Thursday, April 12, 2007

Private Sector Information Sharing in El Paso

The El Paso Times recently ran a short article about a new system that El Paso's downtown businesses have installed to share security information:

Downtown businesses are expected to be the first in El Paso to use a new Internet-based security message and information-sharing system that will allow businesses to share information on security issues or be instantly warned about emergencies.

"It will give us the ability at a moment's notice to send out an emergency notice from the Police Department or Fire Department," said Michael Breitinger, executive director of the Central Business Association and Downtown Management District, which has signed up more than 70 businesses so far to be part of the system.

The system will be used citywide when fully implemented. It will include public law enforcement and public safety agencies, private security firms, school districts, colleges and interested businesses.

El Paso Deputy Police Chief Ken Adcox, a member of the Law Enforce ment and Private Security, or LEAPS, group in El Paso, which is helping to implement the CityWorkSite system, said it will allow police to put out information, including photos and video, to a large number of people.

That could help in the search for a criminal or in finding a lost child, he said. Private security agencies and others also can send information to law enforcement agencies or to each other, he said.
I wonder if this system will mostly be used in a reactive mode, though. So far it sounds like it - they're planning to share information about crimes that have occurred or threats that have already manifested themselves. (And the anticipated flow of information seems to be mostly from the police and fire departments to the businesses, rather than the other way around or between the businesses.)

It will be good if they find ways to use the system - or at least exploit the improved communications that the system will promote - in a proactive mode as well. It sounds like an excellent conduit for sharing information about mutual security concerns and potential threats - before problems actually arise.

Hopefully, the installation of this system helps build bridges among El Paso businesses, as well as between police and private security.

DHS Investigating Chlorine Attacks

Just a brief note: DHS is investigating the Iraq chlorine attacks, GovExec reports:

Homeland Security Department officials are ramping up their efforts to prevent attacks that involve deadly chemicals, especially because insurgents in Iraq have increased their use of bombs laced with chlorine gas.

"We are literally analyzing the living daylights out of these attacks -- the people that are executing them, the agents that are used, the methods that are being used to detonate them and the impacts that they are having," said
Bob Stephan, the Homeland Security Department's assistant secretary for infrastructure protection. "And we are building lessons learned and case studies as these attacks continue to evolve."

The
National Infrastructure Advisory Council, which is comprised of members from private industry, academic institutions and state and local governments, has also made it a priority to complete a study on how the United States can prepare for and respond to chemical, biological or radiological attacks.

The study and associated recommendations are expected to be complete by October, council members said.
I'm a little uncertain about what this new study will do that others haven't done before. There is no shortage of information on CBRN attacks, and other groups (for example, the Gilmore Commission) have dealt with many of the same questions.

As for the
National Infrastructure Advisory Council, they are apparently finding it hard to find chemical industry representatives who are willing to share information with them. The level of trust isn't what it needs to be:
Council members on [April 11], however, noted some of the challenges they face in completing their study. The council is seeking experts who know what kinds of threats and vulnerabilities the chemical industry faces. The council also wants to ensure that information submitted by chemical facility owners and operators is protected from public disclosure.

"There's a general mistrust in industry of this kind of disclosure," said Erle Nye, the council's chairman emeritus.
Once again, we see the value of developing collaborative relationships based on trust.

Just one more thing, which is one of my pet peeves: DHS is not "literally analyzing the living daylights out of these attacks," unless they are actually managing to suck sunlight out of Iraq. It bugs me when people use the word "literally" when they're speaking figuratively.

Wednesday, April 11, 2007

Protecting the Food Sector: How Is DHS Doing?

Even more housecleaning: In February, DHS' Office of the Inspector General (OIG) published an analysis of DHS' role in defending the food sector, which is one of the critical infrastructure sectors identified in the National Infrastructure Protection Plan (NIPP).

The OIG's analysis is lengthy and comprehensive, resulting in 16 recommendations. My review will be selective, focused only on a couple of those recommendations. First, some background on OIG's report:

This report examines DHS activities relating to post-harvest food, and focuses on prevention, protection, preparedness, and detection efforts.

There are four main limitations in DHS’ related efforts.
  • First, DHS must improve internal coordination.
  • Second, DHS needs to engage its public and private food sector partners more effectively.
  • Third, DHS could do more to prioritize resources and activities based on risk.
  • Finally, DHS must fully discharge its food sector responsibilities.
The report makes clear that the risk to the food sector is real:
Food products may be deliberately contaminated with chemical, biological, or radiological agents. In 2003, the FDA wrote that, “If an unintentional contamination of one food … can affect 300,000 individuals, a concerted, deliberate attack on food could be devastating, especially if a more dangerous chemical, biological, or radionuclear agent were used.”
The effects could be significant:
The Centers for Disease Control and Prevention (CDC) estimates that the United States experiences 76 million illnesses, 325,000 hospitalizations, and 5,000 deaths from unintentional food contamination each year. Recent USDA estimates place the annual cost of premature deaths caused by a single common foodborne illness, salmonellosis – an illness resulting from infection with Salmonella bacteria – at over $2.1 billion.

Commentators on the subject have observed that an adverse food sector event could also reduce state and local governments’ ability to maintain order and deliver essential services. A major food contamination event could engender public panic on a local or mass scale, depending on the affected food product and population, and media coverage of the incident.
As I indicated, the OIG made 16 recommendations, but I'm going to focus on the ones that deal with DHS' relationships with other agencies and the food industry. My two emphases will be collaboration and information sharing.

Collaboration

The OIG report clearly indicates that DHS needs to improve its collaborative relationships. Everyone is not singing from the same songbook:
Vibrant cooperation and support between government and the private sector are needed to fully understand vulnerabilities, study possible consequences, prepare for threats, and implement mitigation measures.
One major complication to effective collaboration is the sheer size and complexity of the food industry:
The post-harvest food industry accounts for 12% of the nation’s economic activity and employs more than 10% of the American workforce. It consists of enormous subsectors, including business lines addressing processing, storage, transportation, retail, and food service. Statistics on just two of these subsectors serve to illustrate the magnitude of the sector.

The National Restaurant Association projects that the industry’s 925,000 U.S. locations will reach $511 billion in sales for 2006, serving over 70 billion “meal and snack occasions” for the year. Meanwhile, the nation’s $460 billion food retail business consists of more than 34,000 supermarkets, 13,000 smaller food markets, 1,000 wholesale club stores, 13,000 convenience stores, and 28,000 gas station food outlets.
Regulatory systems are equally complicated, encompassing all levels of government:
Regulation of the food industry is divided between federal, state, and local agencies. State, territorial, and local governments conduct oversight of food retail and food service establishments within their jurisdictions. These levels of government oversee restaurants, institutional food service establishments, and hundreds of thousands of food retailers. Within the federal government, primary responsibility for food safety rests with two agencies. The Food Safety and Inspections Service of the U.S. Department of Agriculture (USDA) oversees the processing of red meat, poultry, and processed egg products. The Food and Drug Administration (FDA) of the Department of Health and Human Services (HHS), in turn, regulates the processing of virtually all other food products. In addition to these two, several other federal agencies provide oversight of food processing, distribution, and retail.
But this complexity makes effective collaboration even more critical:
External coordination is essential for DHS to succeed in executing its responsibilities for food defense and critical infrastructure protection. Relationships with food sector partners are important because of the operational control and regulatory sway that they have with the sector. Related input from public and private sector partners is particularly valuable in light of DHS’ limited food sector experience. Partnerships with governmental entities are also vital because DHS shares so many food sector responsibilities.
To that end…
The Food Information Sharing and Analysis Center (Food ISAC) was established in February 2002…

According to industry representatives, the Food ISAC distributed some useful threat and vulnerability information to food industry associations and firms in 2002 and early 2003. By mid 2003, however, DHS’ Office of Infrastructure Protection had concluded that, as implemented, the Food ISAC was not well-suited to serve the department’s full range of information sharing and analysis objectives.
…and in 2003 many of the functions of the Food ISAC were moved to other newly created organizations …
In August 2003, Office of Infrastructure Protection managers assembled more than 200 food and agriculture sector representatives to discuss the department’s vision for information sharing and coordination. According to the Office of Infrastructure Protection, the assembled sector representatives were then given the opportunity to develop a new organizational structure. Two bodies emerged from this DHS-facilitated process – the Food and Agriculture Government Coordinating Council and the Food and Agriculture Sector Coordinating Council.
Meanwhile, the Food ISAC's output was not effectively replaced. A potentially valuable collaborative partnership was being spoiled:
By spring 2006, the Food ISAC’s contact with the government had deteriorated to the extent that, according to the ISAC, it did not have a dedicated DHS point of contact. This has contributed to a decline in the volume and scope of information disseminated to industry by the ISAC. Industry representatives reported that the flow of information from the ISAC to the private sector had declined, and that this decline had not been offset by increased information flow from other sources.

