Monday, January 6, 2020

Legislative Suggestions – A Personal Perspective


Over the holidays I was asked by a friend why I suggested changes to legislation that I wrote about in my blog posts. She did not understand why I wrote the blog in the first place, not getting paid for it and all, but she was really surprised that I thought that I had any possibility of influencing what happened in Washington. It was an interesting conversation, but I thought it might be worthwhile to explain some of my motivations and intentions here.

Family Tradition


First off, I grew up in a house that demonstrated that involved politically individuals could make a difference. I saw my father start a neighborhood activism movement in San Jose, California in the 60’s as he fought to get streetlights installed in the housing tract in which we lived. His success in our neighborhood led to the establishment of a large number of homeowner associations in the San Jose that had a positive effect on the early growth of that city and he remained an influential figure in the movement until we left that city in 1969.

My mother’s involvement in the Republican Women movement likewise showed me that a personal involvement in politics could lead to effects at the State and national level. And my personal involvement in the movement to succeed from Los Angeles County helped to form the fledgling Santa Clarity County in Southern California. It truly is a family tradition.

Chemical Facility Security News


When I started this blog back in 2007 it was as much a networking tool as anything else. I was an out-of-work chemist who had done little to extend his influence or connections beyond the job that no longer needed me. To make the job search more productive, I started writing about two things that I was strongly interested in, chemical safety and security. The inauguration of the CFATS program fit right into those concerns.

As the blog progressed over the years it began to take on a life of its own; it was no longer just a networking too. I expanded the topics that I covered to include other areas that impacted chemical safety and security including coverage of legislative matters; talking about and explaining bills that could end up having impacts on chemical safety and security. I frequently found those congressional legislative efforts ineffective or counterproductive, so I increasingly spoke out about those problems when writing about the bills as they meandered through the legislative process.

I learned early in both my military career and my chemical career that superiors did not appreciate my ability to point out problems to them unless I could also at least propose a solution to those problems. During the debate about creating an actual legislative basis for the existing CFATS program, a program that was after all designed to be an interim program, I created a draft bill on a now defunct WIKI site, WriteTheBillWiki.com. It did not get anywhere, though I did have some interesting phone conversations about the bill for a while. But, my current habit of proposing language to improve legislation really started with that effort and has become an more common part of my legislative critiques in this blog.

The Intention


Okay, while I would certainly like to see the language changes that I propose in this blog show up in amended versions of the bill, that is not really my intent. I am trying to demonstrate that the purpose of my criticism is not to denigrate the work done by the congressional staffers that actually write these bill or oppose their efforts, but rather help them make their bill a more effective tool at fixing real problems.

You see, I think that a major part of the political problems that we currently face in this country are based on a very parochial outlook on the part of most politicians; we hear too much of ‘do it my way’ instead of ‘lets figure out how to fix this problem’. With the ‘do it my way’ approach, our institutions are now spending too much time trying to erase what the last guy did rather than trying to fix what needs to be fixed.

I DO NOT want to be part of that problem. I would much rather try to be able to say: “I see what you are trying to do. I do not agree with all of it, but I think it would work better if you tried this.” I do not expect an ‘Oh obviously, great idea’ response to these suggestions (though of course they are great ideas, just ask me – grin). What I am more hoping for is: “Hmmm. I didn’t think of that, but maybe if I tried this instead….” If the person realizes that I am trying to help rather than oppose, maybe he will be more willing to listen to my arguments.

But, this is not just about congressional staffers. It is also about engaging with the community that those laws and regulations will ultimately effect. A sizeable percentage of my readers are Washington insiders according to Google, but most are not. Those of you who do not have day-to-day impact on the legislative process should also be taking part in this conversation. If you do not agree with what I suggest, let me know; contact me and suggest your own alternatives or even just explain why you think I am wrong. Help me make my suggestions better.

And if you do agree, send a copy of my blog posts to your congresscritter. Be part of the conversation because we need it to be a conversation not a yelling match.

BTW: Read carefully some of my blog posts and you will realize that I have made a difference in some legislative language, my language was not used, but some of the problems I identified were addressed.

