Monday, October 29, 2007

Students of Homeland Security

Homeland Security is growing as an academic field, with the usual associated pains:

Homeland security as an academic discipline is gaining recognition, according to a new report by ... John Rollins, a specialist in national security at the Congressional Research Service, and Joseph Rowan, senior technical adviser for intelligence systems and architectures to the Marine Corps’ director of intelligence.

[T]he researchers found that 227 schools offer degree or certificate programs in homeland security, comprising about 1,800 courses.

However, the programs still lack standard coursework or core teaching areas, the researchers concluded.

"At this stage of the homeland security academic maturation process, it appears programs and accompanying courses will provide dissimilar and inconsistent learning opportunities for the foreseeable future," they said.

Student interest in homeland security programs is increasing; collaboration among academic institutions is becoming more frequent; student recruitment and retention numbers in the field are rising; and the first homeland security graduates have recently entered or returned to the workforce, they said.
Nothing surprising here. All academic disciplines undergo a period of uncertainty before they get their feet under them.

Thursday, October 25, 2007

The Local Need for Preparedness

This commentary in Domestic Preparedness provides some nice perspective on the need for local communities to be fully prepared for disasters. The writer is MaryAnn Warren, the County Commissioner of Susquehanna County, Pennsylvania, which suffered extensive damage from a flood in June 2006 after 8-10 inches of rain fell in six days.

This should be required reading for local officials, as it illustrates the pain of not being fully prepared. You've got to understand the process:

The first and one of the most important guidelines to understand is that state and federal disaster resources usually are deployed only when the magnitude of an event exceeds local capabilities – and then only at the request of a local government.
You've got to speak the language:
If local elected officials and their emergency-management staff cannot quantify the damages suffered and/or articulate the community’s needs – using the unique language spoken in the emergency-management arena – a community will suffer.

Susquehanna County learned that lesson the hard way – because state emergency-management officials did not immediately realize the severity of the situation we were trying to report to higher levels of government, it was assumed that we were not as bad off as the counties surrounding us in our part of the state.

It cannot be stressed enough how important it is to communicate through proper channels, using correct terminology, to access help.
And you've got to have your ducks lined up ahead of time, or your response will suffer. You can't just freelance it:
One might think that decisions made and/or actions taken during a disaster are executed swiftly, but that would be wrong. Over and over, residents expressed a desire to jump into creek beds with backhoes to clear debris or dredge channels, all in violation of the environmental laws and regulations of the Commonwealth of Pennsylvania. Although it boggles the minds of flood victims (and of elected officials as well), the fact that a disaster has occurred does not mean that permits or processes are waived or accelerated.
The recovery process will also be a headache:
In 2000, Congress passed a law requiring all of the nation’s various governmental jurisdictions to develop hazard-mitigation plans as a condition of receiving certain disaster-recovery funds. Susquehanna County had no such plan in place at the time of the flood, and therefore had to act very fast to redress this oversight – or risk losing recovery funds for those residents left homeless by the flood. There was no getting around this requirement, and residents were justifiably angry.

Fortunately, as it turned out, FEMA’s programs provide for an administrative allowance that may be used to hire experts to support recovery projects. FEMA also offers other grant programs that can be used to fund the development of mitigation plans. Recognizing the need for an expert fluent in FEMA’s programs, Susquehanna County hired a disaster-recovery specialist, a former FEMA employee, to steer the county through what to most local officials was unfamiliar terrain.

The disaster-recovery specialist, drawing fees mostly from administrative allowances, has cost the county very little out of pocket – and, in addition to preparing the county’s all-hazards mitigation plan, has secured more than $2 million in grants and appeals for the county.

The lesson is obvious: When in doubt, find an expert to navigate the disaster-recovery process.
Most disasters are to some degree predictable. Natural disasters have a history that is knowable. Certain industries involve recognizable hazards (e.g., chemical plants, refineries, nuclear power plants). Potential targets for terrorism can be identified, and likely modes of attack can be inferred from past events.

In short, no community should ever be in the dark about the threats facing it. No community should ever be not ready.

Monday, October 22, 2007

Review: National Strategy for Homeland Security (Revised)

I've had a chance to review the new National Strategy for Homeland Security. In many respects, the document suggests that we will continue the present course. But there are a few surprises at the end.

As a strategic guide, it tends to vacillate between being overly specific and not specific enough. In some sections, such as those dealing with terrorism, it is often more specific than a strategic guide would typically be, in that it identifies specific tactical and operational aspects to the fight against terrorism (e.g., the Real ID Act, the US VISIT program, the Container Security Initiative, Megaports Initiative, and Secure Freight Initiative, etc).

But in other sections, such as those focusing on responding to natural disasters, it is less specific than it could have been. It outlines useful goals and objectives, but it tends to be less clear about how we will achieve them (e.g., "...we must better articulate how roles, responsibilities, and lines of authority for all response stakeholders are fulfilled across all levels of government and among the private and nonprofit sectors so that each understands how it supports the broader national response.").

It's as if, where the sense is that things are perceived to be working well (i.e., we haven't had a terrorist attack in 6+ years), we're being very clear about what we'll continue to do. But in areas where things haven't gone so well (i.e., Katrina), we acknowledge that changes need to be made, but we're less clear about what needs to happen now.

Further muddying things is the new "all-hazards" aspect of the new Strategy (or, rather, the "almost all-hazards" emphasis in the new Strategy). Let's go back to the 2002 Strategy, which we can see was clearly focused on terrorism:

The purpose of the Strategy is to mobilize and organize our Nation to secure the U.S. homeland from terrorist attacks.
Compared to this, the 2007 Strategy seemingly adopts a more all-hazards approach:
Our National Strategy for Homeland Security recognizes that while we must continue to focus on the persistent and evolving terrorist threat, we also must address the full range of potential catastrophic events, including man-made and natural disasters, due to their implications for homeland security.

The purpose of our Strategy is to guide, organize, and unify our Nation’s homeland security efforts.
And yet ... in defining Homeland Security, the new Strategy copies - verbatim - the same terrorism-centric definition found in the 2002 version:
Homeland Security is a concerted national effort to prevent terrorist attacks within the United States, reduce America’s vulnerability to terrorism, and minimize the damage and recover from attacks that do occur.
It's odd, isn't it, that we define Homeland Security only in terms of terrorism, but then develop a homeland security strategy that addresses all hazards?