Instead of drawing on the food industry’s post-9/11 momentum on critical infrastructure protection efforts, DHS effectively alienated the ISAC’s leadership and disengaged from its operations. Meanwhile, as we discuss later, the coordination and information sharing mechanisms DHS instituted to address the ISAC’s limitations have been slow to develop and are only partially successful.
Meanwhile, as DHS was working to establish the two new councils, another problem was developing. According to food industry personnel, there was a lack of cooperative spirit:
Past and present council members attributed this sluggish start to DHS. They reported that DHS had taken a “top-driven” approach to its critical infrastructure protection leadership role, and that this detracted from the vitality of the councils and sapped the cooperative spirit from the process.

This approach reportedly created a difficult environment for the growth of collaborative efforts and did little to foster productive working relationships with industry leaders and government experts. Several council participants we interviewed said that DHS needed further growth as a business partner.
In its work with the councils, DHS in some ways acted more like a boss than a partner:
Early Sector Coordinating Council and Government Coordinating Council meetings did not foster efforts to formulate policy, and when DHS solicited the ideas and recommendations of council members on policy matters, the solicitation process was sometimes regarded as flawed. One limiting factor for policy development during meetings was a shortage of time to comment on draft documents. Some Sector Coordinating Council members reported that their association members generally did not comment on DHS drafts because they were provided insufficient time to do so. This made it hard for food associations to communicate their members’ concerns. DHS may have thus lost out on important insights from major components of the nation’s food sector.
And the results were less than optimal - a view which is furthered by GAO reporting on the National Infrastructur Protection Plan (NIPP). See this post for a summary of GAO's recent findings.
[NIPP] Sector-Specific Plans, which are authored by the Sector-Specific Agencies, discuss how each sector will address infrastructure protection. While DHS reportedly developed the Sector-Specific Plan template over the course of a year, it allowed the Sector-Specific Agencies just two months to complete their draft Sector-Specific Plans. This was an especially challenging task because the Sector Specific Agencies were asked to consult with their stakeholders as part of the Sector-Specific Plan formulation process. As a result, staff from the Sector-Specific Agencies indicated that Draft Sector-Specific Plans were assembled hurriedly and were not as valuable as they could have been.
As a result, the councils have also slumped …
Frustration with the slow pace of council progress and disenchantment with DHS’ management style and level of engagement may have led to declining participation in the Government Coordinating Council. Our analysis of Government Coordinating Council meeting minutes shows a difficulty achieving what the Council’s charter calls a “decision-making quorum.”
… and they're feeling unneeded …
[D]uring the crisis following Hurricane Katrina, the Federal Emergency Management Agency was asked to attend a joint session of the councils, but did not do so. The councils were an untapped resource that could have been more involved in getting food and bottled water to affected citizens. We were told that, due to DHS’ perceived unresponsiveness, companies used their own connections to provide food assistance to hurricane victims.
So, what's the answer for DHS? The same as it was in the beginning - foster trusting relationships. Collaboration is not a simple transactional relationship. It is built on mutual respect and trust – and it takes time.
DHS’ ability to foster and maintain a positive relationship with the coordinating councils will do much to determine the department’s overall effectiveness in providing leadership, coordination, and support of food defense efforts.
Information Sharing

There are also issues with information sharing between DHS and the food sector. One problem deals with the ever-troubled Homeland Security Information Network (HSIN):
The Homeland Security Information Network Food and Agriculture portal is a web-based tool for sharing threat and analytical information with sector representatives. DHS engaged food sector representatives in the design and online layout of the portal starting in October 2004. More than a year-and-a-half later, these discussions were still ongoing.
Another problem? Redundancy:
While food sector representatives were aggrieved by the portal’s early stage of development, [the OIG is] concerned that the HSIN's Food and Agriculture portal may essentially duplicate an FBI effort. A limited access web community with information on threats, vulnerabilities, and protective efforts related to the food and agriculture sectors, the FBI’s AgInfraGard became operational in March 2006. As described by the FBI and food sector representatives with access to the web community, much of AgInfraGard’s content is similar to that of the Homeland Security Information Network’s portal. The FBI believes its system is developing more quickly than the Homeland Security Information Network’s and has greater capability for information exchange. Meanwhile, according to one FBI analyst, the DHS system “takes information but it doesn’t give a lot.”
A different struggle has arisen regarding the type of information to share. In trying to analyze the food sector, DHS has focused on identifying assets. But they're not getting the full information on food assets:
As of January 2006, the National Asset Database had information on 77,069 infrastructure assets around the nation. Of those, 6,486 assets, or eight percent, were listed as relating to the post-harvest food sector.

Despite the broad geographic distribution of food industry assets and the prevalence of major food processing, transit, retail, and service facilities in all major U.S. cities, all but 2 of [the 20 most populous U.S.] counties had fewer than ten food assets listed in the National Asset Database.
One problem: Information about food assets is not being fully shared among federal agencies:
One reason data limitations such as these persist is that the Office of Infrastructure Protection has been unable to exploit existing federal information about food industry assets. Office of Infrastructure Protection staff reported that, in one case, this was the result of the FDA’s unwillingness to share information. Office of Infrastructure Protection staff advised us that they had sought the registered food facility list that FDA is required by law to maintain, but said that FDA had resisted sharing this information.
A bigger problem may be that analyzing systems, not assets, is probably the most appropriate means of analyzing the food sector:
The USA PATRIOT Act defines critical infrastructure to include systems and assets, yet the National Asset Database emphasizes assets. To date, the most advanced step by DHS to define parts of the food system has been the development of a sector taxonomy to support the classification of National Asset Database assets.

Industry and federal partners…held that DHS had focused too intently on assets, and devoted too little thought and energy to understanding the food sector as a system.
It doesn't have to be that way. Other federal agencies use a systems approach to analyze the food sector:
USDA and FDA ... focus their vulnerability and consequence assessments on particular industry subsystems and food products, rather than on particular assets.
And private sector representatives agree:
Food sector representatives said that DHS’ asset-orientation would result in an understatement of food sector risk for three reasons.
  • First, they perceived that the DHS’ focus on assets led the department to emphasize the effects of asset destruction over asset exploitation. As discussed earlier, the greatest concern to many in the food sector relates to the exploitation of the sector to distribute intentionally adulterated foods.
  • Second, food sector representatives pointed out that important links in the food supply chain are not easily captured in an asset-based model.
  • Finally, food sector representatives expressed concern that DHS’ asset-orientation would lead it away from an understanding of the second- and third-order effects of a food contamination incident. In focusing on a particular food industry asset, they believed DHS would lose perspective on upstream and downstream consequences of an incident affecting that asset. For example, contamination at a processing facility might not just affect that facility.
Accordingly, to grasp the second- and third-order effects of an adverse food event at a single facility, DHS must first understand that facility’s place within the food supply chain and larger economic system.
The OIG suggests, once again, better dialogue. The risk to the food system is not going to be fully understood unless DHS casts a wide net and listens to its partners.
A more effective dialogue between DHS and its partners is needed to address concerns about asset exploitation, assets that do not have fixed coordinates, and system-wide impacts that the malevolent exploitation of food sector assets might have.
Without effective collaboration and information sharing, risk analysis and resulting interventions are not likely to be optimally effective.

