Saturday, September 6, 2014

NTAS Website Updated – 09-05-14

Saturday is usually the day that I set aside to go back and look at a number of web sites that don’t change frequently, but would have information that readers of this blog might be interested in. One of those web sites is the National Terrorism Advisory System web site. Interestingly every page on that site was ‘updated’ yesterday.

Now this is not one of the sites that I keep site maps for so that I can track infinitesimal changes in the site language so I cannot tell what changes have been specifically made. In fact, it does not look like any real changes have been made to the site; but, each page carries a note at the bottom that: “Last Published Date: September 5, 2014”.

With a lot of politicians talking about the increased homeland threat from the Islamic State of Iraq and the Levant (ISIL) in recent weeks it is interesting that DHS takes the time to publicly ‘update’ its web site for issuing terrorism alerts.


Now watching this web site should not be anyone’s method of getting NTAS alerts. Watching any newsfeed will probably get you the alerts in a timely fashion, but if you want to get immediate notification the web site does provide links for following NTAS on Twitter® or on Facebook®, receiving email notifications, or putting an active link on your web site (like I have on mine).

Thursday, September 4, 2014

ICS-CERT Publishes Traffic Light Sensor Advisory

Today the DHS ICS-CERT published an advisory for a special kind of control system; the the Sensys Networks traffic sensors. The twin vulnerabilities covered in the advisory were initially reported by Cesar Cerrudo of IOActive. Sensys has produced updated versions for two of the three affected products with the third scheduled to be released later this month. There is no indication that Cerrudo has been given the opportunity to verify the efficacy of the mitigation.

The twin vulnerabilities are:

• Download of code without integrity check - CVE-2014-2378; and
• Missing encryption of sensitive data - CVE-2014-2379

ICS-CERT notes that it would take a highly skilled attacker to exploit these vulnerabilities, but it could be done from a neighboring network.

The advisory does not mention that the vulnerabilities were publicly disclosed in an article in Wired magazine and was presented at the 2014 Infiltrate Conference. Nor does it mention that the vulnerabilities were publicly denied by Sensys as late as early last month. So this was hardly a coordinated disclosure and would typically have called for an alert in April.

I can guess why there was no alert from ICS-CERT; this is an industrial control system only in the widest possible definition of the term. Which begs the question; why there was an advisory published today? The only answer that I can think of is that sensor systems like this are destined to become part of a wider network of fully automated traffic systems that would include control of vehicles traversing the system. This advisory may serve as an attempted wake-up call to vehicle control system designers that their un-hackable systems are just as vulnerable as other control systems.


That may be an important effort (if that was the impetus for this advisory), but not if it took away from efforts to deal with control system vulnerabilities that could threaten large populations.

Senate Hold on HR 4007?

I’m hearing rumors from a couple of different sources that some unnamed business organization is shopping around trying to find a Republican Senator to put a hold on the consideration of HR 4007, the CFATS authorization bill approved by the Senate Homeland Security and Governmental Affairs Committee back in July. This seems odd since the two biggest chemical industry organizations SOCMA and the American Chemistry Council have both endorsed the bill (including the Senate changes).

Since I have not talked to anyone from this organization (I’m not sure if it is a business group or a company) I don’t know what their specific objection to the bill is, but I would guess that it is the whistleblower provisions (§2105) of the bill that raise the ire of the organization. That is a shame since the provisions in the Senate version of the bill are among the most watered down whistleblower provisions that I have seen attached to a chemical security bill.

Both homeland security committees have done an excellent job at working to get a bill that has extensive bipartisan support. This is the first time since chemical security legislation was first considered post-9/11 that there was a bill that was not sharply drawn along ideological lines. The chair of the two committees have done some excellent work on crafting a bill that could make it through the legislative process in a divided legislature. It would be a crying shame if a single organization, working through a single Senator, could prevent a comprehensive chemical facility security bill from coming to a vote in the Senate.