Saturday, January 4, 2020

Finally, a Real NTAS Bulletin


Today the DHS Cybersecurity and Infrastructure Security Agency published a National Terrorism Advisory System (NTAS) Bulletin concerning a possibility of a set of potential terrorist threats against the United States by the government of Iran because of this week’s US assassination (okay my word not CISA’s) of Iran’s General Qassem Soleimani.

NTAS Background


In 2011, the Department of Homeland Security replaced the old and usually ignored color-coded alert system with the new NTAS system. For more that four years the NTAS website remained empty of any vacuous warnings about an unchanging terrorist threat to the Homeland; DHS was being careful to avoid the ‘cry wolf’ problem that had plagued the old system.

Originally, the NTAS was expected to issue alerts when there was information available about specific credible threats of an imminent terrorist attack. The idea being that when such an alert was actually issued, the public would be able to respond in some sort of effective manner and not just yawn.

On December 16th, 2015 that system was modified by adding three levels of terrorist attack warnings:

• BULLETIN - Describes current developments or general trends regarding threats of terrorism.
• ELEVATED ALERT - Warns of a credible terrorism threat against the United States.
• IMMINENT ALERT - Warns of a credible, specific and impending terrorism threat against the United States.

The same day that that change to the NTAS was made, the first Bulletin was published. And with that Bulletin, we also learned that a bulletin was issued for a specific period of time. The first bulletin would expire in six months. The second Bulletin was published just before the first expired, but it was given just five months before it expired. The third bulletin [no CAP ‘B” is an editorial comment on my part]; you guessed it, pretty much the same as the first. I stopped reporting about bulletin updates in May of 2018; I still periodically check the NTAS website, but I have generally stopped talking about the Bulletins.

What’s Different This Time?


First off, this Bulletin starts off with a brief (three bullet points) description of why Iran might be upset enough with us this week to do something about it. Next the comes the obligatory “At this time we have no information indicating a specific, credible threat to the Homeland” but the same bullet point notes that: “Iran and its partners, such as Hizballah, have demonstrated the intent and capability to
conduct operations in the United States”. Then there are three basic bullet points about how the Iranian threat could possibly be expected to be seen to develop:

• Iran maintains a robust cyber program and can execute cyber attacks against the United
States. Iran is capable, at a minimum, of carrying out attacks with temporary disruptive
effects against critical infrastructure in the United States.

• Iran likely views terrorist activities as an option to deter or retaliate against its perceived
adversaries. In many instances, Iran has targeted United States interests through its
partners such as Hizballah.

• Homegrown Violent Extremists could capitalize on the heightened tensions to launch individual attacks.

And, of course, the bulletin ends with this final feel good comment: “The Department of Homeland Security is working closely with our federal, state, local, and private sector partners to detect and defend against threats to the Homeland, and will enhance security measures as necessary.”

Finally, the Bulletin expires in 14 days.

Commentary


Okay, there is not any real actionable information here, but then again “At this time we have no information indicating a specific, credible threat to the Homeland.” With out any ‘specific, credible threat’ information, there can hardly be any actionable information to share. If there were, it would not be a bulletin, but either an Elevated Alert or an Imminent Alert. Hopefully, we can avoid seeing any of those.

Okay, so what is a facility security officer to do with this type of information? I did one of my longer blog posts back in 2011: Enhanced Security Planning. The information still applies.

Friday, January 3, 2020

CFATS and Facility Fires

Ever since the West Fertilizer explosion in 2013, I periodically get asked if the Chemical Facility Anti-Terrorism Standards (CFATS) program helps prevent facility fires. The answer is complicated, but generally speaking no, that is not the direct intent of the program; the CFATS is a security program not a safety program. Having said that, it is complicated and worth an additional look.

Safety and Security


Anyone that has worked in an industrial workplace knows that safety and security are intertwined. Security obviously prevents incidents that are the result of malicious intent and those events, if successfully carried out have safety consequences. A terrorist attack could certainly cause a fire at a facility; preventing the attack would certainly prevent the associated fire.

But effective safety programs are also a good way to mitigate the effects of a malicious act. Effective fire prevention and mitigation activities would reduce the negative effects of a successful terrorist attack that was intended to start a fire. So, part of an effective security plan is good integration with the facility safety activities.

