Monday, February 3, 2014

HR 1791 Passed in House

This evening, as expected, the House passed HR 1791, the Medical Preparedness Allowable Use Act, by a bipartisan vote of 391 to 2. The debate lasted all of three minutes.

The bill would allow grant monies under the Urban Area Security Initiative and State Homeland Security Grant Program to be used for enhancing medical preparedness, medical surge capacity, and mass prophylaxis capabilities to respond to chemical or biological incidents.


The bill will almost certainly pass in the Senate, where it will probably receive even less debate as it is considered under unanimous consent provisions.

Congressional Hearings – Week of 2-2-14

This week with both the House and Senate in session again, there will be two hearings held that might be of specific interest to readers of this blog; a hearing on the Coast Guard homeland security mission and a markup of cybersecurity legislation.

Coast Guard

On Tuesday the Border and Maritime Security Subcommittee of the House Homeland Security Committee will hold a hearing on the “Future of the Homeland Security Missions of the Coast Guard.” The only witness currently scheduled will be the Commandant, Admiral Papp. MTSA issues may certainly be raised.

Cybersecurity Legislation

On Wednesday, the House Homeland Security Committee will be holding a markup hearing of the Chairman’s cybersecurity bill, HR 3696. This is the bipartisan National Cybersecurity and Critical Infrastructure Protection Act of 2013 and it is looking increasingly like it may have a good chance of passage this year. The Committee will consider substitute language that I haven’t yet had a chance to review.

On the Floor

Not much happening in the House this week. HR 1791 is being considered today. It is an emergency response grant bill that will certainly pass with broad bipartisan support.


The Senate will be finishing up their consideration of HR 2642, the Agriculture authorization bill.

CFATS Knowledge Center Update – 02-03-14

Today the folks at DHS Infrastructure Security Compliance Division (ISCD) updated their CFATS Knowledge Center web site. They added a brief note in the ‘Latest News’ section of the page about today’s publication in the Federal Register of the 30-day ICR notice for the CFATS Personnel Surety Program (PSP). That note included a link to the Federal Register notice.

In addition, the ‘Document’ section of the Knowledge Center now includes a link to a Fact Sheet concerning the 30-day ICR notice. That fact sheet provides a brief description of the CFATS requirements for a PSP and the options facilities will have to complete the Terrorist Screen Database vetting of their personnel and visitors.

Still in the ‘Document’ section are links to:


Sunday, February 2, 2014

30 Day CFATS PSP ICR – Three Options

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


Scope of the PSP

Risk-Based Performance Standard 12 {6 CFR §27.230(12)} outlines the general requirements for a personnel surety program for personnel. It requires that CFATS covered facilities:

“Perform appropriate background checks on and ensure appropriate credentials for facility personnel, and as appropriate, for unescorted visitors with access to restricted areas or critical assets,”

Most of the background checks listed in the subsequent subparagraphs are conducted by the facility through a variety of governmental and non-governmental agencies. Facilities have a great deal of leeway about the scope of such checks and what negative information will be disqualifying information for determining which individuals will be employed at the facility or which visitors will be provided unescorted access to critical or sensitive areas of the facility.

The background check requirements of §27.230(12)(iv); “Measures designed to identify people with terrorist ties” require access to the Terrorist Screening Database (TSDB) maintained by the FBI. Vetting against that database is described in this ICR as an “inherently governmental function” which requires action by DHS. This ICR describes how individual facilities will initiate such action.

The Options

This ICR provides a description of the three options that DHS has currently designed for fulfilling the facility portion of the requirements for the TSDB vetting. Two of those options require submission of information by the facility; the third utilizes TWIC readers to verify that information on an individual has already been submitted and vetted against the TSDB. The notice continues to maintain that ISCD will consider, on a case by case basis, alternative methods for vetting against the TSDB that facilities might propose in their Site Security Plan (SSP) or Alternative Security Plan (ASP).

The two data submission options would require facilities to submit specific personally identifiable information (PII) to the DHS Infrastructure Security Compliance Division (ISCD) via a new on-line PSP tool within the current Chemical Security Assessment Tool (CSAT). Data submission could be done through either manual entry of individual’s information, submission of an Excel file containing information on multiple individuals, or the Department may allow the submission of the information through a Web-service (a software system designed to support interoperable machine-to-machine interaction over a network).

