Monday, April 4, 2016

Congressional Hearings – Week of 4-4-16

The Senate is back in Washington this week from their Easter recess. While the House is just starting their last week they do have three hearings this week in local venues. Between the two houses there will be two hearings of potential specific interest to readers of this blog; both of them related to cybersecurity.

Local Cybersecurity


The Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee will be holding a hearing Thursday in Sherman, TX on "Cyber Preparedness and Response at the Local Level". There is no witness list available yet, so it is difficult to tell if any control system security issues will be raised.

Cyber Command



The Senate Armed Services Committee will hold a hearing on Tuesday on “United States Cyber Command in review of the Defense Authorization Request for Fiscal Year 2017”. The sole witness scheduled will be Admiral Rogers, Commander, United States Cyber Command. It will be interesting to see if there is any mention of either last December’s cyber-attack on the grid in Ukraine (or its implications for defending the homeland) or the recently reported attacks on either the (very) small dam in New York or the unnamed water system.

CG Sends TWIC Reader Final Rule to OMB

On Saturday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that the Coast Guard had submitted their final rule on Transportation Worker Identification Credential (TWIC); Card Reader Requirements (RIN: 1625-AB21) for review. The notice of proposed rulemaking for this action was published in March 2013.

The abstract for this rulemaking listed in the Fall 2015 Unified Agenda describes the rule this way:

“The Coast Guard is establishing electronic card reader requirements for maritime facilities and vessels to be used in combination with TSA's Transportation Worker Identification Credential (TWIC). Congress enacted several statutory requirements within the Security and Accountability for Every (SAFE) Port Act of 2006 to guide regulations pertaining to TWIC readers, including the need to evaluate TSA's final pilot program report as part of the TWIC reader rulemaking. During the rulemaking process, we will take into account the final pilot data and the various conditions in which TWIC readers may be employed. For example, we will consider the types of vessels and facilities that will use TWIC readers, locations of secure and restricted areas, operational constraints, and need for accessibility. Recordkeeping requirements, amendments to security plans, and the requirement for data exchanges (i.e., Canceled Card List) between TSA and vessel or facility owners/operators will also be addressed in this rulemaking.”

While the Chemical Facility Anti-Terrorism Standards (CFATS) program is not directly affected by this rulemaking, I suspect that facilities that are using Option 3 in the CFATS personnel surety program (PSP) might want to take a look at this rulemaking when it comes out. At some point in time, the DHS Infrastructure Security Compliance Division may consider adding some or all of the requirements from this final rule to their implementation of the TWIC Readers under Option 3. That change, if it comes, would not likely take place until the second phase of the PSP is put into place to include Tier III and Tier IV facilities.


I expect that it will take a couple of months, at least, for OIRA to review and approve this rulemaking.

Saturday, April 2, 2016

2016 Chemical Sector Security Summit Announced

This week DHS and the Chemical Sector Coordinating Council announced the dates for the 2016 Chemical Sector Security Summit (CSSS), published an agenda and opened registration. The CSSS will be held July 19th thru the 21st in Alexandria, VA. As promised DHS has greatly expanded the number of presentations that will be available via web cast this year.

The preferred method for attending the CSSS is (time and money permitting) is still being there in person in person. A number of the presentations are still not included in the web cast for a variety of reasons. That plus the fact that you will never be able to network successfully via a web cast, nor would you be able to attend the related SOCMA Expo that is always held in conjunction with the CSSS all add incentives to attend in person.

Unfortunately, there are a number of us in the chemical security community that will not be able to travel to the CSSS in person. Last year was the first year of web casting and the presentations were very limited. This year DHS is expanding them to include:

• Keynote Address;
• Infrastructure Security Compliance Division (ISCD) Regulatory Update;
• Responsible Agriculture - Lessons Learned;
• What to Expect During a Chemical Facility Anti-Terrorism Standards Inspection;
• Cybersecurity Tabletop Exercise (TTX) Methodology;
• Industry Keynote Address;
• Cyber Keynote Address;
• Former Chemical Sector Chair Panel;
• DHS Voluntary Programs Update;
• Implementing the NIST Cybersecurity Framework; and
• CFATS Compliance Lessons Learned

