Asis-Critical Infrastructure Resource Guide
Asis-Critical Infrastructure Resource Guide
Asis-Critical Infrastructure Resource Guide
Copyright 2007 by ASIS International ASIS International (ASIS) disclaims liability for any personal injury, property or other damages of any nature whatsoever, whether special, indirect, consequential or compensatory, directly or indirectly resulting from the publication, use of, or reliance on this document. In issuing and making this document available, ASIS is not undertaking to render professional or other services for or on behalf of any person or entity. Nor is ASIS undertaking to perform any duty owed by any person or entity to someone else. Anyone using this document should rely on his or her own independent judgment or, as appropriate, seek the advice of a competent professional in determining the exercise of reasonable care in any given circumstance. All rights reserved. Permission is hereby granted to individual users to download this document for their own personal use, with acknowledgement of ASIS International as the source. However, this document may not be downloaded for further copying or reproduction nor may it be sold, offered for sale, or otherwise used commercially.
Table of Contents
Introduction ....................................................................................................................................................................1 Critical Infrastructure Working Group Contributors ...............................................................................................2 ASIS International Staff ........................................................................................................................................2 1.0 Agriculture and Food Sector.....................................................................................................................................3 1.1 Sector Overview ..................................................................................................................................................3 1.2 Professional Development Resources ................................................................................................................4 1.2.1 Government Resources...............................................................................................................................4 1.2.2 Government Resources Canada ..............................................................................................................5 1.2.3 Industry Resources......................................................................................................................................5 1.2.4 Best Practices and Assistance ....................................................................................................................6 2.0 Banking and Finance Sector ....................................................................................................................................9 2.1 Sector Overview ..................................................................................................................................................9 2.2 Professional Development Resources ..............................................................................................................10 3.0 Chemical Sector.....................................................................................................................................................13 3.1 Sector Overview ................................................................................................................................................13 3.2 Professional Development Resources ..............................................................................................................14 3.2.1 Web Links..................................................................................................................................................14 3.2.2 Government Agencies / Resources ...........................................................................................................15 3.2.3 Publications and Misc. Resources .............................................................................................................17 4.0 Commercial Facilities Sector..................................................................................................................................19 4.1 Sector Overview ................................................................................................................................................19 4.2 Professional Development Resources ..............................................................................................................20 4.2.1 Guides, Resources, and Documents by Organization ...............................................................................20 4.2.2 Web links ...................................................................................................................................................21 4.2.3 Security Management Articles (month, year, page) ...................................................................................21 4.2.4 Books.........................................................................................................................................................22 4.2.5 Videotapes / DVD: .....................................................................................................................................25 4.2.6 Seminar Sessions Audiotapes / CD-ROM / DVD (ASIS): ..........................................................................25 5.0 Dams Sector ..........................................................................................................................................................28 5.1 Sector Overview ................................................................................................................................................28 5.2 Professional Development Resources ..............................................................................................................29 6.0 Defense Industrial Base Sector..............................................................................................................................34 6.1 Sector Overview ................................................................................................................................................34 6.2 Professional Development Resources ..............................................................................................................35 7.0 Drinking Water and Water Treatment Sector .........................................................................................................37 7.1 Sector Overview ................................................................................................................................................37 7.2 Professional Development Resources ..............................................................................................................38 7.2.1 Federal Lead Agency Affiliation .................................................................................................................38 7.2.2 Industry Associations and Affiliations.........................................................................................................38 7.2.3 Academic and Research............................................................................................................................39 8.0 Emergency Services Sector ...................................................................................................................................40 8.1 Sector Overview ................................................................................................................................................40 8.2 Professional Development Resources ..............................................................................................................41 8.2.1 Resources: ................................................................................................................................................42 9.0 Energy Sector ........................................................................................................................................................43 9.1 Sector Overview ................................................................................................................................................43 9.2 Professional Development Resources ..............................................................................................................45 9.2.1 Electricity Sector Organizations (North America):......................................................................................46 9.2.2 Electricity Sector Support Organizations (North America) .........................................................................46 9.2.3 References: ...............................................................................................................................................47 9.2.4 Security Support Programs:.......................................................................................................................48 9.2.5 Oil and Natural Gas Professional Development Resources ......................................................................50
10.0 Government Facilities Sector ...............................................................................................................................55 10.1 Sector Overview ..............................................................................................................................................55 10.2 Professional Development Resources ............................................................................................................56 10.2.1 Guides, Resources, and Documents by Organization .............................................................................56 10.2.2 Web links .................................................................................................................................................57 10.2.3 Security Management Articles (month, year, page) .................................................................................57 10.2.4 Books.......................................................................................................................................................58 10.2.5 Videotapes / DVD ....................................................................................................................................61 10.2.6 Seminar Sessions Audiotapes / CD-ROM / DVD (ASIS) .........................................................................61 11.0 Information Technology Sector ............................................................................................................................64 11.1 Sector Overview ..............................................................................................................................................64 11.2 Professional Development Resources ............................................................................................................65 11.2.1 Web Sites ................................................................................................................................................65 11.2.2 Credit Bureaus:........................................................................................................................................67 11.2.3 Books:......................................................................................................................................................67 12.0 National Monuments and Icons Sector ................................................................................................................68 12.1 Sector Overview ..............................................................................................................................................68 12.2 Professional Development Resources ............................................................................................................69 12.2.1 Museums, Libraries, Cultural Properties and other National Icons: .........................................................70 12.2.2 Other Resources, Guides, etc..............................................................................................................71 13.0 Nuclear Reactors, Materials, and Waste Sector...................................................................................................72 13.1 Sector Overview ..............................................................................................................................................72 13.2 Professional Development Resources ............................................................................................................73 14.0 Postal and Shipping Sector ..................................................................................................................................75 14.1 Sector Overview ..............................................................................................................................................75 14.2 Professional Development Resources ............................................................................................................76 14.2.1 Regional Cargo Security Councils: ..........................................................................................................77 14.2.2 Cargo Theft Task Forces: ........................................................................................................................78 15.0 Public Health and Healthcare Sector ...................................................................................................................80 15.1 Sector Overview ..............................................................................................................................................80 15.2 Professional Development Resources ............................................................................................................81 15.2.1 Books, Publications, and News Clips:......................................................................................................82 16.0 Telecommunications Sector .................................................................................................................................83 16.1 Sector Overview ..............................................................................................................................................83 16.2 Professional Development Resources ............................................................................................................84 17.0 Transportation Systems Sector ............................................................................................................................85 17.1 Sector Overview ..............................................................................................................................................85 17.2 Professional Development Resources ............................................................................................................86 17.2.1 Books, Publications, and News Clips.......................................................................................................89 18.0 Additional Resources .........................................................................................................................................102 18.1 Universities / Colleges ...................................................................................................................................103 18.2 Government Organizations............................................................................................................................105 18.3 Government Publications / Newsletters.........................................................................................................107 18.4 Business Associations / Nongovernmental Organizations.............................................................................111 18.5 Resource Database.......................................................................................................................................113
Introduction
The September 11, 2001, attacks demonstrated the extent of our vulnerabilities to the terrorist threat. In the aftermath of these tragic events, we, as a Nation, have demonstrated firm resolve in protecting our critical infrastructures and key assets from further terrorist exploitation. In this effort, government at all levels, the private sector and concerned citizens across the country have begun an important partnership and commitment to action. - President George W. Bush, The National Strategy for the Physical Protection of Critical Infrastructure and Key Assets, February 2003
The ASIS International Critical Infrastructure Working Group (CIWG) initially convened at the ASIS Annual Seminar and Exhibits in San Diego, CA in September 2006. As the CIWG structure and purpose evolved, it was determined that this particular working body could provide a specialized resource to ASIS members who serve the nations 13 critical infrastructures and four key assets as defined by the U.S. Department of Homeland Security (DHS). Moreover, it was envisioned that the CIWG would be a viable link to both private and public sector entities associated with issues relevant to critical infrastructure protection, disaster resilience, and continuity of operations. The organizational structure of the CIWG is representative of all 17 critical infrastructures and key assets. Members are ASIS volunteers who are generally nominated to serve this working group from the existing Councils. As such, the CIWG is a common mechanism for inter council cooperation in protecting the vital interests of our nation through information sharing, educational programs, and resources. This guide represents a work product that can be used as a current resource document for the critical infrastructures and key assets. It is not intended to supplant or supersede existing publications, resources, or documents that have been promulgated by government agencies or industry associations. Rather, it is a useful compendium of information that can be easily accessed and utilized in the critical infrastructure protection arena. This effort could not have been realized without the dedication and commitment of the CIWG volunteers and ASIS staff who worked tirelessly in producing this resource for the infrastructure communities and the Society at large. Our gratitude is extended to all who have been involved in supporting this project. We welcome your comments, suggestions and recommendations regarding this document and how we can best serve you.
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
International Dairy Foods Association Provides Legislative Leadership, best practices, and promotion of dairy foods. National Cattlemens Beef Association Provides information regarding security relative to beef production as well as data regarding outbreaks and various types of pathogens. National Oilseed Processors Association (NOPA) Through its various committees, the Association cooperates with the U.S. Departments of Agriculture, State, and Commerce, as well as other independent and private organizations, both national and international, concerned with oilseed products. National Pork Producers Council Conducts public policy outreach on behalf of its 44 affiliated state association members. Enhances opportunities for the success of U.S. pork producers and other industry stakeholders by establishing the U.S. pork industry as a consistent and responsible supplier of high quality pork to the domestic and world market. The Fertilizer Institute (TFI) Provides safety and security best practices and promotes the safe use of fertilizer.
U.S. Food and Drug Administration (FDA): Strategic Partnership Program Agroterrorism (SPPA) Initiative ALERT Food Defense Awareness Training Protecting the Food Supply from Intentional Adulteration: An Introductory Training Session to Raise Awareness This training is available online and is being hosted by the Food and Drug Administration (FDA). U.S. Department of Agriculture (USDA), Food Safety and Inspection Service (FSIS), Industry Security Guidelines: Developing a Food Defense Plan for Meat and Poultry Slaughter and Processing Plants | PDF | Developed in consultation with very small, small, and large meat and poultry processors, this guide provides an easy, practical, and achievable three-step method for creating a food defense plan. By completing pages 13 -16 of this guide, you will have a plan specific for your operation. Emergency Guidance for Retail Food Establishments | PDF | Practical guidance for retail grocery and food service establishments to plan and respond to emergencies that create the potential for an imminent health hazard. Elements of a Functional Food Defense Plan | PDF | This information serves as guidelines for completing the food defense plan profile extension questions. FSIS Model Food Security Plans The following plans identify the types of preventive steps that establishment operators may take to minimize the risk that their products will be subject to tampering or other malicious criminal activity: Egg Processing Facilities (Apr 2005) | PDF | Import Establishments (Apr 2005) | PDF | Meat and Poultry Processing Facilities (Apr 2005) | PDF | Meat and Poultry Slaughter Facilities (Apr 2005) | PDF | FSIS Notice 28-06, PBIS Profile Extension Instructions on Food Defense Plans for Meat and Poultry Establishments | PDF | FSIS Safety & Security Guidelines for the Transportation & Distribution of Meat, Poultry, & Egg Products | PDF | En Espanol | Chinese | Vietnamese | Korean | This brochure for the food industry provides recommendations to ensure the security of food products through all phases of the distribution process. FSIS Security Guidelines for Food Processors | PDF | En Espanol | Chinese | Vietnamese | Korean | These guidelines assist federal and state inspected plants that produce meat, poultry, and egg products in identifying ways to strengthen their biosecurity protection. Guidelines for the Disposal of Intentionally Adulterated Food Products and the Decontamination of Food Processing Facilities | PDF | This document is intended to serve as a resource guide for the U.S. Department of Agriculture's (USDA) Food Safety and Inspection Service (FSIS) and the Department of Health and Human Services' Food and Drug Administration (FDA) field personnel located in District Offices and at food processing facilities.
Industry Self-Assessment Checklist for Food Security | PDF | FSIS created this selfassessment instrument to provide a tool for establishments to assess the extent to which they have secured their operations. Keep America's Food Safe | PDF | En Espanol | This guidance is designed to assist transporters, warehouses, distributors, retailers, and restaurants with enhancing their security programs to further protect the food supply from contamination due to criminal or terrorist acts.
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
10
The Federal Reserve the Federal Reserve System is the central bank of the United States. It was founded by Congress in 1913 to provide the nation with a safer, more flexible, and more stable monetary and financial system. Over the years, its role in banking and the economy has expanded. Today, the Federal Reserves duties fall into four general areas: Conducting the nations monetary policy by influencing the monetary and credit conditions in the economy in pursuit of maximum employment, stable prices, and moderate long-term interest rates. Supervising and regulating banking institutions to ensure the safety and soundness of the nations banking and financial system and to protect the credit rights of consumers. Maintaining the stability of the financial system and containing systemic risk that may arise in financial markets. Providing financial services to depository institutions, the U.S. government, and foreign official institutions, including playing a major role in operating the nations payments system. The Financial and Banking Information Infrastructure Committee (FBIIC) FBIIC is chartered under the President's Working Group on Financial Markets, and is charged with improving coordination and communication among financial regulators, enhancing the resiliency of the financial sector, and promoting the public/private partnership. Treasury's Assistant Secretary for Financial Institutions chairs the committee. Financial Crimes Enforcement Network (FinCen) the mission of the Financial Crimes Enforcement Network is to safeguard the financial system from the abuses of financial crime, including terrorist financing, money laundering, and other illicit activity. Bank secrecy forms and filing requirements are available at www.fincen.gov/reg_bsaforms.html. Financial Services Information Sharing and Analysis Center (FS/ISAC) Launched in 1999, FS-ISAC was established by the financial services sector in response to 1998's Presidential Directive 63. That directive--later updated by 2003's Homeland Security Presidential Directive 7-mandated that the public and private sectors share information about physical and cyber security threats and vulnerabilities to help protect the U.S. critical infrastructure. Constantly gathering reliable and timely information from financial services providers, commercial security firms, federal, state, and local government agencies, law enforcement and other trusted resources, the FS-ISAC is now uniquely positioned to quickly disseminate physical and cyber threat alerts and other critical information to your organization. This information includes analysis and recommended solutions from leading industry experts. Financial Services Sector Coordinating Council The Financial Services Sector Coordinating Council for Critical Infrastructure Protection and Homeland Security is a group of more than 30 privatesector firms and financial trade associations that works to help reinforce the financial services sectors resilience against terrorist attacks and other threats to the nations financial infrastructure. Formed in 2002, FSSCC works with the Department of Treasury, which has direct responsibility for infrastructure protection and homeland security efforts for the financial services sector, while also serving under the overall guidance of the Department for Homeland Security. ID Theft the Presidents Task Force on Identity Theft was established by Executive Order 13402 on May 10, 2006, launching a new era in the fight against identity theft. Recognizing the heavy financial and emotional toll that identity theft exacts from its victims, and the severe burden it places on the economy, President Bush called for a coordinated approach among government agencies to combat this crime.
