Sunday, June 23, 2013

Comments for TWIC Reader NPRM – 6-22-13

This is part of a continuing series of blog posts on the public comments filed in the previous week for the Coast Guard’s TWIC Reader NPRM. The previous posts in the series are listed below.


There were 10 comments posted this week, a record for this docket but hardly a major closing comment period for a rule that has been as long awaited or as recently debated in Congress as this one.  Maybe the port security community knows more about the TWIC Reader than does Congress or the GAO.

Address GAO Report Concerns

A chemical bulk terminal operator recommends that the final rule be delayed until the Coast Guard and TSA have a chance to address the concerns expressed in the recent GAO report on the TWIC Reader Pilot. This argument was also raised by a member of Congress, a barge operator.

Expand TWIC Reader Requirements

A port security consultant recommends that the TWIC Reader requirements be extended to any Group B or C facility that shares a fence line with a Risk Group A facility. They argue that the common fence line would be easier to access from a lower risk facility if that facility does not require biometric verification of identity and TWIC status. They also argue that each Risk Group B and C facility be required to have one portable TWIC Reader available to respond to sudden changes is security situation that might require the deployment of a TWIC Reader.

An identification card vendor association make the point that Congress did not specify differing security standards based upon some arbitrary risk group ranking. They note that the use of the TWIC as a visual flash pass ID makes it no more useful than any other printed ID card.

Multiple Entries

The chemical bulk terminal operator recommends that the multiple entry rule be changed to require that only during the initial entry to a facility in a 24-hour period should an individual have to utilize a TWIC Reader to gain access. During subsequent entries the TWIC could be used as a flash pass in accordance with USCG Policy Advisory Council (PAC) 08-09 [No link available, I’m sorry, but the CG Homeport page does not provide for permanent links to documents].

A local water taxi company makes a point made in multiple earlier comments that requiring the showing of a TWIC upon every entry to secured spaces on smaller vessels with limited crews makes no sense.

Exempt Smaller Facilities

A marine service organization thinks that automatically making barge fleeting facilities that handle Certain Dangerous Cargo (CDC) Risk Group A facilities ignores the security realities of these facilities, particularly the limited access that is available. An Alaskan cruise line operator expresses the same concern for small cruise facilities.

Crewmember Definition


The barge operator would like to see the final rule include a definition of ‘crewmember’ based upon the definition in Navigation Vessel Inspection Circular 03-07. This is particularly important when considering the 14-crewmember exemption for requiring a TWIC Reader on Risk Group A vessels.

Homemade Chemical Bombs

This is a little bit out of the terrorism realm, but there is an interesting article about ‘homemade chemical bombs’ in the most recent CDC Morbidity and Mortality Weekly Report. These really are not improvised explosive devices, they don’t have that kind of power, but they do cause casualties in middle-America on a fairly routine basis.

Generally speaking these ‘devices’ are not truly explosives because fire is not involved. Some sort of simple chemical reaction (or phase change) causes the production of a gas. The amount of gas produced in a closed container many cause a catastrophic failure of the container, accompanied by a loud bang (or soft boom) and frequently a visible gas cloud. That gas cloud is usually responsible for the more serious injuries associated with these devices because of the toxicity of the gas.

There is little authorities can do to prevent teenagers (chronological or developmental) from constructing these devices. The components are readily available in the home or hardware store. The more effective of these devices (measured by the sound of the boom or size of the gas cloud) do require slightly more expensive chemicals, but these can usually be obtained from high school or college chemical store rooms.

Frequently these ‘bombs’ are made in plastic soda bottles so they have a relative low probability of causing blast or shrapnel type injuries. When made in glass containers or PVC pipe there is a low-level shrapnel (Purists please don’t’ complain that ‘Shrapnel’ comes from a specific type of Civil War era munition, common usage includes flying pieces of bomb casings of any type) hazard, but only very close to the detonating device.

Having played with these things in my youth (long before the Internet we had Headly’s Formulary or the Anarchist’s Cookbook) I can testify that most of the people injured by these devices are the ‘bombers’. These devices typically don’t include fuses; they rely on the speed of chemical reactions and the quality of the ‘bomb case’ to determine when they will actually ‘detonate’; too many variables for the limited attention span of teenagers to perfect.

They are potentially dangerous, the danger increasing as you get closer to the device. The biggest danger to first responders is not being able to tell in advance what the resulting chemical cloud will be. The CO2 cloud from a ‘dry-ice’ bomb is relatively non-hazardous; the chlorine gas from a bleach-bomb can be toxic to severely irritating depending on the amount produced and local ventilation conditions.

There is one type of these chemical bombs that is slightly more dangerous and that is because it produces a very flammable hydrogen gas-cloud. The initial detonation of these ‘aluminum’ bombs is the typical gas pressure reaction, but the resulting gas cloud (depending on local conditions) can result in a secondary explosion producing fire and flying debris.  


All first responders and emergency medical personnel should read the CDC article.

