Thursday, August 4, 2016

ICS-CERT Publishes FY 2015 Assessment Report

Today the DHS ICS-CERT published a report that looks at the results of 112 formal assessments that ICS-CERT conducted of industrial control systems during FY 2015. These assessments were conducted using the ICS-CERT’s Cybersecurity Evaluation Tool (CSET, 38 facilitated assessments), the Design Architecture Review (DAR, 46 assessments), and the Network Architecture Validation and Verification (NAVV, 28 assessments).

The report provides the following snap shot of the assessments conducted in FY 2015 (pg 1):

• ICS-CERT conducted 112 assessments in FY 2015, including 38 facilitated CSET®, 46 DAR, and 28 NAVV assessments.
• There were 638 weaknesses identified through DAR and NAVV assessments.
• The top six categories represented 36 percent of all weaknesses.
• Boundary protection was the most commonly identified area of weakness in both FY 2014 and FY 2015.
• Weaknesses related to boundary protection and least functionality represented 21 percent of all discovered weaknesses.
• Key trends included pervasive issues related to virtual machines, remote access, virtual local area network (VLAN) use, bring your own device (BYOD) risks, use of cloud services, and ICS network monitoring.

While the report draws some interesting conclusions about the most common cybersecurity weaknesses found in these assessments, it is very difficult to determine how these weaknesses apply to the total control system environment in the United States. The small number of facilities assessed, the fact that they were self-selected (the facilities requested ICS-CERT assessments), and the lack of information about facility size, type of control system (DCS, SCADA, etc), or the extent of support the facilities had from internal or contract cybersecurity personnel in setting up the security of their control systems all make it very difficult to draw wider conclusions about the results of these assessments.

The other problem with this report is that we are not even sure that there were 112 separate facilities included in the assessments. The very real possibility that facilities may have had ICS-CERT conduct combinations of assessments could seriously reduce the actual number of facilities involved in the study.


Having said all of that, I think that control system security personnel (professional or the untrained grunts on the frontline) should probably read this 25-page document. Addressing the most common problems identified in these assessments will not necessarily make the associated industrial control systems secure, but they will provide a good starting point for making facilities more secure.

HR 5762 Introduced – Rail Hazmat Safety

Last month Rep. Bonamici (D,OR) introduced HR 5762, the Hazardous Materials Rail Transportation Safety Improvement Act of 2016. The bill provides a number of measures designed to increase the safety of liquid hazardous material transportation by rail.

The bill includes four separate titles:

• Creation and Funding of Hazardous Liquids Rail Spill Liability Account;
• Preparedness;
• Data Collection; and
• Authorization of Appropriations

Hazardous Liquids Rail Spill Liability Account


Title I of the bill would amend 26 USC 9509 to create a Hazardous Liquids Rail Spill Liability Account within the Oil Spill Liability Trust Fund (OSLTF). The account would be used to fund Federal responses to oil and other liquid hazmat discharges resulting from accidents related to rail transportation of liquid hazardous materials. The account would also be used to fund various requirements of this bill.

Monies deposited in this account would come from deposits made to the OSLTF due to rail transportation incidents resulting from:

• Damages to natural resources which are required to be deposited in the Fund under 33 USC 2706(f);
• Amounts recovered by the Trust Fund under §2715; and
• Any penalty paid pursuant to 33 USC 1319(c) or §1321.

Additionally, §103 of the bill would add monies to the Account from fees established on the use of DOT 111 and CPC 1232 railcars for the transportation of hazardous flammable liquids. The fees would increase from an initial $175 per shipment in 2016 to a maximum of $1400 per shipment in 2018. The shipper would be required to pay these fees.

Preparedness


Title II of the bill address actions to be taken by the DOT to enhance potential responses to accidents related to the rail transportation of liquid hazardous materials. These actions include training of local first responders and implementation of a number of NTSB recommendations related to rail hazmat preparedness.

DOT would be required to add training standards for responding “to an accident or incident involving trains transporting at least 20 tank cars of flammable liquids or gases” {new §5115(b)(1)(B)} to the existing requirements of 49 USC 5115. Additionally, the DOT would be required to include planning and training for “to accidents and incidents involving trains transporting at least 20 tank cars of flammable liquids or gases” {new §5116(a)(1)(E)} to the allowable uses for grants under 49 USC 5116.