So we have a Strategy for Homeland Security (i.e., terrorism) that also addresses our vulnerability to natural hazards. Here's how the Strategy explains this:
Indeed, certain non-terrorist events that reach catastrophic levels can have significant implications for homeland security. The resulting national consequences and possible cascading effects from these events might present potential or perceived vulnerabilities that could be exploited, possibly eroding citizens’ confidence in our Nation’s government and ultimately increasing our vulnerability to attack.

This Strategy therefore recognizes that effective preparation for catastrophic natural disasters and man-made disasters, while not homeland security per se, can nevertheless increase the security of the Homeland.
Sooo ... the aspect of homeland security that is affected by natural disasters is that terrorists could take advantage of our increased vulnerability in the wake of a natural disaster to strike us. Do I have that right?

The assumption is that we have to be prepared for natural disasters because al Qaeda might decide to strike us in a moment of opportunity, following a catastrophic disaster. (?)

Question: What's the harm in including natural hazards in the definition of Homeland Security? Why do we have to link natural disasters to "homeland security" in this convoluted fashion?

Doing so seems especially odd, given that DHS is explicit in taking an all-hazards approach; the agency is responsible for preparedness and response for natural disasters. And there's no question at all that a major natural disaster can cause as much destruction - and more - than a catastrophic terrorist attack. If you replayed the three massive New Madrid earthquakes of 1811 and 1812 in today's United States, you would see destruction on a scale we've never seen.

So, why muddy the waters? Why not simply be absolutely clear about whether Homeland Security includes natural and accidental disasters? Why not say that Homeland Security addresses all hazards?

Like I said, it muddies the waters. But on to the review. My intend here is just to quickly review the general outlines of the strategy without much additional analysis.

The first major emphasis of the Strategy is to "Prevent and Disrupt Terrorist Attacks." This involves:
  • A special emphasis on preventing terrorists from acquiring, transporting, and using WMD.
  • Impeding the ability of terrorists to enter the U.S. or to move weapons material into the U.S. This involves both border security and port security.
  • Disrupting the ability of terrorists to function in the U.S. This involves intelligence-gathering and information-sharing to gain "domain awareness" of the (local) environment, so that anomalous behaviors are easier to spot. (There is a special emphasis on Intelligence-Led Policing.) It also involves disrupting terrorist activities such as recruiting, fundraising, training, etc.
The next major emphasis of the Strategy is to "Prevent Violent Extremist Radicalization in the United States." This involves:
  • Engaging key communities - especially the U.S. Muslim community regarding violent jihadism.
  • Identifying the environments where radicalization is most likely (e.g., prisons)
  • Further study into the process of radicalization
Next, the Strategy points to the need to "Protect the American People, Critical Infrastructure, and Key Resources." This involves:
  • Altering terrorists' risk calculus by hardening targets
  • Mitigating the vulnerabilities and enhancing the resilience of critical infrastructure and key resources
  • Ensuring medical preparedness
  • Minimizing the consequences of disasters by ensuring adequate warning
The nation's ability to "Respond and Recover from Incidents" are covered next. This involves:
  • Clarifying roles among various agencies and levels of government in response and recovery
  • Strengthening the response doctrine (e.g., NIMS)
  • Quickly assessing the scale of a disaster
  • More efficiently coordinating the requests for support
  • Conducting immediate, short-term response and recovery actions
  • Effecting a smooth transition from response to recovery
Finally, the last section of the Strategy - and the most important, in my opinion - focuses on the long-term direction that our Homeland Security efforts will take. This is the most strategic part of the document as I see it. It involves:
  • Applying a risk-management framework to all homeland security activities
  • Creating a culture of preparedness
  • Establishing a Homeland Security Management System, which extends the National Preparedness Guidelines and involves four phases: Guidance, Planning, Execution, and Assessment and Evaluation:


  • Focusing on incident management, including applying it to prevention activities
  • Applying advances in science and technology to homeland security
  • Leveraging connections among public and private institutions, as well as between government agencies. This includes sharing information.
  • Streamlining the operations of Congress
I think the ideas in this last section are sound, though the Homeland Security Management System has the potential to be a boondoggle. The strongest strategic emphasis, I think, is in leveraging the connections among various homeland security professionals. This is admittedly a bias of mine - I tend to see the best problem-solving systems arising when people build, nurture, and employ interpersonal and societal structures.

Friday, October 12, 2007

Countering Terrorist Networks and Technologies

The revolution in information technology, like all revolutions, can be used for good or evil. Anytime there is a shakeup in the way things work, there is an opportunity to better the world or make it worse.

With that in mind, it's interesting to review the recent RAND report entitled Network Technologies for Networked Terrorists. With RAND's usual thoroughness, the report outlines the potential ways that terrorist organizations can exploit new information technology and provides suggestions for addressing the threat.

There is, of course, good news and bad news:

Global consumer demand for new capabilities or products has fueled an explosion of new or enhanced technologies, many of which terrorists could use to make their operations more efficient or effective. However, technology can be a double-edged sword: As it boosts effectiveness or efficiency, it might also introduce new vulnerabilities.

Although these technologies can aid terrorist organizations by enabling military functions like command and control (see, for example, Whine, 1999), they can also provide capabilities that increase terrorists’ effectiveness in other necessary activities such as raising money or persuading people to join their causes.
One of my interests is in terrorist recruiting, which I perceive as presenting one of the more significant vulnerabilities of any terrorist group. Generally speaking, the conventional wisdom has been that successful terrorist recruiting involves one-on-one "grooming," bringing a potential recruit into the social sphere of the group and eventually cutting off ties with all other social groups. RAND argues, though, that advanced communication technologies can facilitate this process, making it easier to prime the pump and get recruits into the terrorist mindset at a distance and with more limited personal interaction:
Historically, recruiting for terrorist organizations has been a clandestine process. The need for security and secrecy heretofore has necessitated a low profile and often required that it be conducted face to face. ... Face-to-face recruiting limits the number of individuals who can be contacted. Moreover, small-scale recruiting coupled with the need for secrecy generally has meant a longer recruitment process, as the process must take place unobserved by security (often at a single site or in a few locations). Finally, recruitment into terrorist groups has frequently involved a lengthy proving period. In such circumstances, the technology available and the nature of the recruiting activity both worked to keep the cause local and the pool of potential recruits limited.