Some of the workshop sessions that will not make it into the web cast this year will include:


• CSAT Tool to include Personnel Surety;
• DHS Tools and Resources Exchange;
• Active Shooter;
• Enhanced Cybersecurity Services;
• Interdependencies - Chemical Facilities and Regional Resilience Assessment Programs Lessons Learned;
• Research and Development - Jack Rabbit II;
• Transportation Updates in the Chemical Sector;
• Insider Threat and Social Media - How people get radicalized; and
• Unmanned Aircraft Systems in the Homeland Security Environment


It certainly looks like the 10th Annual CSSS will be worth attending, either in person or via the web cast. I particularly appreciate the fact that most of the cybersecurity related sessions appear to have made it into the webcast.

NIST Updates Workshop Agenda

This week the National Institute of Standards and Technology (NIST) published an updated version of the draft agenda for next week’s NIST Cybersecurity Framework (CSF) Workshop. The new version provides more details about the breakout sessions where most of the work will be accomplished. It also includes more information on some of the panel discussions.

Panel Discussions


There are two of the panel discussions that may be of specific interest to readers of this blog; one on Coast Guard use of the CSF and the other on insurance and the CSF. Here is how the agenda describes these two panels:

US Coast Guard Maritime Profile Strategy – This panel will focus on the work done by the US Coast Guard and partner organizations on building security profiles, based on the Framework, to secure the bulk liquid transport sector.

Insurance – This panel will discuss the benefits to an evolving and growing insurance market of a widely used and consistent approach to understanding and   communicating cyber risks. Panelists will provide their experience with using the Cybersecurity Framework for developing and analyzing data and using the data for underwriting cyber risks.

Other News


The Workshop web page also announced this week that registration has closed for attending the Workshop in person. People that did not complete the registration process will not be allowed on the NIST campus during the workshop. NIST also announced that they would be web casting at least portions of the Workshop on the Workshop homepage starting at 08:30 EDT on April 6th.

NIST also published the ‘official’ TWITTER® hashtag for the Workshop; #NISTCSF. Those of you who already follow NIST on TWITTER (@USNISTGOV) will already have seen that hashtag in their announcements about the Workshop. It is nice to see a government agency taking a proactive use of social media and not just flooding media with meaningless sound bites

Friday, April 1, 2016

ISCD Publishes April 2016 CFATS Update

Today the DHS Infrastructure Security Compliance Division (ISCD) published the April 2016 CFATS Fact Sheet. This updates information about implementation of site security plans (SSPs) at the high-risk chemical companies in the Chemical Facility Anti-Terrorism Standards (CFATS) program. The update shows continued improvement in approvals of SSPs and a sharp increase in the number of facilities at which ISCD has conducted compliance inspections.

The rate in increase in the number of SSP authorizations (the first stage of ISCD actions on proposed SSPs) has greatly dropped off. Since the number of authorized SSPs already exceeds the number of facilities still in the CFATS program, it is difficult to tell how many facilities that are new to the program have yet to have their SSP authorized or how many facilities are having to go back and start over on the SSP process because of changes in the type and amounts of chemicals of interest that have been introduced into facilities with previously authorized (or even approved or inspected) SSPs.

With over 20% of the covered facilities now having undergone compliance inspections of their site security plan, ISCD continues to ignore calls for publishing compliance data on the inspections conducted to date. The last public data on compliance inspection results now comes from a year ago via a GAO report to Congress on the CFATS program. That report showed only 83 compliance inspections having been done and nearly half of the inspected facilities were deficient in implementing agreed upon security measures. Because of the lack inspection information provided by ISCD it is unclear if the inspected facilities are have performed any better than the earlier facilities.

At this point it is not clear whether or not the CFATS program remains on the Congressional target list. The passage of the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014 just over 16 months ago took a lot of pressure off of the program as Congress made an effort to correct some of the more obvious shortcomings of their previous effort at authorizing the chemical facility security program.

NHTSA Publishes Request for Comments on Cybersecurity Guidance

Today the DOT’s National Highway Transportation Safety Administration (NHTSA) has published a notice in the Federal Register (81 FR 18935-18939) requesting comments on proposed guidance for motor vehicle and equipment manufacturers in developing and implementing new and emerging automotive technologies, safety compliance programs, and other business practices in connection with such technologies.