11
Identity Theft Assistance Center (ITAC) the Identity Theft Assistance Center is a cooperative initiative of the financial services industry to address and reduce the human and economic consequences of fraud and identity theft. Since 2004, ITAC has helped thousands of victims restore their financial identities. Interagency Guidelines Establishing Information Security Standards | PDF | This guide summarizes the obligations of financial institutions to protect customer information and illustrates how certain provisions of the Security Guidelines apply to specific situations. The appendix lists resources that may be helpful in assessing risks and designing and implementing information security programs. Securities Industry and Financial Markets Association (SIFMA) Represents the industry, which powers the global economy. Born of the merger between The Securities Industry Association and The Bond Market Association, SIFMA is the single powerful voice for strengthening markets and supporting investors the world over. Our dynamic, new organization is passionately dedicated to representing more than 650 member firms of all sizes, in all financial markets in the U.S. and around the world. We are committed to enhancing the publics trust and confidence in the markets, delivering an efficient, enhanced member network of access and forward-looking services, as well as premiere educational resources for the professionals in our industry and the investors whom they serve. U.S. Treasury the mission of the Department of the Treasury is to promote the conditions for prosperity and stability in the United States and encourage prosperity and stability in the rest of the world. Terrorist Financing the Office of Terrorism and Financial Intelligence (TFI) marshals the department's intelligence and enforcement functions with the twin aims of safeguarding the financial system against illicit use and combating rogue nations, terrorist facilitators, money launderers, drug kingpins, and other national security threats.
12
Chemical Sector
All of these sectors are working together to ensure that their efforts support each other. *
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
13
Chemical Sector
International Association of Drilling Contractors (IADC), Houston, Texas Independent Petroleum Association of America (IPAA), Washington, DC National Ocean Industries Association (NOIA), Washington, DC National Petrochemical and Refiners Association (NPRA), Washington, DC Offshore Operators Committee (OOC), Metairie, LA US Oil and Gas Association (USOGA), Jackson, MS Western States Petroleum Association (WSPA), Sacramento, CA United States Natural Gas, Propane, and Other American Gas Association (AGA), Washington, DC American Public Gas Association (APGA), Washington, DC Compressed Gas Association (CGA), Chantilly, VA Gas Processors Association (GPA), Tulsa, OK
Interstate Natural Gas Association of America (INGAA), Washington, DC National Propane Gas Association (NPGA), Washington, DC United States Retail National Association of Convenience Stores (NACS), Alexandria, VA Petroleum Marketers Association of America (PMAA), Arlington, VA
www.nacsonline.com www.pmaa.org
14
Chemical Sector
Society of Independent Gasoline Marketers of America (SIGMA), Reston, VA United States Transportation Independent Liquid Terminals Association (ILTA), Washington, DC National Tank Truck Carriers (NTTC), Alexandria, VA United States Other American Society of Mechanical Engineers (ASME) International Organization for Standardization (ISO), Geneva, Switzerland National Mining Association (NMA), Washington, DC Canada Canadian Association of Petroleum Producers (CAPP), Calgary, Alberta Canadian Energy Pipeline Association (CEPA), Calgary, Alberta Canadian Gas Association (CGA), Ottawa, Ontario Transport Canada (TC), Ottawa, Ontario
www.sigma.org
www.ilta.org www.tanktruck.netl
15
Chemical Sector
Homeland Security Operations Center (HSOC) National Infrastructure Advisory Council (NIAC) National Infrastructure Protection Plan (NIPP) National Response Plan (NRP) Department of Transportation (DOT): Maritime Administration Pipeline and Hazardous Materials Safety Administration National Pipeline Mapping System Office of Hazardous Materials Safety Office of Pipeline Safety Energy Information Administration (EIA) - Energy Security Environmental Protection Agency (EPA) Federal Bureau of Investigation (FBI): Infragard Program Internet Crime Complaint Center (ICCC) Houston Private Sector Information Sharing Joint Terrorism Task Force Los Angeles Private Sector Information Sharing National Petroleum Council (NPC) , Washington, DC Overseas Security Advisory Council (OSAC) , Washington, DC Transportation Security Administration (TSA) Pipeline Security Division Canada Government Agencies/Resources Canadian Security Intelligence Service , Ottawa, ON Natural Resources Canada Royal Canadian Mounted Police (RCMP)
16
Chemical Sector
17
Chemical Sector
National Archives and Records Administration (NARA) Code of Federal Regulations Protection of Information Critical Energy Infrastructure Information (CEII) Navigation and Inspection Circular (NVIC) 10-04: Guidelines for Handling Security Sensitive Information (SSI) | PDF | Protected Critical Infrastructure Information Program (PCII) Protection of Sensitive Security Information 49 CFR Part 1520 USCG, Sensitive Security Information (SSI) Regulation FAQ | PDF | Rail Security Rail Transportation Security, DHS Proposed Rule 49 CFR Parts 1520 and 1580 Surface Transportation and Rail Security Act of 2007 | PDF | Transportation Worker Identification Credential (TWIC) 49 CFR Parts 10, 12, and 15 - USCG
18
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
19
20
Sustainable Building Technical Manual: Green Building Design, Construction and Operations, EPA Guide to Threat and Risk Assessment Involving On-Site Physical Security Examination: RCMP Strategic National Guidance: The Decontamination of Buildings and Infrastructure Exposed to Chemical, Biological, Radiological, or Nuclear (CBRN) substances or material: Office of the Deputy Prime Minister: UK.
21
Take the Guesswork Out of Guest Control. June 2003, 60. Make Planning a Priority. May 2003, 71. Emergency Preparedness (Book Review). Dec 2002, 124. Los Angeles Tackles High-Rise Security (News and Trends). Sept 2002, 20. A New Forum for Security. June 2002, 71. The Jewel in the Crown [Crown Center Plaza, Kansas City, MO]. Sept 2000, 108. Condo Can Do [Capri Gardens Condominium Association, Miami, FL]. Jan 2000, 68. Tenants Anyone? (Spotlight). April 1999, 15. Security Planning Guidebook: Safeguarding Your Tenants and Property (Book Review). Aug 1996, 118. Building Security Relationships. July 1996, 103. Taking Life Safety to New Heights (Amoco Building, Chicago, IL). June 1996, 40.
4.2.4 Books
Archibald, R., & Medby, J. Security and Safety in Los Angeles High-rise Buildings After 9/11 . Santa Monica, CA: Rand Corporation, 2002. This analysis, commissioned by the Building Owners and Managers Association of Greater Los Angeles, includes Key Considerations for Building Security; Learning from Three Case Studies; Key Resource Guide on High-Rise Building and Multi-Tenant Security. December 2006, ASIS International . Planning Considerations for High-Rise Buildings; Potential Roles for Government; and Recommendations for Los Angeles. Azano, Harry J. Fire Safety and Security for High-Rise Buildings . Crete, IL: Abbott, Langer & Associates, 1995. TH/9445/H63A99/1995. Available to borrow from the ASIS Resources Center. Contents: 1) Recent high-rise disasters; 2) The challenge of high-rise buildings; 3) The role of the security force; 4) Understanding fire; 5) Attacking fire; 6) Sprinkler and standpipe systems; 7) Fire extinguishers and fixed systems; 8) Fire alarm systems; 9) The threat of arson and bombs; 10) High-rise safety program; Conclusion. Craighead, Geoff. High-Rise Security and Fire Life Safety, 2nd Ed . Woburn, MA: Butterworth-Heinemann, 2003. TH/9445/H63C88/2003. Available for purchase from the ASIS Online Bookstore. Includes how to conduct security and fire life safety surveys, effectively manage security programs, and prepare for high-rise emergencies. This new edition includes an analysis of the September 11, 2001, attacks on, and the collapse of, the Word Trade Center towers. Topics include high-rise building
22
development and utilization, building emergency planning; laws, codes, and standards; liaison with law enforcement and fire authorities; high-rise assets; and security and fire life safety threats. DoD Minimum Anti-Terrorism Standards for Buildings: Washington, DC: Department of Defense, 2003. Unified Facilities Criteria .
This document seeks to minimize the likelihood of mass casualties from attacks against DoD personnel in the buildings in which they work and live. Guidance for Filtration and Air-Cleaning Systems to Protect Building Environments from Airborne Chemical, Biological, or Radiological Attacks . Washington, DC. National Institute for Occupational Safety and Health, 2003. This document provides detailed, comprehensive information on selecting and using filtration and aircleaning systems in an efficient and cost-effective manner. Guidance for Protecting Building Environments from Airborne Chemical, Biological, or Radiological Attacks . Washington, DC: National Institute for Occupational Safety and Health, 2002. Prevention is the cornerstone of public and occupational health. This document provides preventive measures that building owners and managers can implement promptly to protect building air environments from a terrorist release of chemical, biological, or radiological contaminants. A Guide to Emergency Evacuation Procedures for Employees with Disabilities. Sacramento, CA: State of California, 1999. Prepared by the Emergency Response Task Force and the California Highway Patrol for the State of California, State Personnel Board, Statewide Disability Advisory Council. Fennelly, Lawrence J., Handbook of Loss Prevention and Crime Prevention, 4th Ed. New York: Butterworth-Heinemann, 2004. HV/8290/H23/2004. This revised volume brings together the expertise of more than 40 security and crime prevention experts who provide practical information and advice. This new edition covering the latest on topics ranging from community-oriented policing to physical security, workplace violence, information security, homeland security, and a host of special topics. See pp. 370-387 for Chapter 25, High-Rise Security and Fire Life Safety and Chapter 26, Multiresidential Security. Fennelly, Lawrence J,. Spotlight on Security for Real Estate Managers . Chicago, IL: Institute for Real Estate Management, 2005. HV/8290/F33/2005. The goal of this book is to help real estate managers understand the issues that form the basis of liability claims and provide some tools than can be used to minimize the likelihood of crime occurring on the properties they manage and be prepared to deal with the consequences in the event a crime occurs at or near their property. The information here will assist the real estate manager in evaluating the security needs of a property and identifying security measures that will meet those needs within the available budget. While some chapters focus on a single property type, most of the strategies presented in the text can be adapted of considered for all types of properties.
23
Kitteringham, Glen. Security and Life Safety for the Commercial High-Rise. Alexandria, VA: ASIS International, 2006. TH/9445/H6K62/2006. Since September 11, 2001, the high-rise industry has been reviewing security and life safety procedures and practices and taking steps to improve security based on building size and importance, geographic location, potential risk to occupants, and risk of attacks. The risk assessment guidelines presented in this book are oriented toward protection of a site's personnel and physical assets. They would also generally apply to protection of computer data, hardware, and software. The security guidance discussed in this book will assist individual companies to assess their properties and determine how best to protect their assets. Ontario Office of the Fire Marshal. A Guide to Strengthen Emergency Management of High-Rise and High- Risk Buildings, Ontario, Canada: Ontario Office of the Fire Marshal, 2002. This guide has been developed as part of the provincial government's commitment to improve Ontario's emergency preparedness and to help owners and operators of large buildings improve occupant safety and security. Protection of Assets Manual. ASIS International, Alexandria, VA. 2004 (with revisions and updates), Volume 4, Chapter 1, pp. 1-35. HV/8290/P975/VOL 4. This comprehensive source covers all aspects of security including access control, training, employee awareness, internal and external theft and fraud, security and civil law, investigations, ethics, alcohol and drug abuse, and more. All business managers and protection professionals with an assets protection responsibility will find this information pertinent in each subject area, and helpful in effectively tackling critical security issues and organizing special research projects. This manual also serves as a central library reference for students pursuing a program in security or assets protection. Risk Management Series: Primer for Design of Commercial Buildings to Mitigate Terrorist Attacks . Washington, DC, Federal Emergency Management Agency, Washington, DC, 2003. This primer introduces a series of concepts that can help building designers, owners, and State and local governments mitigate the threat of hazards resulting from terrorist attacks on new buildings. FEMA 427 specifically addresses four high-population, private-sector building types: commercial office, retail, multifamily residential, and light industrial. This manual contains extensive qualitative design guidance for limiting or mitigating the effects of terrorist attacks, focusing primarily on explosions, but also addressing chemical, biological, and radiological attacks. Sampson, Rana. Drug Dealing in Privately Owned Apartment Complexes . ProblemOriented Guides for Police: Problem-Specific Guides Series, No. 4. Washington, DC: Department of Justice, 2006. This guide focuses on drug dealing in privately owned apartment complexes. The guide makes a clear distinction between open- and closed-drug markets, provides information on what is known about each market type, and provides questions to ask when analyzing each market. It also proposes various responses designed to closed-drug markets and provides a full range of problem-specific measures to determine the effectiveness of those responses.
24
Security Planning Guidebook: Safeguarding your Tenants and Property. Washington, DC: Building Owners and Managers Association International, 1995. HV/7431/S42/1995. Available to borrow from the ASIS Resources Center. Contents: Introduction; Security incidents; Evaluating your security needs; In-house vs. contract security? Working with police, fire dept and others; Tenant communications; Liability and insurance issues; Developing a security and safety communication plan; Putting the plan into action; Appendices: sample plan, crisis communications plan, bomb threats.
4.2.5 Videotapes/DVD:
Emergency Response: Life Safety and Evacuation [videotape: 20 min.]. Emotion Pictures, LLC. 2002. VHS//E543/2002. Demonstrates what the person in charge of life safety for building occupants needs to know, and how to conduct a thorough and complete evacuation. Includes interactions with emergency responders, practicing the plan and ensuring that building occupants understand it, checking life safety systems and exit paths, and more. Also includes a 26-page Instructor's Guide. High-rise Evacuation [videotape: 22 min.]. Quincy, MA: National Fire Protection Association, 2002. VHS//H638/2002. Includes a 12-page instructor's pamphlet. This program is intended to be used regularly as part of a complete evacuation training course that includes a review of building emergency plans. It emphasizes the important role people can take in ensuring fire safety in high rises and in their ability to evacuate safely if fire occurs. The film presents safety features of high-rise buildings and how they contribute to safe evacuation in a fire emergency. The narrator gives the viewer a tour through the building, demonstrating its potential to contain a fire and limit its spread. Because a fire safety plan is dependent upon proper human response, a fire emergency scenario is presented, in which a good plan is carried out quickly and correctly. Lessons From Ground Zero: Evacuation [videotape: 23 min.]. Virginia Beach, VA: Coastal Human Resources, 2002. VHS//L641/2002. This video is the first part of a Lessons From Ground Zero training documentary. It provides first-hand accounts from those who experienced the World Trade Center evacuations on February 26, 1993 and September 11, 2001. It shows how critical changes implemented after the 1993 bombing expedited the evacuation on September 11th and highlights the importance of evacuation plans and fire drills, proper use of fire extinguishers, and necessity of working radios, operational flashlights, fully stocked first aid kits and accurate building maps.
