Tuesday, September 25, 2007

New Massachusetts State Homeland Security Strategy

Massachusetts has released a new state homeland security strategy. It's an all-hazards strategy, which reflects the experience of Hurricane Katrina and the risk of other natural hazards such as pandemic flu.

The strategy lists three major goals:

Our obligations, from the state’s perspective, whether we are planning for response to a terrorism incident, detecting a potential influenza outbreak, managing a major fire, or preparing for a potential hurricane, are guided by three major goals:

1) to create a common operating picture among all homeland security and public safety stakeholders;
2) to strengthen and expand partnerships across assets and capabilities; and
3) to focus efforts on private sector and public participation in prevention and preparedness.
These are laudable goals - it's especially welcome to see the explicit focus on private sector involvement (more on that later). It covers the whole range of preparedness activities, from prevention to response and recovery:
[T]he state is ultimately responsible for ensuring both effective prevention and effective response and recovery.
Prevention primarily relies on intelligence that's funneled through the state's Fusion Center:
The intelligence aspect of prevention, in terms of securing critical infrastructure, maintaining resource databases, and all aspects of the Commonwealth Fusion Center, contributes to prevention by informing law enforcement and public safety officials about vulnerabilities. Once vulnerabilities are recognized, we can begin to find solutions to prevent incidents.
Initial thought - this is focused on vulnerabilities, but risk is not just vulnerability. Calculating a threat involves not just vulnerability, but likelihood and consequence as well.

To organize the effort, they're using not only the Fusion Center. For coordination of recovery efforts, Massachusetts is using a new, collaborative organization:
[W]e have launched the Massachusetts Recovery Alliance that will convene all relevant parties to ensure that all efforts – from building inspections, to federal support, to workforce replacement – are properly integrated after a disaster.
They also have an Implementation Team that oversees state support of HSPD-8, "National Preparedness":
The HSPD-8 Implementation Team is charged with assessing the ability of the Commonwealth to respond to catastrophic events. Since its inception in 2006, the team has identified and ranked existing gaps in capacity and compiled them into a matrix that aids in establishing funding priorities and gives direction and focus to state and regional capability improvement plans.
For implementation purposes, the state has been divided into 5 geographic regions:
Liaisons from EOPSS Homeland Security Division provide guidance and oversight to each of five geographically designed regions - the Northeast, Southeast, Central, Western, and Metro Boston (UASI) - which were created to support strategic planning and operational coordination at the local level. Regional Planning Councils for each region are responsible for developing and guiding the implementation of regional homeland security plans described in this document. ... Five Regional Homeland Security Advisory Councils serve as the governance body (both policy-making and administrative) for each of the regions.



Each region is responsible for developing local relationships (very good) and is relatively autonomous in setting priorities:
Substantial state and local collaboration and coordination have resulted from the working partnerships of the regions. In furtherance of SHSS activities, each region has individually dedicated homeland security resources to collaboration, planning, equipment, training, and evaluation.
  • The Northeast Region has utilized homeland security funding to procure a variety of emergency supplies, coordinate first responder activities, and implement school safety mechanisms.
  • The Southeast Region has made significant strides in improving interoperability and incident command training.
  • The Central Region has expanded the capability of communities to recover from large scale incidents through the procurement and deployment of emergency equipment.
  • Major accomplishments of the Western Region include interoperability and information sharing projects.
  • The Metro Boston Homeland Security Region (MBHSR) has improved intelligence and information sharing, as well as communications interoperability.
In terms of implementing the states three major goals, the strategy briefly outlines some of the implementation activities that should go on statewide. Under the first goal of Creating a Common Operational Picture, the initial emphasis is on the fusion center:
Pursue effective prevention efforts through analysis of risks: In order to understand the strategic threats that face the Commonwealth and take the proper and appropriate protective measures, public safety and public policy officials need access to timely, accurate, and actionable intelligence and information. The Commonwealth Fusion Center is at the center of the state’s efforts to receive, produce, and share intelligence assessments and reports with our local, state, and federal partners. To that end, the Fusion Center has recently incorporated personnel and systems from the Federal Bureau of Investigation (FBI) and the U.S. Department of Homeland Security (DHS) to support the seamless exchange of information and intelligence regarding threats to the nation and the Commonwealth. These assessments and related products are regularly shared with key stakeholders for tactical support, situational awareness, and strategic planning purposes.
The top-down emphasis is a bit worrying - they're incorporating federal personnel into the fusion center. Let's not forget threat information that comes up the chain as well. Hopefully the threat information won't come mostly from "above."

However, it's nice to see that the info on vulnerability of particular assets will come from the local level, because locals know that best. Locals can also provide important info that helps determine likelihood and consequences:
Among the Commonwealth Fusion Center’s intelligence assessments and alerts agenda, a present primary focus is the recent adoption of the Automated Critical Asset Management System (ACAMS), a statewide inventory tool to categorize and prioritize critical infrastructure. The process of assessment includes leveraging existing state and local partnerships with public safety stakeholders and other subject matter experts to collect critical asset data by training and providing them access to ACAMS. These teams will bring together public safety professionals with other subject matter experts (e.g. structural engineers) to produce in-depth, robust vulnerability assessments of critical infrastructure and key resources. When joined with the ongoing assessment of potential threats conducted by the Commonwealth Fusion Center, a clearer assessment of risk in the Commonwealth will emerge.
Seems to me that if the fusion center gets information on threats and vulnerabilities from local personnel, as well as relevant info regarding likelihood and consequences, and really fuses it with the information on threat (as well as info relevant to likelihood and consequences) that comes from the FBI and DHS, then the fusion center will really be doing its job - fusing information from all levels to create an accurate picture of the threat. That's a good approach.

Moving on to some of the other objectives of the strategy...you don't always see this one:
Prepare the Commonwealth for Mass Evacuation and Shelter: To date, there are numerous local and state plans. However, they can not each stand alone and succeed. We need to ensure that the plans are fully integrated, that the expectations of one jurisdiction merge with another, and that the state, through the Massachusetts Emergency Management Agency (MEMA), is able to understand and assist in those efforts. ... This overall state and local effort has three interrelated parts – traffic plans, sheltering capacity assessments, and focus on individuals requiring specific assistance.
Next, a few notes on the second major goal, Strengthen and Expand Partnerships for Prevention and Preparedness. This is good to see:
Integrate Public Health Preparedness into Homeland Security Efforts: Protecting public health is an integral part of an all hazards approach to homeland security, whether it be detecting a naturally occurring or man-made public health threat, or protecting our first responders during a potential chemical, radiological, or biological incident.
But ... is there enough capability built into the public health system to accommodate a catastrophe? (See these two posts.) As for distributing medicines their plan is:
The foundation of the Boston plan is the staffing and operation of large dispensing clinics, located in schools and community centers all over the city, where residents would be able to pick up medications for themselves and their families.
On port security, just an interesting factoid:
[W]e continue to work with affected localities and the state of Rhode Island to oppose the proposed LNG terminal in Fall River. The Commonwealth opposes the proposed terminal based on the potential dangers associated with the storage and transfer of LNG and the U.S. Coast Guard report that expresses safety concerns regarding the transfer of LNG through the proposed waterway.
The risk of LNG to surrounding communities is somewhat unclear. Interesting that Massachusetts is taking this stand.

On Goal #3: Focus on Private Sector and Public Participation in Prevention and Preparedness, it's interesting how many of the specific implementation activities under this goal relate to personal preparedness:
Enhance Personal Preparedness: Help Us Help You Campaign - EOPSS is planning a wide variety of events for September, all of which will reinforce the idea that doing a little advance preparation on an individual level will help the government help you in a time of emergency.

Address the Needs of Individuals Requiring Specific Assistance: Statewide Individuals Requiring Specific Assistance Task Force on Emergency Preparedness: The intention is to enhance emergency preparedness planning for people with specific and/or functional needs and to include them in the planning process as well as exercises and drills.

Continue Community Outreach Efforts: Engage and empower immigrant populations. In order to change the pattern of exclusion, outreach efforts have been employed to engage and empower isolated groups.
I'd actually like to see more detail on how large private sector entities will be incorporated into the planning and preparation process (other than the very welcome involvement in ACAMS noted above). Often, critical businesses such as chemical plants, oil refineries, utilities and so on, are reticent to share information because of proprietary concerns.