Emergency Response


Planned and coordinated on-site and off-site emergency response is an important part of both facility security and safety plans. Both plans must address the potential failure to prevent the unwanted outcomes associated with either a security or safety incident. In fact, the undesirable consequences of either type event are frequently identical. Thus, there needs to be coordination of the emergency response portions of both the security and safety plans for the facility.

CFATS and Safety Incidents


One thing that facility security officers need to remember is that the response to a safety incident is going to have a potentially significant effect on the facility security plan. A fire at a facility is going to disrupt all activities at the facility, especially the security activities. An emergency response from outside agencies is going to bring a large number of people into the facility that may or may not be familiar with the security controls in place. And if those security controls interfere with the operations of emergency response personnel the facility and its staff will suffer.

A site security plan should include actions to be taken to increase security during both security and safety incidents. The increase in traffic into the facility by emergency response personnel, the appearance of crowds of bystanders watching the event and the presence of TV and print news crews along the facility perimeter all need to be taken into account when planning on how to respond to such events. Facilities that have to rely on volunteer fire departments are going to have a special problem with quickly identifying incoming emergency response personnel.

Security plans are also going to have to be able to deal with post incident cleanup activities. While CFATS rules provide for unescorted access to facilities by emergency response personnel during an incident, they do not provide an exemption for post-incident response personnel. After a significant safety event a wide variety of new and unusual personnel are going to be required to have access to the facility. This obviously includes environmental remediation teams at chemical facilities but will also include a variety of government and insurance company investigators. There could also be engineering and construction personnel that will be involved in planning for and executing facility repairs. All of these personnel are going to have to be accommodated by either vetting through the personnel surety program or more likely being escorted by facility personnel.

Finally, facility security officers need to remember their incident reporting requirements under the CFATS program. While an accidental fire at a CFATS covered facility may not sound like a security incident, if it had any effect on the facility security, compromised (even temporarily) any of the facility security measures included in the Site Security Plan, or just help identify problems with the security plan or its emergency response processes; notifications to the Infrastructure Security Compliance Division will be required.

Thursday, January 2, 2020

Firefighters ‘Release’ Hazardous Chemicals


Earlier today there was a fire at an industrial manufacturing facility in Brea, CA that reportedly evolved into a hazardous material release incident. No injuries were reported but evacuations were ordered from a residential development adjacent to the facility. Not a lot of details were available in the various news reports (here, here, and here), but it appears that the water runoff from the firefighting efforts resulted in an alkaline material leaving the facility.

The facility manufactures bolts and fasteners for the aerospace industry. Metal processing of this sort involves a number of different hazardous chemicals in the metal preparation and finishing process. The California EPA lists 112 different hazardous materials stored on the site.

A couple of the articles mention ‘alkali soap’ as the source of the potential hazmat release. While the EPA site does not list any materials by that specific name there are three products that probably fall into that category; all three are solid materials from the same manufacturer that contain 50% sodium hydroxide. If the remainder of the solid product were some sort of fatty acid, the materials could certainly be considered ‘alkali soap’. I have been able to find a safety data sheet (SDS)for one of the products and it would appear to be consistent with an alkali soap.

There is nothing in the story or SDS about the packaging that this product would be found in, but solid materials like this are very often packaged in 50-lb paper bags for ease of handling. If this is were the case in this incident the fire-sprinkler system or the fire fighter’s application of water to the fire very easily could lead to runoff that had a high pH; probably high enough to be of concern for incidental contact off site.

A well thought-out hazardous material storage plan would probably want to ensure that materials like this were protected from possible water damage, particularly from firefighting systems. This material is not a fire hazard according to the SDS so overhead coverage of the area where this material is stored would not be a fire safety issue.

As I have mentioned a number of times over the years in posts about fire incidents at chemical storage facilities, a fire safety plan must address the issue of water runoff during fire fighting in any area where chemicals are stored or used. If not, the facility is going to be responsible for an expensive cleanup after the fire is over. I personally know of one facility that had to scrape soil from 3 miles of creek bed to recover chemical runoff from a fire-fighting effort. All of that soil had to be disposed of as hazardous waste.

Federal Strategy to Defend Against Cyberattacks


There has been a bunch of play about a recent article on TheHill.com on social media in the last 24-hours; Lawmakers close to finalizing federal strategy to defend against cyberattacks. People who only read the headline, or casually read the article are to be forgiven for thinking that congressional action on a new cybersecurity initiative is imminent. Unfortunately, the truth is not quite that bright.