4.2.6 Seminar Sessions Audiotapes / CD-ROM / DVD (ASIS): Building a National Response Plan (2005) Session ID: S10 Participants: Carlos Villarreal (speaker), Geoffrey T Craighead, CPP (moderator) Large companies that have many locations across the United States must have a robust and flexible plan in place to prevent, respond to, and recover from an incident. This session details what one commercial real estate company did to create a national response plan to critical incidents. Hear how the program got started, how it was implemented and tested, and how it is being maintained. Examples of emergency plans, monitoring systems, and notifications protocols will be given.
25
CPTED & Security in the Commercial High-Rise (2004) Session ID: S37 Participants: Glen W Kitteringham, CPP (speaker), William J McShane, CPP (moderator) Security basics are covered including a discussion of policies and procedures, an examination of the physical facilities (3 buildings), a discussion of building residents and users, and a CPTED review and analysis of three specific areas of study within the properties. The First 90 Days After 9/11 (2002) Session ID: S71 Participants: Mark E Raybould, CPP (speaker), Mark T Wright (speaker), Charles J Mattes, CPP (speaker) Hear first-hand from four security professionals who have direct responsibilities for billion dollar assets in major markets like New York Chicago Los Angeles and Houston what immediate challenges they faced and the escalation strategies they implemented during the first 90 days following 9/11 and beyond to protect lives and buildings. You will walk away with valuable and practical information to help you manage facilities after catastrophic events. High-Rise Environments - Protection and Survivability (2002) Session ID: S23 Participants: Phillip Banks, CPP (speaker), Arik S Garber, CPP (moderator), The aftermath of the terrorist events of September 2001 as well as the continuing nation-wide threat environment has resulted in a demand for increased high-rise building security and safety planning. This response includes among other things increased screening of tenants and visitors as well as deliveries coming into the building and advanced emergency planning and preparedness. This session highlights methodologies that will increase your level of survivability from a terrorist attack or a naturally occurring disaster. High Rise Fire - Lessons Learned in Chicago (2004) Session ID: S6 Participants: Carlos Villarreal (speaker), Nancy A. Renfroe, CPP (moderator) This session is two-fold. First, there is a review of the tragic fire that occurred in a downtown Chicago high-rise office building, taking six lives. Then, the next section teaches how to take training to a higher awareness. There is a discussion of new methods to better train personnel to handle fire conditions and what type of fire safety training really works for building occupants. Detailed fire safety presentations do not always communicate the right message. High Rise Fire Simulations: Moving Beyond Fire Drills (2004) Event: 50th Annual Seminar Session ID: S23 Participants: Steve Cichon (speaker), Charles K Hutchinson (speaker), Michael Crocker, CPP (moderator) The theme of this presentation is high-rise fire safety. This training moves beyond the conventional fire drill to a new training platform. This is a simulation conducted in real buildings in a training platform. This includes a zero visibility environment with a building in fire mode. Responders must use building systems and equipment, elevator and fire panel operations, and traffic management. The fire simulation tests all levels of the responder abilities. This presentation is an overview of a highly intense training format that brings together the private and public sector in a unique cross-training environment. Securing an Office Building (2003) Session ID: S24 Participants: Mark E Raybould, CPP (speaker), Louis G Caravelli, CPP (speaker), Carlos Villarreal (moderator)
26
Learn what best practices are being used to address the new threat issues everyone in commercial real estate security is facing. This session will review past standards and discuss the new way of securing an office building. Issues including threat levels, access control systems, CCTV coverage, emergency planning and staffing will be discussed in great detail. Best practices on how to build and review your building's plan also will be discussed during this every informative program. Security and Safety Concerns: High Rise Buildings After 9/11 (2003) Session ID: S32 Participants: Robert A Cizmadia, CPP (speaker), Robert L Pearson (moderator) The density of populations and high-rise buildings within our cities provides the motivation for considering the assessment of security and safety of these architectural wonders. This presentation is targeted towards security and facility managers, property owners, tenants, and architects of such buildings. The content of this presentation will focus on taking an integrated approach in addressing security of high-rise buildings from a security management operational administrative technological and educational awareness perspective.
27
Dams Sector
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
28
Dams Sector
29
Dams Sector
terrorists to spies on U.S. soilfrom cyber villains to corrupt government officialsfrom mobsters to violent gangsfrom child predators to serial killers. Learn more here about our work with law enforcement and intelligence partners across the country and around the globe. Federal Emergency Management Administration (FEMA), National Dam Safety Program Although the Federal Government owns or regulates only about 5 percent of the dams in the United States, many of these dams are significant in terms of size, function, benefit to the public, and hazard potential. Since the implementation of the Federal Guidelines for Dam Safety in 1979, the federal agencies have done an exemplary job in ensuring the safety of dams within their jurisdiction. They accomplish this by sharing resources whenever and wherever possible to achieve results and improvements in dam safety. Many of the federal agencies also maintain very comprehensive research and development programs and training programs, and have now incorporated security considerations and requirements into these programs to protect their dams against terrorist threats. National Dam Safety Review Board The Review Board provides the Director of FEMA with advice in setting national dam safety priorities and considers the effects of national policy issues affecting dam safety. Review Board members include FEMA, the Chair of the Board, and representatives from four federal agencies that serve on the Interagency Committee on Dam Safety (ICODS), five state dam safety officials, and one member from the private sector. Interagency Committee on Dam Safety (ICODS) Established in 1980, encourages the establishment and maintenance of effective federal programs, policies, and guidelines to enhance dam safety and security. ICODS serves as the permanent forum for the coordination of federal activities in dam safety and security. FEMA also chairs ICODS. ICODS Agencies: Department of Agriculture Agricultural Research Service Natural Resources Conservation Service Forest Service Department of Defense, Army Corps of Engineers Department of Energy Department of the Interior Bureau of Indian Affairs Bureau of Land Management Bureau of Reclamation Fish and Wildlife Service National Park Service Department of Labor, Mine Safety and Health Administration Federal Energy Regulatory Commission Department of State, International Boundary and Water Commission Nuclear Regulatory Commission Tennessee Valley Authority
30
Dams Sector
Federal Energy Regulatory Commission (FERC) Hydropower The Commission's responsibilities include: Issuance of licenses for the construction of a new project; Issuance of licenses for the continuance of an existing project (relicensing); and Oversight of all ongoing project operations, including dam safety inspections and environmental monitoring. Homeland Security Information Center (HSIC) The Homeland Security Information Center at NTIS is an invaluable resource for scientific and technical information from the U.S. Government, its contractors, and complementary material from international sources. The HSIC is categorized into these major security concerns: health & medicine, food & agriculture, bio and chemical warfare, preparedness and response, and safety training. Products are available in a variety of formats: electronic download, online access, computer products, multimedia, microfiche, and paper. International Association of Emergency Managers (IAEM) The International Association of Emergency Managers (IAEM) is a non-profit educational organization dedicated to promoting the goals of saving lives and protecting property during emergencies and disasters. The International Journal on Hydropower and Dams A bi-monthly publication, read in 176 countries, dealing with all technical, environmental, social and economic aspects of hydro plants and multipurpose water resources development projects. It combines business news with state-of-the-art technology. Each issue has a regional focus, and special technical themes of interest to engineers in all the related disciplines. National Emergency Management Association (NEMA) NEMA is the professional association of and for state emergency management directors. National Hydropower Association (NHA) The National Hydropower Association, founded in 1983, is the only trade association in the United States dedicated exclusively to advancing the interests of hydropower energy in North America. Located in Washington, D.C., NHA is a member-driven association that accomplishes its policy work and outreach through the initiatives of its standing committees. National Performance of Dams Program Formally launched in 1994, the NPDP is an effort to establish within the dam engineering and safety community the ability to learn from the in-service performance of dams, supporting improvements in dam design, operation, engineering, and public policy. National Society of Professional Engineers (NSPE) The National Society of Professional Engineers (NSPE) is the recognized voice and advocate of licensed Professional Engineers. Founded in 1934, NSPE strengthens the engineering profession by promoting engineering licensure and ethics, enhancing the engineer image, advocating and protecting PEs' legal rights at the national and state levels, publishing news of the profession, providing continuing education opportunities, and much more. NSPE serves some 50,000 members and the public through 53 state and territorial societies and more than 500 chapters. Sandia National Laboratories, Security Risk Assessment Methodology for Dams (RAM-D) Developed by Sandia National Laboratories for the Interagency Forum for Infrastructure Protection (IFIP). The IFIP is a consortium chartered in 1997 to promote information exchange among dam owners and operators for the focused purpose of identifying effective means of countering the potential threat to the security of our nation's more than 75,000 dams. The RAM-DSM is an adaptation of the security
31
Dams Sector
principles, processes, and procedures developed to protect nuclear materials. The RAM-DSM includes tools developed to address issues that are specific to dam facilities. Security Management Solutions (SMS) Dam Assessment Matrix for Security and Vulnerability Risk (DAMSVR) methodology was developed under the direction of FERC. SMS was contracted to pull together existing methodologies from FERC and Bureau of Reclamation, develop a new methodology, and field test the product. Since the completion of the process, SMS has developed a full range of training to support DAMSVR studies. The Infrastructure Security Partnership (TISP) A national public-private partnership, TISP is the recognized leader promoting collaboration to improve the resilience of the nation's critical infrastructure against the adverse impacts of natural and man-made disasters. U.S. Army Corps of Engineers, Institute for Water Resources (IWR) IWR was established to provide the U.S. Army Corps of Engineers with forward-looking insights and analyses on emerging national water resources issues Risk Assessment Methodology for Dams (RAM-D) The Corps has been integrally involved in the creation and implementation of this unique assessment tool designed to help operators of dams, hydroelectric facilities, and power plants make their sites less attractive targets to terrorists. RAM-D helps operators identify who might attack a facility, what resources they might have available, and what steps might be taken to prevent an attack. Operators can use RAM-D to determine where to place sensors, cameras, or lights, or whether to invest in walls, barriers, higher fences, better doors, extra training, or improved policies. The Corps is working to improve the use of RAM-D, while also evaluating other tools and concepts to improve risk assessment efforts and reduce vulnerabilities. U.S. Coast Guard (USCG) a military, multi-mission, maritime service and one of the nations five Armed Services. Its mission is to protect the public, the environment, and U.S. economic interests in the nations ports and waterways, along the coast, on international waters, or in any maritime region as required to support national security. U.S. Department of Agriculture (USDA), USDA Dam Safety Committee (USDADSC) Establishment is in the public's interest in that it will strengthen dam safety efforts in the Department and support the Executive Branch in the implementation of the "Federal Guidelines for Dam Safety." U.S. Department of Energy (DOE), Infrastructure Security and Energy Restoration (ISER) A division of the DOEs Office of Electricity Delivery and Energy Reliability leads the federal government's effort to ensure a robust, secure, and reliable energy infrastructure. United States Society on Dams (USSD) To be the nation's leading organization of professionals dedicated to advancing the role of dams for the benefit of society. USSD is dedicated to: Advancing the knowledge of dam engineering, construction, planning, operation, performance, rehabilitation, decommissioning, maintenance, security, and safety; Fostering dam technology for socially, environmentally, and financially sustainable water resources systems;
32
Dams Sector
Providing public awareness of the role of dams in the management of the nation's water resources; Enhancing practices to meet current and future challenges on dams; and Representing the United States as an active member of the International Commission on Large Dams (ICOLD).
33
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
34
ASIS International With more than 34,000 members, ASIS is the largest international organization for professionals responsible for security, including managers and directors of security. In addition, corporate executives and other management personnel, as well as consultants, architects, attorneys, and federal, state, and local law enforcement, are becoming involved with ASIS to better understand the constant changes in security issues and solutions. ASIS is dedicated to increasing the effectiveness and productivity of security practices by developing educational programs and materials that address broad security concerns, such as the ASIS Annual Seminar and Exhibits, as well as specific security topics. By providing members and the security community with access to a full range of programs and services, and by publishing the only monthly magazine focused strictly on the issues and concerns of security, Security Management, ASIS leads the way for advanced and improved security performance. Annual Membership Fee: $150.00 Central Florida Industrial Security Awareness Council Good source for automated information systems security plans and links to Defense Security Service and FSO topics. Annual Membership Fee: None Chief Security Officer (CSO) A resource for security executives. Annual Membership Fee: None Extranet for Security Professionals (XSP) An on-line tool for security professionals to collaborative and discuss issues of common interest. All information is 128 bit encrypted and the XSP operated at a FOR OFFICIAL USE ONLY level. Registration is limited to individuals who hold at least a Secret security clearance. Although no classified information may be placed on the network, everyone with access to the network is a cleared individual. Some useful features include a collaboration realm where questions may be posed to and answered by the XSP community, posting of the latest versions of government regulations, manuals, and forms, a bulletin board for job posting, recruiting, equipment sharing, and general items of interest, and a calendar of security related events. Annual Membership Fee: None Homeland Security Information Network (HSIN) Critical Infrastructure Pilot. Annual Membership Fee: None Industrial Security Working Group (ISWG) Separate community on OPMIS/XSP. A working group of industrial security directors and mangers involved with SCI programs and the Intelligence Community. ISWG collaborates and directly interacts with IC agencies establishing national security
35
policies and directives. Meetings always include the most senior level government security directors from all IC agencies. Minimum access requirement for participation is TS/SI/TK. Participants are typically the Security Directors or most senior security officials from companies working on IC contracts. Meetings are held at a classified level. National ISWG meetings alternate between East Coast and West Coast companies with facilities large enough to host gatherings of 200-300 attendees. Annual Membership Fee: None National Classification Management Society (NCMS) NCMS was founded in 1964 by a group of government & industry security classification managers and administrators recognizing the importance of establishing a national scope society to advance the practice of Classification Management as a profession. Today, the Society has nearly 2,000 members in the United States and overseas including representatives from NATO countries. Within the U.S., members come from the Department of Energy, Department of Defense, Department of State, National Aeronautics and Space Administration, Federal Bureau of Investigation, National Security Agency, General Accounting Office--virtually every Federal agency that deals with classification--and from the civilian contractors who work with these agencies. As the Society has grown over the years, its focus has also expanded. NCMS now provides professional development for its members in the field of classification management, information security, personnel security, computer security, operations security (OPSEC), facility security, and technology security. Annual Membership Fee: $60.00
36
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
37
American Public Works Association (APWA) American Water Works Association (AWWA) The AWWA Web site provides sites and links relative to security issues. The AWWA, The American Society of Civil Engineers (ASCE), and the Water Environment Federation (WEF) have corroborated on a major infrastructure security enhancement program for the water and wastewater sectors. The AWWA has an established Security Committee that serves as an association resource for its members and member organizations. The AWWA is active in encouraging and supporting the Water and Wastewater Agency Response Network (WARN) initiative. In essence, this program seeks to establish mutual aid and assistance networks for water and wastewater utilities on a statewide basis for response to disasters and other emergencies. ASIS International The Association of Contingency Planners (ACP) Association of Metropolitan Water Agencies (AMWA) European Water Association InfraGard (sponsored by the FBI) This program provides for joint public and private partnering in protecting the nations infrastructures. The Infrastructure Security Partnership (TISP) As quoted from Regional Disaster Resilience: A Guide for Developing an Action Plan, The Infrastructure Security Partnership (TISP) was established following the tragic events of September 11, 2001, as a national forum for public and private-sector organizations to collaborate on issues regarding the resilience of the nations critical
38
infrastructure against the adverse impacts of natural and man-made disasters. TISP membership represents 100 organizations representing more than 1.5 million people and firms. National Association of Water Companies (NAWC) National Infrastructure Protection Plan (NIPP) National Rural Water Association (NRWA) Water ISAC (Information Sharing and Analysis Center)
The above listed resources are intended to provide appropriate members of the infrastructure community with information and assistance of both short and long term benefit. This list is not necessarily comprehensive or definitive it is merely an aid to the CIP process.
