Saturday, July 6, 2013

STB Announces RSTAC Vacancies

The Surface Transportation Board (STB) published an advisory council vacancy notice in Monday’s Federal Register (78 FR 40823-40824; available on-line today). The notice announces two vacancies on the Railroad-Shipper Transportation Advisory Council (RSTAC) one for an at-large (public interest representative) and one for a large shipper representative. According to the notice; “RSTAC focuses on issues of importance to small shippers and small railroads, including car supply, rates, competition, and procedures for addressing claims).


The STB is soliciting suggestions for people to be appointed to fill these vacancies. The notice contains the necessary qualifications and requirements for the positions. Suggestions should be submitted via the STB’s E-Filing link (http://www.stb.dot.gov). Submissions need to be made by July 31st, 2013.

NIST Cybersecurity Framework Update – 07-06-13

This week NIST updated their proposed draft for the Cybersecurity Framework that will be the focus of the upcoming Cybersecurity Workshop (#3) in San Diego. The changes came just about a week after the original draft was posted.

The changes are mostly word-smithing; the most common change is replacing ‘cyber risk’ with ‘cybersecurity risk’. The change in wording seems to be relatively minor but they almost certainly reflect some serious political responses to the first draft.  The fact that NIST responded with changes so quickly (a one-week turnaround is unheard of) indicates the level at which those responses occurred.


I am not sure which bothers me more at this point; the fact that there is already this level of political interference into what should be a mainly technical discussion at this point, or that the leadership at NIST so badly read the politics of this process that they didn’t vet this document with the White House before issuing it. Both of these bode ill for the further development of a useful Cybersecurity Framework.

ICS-CERT Publishes Two Advisories

Back on Wednesday (holiday delay) the DHS ICS-CERT published two advisories affecting products from Alstom Grid and Monroe Electronics. The Alstom Grid products are used to configure protective relays sold by that company. The Monroe Electronics products are used to broadcast Emergency Alert System (EAS) messages.

Alstom Grid

This advisory concerns a self-reported improper authorization vulnerability in their MicCOM S1 Agile Software and older MiCOM S1 Studio Software (Versions of MiCom S1 Studio software from other vendors are not addressed in this advisory). This vulnerability is not remotely exploitable and requires local access action by an authorized user. The vulnerability does allow for privilege escalation.

ICS-CERT reports that Alstom Grid has released an updated version of the software that mitigates the problem. Since the vulnerability is self-reported so is the efficacy of the mitigation.

Monroe Electronics

This advisory reflects an SSH Key vulnerability reported by Mike Davis, a researcher with IOActive, in a coordinated disclosure. It affects the DASDEC-I and DASDEC-II products. It allows a moderately skilled attack to gain remote ‘root access’ to the system, allowing complete control of the system.

ICS-CERT reports that Monroe Electronics has produced a software update that mitigates this vulnerability. It does not report whether or not Mike Davis or IOActive have verified the efficacy of the update.

Expanding ICS

Both of these products are specialized control system applications that are used in relatively limited systems. Both, of course, have the capability to affect operations well outside of their control domain. There are probably thousands of these limited use control systems in use. I would bet that because the organizations producing them do not have large software development shops that there concerns with security programing are relatively limited.


I suppose that it is a sign of the increased interest in ICS security that vulnerabilities in limited application systems like these are starting to be addressed by security researchers. It is especially heartening in this instance to see a Alstom Grid self-reporting their vulnerability. That they detected it in-house is a good sign in and of itself. That they reported it to ICS-CERT is always a good thing.

Thursday, July 4, 2013

Unified Agenda – Spring 2013 – Published

Yesterday the Office of Management and Budget posted the Spring 2013 Unified Agenda on their Reginfo.gov web site. This includes the individual agency lists of rule makings that are planned and/or in various stages of completion. It includes links to the ‘Current Long Term Actions’ list of rulemakings that are under consideration.

DHS Rulemakings

Table 1 below shows the current list of DHS rulemakings on the Unified Agenda that will be of specific interest to the chemical safety and security communities. Chemical safety is not normally considered an DHS concern, but it is one of the missions of the Coast Guard so some chemical safety rulemakings are included on the DHS list.