Don’t get me wrong. Even passage in the Senate does not make this bill a forgone conclusion. Since the Senate version is extensively different from the House version, it would still have to get through the conference process before it could head to the President. With spending bills (more probably a continuing resolution) and political posturing on the legislative agenda for the next two months (actually only 2 weeks early in September a short week late in the month), this bill could easily get lost in the political shuffle. But it won’t even have that chance if it does not come to a floor vote next week.

Wednesday, September 3, 2014

DHS Updates CFATS Status Report

Today DHS ISCD updated their Chemical Security landing page with a link to the CFATS Status Update for August 2014. They also provided a new link to the CFATS ANPRM Listening Session page that I discussed earlier today. There is continued progress in authorizing and approving Site Security Plans (SSP). In fact, twin landmarks were reached; over 2000 authorized SSPs and over 1000 approved SSPs. There is a continued un-explicated decline in the number of covered facilities and still no tally on the number that passed inspections of SSPs.





CFATS Knowledge Center Update – 09-03-14

This afternoon the folks at DHS Infrastructure Security Compliance Division (ISCD) updated the CFATS Knowledge Center with a link to a new page that apparently has been up and operational since August 21st about the CFATS NPRM. That page has a schedule for the listening sessions and a link to a registration web site.

The first listening session is tomorrow at 9:00 am in Washington, DC. That should be interesting with Congress still out of town and presumably much of the press as well; probably more serious discussion and less political posturing. Too bad I could not publicize this sooner. The following sessions will be in:

• Houston, TX – 9-9-14
• Webinar – West Coast Time – 9-12-14
• Atlanta, GA - 9-16-14
• Sacramento, CA – 9-23-14
• Webinar – East Coast Time – 9-26-14
• Chicago, IL – 10-2-14
• Philadelphia, PA – 10-7-14


I’ve registered for the Houston session. I should be there in the afternoon. Look for me if you are going to be in the area.

OMB Approves FRA Securement NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the DOT’s Federal Railroad Administration’s (FRA) notice of proposed rulemaking on hazmat train securement. This proposed rulemaking was not listed in the Administration’s Spring Unified Agenda.

As I noted in an earlier blog post this NPRM probably looks like the rule proposed by the FRA’s Railroad Safety Advisory Committee (RSAC) back in April. That proposed rule would apply to trains with single cars of toxic inhalation hazard (TIH) chemicals or trains with 20 cars (total) of almost any other hazardous material. It would cover most freight trains that I have watched at road crossings over the years.


This rulemaking apparently has a high level of interest within the Administration. It was submitted to OIRA on August 15th and approved yesterday; that is fast action time for OMB. I expect that it will be published in the Federal Register later this week.

DHS Ignores CFATS ANPRM

It has been over two weeks now since DHS published their advanced notice of proposed rulemaking (ANPRM) on possible changes to the Chemical Facility Anti-Terrorism Standards (CFATS), but you would never know it by the two main web sites related to that program. Neither the Chemical Security landing page nor the CFATS Knowledge Center have so much as a mention of the ANPRM. We are now a quarter of the way through the public comment period and there has yet to be a notice of a single one of the public listening sessions promised in the ANPRM.

Now I understand that there has to be a certain amount of frustration over at ISCD about this rulemaking. First off the only requirement for looking at changes in the CFATS program mentioned in the President’s Executive Order on Increasing Chemical Safety and Security (EO 16350) was the requirement to look at possible changes to the DHS chemicals of interest list, making DHS look like the ugly step-child at the chemical safety and security party. Then, after they had worked so hard on the ANPRM it they don’t know whether or not Congress will act on HR 4007 and make the whole effort an exercise in futility.

Finally, to make matters even worse, there has not been a single comment posted to the docket for the ANPRM.  It is certainly too early for corporate comments, but not a single person has bothered to complain about the personnel surety program. Greenpeace has not weighed in on inherently safer technology.


Of course, if ISCD had discussed the ANPRM on their web sites… Or had published the date for the first public meeting… Or had even acknowledged that the ANPRM had been published… Then maybe there would be some public discussion about the ANPRM.
 
/* Use this with templates/template-twocol.html */