39
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
40
41
8.2.1 Resources:
ASIS Business Continuity Guideline | PDF | A guideline that encompasses all elements of disaster management and recovery. ASIS Disaster Preparation Guide | PDF | This guide was prepared to assist its members and others engaged in disaster planning. It was created with business and industry in mind. ASIS Emergency Planning Handbook Provides guidance and direction to corporate security supervisors/managers who have emergency planning responsibilities. It imparts planning guidance in summary form that can be adapted to and supplemented by company procedures and policies. ASIS General Security Risk Assessment Guideline | PDF | A seven-step process that creates a methodology by which security risks at a specific location can be identified and communicated, along with appropriate solutions. ASIS Threat Advisory System Response Guideline | PDF | A guideline to provide private business and industry with possible actions that could be implemented based on the Alert Levels of the Department of Homeland Security. Critical Incident Protocol: A Public Private Partnership | PDF | Office of Domestic Preparedness This publication discusses the essential and beneficial process of the public and private sectors working together to plan for emergencies. Important elements include planning, mitigation, business recovery, lessons learned, best practices, and plan exercising. Emergency Management Guide for Business and Industry | PDF | Federal Emergency Management Agency This guide provides step-by-step advice on how to create and maintain a comprehensive emergency management program. It can be used by manufacturers, corporate offices, retailers, utilities, or any organization where a sizable number of people work or gather. Homeland Security Exercise and Evaluation Program (HSEEP) , Office of Domestic Preparedness HSEEP is both doctrine and policy for designing, developing, conducting, and evaluating exercises. HSEEP is a threat- and performance-based exercise program that includes a cycle, mix, and range of exercise activities of varying degrees of complexity and interaction. HSEEP includes a series of four reference manuals to help states and local jurisdictions establish exercise programs and design, develop, conduct, and evaluate exercises. Volume I: HSEEP Overview and Exercise Program Management (Feb 2007) Volume II: Exercise Planning and Conduct (Feb 2007) Volume III: Exercise Evaluation and Improvement Planning (Feb 2007) Volume IV: Sample Documents and Formats (Introduction) (Feb 2006)
42
Energy Sector
43
Energy Sector
distributed to homes and businesses over 981,000 miles of distribution pipelines. The heavy reliance on pipelines highlights the interdependency with the Transportation Sector and the reliance on the Energy Sector for power means that virtually all sectors have dependencies on the sector. The Energy Sector is well aware of its vulnerabilities and is leading a significant voluntary effort to increase its planning and preparedness. Cooperation through industry groups has resulted in substantial information sharing of effective and best practices across the sector. Many sector owners and operators have extensive experience abroad with infrastructure protection and have more recently focused their attention on cyber security. *
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
44
Energy Sector
45
Energy Sector
46
Energy Sector
9.2.3 References:
Electricity Sector Information and Analysis Center (ESISAC) Guidelines <http://esisac.com/library-guidelines.htm> Security Guideline for the Electricity Sector -- Physical Response Threat Alert System and Cyber Response Guidelines for the Electricity Sector Vulnerability and Risk Assessment Emergency Plans Continuity of Business Operations (updated on 6/1 to Continuity of Operations) Communication Physical Security Cyber Security Risk Management Cyber Security Access Control Cyber Security IT Firewalls Cyber Security Intrusion Detection Employment Background Screening Protecting Potentially Sensitive Information Securing Remote Access to Electronic Control and Protection Systems Threat and Incident Reporting Physical Security Substations Patch Management for Control Systems Control System Business Network Electronic Connectivity Physical Response
North American Electric Reliability Corporation (NERC) Standards <http://www.nerc.com/~filez/standards/Reliability_Standards.html> CIP-001-1 CIP-002-1 CIP-003-1 CIP-004-1 CIP-005-1 CIP-006-1 CIP-007-1 CIP-008-1 CIP-009-1 Sabotage Reporting Critical Cyber Asset Identification Security Management Controls Personnel and Training Electronic Security Perimeter(s) Physical Security of Critical Cyber Assets System Security Management Incident Reporting and Response Planning Recovery Plans for Critical Cyber Assets
NERC Assessment Methods <http://esisac.com/library-assessments.htm> Risk Assessment Methodologies for the Electricity Sector w/ Appendices A to H
47
Energy Sector
NERC Support Documents Energy Sector Specific Plan Final from DHS expected shortly, reference to be provided. Influenza Pandemic Planning, Preparation, and Response Reference Guide | PDF | Potential Mitigation Strategies for the Common Vulnerabilities of Control Systems Identified by the NERC Control Systems Security Working Group | PDF |
American Public Power Association (APPA) Product Store Safety and Security <http://www.appanet.org/store/productsafety.cfm?sn.ItemNumber=11987> APPA Emergency Management Checklist Security Checklist and Guidance Manual
48
Energy Sector
Sponsoring Organization: EEI Program: Security Committee Description: Holds workshops and forums to facilitate security information exchange among its members, NERC, American Gas Association, and government agencies. Sponsoring Organization: EEI and a large group of electric utilities Program: Spare Transformer Sharing Agreement Description: A significant group of utility transmission facility owners developed and signed a Spare Transformer Sharing Agreement designed to require participants to maintain a specified number of high-voltage spare transformers and to provide them to other participants in the event of an act of terrorism. Sponsoring Organization: EPRI Program: Electricity Infrastructure Security Assessment Description: Provides a preliminary analysis of potential terrorist threats to the North American electricity system, together with some suggested countermeasures. Sponsoring Organization: EPRI Program: Infrastructure Security Initiative Description: Develops strategies to strengthen and protect electric power infrastructure and outline plans for rapid recovery from terrorist attacks. Sponsoring Organization: NAESB Program: Energy Sector Business Practices and Electronic Communications Standards Description: Develops and promotes standards for the wholesale and retail natural gas and electricity industries through companies and organizations that participate in the retail and wholesale of natural gas and electricity markets. Sponsoring Organization: NARUC Program: Technical Briefs Description: Identifies key strategies for consideration in dealing with challenges within each of the electricity, natural gas, water, and telecommunications sectors. Provides introductory overviews, suggested protocols, and additional resources on critical infrastructure protection issues. See www.naruc.org/cipbriefs Sponsoring Organization: NERC Program: Critical Infrastructure Protection Committee (CIPC) Description: The Critical Infrastructure Protection Committee coordinates NERC's security initiatives and is comprised of industry experts in the areas of cyber, physical, and operational security. Sponsoring Organization: NERC Program: Electricity Sector Information Sharing and Analysis Center (ESISAC) Description: Gathers, disseminates, and interprets security-related information amongst industry, government, and all the sector entities. Sponsoring Organization: NERC Program: Industry-wide critical spare equipment database Description: Informs companies of the location and technical characteristics of available spare transformers.
49
Energy Sector
50
Energy Sector
3) Area Maritime Security Existing regulatory standards relating to Coast Guard requirements for natural gas facilities in their jurisdiction. Refer to 33 CFR Part 103. 4) Maritime Security Vessels - Existing regulatory standards relating to Coast Guard requirements for natural gas facilities in their jurisdiction. Refer to 33 CFR Part 104. 5) Facility Security Existing regulatory standards relating to Coast Guard requirements for natural gas facilities in their jurisdiction. Refer to 33 CFR Part 105. 6) Outer Continental Shelf Facility Security Existing regulatory standards relating to Coast Guard requirements for natural gas facilities in their jurisdiction. Refer to 33 CFR Part 106. 7) Automatic Identification System; Vessel Carriage Requirement Existing regulatory standards relating to Coast Guard requirements for natural gas facilities in their jurisdiction. Refer to 33 CFR Parts 26, 161, 164, & 165. 8) Transportation Worker Identification Credential (TWIC) Implementation in the Maritime Sector | PDF | Existing regulatory standards relating to Coast Guard requirements for natural gas facilities in their jurisdiction. Refer to 33 CFR Parts 101, 103, 104, 105, 106, & 125; 46 CFR Parts 10, 12, & 15. C. Federal Protection of Sensitive Information 1) Federal Energy Regulatory Commission (FERC) Regulates commercial aspects of interstate transportation of natural gas. FERC regulations provided for certain restrictions on Critical Energy Infrastructure Information (CEII.) 2) Sensitive Security Information (SSI) Federal regulations exist protecting certain transportation-related information records. Refer to 49 CFR Part 1520. SSI is a protection frequently used by DHS / TSA. 3) Protected Critical Infrastructure Information (PCII) PCII is an information-protection tool established by DHS that facilitates information sharing between the government and the private sector. III. KEY INFORMATIONAL WEB SITES A. Federal 1) Homeland Security Information Network (HSIN) Federally sponsored information sharing portal for critical infrastructure protection, including oil and natural gas sector. HSIN is an internet-based information sharing tool providing security-related information -requires membership (password protected.) 2) National Pipeline Mapping System (NPMS) Federally sponsored mapping system showing regulated liquids and natural gas transmission pipelines; maintained by U.S. Department of Transportation, Pipeline and Hazardous Materials Administration (PHMSA). 3) Government Accounting Office (GAO) Copies of reports and testimonies. 4) Daily Open Source Infrastructure Report 5) National Infrastructure Protection Plan 6) National Strategy for the Physical Protection of Critical Infrastructures and Key Assets 7) United States Computer Emergency Readiness Team (US-CERT) Established to protect the nation's Internet infrastructure, US-CERT coordinates defense against and responses to cyber attacks across the nation.
51
Energy Sector
8) DHS TSA Suspicious Incidents Reports (SIR) Classified as Sensitive Security Information (SSI). Weekly reports of suspicious activity reported by the six transportation sectors, Aviation, Maritime, Highway, Pipelines, Rail/Transit, and Cargo/Supply Chain. For more information contact Nicole.Brenon@dhs.gov
B. Industry Also refer to industry web sites listed in IV.B below IV. AGENCIES AND ORGANIZATIONS A. Federal 1) U.S. Department of Homeland Security, Transportation Security Administration, Transportation Sector Network Management, Pipeline Division Coordinates security preparedness of the nation's hazardous liquid and natural gas pipelines. 2) U.S. Department of Homeland Security, Homeland Security Operations Center (HSOC) Serves as critical national center for homeland security information sharing and domestic incident reporting. HSOC represents over 35 agencies and is staffed 24/7. The HSOC also includes the National Infrastructure Coordinating Center (NICC), which has primary responsibility for coordinating communications with the Nations critical infrastructure during an incident. 3) DHS Transportation Security Operations Center (TSOC) Serves as critical national center for transportation security information sharing and domestic incident reporting. TSOC is staffed 24/7. For additional information contact M&L.TSCC@tsa.dot.gov 4) DHS Homeland Infrastructure Threat and Risk Analysis Center (HITRAC) HITRAC is a DHS entity that conducts integrated threat analysis for all critical infrastructure sectors. HITRAC works with the intelligence and law enforcement communities to integrate and analyze intelligence on security threats to homeland infrastructure. For additional information contact IA.PM@hq.dhs.gov 5) FBI Joint Terrorism Task Force (JTTF) Contact local FBI office for additional information on your local JTTF. 6) U.S. Department of Transportation, Pipeline and Hazardous Materials Administration (PHMSA) Regulates pipeline safety of nations hazardous liquid and natural gas pipelines. Coordinates with DHS/TSA on matters pertaining to pipeline security. 7) U.S. Department of Energy, Office of Electricity Deliverability & Energy Reliability, Infrastructure Security and Energy Reliability Division (ISER) Coordinates energy and security reliability efforts. 8) DHS Protective Security Advisors To partner with state and local governments, as well as the private sector, DHS has place security specialists in communities throughout the country to assist local efforts to protect critical assets and provide local perspective to national efforts. 9) Information Sharing and Analysis Center (ISAC) Council 10) Information Sharing and Analysis Center (ISAC) White Papers 11) InfraGard InfraGard is a Federal Bureau of Investigation (FBI) program and is an effort to gain support from the information technology industry and academia for the FBIs investigative efforts in the cyber arena. InfraGard and the FBI have developed a relationship of trust and credibility in the exchange of information concerning various terrorism, intelligence, criminal, and security matters.
52
Energy Sector
12) Infragard Infrastructure Areas B. Industry 1) American Gas Association (AGA), Natural Gas Security Committee (NGSC) the AGA is a trade association representing natural gas local distribution companies across the U.S. with a standing committee (NGSC) dealing with security matters. For additional information contact kdenbow@aga.org . 2) Interstate Natural Gas Association of America (INGAA), Security Committee INGAA is a trade association representing interstate natural gas transmission and storage companies across the U.S. with a standing committee dealing with security matters. 3) ASIS Utilities Security Council C. Government / Industry Coordination 1) Critical Infrastructure Partnership Advisory Council (CIPAC) -CIPAC, which has been exempted from the requirements of the Federal Advisory Committee Act, is the mechanism used for dialogue on key infrastructure issues between government and owner/operators. CIPAC is a non-decisional body and includes sector and government members. 2) Oil and Natural Gas Sector Coordinating Council (ONG SCC) A private forum for coordination of oil and gas security issues across the broad oil and natural gas sector. Involves a broad spectrum of industry associations and provides a forum for interfacing with corresponding Government Coordinating Council (GCC). Various SCCs serve as the governments principal point of contact into each sector. The Oil and Natural Gas SCC utilizes HSIN as a communication interface/tool. For more information e-mail Shona_Turner@sra.com . 3) Government Coordinating Council (GCC) Comprised of representatives across various levels of government as applicable to security of a given sector. GCCs are chaired by the designated Sector-Specific Agency (SSA) for each sector, such as Energy and Transportation. 4) National Infrastructure Advisory Council (NIAC) A FACA advisory committee that provides the Federal government with advice regarding critical infrastructure security across all sectors. Members of the committee are appointed by the President from industry, academia, and state/local governments. Note that the ONG SCC formed a working group with the NIAC on issues regarding pandemic preparedness. D. State and Local Government Refer to also to law enforcement, emergency management, and homeland security officials in your state/local jurisdiction. 1) Buffer Zone Protection Program Provides federal resources to identify and mitigate vulnerabilities to critical infrastructure. E. Other Professional Organizations 1) ASIS General Security Risk Assessment Guideline | PDF | A seven-step process that creates a methodology by which security risks at a specific location can be identified and communicated, along with appropriate solutions. 2) ASIS Threat Advisory System Response Guideline | PDF | A guideline to provide private business and industry with possible actions that could be implemented based on the Alert Levels of the Department of Homeland Security.