The first option is direct vetting of individuals. DHS would take PII provided by the facility through the PSP tool and submit it to the FBI’s Terrorist Screening Center for comparison to the TSDB. Periodically, ISCD would re-submit the same information to determine if an previously vetted individual has been added to the TSDB. This re-vetting would require no action by the facility. There is nothing in the ICR which identifies the frequency of the re-vetting process.

The second option allows DHS to use a slightly different set of PII provided by the facility to verify that other DHS agencies have already vetted the individual against the TSDB. The accepted programs already periodically re-vet against the TSDB (this is a DHS ‘best practice’) so ISCD would be able to periodically (again no definition of the period in ‘periodically’ is provided) re-validate the TSDB status of the individuals by re-checking with the issuing agency. There is no real need to define periodically here since it is purely an internal matter and does not require any action by facility owners or operators.

Presumably ISCD will continue to use TSA to conduct the actual check of the TSDB. Since TSA is charged with recovering the costs of their ‘security assessments’, they will ‘charge’ ISCD for each check of the TSDB that they conduct (I seem to remember hearing that ISCD was already ‘paying’ for this service, but I haven’t been able to track down a source for that information). Checking DHS records for the current status of other security vetting’s will not cost ISCD anything (or possibly just much less).

For facilities, there is no practical difference between option 1 and option 2. They are still required to have information (with minimal differences it the information) submitted to ISCD. They will either do it themselves, or will pay to have a third party do it for them.

There is one DHS vetting program that gets special treatment in the CFATS PSP; the TWIC card. The Department is requiring records checks of the other programs because there is no way to visually verify if the covered identity document is current and/or real. The TWIC, via a TWIC reader can be so confirmed. In the third option, the facility would not have to submit information to the CFATS PSP tool for individuals “if the high-risk chemical facility (or others acting on their behalf) electronically verify and validate the affected individuals' TWICs through the use of TWIC readers (or other technology that is periodically updated using the with revoked card information).” Presumably the last comment refers to either the Canceled Card List (CCL) or the Certificate Revocation List (CRL).

Responses to Comments about Options

There were two comments that suggested alternative methods for vetting personnel that were not employees or contractor employees. NPPD responded that the two suggested methods were outside the scope of the current ICR and implied that they would require a rulemaking to implement.

There was a comment that the proposed options in the 60-day notice did not follow recommendation #16 of the Surface Transportation Security Priority Assessment concerning the reciprocal use of various security threat assessment information. NPPD responded that “the Department has defined, and continues to define, the “enroll once, use many” concept as the ability to reuse previously submitted program enrollment information and/or vetting results upon collection of sufficient information to confirm an individual's prior enrollment in a Department program or prior vetting results”.

There were several comments to the effect that the data submission requirements for the second option actually constituted a second background check. As I noted above, ISCD would not use the provided information to conduct an actual check of the TSDB, but rather to verify a current and valid vetting under the other DHS program.

There was a similar response to comments that Option 2 violated the ‘no additional background check’ requirement of violates 49 U.S.C. 5103a(g)(1)(B)(i) [Note the link in the ICR notice went to §5103 instead of §5103a]. NPPD reiterated that no additional background checks were being done; ISCD was using the information to verify that a claimed vetting document was current. This is being done not only to prevent the use of revoked documents, but also counterfeit documents.

The Details

Once the 30-day ICR is approved by OMB’s Office of Information and Regulatory Affairs (OIRA), we can expect to see ISCD introduce the PSP tool in CFATS. They will publish at least one User’s Manual for the PSP and we can expect to see a new revision of the CSAT Registration manual to reflect the use of outside agencies for the submission of PSP data.

I expect that the actual PSP tool will be a relatively simple tool with a typical CSAT fill in the blanks type format. The ICR notice makes it clear that there will be provisions for uploading MS Excel files or XML files for bulk submissions to the system. The site will either specify the column format or will provide a template for the file (I would bet on the later).

The registration manual revision will be a completely different story. With DHS pushing hard for the use of contract organizations to submit employee data and thousands of vendors who will need to get their employees vetted (frequently for more than one facility) the registration problems look to be really complicated. I would bet that DHS will set up a separate registration program for organizations other than chemical facilities and then provide some method for covered chemical facilities to link their PSP tool to those organizations.


While the ICR notice makes it clear that employee vetting information is not Chemical-Terrorism Vulnerability Information (CVI), under current rules the fact that a facility is considered to be a CFATS covered facility is CVI. I expect that ISCD will relax that particular provision.