Tuesday, April 10, 2007

UK Report on WMD Risk

More housecleaning:

In February the Chatham House (a UK think tank) published a report on the risk of chemical, biological, radiological, and nuclear (CBRN) terrorism. It's essentially a concise, well researched primer on these threats. First, a few notes on the overall CBRN threat:

It is appropriate to think of CBRN as a system, offering all that might be required for a range of terrorist groups from the largest to the smallest, from the almost casual to the most organized, and from the poorest to the best funded.

In the absence of the Cold War military imperative, not only has genuine interest mounted in the civilian applications of WMD-relevant technology, but the illegal proliferation of sensitive technology, materials and knowledge has proved both more tempting and more possible. In short, WMD technology has increasingly become something of a commodity since the end of the Cold War.
Next a few notes on each threat:

Chemical

First, the precursor chemicals for chemical weapons (CW) are widely distributed:
Many of the CW precursor chemicals are ‘dual use’ in that they have civil industrial applications: mustard gas requires ethyl alcohol, sodium sulphide and bleach; thiodiglycol is used for ball-point pen ink, but is also ‘only one chemical step removed’ from mustard gas; the chemical ingredients for tabun (GA) are used in pesticides, those for sarin (GB) in flame retardants, those for soman (GD) in dairy and food-processing equipment, and those for VX in pyrotechnics.
A so-called Improvised Nuclear Device (IND) could also be produced using much larger quantities of lower-grade, less enriched U-235. The device might then ‘fizzle’ rather than detonate its entire mass instantly and efficiently. But if the resulting explosion were to be equivalent to just one or a few kilotons of TNT rather than tens of kilotons, terrorists could still find this option attractive.But taking the next step - building a chemical-weapons capability and actually producing chemical weapons - is difficult, as demonstrated by the widely-cited example of Aum Shinrikyo, who launched the 1995 sarin gas attack in the Tokyo subway:
According to some estimates, Aum Shinrikyo’s attempts to synthesize sarin cost as much as $30 million, involved as many as 80 scientists and other people with advanced laboratory facilities, and took a year or more to achieve.

To produce CW in large-scale quantities is challenging scientifically and technologically, and the handling and weaponizing of CW are generally understood to be very hazardous.
Chemical attacks are made more complicated by environmental factors:
In general, CW are dependent for their effect on ambient weather conditions, and particularly on the temperature, the intensity of sunlight, the strength and direction of wind, and rain (especially, of course, for those agents soluble in water).
For a terrorist group, simplicity may be preferred:
A rather more straightforward option, of course, would be to buy or steal a supply of toxic industrial chemicals, for simple release in a crowded area.
That's what al Qaeda is doing with chlorine in Iraq - simply acquiring whatever they can get and using it to supplement a more conventional attack, usually a truck bomb.

Biological

Biological threats seem relatively simple. All you have to do is acquire the desired biological agent, grow it, package it, and release the biological weapon (BW) as desired - right? But it's not nearly that simple:
BW production involves four stages – acquisition, production, weaponization and delivery – the first three of which are progressively more difficult:

1. Acquisition. It would not be easy to acquire the seed stock of a pathogen or a toxin-producing organism, but it would not be impossible either.
2. Production. The manufacturing of BW agents is not straightforward. Bulk production, in particular, would be demanding and dangerous.
3. Weaponization. Weaponizing a BW agent is yet more challenging, for two reasons. First, the health and safety of those involved in BW production could scarcely be more at risk. Second, it would not be a simple matter to produce a stable device with a predictable effect. BW agents are, in general, vulnerable to environmental and weather conditions.
4. Delivery. Once the first three stages have been passed through successfully, the delivery of a BW device would be a relatively simple matter.

More generally, it should always be borne in mind that BW use would inevitably be a complex undertaking, drawing upon many branches of science and technology, including microbiology, pathology, aerosol physics, aerobiology and meteorology.
And even if the high hurdles were passed, the effects are somewhat unpredictable. In some previous instances of civilian exposure to biological agents, casualties have not been catastrophic:
In 1979 an accident at a Russian military site led to some 65,000 people being exposed to anthrax spores. Of these, only 70 were reported to have been infected with anthrax, of whom 68 died. The anthrax attacks in the United States in late 2001 also had a very limited medical effect, albeit with widespread social and political impact.
Regarding biological weapons, the bigger threat might actually be something that we don't even know about yet. The report quotes G.L. Epstein as saying:
The rapidly increasing capability, market penetration, and geographic dissemination of relevant biotechnical disciplines will inevitably bring weapons capabilities within the reach of those who may wish to use them to do harm. If it takes close to a decade to develop and license a new therapeutic vaccine, it is not today’s threat but the threat a decade from now that we need to counter. And given how much easier it is to pose a threat than to counter one, the threat ten years out may not even materialize until eight or nine years out.
Especially as biotechnology advances, this threat will become increasingly complex.

Radiological

There is a wide variance to the severity of this threat. While the lower end is not hard to imagine, the upper end of the radiological weapons (RW) threat is somewhat unknown:
The ‘maximum credible event’ could be a device (explosive or other) designed to distribute tens or even hundreds of thousands of Curies of radioactive material. Little work has been done to model the effect of such an attack.
But the motivation is there:
‘Some of the major international terror groups, including al-Qaeda, have not only the resources to carry out such an attack, but also the willing martyrs, whose participation would significantly reduce the cost and complexity of any protective systems needed to allow the perpetrator to survive long enough to carry out the attack.’
And the materials are out there:
Radiological materials are used in a wide variety of circumstances: general industry, agriculture, medicine, communications and navigation. But not all radioactive isotopes would be suitable for RW use. Among the candidates, ‘only a few stand out as being highly suitable for radiological terror’: cobalt-60; strontium-90; yttrium-90; caesium-137, iridium-192, radium-226, plutonium-238, americium-241 and californium-252.

The US Nuclear Regulatory Commission has estimated that one licensed US radioactive source is lost every day.
While the phrase "dirty bomb" has entered the lexicon, an explosive might not be the most attractive means for dispersing radioactive material:
Radioactive material can be distributed in a variety of ways; some isotopes can be dissolved in a solvent and poured or sprayed, others can be burned or vaporized. From the point of view of a terrorist group, non-explosive delivery might offer an advantage in that authorities might be slow to suspect and detect radiological release. In the delay, radioactive material might be ingested or inhaled by yet more people, and radioactive pollution allowed to spread still further.
The main effect of a radiological weapon would probably be economic (assuming that the radioactive materials contaminated an area of economic importance, such as the business district of a major city):
There appears to be a reasonably firm consensus in the literature that while the political and economic effects of a RW attack could be extreme, only the largest conceivable RW device could kill more than scores or hundreds of people.

Thus, a recent US Department of Defense study estimated that a 100 lb (45 kg) RW device carried in a backpack, containing radioactive material used for cancer treatment, detonated in a city centre, would kill no one through radiation. However, a truck-borne device using a similar amount of explosive but with about 100 lb (45 kg) of spent nuclear fuel rods could cause lethal doses of radiation within a half-mile radius.
Nuclear

This is the ultimate nightmare, of course. Fortunately, there are only two possible materials suitable for making a nuclear weapon:
Although various nuclear isotopes are used in the construction of a nuclear weapon, at the core of any device must be a mass of sub-critical fissile material – either highly enriched uranium-235 (HEU) or separated, ‘weapons-grade’ plutonium (Pu-239).
And while a terrorist group would need specialized knowledge and plenty of resources, it's not impossible to imagine that they could build a weapon:
Graham Allison, writing in late 2003, claimed that ‘given the right materials – a grapefruit- or soccer ball-sized amount of fissionable material is sufficient – several masters-level engineering students … with several hundred thousand dollars and the type of equipment you could purchase off the shelf at Radio Shack could make a device that would explode. The last time I checked, researchers at Los Alamos, trying to develop strategies to combat this threat, had come up with sixty-nine different workable designs for a nuclear device.’ Barnaby makes a similar point: ‘The difficulty of designing and fabricating a nuclear weapon … is often exaggerated. A competent group of nuclear physicists, and electronics and explosives engineers, given adequate resources and access to the literature, would have little difficulty in designing and constructing such a weapon from scratch. They would not need access to any classified literature.’
If that's not possible, another option exists:
Another alternative might be to eschew nuclear weapons development and delivery altogether, and instead ‘deliver’ an attack on a nuclear power station, using conventional means (such as a large proximate explosion or the direct impact of an aircraft)...

