T H E  R I S K  C O M M U N I C A T O R

The Monthly Newsletter of the
Security Analysis and Risk Management Association
January 2013
SARMA Logo 5-Year - NoLtr
In This Issue
IN THE NEWS: Chemical Industry Defends Current CFATS Security Standards; Napolitano Calls on Congress to Pass Cyber Legislation; TSA Looks For Ways to Use Data to Expand PreCheck.
ANALYSIS: Interview & Video with Scott Algeier, Executive Director, IT-ISAC
KEY REPORTS: Defining Homeland Security - Analysis & Congressional Considerations (CRS); GAO on CBP's Efforts to Minimize Risk of Employee Corruption and Misconduct
JOBS: Information Security & Risk Manager; Risk Assurance ITPA & Security Manager
Thanks to
Our Silver-Level Corporate Patrons


ABS Logo

 Booz Allen Logo

 

ICF logo


Secure Mission Solutions Logo 

Thanks to
Our Bronze-Level Corporate Patrons


VRisk logo
Need Your Own Copy of The Risk Communicator?
Join Our Mailing List
Write for Us
Have you seen a story you would like to see included in The Risk Communicator? Do you have a research project you want to share with your colleagues? If so, please contact the newsletter staff at newsletter@sarma.org.
Get Involved, Get More from SARMA
SARMA Website
SARMApedia
Volunteer to Serve
Feedback/Input
Join SARMA
Legal Matters
Copyright 2012
SARMA
All Rights Reserved

Privacy Policy

The views expressed in The Risk Communicator reflect the views of their authors, and do not neccesarily reflect the views of SARMA, the US Government or the employers or clients of the contributors.

Editor's Note

January 2013 

 

Dear TRC Readers:

 

As we enter 2013, there is no shortage of security and risk management news to discuss, and certainly no lessening in the number of  emerging threats and vulnerabilities with which homeland security professionals, emergency managers and risk professionals must deal.

 

That's why I would like to take this opportunity to request your participation in this year's monthly editions of
The Risk Communicator. SARMA members bring a wealth of knowledge to the table that others could benefit from. Each of you have valuable experience from a multitude of security and risk management disciplines, industries, and agencies.  And we should not let that experience and knowledge sit dormant until the next annual conference.

In addition to keeping you all abreast of SARMA news and what's happening in the larger world of security and risk management, a major part of the mission of
The Risk Communicator is to facilitate knowledge sharing between members. Obviously, this cannot happen without your direct participation.

Therefore, I urge each of you to consider your areas of expertise and to contact me with ideas for feature articles that other SARMA members might benefit from. They don't have to be long or take all of your free time to produce.  You  would be surprised how much valuable discussion, debate and learning can come from a well-crafted 750 word article. Of course, once you get started writing you'll probably realize you have a lot more to say. And that's not a problem either. Longer analysis articles are also welcome.

I look forward to a great year ahead as your TRC editor and hope you will take me up on my offer. TRC needs more voices and your fellow SARMA members will certainly benefit.  Please contact me directly with your ideas at dverton@hstoday.us


Best regards,

Dan Verton

 

Editor, The Risk Communicator

   

In The News

Chemical Industry Defends Current CFATS Security Standards   
 

 

Homeland Security Today (1/28/13)

  
The chemical industry reacted last week to proposals to enact tougher measures for chemical facility security, arguing the current system offers substantive security benefits.

The Society of Chemical Manufacturers and Affiliates (SOCMA), an association based in Washington, DC, opposed legislation from Sen. Frank Lautenberg (D-NJ) that could prompt high-risk chemical, water and wastewater facilities to re-engineer their processes to use less dangerous chemicals if possible. Under the bill, those facilities would adopt inherently safer technology (IST) with the goal of replacing dangerous substances at those sites with less harmful chemicals.

SOCMA said the current program at the Department of Homeland Security (DHS), the Chemical Facility Anti-Terrorism Standards (CFATS), is effectively strengthening security.

"The comprehensive security standards currently being implemented and enforced under federal regulation have repeatedly been deemed appropriate and sufficient by congressional members in both parties in both chambers over multiple Congresses," said Bill Allmond, SOCMA vice president of government and public relations, in a statement on Jan. 24. "Furthermore," he said, "Democratic and Republican administrations alike support the existing standards."