Today, forms of recruiting enabled by network technology greatly expand the scope, effectiveness, and efficiency of previous recruitment activities. First, recruiting can be done remotely. With recruiting materials on the Internet available from almost anywhere, face-to-face contact is not a necessity. This can facilitate recruiting by making a broad audience aware of a group’s existence and cause. Second, remote recruiting is efficient because a single recruiter can develop many candidates at the same time. Terrorist recruiters may now simultaneously work with audiences in many parts of a single country or in many far-flung countries, expanding the pool of potential recruits.
The idea is that recruiters can use distributed media (e.g., the Internet) for some recruiting purposes, generally early in the recruitment process, and then use other media (e.g., videos, which can be easily copied and shared) in a more personal context:
Recruiting normally involves employing a wide variety of communication methods—videos, pamphlets, Web sites, sermons, friendly news media, personal friends, and other influential people—in a number of locations: private homes, schools, religious sites, paramilitary camps, prisons, and so on. These aspects can be used to define two basic dimensions of recruiting:

Public versus private channel. Is the interaction taking place in or out of the public eye? The prevailing laws of the region, rules of the local institutions, and attitudes toward the group all will greatly affect where recruitment efforts fall on this spectrum.

Proximate versus mediated contact. Is the source of the recruitment effort physically close to the target audience? Cultural, technology, and economic circumstance are some of the variables that influence how the recruiting message can be passed to the intended target audience.

The rapid proliferation of network technology greatly increases the opportunity for interactions in mediated recruitment and for effective interactions in proximate recruiting efforts.
This can present challenges for prevention professionals:
Limiting a terrorist’s ability to recruit new members is already difficult. However, some technological advances might make countering terrorist organization recruiting harder still. Recruiting could be made more effective and efficient by the transfer of all or most of the indoctrination process into a virtual setting (e.g., online, videos). Although much recruiting may already be done virtually, indoctrination is more problematic, since many of the techniques used in indoctrination typically require immersion and proximity. Carrying out indoctrination processes through virtual channels would require that individuals be willing to isolate themselves, even in the absence of direct control over their actions by group leaders.
I think that last bolded bit is somewhat encouraging. Generally, a person who seeks to join a group (any group) is not looking for more isolation. They are looking for social interaction. They want to become a part of something. While it is possible that isolated immersion into a virtual world, with a virtual social sphere, could give a recruit this kind of social contact, from the perspective of a terrorist recruiter it may be simpler and more straightforward (albeit slower) to recruit the old fashioned way. The one-on-one, personal method also allow a recruiter to size up each recruit on an individual basis. Recruiting an online persona in a virtual world is riskier from the standpoint of operational security, because as the saying goes, "anyone on the Internet could be a dog."

Interestingly, RAND focuses on one potential avenue for distributed recruiting, the massively multiplayer online game (MMOG). "The SIMS" may be the best-known example of such a game.
The latest generations of computer-based, massively multiplayer online games (MMOGs), in which many individuals interact in a common virtual world, constitute a step toward the conditions in which such indoctrination might take place.

However, as intriguing as the games are and the possibility is that they could be used in ways to help in some serious applications such as reinforcing principles learned in conventional training situations, they represent a fairly modest enhancement to the terrorist repertoire of communication techniques. The communication enabled inside the game does not differ not significantly from other Internet-enabled communication,

A more interesting element of MMOGs, however, is that they might be a means by which groups may begin associations that they take offline, and thereby become a means of helping in recruiting processes.
Given the investment that has to take place to develop one of these games, my sense is that it's something of a long-shot to imagine terrorist groups making widespread use of them, especially when they would have to take their activities offline eventually anyway.

I'll briefly cover one other potential terrorist use of information technology - the planning of a terrorist attack. RAND points out that online information (as we all know) is generally not reliable enough to make final planning decisions. On-hand reconnaissance is necessary. This, of course, presents another vulnerability for any operational terrorist group.
Some useful planning information may be acquired from the Web, but recent studies indicate that, in most instances, it is not of sufficient resolution or reliability for terrorists to use it in final planning because of the risk from flawed or incomplete data to an operation’s success (Baker et al., 2004). It may, however, allow groups to focus their physical observations and thus lower the amount of exposure associated with reconnaissance.
In general, I agree with RAND's suggested strategy for countering the terrorist threat, which is to focus efforts on exploiting terrorist uses of information technology, rather than attempting to deny them the ability to use the technology. In a wired world, it's a lot harder to keep the technology out of their hands than it is to work in the background and exploit the vulnerabilities they expose themselves to, by virtue of using the technology:
The analysis suggests that the approach to countering terrorist groups’ use of network technology should focus primarily on the use of the technology as an efficiency-enhancing mechanism rather than one that allows dramatic new operational effects.

In developing such a strategy, security force decisionmakers should consider not only denial countermeasures—that is, measures that preclude the technology’s adoption, prevent its use, or degrade an adversary’s ability to use it as intended—but also exploitive countermeasures that enable security force operations that disrupt a terrorist organization more directly through offensive operations or arrests.

Security forces would do well to consider a countermeasure strategy based on terrorist organizations’ preference for exploiting the use of network technologies, rather than seeking to counter them directly. ... From a technical perspective, the approach suggested here, which can include allowing terrorists to use a given technology in order to exploit it, may seem counterintuitive, but may be the most effective (and practical) option in some circumstances.
Successful exploitation of a resource can also serve as a deterrent. If a terrorist group suspects that their information network has been compromised, they may give up use of that technology on their own. A well-known case of this is the abandonment of cell phones by al Qaeda operatives in Afghanistan when it became known that their calls could be monitored.
The best use of resources for those attempting to counter terrorist operations would seem to be developing ways to exploit the network technologies that terrorists will continue to use and that offer the highest payoff. ... Such exploitation can support direct action, such as arrests, and, because it threatens a key operational imperative of terrorist organizations, their security, it can also deter the use of the technology.


Drive-Thru Flu Shots

This is not a new idea, of course, but it's nice to see smaller communities thinking ahead, preparing for potential future disasters by changing the way they deliver the good old annual flu shot. Here's what they're doing in Boonville and Newburgh, Indiana:

Warrick County residents who want a flu shot this year can help out the county’s health department and participate in a disaster preparedness drill. On two Saturdays, flu shots will be given at drive-through clinics, one in Boonville and the other in Newburgh.