53
Energy Sector
3) ASIS Business Continuity Guideline | PDF | A guideline that encompasses all elements of disaster management and recovery. 4) ASIS Emergency Planning Handbook Provides guidance and direction to corporate security supervisors/managers who have emergency planning responsibilities. It imparts planning guidance in summary form that can be adapted to and supplemented by company procedures and policies. 5) ASIS Disaster Preparation Guide | PDF | This guide was prepared to assist its members and others engaged in disaster planning. It was created with business and industry in mind. 6) Federal Emergency Management Agency (FEMA), Emergency Planning Guide for Business and Industry | PDF | This guide provides step by step advice on how to create and maintain a comprehensive emergency management program. It can be used by manufacturers, corporate offices, retailers, utilities or any organization where a sizable number of people work or gather. 7) Office of Domestic Preparedness, Critical Incident Protocol: A Public Private Partnership |PDF | This publication Critical Incident Protocol: A Public and Private Partnership discusses the essential and beneficial process of the public and private sectors working together to plan for emergencies. Important elements include planning, mitigation, business recovery, lessons learned, best practices, and plan exercising. 8) Homeland Security Exercise and Evaluation Program (HSEEP), Office of Domestic Preparedness HSEEP is both doctrine and policy for designing, developing, conducting and evaluating exercises. HSEEP is a threat- and performance-based exercise program that includes a cycle, mix and range of exercise activities of varying degrees of complexity and interaction. HSEEP includes a series of four reference manuals to help states and local jurisdictions establish exercise programs and design, develop, conduct, and evaluate exercises. Volume I: Exercise Overview and Doctrine Volume II: Exercise Evaluation and Improvement Volume III: Exercise Program Management and Exercise Planning Process Volume IV: Sample Exercise Documents and Formats
54
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
55
56
Guide to Threat and Risk Assessment Involving On-Site Physical Security Examination: RCMP Strategic National Guidance: The Decontamination of Buildings and Infrastructure Exposed to Chemical, Biological, Radiological, or Nuclear (CBRN) substances or material: Office of the Deputy Prime Minister: UK.
57
Make Planning a Priority. May 2003, 71. Emergency Preparedness (Book Review) Dec 2002, 124. Los Angeles Tackles High-Rise Security (News and Trends). Sept 2002, 20. A New Forum for Security. June 2002, 71. The Jewel in the Crown [Crown Center Plaza, Kansas City, MO]. Sept 2000, 108. Condo Can Do [Capri Gardens Condominium Association, Miami, FL]. Jan 2000, 68. Tenants Anyone? (Spotlight). April 1999, 15. Security Planning Guidebook: Safeguarding Your Tenants and Property (Book Review). Aug 1996, 118. Building Security Relationships. July 1996, 103. Taking Life Safety to New Heights (Amoco Building, Chicago, IL). June 1996, 40.
10.2.4 Books
Archibald, R., & Medby, J. Security and Safety in Los Angeles High-rise Buildings after 9/11 . Santa Monica, CA: Rand Corporation, 2002. This analysis, commissioned by the Building Owners and Managers Association of Greater Los Angeles, includes Key Considerations for Building Security; Learning from Three Case Studies; Key Resource Guide on High-Rise Building and Multi-Tenant Security December 2006, ASIS International. Planning Considerations for High-Rise Buildings; Potential Roles for Government; and Recommendations for Los Angeles. Azano, Harry J. Fire Safety and Security for High-Rise Buildings . Crete, IL: Abbott, Langer & Associates, 1995. TH/9445/H63A99/1995. Available to borrow from the ASIS Resources Center. Contents: 1) Recent high-rise disasters; 2) The challenge of high-rise buildings; 3) The role of the security force; 4) Understanding fire; 5) Attacking fire; 6) Sprinkler and standpipe systems; 7) Fire extinguishers and fixed systems; 8) Fire alarm systems; 9) The threat of arson and bombs; 10) High-rise safety program; Conclusion. Craighead, Geoff. High-Rise Security and Fire Life Safety, 2nd Ed . Woburn, MA: Butterworth-Heinemann, 2003. TH/9445/H63C88/2003. Available for purchase from the ASIS Online Bookstore. Includes how to conduct security and fire life safety surveys, effectively manage security programs, and prepare for high-rise emergencies. This new edition includes an analysis of the September 11, 2001, attacks on, and the collapse of, the Word Trade Center towers. Topics include high-rise building
58
development and utilization, building emergency planning; laws, codes, and standards; liaison with law enforcement and fire authorities; high-rise assets; and security and fire life safety threats. DoD Minimum Anti-Terrorism Standards for Buildings: Washington, DC: Department of Defense, 2003. Unified Facilities Criteria .
This document seeks to minimize the likelihood of mass casualties from attacks against DoD personnel in the buildings in which they work and live. Guidance for Filtration and Air-Cleaning Systems to Protect Building Environments from Airborne Chemical, Biological, or Radiological Attacks . Washington, DC. National Institute for Occupational Safety and Health, 2003. This document provides detailed, comprehensive information on selecting and using filtration and aircleaning systems in an efficient and cost-effective manner. Guidance for Protecting Building Environments from Airborne Chemical, Biological, or Radiological Attacks . Washington, DC: National Institute for Occupational Safety and Health, 2002. Prevention is the cornerstone of public and occupational health. This document provides preventive measures that building owners and managers can implement promptly to protect building air environments from a terrorist release of chemical, biological, or radiological contaminants. A Guide to Emergency Evacuation Procedures Sacramento, CA: State of California, 1999. for Employees with Disabilities .
Prepared by the Emergency Response Task Force and the California Highway Patrol for the State of California, State Personnel Board, Statewide Disability Advisory Council. Fennelly, Lawrence J., Handbook of Loss Prevention and Crime Prevention, 4th Ed. New York: Butterworth-Heinemann, 2004. HV/8290/H23/2004. This revised volume brings together the expertise of more than 40 security and crime prevention experts who provide practical information and advice. This new edition covering the latest on topics ranging from community-oriented policing to physical security, workplace violence, information security, homeland security, and a host of special topics. See pp. 370-387 for Chapter 25, High-Rise Security and Fire Life Safety and Chapter 26, Multiresidential Security. Fennelly, Lawrence J,. Spotlight on Security for Real Estate Managers . Chicago, IL: Institute for Real Estate Management, 2005. HV/8290/F33/2005. The goal of this book is to help real estate managers understand the issues that form the basis of liability claims and provide some tools than can be used to minimize the likelihood of crime occurring on the properties they manage and be prepared to deal with the consequences in the event a crime occurs at or near their property. The information here will assist the real estate manager in evaluating the security needs of a property and identifying security measures that will meet those needs within the available budget. While some chapters focus on a single property type, most of the strategies presented in the text can be adapted of considered for all types of properties.
59
Kitteringham, Glen. Security and Life Safety for the Commercial High-Rise. Alexandria, VA: ASIS International, 2006. TH/9445/H6K62/2006. Since September 11, 2001, the high-rise industry has been reviewing security and life safety procedures and practices and taking steps to improve security based on building size and importance, geographic location, potential risk to occupants, and risk of attacks. The risk assessment guidelines presented in this book are oriented toward protection of a site's personnel and physical assets. They would also generally apply to protection of computer data, hardware, and software. The security guidance discussed in this book will assist individual companies to assess their properties and determine how best to protect their assets. Ontario Office of the Fire Marshal. A Guide to Strengthen Emergency Management of High-Rise and High- Risk Buildings, Ontario, Canada: Ontario Office of the Fire Marshal, 2002. This guide has been developed as part of the provincial government's commitment to improve Ontario's emergency preparedness and to help owners and operators of large buildings improve occupant safety and security. Protection of Assets Manual. ASIS International, Alexandria, VA. 2004 (with revisions and updates), Volume 4, Chapter 1, pp. 1-35. HV/8290/P975/VOL 4. This comprehensive source covers all aspects of security including access control, training, employee awareness, internal and external theft and fraud, security and civil law, investigations, ethics, alcohol and drug abuse, and more. All business managers and protection professionals with an assets protection responsibility will find this information pertinent in each subject area, and helpful in effectively tackling critical security issues and organizing special research projects. This manual also serves as a central library reference for students pursuing a program in security or assets protection. Risk Management Series: Primer for Design of Commercial Buildings to Mitigate Terrorist Attacks . Washington, DC, Federal Emergency Management Agency, Washington, DC, 2003. This primer introduces a series of concepts that can help building designers, owners, and State, and local governments mitigate the threat of hazards resulting from terrorist attacks on new buildings. FEMA 427 specifically addresses four high-population, private-sector building types: commercial office, retail, multifamily residential, and light industrial. This manual contains extensive qualitative design guidance for limiting or mitigating the effects of terrorist attacks, focusing primarily on explosions, but also addressing chemical, biological, and radiological attacks. Sampson, Rana. Drug Dealing in Privately Owned Apartment Complexes . ProblemOriented Guides for Police: Problem-Specific Guides Series, No. 4. Washington, DC: Department of Justice, 2006. This guide focuses on drug dealing in privately owned apartment complexes. The guide makes a clear distinction between open- and closed-drug markets, provides information on what is known about each market type, and provides questions to ask when analyzing each market. It also proposes various responses designed to closed-drug markets and provides a full range of problem-specific measures to determine the effectiveness of those responses.
60
Security Planning Guidebook: Safeguarding your Tenants and Property. Washington, DC: Building Owners and Managers Association International, 1995. HV/7431/S42/1995. Available to borrow from the ASIS Resources Center. Contents: Introduction; Security incidents; Evaluating your security needs; In-house vs. contract security? Working with police, fire dept and others; Tenant communications; Liability and insurance issues; Developing a security and safety communication plan; Putting the plan into action; Appendices: sample plan, crisis communications plan, bomb threats.
61
CPTED & Security in the Commercial High-Rise (2004) Session ID: S37 Participants: Glen W Kitteringham, CPP (speaker), William J McShane, CPP (moderator) Security basics are covered including a discussion of policies and procedures, an examination of the physical facilities (3 buildings), a discussion of building residents and users, and a CPTED review and analysis of three specific areas of study within the properties. The First 90 Days After 9/11 (2002) Session ID: S71 Participants: Mark E Raybould, CPP (speaker), Mark T Wright (speaker), Charles J Mattes, CPP (speaker) Hear first-hand from four security professionals who have direct responsibilities for billion dollar assets in major markets like New York Chicago Los Angeles and Houston what immediate challenges they faced and the escalation strategies they implemented during the first 90 days following 9/11 and beyond to protect lives and buildings. You will walk away with valuable and practical information to help you manage facilities after catastrophic events. High-Rise Environments - Protection and Survivability (2002) Session ID: S23 Participants: Phillip Banks, CPP (speaker), Arik S Garber, CPP (moderator), The aftermath of the terrorist events of September 2001 as well as the continuing nation-wide threat environment has resulted in a demand for increased high-rise building security and safety planning. This response includes among other things increased screening of tenants and visitors as well as deliveries coming into the building and advanced emergency planning and preparedness. This session highlights methodologies that will increase your level of survivability from a terrorist attack or a naturally occurring disaster. High Rise Fire - Lessons Learned in Chicago (2004) Session ID: S6 Participants: Carlos Villarreal (speaker), Nancy A. Renfroe, CPP (moderator) This session is two-fold. First, there is a review of the tragic fire that occurred in a downtown Chicago high-rise office building, taking six lives. Then, the next section teaches how to take training to a higher awareness. There is a discussion of new methods to better train personnel to handle fire conditions and what type of fire safety training really works for building occupants. Detailed fire safety presentations do not always communicate the right message. High Rise Fire Simulations: Moving Beyond Fire Drills (2004) Event: 50th Annual Seminar Session ID: S23 Participants: Steve Cichon (speaker), Charles K Hutchinson (speaker), Michael Crocker, CPP (moderator) The theme of this presentation is high-rise fire safety. This training moves beyond the conventional fire drill to a new training platform. This is a simulation conducted in real buildings in a training platform. This includes a zero visibility environment with a building in fire mode. Responders must use building systems and equipment, elevator and fire panel operations, and traffic management. The fire simulation tests all levels of the responder abilities. This presentation is an overview of a highly intense training format that brings together the private and public sector in a unique cross-training environment. Securing an Office Building (2003) Session ID: S24 Participants: Mark E Raybould, CPP (speaker), Louis G Caravelli, CPP (speaker), Carlos Villarreal (moderator)
62
Learn what best practices are being used to address the new threat issues everyone in commercial real estate security is facing. This session will review past standards and discuss the new way of securing an office building. Issues including threat levels, access control systems, CCTV coverage, emergency planning, and staffing will be discussed in great detail. Best practices on how to build and review your building's plan also will be discussed during this every informative program. Security and Safety Concerns: High Rise Buildings After 9/11 (2003) Session ID: S32 Participants: Robert A Cizmadia, CPP (speaker), Robert L Pearson (moderator) The density of populations and high-rise buildings within our cities provides the motivation for considering the assessment of security and safety of these architectural wonders. This presentation is targeted towards security and facility managers, property owners, tenants, and architects of such buildings. The content of this presentation will focus on taking an integrated approach in addressing security of high-rise buildings from a security management operational administrative technological and educational awareness perspective.