Section 204 of the bill would require DOT to implement the following National Transportation Safety Board (NTSB) recommendations:

R–07–002, dated April 25, 2007, relating to real-time information regarding the identity and location of all hazardous materials on a train:
R–14–014, dated August 22, 2014 (relating to railroads providing communities and States with current commodity flow data and assisting with development of emergency operation and response plans;
R–14–018, dated August 22, 2014 (relating to ensuring that emergency response information carried by train crews is consistent with the Emergency Response Guidebook;
R–14–075 and R–14–076, dated December 30, 2014 (relating to allowable limits for track conditions; and
R–14–019, dated August 22, 2014 (relating to developing, implementing and periodically evaluating requirements for railroads that transport hazardous materials to conduct public education programs for communities along railroad hazardous materials routes.

Data Collection


Title III of the bill requires the Department of Transportation and the Department of Commerce (for the Census study) to conduct four studies, each with a mandated report to Congress. Those studies involve:

• National flammable rail fire preparedness survey (§301);
• Hazardous materials railcar census (§302);
• Energy train data collection (§303); and
• Train length study.

Authorization


Title IV of the bill provides authorization for spending to support some of the requirements of this bill. The authorizations include:

• High hazard rail shipments preparedness and training grants - $15 million per year for 2016, 2017, and 2018 {§401(a)};
• Track relocation and railroad inspection safety grants - $25 million per year for 2016, 2017, 2018, and 2019 {§401(b)};
• Data collection funding - $5 million for each of the three non-census studies mentioned above {§401(c)}; and
• Federal spill response funding under 42 USC 9604 (CERCLA) for flammable liquids and gasses rail-accident related spills - $100 million {§401(d)};

Moving Forward



Bonamici is not a member of any of the four committees to which this bill was referred for consideration. This means that it is unlikely that any of these committees will consider the bill. If the bill were to make it out of committee to be considered by the whole House, the bill would almost certainly be opposed by most of the Republican (and some Democratic) members of the House because of the additional spending authorized by the bill and the fees being required for the continued use of DOT 111 and CPC 1232 railcars for flammable liquid transport.

Wednesday, August 3, 2016

PHMSA Publishes HHFT Oil Spill Response Rule

Last week the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) published a notice of proposed rulemaking (NPRM) in the Federal Register  (81 FR 50067-50129) concerning oil spill response plans and information sharing for high-hazard flammable trains. The advance notice of proposed rulemaking (ANPRM) for this rulemaking was published in August of 2014.

This rulemaking addresses three general areas:


Oil Spill Response Plans


The current hazardous materials regulations (49 CFR 130) currently requires two types of oil spill response plans (OSRP). The basic OSRP {§130.31(a)} covers any oil shipment in containers of 3,500 gallons or greater. The comprehensive OSRP {§130.31(b)} covers any oil shipment in containers of 42,000 gallons or greater. Since railcars used for transporting crude oil are generally 30,000 gallons, railroads are currently only required to prepare basic OSRPs.

This NPRM proposes to generally re-write Part 130; moving (and expanding) the comprehensive OSRP requirements to a new Subpart C. The changes to the comprehensive OSRP requirements would include:

• Expanding the applicability for comprehensive oil spill response plans to include “Any railroad which transports a single train transporting 20 or more loaded tank cars of liquid petroleum oil in a continuous block or a single train carrying 35 or more loaded tank cars of liquid petroleum oil throughout the train consist” {new §130.101(b)};
• Establishing a general requirement for the overall development of the comprehensive response plan and requires the plan uses the National Incident Management System (NIMS) and Incident Command System (ICS) {new §130.102(a)};
• Establishing a general requirement for the plan format including the development a core plan and the establishment of geographic response zones and accompanying response zone appendixes {new §130.102(b)};
• Establishing requirements for the notification procedures and contact information that a railroad must include in a comprehensive oil spill response plan {new §130.105};
• Establishing requirements for equipment testing and drill procedures consistent with PREP requirements for comprehensive oil spill response plans {new §130.108}; and
• Establishing requirements and procedures to submit comprehensive oil spill response plans for approval to FRA {new §130.111};

Nothing in this rule changes the basic OSRP requirement that the plan is targeted at oil spill containment and recovery. In fact, a new definition is added in §130.5 for ‘Response Activities’ that specifically limits that definition to the “the containment and removal of oil from navigable waters and adjoining shorelines”.