While it is certainly important for individual citizens to be prepared, it's even moreso for the owners and operators of critical infrastructure elements to be coordinated with the state's preparation and response.

Update Sept. 26, 2007: I'd forgotten about this audit from last year that found Massachusetts unprepared (also see my post). The state Senate committee that oversaw the audit found four areas of concern:
  • The state’s insufficient oversight of homeland security planning by cities, towns and the state’s agencies and authorities;
  • The state’s failure to provide first responders with the proper means to protect against terrorist activity and natural disasters;
  • The state’s inadequate communication of the statewide strategy; and
  • The state’s unsuccessful implementation of its homeland security plan.


Friday, September 21, 2007

NYC Public Health System Not Fully Prepared

Not terribly surprising:

New York City's health care system is not prepared for a major disaster such as a large-scale attack, hurricane or pandemic, health care and disaster planning experts said.

The city, struck in the September 11 attacks and a world financial center, is vulnerable due to underfunding and a lack of understanding of the possible complexities of a crisis, officials from city hospitals and emergency services said this week at a conference on disaster preparedness.

"We have no idea what a prepared New York is. What we're doing now is random acts of preparedness that all together don't really amount to an appropriate safety net," said Irwin Redlener, director of the National Center for Disaster Preparedness at Columbia University's Mailman School of Public Health.

"We're in a very, very bad place."
There's a problem - long known - with a lack of excess capability. NYC, despite its high-profile status, is not immune to the problem:
Brian O'Neill, who heads emergency services for the North Shore - Long Island Jewish Health System, said the city's emergency services have the potential to move large numbers of people injured in a catastrophe, but not necessarily the hospital capacity to deal with them.

"We don't have 20,000 open beds ... for hospitals to absorb that," O'Neill said. "We would have to rely, at that point in time, for long-term solutions from the federal government."

Columbia's Redlener said hospitals would be immediately overwhelmed in such a situation and the number of deaths would balloon.
Like I said, all of this is not terribly surprising. Given the threat of pandemic flu, there has been a lot of study of our public health system. The basic problem is that we've given up excess capability for the sake of efficiency. (Which makes perfect sense for most businesses but is debatable in the healthcare field, where you need to be able to accommodate surges in demand.)

The Trust for America's Health reported late last year that we don't have enough beds for a flu pandemic. (Also see my post.)
Half of states would run out of hospital beds within two weeks of a moderately severe pandemic flu outbreak.
Last December, the Trust for America's Health, in it's "Ready or Not?" report, found that:
  • Forty states and D.C. have a shortage of registered nurses.
  • Six states cut their public health budgets between FY 2004-05 and FY 2005-06. As of FY 2005-06, the median state funding for public health is only $31 per person per year.
  • And that the public health system is hampered by:
    • Lack of clear roles for the various state, local, and federal agencies.
    • Limited coordination among the levels of government, including determination of how federal assets would be deployed to states and localities, and across jurisdictions, such as sharing assets and resources among states.
    • No minimum standards, guidelines, or recommendations for capacity levels or services required of state and local health departments. This results in major differences in services and competencies across state and local agencies.
    Public health officials in NYC are seeing the effects of this lack of clarity:
    Bruce Logan, Chief of New York Downtown Hospital's Department of Medicine, said he was unable to get federal funding for an expansion of the hospital's emergency room, despite being four blocks away from Ground Zero where the World Trade Center's twin towers were destroyed on September 11 and the first hospital to respond to the attacks.

    "We're in the financial capital of the world ... I see that emergency room as an element of our national defense," Logan said. "Unfortunately, I can't get our government officials -- especially the state and federal ones -- to see it the same way."
    Public health is like anything else: You pays your money, you takes your chances. And we are taking our chances, that's for sure.

    (Note:
    Late in 2007, we're supposed to get an updated report on the status of public health preparedness from the CDC.)

    Thursday, September 20, 2007

    Status Report on the Information Sharing Environment

    The Program Manager of the new Information Sharing Environment (PM-ISE) just released a new status report on the Information Sharing Environment. (For background on ISE, also see prior posts like these, especially this one.) The PM-ISE produced an implementation plan in November 2006; and since then they've been working to build the system.

    Starting with the small stuff, the report gives us an interesting analogy to describe the ISE:

    The ISE is not a new, independent information system. ... The ISE is a system of walkways, skyways, and corridors connecting the homeland security, intelligence, defense, law enforcement, and foreign affairs communities and the users of terrorism-related information within those communities.
    Hmm ... sounds futuristic ... [cue the theremin] ...

    Anyway:

    As you might expect, the status report reflects a lot of initial planning and organizational activity. Yet it also sheds some light on DHS' priorities. For sharing information with state, local, and tribal agencies, there is a continued emphasis on fusion centers - almost to the point of total dependence:
    State and major urban area fusion centers are vital organizations and are critical to sharing information related to terrorism. They will serve as the primary focal points within the State and local environment for the receipt and sharing of terrorism-related information, while at the same time also handling “all crimes” and “all hazards” related information. ... Agencies will provide terrorism-related information to state, local, and tribal (SLT) authorities primarily through these fusion centers.
    Comparing the two bolded bits above, I like the first one a lot better. It emphasizes sharing and receiving information. The second implies that information-sharing is one-way. Hopefully I'm just being paranoid. The status report also says:
    As part of the ISE, State and major urban area fusion centers will blend Federal and local information and produce informational products that support the needs of law enforcement and other State and local executives as they develop strategic priorities for their Agencies and, at the same time, produce products that will support the needs of individual police officers, deputy sheriffs, emergency managers, homeland security officials, and others who work with community members to prepare for and prevent crime, violence, and disorder.
    They're aiming to network the fusion centers - a good approach:
    Pursuant to Presidential Guideline 2, the Federal Government is promoting the establishment of an integrated network of fusion centers to facilitate effective nationwide terrorism-related information sharing. ... .
    One question: Last November's implementation plan called for the creation of "hub" fusion centers: "
    DOJ and DHS will work with Governors or other senior State and local leaders to designate a single fusion center to serve as the statewide or regional hub to interface with the Federal government and through which to coordinate the gathering, processing, analysis, and dissemination of terrorism information."

    But the word "hub" does not appear in the status report. Has this idea been abandoned, or is it just further down the road?

    Here's how they're organizing the effort:

    An interagency Fusion Center Coordination Group (FCCG) has been established. Co-chaired by DHS and the FBI, this group, with the full participation of State and local officials, is responsible for ensuring that the Federal Government’s efforts to work with State and major urban area fusion centers are coordinated and carried out in a manner consistent with the President’s direction.

    The Interagency Threat Assessment and Coordination Group (ITACG) is the component within the NCTC that enables and ensures the timely and consistent Federal government-wide coordination of intelligence reports regarding terrorist threats and events that are intended for dissemination to SLT authorities and the private sector.
    Inclusion is good:
    There has been active participation by SLT government officials in all activities related to the development and design of the ISE. The ISC established a SLT Subcommittee to provide input regarding the needs and capabilities of SLT and SLT representatives were actively involved in drafting the ISE IP. Representatives also are involved in ISE-related working groups focused on implementing the ISE ...
    And there is money:

    DOJ and DHS are working together to ensure that relevant Fiscal Year (FY) grant programs prioritize efforts to establish fusion centers (first done for FY2007).

    And the feds will be involved, in-person:
    FBI and DHS are developing an integrated deployment plan to ensure both organizations deploy Federal personnel to State and major urban area fusion centers in a coordinated manner.
    But then .... there's this:
    Where practical, Federal organizations will assign personnel to fusion centers and, to the extent practicable, will strive to integrate and collocate resources.
    "Where practical"? "To the extent practicable"? That's no way to communicate a firm commitment to the effort, especially considering that a recent CRS report on fusion centers found that "
    federal participation in state and regional fusion centers appears to influence the relationship between levels of government, state, and local access to information and resources, the flow of information/intelligence, and maturation with regards to intelligence cycle functions ... In general, fusion centers collocated with a federal agency reported favorable relationships with that agency. This was often in stark contrast to the views of other fusion centers not collocated with a federal agency(s)."