OS
Final Rule
Ammonium Nitrate Security Program
OS
Final Rule
Classified National Security Information
USCG
NPRM
Updates to Maritime Security
USCG
Final Rule
Transportation Worker Identification Credential (TWIC); Card Reader Requirements
USCG
Final Rule
Bulk Packaging To Allow for Transfer of Hazardous Liquid Cargoes
USCG
Final Rule
Revision to Transportation Worker Identification Credential (TWIC) Requirements for Mariners
USCG
Final Rule
2012 Liquid Chemical Categorization Updates
TSA
NPRM
General Aviation Security and Other Aircraft Operator Security
TSA
NPRM
Security Training for Surface Mode Employees
TSA
NPRM
Freight Railroads and Passenger Railroads--Vulnerability Assessment and Security Plan
TSA
NPRM
Standardized Vetting, Adjudication, and Redress Services
Table 1: Current DHS Chemical Safety/Security Rulemakings

Comparing this latest Unified Agenda with the previous version published last December there are no major deletions or additions on the list of regulatory actions that the chemical safety/security communities will be specifically interested in on the DHS list (I’ll take a quick look at DOT and EPA lists in a separate post). The TWIC Card Reader rule did move into the ‘Final Rule’ category since the NPRM for that rulemaking has been published.

It hasn’t really struck me until today, but there are no cybersecurity specific rule makings on the DHS list.

There was some movement from the long term actions list to the current Unified Agenda, those items have been marked in BOLD in the table above.

The only changes within the rulemaking plans for these items are changes to the expected dates of the next action. The dates included in the Unified Agenda are, at best, hopeful guesses and the further they are in the future the less accurate they become.

In fact, the only date provided for the rulemaking activities listed above that is worth discussing is the July 2013 date for the Bulk Packaging To Allow for Transfer of Hazardous Liquid Cargoes rulemaking by the Coast Guard. The NPRM was published last year and the ‘expected date’ for the Final Rule is this month. If it is published by the end of July I will be surprised and I will be disappointed if it isn’t published by the end of September.

Long Term Actions

The Long Term Actions list is shown in table 2 below. There are no new additions to this list.

USCG
Top Screen Information Collection From MTSA-Regulated Facilities Handling Chemicals
TSA
Protection of Sensitive Security Information (SSI)
TSA
Drivers Licensed by Canada or Mexico Transporting Hazardous Materials To and Within the United States
Table 2: Long Term Actions

The last two items in the table already have interim final rules in place and just require TSA to respond to comments filed on that action and update the rule. The interim final rules date back to 2004 and 2006 and there is no incentive for TSA to take any action to ‘complete’ these rulemakings.

The Coast Guard Top-Screen for MTSA facilities rule is a slightly different story. This was initiated as part of a congressionally mandated harmonization of the chemical security rules under CFATS and MTSA and keeps moving back and forth between the Unified Agenda and the Long Term Actions list. I doubt that any action will ever be taken on this unless there is an attack on a chemical facility covered by MTSA.


BTW: The Pending DHS Security Rules page on this blog has not been updated in a while; it is hard to get motivated to update it since DHS is SOOOOO slow in moving their rules along. The Obama Administration’s resumption of periodically publishing the Unified Agenda will provide the needed impetus for getting that page updated.

Tuesday, July 2, 2013

DHS ITF IdeaScale Cybersecurity Project – CI Registration

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier post in this series was:


Earlier today the IdeaScale people moved my Friday idea submission from submitted to posted. This idea is based upon the ICS-CERT story about pipeline booster station attacks earlier this year. Unless you are signed up for the US-CERT restricted portal and logged in with the Control Systems Compartment there, you still would not have access to the list of the IPs involved in that attack. I have long recommended that facility security managers and cybersecurity managers should sign up with both the US-CERT secure portal and with Homeland Security Information Network. These should both be useable sources of sensitive but not classified intelligence information of interest to security managers.

The IdeaScale posting puts that recommendation into another venue and suggest that participation in the US-CERT site should be mandatory for facilities identified as high-risk critical infrastructure facilities under the President’s cybersecurity Executive Order (EO 1336).

Issues Discussion

I have had some interesting feedback on the ideas that I have submitted to date on the DHS ITF IdeaScale Cybersecurity Project. That is what I like about contributing to these IdeaScale projects; ideas can get discussed in a public venue with input from a wide variety of personnel with different backgrounds and experiences. Anyone can put forward an idea, and everyone can respond to that idea in a public venue that can engender further input.


Once again, I would like to take the opportunity to urge everyone to visit this IdeaScale site and put in your two cents worth. If you have no more time available than to read a couple of the ideas that catch your fancy, please vote on whether or not you thing the idea has merit. If you have more time available, contribute a comment like Richard did; it will add to the discussion. But better yet, put one of your ideas down on paper and then post it to the site for others to read, vote upon and discuss. Be a real contributor to the development of national policy.