63
The Information Technology (IT) Sector has a key role in securing the Nations cyberspace. The IT Sector is composed of entitiesowners and operators and their respective associationswho produce and provide hardware, software, and IT systems and services, including development, integration, operations, communications, and security. The IT Sector is comprised of, but not limited to, the following: Domain Name Systems root and Generic Top-Level Domain operators; Internet Service Providers; Internet backbone providers; Internet portal and e-mail providers; networking hardware companies; and other hardware manufacturers, software companies, security services vendors, communications companies that characterize themselves as having an IT role, edge and core service providers, and IT systems integrators. In addition, Federal, State, and local governments participate in the IT Sector as providers of government IT services that are designed to meet the needs of citizens, businesses, and employees. *
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
64
65
Perl Script for Analyzing Network Traffic Recommendations for Thwarting Spyware Roadmap to Defeating DDoS SANS Free Resources List of free resources for computer and Internet security. SANS Internet Storm Center - The Internet Storm Center gathers millions of intrusion detection log entries every day, from sensors covering over 500,000 IP addresses in over 50 countries ... identifying the sites that are used for attacks, and providing authoritative data on the types of attacks that are being mounted against computers in various industries and regions around the globe. SANS News Browser Service Security for Non-technical Executives The 7 Top Management Errors that Lead to Computer Security Vulnerabilities TCP/IP and Tcpdump Flyer | PDF | SecurityFocus A vendor-neutral site that provides objective, timely and comprehensive security information to all members of the security community, from end users, security hobbyists and network administrators to security consultants, IT Managers, CIOs and CSOs. SecurityFocus Bugtraq SecurityFocus Vulnerabilities list Sophos' Security Information (includes latest threats, viruses, white papers) Symantec Latest Threats, Vulnerabilities, Risks, etc (includes search function and links to removal tools, security updates, etc). TrendMicro TrendMicro HijackThis Free Tool to scan PC file & registry settings TrendMicro HouseCall Free online virus scanner. TrendMicro Latest Threat Advisories Windows Security Aggregator of articles, news, patches, etc.
66
11.2.3 Books:
Cyber Threat Levels Response Handbook, by James P. Litchko, Ron Lander, & Lew Wagner (2004). Published by KNOW Book Publishing. ISBN-13: 978-0974004525. KNOW IT Security: Secure IT Systems Casino Style, by Jim Litchko (2004). Published by KNOW Book Publishing. ISBN-13: 978-0974884509. This book provides non-technical individuals with a quick, entertaining, and effective introduction on how to achieve successful IT security. Hacking Wireless Networks for Dummies, by Kevin Beaver, Peter T. Davis & Devin K. Akin (2005). Published by For Dummies. ISBN-13: 978-0764597305. Learn how to secure a basic wireless network by studying common attacks. Defeating the Hacker: A Non-technical Guide to Computer Security , by Robert Schifreen (2006). Published by Wiley. ISBN-13: 978-0470025550 Network Security Evaluation Using the NSA IEM , by Russ Rogers, et al. (2005). Published by Syngress. ISBN-13: 978-1597490351 Security Log Management: Identifying Patterns in the Chaos, by Jacob Babbin, et al. (2006). Published by Syngress. ISBN-13: 978-1597490429. Learn how to garner important information from voluminous computer security log files Perfect Passwords: Selection, Protection, and Authentication, by Mark Burnett and Dave Kleiman (2005). ISBN-13: 978-1597490412.
67
* Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
68
69
cycle, mix and range of exercise activities of varying degrees of complexity and interaction. HSEEP includes a series of four reference manuals to help states and local jurisdictions establish exercise programs and design, develop, conduct, and evaluate exercises. Volume I: Exercise Overview and Doctrine Volume II: Exercise Evaluation and Improvement Volume III: Exercise Program Management and Exercise Planning Process Volume IV: Sample Exercise Documents and Formats
70
71
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
72
73
73.55 73.56
Requirements for Physical Protection of Licensed Activities in Nuclear Power Reactors Against Radiological Sabotage Personnel Access Authorization for Nuclear Power Plants
74
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
75
76
77
78
New York (contd) New York City Police Department Major Case Squad Sergeant Francis Buddy Murnane (718) 265-7327 Suffolk County Police Department Long Island New York Robbery Bureau Sergeant Al Feinstein (631) 852-6176 Illinois FBI Chicago Interstate Theft Task Force SA Bill Griffin (312) 786-2772 (312) 786-2525 telefax (312) 431-1333 24-hour number Downtown Chicago SA Chuck Pearson (708) 429-2227 Chicagoland area Nevada Las Vegas Metropolitan Police Department VIPER (Auto & Cargo) Task Force Lieutenant Larry Spinoza (702) 229-3576
79
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
80
81
National Institute for Occupational Safety and Health (NIOSH) The federal agency responsible for conducting research and making recommendations for the prevention of work-related injury and illness. Occupational Safety and Health Administration (OSHA) OSHA's mission is to assure the safety and health of America's workers by setting and enforcing standards; providing training, outreach, and education; establishing partnerships; and encouraging continual improvement in workplace safety and health. Pandemic Flu One-stop access to U.S. Government avian and pandemic flu information. Managed by the Department of Health and Human Services.
82
Telecommunications Sector
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
83
Telecommunications Sector
84
Excerpt from U.S. Department of Homeland Security, National Infrastructure Protection Plan, 2006.
85
86
Federal Highway Administration (FHWA) GIS in Transportation GIS Cafe article by Lili Eylon Office of Infrastructure Provides leadership, technical expertise, and program assistance in: Federal-Aid Highway Programs; Asset Management; Pavements; and Bridges to help sustain America's mobility. Federal Transit Administration Office of Safety and Security Concerned with matters relating to the safety and security of our nation's mass transit systems. Federal Transit Administration Updates Nationwide Transit Safety and Security Awareness Program Homeland Security Institute This is an excellent, up-to-date reference site. E-newsletter is available for free. Formerly the ANSER Institute for Homeland Security. Information Sharing & Analysis DHS sub-organization responsible for CI protection InfraGard. InfraGard's goal to improve and extend information sharing between private industry and the government, particularly the FBI, when it comes to critical national infrastructures. Infrastructure Policy Group Reports issues and trends in infrastructure policy at the state government level. Institute for Biosecurity An excellent focused site on the topic of bioterrorism with lots of links. International Cargo Security Council Contains links to publications and web sites related to cargo security. Logistics Management National Consortia on Remote Sensing in Transportation (NCRST) NCRST-Infrastructure is pursuing a broad program of research and outreach in identification and protection of critical transport infrastructure. National Transportation Library NCGIA CCTP Unit 3 Locating Transportation Data, by Val Noronha In the NCGIA Core Curriculum for Technical Programs) NCGIA Core Curriculum in GISci Detailed Outline. The entrance page for the NCGIA Core Curriculum in Geographic Information Science, the latest version of the NCGIA GIS Core Curriculum project NSDI FrameWork Transportation Standard Now Proposed as FGDC Standard GIS Cafe article; summary of FGDC/NSDI standards for transportation NYPD Transit Includes a history of policing the NYC Subway, a profile on the "Job of a Transit Cop," and unit profiles of the specialized Vandal and Homeless Outreach Squads. Also contains pages on
87
Transit Boroughs Manhattan, Bronx, Brooklyn and Queens, including information on patrol areas (known as transit districts) and the stations and subway lines they cover. Partnership for Critical Infrastructure Security The Partnership for Critical Infrastructure Security is a non-profit organization run by companies and private sector associations representing critical infrastructure industries. It offers a forum for networking among government agencies and industry representatives on reducing vulnerabilities, mitigating risks, identifying strategic objectives and sharing information on security practices. Public Safety (PS) Canada Canadas lead department for public safety. PS build and implement national policies for emergency management and national security. Technical Support Working Group (TSWG) Infrastructure Protection Informational Web site of the Technical Support Working Group of the Department of Defense, which conducts research and development projects for combating terrorism. The Infrastructure Security Partnership (TISP) An association of associations offering help and advice primarily in engineering areas regarding homeland security and infrastructure protection, with links to member organizations. Transportation Research Board (TRB) Part of the National Academies of Sciences. Transportation System Security In light of the tragic events of September 11, 2001, enhancing the security of our transportation system is expected to be one of the highest priorities of transportation agencies. TRB and The National Academies have generated extensive information on this issue in recent years. This web site brings together much of this information. Also included are links to other related Web sites that contain discussions of issues, actions which can be taken, guidance and training opportunities. Transit Standards Consortium Mass transit standards and improvements. Transportation and Infrastructure Research, Rand Corporation RAND Europe, a division of RAND, specializes in transportation issues, including planning, policy, safety, and environmental considerations of air, water, and surface systems. Many RAND divisions participate in research on critical infrastructure, such as power grids or waterways. Transportation Security Administration (TSA) The Transportation Security Administration protects the Nation's transportation systems to ensure freedom of movement for people and commerce. TRISOnline The National Transportation Library provides this online database. Use it to retrieve bibliographic data on airport security, bus security, train security, etc. Tropical Shipping From Canada to South Florida, Tropical Shipping operates state-of-the-art facilities in select seaside ports to meet your freight-shipping needs to and from the Caribbean and the Bahamas. Tutor2U Inter-brand Consultancy.
88
U.S. Department of Homeland Security (DHS) U.S. Customs and Border Protection (CBP) U.S. Department of Transportation, Office of Inspector General Aviation and Special Programs Reading Room Surface and Maritime Reading Room U.S. General Accounting Office Reports on Airport Security Issues (Special Collection) Reports on Homeland Security Issues (Special Collection)
89
Aviation Security Civil aviation security exists to prevent criminal activity on aircraft and in airports. Criminal activity includes acts such as hijacking (air piracy), damaging or destroying aircraft and nearby areas with bombs, and assaulting passengers and aviation employees. Today, aviation security is high on the list of priorities of air travelers, the Federal Government, and the international air community. In the earliest days of aviation, however, aviation security was only a minor concern. Article on the history of aviation security by the U.S. Centennial of Flight Commission. Aviation Security Articles from the U.S. News & World Report Type in "aviation security" to retrieve recent articles. Aviation Security: Counterterrorism Publications for Law Enforcement Officials Background Q&A: The UAE Purchase of American Port Facilities Questions and answers about issues surrounding a purchase that would give a company from Dubai (in the United Arab Emirates) "control over facilities in six U.S. ports: New York, Miami, Newark-Port Elizabeth, Philadelphia, New Orleans, and Baltimore." Discusses security concerns (weapons of mass destruction and vulnerability of liquefied natural gas), the company (DP World), significance of operation of U.S. ports by foreign companies, and related topics. Provided by Council on Foreign Relations. Source: Librarians' Internet Index, Week of March 2, 2006. Basic Characteristics of Freight Rail Transportation in the United States | PDF | This report provides a preliminary assessment of the freight railroad system as a critical infrastructure of the U.S., and describes the system's ability to continue to operate after accidents, natural disasters, actions caused by trespassers and possible terrorist threats. Critical Infrastructure Assurance Office. January 1997. Books About Airport Security in the MSU Libraries Border and Transportation Security: The Complexity of the Challenge | PDF | Jennifer E. Lake et al., Congressional Research Service Domestic Social Policy Division (March 29, 2005). 19pp. Posted by the Federation of American Scientists. Discusses advance passenger and cargo manifests, the Container Security Initiative, the Customs-Trade Partnership Against Terrorism (C-TPAT), and other current programs. Lake, J., Robinson, W., and Seghetti, L. Domestic Social Policy Division. Border and Transportation Security: Overview of Congressional Issues | PDF | Summarizes the roles and responsibilities of federal agencies involved in border and transportation security, and discusses issues confronting the 109th Congress. Jennifer E. Lake, Congressional Research Service (Dec. 17, 2004). 25pp. Posted by the Federation of American Scientists. Border and Transportation Security: Possible New Directions and Policy Options | PDF | William H. Robinson et al. Congressional Research Service Domestic Social Policy Division, March 29, 2005. 24pp. Posted by the Federation of American Scientists. Discusses biometric identification, maritime domain awareness, smart containers, and other developing programs. Border and Transportation Security: Selected Programs and Policies | PDF | Lisa M. Seghetti et al. Congressional Research Service Domestic Social Policy Division, March 29, 2005. 28pp. Posted by the Federation of American Scientists. Cargo Security: High Tech Protection, High Tech Threats | PDF | "The $2.7 trillion transportation industry accounts for 17 percent of the U.S. economy. But an estimated $30 to $50
90
billion in cargo is stolen worldwide each year." Computer-savvy criminals, backed by syndicates and assisted by corporation insiders, are manipulating the new shipping technology for illicit gains. Security professionals must maintain the expertise to anticipate and prevent sophisticated theft at every link in the worldwide supply chain. Ed Badolato, President, CMS, Inc. Cargo Theft: Americas Most Serious Property Crime | PDF | Edward V. Badolato, Security Management Magazine (July 2000). Posted by Contingency Management Services, Inc. Cleveland Transit Authority: Integrating CCTV, Access Control and Life Safety [Access restricted to MSU faculty and students or Proquest subscribers] Article by John Mesenbrink appearing in Security 39, no. 3 (March 2002). Whether they take a bus to work, ride the train to the airport or travel among the 59 municipalities it serves, Greater Cleveland Regional Transit Authority's riders logged nearly 60 million trips a year. The RTA is one of the largest transit systems in the United States. That makes it especially difficult to provide a safe environment for its 4 million riders and 3,000 employees, and protect its many buildings, millions of dollars of physical assets and the more than $30 million it collects in fares every year. Coast Guard Must Ramp Up Security, Acquisition Efforts, GovExec.com (Feb. 13, 2003) The Coast Guard should accelerate efforts to protect U.S. seaports from terrorism and move ahead on its $11 billion Deepwater acquisition project, senators from coastal states said Wednesday. Sen. Olympia Snowe, R-Maine, called on the Coast Guard to speed up security assessments of seaports and said she would try to increase funding for Deepwater, the services 30year upgrade of its offshore fleet, so the project could be finished in 10 years. Computer Assisted Passenger Pre-Screening In the past 18 months, most airline passengers have been more than willing to sacrifice a little convenience in the name of safety. The Transportation Security Administration bets they are willing to sacrifice privacy as well. That's the premise anyway of TSA's Computer Assisted Passenger Pre-Screening (CAPPS) II program, which Lockheed Martin Corp. will develop in the coming months to serve as a watchdog for the aviation industry. The program, which will receive passenger data from airline systems, will search government watch lists, financial records and other databases, looking for suspicious activity. The system will then assign a red, yellow or green threat level to passengers. Red indicates that a passenger cannot board an airplane; yellow will trigger close scrutiny of a passenger. Beware of the Watchdog TSA Awards Passenger Screening Contract Senators Call for CAPPS Oversight Contraband, Organized Crime, and the Threat to the Transportation and Supply Chain Function | PDF | The National Cargo Security Council a coalition of public and private transportation organizations - has retained FIA International Research Ltd. ("FIA") to examine how the transportation and supply chain function is impacted by cargo crime and the worldwide expansion of contraband markets in otherwise legal products... September 2001. Counter-Terrorism: Publications: Port Security Collection of government publications on the security of U.S. ports. Topics include port and maritime security challenges, policy and practices,
91
