Thursday, May 13, 2010

Additional CSB IST Study Comments

With the final day for submitting comments on the proposed National Academy of Sciences study on the IST situation at the Bayer CropScience facility in Institute, WV the Chemical Safety Board posted a second batch of comments that it has already received. The nine included in this file bring the total to 20 comments received to date.

I am happy to see that there are some major players on both sides of the IST debate that are included in the second batch of submissions, including the ACC, Greenpeace, API/NPRA and the AFL-CIO. Still nothing from Bayer, but they may be maintaining a low profile on this matter. I’m surprised though that they haven’t at least submitted a letter confirming their support for such a study; that would seem to me to be a PR101 requirement.

Well, we still have today for submissions, so I expect that there will be at least one more batch of comments posted on the CSB web site, perhaps tomorrow or next Monday. If we continue to get the major player’s views on the record, I’ll withdraw my earlier complaint about the short time frame for the comment submission process.

Top Screen CVI

The latest posting on the Chemical Security Action Blog by Ryan Loughin takes a look at the CFATS Top Screen. While the vast majority of initial Top Screens have already been submitted, there will be a number of new facilities submitting their first Top Screens every month. This blog will be a valuable initial source of information for those first time submitters. Having said that, I do have a tiny nit to pick with one piece of information that Ryan includes in this post. He states that “that the person filling out the Top-Screen questionnaire must be Chemical-terrorism Vulnerability Information (CVI) authorized”. Then he explains that this “means someone who has had training by DHS on the handling of sensitive material and information”. It is that last statement that I have a minor, technical problem with. According to the Top Screen Users Manual, a first time Top Screen submitter must accept the “CSAT Top-Screen Authorizing Statements” found on the initial Top Screen page to become an “authorized user of CVI for access to CVI created by the completion of the CSAT Top-Screen” (pg 12). Now the Authorizing Statements summarize the information provided in the CVI training, but they are not a substitute for completing the training. If the facility is declared a high-risk facility, the Submitter and Preparer will have to complete the actual CVI training before they are allowed into the more advanced tools in the Chemical Security Assessment Tool (CSAT). DHS set the Top Screen CVI requirements up this way to avoid having to require tens of thousands of people to complete CVI training that would never require access to CVI beyond the letter from DHS stating that they are not a covered facility under CFATS. According to the Top Screen Users Manual, now that the initial surge of Top Screen submissions is complete, the CVI requirements may be changing: “DHS expects that in the near future access to the Top-Screen will be limited to only CVI Authorized Users that have completed the CVI training and received a CVI Authorized User Number.” (pg 12) When that happens Ryan’s post will be 100% correct instead of ‘just’ 99.99% correct. Besides, completing the full CVI training is probably a good idea for the first time Top Screen user in any case.

Wednesday, May 12, 2010

Check Your Barrier Plan

There is an interesting article over at WashingtonPost.com about a recent vehicular accident at the Hirshhorn Museum in Washington, DC. It seems that last Tuesday a UPS delivery vehicle plowed through the “building's 1,200-pound cement security planters” and then entered the glass wall at the front of the building. No word yet what caused the accident, but no one thinks that terrorists were involved (I guess since there were no bombs or weapons in the truck). Well, it turns out that these weren’t the real security barriers; these are temporary (since 2003, I lived in WWII vintage temporary military barracks like that once, twice; oh well you get the idea). The real ones will get funded in a “future fiscal year” according to a Smithsonian spokesperson. Well, I could go on making fun of the Smithsonian and their security, but it wouldn’t really be fair. I don’t know what kind of threat assessment was done for the building. Depending on that assessment, these ‘visual deterrents’ may have been deemed to be perfectly adequate for the threat facing that facility. Besides; real barriers cost real money. Check Your Barriers Planters are one of the anti-vehicular barriers listed in Table C-1 (pg 149-50) of the RBPS Guidance Document. Unfortunately, just because something with that name is listed does not mean that your planter/barrier is going to stop the proverbial truck borne IED. If they are just sitting on top of a paved surface they will probably be able to be shoved around just as well as the ones at the Hirshhorn. The people who installed your barriers should be able to tell you the K-Rating for the barrier. You’ll need to have selected the appropriate K-Rating for your facility based upon the maximum speed that a VBIED (vehicle borne IED) could approach the area where the barrier is located. Note: the K-Rating is briefly explained on page 150 of the RBPS Guidance Document. A reasonable rule of thumb is that if they didn’t have to dig up something to ‘attach’ the barrier to your facility, then you probably have one of those visual deterrents.