    Hopefully I'm just still being paranoid. A few more uncoordinated notes:

    On the architecture:
    During this past year, the PM-ISE introduced the ISE architecture and standards framework, a cross-community, perpetuating framework to help ISE participants adjust, plan, install, and operate current and future information resources that form the infrastructure fabric of the ISE.
    On creating a culture of sharing:
    Development of a strong information sharing culture will require both the resources and commitment to improve current sharing practices and policies, and the accountability to ensure that the improvements are implemented.
    True enough, but they have a long way to go. They're just starting to develop the training on core concepts, both for federal agencies and SLT:
    “Core” awareness training and Agency-specific training are currently under development and review by the ISC Training Working Group.

    Furthermore, the ISC Training Working Group will assist DOJ, DHS, and FBI in the development of information sharing training guidelines for use by SLT governments.
    A last note on private-sector sharing and how it's envisioned:
    The Critical Infrastructure Partnership Advisory Council (CIPAC) is the primary mechanism through which this coordination takes place. The CIPAC facilitates decision-making across Federal, SLT government, and private sector partners to support ISE-related policy, strategy, plans, issues, and requirements development.
    They're going to network with the Sector Coordinating Councils and Government Coordinating Councils created under the National Infrastructure Protection Plan. (Though those are still under development, too.)


    Wednesday, September 19, 2007

    WHO Guidelines Mental Health and Psychosocial Support in Emergency Settings

    The WHO's Inter-Agency Standing Committee Task Force on Mental Health and Psychosocial Support in Emergency Settings has developed new guidelines for providing psychological support during emergencies. A few quick notes:

    The core idea behind [these guidelines] is that, in the early phase of an emergency, social supports are essential to protect and support mental health and psychosocial well-being.

    Scientific evidence regarding the mental health and psychosocial supports that prove most effective in emergency settings is still thin. ... The focus of the guidelines is on implementing minimum responses, which are essential, high-priority responses that should be implemented as soon as possible in an emergency.

    [This document] calls for a single, overarching coordination group on mental health and psychosocial support to be set up when an emergency response is first mobilised.
    The most practical part of the doc is the matrix of interventions (starts on page 19 of the doc), which defines general actions that should be considered during the preparedness phase, in the midst of the emergency, and during the long-term response and recovery phase.

    All things considered, this is a quite useful document for preparedness professionals.

    Tuesday, September 18, 2007

    How to Stay Put

    In a new report, the Redefining Readiness Workgroup argues that, with better preparedness on the part of communities, citizens can successfully shelter in place in the event of an emergency:

    In 2004, the Redefining Readiness study found that many people will not be able to shelter in place in an emergency. Exploring how the American public would handle a “dirty bomb” explosion, the study found that only three-fifths (59%) of the population would stay inside a building other than their own home for as long as officials told them. This is cause for concern because people who do not shelter in place will endanger themselves and others. When they go outside, they will expose themselves to toxic dust and radiation, and when they open the door to leave, they will put others in the building at risk by letting dust and radiation inside.

    The Redefining Readiness study showed that three-quarters of the people who would not be able to shelter in place under existing conditions would do so if certain issues were addressed.
    To examine how to resolve these issues, the RR Workgroup conducted discussions in a variety of communities, in which a number of residents examined the problems they might experience in a sheltering-in-place event. Many of the findings are pretty obvious, but a few are worth highlighting:
    People can’t protect themselves by sheltering in place unless they have timely, specific, and believable information about the emergency.

    Informing people about the emergency and what to do is important, but the ability of people to protect themselves by sheltering in place depends on a lot more than communication and public education.

    Much of what people and organizations currently are being told to do does little to help and sometimes makes matters worse. ... Currently, the public is being instructed to keep a supply of food and water in their homes, and most keep their medications there as well. But in a shelter-in-place emergency many people will need to take shelter in buildings other than their homes ...

    Managers are also being told to identify “safe rooms” where people can go to be protected from toxic substances outside. But while detailed instructions are usually given for sealing the room, little or no attention is paid to identifying and preparing rooms that:

    (1) can accommodate the number of people who are likely to need shelter;
    (2) give the people inside safe access to the supplies and facilities that are critical to meeting their basic, medical, and emotional needs;
    (3) assure breathable air and tolerable temperatures; and
    (4) minimize other conditions that can provoke unruly or violent behavior.
    Rather than tell people what to do, the RR Workgroup presents a series of questions for citizens to think about, in 4 contexts:
    • Households
    • Workplaces
    • Childcare settings, including schools
    • Government settings
    The questions provide good food for thought, but some of them are general and of limited use to a person without specific information about the threat. For example:
    How will we be protected from toxic substances outside if we are some place else at the time of the emergency, such as at work, school, day care, shopping, or in a restaurant?
    The answer depends on which toxic substance you're talking about, where you are in relation to it, what your options are for sheltering in place, etc.

    My biggest question is simple: How do you ensure that people will drill it? Compared to other, more common risks (e.g., fires, storms), accidents or attacks that might involve sheltering in place are relatively rare. Especially in contexts such as workplaces and schools, employees and students won't act correctly in an emergency unless they've drilled it.


    The Smartest Way to Spend $22 Million?

    Do we need this?

    H.R. 1955 would direct the Department of Homeland Security (DHS) to establish a university-based Center of Excellence for the Study of Violent Radicalization and Homegrown Terrorism in the United States. The bill also would establish a commission to investigate the causes of terrorist acts committed by persons raised or living in the United States and would require DHS to prepare reports on certain issues relating to domestic terrorism.

    CBO estimates that the agency would spend about $22 million over the 2008-2012 period to implement the legislation.
    It sounds like an attempt to centralize and formalize the study of extremism and terrorism. But the marketplace of ideas is a better forum for working this out.

    Friday, August 24, 2007

    Viral Transmission of Information on Explosives

    Here's another post from Douglas Farah that's well worth the time. The threat from terrorists is quickly evolving, allowing them to rapidly learn how to use deadly technologies more effectively.

    One of the most alarming things about the new transnationalism among terrorist groups is the rapid ability to transfer knowledge and technology, both through the the Internet and through individual training.
    A possible point of relevance: In a post last week I wondered if it's reasonable to conclude that travel overseas is necessary before a jihadist can become an operational threat. Farah's piece lends credence to the idea that, from a technological perspective, overseas in-person training is becoming less necessary.

    In this case, the more significant reason for overseas travel seems to be to take the last steps toward ultimate allegiance to the cause - a finding which the recent NYPD report on the radicalization process also indicated.

    Farah again:
    [W]hat is making the current situation different is that, instead of having to travel and hold clandestine meetings to trade information and methods, much of the information can now be transferred in the blink of an eye or the touch of a computer key.

    Military sources say that the switching from low tech Improvised Explosive Devices (IEDs) to high tech back to low tech is mirrored almost in real time between insurgents in Iraq and those fighting in Afghanistan.

    What's becoming clear is that the operational information that permits someone to learn the terrorist trade is becoming commoditized:
    With decentralized networks, sort of like Napster in the music world or Skype in the computer/telecommunications world, once a technology is invented to solve a certain problem, it is put out there with no strings attached. People can take it, improve it, merge it, and it belongs to no one and everyone.

    In reality we are fighting a viral network that can be disrupted, hurt, but which has a regenerative capacity that is only limited by the number of people wanting to wage jihad against us.
    Farah's last point is instructive. Strategic success in the war against jihadists is determined by the number of people wanting to wage jihad, because it is becoming increasingly difficult to keep a lid on the operational knowledge required to commit a terrorist act.

    The operational knowledge for committing terrorism is becoming a commodity.

    However, developing the motivation for committing terrorism is still entirely reliant on social networks. It is this aspect of the terrorist threat (and here I'm extending terrorism beyond jihadist terrorism) that provides a real vulnerability for the terrorist and a real opportunity for those seeking to prevent terrorism.

    Final thought: Are we sharing information as well as the insurgents in Iraq and Afghanistan?

    Wednesday, August 22, 2007

    North American Plan for Avian & Pandemic Influenza

    Courtesy of the State Department, we have a new North American Plan for Avian & Pandemic Influenza, which outlines a coordinated effort by Canada, the U.S., and Mexico to prepare for and respond to the threat of avian and/or pandemic flu.

    Here's its stated purpose:

    The North American Plan for Avian and Pandemic Influenza outlines how Canada, Mexico and the United States intend to work together to combat an outbreak of avian influenza or an influenza pandemic in North America.
    That word "how" may be a bit misleading, as the plan is short on operational details. In many places it simply says the three countries will "develop a plan to do X." Some snags are inevitable during the development and implementation of the operational elements.