identification systems, container security, potential impact of terrorist attacks on freight transport, role of government agencies (such as the U.S. Coast Guard), and more. Publications go back to 2002. From the Counter-Terrorism Training Coordination Working Group convened by the U.S. Department of Justice. Source: Librarians' Internet Index, Week of March 2, 2006. Detection of Explosives for Commercial Aviation Security, Committee on Commercial Aviation Security, National Materials Advisory Board, Commission on Engineering and Technical Systems, National Research Council. Washington, DC: National Academy Press, 1993. 87pp. This book advises the Federal Aeronautics Administration (FAA) on the detection of small, concealed explosives that a terrorist could plant surreptitiously on a commercial airplane. The book identifies key issues for the FAA regarding explosive detection technology that can be implemented in airport terminals. Recommendations are made in the areas of systems engineering, testing, and technology development. Detour Ahead: Critical Vulnerabilities in America's Rail and Mass Transit Security Programs , Transportation Research Board of the National Academies Press (2006). U. S. Congressman Bennie G. Thompson, ranking member of the U.S. House of Representatives Homeland Security Committee, has released a report that was prepared by the Democratic staff of the committee that examines the potential vulnerabilities of Americas rail and mass transit security programs. The report was produced to coincide with the first anniversary of the London public transportation bombings of July 7, 2005. DHS Plans Web site to Help Identify Transportation Vulnerabilities The Department of Homeland Security plans to set up a free Web site that will allow owners and operators of transportation systems to voluntarily assess their security protections against terrorist attacks and receive recommendations on how to make improvements, the department announced this week. DHS is seeking public and industry comment on the Vulnerability Identification Self-Assessment Tool. The department submitted a request Wednesday to the Office of Management and Budget for emergency processing and approval authority to move forward on developing the tool. Comments are due to OMB by Sept. 9. The tool would be free to users and managed by the Transportation Security Administration. "After its inception, TSA faced the challenge of securing all of the different modes within the transportation sector," the Federal Register notice states. "A methodology was required in order to support inter- and intramodal analysis and decision-making. Millions of assets exist within the transportation sector, ranging from over 500,000 highway-bridges to over 19,000 general aviation airports. DOT Begins Recruiting Federal Security Directors for Airports, U.S. Department of Transportation (Jan. 8, 2002). News release. DOT Report Says U.S. Transit Systems Vulnerable to Terrorist Threat According to recent report published by the U.S. Transportation Department, buses and trains in the United States are becoming inviting targets for terrorist acts. Excerpted from: ERRI DAILY INTELLIGENCE REPORT-ERRI Risk Assessment Services-Saturday, February 28, 1998 Vol. 4 059
92
DOT Taps Private Industry for Help in Building Transportation Security Administration, U.S. Department of Transportation (Jan. 16, 2002) News release. Emergency Preparedness for Transit Terrorism [electronic resource], Annabelle Boyd and John P. Sullivan. Washington, D.C.: National Academy Press, 1997. Cataloged for Magic Emergency Response Guidebook (2000): A Guidebook for First Responders During the Initial Phase of a Dangerous Goods/Hazardous Materials Incident, U.S. Department of Transportation. An Evaluation of the Transportation Security Administrations Screener Training and Methods of Testing | PDF | Department of Homeland Security, Transportation Security Administration, Office of Inspector General (2004). 122p. Still available thanks to the Internet Archive. Copyright request 2175. Federal Cargo Inspection System Found Wanting A system used by the Homeland Security Department to help inspectors identify high-risk cargo coming into U.S. seaports needs improvement in order to better screen for weapons of mass destruction, according to a new report. In a summary report released this week, the Homeland Security Department's inspector general found deficiencies in an inspection system used by the Customs and Border Protection Bureau. Called the Automated Targeting System, it is used by CBP inspectors at domestic and foreign ports to help identify highrisk cargo containers for inspection. About 9 million containers arrive annually at U.S. seaports, making it impossible to physically inspect each of them without hampering the flow of commerce. Geography of Transit Crime: Documentation and Evaluation of Crime Incidence On and Around the Green Line Stations in Los Angeles | PDF | 43 pp. GlobalIncidentMap.com Highlights | PDF | U.S. Government Accountability Office Homeland Security: Protecting Airliners from Terrorist Missiles | PDF | Could shoulderfired missiles be the next terrorist weapon? In late Octoberjust two weeks before press reports indicated that some 4,000 surface-to-air missiles had gone missing from Saddam Hussein's arsenal after the invasion of Iraqthe Congressional Research Service released a report assessing the threat such missiles pose to the U.S. airline industry. According to the study, some twenty-five to thirty terrorist and insurgent groups already have surface-to-air missiles, including groups in Turkey, Thailand, Ireland, and Russia. The weapons generally have a range of about four miles, meaning that planes are safe while flying at 20,000 feet or higher, but vulnerable during takeoff and descent. The report notes that since surface-to-air missiles were first developed, in the late 1950s, there have been only six incidents in which passenger jets have been attacked with them; only two of these attacks were classified as "catastrophic," resulting in the deaths of all passengers on board. (The most recent attack occurred in November of 2002, when terrorists linked to Al-Qaeda unsuccessfully fired two surface-to-air missiles at an Israeli passenger jet in Mombasa, Kenya.) The bad news, according to the report, is that there is no simple or affordable way of protecting planes from such missiles. If the U.S. government were to install countermeasures on each of the country's thousands of large passenger jets, the cost would be somewhere between one and three million dollars per
93
aircraft. Deterrence flares (which will soon be installed on planes flown by the Israeli airline El Al) are not good at fooling newer models of the missiles and pose a fire hazard to the areas surrounding an airport. Evasive maneuvering by pilots is deemed "not a viable option." Christopher Bolkcom, Andrew Feickert, and Bartholomew Elias, Congressional Research Service, Oct. 22, 2004, 27pp. Posted by the Federation of American Scientists. Information Concerning the Arming of Commercial Pilots | PDF | GAO-02-822R. Improving Transit Security: A Synthesis of Transit Practice | PDF | National Research Council, Transportation Research Board. 1997. 45pp. Innovators in Supply Chain Security: Better Security Drives Business Value | PDF | National Association of Manufacturers. July 2006. 34 pp. Intermodal Cargo Transportation: Industry Best Security Practices May 1999. The Job of a Transit Cop Keeping Cargo Safe: Container Security Initiative, U.S. Customs and Border Protection Facts sheets about the Container Security Initiative (CSI), "a program intended to help increase security for containerized cargo shipped to the United States from around the world." Discusses elements of this anti-terrorism program, the ports where the CSI is in operation, and related material. Includes links to news releases about the CSI. Chapter 7. Transportation Systems, Making the Nation Safe: The Role of Science and Technology in Countering Terrorism, The National Academies Press (2002). Maritime Security: Overview of Issues | PDF | Library of Congress, Congressional Research Service report RS21079 by John F. Frittelli, updated December 5, 2003. 6 pp. Mass Transit Defends Itself Against Terrorism This article, written by ANSER analyst and editor Steve Dunham, examines how transportation systems have long been victim to various forms of terrorist attack and exploitation. The author conducts a rough historical review of terrorist attack on transportation, examines some of the risks inherent in the system, and discusses efforts by local authorities to improve both safety and security in this sector of critical infrastructure. Article by Steve Dunham appearing in the Journal of Homeland Security, March 2002. Mass Transit: Federal Action Could Help Transit Agencies Address Security Challenges | PDF | GAO-03-263 December 13, 2002. Mass Transit Terror: Madrid & London; Is America Next? [Access restricted to MSU faculty and students or Proquest subscribers] Article by Dean C Alexander. Security. Oct 2005. Vol. 42, Issue 10; pg. 20. After the London attacks, the US terror threat level for mass transit was raised from Code Yellow to Code Orange. US mass transit systems are valued in the hundreds of billions of dollars, and tallied 9 billion passenger trips in 2000. Increased security measures on some portions of European and American ground transportation were implemented shortly after the Mar 11 Madrid attacks, and
94
London's Jul 7 incidents. Countermeasures included greater use of uniformed and undercover police, bombing-sniffing dogs, surveillance cameras, incorporating explosives and bio-chemradiological detection equipment, spot-testing individual, inspecting trash receptacles, and requiring photo identification when purchasing selected tickets. A post-Mar 11 Department of Homeland Security measure, aims to improve security on intercity buses by taking measures to protect the driver, monitoring and commuting with buses, implementing and operating passenger and baggage screening programs, assessing critical needs and vulnerabilities, and training transportation personnel to recognize potential threats. National Strategy for Aviation Security | PDF | The National Strategy for Maritime Security | PDF | Describes specific threats to ocean activities, strategic security goals, and five strategic actions. Also includes eight supporting plans to address specific threats and challenges of the maritime environment. From the Office of the President. The Oh Police: Transit Police and Counterterrorism Steve Dunham of ANSER explains the vital but often overlooked role of the transit police in combating terrorism, assisting other law enforcement agencies, and restoring and preserving transportation in emergencies. He provides numerous examples of the transit polices expertise, and he notes their innovative ways of information sharing with other emergency responders, their own employees, and the patrons of the transportation system. Dunham also cites the many wayscreating coordination plans and procedures; conducting drills, simulations, and assessments; mobilizing command centers and procuring special equipmentthe transit police are successful in creating a premier command structure. Article by Steve Dunham appearing in the Journal of Homeland Security, July 2002. Operation Safe Commerce The Transportation Security Administration (TSA) is reviewing applications for a pilot program that will help cargo handlers implement technologies to protect sea containers from terrorist threats, several port security experts told lawmakers recently. Transportation officials have said they expect to allocate about $28 million in grants later this year for Operation Safe Commerce (OSC), a government and industry partnership that identifies cargo "supply chain" vulnerabilities along particular trade routes. "Operation Safe Commerce is ... dedicated to finding methods and technologies to protect commercial shipments from threats of terrorist attack, illegal immigration and other contraband while minimizing the economic impact upon the vital transportation system," Asa Hutchinson, the Homeland Security Department's undersecretary for border and transportation security, said during a Senate Governmental Affairs Committee hearing last week. Article by B. Molly, M. Peterson, National Journal's Technology Daily, appearing in GovExec.com, March 25, 2003. Policing Mass Transit: A Comprehensive Approach to Designing a Safe, Secure, and Desirable Transit Policing and Management System, Kurt R. Nelson., Springfield, Ill. : Charles C Thomas Publisher, c1999. 211pp. Main Library Stacks HE194.5.U6 N45 1999. This book is a comprehensive examination of the topics needed to insure the public's safety while using mass transit. Not only will law enforcement professionals and students find it a useful reference, it is also of benefit to transit managers and planners who need to incorporate safety and
95
security design into a mass transit system. The first section of the book discusses the foundations of creating a systematic approach to safety and security. The initial chapter establishes the community orientation needed for creating a stakeholder-vested transit system. From that foundation, an examination of information management and planning finish the discourse on the elemental portions of creating a total system. The next section divides mass transit into its basic components of buses, light rail, and fixed locations/stations. Each component requires consideration of unique or specialized issues. Finally, the last section covers specific topics of concern, such as terrorism, youths, gangs, mentally ill, homeless, and other pertinent areas of interest to both transit policing and system management. Policing Mass Transit is a book well-suited to students, planners, transit managers, and law enforcement officers. It is a comprehensive approach to designing a safe, secure, and desirable mass transit system. Policing Mass Transit: Serving a Unique Community An article by Kurt R. Nelson from the FBI Law Enforcement Bulletin (January 1997). Policing Transportation Facilities, Henry I. DeGeneste and John P. Sullivan., Springfield, Ill. : C.C. Thomas, c1994. 162pp. Main Library Stacks HV8291.U6 D44 1994 This book is the first comprehensive volume on the emerging discipline of transport policing. The text reviews the major issues concerning security and policing of transportation facilities and provides a framework for informed decision making. Topics include commuter rail and subway crime; maritime, port and cargo security; airport crime transportation terrorism; illegal drugs in transit, hazardous cargo, public bus and rail terminal crime and the special issues of homeless and mentally ill persons in transport centers. The book serves as a valuable resource for managers and command level staff at transit, railway, airport, and seaport police departments; police agencies with transport facilities in their jurisdiction; transportation facility managers; students and universities with programs in criminal justice, police science, government, public administration, transportation, and urban planning; police academies; and government departments of transportation. The text represents years of research, field interviews, teaching experience, administration, and program development in providing administrators and police with a framework for developing strategies to protect their facilities and patrons from current and future security risks. Port and Maritime Security: Background and Issues for Congress | PDF | Library of Congress, Congressional Research Service report RL31733 by John F. Frittelli, updated December 5, 2003. Port and Maritime Security in the United States: Reactions to an Evolving Threat. Colin Robinson. Center for Defense Information (Jan. 28, 2003) Each day, more than 16,000 containers arrive in the United States by ship, truck, or rail, yet only 2 percent of those that come by sea are inspected. Port and Maritime Security: Potential for Terrorist Nuclear Attack Using Oil Tankers | PDF | CRS report, Dec. 7, 2004 made available by the Federation of Atomic Scientists. Port Risk Management: Additional Federal Guidance Would Aid Ports in Disaster Planning and Recovery | PDF | GAO-07-412, March 28.
96
Port Security: Counter-terrorism Publications for Law Enforcement Officials Ports Work to Shore Up Security [Access restricted to MSU faculty and students or Proquest subscribers] Article by Michael Bradford appearing in Business Insurance 36 (September 16, 2002): 10 A year after terrorists attacked from the skies, U.S. ports are still finding their way in the effort to secure their own vast and vulnerable territory. Most have made some improvements with help from federal funds, albeit in amounts that some in the maritime industry have called inadequate. Critics of port security are blunt: The agencies in charge of security do not have the funding or personnel to protect the maritime industry, said Charming Hayden, president of the Steamship Association of Louisiana. He called the $92.3 million that the federal government granted earlier this year to improve port security a drop in the bucket. There is a $2.2 billion need just to do the minimum at the nation's ports, said Beth Rooney, manager of port security at the Port Authority of New York & New Jersey. Preventing Mass Transit Crime, Ronald V. Clarke. Monsey, N.Y. : Criminal Justice Press, 1996. Main Library Stacks HV7431 .C8 v.6 This collection explores situational crime prevention approaches at New York's Port Authority Bus Terminal, in the NYC Subway, and at transit systems in Washington, DC, Paris, and Chicago. Crime Prevention Studies v.6. The Prospects for Improving Cargo Container Security | PDF | This paper addresses the concerns of cargo container security and solutions to the problems posed by transnational threats to international and national security. Protecting the Nation's Ports : Fact Sheet As a member of the Department of Homeland Security, the Coast Guard continues to play an integral role in maintaining the operations of our ports and waterways by providing a secure environment in which mariners and the American people can safely go about the business of living and working freely. The Coast Guard's port security mission is not new, but it is definitely more visible today than it was prior to the tragic events of Sept. 11, 2001. Department of Homeland Security Press Release. Public Transportation System Security and Emergency Preparedness Planning Guide | PDF | Transportation Security Agency publication, January 2003. Rail and Transit Security Initiatives : Fact Sheet The responsibility of securing our nation's rail and mass transit systems is a shared one. The Department of Homeland Security (DHS), the Department of Transportation (DOT) and other federal agencies have taken significant steps to enhance rail and transit security in the last two years in partnership with the public and private entities that own and operate the nation's transit and rail systems. Efforts the past two years have focused on greater information sharing between the industry and all levels of government, assessing vulnerabilities in the rail and transit sector to develop new security measures and plans, increasing training and public awareness campaigns and providing greater assistance and funding for rail transit activities.
