Tuesday, February 9, 2010

HR 4580 Introduced

Last week Congressman Markey (D,MA) introduced HR 4580, the Metropolitan Medical Response System Act of 2010. This bill would authorize the currently existing MMRS program that is administered under FEMA. The program was started under the Department of Health and Human Services (HHS) in 1996 and currently funds programs in 124 jurisdictions around the country. According to the findings section of this bill:
“The Metropolitan Medical Response System (MMRS) is the only program at the Federal level that supports the integration of local emergency management, law enforcement, and health and medical systems into a coordinated response to a mass casualty event caused by a weapon of mass destruction, an incident involving hazardous materials, an epidemic disease outbreak, or a natural disaster.” {§2(2)}
The bill notes that MMRS program “provides tangible benefits in the form of increased operational capacity and communication, improved personnel training, stockpiled pharmaceuticals, and adequate supplies of personal protective equipment and other specialized response equipment” {§2(5)}. The FY 2010 funding for this program was provided by the Homeland Security Grant Program (HSGP). A total of $39,359,956 in MMRS grants will be split evenly between the 124 agencies currently enrolled in the program. CFATS and Emergency Response While the bill lists a variety of federal programs that are supported by the existing MMRS grants, there is, unfortunately, no mention of how the program could support emergency response planning for high-risk chemical facilities covered under CFATS. This is somewhat surprising since Congressman Markey was so involved in the development and passage of HR 2868, a bill to extend the scope of CFATS authorization, in the House. I have often commented that emergency response planning has got to be a key component of any security plan. When most people think of emergency response they think of police, fire, and EMT personnel. What is typically missed is what happens after casualties are removed from the incident scene. After all, don’t doctors know how to treat casualties? Casualties from a chemical incident (terrorist or accident, it doesn’t make any difference) are going to present a wide variety of injuries and symptoms depending on the chemical involved. Toxic chemicals may present special challenges because of the wide variety of potential effects the patients will experience based on the type and extent of the exposure they experience. Lacking specific training for proper detection, diagnosis and treatment for the exposure to the specific chemicals involved, medical personnel may not be able to provide adequate medical care. It is absolutely critical that the medical personnel that will be performing triage, diagnosis and treatment are trained in advance on the proper responses to the chemical exposure for the potentially wide variety of chemicals found at a modern chemical facility. This can only happen when the medical management team is aware of the chemicals found at facilities within its service area and that requires communication with the chemical facilities. While all chemical facilities should be communicating with their supporting services as part of their facility emergency response planning, there is a special responsibility for facilities covered under CFATS regulations. By definition they have been identified as being at high-risk for a terrorist attack and their emergency response planning takes on a special significance because of that. High-risk facilities with release-toxic chemicals of interest (COI) should expect that terrorists would attempt to conduct an attack that would result in the release of those toxic COI. Thus, the medical community absolutely needs to be informed in advance of those COI. CFATS and MMRS Since the MMRS program is designed to provide support for mechanisms for coordinated emergency response functions to include the whole response community, specifically including hospitals, this legislation might be an appropriate place to address requirements for emergency response planning for CFATS facilities. Suggested provisions for CFATS emergency response planning would include:
Requiring each MMRS organization to establish a CFATS planning team, members of the team would include emergency response and medical members who have completed Chemical-Terrorism Vulnerability Information (CVI) training/certification; Requiring each CFATS facility with release-toxic COI on site to provide a list of all such chemicals to the local MMRS CFATS planning team; Requiring the MMRS CFATS planning team to develop a plan for dealing with chemical casualties for exposure to each of the release-toxic COI that have been identified in the team’s service area; Requiring the MMRS CFATS planning team to be involved in the planning for emergency response exercises conducted at CFATS facilities in the team’s service area; and Requiring DHS Chemical Facility Inspectors to include a review of MMRS CFATS planning team efforts in any inspection/evaluation of a CFATS facility containing release-toxic COI.