According to SOCMA, more than 2,700 chemical facilities took steps to reduce the amount of dangerous substances at their plants, thereby completely removing them from regulation under CFATS as they became safer places. Moreover, the secretary of homeland security has the authority currently to shut down facilities that are not in compliance.

CFATS should receive long-term authorization instead of a year-to-year authorization it has received since its inception, SOCMA said.
  
  
Read Full Story: http://ow.ly/heYAK

 
 

  
Napolitano Again Calls Upon Congress to Pass Comprehensive Cybersecurity Legislation   

Homeland Security Today (1/25/13)
  
Homeland Security Secretary Janet Napolitano this month once again called upon Congress to pass comprehensive cybersecurity legislation to strengthen US authorities over critical infrastructure vulnerable to a major cyberattack.

Speaking at the Woodrow Wilson Center in Washington, DC, Napolitano stressed that the Department of Homeland Security (DHS) has significantly improved its cybersecurity capabilities in the past several years but that Congress must grant it more authority, particularly in sharing information.

A "cyber 9/11 ... could happen imminently," Napolitano warned. As seen after Hurricane Sandy, significant failures of critical infrastructure like the electric grid affects basic needs like heating and lighting for US citizens.

DHS holds overall responsibility for protecting infrastructure, Napolitano asserted. It requires the authority to protect the public good by doing what it can to keep critical infrastructure like the electric grid up and running.

As such, Congress should act before such infrastructure damage occurs due to a cyberattack, the secretary declared.

"We shouldn't wait until there is a 9/11 in the cyberworld. There are things we can and should be doing right now that if not prevent than would mitigate the extent of damage that could be caused," Napolitano remarked.

  

  
Read Full Story: http://ow.ly/heZ6Z
  

 
TSA Looks for Ways to Use Data to Expand PreCheck Trusted Travelers    

Homeland Security Today (1/29/13)

The Transportation Security Administration (TSA) Monday held an industry day to explore the possibility of using commercial data to prescreen air passengers and thus speed their physical screening at US airports.

TSA has been putting trusted travelers through expedited screening through its PreCheck program but the agency is now seeking ways to expand the population of travelers eligible for faster and lighter screening.

Speaking separately at the Woodrow Wilson Center on Jan. 24, Homeland Security Secretary Janet Napolitano said it is the goal of TSA to make half of the US population eligible for expedited screening within two years' time.

In an industry day at TSA headquarters in Arlington, Va., the agency asked private companies for assistance in figuring out how to do that. TSA released a request for information (RFI) on Jan. 8 seeking white papers exploring ideas. TSA is accepting white papers through April 1.

Read Full Story http://ow.ly/heZB6

  
  

Analysis

 

Interview: Scott Algeier, Exec. Director, IT-ISAC

By: Dan Verton

I produced the following story and video for Homeland Security Today.

When it comes to public-private partnerships and information sharing for national cybersecurity, few are better positioned than Scott Algeier to offer a well-informed assessment of the nation's progress to date.

Algeier's involvement in helping to build partnerships between the government and the private sector for cybersecurity and critical infrastructure protection pre-dates the terrorist attacks of Sept. 11, 2001, when he served as the US Chamber of Commerce's Manager for Homeland Security. While in this position, Algeier coordinated the Chamber's critical infrastructure protection, cyber security, and disaster management public policy initiatives, and served as a member of the Information Sharing Study Group of the President's National Infrastructure Advisory Council.

"I started at the Chamber working with what is now known as the Partnership for Critical Infrastructure Security, which really focused on trying to bring industry and government together, in partnership, to enhance the security of critical infrastructure," said Algeier.

A major part of Algeier's work with the Chamber involved working on the private sector's input to public policy on cybersecurity. He spent the next five years working with the newly-formed Information Technology sector's Information Sharing and Analysis Center (IT-ISAC) to help improve not only the relationship between the government and the private sector, but also the processes and procedures by which the Department of Homeland Security (DHS) and private companies shared critical information on cybersecurity vulnerabilities and emerging threats.