In 1981 a US study estimated that such an attack carried out with an explosive-laden aircraft could cause 130,000 deaths.
Perhaps most ominously, the study points out that, in the eyes of a terrorist group such as al Qaeda, the risk of destruction is not a limiting factor - though it may be a factor in the response of their target:
But the difficulty arises, of course, when traditional terrorism gives way to so-called ‘expressive terrorism’, and when the object of nuclear weapon use would be not to negotiate but simply to destroy. For terrorist individuals and groups driven by some religious, millennial or apocalyptic vision, the massive and hugely symbolic impact of a unilateral, ‘spectacular’ nuclear strike could be precisely their goal. Furthermore, the destruction of themselves and everything associated with them in the retaliatory attack which followed their nuclear attack might be a prospect to be accepted, if not welcomed. What, then, would be the point of launching a nuclear counterattack against such perpetrators, other than to provide for them the martyrdom they seek?

Quite apart from the massive human cost of such an attack, the rationale for a punitive nuclear response falls away when account is taken of the likely size and scale of the organization carrying out the attack; would a group of a few hundred people dispersed across a wide area, and perhaps even among several countries, really be a suitable target for a retaliatory nuclear strike? If not, and if the decision is taken instead to pursue the terrorists with conventional military means, then the terrorists will have gained whatever benefit they envisage from a nuclear attack, without a substantial change in their circumstances, since they would have expected to be pursued by conventional military forces in any case.

The prospect now begins to loom of a nuclear weapon state being self-deterred when contemplating the wisdom of a nuclear response to a limited nuclear attack. ... Surprisingly perhaps, the ‘post-modern’ terrorist begins to assume a good deal of initiative in this scenario; the rewards of nuclear use might be perceived as maximal, with the attendant risks minimal (or, at least, unchanged).
While this threat may be improbable, the risk is so great that it cannot be ignored:
[I]t might be improbable that a terrorist organization could either design and manufacture, or acquire a nuclear weapon, and then deliver it, but even the slightest possibility that this could happen would entail massively disproportionate consequences. In other words, the risk of terrorist use of nuclear weapons, as traditionally calculated, could scarcely be higher. For Western governments the risk is of such a magnitude that worst-case analysis seems not only unavoidable but also appropriate.

CDC Community Flu Planning Guide

Catching up on an old item here. The CDC recently released interim guidelines for a community strategy to mitigate the effects of pandemic flu mitigation. The guidelines focus on "early, targeted, and layered use of nonpharmaceutical interventions":

This document provides interim planning guidance for State, territorial, tribal, and local communities that focuses on several measures other than vaccination and drug treatment that might be useful during an influenza pandemic to reduce its harm.
The guide points out that:
It is highly unlikely that the most effective tool for mitigating a pandemic (i.e., a well-matched pandemic strain vaccine) will be available when a pandemic begins. This means that we must be prepared to face the first wave of the next pandemic without vaccine and potentially without sufficient quantities of influenza antiviral medications.
As a result, the guide focuses on four nonpharmaceutical interventions that can mitigate the effects of a flu pandemic:
1. Isolation and treatment (as appropriate) with influenza antiviral medications of all persons with confirmed or probable pandemic influenza. Isolation may occur in the home or healthcare setting, depending on the severity of an individual’s illness and /or the current capacity of the healthcare infrastructure.

2. Voluntary home quarantine of members of households with confirmed or probable influenza case(s) and consideration of combining this intervention with the prophylactic use of antiviral medications, providing sufficient quantities of effective medications exist and that a feasible means of distributing them is in place.

3. Dismissal of students from school (including public and private schools as well as colleges and universities) and school-based activities and closure of childcare programs, coupled with protecting children and teenagers through social distancing in the community to achieve reductions of out-of-school social contacts and community mixing.

4. Use of social distancing measures to reduce contact between adults in the community and workplace, including, for example, cancellation of large public gatherings and alteration of workplace environments and schedules to decrease social density and preserve a healthy workplace to the greatest extent possible without disrupting essential services. Enable institution of workplace leave policies that align incentives and facilitate adherence with the nonpharmaceutical interventions (NPIs) outlined above.
One innovation in the guide is the "Pandemic Severity Index," which categorizes the severity of pandemics based on the case fatality ratio:
Future pandemics will be assigned to one of five discrete categories of increasing severity (Category 1 to Category 5).
As the severity of a pandemic increases, the suggested interventions increase. For Category 1 pandemics, the only recommended community-wide intervention is the voluntary isolation of ill persons. For Category 2 and 3 pandemics, other measures such as school closures and other social distancing interventions may be appropriate. For Category 4 and 5 pandemics, it is recommended that community leaders implement all nonpharmeceutical interventions.

The guide points out that timing is critical:
Implementing these measures prior to the pandemic may result in economic and social hardship without public health benefit and over time, may result in “intervention fatigue” and erosion of public adherence. Conversely, implementing these interventions after extensive spread of pandemic influenza illness in a community may limit the public health benefits of employing these measures.
But the guide suggests an appropriate epidemiological trigger for implementing interventions:
This guidance suggests that the primary activation trigger for initiating interventions be the arrival and transmission of pandemic virus. This trigger is best defined by a laboratory-confirmed cluster of infection with a novel influenza virus and evidence of community transmission (i.e., epidemiologically linked cases from more than one household).
There is a special caution about cascading effects of any intervention:
Communities must be prepared for the cascading second- and third-order consequences of the interventions, such as increased workplace absenteeism related to child-minding responsibilities if schools dismiss students and childcare programs close.
For example, according to a 2006 poll conducted by the Harvard School for Public Health:
Nearly three-fourths (73 percent) said they would have someone to take care of them at home if they became ill with pandemic influenza and had to remain at home for seven to ten days. However, about one in four (24 percent) said they would not have someone to take care of them.

More than four in ten respondents living in one-adult households (45 percent) and about one-third of low-income (36 percent), African-American (34 percent), disabled (33 percent), or chronically ill (32 percent) adults said they would not have anyone to take care of them if they were ill and had to remain at home.

While most employed people (74 percent) believed they could miss 7-10 days of work without having serious financial problems, one in four (25 percent) said they would face such problems. A majority (57 percent) think they would have serious financial problems if they had to miss work for 1 month, and three-fourths of respondents (76 percent) thought they would have such problems if they were away from work for 3 months.
These findings suggest that, while a vast majority of people say they are willing to adhere to community-wide interventions in the early stages of a pandemic, "adherence fatigue" may set in after a period of time. In addition, a community must have plans in place for their at-risk populations.

To minimize the adverse effects of both pandemics and their cascading effects, the guide emphasizes that planning is critical:
Communities should undertake appropriate planning to address both the consequences of these interventions and direct effects of the pandemic.
Communication is absolutely critical, to mitigate both the effects of the disease itself and the fear that the disease may cause (which could have cascading effects on the healthcare system, as the "worried well" could overload a community's healthcare resources):
It is also critical for communities to begin planning their risk communication strategies. This includes public engagement and messages to help individuals, families, employers, and many other stakeholders to prepare.
For any community, it is important to test the plan:
Since few communities have experienced disasters on the scale of a severe pandemic, drills and exercises are critical in testing the efficacy of plans.
Of course, just about everything in this document is common sense. Other recent flu guides have said much the same thing (see this post). Given the ever-present risk of a flu pandemic - which may or may not turn out to be bird flu - it is simply irresponsible not to develop plans. Human history tells us that a pandemic flu will eventually strike. The only question is how well we have planned for it.