The article is about the Cyberspace Solarium Commission which was established by Congress in the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (PL 115–232). Section 1652 (132 STAT. 2140). I briefly discussed the Commission when it was first suggested in 2017. As it was outlined in the 2018 bill the Commission was tasked with developing “a commission to develop a consensus on a strategic approach to defending the United States in cyberspace against cyber attacks of significant consequences” {§1652(a)(1)}.

Commission Members


The Commission consists of 16 members, only four of which were members of Congress; two from the Senate and two from the House; a Republican and a Democrat from each. Four would be from the Executive Branch; DNI, DHS, DOD and FBI. The remaining eight would be appointed by House and Senate Leadership but could not be member of either body.

Those eight members were to be people who were “nationally recognized for expertise, knowledge, or experience in” {§1652(b)(1)(B)}:

• Cyber strategy or national-level strategies to combat long-term adversaries;
• Cyber technology and innovation;
• Use of intelligence information by national policymakers and military leaders; or
• The implementation, funding, or oversight of the national security policies of the United States.

Commission Duties


Section 1652(f) set forth the duties of the Commission. Those include:

• To define the core objectives and priorities of the strategy described in subsection (a)(1).

• To weigh the costs and benefits of various strategic options to defend the United States, including the political system of the United States, the national security industrial sector of the United States, and the innovation base of the United States. The options to be assessed should include deterrence,
norms-based regimes, and active disruption of adversary attacks through persistent engagement.

• To evaluate whether the options described in paragraph are exclusive or complementary, the best means for executing such options, and how the United States should incorporate and implement such options within its national strategy.

• To review and make determinations on the difficult choices present within such options, among them what normsbased regimes the United States should seek to establish, how the United States should enforce such norms, how much damage the United States should be willing to incur in a deterrence or persistent denial strategy, what attacks warrant response in a deterrence or persistent denial strategy, and how the United States can best execute these strategies.

• To review adversarial strategies and intentions, current programs for the defense of the United States, and the capabilities of the Federal Government to understand if and how adversaries are currently being deterred or thwarted in their aims and ambitions in cyberspace.

• To evaluate the effectiveness of the current national cyber policy relating to cyberspace, cybersecurity, and cyber warfare to disrupt, defeat and deter cyberattacks.

• In weighing the options for defending the United States, to consider possible structures and authorities that need to be established, revised, or augmented within the Federal Government.

Commentary


The Commission was patterned after Eisenhower’s 1953 National Security Council’s Solarium Special Committee that was used to help formulate Eisenhower’s containment strategy vis-à-vis the Soviet Union. It was established to provide a strategic vision on how to deal with cyberattacks by nation state adversaries. It was not intended to formulate tactical doctrine on how to respond to specific attacks, but rather to provide a framework under which such doctrine can be developed.

Not wanting to belittle this work, it is very important, but it will not directly guide anyone on how to protect government or private sector information technology or operational technology systems from attack. Instead, what it should do is to provide Congress and the President with a workable guide on how to develop governmental policy and define interagency cooperative responsibilities to organize and fund the Federal government’s attempts to defend national and critical infrastructure systems from organized cyberattacks by enemies overseas.

The report from the Commission will be but a first step in this process. Unfortunately, it will land in Congress at a most inopportune time; in a Presidential election year at the start of the spending bill introduction process. There will be little time this year for Congress to review (and there will be numerous hearings about this report), much less act on the recommendations of the Commission. It will likely fall to the 117th Congress to start to take whatever actions will be necessary to begin the implementation of the ideas that the Commission generates. And, more congresses down the road will have to continue to work the problems identified as our adversaries continue to change their strategies, tactics and operational objectives. This is just the start of a new cold war.

New Small UAS Registration ICR


As part of last week’s notice of proposed rulemaking (NPRM), the DOT’s Federal Aviation Administration (FAA) announced that as part of that proposed rule on remote identification of unmanned aerial systems (UAS) it would be required to submit a new information collection request (ICR) to the OMB’s Office of Information and Regulatory Affairs (OIRA) for the required revision to the small UAS registration process.