Legal Authority


A substantial portion of the notice establishes the legal authority for NHTSA to regulate the safety of the electronic portions of automotive equipment. They specifically note that under provisions of 49 USC 30102:

“With respect to new and emerging technologies, NHTSA considers automated vehicle technologies, systems, and equipment to be motor vehicle equipment, whether they are offered to the public as part of a new motor vehicle (as original equipment) or as an after-market replacement(s) of or improvement(s) to original equipment. NHTSA also considers software (including, but not necessarily limited to, the programs, instructions, code, and data used to operate computers and related devices), and after-market software updates, to be motor vehicle equipment within the meaning of the Safety Act.”

The notice goes on to explain that in accordance with the requirements of 49 CFR Part 573: “Accordingly, a manufacturer of new and emerging vehicle technologies and equipment, whether it is the supplier of the equipment or the manufacturer of a motor vehicle on which the equipment is installed, has an obligation to notify NHTSA of any and all safety-related defects.”

NHTSA explains that it normally uses the performance record for a vehicle to determine if a safety defect exists, explaining that this is done primarily where the engineering or root cause of the defect is not known. The notice goes on to explain that: “Where, however, the engineering or root cause is known, the Agency need not proceed with analyzing the performance record.”

NHTSA goes on to explain that the Safety Act requires a forward looking risk analysis that is designed “not to protect individuals from the risks associated with defective vehicles only after serious injuries have already occurred; it is to prevent serious injuries stemming from established defects before they occur”. They go on to note:

“Moreover, a defect may be considered ‘per se’ safety-related if it causes the failure of a critical component; causes a vehicle fire; causes a loss of vehicle control; or suddenly moves the driver away from steering, accelerator, and brake controls—regardless of how many injuries or accidents are likely to occur in the future.”

Thus, NHTSA concludes that their enforcement authority concerning safety-related defects in motor vehicles and equipment extends and applies equally to new and emerging automotive technologies; including existing automation and crash avoidance technologies and future autonomous vehicle technology.

Software Guidance


NHTSA notes that software on the vehicle or off the vehicle in portable devices presents unique safety risks because such software can interact with a motor vehicle's critical safety systems (i.e., systems encompassing critical control functions such as braking, steering, or acceleration) and states that:

“If software has manifested a safety-related performance failure, or otherwise presents an unreasonable risk to safety, then the software failure or safety-risk constitutes a defect compelling a recall.”

As such the notice provides the following recommendations:

Manufacturers should consider adopting a life-cycle approach to safety risks when developing automated vehicles, other innovative automotive technologies, and safety compliance programs and other business practices in connection with such technologies;
Manufacturers should consider developing a simulator, using case scenarios and threat modeling on all systems, sub-systems, and devices, to test for safety risks, including cybersecurity vulnerabilities, at all steps in the manufacturing process for the entire supply chain, to implement an effective risk mitigation plan;
Manufacturers of emerging technologies and the motor vehicles on which such technology is installed have a continuing obligation to proactively identify safety concerns and mitigate the risks of harm; and
If a manufacturer discovers or is otherwise made aware of any defects, noncompliances, or other unreasonable risks to safety after the vehicle and/or technology has been in safe operation for some time, then it should strongly consider promptly contacting the appropriate NHTSA personnel to determine the necessary next steps.

Commentary


For those expecting any detailed cybersecurity process or procedures to be outlined in this document will be sorely disappointed. The ‘guidance’ provided is only the most basic and does not even attempt to address routine cybersecurity issues such as authentication and encryption, separation of networks, or authorized access to critical functions. That is the type of discussion I would expect to see in some future motor vehicle safety standard (MVSS) for cybersecurity.

What this guidance document is clearly intended to do is to establish the legal authority of the NHTSA to regulate cybersecurity as part of the Safety Act. It establishes NHTSA’s intent to address cybersecurity vulnerabilities even if few or no actual accidents involving those vulnerabilities have been reported.