DHS HSAC Teleconference 05-27-10

The Department of Homeland Security posted a notice in today’s Federal register that the Homeland Security Advisory Council will be holding a teleconference on May 27th to receive and discuss the final report of their DHS Quadrennial Review Advisory Committee. Pre-registered public participation in the teleconference is authorized. To register, individuals must submit their full legal name, email number, and phone number to a HSAC staff member by email (HSAC@dhs.gov) or phone {(202) 447-3135} no later than 5:00 pm EDT on May 25th. Written comments can be submitted via www.Regulations.gov (Docket Number DHS-2010-0039).

Tuesday, May 11, 2010

High-Tech, High-Res

There is an interesting article over on HomelandSecurityNewsWire.com about a new surveillance camera being developed by DHS S&T. It is a new 360 surveillance video camera that is able to provide high-quality videos over the whole range of the camera while allowing high-quality live-zooms in one area while continuing to record in other areas. According to the article, this sounds like a security officer’s answer to video surveillance prayers. Now I am not a video surveillance expert, but I think that I know enough to pick out a couple of obvious problems that will limit deployment of this new system. First off, the camera system, ISIS (Imaging System for Immersive Surveillance) does provide huge amounts of detail, up to 100 megapixels according to the S&T web site. According to the S&T program director that is “as detailed as 50 full-HDTV movies playing at once”. That much information flowing from the camera to the security station is sure to take up massive amounts of bandwidth. That much bandwidth will almost certainly require a dedicated hard line from the camera to the security station; not a simple network connection. Even at-camera data compression will be inadequate to this task unless the video quality is degraded so much that it is just another 360 surveillance camera. Likewise, data storage is going to get expensive quickly. Every minute of stored observation for this one ‘camera’ will take up as much storage as 50 standard megapixel cameras. Once again, data compression can reduce that significantly, but only at the cost of lost detail. As a security-detection tool it is going to have the problem of providing a method for security team members to provide real-time surveillance over the observed area; data display and data density problems will be difficult to overcome. Both the article and the S&T web site explain that video analytics will help with that problem. Unfortunately, the infamous ‘guy changing his shirt in Time Square’ shows the limitations of using a video analytics model. No, the best use of ISIS will be in video forensics, determining what actually happened in an area after the event. Even then it will only be of real use in large wide open areas where there are few visual obstructions. There it will allow for continuous tracking and recording of the movement of a pre-identified individual through an area without the problem of handing off the target from one camera to another.

CFATS Background Check Comments

There are only two days left on the 30-day comment period on the information collection request posted by ISCD for the proposed CFATS background check tool. So far, only one comment has been posted on the www.Regulations.gov web site (docket # DHS-2009-0026); the Institute for Manufacturers of Explosives’ comment was posted on the site today. As I noted last year during the comment period for the 60-day notice these ICR requests seldom garner any comments, but this is a hot button issue within the chemical security community. I expect that the IME comments are just the first of many that will start to flow into the site. The regulated community certainly deserves it’s say during the consideration of deploying this tool, but it will be just another delay in the full-blown implementation of the CFATS program. Another delay that Congress will not doubt complain about, but that’s the way things go. The CFATS program is a complex operation with very little in the way of Congressional guidance. DHS has had to write a regulatory scheme, implement a number of innovative data collection tools, build an inspection team and deal with a budgetary process that made advance planning very difficult. Oh, and face an impending program authority expiration date because Congress cannot write permanently authorizing legislation that will pass political muster.

DHS-CERT CSSP Calendar Page Update 05-11-10

The DHS-CERT Control System Security Program has updated their Calendar web page. They have had June training date posted for their Introduction to Industrial Control Systems Cybersecurity for Federal Employees class for almost a week now, but today they have added a class description and registration information. It’s kind of odd since a July training date has had this type information available since last month.

Of course, the July training is an advance class that lasts five days and is being held in the Idaho Falls, ID training center. The June 9th class will be held in Washington, DC and it will be an introductory course. These classes are for Federal employees and contractors and are free of charge. Only a limited number of spaces are available. As DHS and the rest of the Federal Government ramp up the number of employees available for cyber security duties, classes like these are going to be very valuable. As I noted in my blog about the July class, I certainly recommend that ISCD get as many of their chemical inspectors to these classes as possible. Last week I explained that there is a weakness in the CFATS inspection program because of the dearth of qualified ICS security experts to conduct SSP inspections. These CERT classes will be invaluable in correcting that situation. As always, I would really like to hear from any readers that attend these classes. I would like to hear the gory details of how well these classes are taught and how comprehensive the coverage is. As a professional instructor I know that student feedback is not necessarily a good gauge of instructional performance, but it is one of the few metrics to which I will have access.

 
/* Use this with templates/template-twocol.html */