Internet of Things and Cybersecurity

There is an interesting blog post over at ThoghtFest.co.uk about how vulnerabilities in the ‘internet of things’ may impact cybersecurity operations. The author, Bob Griffin, the Chief Security Architect at RSA, uses recent reports about a ‘smart’ refrigerator being used in an DOS attack to take a brief look at how we are going about security critical infrastructure.

Bob makes the point that while it is sad that the embedded processor in the refrigerator is vulnerable to attack and subsequent use as a message source during a DOS attack, it does not really make that refrigerator a cyber threat. Instead, it would seem that it would be more profitable for a security manager to focus on how his networked items respond to such an attack. If his network is properly and adequately protected then a rogue refrigerator is no more of a threat that a script kiddie with an old computer and slow modem.

The time spent responding to the ever increasing number of vulnerabilities, and particularly the vulnerabilities being discovered in industrial controls systems, will detract from the real core security problem here; the detection and response on assaults on our systems. Regardless how good our security teams are, something is going to get through the security perimeter and assault our systems. Attackers only have to get it right one time while the defense only has to fumble one attack to fail.

The fight to improve system design and reduce device vulnerability, must of course continue on. But system administrators and owners need to concentrate on understanding their systems and being able to spot anomalous behavior and traffic. Then they must have the tools available to isolate the problem and then remediate it. Only then will we be able to really discuss system security and resiliency.

Saturday, February 1, 2014

30 Day CFATS PSP ICR Published

The DHS National Protection and Programs Directorate (NPPD) published a 30-day information collection request (ICR) notice in Monday’s Federal Register (79 FR 6417-6452) for the long overdue personnel surety program (PSP) for the Chemical Facility Anti-Terrorism Standards (CFATS) program. The ICR lays out at great length (35 Federal Register pages) how facilities would be expected to vet their employees, contractors, and visitors for unaccompanied access to security critical areas at high-risk chemical facilities regulated under CFATS.

NPPD’s Infrastructure Security Compliance Division (ISCD) expects that facilities will use one or more of three basic options for vetting personnel against the Department’s Terrorist Screening Database (TSDB):

Option 1 – Direct vetting

These options are essentially the same ones that were included in the earlier 60-day ICR notice, but the devil is in the details. Included in the ICR discussion are responses to the 28 comments that had been received on the earlier notice. Those ISCD responses include why they have adopted or rejected the changes suggested by the commentor.

As I did with the earlier ICR notice, I will be taking a detailed look at the provisions of the revised program in a series of blog posts.

Public Comments Solicited

As with all 30-day ICR notices public comments are being solicited. While they may be sent directly to the OMB’s Office of Information and Regulatory Affairs (OIRA), NPPD has made provisions for submission through the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0061). Comments should be submitted by March 5, 2014.

Moving Forward

The publication of a 30-day ICR notice on a new information collection program usually means that the program is nearing implementation; typically going on line in three to four months. For controversial programs the delays can be quite lengthy and the most controversial plans frequently die here, still born. While the CFATS program clearly needs a viable PSP, it is unlikely that this ICR will move forward quickly.

CFATS Legislation Effects

Throwing a further potentially complicating factor into this process is the impending introduction of new CFATS legislation by Rep. McCaul, Chair of the House Homeland Security Committee. One of the components of this bill that I have been hearing rumors about is language addressing the personnel surety issue. Chairman McCaul has frequently chided ISCD Director Wulf for not making more use of the TWIC program for the CFATS PSP.

Of course, that bill would have to pass in both the House and Senate for it to have any legal effect on the CFATS PSP. But, the presence of a viable bill in the legislative process with a significantly different look at PSP might serve to delay consideration of this ICR at OIRA.


On the other hand, the reasons for the frequent delays in the introduction of McCaul’s bill may have been because he was waiting for this notice to be published because the bill explicitly provides legislative support for this program. In that case, if the bill were to move expeditiously through the legislative process (and it would have to come to a Senate vote before the summer recess to have much chance of passing in an election year), then OIRA’s review of this notice might be accelerated.

An Alternative to S 1961

Yesterday I wrote a blog post describing the provisions of the recently introduced S 1961, the Chemical Safety and Drinking Water Protection Act of 2014. As I made clear in that post, this bill is a typical knee jerk reaction from a politician to a public calamity. It is a response to a real problem, but it is inadequately thought through and a sure route to unintended consequences.

Of course, it is easy to criticize something, but it is not very helpful. I am going to try this year to be more pro-active in my responses to legislation that I object to and try to offer an alternative way to deal with the same problem. This post is an attempt to do that with S 1961.