“It will test our disaster plan and our ability to give a large number of vaccines to a large number of people in a limited time,” said Sharon James, a Warrick County Public Health Nurse. “If we’d have an outbreak, we might be called upon to give medicine or a vaccine for whatever is out there.”

“The only way to know if we can do this is to practice,” said James. “And the only way to practice is to get people to come."

The idea of having drive-through clinics is a new one for the Warrick Health Department.

The idea, said James, came from a local hospital that tried the tactic last year. Patients will be directed to locations to fill out paperwork and get the flu shots without ever leaving their vehicles.

“People will pull into the parking lot, and there will be traffic controllers to direct them,” said James. “They will fill out their paperwork, be given an information statement and pay their money. Then they will drive forward under a tent, and there will be nurses on either side of the car, so we can do the driver and passenger at the same time.”
Another idea for emergency distribution of medicines that I find intriguing is to enlist the help of restaurants with drive-thru windows to serve as distribution points. Decentralizing the distribution can help speed the process and raise public confidence in the public health system. The trick is to work out the logistics and the record-keeping.

Thursday, October 11, 2007

Information Sharing in Reluctant Neighborhoods

The latest issue of Officer.com has a nice article on encouraging information-sharing between police and citizens, especially in neighborhoods where residents are generally hesitant and may be distrustful of the police. The article focuses on recruiting volunteers who will regularly help police, but the advice is sound in any case.

Police officers are advised to think like marketing executives, paying close attention to the needs of their "customers" (i.e., those who may share information with them):

[T]hought should be given to how your volunteers will be perceived by their fellow citizens.

When faced with troubled areas of your community, a different approach to marketing your volunteer unit to soften the perception could be as simple as a name change. Choosing a unit name such as Neighborhood Assistance Volunteers or Community Support Team removes what could be viewed as negative words.

At some point, your volunteers will speak with their peers in the community, at which time they can explain their purpose.

Not feeling singled out by their peers as "police in hiding" may also provide an incentive for members of the community to step up and perhaps join the team or at least pass on information that may help your agency to solve and prevent crimes.
Projecting an image of helping the community - being supportive and assistive - extends beyond just words:
Some simple resources to consider would be providing your volunteers with a list of community agencies that offer help to folks who may be having problems paying their utility bills, resolving disputes with neighbors and landlords, finding educational programs to increase their self-worth and more.

Other ideas may include providing your volunteer units with donated child safety car seats, and/or bicycle helmets for families that may not otherwise be able to afford them.

Other items to consider may be new donated basketballs, footballs and games to give children in the community something constructive to do, rather than just hanging out on the street corner. Doing so will help your volunteers "walk the walk" if challenged by their peers to demonstrate how they are "assisting and supporting" the community versus "working for the police."
This is all part of building a trusting relationship. In the end, we freely share information with those we trust.

Pandemic Flu: Europe Not Prepared?

Just a brief note on this article regarding European preparedness for pandemic flu:

The study of 29 European countries by scientists at the London School of Hygiene and Tropical Medicine highlighted shortcomings in preparation for vaccine and antiviral drug distribution, insufficient stockpiles, and incoherent plans for border controls.
None of that sounds very good - but this is a pretty brief list. Some other issues are potentially more important. For example, it's likely that in the early stages of a pandemic, no vaccine will be available, as it will take time to develop a vaccine that targets the pandemic strain. Communities and nations have to be prepared for that phase of a pandemic.

In the absence of vaccine, social distancing is one of the best tools for slowing the progress of pandemic flu, so the planning needs to take into account healthcare resources, economic necessities such as food and water, and schools.

The full WHO report on Europe is here.

(Hat-tip to H5N1.)

Tuesday, October 09, 2007

Revised Homeland Security Strategy

The White House has formally released the revised National Strategy for Homeland Security. Also see this fact sheet.

(Hat tip to Jonah at
HLS Watch)



Fight the Network, Not the Terrorist

Douglas Farah's post, "Why the Suicide Bomb Network Must be Dismantled," made me think more about a few recent incidents in which potential terrorist bombings have been prevented at more-or-less the last minute (e.g., London/Glasgow, Austria).

While it's comforting that no innocent lives were lost in these incidents, this is no way to fight a terrorist network. Farah also takes this view:

It is true that it is virtually impossible to halt the actual suicide bomber on his mission. But there are vulnerabilities in the network that create these human weapons. These areas can be far more easily attacked than the final product.

As Bob Baer, formerly of the CIA, recently wrote ... "this is an ideological battle that will be won, or lost, at the local mosque, at the family dinner table or between friends across the Islamic world."
Baer makes an important point here. Outsiders will not be able to "win" an ideological war between jihadists and nonviolent Muslims. But Jihadists are vulnerable in this ideological war, as the U.S. Military Academy's "Militant Ideology Atlas" pointed out:
The Jihadis lose credibility among mainstream Muslims when they attack women, children, and the elderly; damage the sources of a nation's wealth (such as tourism and oil); kill other Muslims; and declare other Muslims apostates.
(Also see my post on the Atlas.)

Evan Kohlmann also made a similar argument at the Counterterrorism Blog yesterday, pointing out that Algerian jihadists in the 1990s overreached and suffered backlash from the non-extremist population:
These men adopted a new philosophy that was, in short, "you are either with us or against us." According to Abu Hamza, "They classed the [faithful] Mujaahidin doing proper Islam as apostates. This was because they did not label every single person as a kaafir [infidel]… Anyone who differs with them, they call him a kaafir [infidel]."

In reflection, Abu Hamza al-Masri was deeply critical of these actions, referring to them as the equivalent of "shooting ourselves in the head": "This gave the enemies of jihaad a gun that they had never dreamed of having, ready pointed at us and loaded... This had far reaching consequences that sent an earthquake of instability among the adherents [of the mujahideen] and [their] aims. This worked beautifully for the enemies of Islam who were searching for a doorway or any angle to help them...in hopes that many people will leave the jihaad principles and the path of jihaad, only to seek reform through other means that are un-Islamic, like Democracy, Socialism, etc."
So there is an avenue for undermining the ideological legitimacy of the jihadists.