By 2005, the IT-ISAC had matured to the point where it needed a full-time director. Algeier was the obvious choice at the time and he's been at the helm ever since.

"Our goal is to provide a trusted forum for members to share information about cyber threats," said Algeier. "We have a secure Web portal, listservs, conference calls with member companies, and dedicated analysts that provide analytical support."

It was under Algeier's leadership in 2009 that the IT-ISAC inked an agreement with DHS to place a private sector analyst from the IT sector inside the newly-established National Cybersecurity and Communications Integration Center (NCCIC), the nation's primary cyber security operations center. The NCCIC opened in October 2009 as a 24-hour, DHS-led coordinated watch and warning center with the mission of identifying and responding to threats and incidents affecting the nation's critical information technology and cyber infrastructure.

There are currently two full-time analysts working for the IT-ISAC from virtual offices in Boston and Los Angeles, with a third analyst position under consideration. But as Algeier points out, most of the analytical work that comes out of the IT-ISAC comes from its more than 25 member companies, which include some of the largest IT and security companies in the world, such as Intel Corp., Microsoft Corp., Oracle Corp, Symantec Corp. and others. And this is part of the unique strength of the IT-ISAC model, he said.

"We're really building a powerful, integrated analytical capability where we can bring some of the brightest minds together from across the sector," said Algeier.

But things continue to change rapidly in cybersecurity, particularly in the area of vulnerability models for disclosures. Today, private companies tend to disclose vulnerabilities to their customer base first before sharing information with outside entities.  As a result, the IT-ISAC is adjusting its approach, said Algeier.

"One of the areas our members have asked us to look at is the attack front," he said. "So the new model is looking at ways we can facilitate information sharing by our members about what attacks they're seeing. That doesn't mean we've abandoned vulnerability disclosure [and] it doesn't mean we've abandoned the sector-wide response capability."

Information Sharing Today

During our interview, Algeier offered a candid assessment of the current state of information sharing between the government and the private sector. While there have been several improvements made over the last few years, "we're not where we need to be," he said.

One of the successes he points to is the first ever baseline risk assessment for the IT sector as a whole -- an initiative that Algeier took part in as the Industry Chair of the IT Sector Risk Assessment Committee. The assessment focused on events that are considered low-likelihood but high consequence attacks, and events that are considered high-likelihood but low consequence.  Since the assessment was published in 2009, important follow-up work has been accomplished on the Domain Name System (DNS) portion of the risk assessment.

Algeier also points to the creation of the NCCIC and the establishment of an IT Sector analyst position there as another major improvement in information sharing. But more work needs to be done, he said.

"We have a lot of individual initiatives, but we don't have an integrated program," said Algeier. "One of the challenges we have is that industry and government have common interests, but we look at the threats in a different way."

From where Algeier sits, the government is focused on threats and vulnerabilities from a national security perspective and, as a result, often looks at the worst-case scenario first. The private sector, on the other hand, looks at emerging threats and vulnerabilities from a business perspective.

"The government works from the worst-case scenario," said Algeier, but they "haven't demonstrated to us that the worst-case scenario is really the most likely scenario. The burden is on the government to bring that evidence to industry. Right now, we don't see it."

Watch HSToday's Interview with Scott Algeier  

 

Interview With Scott Algeier
Interview With Scott Algeier

 

   

Key Reports

Defining Homeland Security: Analysis and Congressional Considerations
- Congressional Research Service (CRS)

 

Ten years after the September 11, 2001, terrorist attacks, the U.S. government does not have a single definition for "homeland security." Currently, different strategic documents and mission statements offer varying missions that are derived from different homeland security definitions.

Historically, the strategic documents framing national homeland security policy have included national strategies produced by the White  House and documents developed by the Department of Homeland Security (DHS). Prior to the 2010 National Security Strategy, the 2002 and 2007 National Strategies for Homeland Security were the guiding documents produced by the White House. In 2011, the White House issued the National Strategy for Counterterrorism.