    Still,
    the plan does seem to be based on the right principles. The plan is explicitly collaborative - appropriately so, as influenza ignores borders:
    Coordination among Canada, Mexico and the United States will be critical in the event of an avian influenza outbreak or pandemic. The Plan, therefore, describes the organizational emergency management frameworks in each of the three countries and how they intend to coordinate their activities.
    Of course, this isn't happening in a vacuum. Each country already has plans to deal with pandemic flu, including:
    The coordination among the three countries would be governed by:
    It's nice to see the plan pay attention to cascading effects, particularly critical infrastructure:
    While influenza cannot physically damage critical infrastructure, a pandemic could weaken it by diverting essential resources or removing essential personnel from the workplace. This Plan, therefore, extends beyond the health sector to include a coordinated approach to critical infrastructure protection, including the importance of business continuity planning and recognition of interdependencies among sectors.
    The coordination would start at the top:
    Canada, Mexico and the United States have established the senior level Coordinating Body on Avian and Pandemic Influenza to facilitate planning and preparedness ... This Coordinating Body is to serve as the contact group in the event of an outbreak of highly pathogenic avian influenza or a novel strain of human influenza. It is to convene to support rapid and coordinated decision making, facilitate information sharing and address other coordination issues. Because the trilateral Coordinating Body includes senior officials from most of the key agencies that would be involved in supporting the response to an avian influenza outbreak or pandemic influenza, it is intended to play a significant role in promoting coordination among the three countries at senior official levels.
    On the ground level, the plan calls for emergency response assistance in the event of a pandemic, as well as joint training in preparation for a potential pandemic:
    Specifically, the authorities of Canada, Mexico and the United States intend to conduct trilateral or bilateral exercises to assess and strengthen their emergency response and contingency plans.
    One of the more interesting parts of the plan is the communications strategy. The three countries intend to:
    • Meet regularly on communications issues and seek opportunities to work together on communications planning and messaging;
    • Establish procedures and pathways to exchange pre-release information during the event;
    • Identify appropriate communications point persons from each country to maintain regular contact, share information, and identify and address emerging issues;
    • Develop plans for communications coordination during the actual event of an outbreak of avian or pandemic influenza;
    • Undertake the development of risk communications strategies to provide stakeholders with information on disease prevention, disease recognition, bio-security procedures and their responsibilities in the event of an incursion of avian or pandemic influenza;
    Pursue the development of risk communications strategies in relation to pandemic influenza to help decision makers and individuals make well-informed decisions and take appropriate actions on health risk issues to help reduce mortality, morbidity and socio-economic disruption;
    Develop key messages related to avian and pandemic influenza for the specific use of senior officials;
    Pursue the development of communications messages for avian influenza and both pre-pandemic and pandemic periods. Messages would focus on core themes such as efforts to control spread of avian influenza, import/export measures, border measure, etc.;
    The three countries plan to share information in a variety of relevant areas, including outbreaks in animals, surveillance, epidemiology, traits of the virus, and vaccine development and production.

    Sharing personnel is a concern. The approach is rather encouraging - the plan is to expedite licensing recognition as well as create established liaison positions among public health personnel.
    It is possible that a state or province will request additional health care personnel through its national government to respond to an emergency. Because each state or province in the United States and Canada, respectively, controls the licensure of health professionals, the national government should encourage its states or provinces to develop procedures for the exchange of licensed personnel that may include the temporary, rapid recognition of existing licenses or certificates. In the case of the Mexican states, the Federal Labor Law governs licensure. Thus, movement of personnel among and within the Mexican states and municipalities requires no additional procedures. Issues such as liability, indemnification and proper documentation necessary to work in the other countries should be addressed through relevant national, state or provincial authorities.

    Canada, Mexico and the United States intend to establish protocols for the exchange of appropriate public health liaison officers. Each country, at the request of one of the other countries, should deploy a liaison officer to the public health department/agency of that country on an ongoing basis. The public health liaison officer should act as a liaison for the other national public health department/agency, facilitate communications among emergency operations centers (EOCs) and be a point of contact for the officer’s particular national public health agency.
    The creation of dedicated liaisons should only help the collaborative efforts of the public health systems in the three countries. Dedicated liaisons will be able to create closer, more trusting relationships than ad hoc liaisons would be able to.

    On critical infrastructure issues, the plan has the right intentions, if few details:
    Where appropriate, governments should coordinate timely national, regional and local support among appropriate public and private sector resources.
    This is a bit confusing:
    The countries intend to develop mutually acceptable risk, vulnerability and interdependency assessment procedures and methodologies. The countries also intend to undertake joint and/or coordinated risk assessments.
    Wait a minute. They're going to start by developing procedures and methodologies for evaluating the risk, vulnerability and interdependency of critical infrastructure sectors? And then they're going to conduct the risk assessments?

    In the U.S., that work is supposed to be ongoing already, as part of the ongoing National Infrastructure Protection Plan (NIPP). While I grant that there may be specific ways in which cross-border interdependencies differ from intra-border interdependencies, the general interrelationships among critical infrastructure sectors ought to be similar whether you're examining the infrastructure in a nation or a region. So - are we doing the same work twice? (See these two posts for background on the NIPP's status.) Another problem: The risk assessments aren't due to be complete until December 2009.

    Even without consulting a thorough risk assessment, the plan identifies the food sector as a particularly obvious vulnerability:
    Given the significant degree of North American integration, the agri-food sector is particularly vulnerable to disruptions in cross-border trade, as there is significant cross-border movement in key farm inputs, intermediate agricultural products and final food products.
    Here's a half-a-loaf idea:
    The countries should develop contact lists of all appropriate key critical infrastructure public and private sector partners in order to improve coordination among all partners domestically and internationally during a pandemic. These lists should be updated regularly, perhaps annually, and should also include clearly established communications roles and responsibilities.
    That's a good start, but the simple fact of the list isn't going to make collaboration better. To the contrary, the existence of the list may provide a false sense of security unless the key critical infrastructure partners actually do some on-the-ground coordination. To its credit the plan encourages this but also seems to equivocate on the idea, as the critical infrastructure owners are mostly private sector entities which can't be easily co-opted into the international plan. Here's some rather wishy-washy language for you:
    To the best of their abilities, the three countries are to endeavor to include an array of relevant public and private sector critical infrastructure partners and appropriate public health officials in their pandemic preparedness training and exercises to help uncover potential weaknesses in established systems and to forge bonds among personnel.
    That last bolded bit is good - it is a good reason to succeed in this effort. But the first two bolded bits already seem to indicate some backtracking in case the private sector partners don't want to play along.

    As I said earlier, the plan does seem to have the right idea regarding coordinated effort. But it's easy to have the right idea at the outset of a project. When you get down to the operational level, that's the real test. Most of the tasks required by the plan are due to be completed within the next 12-18 months, and they'll give a better idea of the operational details. We'll see where it goes from here.

    Monday, August 20, 2007

    Excellent Questions, Good Responses

    At The Logbook, Justin asks an excellent question - one I hadn't seen asked before - regarding the Minneapolis bridge collapse.

    The bridge disaster was bad enough; but the threat can multiply quickly in the event of cascading failures. Intentional actors such as terrorists will seek to create cascading failures, so accounting for them is an essential element of preparedness.

    Fortunately, emergency managers in Minneapolis were prepared for a number of contingencies that presented themselves in the bridge collapse - in some cases, the plans had recently been completed:

    Before the bridge fell:

  • The state practiced snap assembly of an emergency operations center, where agencies could quickly coordinate their immediate response to a tragedy.
  • Minneapolis studied where to place massive amounts of debris in a disaster.
  • Most local law enforcement officials had updated radio systems, allowing them to talk to each other in emergencies.
  • The Minnesota Department of Transportation developed traffic plans in case a bridge failed.

  • "We had a state bridge, in a county river, between two banks of a city. ... But we didn't have one problem with any of these issues, because we knew who was in charge of the assets," said Rocco Forte, Minneapolis emergency preparedness director.

    Rescuers also could talk to each other on emergency radios. ... Carver, Anoka and Hennepin counties' emergency responders all use new-generation 800 MHz radios.