Within the local community, early collaboration and planning are critical. Local leaders, business people, school administrators, public health professionals, and healthcare providers need to ask themselves who would be affected by a change in their operations resulting from a flu pandemic. Early collaboration and information sharing will be critical to developing plans that mitigate the effects of a pandemic for all.

Monday, April 09, 2007

Crime + Terrorism = Vulnerability

A few news items today call to mind the ever-growing connection between crime and terrorism. First, a new report from the Center for Policing Terrorism (CPT) highlights the problem:

[Non-state-sponsored] terrorist groups ... pose the greatest threat to the United States. Consistent with post-Cold War trends, these groups have become heavily involved in criminal activities.
Specifically, the report addresses five common criminal activities that terrorists have engaged in:
  • Drug trafficking
  • Financial scams
  • Cyber-crime
  • Illegal money transfers
  • Immigration violations
The link between terrorism and drugs is well established, both overseas (e.g., poppy farming in Afghanistan) and in the U.S.:
[A]s U.S. News & World Report has said, “[n]early half of the 41 groups on the government’s list of terrorist organizations are tied to narcotics trafficking, according to DEA [Drug Enforcement Agency] statistics.”

In January 2002, the federal investigation dubbed Operation Mountain Express III culminated in a series of raids that ... resulted in charges against 136 people, and the seizure of “nearly 36 tons of pseudoephedrine, 179 pounds of methamphetamine, $4.5 million in cash, eight real estate properties and 160 cars used by drug gangs.” [I]n the wake of the operation Asa Hutchinson, then the DEA’s director, revealed that “[a] significant portion of some of the sales are sent to the Middle East to benefit terrorist organizations.”

Around the same time as Mountain Express III, federal investigators were also engaged in Operation Green Quest [which] likewise exposed instances of drug money being laundered in support of Hizballah.

One little-known aspect of the [March 2004 Madrid] train bombings is that the Madrid cell received substantial financing from the sale of drugs, something the cell’s ideologues justified “as a weapon of jihad.”
Financial scams come in many flavors, including identity theft, bank fraud, counterfeiting, and cigarette smuggling. Of these, identity theft is especially attractive to terrorists, because it facilitates the commission of other crimes:
One critical aspect of identity theft, according to Dennis Lormel, the chief of the FBI’s
Terrorism Financial Review Group, is the “cloak of anonymity” that it provides. He noted that identities are often stolen in order to carry out such violations of federal law as bank fraud, credit card fraud, wire fraud, mail fraud, bankruptcy fraud, and computer crimes.
Bank fraud has also proven lucrative. It may include:
"...a wide range of offenses, including credit card fraud, bank fraud, mail fraud, mortgage fraud, wire fraud, bankruptcy fraud," and others.
Cigarette smuggling, which involves the illegal transport of cigarettes from states with low tobacco taxes (e.g., North Carolina and Virginia) to states with high tobacco taxes (e.g., New York, Michigan), is also a large and growing source of illegal income:
By mid-2004, the ATF had more than 300 open cases of illegal cigarette trafficking, and an official reported that several of these were linked to terrorist fundraising.
One of the most common vulnerabilities for terrorists - including the 9/11 attackers - is immigration violations:
Janice Kephart, former counsel to the 9/11 Commission, recently authored a report entitled Immigration and Terrorism that examines the histories of 94 foreign-born terrorists who operated in the United States between the early 1990s and 2004. It concludes that of these 94 terrorists, “about two-thirds (59) committed immigration fraud prior to or in conjunction with taking part in terrorist activity.”
The CPT report advocates taking an aggressive approach to terrorist policing - going after suspected terrorists and terrorist supporters by pursuing any and all illegal activities, no matter how minor. The authors point out that this strategy has been successful in attacking organized crime networks.

To attack criminal and terrorist networks, information sharing is vital. So it's always good to hear about new efforts such as the one established between police agencies in Central Florida and Puerto Rico to share information about criminal gangs that operate in both locations. The Florida Sun-Sentinel reported:
Criminal suspects moving between Central Florida and Puerto Rico face new scrutiny after an agreement reached [April 4] between law-enforcement agencies.

Computerized information sharing about gang members begins almost immediately between police on the mainland and the island as a result of last month's arrests of workers at Orlando International Airport on gun-smuggling charges.

"We're establishing a great partnership," said Orange County Sheriff Kevin Beary, standing next to Puerto Rico police Superintendent Pedro Toledo.

Investigators in Central Florida and Puerto Rico have complained since the mid-1990s that their counterparts rarely responded without repeated requests for help. The lack of an information-sharing system was one of the main reasons.

Puerto Rico police now will have instant access to information collected and shared by local, state and federal law-enforcement agencies and fire departments in nine Central Florida counties.

The same criminal information exchange, known as a Fusion Center that is funded by the federal Department of Homeland Security, will pass on information from Puerto Rico to local authorities.
It's good to see the Fusion Centers extending the information sharing network. Yet some other DHS facilities still have work to do before they collaborate effectively, according to a new GAO report. Washington Technology reported:
The Homeland Security Department’s gaggle of 25 national and regional operations centers that run around the clock every day of the year suffer from poor collaboration and coordination, auditors said. DHS’ slipshod management has hobbled the effectiveness of a pivotal information-sharing network and created other problems, the Government Accountability Office said in a report issued [April 5].

Management disarray within the DHS operations centers extends to the department’s Homeland Security Information Network (HSIN), the report said. Though department officials repeatedly have boasted about their success in developing the collaboration tool, GAO found that DHS had not provided standards, policies and procedures for its use.

DHS officials evaluated a draft of the report, according to the letter. They agreed with the recommendations and said the Operations Directorate was working to bolster collaboration.
They have been trying to get the HSIN right for a while now. (See this post.) But it had been my understanding that the HSIN would be replaced by the new Homeland Security Data Network. (See this post.)

Developments in WMD Response

A couple of brief items on emergency response for weapons of mass destruction:

UPI reports that the National Guard has certified a WMD response team for the Washington D.C. area:

The U.S. Department of Defense certified a Weapons of Mass Destruction Civil Support Team for the capital on April 6.

The team is trained to assist civil authorities in the event of a domestic threat of a chemical, biological, radiological, nuclear or explosive weapon. The CST will respond rapidly to a suspected or actual terrorist attack to determine the effects of the attack and provide situational understanding and technical consultation to local authorities.

Congress authorized 55 WMD Civil Support Teams to be fielded in every U.S. state and territory. The Washington-based team is the 49th team to be certified.

According to the DOD, the remaining six teams will be fully trained and certified by September 2007.
It's good to see this kind of progress. Of course, the real response to a WMD event - especially in a multi-jurisdictional area like the nation's capital - would be very complicated, involving a large number of actors. (See this post.)

For background on WMD CSTs, see this DoD regulation/instruction and this Army Field Manual.

A separate UPI article says that Duke University researchers have developed a test that shortens the time required to determine whether a person has been exposed to radiation:
The test scans the genes in a blood sample to determine the extent of the victim's exposure and produce results within the 72-hour window during which treatment is most effective.

"If a terrorist attack involving radioactive material were to occur, hospitals might be overrun with people seeking treatment, many of whom have actually been exposed and many of whom are simply panicked," said Dr. John Chute of the Duke Adult Bone Marrow and Stem Cell Transplant Program. "We have to be able to efficiently screen a large number of people for radiation exposure in order to respond effectively to a mass casualty event."

Current testing can require several days before results are available. However, Chute and his colleagues applied a technique used to measure the progress of radiation treatment in cancer to patients exposed to radiation from a "dirty bomb" or an accident at a nuclear power plant.