Comments on Proposed Revisions to NIPP – 6-22-13

This is the first in a series of blog posts about the public comments posted to the DHS proposed revisions to the National Infrastructure Protection Plan (NIPP).

We are now a little over a week into the one month comment period and four comments, all from individuals, have been posted to the Federal eRulemaking Portal for this docket. None of them is particularly responsive to the proposed revisions to the NIPP. We do have suggestions for:

• Building sea water canals into the interior of Western Africa to help prevent hurricanes along the East Coast and Gulf Coast of the United States;
• Providing more public availability of severe weather warnings;
• Placing educational institutions in their own Critical Infrastructure Sector (okay this comes close to what the NIPP is all about); and
• Making it a federal criminal offense to undertake a variety of criminal actions on, at or against Critical Infrastructure facilities (it takes Congress to enact criminal statutes).

The main problem with these suggestions is that they actually propose specific actions to be taken by the Federal Government. Anyone that has managed to stay awake long enough to read the current NIPP (and I am not one of that very limited number) would understand that this is a bureaucratic statement of general policy that is flexible enough to cover just about any action the Federal Government takes or doesn’t take with regards to Homeland Security.


I suspect that in the coming weeks we will see comments from a number of NGOs and contractors suggesting additions that would favor their pet projects. That is what we saw during the comment period for the last update in 2008.

Saturday, June 22, 2013

Unannounced Changes to CFATS Web Sites

I noted earlier this week that DHS had apparently made changes to their Chemical Security web page. After looking at a number of other CFATS related web sites this morning, it is fairly clear that DHS has made changes to a number of their web pages. Most of these are cosmetic and all remove the “Welcome to the new DHS Web Site – Give us your feedback” banner that was put on the pages during the last wholesale revision of the DHS web site.

There are two changes associated with the Security Vulnerability Assessment Tool web site that deserve some attention; the wording revision on the page and a change in one of the links.

SVA Wording Change

The SVA page from last year included the following ‘schedule’ for the submission of SVA’a following the DHS notification of initial high-risk assessment and tier assignment:

• Preliminary Tier 1 facilities have 90 days to complete and submit a CSAT SVA from the date of written notification
• Preliminary Tier 2 facilities have 120 days to complete and submit a CSAT SVA from the date of written notification
• Preliminary Tier 3 facilities have 150 days to complete and submit a CSAT SVA from the date of written notification
• Preliminary Tier 4 facilities have 180 days to complete and submit a CSAT SVA from the date of written notification or a Department-approved Alternative Security Program (ASP)

The new page simply states: “Unless specifically notified by the Department to the contrary, the SVA must be submitted within 90 calendar days from the date of written notification.”

The new page requirement is certainly in line with the requirements set forth in the CFATS regulations {§27.210(b)(2)}. The old page explained the laxer requirements by stating: “These deadlines were established by the Assistant Secretary of Infrastructure Protection consistent with his discretion under the Interim Final Rule, published on June 8, 2007.”

The staged submission requirements reflected the fact that DHS was having severe difficulties in getting the reviews completed on the existing Site Security Plans and thus the Department wanted to concentrate its efforts on the highest risk facilities throughout the review process. Now that the Department is starting to clear its backlog of SSP reviews they will have more assets available to concentrate on SVA reviews as well so the staged submission deadline is no longer warranted.

While the change is policy is almost certainly justified, there has been no formal notification that the policy has changed. I understand that a schedule printed on an official web site does not carry the same weight as a published regulation, but there was still a change in policy made and the community deserves formal notification of that change.

Manual Change

Both the old and new versions of the web site contain links to the SVA Questions Manual:

• Older version - Review CSAT SVA Questions (PDF, 107 pages - 1.26 MB)
• Newer version - Review CSAT SVA Questions (PDF, 105 pages - 368 KB)

It is clear that the descriptions are different and quick looks at each manual (both links are currently working) show that they are indeed different. I have not had a chance to determine specifically how different, but they are not identical, even though they both have the same date and version numbers printed in the document.


Once again, change is a necessary thing, but the community deserves and requires explanation when changes are made and why they happen. This is not currently happening and that is disturbing to say the least.

NIST Framework Development Update – 06-22-13

Earlier this week the National Institute of Standards and Technology published a brief update about the development of the Cybersecurity Framework on their web site. The update provides a brief discussion of where the process currently is and how NIST intends to get to the required publication of the Framework. This is part of NIST’s commendable attempt to keep the cybersecurity community engaged in the process.

Cybersecurity Framework Elements

The important new information in this update is a listing of the elements that NIST intends to include in their draft Framework. While most of this was outlined in the President’s Executive Order (EO 13636), this update provides a little more meat to the bare bones provided by the President. Abstracting that information further, the NIST Framework will:

• Identify effective existing practices to inform an organization’s risk management decisions;
• Provide a modular and flexible approach to enable organizations to relate cybersecurity needs to diverse sector and organization business drivers;
• Reinforce cybersecurity risk management as it relates to the enterprise risk management processes of an organization;
• Provide a means for an organization to express the maturity of their cybersecurity risk management practices;
• Include workforce considerations; and
• Address the need for organizations to manage the various types of dependencies, including those related to providers, processes, and technologies.