    The planning and preparations also paid off in almost eerily specific ways.

    "We do have a plan for if a bridge goes down. Our folks didn't have to sit there and say: 'OK, what are we going to do?' We had a plan in place. That's why it could happen as quickly as it did," Transportation Commissioner Carol Molnau said.

    And Minneapolis officials were trained and equipped to deal with a structural collapse. In 2002, city, county and state officials realized they had no one ready to deal with a massive building collapse. "It was a huge gap to have identified," said Tim Turnbull, director of emergency preparedness for Hennepin County. ... The city of Minneapolis secured about $3.5 million for training and equipping a collapsed-structure team.
    There's simply no substitute for preparedness - as this well-written post from ThreatsWatch points out. The crux of the argument:
    Much more important than planning, preparedness is about setting up social structures so that people fall into doing something sensible when things go wrong.

    It really doesn’t matter what disaster scenario you’re testing. The real disaster won’t be like the test, regardless of what you do, so just pick one and go.
    Yup.

    National Bio-Surveillance System Falls Short

    Over at In Case of Emergency, Jimmy Jazz walks us through the recent DHS Inspector General's report on the National Bio-Surveillance Integration System (NBIS). It's not a pretty sight. The DHS OIG concludes that:

    NBIS, a key element of DHS’ bio-protection program, is falling short of its objectives. Specifically, DHS has not provided consistent leadership and staff support to ensure successful execution of the NBIS program.
    Jimmy summarizes the problem:
    To date, there is no coordinated effort to coalesce the data gathered into anything resembling intelligence - never mind injecting actual intelligence reports into the soup that is bio-surveillance.
    The challenge of creating and/or integrating information sharing systems continues to be an ongoing problem - from HSIN to fusion centers to the NBIS.

    Fighting Leaderless Networks

    Here's a nice post from Douglas Farah on the increasing phenomenon of decentralized, leaderless networks such as the "new" al Qaeda or revamped organized crime networks. Farah argues that a new strategy is required for fighting these networks. A few key paragraphs:

    As a starfish can reconstitute itself out of almost any part that is severed, and has no real, centralized brain but a series of nerve impulses that guide its movements, so terrorist groups and criminal groups often thrive when deprived of centralized leadership.

    This leads to deeply-troubling scenarios, because so much emphasis, both here and abroad, has focused on decapitating the leadership, rather than dealing with the network as a network.

    Decapitation is often the key strategic objective, because our entire system is geared toward fighting organizations with a strict hierarchy, as our organizations are.

    Successfully countering these groups and their growing reach will require a radical new assessment of both strategy and tactics in the military, intelligence community and law enforcement. But that will require a willingness to dump old assumptions and paradigms, something that has not really happened since 9-11.
    Random thoughts:

    1. Perhaps the network-vs-network element of the current anti-al Qaeda strategy in Iraq (i.e., cooperating with local tribes and former insurgent groups) is one reason for its effectiveness, as compared to former tactical approaches.

    2. From a local homeland security perspective, what are the active local networks that could be used to counter the terrorist threat? What do we know about "our turf" that can be turned to strategic or tactical advantage?

    3. What potential local networks do not exist yet?

    4. What local networks could be made more effective?

    Other Views on the NYPD Report

    In a follow-up to last week's post about the NYPD report on jihadist radicalization, today I did a quick review of what others are saying about the report. I've tried to avoid the shallow analyses and partisan sniping that the report has generated and focus on some substantive comments from various corners:

    TPM Muckraker argues that the radicalization process described by the NYPD is too generic to be of much practical value:

    [T]he process is itself a generic description of the process of joining any identity-oriented group. al-Qaeda adherents or al-Qaeda-inspired radicals are a maddeningly diverse bunch, extending in background from former high-tech engineers to Mary Kay cosmetics representatives to former metalheads. They can be second-generation U.S. or European Muslims, or converts.

    As a result, describing patterns of "pre-jihadist" behavior inclines towards the generic, making it difficult to know what to do with the information.
    Point acknowledged. There are two ways to deal with this, as I see it:

    1. To locate potential emerging jihadist radicals, make sure you've got trustworthy contacts within the local Muslim community. (More on this below.) Unlike other major battles that law enforcement must fight (e.g., against organized crime, drug gangs, etc.) the fight against jihadist radicalization includes an element that can potentially serve as a major advantage: The presence of trustworthy people who may be in close proximity to potential jihadist radicals. It's worth remembering that as radicalization proceeds, jihadists tend to leave the mosque. They want to separate themselves from our potential allies within the Muslim community, who can help guard against emerging radicalism. The challenge for homeland security is developing a trusting relationship, often across religious and ethnic boundaries. It can be done, however.

    2. Watch for precursor crimes that emerging terrorists tend to commit. The commission of these crimes differentiates potential terrorists from other identity-oriented groups.

    Columnist Peggy Noonan argues that we make it easy for potential terrorists to see us as "bad":
    The only thing I'd add is that all modern young people come from two environments. The first is the immediate family, which is human and therefore by definition imperfect, sometimes to a serious and destructive degree. The other is the broader culture in which we all live, and which includes everything from schools to the neighborhood to the media. It's not a new thing to say but it's still true that the latter, which is more powerful than ever, is wholly devoted to the material. People are money winners or luxury item enjoyers. They just want stuff. It is soulless.

    The view we show of life to ourselves, and to whatever lost young men are watching, is not broad and inspiriting. It is limited and dispiriting. It is every man for himself.

    We make it too easy for those who want to hate us to hate us. We make ourselves look bad in our media, which helps future jihadists think that they must, by hating us, be good.
    Even if Noonan is right that the root of the problem is a "soulless" culture, this is such a broad take on the problem that it's hard to know what to do with it. Such a broad, sweeping problem would require a broad, sweeping solution.

    On the local level, I suppose it's possible to do everything we can as individuals to show that American culture is not soulless. Most people already do that every day. I suppose it's always good to remind ourselves to be good, though.

    Senator Joseph Lieberman (I - CT) issued a statement which mostly consisted of bland platitudes. But I though this particular bland platitude was worth repeating:
    The report underscores the critical role of local law enforcement in proactive efforts to find the terrorists before they strike.
    I'd be doing a disservice if I didn't consider the reaction from major American Muslim organizations; after all, this is a report about the potential growth of jihadism in the U.S. The Council on American-Islamic Relations (CAIR) said the report would cast suspicion on all Muslims:
    [A] new NYPD report on "radicalization" may result in all U.S. Muslims being viewed with suspicion.

    "Whatever one thinks of the analysis contained in the report, its sweeping generalizations and mixing of unrelated elements may serve to cast a pall of suspicion over the entire American Muslim community."
    The Muslim Public Affairs council added:
    The report and comments made by NYPD officials use overly broad language to describe average Muslim American young people who they say could pose a threat. ... This generalization could potentially lead to further isolation of youth who will feel like they are being singled out due to their racial or religious background.
    Meanwhile, the American Islamic Forum for Democracy (AIFD) commended the report and criticized the reaction of CAIR and MPAC, arguing that:
    Understanding the ideological footprints which create a radicalized Islamist is vitally necessary in detecting and preventing future tragedies from occurring. Vigilance and caution is far different from blanket suspicion.
    My take: If everyone acts incredibly dumb about this, then CAIR and MPAC could be right. If law enforcement agencies do in fact read the report as MPAC reads it (i.e., as a direction to "be on the lookout for Arab males between the ages of 18-35") then they'll cast a net that's far too broad and in the end they'll end up alienating the very people who could be helpful allies in this ideological struggle.

    If, however, everyone is smart about it, then no such scenario needs to occur. Jihadist-inspired terrorism is a fact, and the U.S. is vulnerable to it (New York in particular). It is perfectly reasonable for the NYPD to examine this phenomenon and its roots - in fact it would be a dereliction of duty for the NYPD not to examine it. Furthermore the NYPD is right to point out that you can't predict where a jihadist will come from. The profile of jihadists is incredibly diverse. The stories of John Walker Lindh and Adam Gadahn are more than enough evidence of that.

    I'll go out on a fairly sturdy limb and say that the average U.S. police officer does not have a deep, highly sophisticated understanding of Islamic theology and/or a very intimate familiarity with the Muslim community in their jurisdiction. To avoid counterproductive, "broad brush" anti-terrorism efforts, they need better information. They need to understand the subtleties that may indicate cells of jihadism within the Muslim community. The best way to gain this understanding is through sharing information with the Muslim community itself.