The next step will be finding methods of quickly extracting thousands of blood samples from a disaster area and getting them to a testing lab post haste, Duke said.
Given the likelihood of a "dirty bomb" radiological attack, it only makes sense to build the infrastructure for responding to this kind of event. Testing would be part of it. Decontamination centers (such as the new one in New York) are another.

Both testing and decontamination - as well as communication - would be important to decreasing the psychological impact of the event (e.g., reducing the number of "worried well" who report to hospitals). The "worried well" were a major problem in the aftermath of the 1995 Aum Shinrikyo sarin gas attack in the Tokyo subway. For more on the Tokyo attack and the "worried well," see these three reports.

Friday, April 06, 2007

Chlorine, Iraq, and Chemical Security

Another chlorine attack in Iraq. It's number 9.

The bombing in Anbar province marked the ninth use of suicide chlorine bombs in the sprawling, mainly desert territory that has been a stronghold of the Sunni insurgency. Recently, however, many Anbar tribes have switched allegiance, with large numbers of military-age men joining the police force and Iraqi army in a bid to expel al-Qaida in Iraq fighters.
(Off-topic, that's good news about the Anbar tribes switching sides. It reminds me of the widely distributed PowerPoint presentation created by an Army Captain who served in Anbar before he was killed by an IED in December 2006.)

Back on topic now: Al-Qaeda is showing that they are interested in refining their ability to use chlorine in attacks. Anyone responsible for local homeland security ought to make sure they know as much as possible about the location and security of stocks of chlorine in their area, if they don't already. This includes chlorine that passes through in trucks and railcars, to the extent possible. Even though all the detailed information on rail shipments isn't available to local authorities, some is - but you have to ask for it:
Tom White, spokesman for the Association of American Railroads, an industry lobbying group, said that in 2005, railroad companies agreed to provide local officials with a listing of the top 25 chemicals by volume coming through their communities -- if they ask for it.
Rail security is an evolving situation which involves pending litigation and political maneuvering. Hopefully in the end, more information will be forthcoming:
The U.S. Conference of Mayors has asked the federal Department of Homeland Security to require railroads to tell cities when highly toxic shipments are coming their way, or to at least require better communication about the types of chemicals being shipped through communities.
For chemical plants, the situation is less clear, as documented in these recent posts. New DHS effectively block state and local authorities from having a say in the security of chemical plants. But regardless of how the political situation shakes out, it's helpful to develop trusting relationships between chemical plant security personnel and local authorities. An accident, attack, or natural disaster is no time for introductions.

Tuesday, April 03, 2007

Emergency Alerts in Australia and the U.S.

Australia's Daily Telegraph reports on that country's erratic response to the April 2 tsunami that killed at least two dozen people in the Solomon Islands. People were going every which way:

[W]hile scores of schoolgirls were evacuated from their classrooms in Manly on Monday, would-be spectators in other parts of Sydney grabbed deckchairs and binoculars and headed to their nearest beach and waited for a tsunami to arrive.

Off the coast, the situation was much the same: as some boats set sail for deeper waters, other crews gunned their engines and returned to the perceived safety of the shore.

Experts agree that on some parts of the east coast, the warnings were initially distributed appropriately on Monday. However that, unfortunately, is where the consensus ends.

There is some evidence to support the argument that not enough was done to allay widespread fears of a disaster.

Professor Ted Bryant from the University of Wollongong described the organisation after the initial wave hit north Queensland as "erratic''.

The tsunami expert said far from spending the day evacuating beaches in Sydney, emergency services personnel should have been told that the tsunami threat had abated during the morning.

"After the wave hit in north Queensland, I knew from looking at the computer that it was was not big, yet we were still hearing reports of the ocean being cleared and beaches being cleared and I think that was part of the overreaction,'' Professor Bryant said.
It's remarkable that, even after the 2004 Indian Ocean tsunami, there could be a mixed response like this. Reliable chains of communication have to be established ahead of time, and it's just as important to get a reliable "all-clear" as it is to get the initial warning out.

In a way this reminds me of Boston's recent cartoon scare. After the initial panic, it took a long time to defuse the situation.

Meanwhile, a recent GAO report indicates that the emergency alert system (EAS) may not provide better results in the United States. GAO says the existing system - which relies on messages to be relayed from "primary" stations to others - is not completely reliable:
To date, EAS has never been used to transmit a national-level alert. ... For presidential, or national-level, EAS alerts, a hierarchical distribution system would be used to relay the message. Currently, 34 stations have been designated National Primary stations, often referred to as Primary Entry Point (PEP) stations.

In a national test [in January 2007], three [of 34] primary relay stations failed, and in one state test, a state representative reported that the message was not received beyond an area roughly 50 to 70 miles from the state capital.
At least they're testing the system, right? Not really. The Jan 2007 test wasn't part of a regular testing regimen:
Despite ... efforts to improve the relay system, we found a lack of ongoing testing to ensure that the system would work as intended during a national-level alert.
Even if the system were to work as intended, it is slow:
Stakeholders also said the relay system was too slow to transmit EAS alerts to the public in a timely manner. For example, a technical consultant to a state broadcast association estimated that it would take an hour to disseminate an EAS alert throughout the state.
And that does not assume stations would lose power, which is likely in a major disaster:
FEMA officials expressed concern about the reliability of the relay system, or daisy chain, used to disseminate national-level EAS messages. In addition, they expressed significant concern about the reliability of electrical power for broadcast stations during disasters, noting that without electrical power (or fuel for backup generators), a broadcaster cannot issue emergency alerts. ... We heard that a lack of redundancy among key broadcasters makes the current daisy chain system prone to failure. For example, the chair of a state emergency communications committee told us redundancy is lacking among the PEP stations, and therefore, if a PEP station were disabled during a disaster in a major metropolitan area, an EAS alert would likely fail to reach a sizable portion of the population.
Of course, it's also important for the people operating the equipment and writing the alert messages to know what they're doing. But many of them are short-time employees who haven't been fully trained:
Another limitation of the current alerting system, stakeholders said, is inadequate training for EAS participants, both in the use of EAS equipment and in the drafting of EAS messages. ... According to the Partnership for Public Warning, EAS participants require extensive training to properly set up EAS equipment. The Partnership for Public Warning further reported that personnel using EAS equipment often lack proper training and that inadequate training is a main factor preventing the nation from having a unified warning system. ... State and local officials also identified inadequate training as a limitation of the current EAS. For example, the director of a state emergency communications committee described the lack of EAS training for emergency personnel who craft the messages as the primary challenge facing his state’s EAS.
Perhaps the worst news in the report is the lack of collaboration among stakeholders:
A final limitation of EAS that we heard about was a lack of coordination among EAS stakeholders at the state and local levels. A member of a state emergency communications committee said that, historically, there has been little coordination between the media and the state emergency management office and that the broadcast industry had little involvement in his state’s initial EAS plan. A participant from the Media Security and Reliability Council noted that coordination among broadcast media and other local stakeholders during emergencies is a major issue that has yet to be addressed. Such coordination could be achieved through the development of detailed regional and local emergency response plans, which would coordinate the actions of local officials and broadcasters in response to emergencies. He said to date, such plans have largely not been developed.
FEMA is aware that the EAS system needs to get better, in a number of ways. For one thing, it's delivery media are becoming a bit old-fashioned.
The EAS is limited (for now) to sending messages over just television and radio:
EAS provides messages over two media (television and radio), but does not transmit messages via other communications devices that Americans routinely use, such as cell phones, personal digital assistants, and computers.
The way to fix this is to offer emergency alerts in other media, as some U.S. cities are already doing (e.g., Washington D.C. and San Francisco). But creating an integrated system is complicated by the fact that many stakeholders are not used to collaborating:
Several efforts to develop an integrated alert system—one that would provide effective warnings over all broadcast media devices available to the public—are underway. ... Coordination and collaboration among a variety of stakeholders will be critical to ensure that all elements of the system can work together and produce accurate, timely alerts for all Americans.

