Friday, July 11, 2014

OMB Approves TSA Highway Base Program ICR

On Tuesday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the Transportation Security Administration’s (TSA) request for approval of an information collection request (ICR) to support the agency’s new Baseline Assessment for Security Enhancement (BASE) program that replaces their old Corporate Security Review Program. This BASE ICR supports the portion of the program looking at the over-the-highway transportation sector.

There was apparently some sort of administrative finagling going on with this ICR. The original 60-day Notice was published in May of 2012 and the 30-day Notice was published in November of the same year. According to OIRA, the ICR was not actually submitted to them until March of 2013. Something was wrong with that submission so TSA withdrew the ICR application on Monday and resubmitted the same day with all of the same supporting information. It was approved the same day. I can’t find any difference between the two submissions.

The other odd thing about this ICR is that while it covers all over-the-highway modes of transportation, it specifically does not cover Hazmat shippers or transporters. In their supporting statement [Word® download link] TSA notes (pg 4):

“While TSA is the lead federal agency for all modes of transportation, at this time TSA has decided to not conduct the Highway BASE of hazardous material carriers and shippers in order to avoid duplication with Federal Motor Carrier Safety Administration (FMCSA) assessments for compliance with requirements of the Pipeline and Hazardous Materials Administration (PHMSA).”

This is one of the problems that TSA has continued to have with surface security issues; since they were removed from the Transportation Department when DHS was stood up there have been numerous conflicts between DOT agencies and TSA over jurisdictional issues. This is reflected in the comment that was appended to by blog post on the 30-day ICR notice.


While the PHMSA hazmat transportation security regulations (49 CFR 172.800 et seq) are generic with no truly enforceable standards, they have at least been given the authority to require security plans. Congress has not given TSA any real authority to regulate hazmat transportation beyond the limited authority to address a limited number of hazmat materials transported by rail (49 CFR 1580).

Thursday, July 10, 2014

OMB Announces Approval of PHMSA Pipeline Accident Report ICR

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved, with change, the Pipeline and Hazardous Material Safety Administration’s (PHMSA) information collection request (ICR) supporting the pipeline accident reporting system. I have discussed the proposed changes to the ICR here and here. The ‘with change’ statement here means changes made due to industry comments received on the 30-day ICR notice. PHMSA’s response to those comments can be found here.


It is unusual to receive industry comments on an ICR notice. In this instance there were comments submitted on both notices. Unfortunately the public response to the 30-day notice comments is buried on an OIRA web site where most people will never see it (Okay, most people probably don’t care).

Bills Introduced – 7-9-14

Both the House and Senate are in Washington operating in that grey space between the electioneering modes and legislative modes. Thirty-five bills were introduced yesterday; one of which may be of specific interest to readers of this blog:

HR 5035 Latest Title: To reauthorize the National Institute of Standards and Technology, and for other purposes. Sponsor: Rep Bucshon, Larry (R,IN)


I’ll be watching for potential cybersecurity language in this bill.

Wednesday, July 9, 2014

Two Other Homeland Security Bills Also Passed Yesterday

In addition to the passage of HR 4007 yesterday two other homeland security related bills that have been previously discussed in this blog were also passed under the suspension of the rules process. The two bills were passed with recorded votes that were substantially bipartisan.

The two bills are:


Both bills had substantial bipartisan support in the House Homeland Security Committee and that was reflected in the final votes on the floor of the House. HR 4263 passed by a vote of 375 to 19, with the opposition coming from Republicans. HR 4289 passed by a vote of 393 to 0.


If these bills get taken up by the Senate it will probably be under a unanimous consent process at the end of a slow day.

Tuesday, July 8, 2014

ICS-CERT Updates ABB HeartBleed and Publishes Yokogawa Overflow

Today the DHS ICS-CERT updated a two-month old HeartBleed advisory for the ABB 650 Series application and issued a new buffer overflow advisory for Yokogawa Centum products. Yokogawa also updated an earlier advisory that has not yet been noticed by ICS-CERT.

ABB HeartBleed Update

This advisory update provides notice that ABB has produced a maintenance Release (available through customer service) that mitigates the OpenSSL bug in the 650 Series application. ABB has also updated their Cyber Security Advisory for the HeartBleed bug in their equipment. Interestingly the ABB published advisory can’t make up its mind (at the top of page 2) if the CVSS Score is 5.0 or 4.8 (not that there is much difference). ICS-CERT reports a score of 5.0.

Yokogawa Advisory

This advisory reports a single buffer stack overflow vulnerability in Yokogawa Centum products that was reported by Rapid7 in a coordinated disclosure. Yokogawa has produced a patch that mitigates the vulnerability but there is no indication in the advisory that Rapid7 has been able to verify the efficacy of the patch.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute arbitrary code. Yokogawa reports that the vulnerability only is accessible when the Expanded Test Functions Package is in use.

A Yokogawa Update

While following the ICS-CERT link to the Yokogawa report referenced above, I noticed that the Company had also updated an earlier report about four buffer overflow vulnerabilities reported earlier. I don’t know why ICS-CERT is reporting on the update (yet?).


The new data in this update is found in the Table 1 list of affected products and fixes. It reports a newer patch for the CENTUM 3000, CENTUM VP, and Exaopc Server products that addresses both the earlier vulnerabilities and the one reported by ICS-CERT today. It also reports that earlier versions of ProSafe-RS that were earlier reported as having no patches available may now be corrected.

House Passes HR 4007 on Voice Vote

Earlier this afternoon (5:09 pm EDT) the House HR 4007, the Chemical Facility Anti-Terrorism Standards Program Authorization and Accountability Act of 2014, by voice vote. There was about 30 minutes of debate on the bill. While it is hard to determine how much actual opposition there was to this bill, a voice vote, without a call for a recorded vote afterwards, is a pretty good sign that there was widespread bipartisan support for the bill. As I mentioned this weekend, this bodes well for the prompt consideration and passage of this bill in the Senate.

Update Added 17:30 CDT:

The American Chemistry council congratulated the House on passing this bill today; noting that:

“This bill will provide the operational stability that DHS has sorely needed to make CFATS successful, and help the agency recruit and retain top talent to effectively implement the program. The measure will also encourage industry to continue to make long-term capital commitments to enhance security and is consistent with the recommendations issued by an interagency Working Group as part of Executive Order 13650, ‘Improving Chemical Facility Safety and Security.”

SOCMA Tweeted®: Thank you @RepMeehan and @HouseHomeland for all of your hard work on H.R. 4007! #CFATS


OMB Approves 2014-2015 Methyl Bromide Exceptions

The OMB’s Office of Information and Regulatory Affairs (OIRA) announced yesterday that it had approved the EPA’s final rule for the critical use exceptions (CUE) for the continued use of methyl bromide under the Montreal Protocol. Publication of the rule could be seen by the end of the week.

There are a couple of interesting comments in the docket for this rule (here, here and here; PDF download links). What is missing from the docket this year is a copy of the EPA’s letter to users and manufacturers of methyl bromide notifying them that the EPA would take no enforcement action against users and manufacturers for the use of methyl bromide for CUE this year while the EPA got this delayed rule through the publication process.

Once again it is clear that DHS erred in 2007 when it removed methyl bromide from the final version of Appendix a to 6 CFR 27 based upon the EPA’s assurance that methyl bromide was being phased out of use/production. While the use of methyl bromide has certainly decreased it shows no sign of disappearing from the US market place.


Perhaps if manufacturers and distributors were subject to CFATS program security costs, there might have been more of an incentive to phase out this toxic inhalation hazard product.
 
/* Use this with templates/template-twocol.html */