Finally, it formally puts automotive manufacturers on notice that they are responsible for the cybersecurity of all on vehicle components and off-vehicle applications designed to affect electronic vehicle components. This is especially important because the major auto manufacturers are no longer manufacturing more than a very small percentage of the component parts (including electronic systems) that go into the vehicle.

The one major part of this overarching guidance that is missing is any mention of the role of independent security researchers. Most computer system related manufacturers have long ago learned that a large portion of the cyber vulnerabilities in their systems have been identified by researchers outside of their organizations.


Coordination between those researchers and the vendors is an important consideration. It would have been appropriate in this document to announce the formation of an office within NHTSA that would provide that coordination or an announcement that NHTSA and the DHS ICS-CERT had signed a memorandum of understanding that ICS-CERT would perform that role in conjunction with the folks at NHTSA.

PHMSA Publishes Reverse Logistics Final Rule

Yesterday the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) published a final rule in the Federal Register (81 FR 18527-18541) that provides a definition of ‘reverse logistics’ (essentially - returning shipments from retail stores to a product's manufacturer, supplier, or distribution facility) to the hazardous material regulations (HMR) and expands a previously existing exception for return shipments of used automobile batteries transported between a retail facility and a recycling center.

Reverse Logistics


PHMSA has made a number of changes to the definition of the term ‘reverse logistics’ from the definition offered in the NPRM. Those changes were based upon suggestions received in the public comments to the NPRM. Those changes include:

Removing the words ‘final destination’;
Modifying the definition to include both the process of offering hazmat for transport and the transport of hazmat;
Clarifying the concept of ‘capturing value’;
Removing the phrase ‘proper disposal’;
Clarifying that the term only applies to the return of hazardous materials from a retail store to the product's manufacturer, supplier, or distribution facility.

Covered Hazard Classes


PHMSA made a number of changes to the hazard classes affected by this rulemaking. In general the rule is consistent with existing limited quantity provisions of the HMR. One exception is that the final rule authorizes the transportation by private carrier of certain Division 2.1 and 2.2 cylinders without the cylinders being tested for pressure. Other exceptions that would be allowed when shipped by private carrier include:

• For the shipment of 1.4G (fireworks and flares);
• Division 2.1 and 2.2 cylinders (that do not qualify as limited quantity shipments) sold as retail products; and
• The return of equipment powered by flammable liquids or flammable gases.

The preamble to the rule includes a discussion of the changes that have been made concerning the reverse logistic shipment of Division 1.4 materials including fireworks, flares and ammunition.

In this final rule PHMSA is excluding the following classes from coverage under the reverse logistics rule:

• Division 4.1;
• Division 5.2;
• Division 6.1 (except consumer products in PG II and PG III, not including TIH material); and
• Division 6.2

Additionally, PHMSA is excluding any materials found in Table 1 of the §172.504 and is only including a portion of the materials found in Table II. PHMSA is also limiting Class 5 and Class 8 materials to only those in PG II or PG III. Return shipment of lithium batteries is not included in this rulemaking since this is already addressed in §173.185.

Packaging


A number of the commenters proposed changes to the NPRM language on packaging. Based upon those comments PHMSA is making some changes to the packaging language. First it is adding language clarifying that packages should be in the original packaging or a package of similar strength and integrity. Next, they are setting a 30 kg (66 pound) limit for each package shipped under the reverse logistics section. Additionally, PHMSA is removing language that would have included provisions for shipping leaking containers under the reverse logistics rule.

In response to comments about reverse logistics shipments of powered equipment PHMSA is taking two actions. First it is allowing the return of internal combustion powered equipment by motor vehicle provided the fuel tank remains securely closed. Secondly it is limiting such shipments to transportation by private carrier.

Hazard Communication


After receiving a number of comments on the proposed hazard communication language in the NPRM, PHMSA made a substantial change in marking requirements. For shipments by private carrier PHMSA is requiring packages shipped under the reverse logistics provisions to be marked: “REVERSE LOGISTICS—HIGHWAY TRANSPORT ONLY—UNDER 49 CFR 173.157”. For any shipments not made by private carrier packages would be marked under the limited quantity provisions of the HMR.

Effective Dates



The effective date for this rule is the publication date; March 31st, 2016.
 
/* Use this with templates/template-twocol.html */