FEMA officials believe an integrated alert system will have advantages over the current system but told us challenges to its implementation remain. A key challenge, FEMA said, is gaining the cooperation of federal, state, and local emergency management organizations on the use of a standardized technology for disseminating alerts. ... Additionally, we believe the implementation of an integrated alert system will require collaboration among a variety of stakeholders to ensure that all elements of the system can work together and can convey accurate, timely emergency alerts to all Americans. ... Furthermore, the plan says all of the FEMA pilot projects require regular interaction with private sector and media organizations. However, there does not appear to be a collaborative, consensus-based forum for all interested stakeholders—public and private—to work together to develop processes, standards, systems, and strategies related to implementing an integrated system. ... In the absence of such a forum, coordination might continue on an ad hoc, rather than a strategic, basis. According to one stakeholder, federal efforts to develop an integrated system have focused thus far on the ability of EAS to deliver a national alert, to the exclusion of state and local needs. In particular, a state emergency manager told us his organization, which has developed an advanced alert system, had not been contacted by FEMA regarding its experience in the system’s design or implementation.
The problem of emergency alerts is only going to get worse - or better - depending on how you see it. As communications media evolve, there will be increasing choices for sending and receiving messages. The alert system must keep up.

Once again, collaboration seems to be the key. In Australia, they weren't on the same page when the tsunami warning came. When the next disaster hits the U.S., will the emergency alert system be any better? It doesn't seem so, unless the stakeholders collaborate.

Friday, March 30, 2007

HSPD-19: Combating Terrorist Use of Explosives in the United States

The White House recently released Homeland Security Presidential Directive 19 (HSPD-19): "Combating Terrorist Use of Explosives in the United States."

Just a couple of notes here. First, the directive emphasizes explosives detection. One of its requirements is the development of a national strategy "on how more effectively to deter, prevent, detect, protect against, and respond to explosive attacks." Some of the specific requirements for the new strategy are:

  • an inventory and description of all current Federal Government assets and capabilities specifically relating to the detection of explosives or the protection against or response to explosive attacks
  • an inventory and description of current research, development, testing, and evaluation initiatives relating to the detection of and protection against explosives and anticipated advances in capabilities for reducing the threat of explosive attacks
  • recommendations for improved detection of explosive chemical compounds, precursor chemicals used to make improvised explosive chemical compounds, and explosive device components
  • an assessment of the effectiveness of, and, as necessary, recommendations for improving Federal Government training and education initiatives relating to explosive attack detection, including canine training and performance standards
Trying to detect explosives is a risky strategy. It assumes that someone has already made the bomb, or has acquired the precursors for it. There may not be much time between the making of the bomb and its deployment.

The HSPD also has some directives for information-sharing at all levels (and with the private sector), which is good to see. I'm a little leery of the "build it and they will come" philosophy which seems to underlie these instructions, though:
The Attorney General, in coordination with the Secretary of Homeland Security and the Director of National Intelligence, shall maintain and make available to Federal, State, local, territorial, and tribal law enforcement entities, and other first responders at the discretion of the Attorney General, a web‑based secure portal that includes information on incidents involving the suspected criminal misuse of explosives, including those voluntarily reported by State, local, territorial, and tribal authorities.

The Secretary of Homeland Security, in coordination with the Attorney General, the Director of National Intelligence, and the Secretaries of State and Defense, shall maintain secure information-sharing systems that make available to law enforcement agencies, and other first responders at the discretion of the Secretary of Homeland Security, information, including lessons learned and best practices, concerning the use of explosives as a terrorist weapon and related insurgent war fighting tactics ...
As experience with the old Homeland Security Information Network (HSIN) has shown, just building an IT network or portal doesn't guarantee that it will be used. Simply making the information systems available is usually not enough. (See these two posts.)

Updated: More Wrangling on Chemical Plant Security

The wrangling over chemical plant security isn't going away. One of the key issues - whether the federal government's rules can supersede state laws - has been revisited in the new supplemental spending bill. The Record (NJ) reports:

New Jersey's chemical plant security standards would be protected from possible dilution by the federal Department of Homeland Security under a bill the Senate approved Thursday.

Sen. Frank Lautenberg, D-N.J., lobbied aggressively for a provision in a $122 billion emergency war spending bill that allows states to implement chemical security standards that go beyond what DHS requires.

The American Chemistry Council worked to strip Lautenberg's provision, arguing it could delay implementation of DHS regulations proposed in December -- and leave the nation vulnerable to a terrorist attack on chemical plants.

Unlike the federal rules, New Jersey's rules require chemical plants to study whether "inherently safer technology" is available that would reduce the risk of an accident or potential harm from an attack.
Mostly this is a political turf issue (i.e., who gets to make the rules?), but there are real implications to this. Chemical plants are an attractive target. (See this post from last week.)

Why shouldn't states and localities have a say - or in some cases, just the information - about what's in their backyards and how the chemical industry should maintain safety and security? States and localities certainly have a legitimate interest in this.

Updated 2007-04-03: On April 2, DHS released its final rules on security at chemical plants. The rules permit the pre-emption of state laws, GovExec reported:
[DHS] tried to specify when state laws will be overridden.

"Some states have existing laws for regulating chemical facilities," the department said in a statement. "Only state laws and requirements that conflict or interfere with these regulations, or the purpose for the regulations, will be pre-empted. Currently, the department has no reason to conclude that any existing state laws are applied in a way that would impede the federal rule."

The department also maintains the authority to pre-empt state health, safety or environmental protections, according to the rules.
Sen. Lautenberg is continuing to push for legislation that would prohibit DHS from pre-empting state or local statues, except "when a clearly defined conflict exists."

Terrorist Financing 101

Over at the Counterterrorism Blog, there's a nice primer on terrorist financing. The whole thing is worth reading, but I thought the following excerpt was especially relevant to local efforts to prevent terrorism:

The unfortunate reality is that regardless of the level of vigilance and detection, terrorists will always have access to funds; however, the more robust the detective efforts, the greater the likelihood for disruption. Every disruptive success reduces the operational capability of terrorists. In this vein, one of the primary areas of vulnerability to terrorists is finance. It is critically important that financial and non-financial institutions understand this fact and the vital role they play in the process.

Two key areas where terrorists are vulnerable when dealing with financial institutions are with respect to Know Your Customer (KYC) practices and Suspicious Activity Reporting (SAR). Whether using their true names or false identities, terrorists are at risk of detection through KYC mechanisms.

Financial Institutions should incorporate terrorist financing specific training into their AML training programs. It is essential to understand and simplify terrorist financing as much as possible. It is equally important for individuals in the financial and business sector to understand that they are on the front line of the economic war on terrorism and are capable of playing a vital role through risk recognition, AML monitoring and mechanisms to include KYC and SARs.
This all gets back to the basic idea of collaborating and sharing information with others. If you work in a financial institution and notice something suspicious, you're more likely to report it if: A) someone has shared information with you about the threat, and B) your institution has a trusting relationship with law enforcement and other authorities.

Wednesday, March 28, 2007

Private Sector Emergency Recovery: What the HERC?

This story is a few months old, but I really like the idea. Business leaders in Hernando County, Florida, have teamed up to create the Hernando Emergency Recovery Council (HERC). It's a collaborative private group that will provide necessary resources in the event of a disaster:

Soon, if disasters strike, victims will be able to call the Hernando Emergency Recovery Council Inc. to get aid that is both immediate and local, said the organization's president, Robert Kanner.

"We hope to have businesses pledge plywood and roof shingles and labor so when the fictional Mrs. Smith contacts us, we're able to pool together our resources," Kanner said.

The key, county emergency management director Tom Leto said, is to round up local resources that can provide goods and services.

Already Kanner and HERC's board of directors have signed up some 20 individuals and businesses - "point people" - willing to respond with resources, whether they be physical, emotional or spiritual.

Said Leto: "The better you are at organizing resources in advance, the better you can respond to the disaster. It's difficult to organize resources at the last minute."