S 1243 Introduced – FT 2014 DOT Spending

As I mentioned in an earlier post Sen. Murray (D,WA) introduced S 1243, the Transportation, Housing and Urban Development, and Related Agencies Appropriations Act, 2014. This bill does not actually include any specific chemical safety or cybersecurity (beyond Department IT cybersecurity spending) provisions. The Senate Appropriations Committee report does, however, include hazmat transportation safety provisions and limited cybersecurity provisions.

Cybersecurity

The Report accompanying this bill briefly addresses a unique set of control system security concerns. First the report notes that 77% of the Department’s cybersecurity budget (or $105 million) is directed to the budget of the Federal Aviation Administration. The Report then goes on to note that two separate DOT IG reports indicate “the FAA had not adequately implemented security requirements for its Automatic Dependent Surveillance-Broadcast System” (pg 33) or its En Route Automation Modernization System. The report concludes that the Committee “expects the Vice President of [FAA] Program Management to coordinate with the CIO for the FAA and for the Department to ensure the security of FAA’s systems is made a high priority”

PHMSA Spending

The spending bill provides modest increases in funding for PHMSA programs. Both the Pipeline Safety Fund and the HAZMAT show increases over the pre-sequester FY 2013 spending, but the HAZMAT program is slightly less than requested by the President. The President continues to propose a HAZMAT special permit fee in his budget, but “the Committee believes that such a fee should be established through the regulatory process or should be addressed through the authorization process” (pgs 90-1) and does not include that in the bill.

Moving Forward

Because of Constitutional limitations, this bill will probably not be brought up until the House passes their version of the bill at which time the Senate would typically substitute this language for the House wording, pass the bill (probably with a number of amendments) and then go to conference to iron out the differences.

In recent years this bill is usually folded into the Omnibus spending bill because Congress has been unable to pass all 13 of the individual appropriations bills before the end of the fiscal year on September 30th. I suspect that that will occur this year as well.

CFATS Knowledge Center Update – 07-01-13

Yesterday the folks at ISCD updated their CFATS Knowledge Center web site by adding two new frequently asked questions and their responses. Both questions/responses deal with the appropriate method of handling when a covered facility makes material modifications to its operations or site.

The ‘Latest News’ section of the page notes that the “Department has clarified and updated responses to two FAQs”; FAQ 1614 and 1663. This is not quite accurate since neither FAQ show up in the “CFATS Knowledge Center Issues” copied from the site on 6-24-13, the date of the previous FAQ revision. It would have been more appropriate to describe the situation as DHS has clarified the requirements for dealing with Security Vulnerability Assessments (SVA) and Site Security Plans (SSP) when the facility has made material modifications to their operations or site by adding two new FAQ and their responses.

SVA or SSP Requirements Continue

When a facility makes a material modification while it has either an SVA or SSP deadline pending, it should continue preparing the appropriate documents as if no material modifications had been made. Within 60-days of making the material modification {as outlined in 6 CFR §27.210(d)} the facility must submit a revised Top Screen and ISCD will determine if modifications need to be made to either the SVA or the SSP. The new notification letter will provide the facility with a new deadline for making the indicated changes.

Removing COI

For a couple of years now ISCD has been promising to provide guidance on what a facility needs to do to document the removal of a DHS chemical of interest (COI) from a facility. Since over 3,000 facilities have removed, reduced or modified COI holdings according to the latest (June 2013) CFATS Fact Sheet, it is about time for this guidance to be made available.

According to both of today’s new FAQ responses, “, the facility should provide supporting documentation to the Department, to include the following, as applicable:

• “Reason for the revised Top-Screen submission;
• “Description of removal of COI(s) (e.g., sold to customers, used in process, returned to vendor);
• “Receiving location(s) of COI(s);
• “Documentation for permanent change of process;
• “Documentation supporting closure/sale/end of lease;
• “Invoices/bills of lading/inventory control forms: Material Safety Data Sheet (MSDS)/product labels, planned future inventory of COI(s);
• “Substitute chemical and/or process;
• “Description of management controls for future quantities of COI(s); and,
• “Vendor information.

Both responses state that such information should be provided to the CFATS Help Desk (866) 323-2957, Fax (866) 731-2728, EMAIL: csat@dhs.gov. There should be a friendly reminder here that the submitted data should be protected and transmitted as Chemical-terrorism Vulnerability Information (CVI). It would be nice if there were a CSAT tool for making this submission so that the facility would not find it necessary to email or snail mail CVI material.


BTW: I have complained of late about ISCD making changes to FAQs and their responses and not providing clear notification that such changes have been made. I would like to reiterate that ISCD has made such notification in this case.
 
/* Use this with templates/template-twocol.html */