On the policing side, Farah goes on to argue, as I've also noted before, that some of the most vulnerable elements of a terrorist network are found in the recruiting and fundraising functions.
Imams that drum up volunteers-a key element. One that is often undertaken by mosques associated with the Muslim Brotherhood, particularly in Europe, and most noticeably in Great Britain.

Forgers almost always operate in networks, with different types of expertise working together. Another choke point.

Any of these chokepoints, from radicalization in mosques to radicalization in prison to cutting off the criminal enterprises that convey the suicide bombers to Iraq, are more efficient that hoping to stop the young person once they are one their way with a vest packed with explosives.
That's absolutely right.


Monday, October 08, 2007

Complications of a Regional Approach

I like the regional approach to security. A number of states have taken regional approaches, from Massachusetts, to Virginia, to Missouri. DHS has encouraged regional and multistate approaches; so has the National Governor's Association.

Many potential threats - both natural and man-made - are regional in scope. Regional approaches foster collaboration between neighboring jurisdictions, even those across international boundaries, such as

But there is a trick. We have existing government structures for local communities, states, and the nation. But for regions - not so much.

The Altoona Mirror reported that Pennsylvania has experienced problems defining ownership of assets that had been acquired for regional task forces:

The South Central Mountain Counter-Terrorism Task Force stopped its financial operations this summer because of concerns raised about who owns the federally funded equipment distributed throughout the eight-county region.

"The task force equipment wouldn’t have been locked up, and we wouldn’t have been told, 'You can’t use it,'" said Dave Cubbison, director of the Bedford County Department of Emergency Services.

Ownership became an issue when Centre County was advised by its auditor last year that it should list itself as the owner of all equipment bought for the task force. Centre is the task force’s financial agent.

The county disagreed with the finding because the equipment had been distributed throughout the eight counties.

"It was never clarified by the state," Nichols said.

The clarification came in a June e-mail from PEMA, which buys the equipment. The county that receives the equipment through the U.S. Department of Homeland Security grant is considered the "owner," Centre County Emergency Management Director Randy Rockey said.

Financial operations resumed in September after the task force received clarification from the state and federal governments, said task force chairman David Nichols, also Snyder County’s emergency management director.
Pennsylvania has also experienced problems with keeping inventory of available assets.
Another problem identified in the state report is the lack of a centralized database to manage resources on the municipal, county, task force and state levels.

Each county in the task force keeps track of its equipment, mostly on spreadsheets.
If you don't know an asset is available, it might as well not be available. It's critical to share this information.

Port Security Shortfall

Just taking note:

The Coast Guard faces budget challenges in obtaining the $260 million it estimates is needed to upgrade its command centers to meet the requirements of the Safe Port Act of 2006, according to a new report from the Government Accountability Office.

[A]ccording to the Coast Guard, none of the existing 35 sector command centers currently meets the requirements of the act, the report states.

However, four joint operations centers the Coast Guard has established with the Navy are a significant step in meeting these requirements, the report states.
There's nothing new about funding shortfalls, of course. Ports are such critical links in our economic system and critical nodes in our domestic security system, that I continue to be amazed by any shortfalls in securing them.

Friday, October 05, 2007

Bird Flu - Taking Note of the News...

This may not mean anything, but due diligence requires that we take note:

The H5N1 bird flu virus has mutated to infect people more easily, although it still has not transformed into a pandemic strain, researchers said on Thursday.

The changes are worrying, said Dr. Yoshihiro Kawaoka of the University of Wisconsin-Madison.

"We have identified a specific change that could make bird flu grow in the upper respiratory tract of humans," said Kawaoka, who led the study.

"[U]sually the bird flu doesn't grow well in the nose or throat of humans," Kawaoka said. This particular mutation allows H5N1 to live well in the cooler temperatures of the human upper respiratory tract.

"Clearly there are more mutations that are needed. We don't know how many mutations are needed for them to become pandemic strains."
The next pandemic flu might be next week, might be next year, might be in 20 years. The pandemic flu might not come from birds, either.

As Hamlet said, "The readiness is all."

(Related item: The California Association of Health Facilities has issued a new pandemic flu workbook for long-term care providers.)

Update Oct. 8, 2007: A bit of perspective from Effect Measure:
This is pretty scary sounding but it isn't new scary sounding. Kawaoka confirmed and filled in the picture about a mutation we already knew about, which is why he looked at it more closely in this paper. As far as we know the suspicion that a mutation in the PB2 gene at position 627 that substitutes lysine for glutamic acid (the mutation is written E627K in shorthand) goes as far back as 1992 when Subbarao, London and Murphy showed it was needed for a bird virus to infect mammalian cells. The idea that temperature is important was reported by Massin and colleagues in 2001.


Can We Count on Overseas Interdiction? Maybe Not So Much

Just a brief note on a new GAO statement on the effectiveness of U.S. law enforcement agencies' work with foreign governments to prevent terrorism. The report focuses on federal agencies such as DHS, the FBI, Immigration and Customs Enforcement, etc.

Generally it finds that, in spite of some recent successes, the effort is not organized as well as it could be:

Law enforcement agencies (LEAs) have increased efforts to help foreign nations identify, disrupt, and prosecute terrorists. However, we found that because most LEAs, with the exception of the FBI, have not been given clear guidance, they lacked clearly defined roles and responsibilities on helping foreign nations identify, disrupt, and prosecute terrorists. In one country we visited, the lack of clear roles and responsibilities between two U.S. LEAs may have compromised several joint operations intended to identify and disrupt potential terrorist activities, according to the U.S. and foreign nation LEAs. In addition, we found LEAs generally lacked guidance on using resources to assist foreign nations in addressing terrorist vulnerabilities and generally lacked performance monitoring systems and formal structures for sharing information and collaborating.
It's not like they haven't been doing anything; they have, especially the FBI. It's just not coordinated. One result has been a lack of information sharing that is especially disheartening:
In three of the four embassies we visited, we found that the embassies generally retained pre-9/11 structures for information sharing among LEAs. Although embassies generally use law enforcement working groups to share information, we found they were not focused on joint investigative or operational efforts to identify and disrupt terrorist acts. For example, in one country we visited with an extremely high terrorist threat, an FBI official told us that the law enforcement working group had never been asked to try to identify or disrupt any of the terrorists on the most wanted lists of the departments of State or Defense, or of the foreign nation itself.
Of course, for local officials this doesn't really change anything. Local officials need to be vigilant. But it would be better to hear that overseas efforts - to stop them "over there" - are better organized.