Information Sharing


While information sharing was not included in the ANPRM for this rulemaking, Congress did recently specifically direct DOT to “require each Class I railroad to provide advanced
notification and information on high-hazard flammable trains to each State emergency response commission, consistent with the notification content requirements in Emergency Order Docket No. DOT–OST–2014–0067 [.PDF Download link added]” {§7302(a)(3) of the FAST Act (PL HR 114-94)}.

This NPRM establishes information sharing requirements that expands the notification requirements of the Emergency Order to include all Highly Hazardous Flammable Trains (HHFT) as defined in §171.8. The NPRM would require monthly reports to State and Tribal Emergency Response Commissions (SERC and TERC) that would include:

• A reasonable estimate of the number of HHFTs that the railroad expects to operate each week, through each county within the state or through each tribal jurisdiction;
• The routes over which the HHFTs will operate;
• A description of the hazardous material being transported and all applicable emergency response information required by subparts C [Shipping Papers] and G [Emergency Response Information] of part 172; at least one point of contact at the railroad (including name, title, phone number and address) with knowledge of the railroad's transportation of affected trains (referred to as the “HHFT point of contact”); and
• If a route is subject to the comprehensive spill plan requirements, the notification must include a description of the response zones (including counties and states) and contact information for the qualified individual and alternate, as specified under § 130.104(a).

SERCs and TERCs would be required to share the supplied information with “appropriate local authorities, upon request” {new §174.312(a)}. Further dissemination of the information may be restricted upon request by the submitting railroad if the railroad determines that the information may be “security sensitive or proprietary and exempt from public disclosure” {new §174.312(a)(2)(iii)}. The language does not make the information Sensitive Security Information under §1520.5 so the SERC and TERC would be able to make their own decisions as to what State or local regulations applied to the protection of the information.

Initial Boiling Point Test


One of the concerns about shipping crude oil from the Bakken region is that the current standard for classifying the crude oil for shipment may not appropriately address the volatility of the crude oil. Suggestions have been made to include a vapor pressure measurement for use in the classification of crude oil and I have discussed the problems with that sort of measurement.

The current testing process outlined in §173.120 and §173.121 almost certainly allow significant amounts of the light-ends (low molecular weight hydrocarbons). Depending on the concentration of these light-ends, these current test methods could significantly under-state the flammability of the material.

Recognizing this problem, PHMSA and the American Petroleum Institute (API) came up with a best practice (ANSI/API RP 3000) for measuring the flammability of crude oil that includes using ASTM D7900 for determining initial boiling point. This test method, however, is not one of the approved methods for classifying flammable liquids in §173.121. This NPRM would add ASTM D7900 as an acceptable alternative for determining initial boiling point to be used in determining packing groups for Class 3 (flammable liquids) hazardous material.

Public Comments


PHMSA is soliciting public comments on this rule making. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2014-0105). Comments should be submitted by 9-27-16.

Commentary


My major concern with the OSRP section of the NPRM is that it fails to address what is the most publicly acknowledged problem with crude oil transportation by unit trains; the potential for catastrophic fires and explosions resulting from a rail accident and the inability of most local first response agencies to properly deal with this type of catastrophic emergency. Unfortunately, the current OSRP rules are based upon the Clean Water Act provisions that are intended to protect waterways (and drinking water sources) from contamination with crude oil. Until Congress specifically addresses the flammability problems associated with a variety of energy chemicals shipped by unit trains, neither PHMSA, FRA, nor the Coast Guard will be able to address these very real probable consequences of oil spills.

PHMSA took a pass on addressing the issue of confidentiality of HHFT train schedule information by allowing the railroads to claim that the information was either sensitive from a security perspective or confidential business information and then allowing each SERC or TERC to evaluate those claims based upon State and local laws. Again, PHMSA has not really been authorized to make a determination that the information falls within the Sensitive Security Information rules; only TSA is authorized to make that determination. Again this is going to take Congressional action to resolve this problem.

The issue of crude oil testing is a more complex problem. The addition of ASTM D7900 to the list of allowable test methods provides crude oil shippers with a more accurate method of classifying crude oil based upon the initial boiling point. PHMSA has long maintained that shippers are responsible for determining which of the allowed test methods is the most appropriate for classifying the material which they ship. The use of this test should result in upgrading some shipments from Packing Groups II and III and that will result in some increase in safety of those shipments.

What is missing, however, is a more complete discussion of the role of volatility in the fires and explosions seen in a relatively small number of crude oil derailments. Measurement of volatility, alone will not increase safety unless some additional safety measures are required for flammable liquids with higher vapor pressures. For crude oil, that could include a requirement to remove light-ends from the material to reduce vapor pressure before it is offered for shipment.