ICS Security Book

This last weekend Joe Weiss, a vocal expert on industrial control system (ICS) security issues, announced that his new book on ICS security has an announced publication date of April 10th, 2010. According to the publisher’s web site the book, Protecting Industrial Control Systems from Electronic Threats, will be aimed “at both the novice and expert in IT security and industrial control systems (ICS), this book will help readers gain a better understanding of protecting ICSs from electronic threats[emphasis added]”. I think that it is interesting that both Joe and his publisher are avoiding the claim that this is directed at terrorist threats. Joe has long been vocal in noting that both deliberate and accidental electronic threats exist against which ICS systems must be protected. The publisher, Momentum Press, also notes that the book addresses:
•“How to better understand the convergence between Industrial Control Systems (ICS) and general IT systems •“Insight into educational needs and certifications •“How to conduct Risk and Vulnerability Assessments •“Descriptions and observations from malicious and unintentional ICS cyber incidents •“Recommendations for securing ICS”
The book will be available in both soft-cover and electronic versions. Advance orders are being accepted.

Snow Days for Congress

Vincent Morris, the spokesman for the House Rules Committee just posted the following on Twitter: “it's official - no votes the rest of the week. Snow storm threat closes down house business. Also rules meeting on intell & anti-trust off “. This is hardly surprising, with a forecast for a foot of snow this evening, on top of almost 3 foot of snow last weekend; all of Washington will probably be taking a couple more days off. No word yet if today’s House session will resume at 2:00 pm as scheduled or if there will be pro-forma sessions the rest of the week. None of the Congressional web sites that I have checked note anything about a snow closure. A Senate Homeland Security Committee Subcommittee hearing today was postponed with a new date and time ‘to be determined’. The chemical security type hearings that I have reported on for this week are still being listed as ‘scheduled’. I expect that the only one that might happen is today’s hearing before the Homeland Security Subcommittee on the DHS budget at 3:00 pm EST. LATE NOTE: The House adjorned after a proforma session at 2:00 pm EST. Next business day will be Monday, February 22nd.

Reader Comment – 02-04-10 Ammonium Nitrate

Still catching up on reader comments from last week. Laurie Thomas left a comment on the IED Training blog. She noted that:
“Anyone who wants to have their eyes opened about IED's on U. S. soil needs to take about ten minutes and simply do an internet search on stolen ammonium nitrate. Big amounts here, big amounts there. Some large enough to warrant DHS threat directives. The first hit is, "Canada - 2 tons of ammonium nitrate possibly still missing?" What is scarier, that people are walking away with the stuff; or that despite all our precautions and programs our accounting is so porous that we just don't know how much of the stuff is supposed to be on hand?”
Both theft and loss of ammonium nitrate (AN) are potential problems for security personnel that are trying to prevent IED attacks across the country. Currently the only controls in place on the sale or transfer of AN are voluntary measures put into place by the AN industry and some State controls. Clearly, these are not adequate security procedures.

One of the major problems facing DHS in establishing their regulation of AN is how to deal with the bulk shipment and transfer of this solid material. AN fertilizer is used in very large quantities in many areas of the country and is sold by barge and truck load quantities. The controls on transfers of such large quantities are going to be difficult to establish in such a manner so as to allow the detection of theft or diversion of amounts that can be used in relatively large IEDs or even in small VBIEDs.

Even where AN is used in smaller packaged quantities, it is going to be difficult to convince users to establish the level of inventory controls necessary to detect the theft and/or diversion of IED quantities of AN. Because of the significant change in handling procedures required to affect this level of inventory control it will take a significant sized inspection force to enforce the new regulations; an inspection force that Congress has not allowed for in their funding for this program. 

DHS has its work cut out for it as it tries to develop regulations designed to prevent the theft and diversion of this commodity chemical that can be readily converted to a powerful explosive.

Monday, February 8, 2010

Congressional Hearings – Week of 02-08-10

If Congress can get back into town after this weekend’s snow storm, it looks like committee work will start to pick back up. For the chemical security community there will be multiple appearances by Secretary Napolitano explaining the Obama Administration’s DHS FY 2011 Budget request and a Judiciary Committee meeting on counter-terrorism information. Budget Hearings In addition to the two committee hearings on the budget that I mentioned last week there is one more Secretarial appearance on the schedule. The Secretary will appear before the House Appropriations Sub-Committee on Homeland Security on Tuesday at 3:00 pm EST. Once again, there will probably be little mention of the CFATS program funding in this hearing, but someone might ask a question or two about the extension of the CFATS authorization. I expect that the written testimony provided by Napolitano will be the same for all three hearings this week. Information Sharing The House Judiciary Committee will be holding a hearing on Wednesday the 10th at 10:00 am EST entitled: “Sharing and Analyzing Information to Prevent Terrorism”. Currently that is the only information available. I suspect that this might be just another hearing on the lack of information sharing that lead up to the Underwear Bomber fiasco, but it could easily encompass more than that looking at the title. We’ll know more when they publish their witness list later in the week.