Thursday, October 04, 2007

The Nuclear Threat: A Close Look

The Nuclear Threat Initiative (NTI) has just released the Securing the Bomb 2007 report on the threat of nuclear terrorism. The report focuses on the risk of detonation of a nuclear weapon, primarily by terrorists. It pays little comparatively attention to other nuclear risks such as "dirty bombs" or attacks/accidents at nuclear power facilities.

NTI makes clear, early on, that the risk is real. There are two main scenarios: Either a terrorist group steals or buys a nuclear weapon on the black-market (perhaps stolen from Russia or Pakistan), or a terrorist group acquires nuclear material (either highly enriched uranium [HEU] or plutonium) with the intent of making a nuclear weapon. For technical reasons, HEU would be the more likely choice, as HEU can be used in a simpler "gun" type device.

NTI makes clear that the risk is realistic, even if it's remote compared to other risks such as conventional explosives.

A terrorist's first problem would be acquiring the material. The good news is that they can't make it on their own - it's too technically difficult. But it may be possible to acquire it, especially through three potential avenues:

[I]t appears that the highest risks of nuclear theft today are in Russia, Pakistan, and at HEU-fueled research reactors.

Russia has the world’s largest stockpile of nuclear weapons and materials, and remains the only state in the world where authorities have confirmed that terrorists have been carrying out reconnaissance at nuclear warhead storage sites.

[I]n February 2006, Russian citizen Oleg Khinsagov was arrested (along with three Georgian accomplices) with some 100 grams of HEU enriched to 89% U-235. The arrest was part of a sting operation in which a Georgian government agent posed as an Islamist buyer for a “serious organization.”
The risk of theft is real:
Today, security for the world’s vast and widely distributed nuclear stockpiles varies enormously, from excellent to appalling.

[A] substantial number of incidents of actual theft of weapons-usable nuclear material have occurred. ... The IAEA database on nuclear smuggling includes 15 incidents of real theft and smuggling of separated plutonium or HEU confirmed by the states involved.

In Russia, Chechen terrorists (some of whom have close links to al Qaeda) have carried out reconnaissance at nuclear weapon storage sites.
Locally, the greatest risk comes from research reactors:
More than 140 research reactors around the world are still fueled by HEU (though usually in forms that would require modest chemical processing before the material could be used in a bomb), and many of these facilities have modest security in place—no more than a night watchman and a chain-link fence in some cases.

A majority of research reactors are either in the United States or Russia.
Even at U.S. research reactors - especially at universities - security is relatively low:
Nuclear Regulatory Commission (NRC) security rules for research reactors are remarkably weak. ... U.S. HEU-fueled research reactors regulated by the NRC continue to have only the most modest security measures in place.

[As of the end of 2007] there will be 19 remaining HEU-fueled research reactors in the United States, of which 8 are licensed by the NRC.


Most civilian research reactors have very modest security. Some are located on university campuses, where providing serious security against terrorist attack would be virtually impossible—and where many of the operators are students, who cycle through frequently, making it extraordinarily difficult to provide serious checks of potential insider thieves.

In mid-2005 an investigation by ABC News documented conditions ranging from sleeping guards to security doors propped open with books at nearly all of the 26 U.S. university-based research reactors, including those with HEU.


None of the U.S. NRC-regulated HEU-fueled research reactors should be considered adequately secured against plausible terrorist and criminal threats (though several have either very modest amounts of HEU on-site, or HEU that is quite radioactive).
Once weapons-capable nuclear material has been stolen, especially HEU, it's virtually impossible to detect and locate. Unlike many nuclear materials (such as the fuel for a nuclear power plant), HEU gives off relatively little radiation, making it possible to transport with only minimal shielding.
[O]nce nuclear material has been stolen, it could be anywhere, and all the subsequent layers of defense, unfortunately, are variations on looking for needles in haystacks.

Moreover, the radioactivity from these materials is weak and difficult to detect from any substantial distance. ... You still can’t detect a nuclear device unless you are close to it.

Radiation detectors ... would have essentially no chance of detecting “clean” HEU with even modest shielding.

Even the expensive new Advanced Spectroscopic Portals now being developed would not substantially improve the ability to detect shielded HEU.
As drug smugglers and illegal immigrants have amply shown, it is not hard to sneak into the United States:
The myriad routes across the world’s scantily protected borders make nuclear smuggling almost impossible to stop. ... Attempting to protect the United States from nuclear terrorism by detecting and stopping nuclear contraband at the U.S. borders is like a football team defending at its own goal line.
And although terrorists could not enrich uranium themselves, it is conceivable that they could develop and transport a crude weapon:
Terrorists would need about 50 kilograms (110 pounds) of HEU for the simplest gun-type bomb—an amount of material roughly the size of a six-pack.

Even before the Afghan war, U.S. intelligence concluded that “fabrication of at least a ‘crude’ nuclear device was within al-Qa’ida’s capabilities, if it could obtain fissile material.”

Even a fully assembled bomb of the crude type terrorists might make could fit in a truck, a fishing boat, a small plane, or the hold of a yacht.
So there is some level of realistic threat, despite the technical difficulties involved and the challenge of acquiring fissile material.

How to solve the problem? A lot of the potential solutions would be in the jurisdiction of agencies such as the Department of Energy and Nuclear Regulatory Commission, along with the State Department and International Atomic Energy Agency (IAEA) for international efforts.