To be an effective safety tool, any vapor pressure testing is going to have to specifically address protection of samples from vapor loss (sealed sampling devices and sample containers) as well as measuring vapor pressure at multiple temperatures if there is any hope of using the test as an effective tool for predicting the safety consequences of the fluid vapor pressure.


The current NPRM provides a good first step at addressing the transportation safety classification of crude oil. Hopefully PHMSA will continue to look at possible additional changes to test methodology to more completely identify the safety issues associated with crude oil transportation.

Tuesday, August 2, 2016

ICS-CERT Publishes Two Advisories

This morning the DHS ICS-CERT published two industrial control system security advisories for products from Siemens and Moxa.

Siemens Advisory


This advisory describes a privilege escalation vulnerability in the Siemens SINEMA Server. The vulnerability was reported by rgod via the Zero Day Initiative. Siemens has developed a temporary fix for the vulnerability while a new version is being developed. There is no indication that rgod has been provided an opportunity to verify the efficacy of the temporary fix.

ICS-CERT reports that a relatively low skilled attacker with local access could exploit the vulnerability with a social engineering attack to escalate their privileges.

Moxa Advisory


This advisory describes an SQL injection vulnerability in the Moxa SoftCMS. The vulnerability was reported by Zhou Yu of Acorn Network Security via the Zero Day Initiative. Moxa has produced an update to mitigate the vulnerability, but there is no indication that Yu has been provided the opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to execute arbitrary commands on the target system.

ISCD Updates CFAT FAQ – 08-02-16

Today the DHS Infrastructure Security Compliance Division (ISCD) updated the response to one of the frequently asked questions found in the CFATS Knowledge Center. The updated FAQ response was for FAQ #1627; “Can I have multiple Preparers or Reviewers for the Site Security Plan (SSP)?”

The answer provided when this FAQ was first published in May of 2009 was brief and somewhat stilted: “Yes, but this is a unique feature of the SSP, designed to facilitate the involvement of subject matter experts in the many areas covered by the SSP.”


Today’s response was essentially the same (Yes), but provides a little bit more information about the use of multiple Preparers and Reviewers.

FAST Act Rule Approved by OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the DOT’s Pipeline and Hazardous Material Safety Administration’s (PHMSA) direct final rule implementing the requirements of the Fixing America’s Surface Transportation (FAST) Act of 2015 (HR 22 – PL 114-94). OIRA acted fairly quickly on this rulemaking, given that it was submitted by PHMSA just back in June.

This rule implements Congressionally mandated changes to the hazardous material regulations related to railcars used to ship flammable materials. This includes changes to the DOT 111 phase-out schedule, and changes to the DOT 117 railcar standard. Since DOT was given no leeway on these changes by Congress, the rule did not require the normal publish and comment process; going instead directly to the issuing of the final rule.

This rule will almost certainly be published in the Federal Register this week.

New Wassenaar Rule Sent to OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule for review from the DOC’s Bureau of Industry and Security (BIS) concerning the latest updates to the 2015 Wassenaar Arrangement implementation. This rulemaking does not appear to address the ‘intrusion software’ issues associated with the 2013 Wassenaar Arrangement.

According to the abstract in the 2016 Spring Unified Agenda listing for this rulemaking this rulemaking will address:

“This rule harmonizes the CCL [the Commerce Control List] with the changes made to the WA List at the Plenary by revising Export Control Classification Numbers (ECCNs) controlled for national security reasons in each category of the CCL, as well as making other associated changes to the EAR. The WA agreements include raising of the Adjusted Peak Performance for high performance computers, therefore other parts of the EAR that have APP limitations are also amended by this rule, e.g., de minimis, License Exception APP, reporting requirements. This rule removes the Foreign National Review requirement associated with deemed exports under License Exceptions APP and CIV, because after years of reviewing these requests with no denials ever coming from this information BIS has determined it is not an efficient use of U.S. Government resources. Because this year's WA agreements include the total restructuring of Category 5 part 2, BIS is taking this opportunity to also streamline and update license requirements and policies associated with Category 5 part 2 [Information Security .PDF download] in this rule.”

The information security license and policy update portion of this rule should probably be watched fairly closely when it is published. Again, this is a direct final rule without the normal publish and comment process being required. This is the same process that was used (and later withdrawn) on the intrusion software rulemaking last year.
 
/* Use this with templates/template-twocol.html */