    If both law enforcement and American Muslims are smart, they'll collaborate in the interest of a common goal: preventing radicalization and jihadism in the U.S. If neither makes the attempt, then an important opportunity will be missed.

    Wednesday, August 15, 2007

    NYPD Report on Homegrown Terrorism

    The NYPD Intelligence Division has released a major new report on homegrown terrorism, Radicalization in the West: The Homegrown Threat. Specifically, the report focuses on the process by which seemingly ordinary citizens become radicalized as jihadists.

    The report has been briefly covered elsewhere. Here, I'll try to dig a bit deeper and connect it to some other sources on the radicalization and recruitment processes.

    A few initial thoughts:

    1. The NYPD study spends virtually all of its energy examining the activities of terrorists during the radicalization process - the phases during which radicals are recruited, become committed to the cause, and eventually go operational. As I've emphasized before, I think that the recruiting and radicalization process are absolutely the place to undertake counterterrorist activities. The earlier phases present the best opportunities for detecting existing radicals and for preventing the radicalization of potential recruits. The report itself says:

    Where once we would have defined the initial indicator of the threat at the point where a terrorist or group of terrorists would actually plan an attack, we have now shifted our focus to a much earlier point—a point where we believe the potential terrorist or group of terrorists begin and progress through a process of radicalization.
    2. From a theoretical perspective, the study does not really provide much new insight into the radicalization process. The four-step process described in the NYPD study (Pre-Radicalization, Self-Identification, Indoctrination, Jihadization) has been described elsewhere, albeit in different terms. For example, see the State Department's recent e-journal Countering the Terrorist Mentality, this chapter of the McGraw-Hill Homeland Security Handbook, or the excellent book Unconquerable Nation by Brian Michael Jenkins, who also participated in the creation of the NYPD report.) However, the NYPD study still has great value in that it describes how this process has played out in the real world, in 11 different cases of jihadism, both inside the US and in other Western countries.

    In other words, the study bridges the gap between theory and practice. As such, it provides a useful blueprint for law enforcement and other agencies (such as the FDNY) who seek to prevent future terrorist activities.


    3. The title of the NYPD report, "Radicalization in the West: The Homegrown Threat" strikes me a a misnomer, since the report focuses exclusively on jihadist radicalism. Generally speaking, the process of radicalization, as well as the attendant threat of terrorism, applies to other ideologies as well (e.g., the anti-government ideology of Timothy McVeigh).

    So ... on to the review.

    The guts of the NYPD report is as follows. If you read nothing else of this bloated post, read this:
    An assessment of the various reported models of radicalization leads to the conclusion
    that the radicalization process is composed of four distinct phases:

    • Stage 1: Pre-Radicalization • Stage 2: Self-Identification • Stage 3: Indoctrination • Stage 4: Jihadization

    o Each of these phases is unique and has specific signatures
    o All individuals who begin this process do not necessarily pass through all the stages
    o Many stop or abandon this process at different points
    o Although this model is sequential, individuals do not always follow a perfectly linear progression
    o Individuals who do pass through this entire process are quite likely to be involved in the planning or implementation of a terrorist act
    Significantly, NYPD makes an important note which I've argued before: There are "markers" to the radicalization process, and these present a significant vulnerability for potential terrorists:
    The four stages of the radicalization process, each with its distinct set of indicators and signatures, are clearly evident in each of the nearly one dozen terrorist-related case studies reviewed in this report.

    o In spite of the differences in both circumstances and environment in each of the cases, there is a remarkable consistency in the behaviors and trajectory of each of the plots across all the stages.
    o This consistency provides a tool for predictability.
    I'll take a closer look at the four stages suggested by the NYPD and then offer some insights into where we might go from here.

    Pre-Radicalization


    The NYPD points out that, for the most part, jihadists are self-selected. They move voluntarily into the radicalization process. (A point that was also made by Brian Michael Jenkins in his April testimony before Congress.) There are no specific triggers that spur the start of the radicalization process:
    [T]he transformation of a Western-based individual to a terrorist is not triggered by oppression, suffering, revenge, or desperation. Rather, it is a phenomenon that occurs because the individual is looking for an identity and a cause and unfortunately, often finds them in the extremist Islam.

    There is no useful profile to assist law enforcement or intelligence to predict who will follow this trajectory of radicalization. Rather, the individuals who take this course begin as “unremarkable” from various walks of life.
    It's been argued before that there is "no profile" for a jihadist, but I prefer the NYPD language - that there's "no useful profile." It's possible to create a profile, using the broad outlines that NYPD and others have suggested. Jihadist recruits do tend to be young males who are searching for something that will give their life meaning. But since that describes almost every male in the world between the ages of - say - 15 and 25, it's not particularly useful as a predictive model.
    This [Salafist] ideology is proliferating in Western democracies at a logarithmic rate. The Internet, certain Salafi-based NGO’s (non-governmental organizations), extremist sermons /study groups, Salafi literature, jihadi videotapes, extremist - sponsored trips to radical madrassas and militant training camps abroad have served as “extremist incubators” for young, susceptible Muslims -- especially ones living in diaspora communities in the West.

    The Internet is a driver and enabler for the process of radicalization.

    The radicalization process is accelerating in terms of how long it takes and the individuals are continuing to get younger. [JB: Trends that have also been noted in Britain.] Moreover, with the higher risks associated with heading down this pathway, individuals will seek to conceal their actions earlier, making intelligence and law enforcement’s job even more difficult.

    Individuals generally appear to begin the radicalization process on their own. Invariably, as they progress through the stages of radicalization they seek like-minded individuals. This leads to the creation of groups or clusters. These clusters appear almost essential to progressing to the Jihadization stage—the critical stage that leads to a terrorist act.
    The last paragraph above is vital: Radicalization is a social process. Groups of like-minded people are almost always involved.

    There are very few Ted Kacynski's out there - loners who are drawn into radical beliefs and progress on their own through the process of becoming operational terrorists.

    This is a vulnerability for terrorists. They must cluster together. They must have safe spaces. They must, at some point, share their radical beliefs with one another. As they go operational, they must maintain security.

    There is not only an actual vulnerability in all of these social activities; there is also a strong perception of vulnerability. Terrorists have to look over their shoulders. Even the perception of a threat can be a strong de-motivating factor to them, as the anxieties of the Fort Dix plotters suggest.

    And even top al Qaeda strategists recognize the vulnerability of operations if the participants are not fully indoctrinated into the ideology.

    As a social process, radicalization relies on leaders:
    Although there are many groups or clusters of individuals that are on the path of radicalization, each group needs certain archetypes to evolve from just being a “bunch of guys” to an operational terrorist cell. All eleven case studies had a “spiritual sanctioner” who provides the justification for jihad—a justification that is especially essential for the suicide terrorist [as well as] an “operational leader” who is essential as the group decides to conduct a terrorist act--organizing, controlling and keeping the group focused and its motivation high.

    The sanctioner is responsible for developing the “Us-versus-Them/War on Islam” worldview among the group that provides the moral justification for jihad. The sanctioner is often a “self-taught” Islamic scholar and will spend countless hours providing a “cut-and-paste” version of Islam which radicalizes his followers. In many cases, the sanctioner is not involved in any operational planning but is vital in creating the jihadi mindset. The role of this “spiritual sanctioner” cannot be underestimated because “if an individual respects an Islamic scholar and that scholar tells him that fighting in the jihad is a religious duty and the only way to please God, the advice can have an enormous effect on choices.”
    The "self-taught" nature of the sanctioner is a vulnerability. Islam does not typically encourage freelancing where theology is concerned, which can help to undermine the perceived religious justification for jihadism. Of course, to adopt this strategy will imply the development of a relationship with local, respected Muslim imams.

    Without a solid foundation in ideology, the terrorist project can crumble:
    Ideology is the bedrock and catalyst for radicalization. It defines the conflict, guides movements, identifies the issues, drives recruitment, and is the basis for action.
    See also the recent testimony by Frank Cilluffo, director of the Homeland Security Policy Institute at George Washington U, who argued that "extremists have woven an effective tale of an imaginary “clash of civilizations.” The extremists’ compelling “call to action” based partly on myths and falsehoods begs for the development of an effective counter-narrative that forcefully refutes and responds to the extremists’ own.