Workforce Considerations

The brief discussion of the workforce considerations deserves special emphasis. This document makes it clear that the Cybersecurity Framework will address to separate levels of training requirements. First there will be the general awareness of cybersecurity requirements that all personnel with access to the critical cyber-systems will have to undergo. Interestingly the update makes it clear that the ‘all personnel’ should include “employees, partners, and customers” that have system access.

The second level of training will have to focus on ‘cybersecurity personnel’. The update notes that “the cybersecurity workforce must be trained and must maintain the skills necessary to understand the operating environment, the threats and vulnerabilities to that environment, and the practices available to combat those threats and vulnerabilities” (pg 2). The development of this type of training is one of the areas that NIST should stress in their proposed Federally Funded Research and Development Center (FFRDC). At the very least there is going to have to be some sort of federal support and guidance in the development of this professional workforce training program.

NIST Still Looking for Information

The update makes it clear that NIST is not done with the information collection phase of its process development (and hopefully this indicates the realization that such information collection efforts will have to continue to be an integral part of the Framework). Specifically NIST is looking for additional input in the following areas:

• The identification and availability of foundational cybersecurity practices;
• The actionable expression and management of privacy and civil liberties needs;
• The availability of outcome-oriented metrics that leaders can use in evaluating the position and progress of the organization’s cybersecurity status; and
• The mechanisms to enable critical dependency analysis for supply chains based on mission/business function.

Moving Forward

The update reiterates the previous report that NIST will have an outline of the draft of the preliminary (this will certainly be a working document given all of those qualifiers) Cybersecurity Framework available by the end of the month; which means this coming week. All of this lead up to the 3rd Cybersecurity Framework Workshop to be held in San Diego, CA on July 10th and 12th.

NIST expects this Workshop to result in an initial draft of the Framework to include “a corresponding list of standards, guidelines, and practices that are currently being used by industry” (pg 2). We can only hope that the Framework being developed includes a methodology for keeping that list updated with revisions and new standards as the cybersecurity field continues to grow and mature.


NIST recognizes that everyone with an interest in, or input for, the development of the Cybersecurity Framework will not be able to attend the Workshop in San Diego. They are encouraging folks who cannot attend to provide their input via email (cyberframework@nist.gov).

Friday, June 21, 2013

NIST to Sponsor Cybersecurity FFRDC

Today the National Institute of Standards and Technology published a notice in the Federal Register (78 FR 37521-37522) re-announcing their intention to “to sponsor a Federally Funded Research and Development Center (FFRDC) to facilitate public-private collaboration for accelerating the widespread adoption of integrated cybersecurity tools and technologies”. This is the second of three required notices; the first was published on April 22nd.

NIST hosts the National Cybersecurity Center of Excellence (NCCoE), “a public-private collaboration for accelerating the widespread adoption of integrated cybersecurity tools and technologies”. NIST has determined that they need to establish an FFRDC to support the mission of the NCCoE. The FFRDC will have three main purposes:

• Research, Development, Engineering and Technical support;
• Program/Project Management, to include but not limited to expert advice and guidance in the areas of program and project management focused on increasing the effectiveness and efficiency of cybersecurity applications, prototyping, demonstrations, and technical activities; and
• Facilities Management.

In the area of RDE&T support the FFRDC will:

Establish relationships with private sector organizations;
Develop research, frameworks and implementation strategies for inducing industry to invest in and expedite adoption of effective cybersecurity controls and mechanisms;
Provide systems engineering support to NCCoE programs and proposed security platform development, selection, and implementation;
Generate technical expertise to create a relevant cybersecurity workforce; and

Deliver strategies and plans for applying cybersecurity standards, guidelines, and best practice inducements.

Bills Introduced – 6-20-13

We had four bills of potential interest to the cybersecurity community yesterday, a DOD authorization bill and three that would change the criminal statutes related to cybersecurity. The bills are:

S 1196 Latest Title: A bill to amend title 18, United States Code, to provide for clarification as to the meaning of access without authorization, and for other purposes.
Sponsor: Sen Wyden, Ron (D,OR)

S 1197 Latest Title: An original bill to authorize appropriations for fiscal year 2014 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes. Sponsor: Sen Levin, Carl (D,MI)

HR 2454 Latest Title: To amend title 18, United States Code, to provide for clarification as to the meaning of access without authorization, and for other purposes. Sponsor: Rep Lofgren, Zoe (D-CA)

HR 2466 Latest Title: To amend title 18, United States Code to provide for strengthened protections against theft of trade secrets, and for other purposes. Sponsor: Rep Lofgren, Zoe (D-CA)


S 1196 and HR 2454 are likely companion bills, bills introduced in both the House and Senate with identical language.
 
/* Use this with templates/template-twocol.html */