In conjunction with these White House strategies, DHS has developed a series of evolving strategic documents based on the two national homeland security strategies and include the 2008 Strategic Plan-One Team, One Mission, Securing the Homeland; the 2010 Quadrennial Homeland Security Review and Bottom-Up Review; and the 2012 Department of Homeland Security Strategic Plan. The 2012 DHS strategic plan is the latest evolution in DHS's process of defining its mission, goals, and responsibilities. This plan, however, only addresses the department's homeland security purview and is not a document that addresses homeland security missions and responsibilities that are shared across the federal government. Currently, the Department of Homeland Security is developing the 2014 Quadrennial Homeland Security Review, which is due late 2013 or early 2014.

Varied homeland security definitions and missions may impede the development of a coherent national homeland security strategy, and may hamper the effectiveness of congressional oversight. Definitions and missions are part of strategy development. Policymakers develop strategy by identifying national interests, prioritizing goals to achieve those national interests, and arraying instruments of national power to achieve the national interests. Developing an effective homeland security strategy, however, may be complicated if the key concept of homeland security is not defined and its missions are not aligned and synchronized among different federal entities with homeland security responsibilities.

This report discusses the evolution of national and DHS-specific homeland security strategic documents and their homeland security definitions and missions, and analyzes the policy question of how varied homeland security definitions and missions may affect the development of national homeland security strategy. This report, however, does not examine DHS implementation of strategy.

  

 

Download The Full Report http://www.hstoday.us/fileadmin/PDFs/DHSPriorities.PDF 

 

 

 


 

Additional Actions Needed to Strengthen CBP Efforts to Mitigate Risk of Employee Corruption and Misconduct - Government Accountability Office (GAO)

 

 

Although US Customs and Border Protection (CBP) remains concerned about the negative impact that corruption cases involving CBP agents have on agency-wide integrity, a recent report by the Government Accountability Office (GAO) found that corruption-related arrests of CBP employees accounted for less than 1 percent of the entire CBP workforce during the last eight years.

"The majority of arrests of CBP employees were related to misconduct," according to the GAO audit report, which had been requested by the Senate Committee on Homeland Security and Governmental Affairs and released in Dec. 2012.

The 48-page audit report found "there were 2,170 reported incidents of arrests for acts of misconduct such as domestic violence or driving under the influence from fiscal year 2005 through fiscal year 2012, and a total of 144 current or former CBP employees were arrested or indicted for corruption-related activities, such as the smuggling of aliens and drugs." As of October 2012, 125 had been convicted.

 

Download The Full Report

http://www.gao.gov/assets/660/650505.pdf

 

 


 

Jobs 

  

Information Security & Risk Manager

Parsons Brinckerhoff - Lancaster, Pennsylvania Area  

 

Job Description:

  

Under the supervision of the Enterprise Director of Information Security, at our new shared services facility in Lancaster, PA, manage major global Information Security initiatives, projects and programs in the areas of policy compliance, security architecture standards and controls related to best practices for Information Security Management.   

 

View Job Posting - http://ow.ly/hf5k4 

  


Risk Assurance ITPA IT Risk & Security Manager (PHI) PwC - Philadelphia, PA (Greater Philadelphia Area) 
  

Job Description:

  

Are you interested in the opportunity to work for an industry-leading firm that services Fortune 500 companies, and will give you the experience and exposure you need to build your career? If you are, then PricewaterhouseCoopers LLP (www.pwc.com/us) is the firm for you. PricewaterhouseCoopers LLP (PwC US) is well placed to help clients meet the challenges and opportunities of the US marketplace in the areas of assurance, tax, and advisory. We offer the perspective of being part of a global network of firms combined with detailed knowledge of local, state and US national issues. More than 169,000 people in over 158 countries across the PwC network are committed to deliver quality in assurance, tax and advisory services. People across the PwC network share knowledge, experience and solutions to develop fresh perspectives and deliver practical advice.

At PwC US, you will be part of a learning culture, where teamwork and collaboration are encouraged, excellence is rewarded, and diversity is respected and valued. We offer a flexible career progression model that allows for a variety of challenging opportunities throughout your career. We provide unparalleled coaching, mentoring, and career development programs; global opportunities; and state of the art technology-driven methodologies to help you provide quality service to our clients.

  

  

View Job Posting - http://ow.ly/hf5y7 

         

  

More Career Postings Available at SARMA Careers Online