    Of course, along with ideological grounding there are more practical concerns. Since radicalization is a social process, jihadists need physical spaces in which to operate:

    Critically important to the process of radicalization are the different venues that provide the extremist fodder or fuel for radicalizing—venues, to which we refer to as “radicalization incubators.”

    Generally these locations, which together comprise the radical subculture of a community, are rife with extremist rhetoric. Though the locations can be mosques, more likely incubators include cafes, cab driver hangouts, flophouses, prisons, student associations, nongovernmental organizations, hookah (water pipe) bars, butcher shops and book stores. While it is difficult to predict who will radicalize, these nodes are likely places where like-minded individuals will congregate as they move through the radicalization process. The Internet, with its thousands of extremist websites and chat-rooms, is a virtual incubator of its own. In fact, many of the extremists began their radical conversion while researching or just surfing in the cyber world.
    The existence of these "incubators" can facilitate the transition from peaceful, pre-radicalized citizen to self-identified jihadist.

    Self-Identification Phase

    As indicated before, potential jihadists are typically seeking a cause - something to give meaning to their lives. If they find a cause and meaning in a radical group, they are susceptible to radicalization themselves:
    Individuals most vulnerable to experiencing this phase are often those who are at a crossroad in life—those who are trying to establish an identity, or a direction, while seeking approval and validation for the path taken.

    Ultimately the individual is alienated from his former life and affiliates with like-minded individuals, who, via small group dynamics, strengthen his dedication to Salafi Islam. Importantly, this phase is characterized by a self-selection process by which individuals first join a group that then becomes radicalized.

    These crises often compel these individuals to seek out other like-minded individuals, who may be experiencing the same inner conflict. Subsequently, clusters of like-minded individuals begin to form, usually around social circles that germinate within the extremist incubators.
    It should be noted that this process of self-identification is not unique to the jihadist enterprise. Young people want to join something that gives structure and meaning to their lives.

    In a healthy environment, young people will have a wide range of positive choices to do so. These may be affiliated with churches, schools, civic organizations, the military, a trade or technical profession - just about anything.

    But the negative side, young people may find meaning and support within gangs, criminal organizations, or even terrorist organizations. This suggests that it is vital to ensure that young people are exposed to a wide range of positive choices.

    Indoctrination

    As suggested by the al Qaeda doctrine referred to above, it is essential for jihadists to entirely accept the ideology. This occurs during the Indoctrination stage.
    Indoctrination is the stage in which an individual progressively intensifies his beliefs, wholly adopts jihadi-Salafi ideology and concludes, without question, that the conditions and circumstances exist where action is required to support and further the Salafist cause.

    The key aspect of this stage is the acceptance of a religious-political worldview that justifies, legitimizes, encourages, or supports violence against anything kufr, or un-Islamic, including the West, its citizens, its allies, or other Muslims whose opinions are contrary to the extremist agenda. In effect, as the individuals become indoctrinated, they re-define their direction in life.
    NYPD suggests that, for jihadists, one of the key indicators of this stage is ironically:
    Withdrawal from the Mosque. As individuals begin to conceive militant jihad as an objective, they retreat from the mosque—the mosque that not only served as an extremist incubator for their formative years in becoming radicalized but also and often as the place where these individuals met their like-minded cohorts. This withdrawal is sometimes provoked by the fact that the mosque no longer serves the individual’s radicalization needs. In other words, the individual’s level of extremism surpasses that of the mosque.
    This suggests that a trusting relationship with the local imam may be helpful in identifying potential radicals.

    Jihadization

    During the final phase, Jihadization:
    [M]embers of the cluster accept their individual duty to participate in jihad and self-designate themselves as holy warriors or mujahedeen.
    The group is more important, but also harder to bust.
    By the jihadization phase, small group dynamics play a much more prominent role. While during the earlier stages, the group members may have been only acquaintances, meeting each other in Salafi chat rooms, at university or simply by being friends, by the jihadization phase the group has solidified and hardened. Individuals see themselves as part a movement and group loyalty becomes paramount above all other relationships.
    Once indoctrination is complete, the Jihadization stage may occur quickly. And for one or more members of the group, overseas travel may be a trigger:
    It is critical to note that while the other stages of radicalization may take place, gradually, over two to three years, the jihadization stage—the stage which defines the actual attack--can occur quickly, and with very little warning. In some cases, this stage runs its course in as little as a couple of weeks. The jihadization stage contains many substages, all of which usually occur, but not necessarily sequentially. Each of these substages is characterized by a unique set of indicator(s).

    • Accepting Jihad/Decision to Commit Jihad. As each group member accepts jihad, they often look abroad--seeking that one trigger that will lead to their final acceptance of jihad or for others an opportunity to actually conduct jihad.

    Frequently, but not always, one or more members of a particular Western-based cluster travels abroad. This travel often follows or contributes to a member’s decision to commit jihad. The travel is more often than not to a militant training camp—a camp usually in a country or region that is regarded as a field of jihad.
    There are also more mundane matters in going operational. All of these present opportunities for detection and intervention:
    Prior to launching the attack, many of these clusters have participated in some form of group training and preparation to include:

    “Outward Bound”-like Activities. Activities such as camping, white-water rafting, paintball games, target shooting, and even outdoor simulations of military-like maneuvers have been popular among these groups once they reach this stage of radicalization.

    Attack Planning. Once a cluster or group decides to conduct an attack, they begin conducting research while holding secretive tactical group discussions on targets, the mode of attack, the operational scenario (date, time, and hour), and the role of each group member. This sub-stage includes several indicators such as:

    o Reconnaissance/Surveillance. Drawing maps, videotaping targets, and staking out target areas will invariably be conducted in the run-up to any attack.

    o Acquiring Materiel/Developing the Device. The majority of the devices used or that were being planned to be used in the homegrown plots were either commercially available or reasonably obtainable. Fertilizer-based devices, commercial explosives, cell phones and explosive ignition devices have all been acquired with relative ease.

    That said, the acquisition of the materiel and the development of the weapon has on occasion been associated with low-end criminal activity and almost always suspicious activity such as: cooking chemicals to form explosives in bathtubs, purchasing large amounts of any one chemical or material, outfitting/modifying backpacks, buying TNT and wiring watches as detonators.
    If the signs of radicalization are not discovered by this time, it's essentially too late:
    The ultimate stage of jihadization is, of course, the actual attack. By this time, all the potential preemptive indicators have expired. The terrorists have attained both intention and capability and the chances for law enforcement and intelligence thwarting or preventing an attack is extremely low.
    This is the same point I made in this post regarding the London and Glasgow bombings.

    Strategies for Addressing the Radicalization Process


    What to do about the radicalization process, then? The challenges are clear:
    Identifying whether an individual is being radicalized is hard to detect, especially in the early stages.

    The individuals are not on the law enforcement radar. Most have never been arrested or involved in any kind of legal trouble. Other than some commonalities in age and religion, individuals undergoing radicalization appear as “ordinary” citizens, who look, act, talk, and walk like everyone around them. In fact, in the United Kingdom, it is precisely those “ordinary” middle class university students who are sought after by local extremists because they are “clean skins”.

    In the early stages of their radicalization, these individuals rarely travel, are not participating in any kind of militant activity, yet they are slowly building the mindset, intention, and commitment to conduct jihad.

    As evidenced by all eleven case studies these groups, or clusters of extremists:

    Act autonomously, can radicalize quickly, and often are made up of individuals, who on the surface, appear to be well-integrated into society.

    Are not “name brand” terrorists or part of any known terrorist group. For the most part, they have little or no links to known militant groups or actors. Rather they are like-minded individuals who spend time together in clusters organized, originally, by previously established social network links.

    Are not crime syndicates and therefore, applying organized crime strategies will fail.
    The NYPD report does not delve deeply into potential solutions, but instead provides a template for understanding how solutions may be developed.