The Problem

The incident in Charleston, WV clearly points out a potential problem for every water facility that uses surface waters for its facility intake. There have probably been thousands of similar chemical spills upstream of those facilities over the decades. The difference here was two-fold; first the water facility was not aware that its normal treatment system could not remove the offending chemical from the water; and two there was no existing standard by which to judge an ‘acceptable level of contamination’ for that chemical in a drinking water system. Any proper response to this incident needs to take those two circumstances into account.

Water treatment facilities, particularly those that use surface water, have a need to know what bulk chemicals are stored upstream of their intakes. They need to know which of those chemicals their intake treatment systems can remove from the water and which cannot be removed. For chemicals that cannot be removed from the intake water, the facilities have to have procedures and processes in place to stop those chemicals from entering the system.

Organizations that store bulk chemicals have a duty to ensure that those chemicals are properly and safely contained. Acknowledging that spills are going to happen, a realistic regulatory schema will require a more complete and effective response the more hazardous the chemical is or the larger the amount of the chemical that is stored on site. For a chemical that has no known toxicity and is stored in drums there is no need to burden a drinking water regulatory body with oversight responsibility for that chemical storage facility that can have no effect on the operation of drinking water treatment facilities.

Identify the Problem Tanks

A more effective regulatory scheme would have started with modifications to the current requirements in §300j-13 for source water assessments. It would have added a new sub-paragraph to §300j-13 requiring the identification of all bulk storage chemical tanks over a given size that could in a catastrophic accident result in the contents of the storage tank reaching the source water of the treatment plant within 24 hours of that accident.

Any facility holding such a tank would be covered by the requirements of a drinking water source protection act to report the contents of such tanks to the local water treatment facility. The drinking water treatment facility would determine which of those chemicals have been demonstrated to be removed by their existing water intake treatment system. Each facility would be informed of which of its holding of bulk chemicals is not capable of being removed from the intake water by the drinking water treatment facility. These would be designated as ‘chemicals that require drinking water protection’.

Have a Certified Professional Evaluate the Tank Design

The requirements of the proposed §1472 would be a good starting point for all bulk storage tank holding chemicals with such designation. Such tanks would be defined as ‘covered bulk storage tanks’. Paragraph (b)(2)(A) would be modified to combine the first three sub-paragraphs under a new paragraph (A) with which would read:

“(A) A requirement for a Professional Engineer to certify the design of each covered tank to include:
“(i) materials of construction;
“(ii) leak detection;
“(iii) overfill controls; and
“(iv) overflow controls on all outflows from the tank;

All of the remaining items in the current paragraph (A) would be combined in a subsequent paragraph (B). The current paragraph (B) and (C) would be renumbered and the words ‘covered bulk storage tank’ would be substituted for each instance of ‘covered chemical storage facility’. This would ensure that the chemicals that could have an adverse impact on a given water treatment facility would be required to meet minimum standards for spill prevention and response.

Establish Minimum Toxicity Testing Standards

The Administrator of the EPA, in conjunction with the Director of the CDC, would be required to develop minimum standards for toxicity testing of chemicals that require drinking water protection. In addition the Director of the CDC would be required to conduct a rulemaking that would establish an acceptable methodology for determining the maximum safe concentration of a chemical in drinking water from data produced in the minimum toxicity testing standards.

Each manufacturer of a chemical determined to be a chemical that requires drinking water protection would be responsible for testing the toxicity of that chemical using the established minimum testing standards. EPA would establish a grant program to help small chemical manufacturers fund such studies. The complete results of such studies would be forwarded to the EPA for peer review and subsequent determination of the maximum safe drinking water concentration for that chemical. The EPA would periodically publish any newly determined toxicity data and maximum safe drinking water concentrations, along with an accepted test method for detecting such chemicals at 10% of the maximum safe concentration in the Federal Register.

Conduct Incident Follow-up Health Monitoring

Finally, the CDC would be required to conduct long-term health studies of any population that was exposed to a chemical that requires drinking water protection due to accidental or deliberate release of such a chemical that subsequently contaminated a public water treatment facility’s output at concentrations between the chemical detection limit and the maximum safe drinking water concentration.

Addressing the Root Causes


This type of program would address the legitimate need to protect public treatment works from contamination by chemicals that they cannot remove from the water. It would also provide clear standards for determining the safe level of exposure to such chemicals in the event of an accident where such prevention standards did not work. And it would provide long-term verification that the protections being put into place actually protected the public.
 
/* Use this with templates/template-twocol.html */