Reader Comment – 02-03-10 Cyber Sec Resp 2

Last week (sorry for the delay in mentioning this) D3 left another comment in our conversation about cyber security responsibility. As usual the comments are worth going back and reading. D3’s closing remark in the comment is worth some discussion here on this blog. D3 closed by saying: “I just think that we in the security industry (whether general or specific) need to observe the entire spectrum of issues.” Cyber security issues have an impact on almost every other security procedure or control system at high-risk facilities. Ignoring for the moment the security of our industrial control systems, facilities might use computer based security systems to control facility access, monitor security cameras and other security monitoring systems. This means that the security of those systems must also be assured. To ensure that COI shipped from the facility only go to legitimate, vetted customers, we use a variety of computer based inventory and customer management systems. The security of these systems must also be assured. All of these disparate computer systems require both system security and physical security measures to adequately protect them against attack. The necessary security measures for these systems must include personnel surety controls for those with physical or electronic access to the systems. One area of cyber security that is nearly always ignored when discussing facility security issues is the issue of identity theft. This can affect facility security in two different areas. The most obvious is the identity theft of current employees. While the employees will be most concerned with the affect on their personal finances, facility security personnel should be concerned with the compromise of electronic access to protected cyber systems. Identity theft can result in an even more basic compromise of the facility security when new employees use a fake identity to get a job at the facility. There are frequent stories in the national news about illegal immigrants using stolen identities to gain jobs. If it is that easy for the run of the mill illegal to gain access to identity documents, how easy would it be for a terrorist or terrorist supporter to do the same to gain ‘legitimate’ access to high-risk chemical facilities? So, D3 is correct, security managers need to cast a wide net in the security concerns that they have to take into account when managing the security program for high-risk chemical facilities. The wide diversity of cyber security issues is just one example.

UK vs Terrorist Web Pages

Thanks to a tweet by HSPI I found the “Reporting Terrorist Material Online” web page posted by the British Government that calls for the assistance of the British public in shutting down inappropriate terrorist web sites. This is an attempt by the Brits to shut down the online spread of the radical-Jihadist message that helps provide for the radicalization of individual Muslims that may become lone-wolf terrorists. The website makes the distinction between illegal (under British law) and offensive web sites. The site provides a definition of what constitutes an illegal website and a link to a page for reporting such sites. It also gives instructions for what to do if an individual finds a legal site to be offensive. This includes recommending that the individual contact the web site administrator or the website hosting company to register their complaint. The description of what would be considered an illegal web site is broad enough so that it is almost certain that some legal web sites would be included in those reported by the public. I think that it would be safe to assume that the British intelligence folks would like to use this as a method to identify new web sites for them to monitor as part of their counter-terrorism intelligence collection plan. The inclusion of the listing of techniques to get rid of legal, but offensive web sites is an interesting technique. It provides a way of extending the assault on ‘terrorist’ web pages while minimizing the potential for charges of censorship against the government. If it is the private sector that is taking down the offensive site it cannot be considered government censorship. I am not sure that the US Government could pursue a similar method of attacking Jihadist web sites. I am not aware of specific legislation similar to what the Brits have (the Terrorism Act 2000 and the Terrorism Act 2006) that would specifically outlaw terrorist web sites. Even the suggestions for private actions against offensive web sites would probably be attacked in the US as an impermissible government interference with free speech. Intelligence agencies, however, have a legitimate right to monitor anti-government rhetoric publicly posted on the internet. Conversations that take place in public chatrooms provide no expectation of privacy that would protect the speech from surreptitious monitoring by such agencies. Similarly, publicly posted web sites are available for all to see, so no one could reasonably object to intelligence agencies monitoring the information on such sites. With that in mind, it might be a good idea to provide the web surfing public in the United States with a mechanism for reporting violent Jihadist web sites that they encounter during their electronic travels. While one would suspect that most sites reported would already have been identified by intelligence agencies, this would provide another mechanism for identifying new web sites that crop up.

 
/* Use this with templates/template-twocol.html */