d of thought?

If you stand on a soap box in the park and shout all day long, you have no right to complain that someone listened to what you said. The whole point of standing on that soap box and yelling is to get attention. If they pay attention, be proud; you’ve accomplished what you’ve set out to do. Don’t complain if they keep track of what you say, say it again to make sure they got it right.

If you are afraid of what the Gubmint might think about what you have to say, don’t say it where the Gubmint might listen. Say it softly in your shower late at night with the radio playing loud. Cower in the dark, afraid of the light. Just don’t complain when no one listens because they can’t hear you.

The strongest, bravest thing that a person can do is to stand out in the bright sunshine and speak the truth as you see it. Proclaim to the world what is wrong and how to correct it. You might not have any success in changing things, but at least you will have tried. The people that don’t try will never change anything.

So Raytheon, Google and the rest watch closely what I say. Spread the word far and wide; just get the URL correct. People in the Gubmint, read my words often, discuss what I think, consider what I propose. I DARE YOU.

Congressional Hearings – Week of 2-10-11


While the focus this week will be on the President’s State of the Union speech, Congressional hearings will be taking place this week. There will be three organizational hearings for committees of interest in the Senate. There will also be three hearings addressing background issues that might impact future hearings and legislation; two in the House and one in the Senate.

Organizational Meetings

Three Senate committees will be holding short (scheduled for 30 minutes in two cases) organizational meetings this week. The committees are:


The most important thing that will come out of these meetings will be the listing of subcommittee chairs and members. This is all decided in advance, but the democratic trappings must be observed.

Sequestration Hearing

The Senate Appropriations Committee will be holding a hearing on Valentine’s Day looking at sequestration issues. There will be much wailing and gnashing of teeth about the devastating effects of sequestration on the Federal government. Among the dire prognosticators will be Secretary Napolitano. I doubt if CFATS or computer security will receive special mention, but you can never tell.

Threats to the Homeland

The House Homeland Security Committee will be holding a hearing on Wednesday that will look at a “New Perspective on Threats to the Homeland”. I expect that we will be hearing more about al Qaeda in Africa and homegrown threats and perhaps cyber-threats. The witnesses will all be from the civilian sector, so the testimony will all be unclassified and more openly opinionated. The witnesses include:

• Admiral Thad Allen, Senior Vice President, Booz Allen Hamilton
• Mr. Shawn Henry, President, CrowdStrike Services
• Mr. Michael Leiter, Senior Counselor, Palantir Technologies
• Hon. David M. Walker, Founder and CEO, The Comeback America Initiative
• Mr. Clark Kent Ervin, Partner, Patton Boggs, LLP

Infrastructure

The House Transportation Committee will also meet on Wednesday. They will be looking at the “Federal Role in America’s Infrastructure”. Topics of interest are sure to include maintaining, replacing and securing that infrastructure. Again, they will all be private sector witnesses, but it looks like they will have a slightly more diverse background. They will include:

• Thomas J. Donohue, President and CEO, U.S. Chamber of Commerce
• Edward G. Rendell, Co-Chair, Building America’s Future, and former Pennsylvania Governor
• Terry O’Sullivan, General President, Laborers’ International Union of North America

On the Floor

There is nothing currently on the agenda for the coming week on the floor of either the House or Senate that looks to be of particular interest to the chemical security or cybersecurity communities. The Collinsville Renewable Energy Promotion Act (HR 316) will be coming up in the House under suspension of the rules so there will be no amendments, little debate, and it will probably pass. This bill restores and extends federal permits to construct two hydropower facilities in Connecticut. Nothing of interest here, you can move along.

Friday, February 8, 2013

Chemical Defense Project ICR


Today the DHS Office of Health Affairs published a 60-day information collection request (ICR) notice in the Federal Register (78 FR 9405) for a new ICR to support a program mentioned in the 2012 spending bill (HR 2055, PL 112-74) Conference Report, the Chemical Defense Program.

Chemical Defense Program

According to congressional testimony by Testimony of Alexander G. Garza, MD, MPH, Assistant Secretary for Health Affairs and Chief Medical Officer 

“OHA’s Chemical Defense Program (CDP) provides health and medical expertise related to chemical preparedness, detection, response, and resilience—all critical to a comprehensive approach to protect against a chemical attack. Technologies and operations already employed at the federal, state and local level are being leveraged to create a comprehensive chemical defense framework. The chemical defense framework will create synergies and efficiencies among the many ongoing, but currently separate, chemical defense efforts. This framework will integrate DHS’s current capabilities as well as strengthen relationships both horizontally and vertically amongst all federal, state, local and tribal chemical defense stakeholders.”

The ICR

The ICR would allow the Office of Health Affairs (OHA) to collect data from “respondents interested in hosting a demonstration project aimed at developing a comprehensive chemical defense framework”. The information collected would include:

• Name of state, local, tribal, or territorial government agency;
• Address; submitter's name, position and contact information;
• Identified venue for demonstration project;
• Interest in developing a chemical defense capability;
• Specific reasons for the communities interest and needs for a chemical defense capability;
• Community chemical threat assessed risks if applicable; and
• Any additional information respondent requests for consideration

An example of the types of projects that would be considered for this program would be the recent Baltimore, MD study of chemical agent dispersion in subways.