    In his introduction to the NYPD report, RAND's Brian Michael Jenkins also contextualizes the challenge for law enforcement:
    [E]fforts should be made to enhance the intelligence capabilities of local police, who through community policing, routine criminal investigations, or dedicated intelligence operations may be best positioned to uncover future terrorist plots. Of these, continued intelligence operations are the most important. Radicalization makes little noise. It borders on areas protected by the First and Fourth Amendments. It takes place over a long period of time. It therefore does not lend itself to a traditional criminal investigations approach.
    NYPD notes that signs of radicalization are often subtle:
    The subtle and non-criminal nature of the behaviors involved in the process of radicalization makes it difficult to identify or even monitor from a law enforcement standpoint. Taken in isolation, individual behaviors can be seen as innocuous; however, when seen as part of the continuum of the radicalization process, their significance becomes more important. Considering the sequencing of these behaviors and the need to identify those entering this process at the earliest possible stage makes intelligence the critical tool in helping to thwart an attack or even prevent the planning of future plots.
    In the US cases examined by NYPD, it was not always even readily apparent that radicalization had occurred:
    The three U.S.-based cases provided fewer examples of signature activities during the stages and sub-stages of the radicalization process than the five foreign examples. The lack of rich details on these U.S. cases, coupled with the fact that they were disrupted at a relatively early stage, obscured the fact that radicalization had occurred.
    Although NYPD does not provide a blueprint for intervention, others have suggested potential approaches to countering the radicalization process. I think there's a nice dovetail between the radicalization process identified by NYPD and the solution set offered by the State Department in Countering the Terrorist Mentality:
    To make such active measures effective, the three strategic components of the terrorist threat that must be neutralized are leaders, safe havens, and underlying conditions.
    Addressing underlying conditions will affect the Pre-Radicalization stage. Disrupting the perceived security of safe havens will frustrate the Self-Identification and Indoctrination stages. Identifying and neutralizing leaders will deter action during the Indoctrination and Jihadization stages.

    Another preventive approach is the "Capone Strategy" I've discussed before, which exploits the common vulnerability of terrorists: the commission of "precursor crimes." (See this CRS report for more on precursor crimes.)

    From a broader perspective, it is important to recognize that "top-down" approaches are likely to be ineffective. Per the previously cited testimony by Frank Cilluffo:
    [T]he solution sets for the problem under discussion must emanate principally from the grassroots, from local communities, their leaders and the citizens that reside there. ... law enforcement at the local level should develop new relationships and deepen existing ones within Muslim communities as local figures are best placed to identify radicalization at its earliest stages.
    There is, of course, a delicate balance to be maintained here, as Jenkins alluded to when he discussed First and Fourth Amendment concerns. The United States cannot become a police state. The nation was founded on the then-radical principle that if people are given liberty, they can be generally counted upon to do the right thing. In short, we are a nation built on trust. We cannot jeopardize that principle. As Frank Cilluffo and 9/11 Commission co-chair Lee Hamilton argued on behalf of the Future of Terrorism Task Force:
    Trust is the most valuable currency we have in this battle because trust underpins all counterterrorism tools (e.g., military, diplomatic/policy, legal, economic and covert action).
    All things considered, the NYPD report is an excellent addition to the literature that can help local homeland security professionals develop a strategy to prepare for and prevent terrorism.

    Cross-posted in IPS Blogs at the Institute for Preventive Strategies.

    Got Infrastructure?

    A thought regarding the continued dust-up in New York over the Buckeye Pipeline:

    "Sections of this pipeline are located in areas not visible to routine police and security patrols," Rasinya said in his testimony to representatives of the state Senate and the Police Department, the Mayor's Office of Emergency Management, the American Red Cross and local Civilian Emergency Response Teams.

    Right now, the pipeline is protected only by a broken Cyclone fence that is easy to break through or hop over.
    Putting aside the question of the seriousness of this particular plot, the attention on the pipeline raises a legitimate question for local emergency preparedness and response personnel:

    What are the critical infrastructure elements in your community?

    The US is criss-crossed with critical infrastructure networks. Besides fuel and natural gas pipelines, are there key nodes in the electric grid? Key chokepoints in the transportation and shipping network (e.g., bridges, tunnels, distribution centers)? Telecommunications hubs? Aqueducts? Financial centers?

    These questions apply to all-hazards preparedness, not just terrorism preparation and prevention. Knowing the critical infrastructure nodes translates into better opportunities for prevention, as well as improved response and recovery.

    U.S. Jihadists: Passport Required?

    The following snippet from Chris Heffelfinger's recent piece in Terrorism Monitor, "Behind the Indoctrination and Training of American Jihadis," caught my eye:

    After conducting numerous case studies at the Combating Terrorism Center at West Point, research has demonstrated a pattern for radicalization among Americans who embrace jihad, whether foreign or U.S. born. The cases of the Lackawanna Six, the Portland Seven, the Virginia Jihad Group, as well as John Walker Lindh, Adam Gadahn and others demonstrate the need to travel overseas to receive training. In all of the above cases, the individuals traveled, or attempted to travel, to Pakistan or Afghanistan.
    Yes ... but past performance does not necessarily indicate future results.

    Heffelfinger seems to be arguing that traveling and training overseas are necessary preconditions for jihadist radicalization among Americans.

    While I acknowledge that the U.S. terrorism suspects who have lacked overseas training have been more aspirational than operational, it seems premature to conclude that in the absence of overseas training, radicalization and/or technical proficiency in terrorist tactics is not possible.

    We are a nation awash in potential targets and the materials necessary to carry out a terrorist act. And while there is a strong social element to terrorist indoctrination, it certainly seems to be possible that a group of like-minded individuals could spur one another down the path to jihadism.

    Tuesday, August 14, 2007

    Disaster Communication and New Technologies

    A couple of notes regarding communication technologies:

    Via Jimmy Jazz, we learn that the LA Fire Department is using Twitter to provide quick updates and information - mostly responses to accidents, fires, etc., but also new postings on the LAFD blog.

    Via GovTech, we learn that Minneapolis' principal WiFi consultant discovered a number of new uses for the WiFi network during the recent bridge collapse:

    As the event unfolded, a number of immediate potential uses of the wireless network became apparent. They included
    • opening an alternate path to electronic communication and information for city personnel;
    • extending the Wi-Fi network infrastructure to fully blanket the scene of the bridge collapse for emergency personnel onsite connectivity;
    • implementing live multiple perspective camera coverage of the scene for EOC and Command Post uses;
    • and providing community links to city of Minneapolis resources, hospital emergency coordination units, state of Minnesota Department of Transportation (MNDOT) traffic routing information, Red Cross Blood Bank collection points, and local and national news outlets.
    As communication technologies proliferate, local agencies will have an ever-increasing range of communication options that may be used in an emergency situation. This also means that, if communications are to be coordinated and effective, plans will have to be strategic and constantly reviewed.

    Pandemic Preparedness and Non-Pharmaceutical Interventions

    The public health folks at Effect Measure do their usual good job as they analyze a study (subscription only) in the Journal of the American Medical Association (JAMA), which Time also covered.

    The JAMA study examined the effectiveness of various non-pharmaceutical interventions (NPIs) in mitigating the spread of the 1918 Spanish Flu pandemic. For local communities, examining such a study is useful in light of the fact that the CDC's interim Community Flu Planning Guide emphasizes the early, layered, targeted use of non-pharmaceutical interventions (also see this post).

    In examining the JAMA study, Effect Measure finds:

    They classified the non pharmaceutical interventions (NPIs) into three broad categories: school closures; bans on public gatherings; isolation and quarantine and looked at timing and timeliness as well as combinations of NPI categories for effects on excess mortality, height of epidemic peak and timing of epidemic peak, using multivariate analysis.

    What is quite clear from the analysis ... is that information about when, how long and in what combination NPIs were used in relation to the onset of the epidemic in a city explains a great deal of the variation in epidemic experience.

    The analysis showed that combinations were more effective than single interventions.
    Short answer: Layered interventions work.
    The bottom line is that the earlier a city acts and the more coordinated and multifaceted its response the better off it seemed to be -- in general. The data certainly do not demonstrate that quarantine itself is effective -- they are not able to make that statement. Cities that acted using isolation and quarantine did seem to do better, especially if in combination with other measures, but we don't know the effectiveness of either separately or in combination since they were not reported or analyzed separately in the paper.

    What these data do seem to establish is that the better prepared and organized a community is, the better off it will be. And the more a community ignores and denies a problem, the worse off it will be. This is the real message, not that "quarantines work."
    There is nothing surprising in learning that preparation is critical for an effective, coordinated response. It's always good to review empirical data, however.