Current Small UAS Registration ICR


The FAA currently has an approved ICR for the registration of small UAS as currently required under 14 CFR 48.100. It covers the registration requirements for both commercial and hobby small UAS owners. The supporting document [.DOCX download link] for the latest update to that ICR (approval is still pending) provides the following data about the estimated three years-worth of data collections under this ICR:


Number of sUAS Owners (Thousands)

Commercial
Hobbyist
Year
Register
De-Register
Register
De-Register
2019
200
-
873
-
2020
273
200
900
873
2021
356
273
913
900
Average
276
237
895
887

The numbers in the registration estimates are derived from the FAA’s estimates on the sales of small UAS in the listed years. The numbers in the de-registration estimates are derived from the assumption that a registered UAS only has a service life of one-year and thus needs to be deregistered in the following year. (Commentary: I would assume that this service life assumption is why the FAA did not address the grandfathering issue that I noted in my previous blog post.)

The FAA also notes in that ICR supporting document that the average ‘fleet size’ for the hobbyist registrant is 1.5 small UAS, so the actual numbers of UAS covered by the registration numbers listed above are 1,309,500; 1,350,000; 1,369,500; and 1,342,500 respectively.

New ICR Proposal


In the NPRM, the FAA, instead of proposing to revise the current small UAS registration ICR is proposing to submit a new ICR that would allow for the changes in the registration process proposed in the new rule.

For small UAS previously registering under §48.100(a) (commercial) there would only be two ‘new’ data elements that would need to be reported: telephone number and serial number. The serial number was previously only required ‘if available’. The new rule would have the FAA provide a serial number for registrants that did not have a serial number available. All new small UAS manufactured would be required to have a serial number.

The big change comes for small UAS users previously registered under §48.100(b) (hobby). Users would no longer be registered, each small UAS would be. For users with a single UAS this would require modification of the current registration. For users with multiple UAS, a new registration would be required for all but one of the currently covered UAS. The single updated registration would have to add manufacturer name, model name, serial number, and telephone number to the current registration.

The NPRM proposes the following potential burden information for the proposed ICR:

Year
Registrations
Hourly burden
Total cost ($Mil.)
1
442,623
12,082
$0.17
2
335,236
8,040
0.11
3
372,127
8,899
0.13

Commentary


There are two problems with this proposal. First, while it does not specifically say so, it would appear that the FAA is proposing to only require UAS users already registered on the effective of the rule to update their registration when their current registration expires (at the end of three years unless otherwise de-registered), that can be the only reason that I would see for having three year’s data listed in the table.

Using the data from the latest ICR update describe above there would be a total of 1,269,000 registrations (based upon the 2021 estimate) currently in the small UAS registration program that would have to be updated in the new ICR; and the number would be even higher in 2024 (the earliest practical effective date given the proposed 3 year delay in the NPRM). The totals given in the NPRM would only be 1,149,986. That is about 10% low and the NPRM gives no information on how their number was obtained.

On the other hand, given the FAA’s assumption that most small UAS would be go out of service within a year of registration, the numbers seem way too high. In fact, that assumption would seem to obviate the need for a separate ICR for the reregistration.

It would seem to me that a modification to the current small UAS registration ICR would be an easier way to proceed. In order to prevent too much front loading of the year 1 collection data, the FAA could require that registrants would immediately begin providing the new telephone number information at their next reregistration instead of waiting for the effective date for the bulk of the rulemaking. This could be justified under the current versions of both §48.100 (a) and (b) since they both contain provisions for “Other information as required by the Administrator.”

Wednesday, January 1, 2020

HR 5527 Introduced – Grid Modernization Grants


Last month Rep Sarbanes (D,MD) introduced HR 5527, the 21st Century Power Grid Act. The bill would require DOE to establish a grant program to carry out projects related to the modernization of the electric grid. The plan includes cybersecurity provisions.

Grant Program


The grant program would include projects {§2(a)}:

• For the deployment of technologies to improve monitoring of, advanced controls for, and prediction of performance of, a distribution system; and
• Related to transmission system planning and operation

Eligible projects would be designed to {§2(b)}:

• Improve the resiliency, performance, or efficiency of the electric grid, while ensuring the continued provision of safe, secure, reliable, and affordable power;
• Deploy a new product or technology that could be used by customers of an electric utility.