Public Comments

The OHA is soliciting public comments on this ICR. Comments may be submitted to CAPT Joselito Ignacio (joselito.ignacio@hq.dhs.gov, or 202-254-5738). Comments should be submitted by April 9th, 2013.

It is a shame to see that OHA is not utilizing the Federal eRulemaking Portal for the collection of these comments. The current procedure does not allow for full public viewing of comments submitted. This adds an appearance of secrecy that is unnecessary in this process.

Suggested Project

There is one project in particular that I would be very interested in seeing a local emergency planning committee undertake under this program. It would be to establish a communications protocol between chemical facilities in an area that have significant amounts of toxic inhalation chemicals on hand and local medical treatment facilities so that those facilities would be able to prepare in advance for mass casualty events related to the release, accidental or otherwise, of such chemicals. An evaluation of the lessons learned from such a program would be very instructional for other similarly affected communities and the regulatory community. Houston, TX, Charleston, WV or Louisville, KY would be excellent communities in which this project could be done.

Bills Introduced 02-07-13


Yesterday, with only the Senate in session (the House was only in town for a short week) there were 38 pieces of legislation introduced. One of those was of potential interest to readers of this blog; S 242, bill to reauthorize certain programs under the Public Health Service Act and the Federal Food, Drug, and Cosmetic Act with respect to public health security and all-hazards preparedness and response, and for other purposes. This bill was introduced by Sen. Burr (R,NC).

This bill looks like it may be similar to HR 307, the Pandemic and All-Hazards Preparedness Reauthorization Act of 2013, that was passed last month in the House.  It would make little sense to introduce a companion bill when the House bill has already been referred to the Senate, so this may include some alternative language. Still that could have been handled with an amendment to the House bill, so we will have to wait and see what the bill actually says when it is published by the GPO.

Again, I would like to see it include a requirement for high-risk chemical facilities to notify local health agencies and hospitals of significant quantities of toxic inhalation chemicals used at those facilities so that there medical response community could be properly prepared for a mass casualty event if there were a large release of such materials either due to an accidental release or a terrorist attack.

Wednesday, February 6, 2013

Congressional Bills Introduced – 02-05-13


There was one bill introduced in the House yesterday that would seem to be of potential interest to readers of this blog; HR 508, a bill to extend the Terrorism Risk Insurance Program for five years. The original TRIA bill was introduced in 2002. The Department of the Treasury program is administered under 31 CFR Part 50. It will be interesting to see what provisions of this would be changed by this bill.

ICS-CERT Updates CSET


Thanks to a Tweet® from ICS-CERT we know that DHS has updated their Cyber Security Evaluation Tool (CSET) to version 5.0. Because of the recent revision to the ICS-CERT web site and the CSET web page in particular it is not possible to tell what version of CSET is actually available from that site. Even more confusing is the fact that the URL for the CSET factsheet (http://ics-cert.us-cert.gov/pdf/DHS_CyberSecurity_CSSP-CSET-v4.pdf) seems to indicate that it is for version 4.

CSET Fact Sheet

I wrote about the upgrade to version 4.1 just a little over a year ago. The fact sheet has certainly been revised in format, but I don’t really see any new information on the new fact sheet about the CSET. There is some new information provided about the experiences of the Control System Security Program (CSSP) teams experiences assisting facilities in completing the CSET. It notes:

“The CSSP team observed that the most common vulnerabilities identified through CSET self-assessments were a lack of adequate control system inventories and formal documentation; no audit capabilities and accountability for event monitoring; and missing permissions, privileges, and access control restrictions. Other categories of vulnerabilities included improper authentication and credentials management practices, flaws in network architecture designs, configuration (implementation) settings within network components, and traceability on cybersecurity configuration and maintenance.”

Onsite Consultation

There is a link to a new document on the CSET web page; Onsite Consultation and Self-Assessment. As in the past facility management has the option of conducting a self-assessment of their control system (and IT systems) using either the downloadable version of CSET or a CD version (send an email to: CSET@hq.dhs.gov) of the tool or the facility can request an onsite CSSP team visit to assist in the CSET evaluation (certainly my recommended procedure). There is a new assessment that is mentioned on this new document; the Tier 2 Network Architecture Review (with the previously mentioned CSET evaluation being the Tier 1 assessment). It is described this way:

“The Tier 2 assessment, like Tier 1, is conducted onsite by the asset owners with the support of  CSSP cybersecurity professionals. However, the Tier 2 consultation provides a more robust evaluation of system interdependencies, vulnerabilities, and mitigation options. This consultation typically requires additional rigor and technical staff and often takes two to three days to complete.”

It is recommended for “most high-security control systems, such as chemical, power and nuclear plants, telecommunications facilities, government facilities, schools, hospitals, and other high-value infrastructure assets”.

Recommendation

As I have mentioned in past posts about the CSET, I have not seen a memorandum of understanding between ISCD and ICS-CERT about any cooperation between those two agencies on cybersecurity requirements under CFATS. Without such an agreement there is no way that the completion of CSET and implementing its suggested security improvements is any guarantee of meeting the RBPS 8 requirements of CFATS.

Having said that, I think that documenting a CSET evaluation, particularly one with an onsite CSSP team involvement, and successfully implementing its recommendations, will go a long way to helping a facility meet the RBPS requirements.

BTW: If anyone at ICS-CERT would like to describe the differences between CSET version 4.1 and 5.0 I would be happy to provide blog space for that description.
 
/* Use this with templates/template-twocol.html */