However, there is a local element to solving this problem. Police work is extremely important:

Almost all of the known interdictions have resulted from good police or intelligence work—from sting operations, or from people who became aware of the conspiracy deciding to inform the authorities. There are a wide range of steps that can and should be taken to strengthen international police and intelligence cooperation, to pursue additional demand stings (posing as buyers of nuclear material or expertise) and supply stings (posing as sellers), and to encourage the semi-feudal chieftains who control some of the world’s most dangerous borders to let us know about transports of nuclear material.
Some local police agencies have even provided security for local research reactors:

At the reactor at the Massachusetts Institute of Technology (MIT), since 9/11, there have been 1-2 Cambridge police officers with side-arms on-site to provide security—though these are not required by NRC rules. (Prior to the 9/11 attacks, the facility had no armed guards on-site, relying on response from off-site campus police of-ficers in the event of a problem.)
Other law enforcement activities, such as preventing recruiting and curtailing financial activities, may also be effective:
Terrorist efforts to recruit people with relevant expertise—such as nuclear physicists, metallurgists, or uranium machinists—may be one of the more detectable activities associated with a nuclear weapons effort. To increase awareness of this potential problem (and increase the chance that such recruitment attempts would be reported), police and intelligence agencies should seek to build relationships at locations that may pose particular opportunities for such recruiting efforts.

[I]t is worth making a major effort to change the conditions that make it easier for extreme Islamist terrorist groups to recruit and raise funds—to reduce the dangers of all forms of terrorism, not just nuclear terrorism.
Given the global nature of the threat, as well as the technical expertise required for dealing with nuclear materials, local officials may have relatively limited options to deal with the threat of nuclear terrorism; but that's not the same thing as having no options.

Wednesday, October 03, 2007

FEB's: Greasing the Wheels?

Given recent reports regarding the complexity and lack of clarity regarding the response to a biological incident (read: pandemic flu), GAO Director of Strategic Issues, Bernice Steinhardt, speaks glowingly of the ability of Federal Executive Boards (FEBs) to grease the wheels.

Created by a Presidential Directive in 1961, the FEBs are composed of the federal field office agency heads and military commanders in the FEBs’ areas of service.

Located in 28 cities with a large federal presence, the FEBs are interagency coordinating groups designed to strengthen federal management practices and improve intergovernmental relations. The FEBs bring together the federal agency leaders in their service areas and have a long history of establishing and maintaining communications links, coordinating intergovernmental activities, identifying common ground, and building cooperative relationships. The boards also partner with community organizations and participate as a unified federal force in local civic affairs.

The Office of Personnel Management (OPM), which provides direction to the FEBs, and the boards have designated emergency preparedness, security, and safety as an FEB core function and are continuing to work on a strategic plan that will include a common set of performance standards for their emergency support activities.
They already outreach with state and local agencies - good!
OPM reported that it expects the boards to serve as federal liaisons for state and local emergency officials and to assess local emergency situations in cooperation with federal, state, and local officials.

As a natural outgrowth of their general civic activities and through activities such as hosting emergency preparedness training, some of the boards have established relationships with, for example, federal, state, and local governments; emergency management officials; first responders; and health officials in their communities. Some of the FEBs are already building capacity for pandemic influenza response within their member agencies and community organizations by hosting pandemic influenza training and exercises.

Terrific! But all is not rosy.
The FEBs, however, face key challenges in providing emergency support, and these interrelated issues limit the capacity of the FEBs to provide a consistent and sustained contribution to emergency preparedness and response. First, their role is not defined in national emergency plans, which may contribute to federal agency officials being unfamiliar with their capabilities. In addition, with no congressional appropriations, the FEBs depend on host agencies and other member agencies for their resources.
True. FEBs are not mentioned in the National Strategy for Pandemic Influenza or its Implementation Plan, the North American Plan for Avian and Pandemic Influenza, the DOD Pandemic Flu Implementation Plan, or the HHS Pandemic Influenza Plan.

The FEBs are mentioned - once - in the National Response Plan. But their duty is limited to the first hour after an incident, when they are to deliver a "Federal Government status announcement [when the affected area is] outside the National Capital Region (NCR)." And then the FEBs get no mention at all in the draft National Response Framework, the proposed successor to the NRP.

This is a real detriment:
According to both FEB directors and FEMA officials, the FEBs could carry out their emergency support role more effectively if their role was included in national emergency management plans. FEMA officials from two different regions said they felt the boards could be used more effectively and that they add value to the nation’s emergency operations.
So it's perhaps a bit of a stretch to suggest that the FEBs will automatically slot into these plans. Still, they're an existing entity with the right kind of networking skills and mission:
Research has shown that systems like the FEBs have proven to be valuable public management tools because they can operate horizontally, across agencies in this case, and integrate the strengths and resources of a variety of organizations in the public, private, and nonprofit sectors to effectively address critical public problems, such as pandemic influenza.
And they've done good work in the past:

The FEBs have played a role in responding to past emergencies. For example, when the Oklahoma City Murrah Federal Building was bombed on April 19, 1995, the FEB staff knew all of the agencies in the Murrah Building; the home telephone numbers of critical staff; the city, county, and state principals in Oklahoma City; and which federal agencies were available to provide immediate relief and support.

During hurricanes Katrina and Rita, according to a FEMA official, the New Orleans FEB executive director established and maintained an essential communication link between FEMA’s Office of National Security Coordination and OPM.
But their effectiveness is far from universal:
Although all of the boards reported some involvement of state and local officials in their emergency activities, the degree of board connections with state and local officials varied. ... The Dallas-Fort Worth FEB executive director reported that the board partners with state and local government representatives, the private sector, law enforcement, and first responders, all of which are key players in assessing local emergency situations. On the other hand, the Chicago FEB executive director said that because Chicago is so large, the board has few established relationships with state and local officials.
There are other obstacles as well, starting with a serious lack of appropriations:
Although membership by agency heads on the boards is required, active participation is voluntary in practice, and the boards operate with no independent authority. The FEBs also have no congressional charter and receive no congressional appropriation but rather depend on voluntary contributions from their member agencies.
So is this a silver bullet? Even the FEBs say, "maybe not."
Looking ahead, however, representatives from 14 of the 28 FEBs disagreed on the role the boards should play in emergency service support, particularly during an emergency. Without adequate staff and resources, some of the executive directors expressed concern that they will not be able to meet expectations.
But with pandemic flu, the FEBs do have certain strengths:

[T]he nature of pandemic influenza, which presents different concerns than localized natural disasters, may make the FEBs a valuable asset in pandemic preparedness and response.
Many of the FEBs have cultivated relationships within their federal, state, and local governments and their metropolitan area community organizations as a natural outgrowth of their general activities. For example, FEB activities, such as the Combined Federal Campaign and scholarship programs, bring the boards into contact with local charities and school boards.