Kanner himself is a volunteer who approached Leto about helping the community in some way.

Now, the two want to tap into the business community, aiming to enlist them not just for humanitarian reasons, but also to help themselves get back in business and stabilize the county economy in the wake of a disaster.

HERC and the Emergency Management Office will work together, Leto said.

"If the Emergency Operations Center does encounter a need the county is short on, the county will go to HERC and we will ask if they can fill it," he said.
There is a lot to like here. The collaboration between local businesses and government; the holistic approach to providing resources (i.e., focusing on all of a victim's potential needs, not just the physical ones); the stronger bonds within the community.

These things are beneficial to the community even if a disaster never strikes.

Governor's Guide to Homeland Security

The National Governor's Association (NGA) recently released A Governor's Guide to Homeland Security, the purpose of which is:

...to provide governors with an overview of their homeland security roles and responsibilities and to offer some guidance on how to approach issues such as mutual aid, information sharing, obtaining assistance from the military, and protecting critical infrastructure.
Essentially the document is a primer on preparation and response. It assumes that the reader is generally unfamiliar with many planning and response mechanisms, so it spends a lot of time describing these. It's useful for anyone who wants an overview of emergency preparation and response from the state-level perspective.

Some portions of the guide are worth highlighting, though, mostly because they describe efforts to collaborate and share information. Most interesting is the description of some public-private partnerships. While the guide points out that ...
Partnering effectively with the private sector to improve disaster preparedness and response is an area of emergency management that has begun to receive attention only recently.
... and ...
Thus far, most public-private partnerships in the area of emergency preparedness and response exist at the local, rather than at the state, level.
... there is a real need, and some real benefits, to collaborating with the private sector - especially with owners of critical infrastructure assets:
Governors should work closely with the private sector to develop emergency response and risk communications plans for incidents affecting privately owned systems or infrastructure. Forging a trust-based relationship between emergency response officials and the private sector is essential to ensure effective security preparations, including accurate vulnerability assessments and the integration of private-sector emergency response plans with those of government agencies.

During the 2004 hurricane season, Florida utilities sent representatives to the state emergency operations center (EOC) and to local government EOCs. Other utility officials were available by telephone or other communications systems. As a result, emerging problems were capable of being solved at the local level by officials who felt empowered to make critical decisions and then report what they had accomplished.
Within government, the need for information sharing remains great:
A lack of information sharing can be an obstacle to implementing an effective homeland security strategy. The fragmented nature of data collection and incident reporting among state, local, and federal law enforcement agencies hinders their ability to connect information that may point to terrorist plots or other ongoing criminal activity, and the private sector—which owns a significant amount of data and an estimated 85 percent of the nation’s critical infrastructure—often is not connected to the homeland security intelligence and information-sharing networks.
So far, efforts to share information about potential threats and responses have largely been funneled through state fusion centers (which I've previously discussed here, here, here, here, here, and here). The guide briefly describes how a few of these fusion centers operate:
Arizona’s fusion center, known as the Arizona Counter-Terrorism Information Center (ACTIC), opened in 2004 as the state’s central analysis hub for real-time crime and terrorism-related intelligence and information. ACTIC is staffed with more than 200 detectives, special agents, analysts, and other personnel representing 34 state, local, and federal agencies. ACTIC also includes a complete integration of the FBI’s Joint Terrorism Task Force (JTTF).

Georgia’s Information Sharing and Analysis Center (GISAC) has an analytical and investigatory role. Each investigator is assigned an analyst, and officials report regular contact between investigators and their assigned analysts to share information.

The Illinois Statewide Terrorism Intelligence Center (STIC) includes analysts and representatives of agencies dealing with narcotics, sex offenses, violent crimes, andmotor vehicle theft. ... In 2005, the Illinois STIC colocated its facility with the state emergency operations center.

In 2006, North Carolina opened its Information Sharing and Analysis Center (ISAAC). The ISAAC serves as the focal point for collection, analysis, and dissemination of information on possible terrorist and criminal threats. ... ISAAC staff collaborate to analyze information from a variety of sources, including tips from the public, public records such as driver’s license and vehicle registration records, and national law enforcement databases.
Because collaboration among agencies is also vital, the guide also describes some of the intrastate mutual aid organizations that states have set up:
Several states already had, or have since developed, state-wide mutual aid programs. In April 2002, for example, Iowa introduced a voluntary statewide mutual aid program known as the Iowa Mutual Aid Compact (IMAC). Modeled on the national Emergency Management Assistance Compact, IMAC establishes a system through which political subdivisions can help each other during disasters that have been declared either by local officials or by the governor.

Kansas has a similar statewide mutual aid system, created in the 2006 Kansas Intrastate Mutual Aid Act. The act provides for a system of intrastate mutual aid between participating political subdivisions in cases of declared disasters as well as during drills and exercises in preparation for such disasters.

In Illinois, meanwhile, the fire service developed and implemented a mutual aid system that began in the northern part of the state but has since expanded to all of Illinois, southern Wisconsin, and parts of Indiana. The Mutual Aid Box Alarm System (MABAS) comprises hundreds of fire departments and provides an orderly system for dispatching fire and emergency medical service equipment and personnel to fires, accidents, or other incidents. ... The system is managed through geographic divisions by which local fire departments can access assistance. From its inception, MABAS included procedures for ensuring the integration of assisting personnel and equipment into the local command structure.
Also regarding mutual aid, the guide points out that all 50 states are now part of the Emergency Management Assistance Compact (EMAC):
The National Governors Association has endorsed EMAC and, in 2006, Hawaii became the 50th state to join the compact, which also counts District of Columbia, Puerto Rico, and the U.S. Virgin Islands among its members.
However, the experience of Hurricane Katrina shows that EMAC remains unfamiliar to some local and federal agency personnel:
Out-of-state teams were able to reach affected areas of the Gulf Coast efficiently through EMAC deployments. However, their integration with response crews already on the ground was complicated by the fact that many local officials, and some federal officials, were unfamiliar with EMAC and questioned or rejected the credentials of the EMAC-deployed teams.
In addition to intrastate mutual aid and EMAC, states
can also see benefits from regional organizations:
Similarly, governors should consider working together to develop strategies for managing events that affect regions of the country. In some regions, this already is taking place.The Pacific NorthWest Economic Region (PNWER), which comprises Alaska, Idaho, Montana, Oregon, Washington, and the Canadian provinces of Alberta, British Columbia, and the Yukon, created a partnership for regional infrastructure security to develop a regional protection, preparedness, and response plan for dealing with infrastructure-related emergencies.
In 2006, Arizona Governor Janet Napolitano signed a memorandum of understanding with California Governor Arnold Schwarzenegger, Texas Governor Rick Perry, and New Mexico Governor Bill Richardson that will enable the four southwest border states to share unclassified and classified intelligence information to provide better security along the border.
One thing that affects states' ability to choose various options for homeland security is the underlying structure of their homeland security organizations. The guide points out that states have chosen one of three main structures:

Homeland Security Advisor with Committee/Coordinating Council: Some governors have appointed homeland security advisors or directors to provide direct counsel to and speak on behalf of the governor on matters related to homeland security. [T]he advisor often chairs a committee — made up of representatives of relevant state agencies, including public safety, the National Guard, emergency management, public health, and others—charged with developing preparedness and response strategies. [Examples: Maryland, Nebraska, Washington]

Department of Homeland Security: [G]overnors are beginning to create state departments of homeland security that have the statutory authority to oversee operations as well as to develop all-hazards approaches to mitigation, preparedness, and response. [Examples: Alabama, Arizona, Delaware, Indiana]

Homeland Security Functions Under Existing Agencies: In many states, the homeland security functions have been assigned to an existing agency, such as public safety or the military department. Generally, these homeland security advisors, at a minimum, coordinate response resources and activities across the various state agencies, and in many cases, they have planning and budgetary authority. [Examples: Florida, Idaho]