Thursday, March 2, 2023

Review - CSB Publishes 60-day ICR Renewal Notice for Chemical Incident Reporting

Today, the Chemical Safety and Hazard Investigation Board (CSB) published a 60-day information collection renewal notice in the Federal Register (88 FR 13086) for their “CSB Accidental Release Reporting Form”. This is the first renewal (there was a revision in 2021, but it did not change any burden information) for this collection since it was initially approved in 2020). A downward revision of the burden estimate is included in this notice.

The CSB is soliciting public comments on this ICR renewal. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # CSB_FRDOC_0001-0028). Comments should be submitted by April 28th, 2023.

 

For more details about the revision of the burden estimate, including a discussion of the basis for the change, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/csb-publishes-60-day-icr-renewal - subscription required.

Review – 4 Advisories and 1 Update – 3-2-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Rittal, Baicells, and Mitsubishi. They also published a medical device security advisory for products from Medtronic. They updated a control system security advisory for products from Mitsubishi.

Advisories

Rittal Advisory - This advisory describes an improper access control vulnerability in the Rittal CMC III locks.

Baicells Advisory - This advisory described a command injection vulnerability in the Baicells LTE TDD eNodeB devices.

Mitsubishi Advisory - This advisory describes a plain-text storage of a password vulnerability in the Mitsubishi Electric MELSEC iQ-F products.

Medtronic Advisory - This advisory describes an unverified password change vulnerability in the Medtronic Micros Clinician (A51200) app and InterStim X Clinician (A51300).

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on November 22nd, 2022.

 

For more details on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-3-2-23 - subscription required.

Bills Introduced – 3-1-23

Yesterday, with both the House and Senate in session, there were 127 bills introduced. Three of those bills may receive additional coverage in this blog:

HR 1285 To require a report from the Secretary of Homeland Security on the existence of programs and components of the Department of Homeland Security that are not explicitly authorized in statute. Donalds, Byron [Rep.-R-FL-19]

HR 1288 To amend the Chemical and Biological Weapons Control and Warfare Elimination Act of 1991 to impose sanctions against governments of foreign states that engage in an act or acts of gross negligence with respect to state owned, operated, or directed chemical or biological programs. Feenstra, Randy [Rep.-R-IA-4]

S 576 A bill to enhance safety requirements for trains transporting hazardous materials, and for other purposes. Brown, Sherrod [Sen.-D-OH]

I will be covering HR 1285 and S 576.

I suspect that HR 1288 will be dealing with responding to the reported release of COVID-19 from Chines labs. I will  be covering this bill if the language or definitions specifically include large scale chemical manufacturing releases in the ‘act or acts of gross negligence’ scope of the bill.

NOTE: The House will not be in session today and will meet in pro forma session on Friday.

NOTE: Corrected date in Title, 06:35 3-3-23

Wednesday, March 1, 2023

Short Takes – 3-1-23

Hackers Claim They Breached T-Mobile More Than 100 Times in 2022. KrebsOnSecurity.com article. Pull quote: ““They underestimate these actors and say this person isn’t technically sophisticated,” she [Allison Nixon] said. “But if you’re rolling around in millions worth of stolen crypto currency, you can buy that sophistication. I know for a fact some of these compromises were at the hands of these ‘script kiddies,’ but they’re not ripping off other people’s scripts so much as hiring people to make scripts for them. And they don’t care what gets the job done, as long as they get to steal the money.””

Dow and X-energy to build U.S. Gulf Coast nuclear demonstration plant. Reuters.com article. Possible CFATS implications? Pull quote: “The X-energy plant will provide a Dow facility with process heat and power to make products. Dow, a chemicals company, makes a wide variety of products including polyethylene used in packaging, paints, and foams.”

In an Epic Battle of Tanks, Russia Was Routed, Repeating Earlier Mistakes. NYTimes.com article. Pull quote: “A three-week battle on a plain near the coal-mining town of Vuhledar in southern Ukraine produced what Ukrainian officials say was the biggest tank battle of the war so far, and a stinging setback for the Russians.”

Russia claims an “external impact” damaged its Progress spacecraft. ArsTEchnia.com article. Pull quote: “Moreover, if there are so many micrometeorites intersecting with the space station's orbit, why is the outpost not riddled with holes? NASA does not presently have a sensor or other means of recording hits to the ISS unless they cause notable damage. But given that the Soyuz and Progress vehicles only make up 1 percent or less of the station's footprint in space, the ISS would likely be incurring significant damage if there was a cloud of micrometeorites or debris.”

OCS Updates FAQ Response – 3-1-23

Today, CISA’s Office of Chemical Security (OCS) published an updated responses to a FAQ on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The revised FAQ responses were for FAQ #1275. This is the same FAQ that was ‘updated’ yesterday. Yesterday’s non-update is no longer listed.

FAQ #1275 What needs to be done with the facility ID in the Chemical Security Assessment Tool (CSAT) when a covered chemical facility is bought or sold?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ, you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

For the most part the changes in the response are wording changes that clarify the status of the ‘buyer’ and ‘seller’ {for example changing the word ‘buyer’ to ‘new owner/operator (buyer)’ in the initial discussion for Option 1}.

A slightly more complex change is made in the discussion of the requirements for Option 1. It changes the sentence:

“The buyer should explain that his organization is willing to assume the ID and take responsibility for the submitted and the future surveys and should explicitly document that the COI holdings and facility operations will remain the same.”

To read:

“The buyer should explain that the new organization is willing to assume the existing ID and take responsibility for surveys submitted by the seller. The buyer should explicitly document that the COI holdings and facility operations remain the same or submit a new survey if the buyer intends to make material modifications to its operations or site.”

Finally, a new sentence is added to the end of that discussion:

“If the buyer is unable to obtain a letter and/or contact information from the seller, then the buyer should include a statement in their letter accounting for this.”

Bills Introduced – 2-28-23

Yesterday, with both the House and Senate in Washington, there were 96 bills introduced. Two of those bills will receive additional coverage in this blog:

HR 1238 To direct the Secretary of Transportation to issue certain regulations to define high-hazard flammable train, and for other purposes. Deluzio, Christopher R. [Rep.-D-PA-17] 

S 559 A bill to amend the Federal Fire Prevention and Control Act of 1974 to authorize appropriations for the United States Fire Administration and firefighter assistance grant programs. Peters, Gary C. [Sen.-D-MI]

Bills Introduced – 2-27-23

On Monday, with both the House and Senate in session, there were 57 bills introduced. One of those bills will see additional coverage in this blog:

HR 1219 To establish a food and agriculture cybersecurity clearinghouse in the National Telecommunications and Information Administration, and for other purposes. Pfluger, August [Rep.-R-TX-11]

 
/* Use this with templates/template-twocol.html */