Additionally, the projects would be required to demonstrate {§2(b)(3)}:

• Secure integration and management of energy resources, including through distributed energy generation, combined heat and power, microgrids, energy storage, electric vehicles, energy efficiency, demand response, or controllable loads; or
• Secure integration and interoperability of communications and information technologies related to the electric grid.

Each approved project would be required “include the development of a cybersecurity plan written in accordance with guidelines developed by the Secretary of Energy” {§2(c)}.

The bill would authorize $200 million per year through 2025 to fund the grant program.

Moving Forward


Sarbanes and his three cosponsors {Rep McNerney (D,CA), Rep Kennedy (D,MA), and Rep Veasey (D,TX} are all members of the House Energy and Commerce Committee to which this bill was assigned for consideration. They are also members of the Energy Subcommittee which would have jurisdiction within the Committee for the bill. This means that it is likely that they would have sufficient influence to see this bill considered in at least the Energy Subcommittee.

There are two things that might engender opposition to the bill; the spending authorization and the cybersecurity plan requirement. Spending monies have to come from somewhere and that is generally a zero-sum game, so some other programs would likely pay the bill. Any bill that gives and Executive Branch agency the authority to require a private sector entity to do something is going to face some knee jerk opposition from Republicans. I am afraid that this is the reason that there are no Republican cosponsors to the bill.

I do suspect that the bill still could receive some bipartisan support in Committee, but probably not enough to allow the House leadership to see this bill considered on the floor under the suspension of the rules process; it probably would not receive the supermajority required for passage under that procedure.

Commentary


Again, this is not strictly speaking a cybersecurity bill, but it will certainly have cybersecurity impacts. Because grid management is all about communications between various independent control systems, the provisions about demonstrating ‘secure integration and interoperability of communications and information technologies related to the electric grid’ is almost as much about cybersecurity as it is about communications and information technologies.

The interesting provision here, and one that is likely to be modified if broader support is to be found for this bill, is the cybersecurity plan requirements. The crafters of the bill gave DOE total leeway in determining what sort of guidelines would be required for the grantees to comply with in crafting their cybersecurity plan. I was particularly surprised not to see a reference to the NIST Cybersecurity Framework in this requirement. While the CSF has nothing to do with crafting a cybersecurity plan (it is a risk management tool not an operational guideline), it is a congressional favorite for pawning off ideas about cybersecurity issues; it makes folks sound like they know something about cybersecurity.

I think that the following rewording of §2(c) might be a way to accomplish what the committee staff was trying to accomplish with this plan provision while allowing more Republicans to support the measure:

(c) Cybersecurity Plan

(1) Each project carried out with financial assistance provided under subsection (a) shall include the development of a cybersecurity plan written in accordance with guidelines developed by the Secretary of Energy;

(2) In crafting the guidelines describe in (1) the Secretary will:

(A) establish risk-based performance measures that the plans would be required to meet; and

(B) keep in mind that each grantee will have unique systems and equipment requirements that would make requiring any specific security measure or equipment in the guidelines counter-productive;

(C) refer to the NIST Cybersecurity Framework for the risk management objective of the plan;

(3) Each submitted plan will be approved by the Secretary before any of the funds provided under (a) allocated;

(4) Disapproval of plan will only be done because the plan does not meet one or more of the risk-based performance standards established in (2)(A);

(5) For plans that are determined by the Secretary to not adequately address the risk-based performance standards in (2)(A), the Secretary will:

(A) provide detailed explanations about the deficiencies in the cybersecurity plan to any requestor whose cybersecurity plan did not adequately address the risk-based performance standards in (A); and

(B) ensure that requesters will be provided one opportunity to modify their proposed cybersecurity plans if the Secretary finds that they do not meet the risk-based performance measures outlined in the guidelines; and

(6) Nothing in this bill would authorize the Secretary to require the use of these guidelines by any entity that is not applying for financial assistance under the program described in (a).

I know, I cribbed the basic idea from the Chemical Facility Anti-Terrorism Standards (CFATS) program, but it is probably the best way to craft standards that would have applicability to a wide variety of varied installations.

 
/* Use this with templates/template-twocol.html */