In terms of current pandemic planning, some of the FEBs are already building capacity for pandemic influenza response within their member agencies and community organizations by hosting pandemic influenza training and exercises.
The big question: Can FEBs really facilitate broader information sharing and clarify responsibilities? Or would it be a case of one more group without a clear mandate, gumming up the works?


Another Information Sharing System

FEMA has contracted an IT company to create an information-sharing system for emergency response:

Emergency responders nationwide will soon have access to vital information via a single online source.

The Federal Emergency Management Agency awarded a contract Sept. 28 to CNI All Points Logistics to set up FEMA’s Emergency Management Information Management System (EMIMS) as a repository for emergency management information.

"The system will be used to coordinate and effectively manage the incident, to develop future operational plans, to prepare comprehensive periodic reports, to track information requests and other pending actions, and to maintain accurate records,” according to a FEMA news release.

EMIMS sorts emergency information for validity and importance and then distributes it to multiple offices, including the National Response Coordination Center (NRCC), Regional Response Coordination Center and the Joint Field Offices.

"Any person who’s in a position of command-and-control responsibilities, such as [the head of] the NRCC, needs instant access to information that he needs to make decisions in reference to the proper way to respond to whatever happens to be going on,” said John Richardson, contract specialist at FEMA. “This system will consolidate all that information and provide it in a format which [responders] will be able to read.”

Richardson said the basic system should be installed in two weeks, with additional customization to follow.
Questions: Let's say I'm with another federal agency, working at the Joint Field Office (JFO) under one of the Emergency Support Functions (ESFs). Do I have access to this system? Do I have access to this information? Is this system compatible with the other information systems that I already use?

Also, will the information be shared with state and local personnel? If I'm working at a state Emergency Operations Center - same deal.


Preparedness: Are We REALLY Sure?

It's hard to see the justification behind this:

The nation is preparing for its biggest terrorism exercise ever next week when three fictional "dirty bombs" go off and cripple transportation arteries in two major U.S. cities and Guam, according to a document obtained by The Associated Press.

Yet even as this drill begins, details from the previous national exercise held in 2005 have yet to be publicly released — information that's supposed to help officials prepare for the next real attack.

"The challenge with TOPOFF is not the exercise itself. It's to move as quickly as possible to remedy what perceives to be the problems that are uncovered," former Homeland Security Secretary Tom Ridge said in an interview with AP this week.
Yes indeed.
Ridge, who launched his own security consulting company on Monday, said he's a big fan of the TOPOFF exercises. But he said "it's not acceptable" that the review from the 2005 exercise is still not released publicly.

The after action report from TOPOFF 3, which deals with issues that came up in the 2005 exercise, is supposed to identify areas for improvement. That report is still going through internal reviews.
If one were feeling snarky, one might wonder if al Qaeda uses a similar review process.
According to a brief summary of the 2005 exercise — marked For Official Use Only, but obtained by AP — problems arose when officials realized the federal government's law for providing assistance does not cover biological incidents.
Hmm ... no clear authority for biological incidents. That sounds familiar.

Tuesday, October 02, 2007

Stopped at the Last Second

Yet another tale of a last-second intervention: A guy in Austria walks into the US Embassy with a sack of grenades and nails:

A Bosnian man carrying a bag of hand grenades and nails has been arrested after trying to enter the US Embassy in Vienna.

He was detained after a metal detector alarm sounded as he attempted to walk into the building, according to reports.

He dropped the backpack, fled on foot, but was arrested a short distance away. The bag also contained Islamic literature, Austrian police say.

"There were a lot of nails in that bag. Had it exploded, it would have had an enormous shrapnel effect," Doris Edelbacher, of Austria's counterterrorism office, said.

Great news, everything worked out, except...

It was only the last layer of security that stopped him. You can't count on last-second stops as a prevention strategy.


Monday, October 01, 2007

Are We Prepared? Are We Sure?

An article from last week's Federal Computer Week was provocative in that it raises the question: How do we know we're prepared?

A misconfigured firewall that malfunctioned during a federal disaster preparedness exercise in April showed how tenuous disaster preparation can be.

Mike Nicholson, director of the requirements office of the information technology division at the Homeland Security Department’s National Protection and Programs Directorate, said the firewall problem prevented an Army unit from connecting with the Defense Information Systems Agency, almost scuttling the demonstration.

“It took a month to get that resolved,” a delay that would not have been acceptable during a real emergency, Nicholson said.

That lesson highlights the reality that emergency preparedness requires training for almost every possible situation.

But many DHS officials say that even thorough training might not be sufficient. The most well-prepared plans can be derailed by the unpredictable nature of disasters.
Here's the thing: It's not how "well-prepared" the plan is. It's how adaptable it is. It's how flexible it is. it's how non-brittle it is.

You can plan and exercise your disaster strategy again and again, but it is still at risk if it is a brittle system, or if it relies on brittle systems. And we do have some brittle systems.
Other officials said a major component of disaster preparedness is coordinating with state and local governments. Although disasters typically are localized events, the federal response can be stymied by lack of local knowledge and obsolete information technology systems.

For example, making quick emergency acquisitions can be difficult because of regulations that require the government to spend some disaster relief money with local businesses to help rebuild economies in affected areas.

“The problem is trying to get these local communities acclimated to federal contracting,” said Tina Burnette, director of acquisitions management at the Federal Emergency Management Agency. “The laws that govern federal contracting are complicated.”
Think about those highlighted words, and whether they signify an adaptable or a brittle system. Federal agencies lack knowledge of local assets (a solveable problem in an adaptable system, but an intractable one in a brittle system). We are burdened with old, unchanging IT systems. We box ourselves in with regulations and complicated contracting rules.

Adaptability is the key to survival, both in nature and in human systems. It is even more so during a catastrophe.

Friday, September 28, 2007

On Precursor Crimes

Just a quickie on precursor crimes. In The Washington Institute for Near East Policy's PolicyWatch/PeaceWatch Michael Jacobsen writes:

[Europe and America's] preventive strategy [regarding terrorism] has revolved around an increasingly aggressive law enforcement approach. In 2006 alone, for example, European authorities arrested a total of 260 terrorist suspects. Most of these individuals were charged not with plotting attacks, but with a variety of other terrorism-related offenses such as financing, recruiting, and facilitation.
Also see these other posts re: precursor crimes.