97
Today, the Department announced additional security initiatives that aim to further reduce vulnerabilities to transit and rail systems and make commuters and transit riders more secure. Currently, the Federal government provides leadership and technical assistance to transit and rail system owners and operators. New initiatives to be undertaken will target three specific areas: threat response support capability, public awareness and participation, and future technological innovations. U.S. Department of Homeland Security Press Release. Recommended Emergency Preparedness Guidelines for Rail Transit Systems This document contains recommended guidelines which are designed to assist rail transit systems to assess, develop, document and improve their capability for responding to emergency situations, and to coordinate these efforts with emergency response organizations in a manner which best protects the traveling public and transit system facilities and equipment. National Transportation Library. Report on El Salvador: How Transportation Security Patterns and Trends in Central America Adversely Affect Cargo Security | PDF | Report by Edward V. Badolato, Chairman of the National Security Cargo Council. March 1998. Seacurity: Improving the Security of the Global Sea-container Shipping System | PDF | The purpose of this document is to raise awareness concerning the current status of maritime security and its vulnerability to terrorism. The main obstacles in achieving a less vulnerable maritime system are identified. Maarten van de Voort. The RAND Corporation. Feb. 11, 2004. Seaports Called 'Critically Vulnerable' to Terrorism The nation's seaports remain "critically vulnerable" to terrorists seeking to smuggle weapons of mass destructionor themselvesinto the United States, several port security experts told a Senate panel on Thursday. "There are vulnerabilities in our sea cargo-container system that have the potential for exploitation by terrorists," Asa Hutchinson, the Homeland Security Department's undersecretary for border and transportation security, said during a Governmental Affairs Committee hearing. "In fact, most experts believe a terrorist attack using a container is likely." Capt. Jeffrey Monroe, director of ports and transportation for the city of Portland, Maine, said that although federal, state and local officials have made "great strides" in securing ports since Sept. 11, 2001, "we still must find solutions to the most serious problems on the waterfront." Those problems include a lack of coordination and procedural standards among agencies that regulate maritime commerce, and port managers' ongoing lack of access to intelligence data, according to Monroe. Article by Molly M. Peterson, National Journal's Technology Daily, appearing in GovExec.com, March 21, 2003. Securing Intermodal Connections: Meeting the Challenges of Rail-Aviation and Passenger Facilities | PDF | Prepared for Facility Security: Protecting Infrastructure and Special Events. Securing Rail Freight ANSER editor Steve Dunham looks at the terrorist threats to movement of freight by rail and what the railroads are doing to bolster security. Article appearing in the Journal of Homeland Security, February 2003. Securing U.S. Ports : Fact Sheet This February 2006 overview of U.S. ports includes details about the groups responsible for the ports (U.S. Customs and Board Protection, Coast Guard, terminal operator, and port authority), security measures (such as screening and inspection and the
98
Container Security Initiative), the United Arab Emirates (UAE)/Dubai Ports World acquisition, and related topics. From the U.S. Department of Homeland Security. Sky Marshall Program The Federal Air Marshal program is supposed to defend against hijackings and catastrophic terrorist attacks such as those that occurred on Sept. 11, 2001. However, despite the high hopes held for the scheme, its breakneck pace of expansion continues to expose some worrying flaws. The total budget for the program increased from $1 million to $481 million in the first year and may reach $1 billion by the end of 2003, while the number of officers has grown from 32 in 2001 to nearly 4,000 today. David Savino. Center for Defense Information, Feb. 24, 2003. Smuggling and Security in the Indochina Region Report by Edward V. Badolato, President of Contingency Management Services, Inc. June 29, 2000. Look under the topic "transportation security" for link. Special Collection on Airport Security Provides access to 68 GAO reports on airport security. A Strategy of Trust: What Will it Take to Secure Our Global Supply Chain? | PDF | Surface Transportation Security: Enforcement Officials Counter-terrorism Publications for Law
Terror at Sea: The Maritime Threat Ocean-going vessels carry over 80 percent of global trade, including vital supplies of oil and natural gas. Despite the measures taken since 9/11, the maritime sector remains vulnerable to terrorism. Terror at Sea examines the potential for terrorism against maritime facilities and recommends steps that can be taken to enhance the security of the maritime sector. Terrorist Nuclear Attacks on Seaports: Threat and Response | PDF | An update of a 2002 report on the threat to seaports from a concealed nuclear device in a container ship. Jonathan Medalia, Congressional Research Service, updated Jan. 24, 2005, 6pp. Posted by the Federation of American Scientists. Terrorist Threats Spur Security Efforts [Access limited to MSU faculty and students or Proquest subscribers] Article by Douglas McLeod appearing in Business Insurance 36 (September 23, 2002): 3 The threat of a terrorist attack using cargo containers and ports is leading government agencies and private groups to create new security procedures for shipping, several experts report. The U.S. Customs Service, U.S. Coast Guard and the International Maritime Organization are among the agencies developing programs ranging from inspecting "high-risk" containers to creating a system of security alerts and accompanying procedures for ships and ports. About 90 percent of the world's cargo moves by container, with 200 million containers moving between major seaports globally each year and more than 16 million arriving in the United States by ship, truck and rail, the Customs Service said. The Customs Service earlier this year launched a Container Security Initiative intended to keep out potentially dangerous cargo. Under new Customs regulations, carriers must provide U.S. Customs officials in foreign seaports with cargo manifests 24 hours before vessel loading. Ports in
99
Canada, Singapore, Netherlands, France, and Germany are among those that have agreed to participate so far. Top 20 Security Program Action Items for Transit Agencies Provides the most important elements identified by the FTA that transit agencies should incorporate into their System Security Program Plans. Transit Police: On Foot, In Buses, On Trains, In Squad Cars Transit policing is the epitome of community policing.. - Metro Transit Police Chief Jack Nelson. Transit Security Handbook | PDF | Contains information on FTA System Security Planning for US Systems, with an emphasis of Rail Fixed Guideway Systems. Also contains information on crime levels and patron perceptions, as well as terrorism prevention activities. Volpe National Transportation Systems Center. 1998. Transit Security Training Tools Transport Systems as Terror Targets Public transport networks in major cities are increasingly the target for terror attacks. Kathryn Westcott, BBC News Web site, July 7, 2005. Transportation Security Agenda for the 21st Century | PDF | Criminals plan to exploit and terrorists plot to disrupt the U.S. transportation system. Because both activities are escalating, transportation security must become a national priority, according to this author. The solution requires global initiatives that complement concerns about cost and competitiveness. Stephen E. Flynn. Transportation Security Guidelines for the U.S. Chemical Industry | PDF | Attention to security is a natural corollary to the chemical industrys safety culture. Security efforts, like safety efforts, protect the community and employees while keeping the transportation of hazardous materials operational. By reducing the risk of a wide range of threats to the transportation of hazardous materials, security measures can serve to enhance the goal of the safe transportation of hazardous materials. August 2, 2002. Transportation Security: Transportation Planning Needed to Optimize Resources | PDF | The General Accountability Office (GAO) has released GAO-05-357T describing DHS and TSA efforts in managing risks and allocating across aviation and surface transportation modes, and in integrating screening, credentialing, and R&D efforts to achieve efficiencies. GAO Testimony by Cathleen A. Berrick. 2005. 41pp. Transportation System Security In light of the tragic events of September 11, 2001, enhancing the security of our transportation system is expected to be one of the highest priorities of transportation agencies. TRB and The National Academies have generated extensive information on this issue in recent years. This web site brings together much of this information. Also included are links to other related Web sites that contain discussions of issues, actions which can be taken, guidance and training opportunities. This web site, which is being sponsored by the Transportation Research Board (TRB) Committee on Critical Transportation Infrastructure Protection (ABE40), will continue to be updated as more information becomes available.
100
Visibility and Vigilance: Metro's Situational Approach to Preventing Subway Crime | PDF | Nancy G. La Vigne. [Washington, DC] : U.S. Dept. of Justice, Office of Justice Programs, National Institute of Justice, [1997] This November 1997 NIJ Research in Brief by Nancy G. LaVigne discusses how design, management, and maintenance efforts have contributed to low transit crime rates at Washington, DC's Metro. Cataloged for Magic. White House Commission on Aviation Safety and Security Also known as the Gore Commission, the White House Commission on Aviation Safety and Security finished its work on February 12, 1997. Web page still available courtesy of the Federation of American Scientists.
101
Additional Resources
102
Additional Resources
103
Additional Resources
Texas A & M Texas Engineering Extension Service (TEEX) TEEXs goals have included developing businesses and the economy, protecting people and the environment, and building a safe, modern infrastructure. The agencys ongoing efforts have resulted in cleaner drinking water, better roads and infrastructure, improved workplace safety and enhanced public safety through the training of law enforcement officers and firefighters. TEEX also offers federally funded training programs that are free to public and private sector professionals. Louisiana State University Academy of Counter-Terrorism Education, National Center for Biomedical Research and Training (NCBRT) The NCBRT offers a wide range of training programs for the public and private sector to prepare those responsible for the planning and response to terrorist events involving weapons of mass destruction. Some of the training is free and programs cover awareness level, computerized specialized training, emergency response to biological incidents, crisis response training, hostage negotiations, senior crisis management, public safety WMD response, WMD awareness for the healthcare profession and more. George Mason University Critical Infrastructure Protection Program This program is a resource on CI/KR protection and management and their web site includes a newsletter, publications, research, projects, library, and an extensive outreach. Critical Infrastructure Protection in the National Capital Region This extensive 20 volume publication provides the analytic foundation for securing CI/KR services that are essential to the greater Washington D.C.s region. It provides recommendations, and focuses on the various sectors, with supporting information on risk management and analysis, along with how to create a partnership, governance, and certain initiatives. University of Toronto, Joint Centre for Bioethics Stand on Guard for Thee: Ethical Considerations in Preparedness Planning for Pandemic Influenza | PDF | The Pandemic Influenza Working Group at the University of Toronto The discussion of ethics in critical incident management by business professionals, public safety officials, non-profit leaders, and community stakeholders can either move to the lower level of priorities or become quagmire. Though this report reflects the medical community, it is easily applicable to the business community and will provide thought-provoking discussions on ethics.
104
Additional Resources
105
Additional Resources
Homeland Security Exercise and Evaluation Program (HSEEP) , U.S. Department of Homeland Security The HSEEP is a capabilities and performance-based exercise program that provides a standardized policy, methodology, and language for designing, developing, conducting and evaluating all exercises. HSEEP also facilitates the creation of self-sustaining, capabilitiesbased exercise programs by providing tools and resources such as guidance, training, technology, and direct support. Incident Command System (ICS), U.S. Occupational and Health Organization (OSHA) The ICS is a long proven system of handling field response activities in emergencies. It provides essential management using common terminology, modular organization, integrated communications, a unified command structure, consolidated action plans, manageable span-ofcontrol, predesigned incident facilities and comprehensive resource management. It organizes any emergency response effort into five basic functions: command, planning/intelligence, operations, logistics, and finance/administration. Almost all public agencies across the nation use this system, in addition to some private sectors that are regulated to do so. Additionally, public responder agencies are recommending that businesses and non-profit organizations adopt this system. Lessons Learned Information Systems (LLIS), U.S. Department of Homeland Security LLIS is a national network of Lessons Learned and Best Practices for emergency response providers and homeland security officials. LLIS.gov's secure, restricted-access information is designed to facilitate efforts to prevent, prepare for and respond to acts of terrorism and other incidents across all disciplines and communities throughout the US. This Web site is available to the private sector, and requires verification processes. The National Incident Management System (NIMS) | PDF | U.S. Department of Homeland Security The NIMS document (130 pages) provides a consistent nationwide template to enable all government, private sector, and nongovernmental organizations to work together during any domestic incident. Its applicable across a wide spectrum of potential incidents and hazardous scenarios. Additionally, it provides a framework of coordination and cooperation processes between public and private entities for joint emergency planning, preparedness and response activities. The Training and Education Division (TED), National Integration Center, Federal Emergency Management Agency, U.S. Department of Homeland Security TED provides grants to states and local jurisdictions, including hands-on training through a number of residential training facilities and in-service training at the local level, funding and working with state and local jurisdictions to plan and execute exercises, and providing technical assistance on-site to state and local jurisdictions. Some of the TED grants are for the private sector, as well. Formerly known as the Office of Grants and Training (G&T). Protective Security Advisor (PSA), The Protective Security Coordination Division, U.S. Department of Homeland Security PSA professionals bring a wealth of anti-terrorism and security experience for critical infrastructure protection and are assigned to each state to assist governmental agencies, businesses, and non-profit organizations. The PSA professional will assist in vulnerability assessment, risk analysis, security practices, and as a liaison to the U.S. Department
106
Additional Resources
of Homeland Security. To locate a PSA professional, contact your state homeland security department or call the PSA Duty Desk, Risk Management Division at (703) 235-5724. ReadyBusiness.Gov, U.S. Department of Homeland Security This Internet based federal service is designed specifically for the business community. It outlines commonsense measures business owners and managers can take to start getting ready. It provides practical steps and easyto-use templates to help you plan for your company's future. These recommendations reflect the Emergency Preparedness and Business Continuity Standard (NFPA 1600) developed by the National Fire Protection Association and endorsed by the American National Standards Institute and the Department of Homeland Security. It also provides useful links to resources providing more detailed business continuity and disaster preparedness information. U.S. Federal Emergency Management Agency (FEMA) FEMA is a federal government agency charged with managing the national response to terrorist incidents, man-made crises, and natural disasters. FEMA has a section devoted to assisting the business community.
107
Additional Resources
Emergency Management Guide for Business and Industry | PDF | Federal Emergency Management Agency (FEMA) This 67-page guide provides step-by-step advice on how to create and maintain a comprehensive emergency management program. It can be used by manufacturers, corporate offices, retailers, utilities, or any organization where a sizable number of people work or gather, and the concepts are applicable whether the company is large or small. Emergency Response Guidebook (ERG), 2004 Edition The ERG was developed jointly by the US Department of Transportation, Transport Canada, and the Secretariat of Communications and Transportation of Mexico (SCT) for use by firefighters, police, and other emergency services personnel who may be the first to arrive at the scene of a transportation incident involving a hazardous material. It is primarily a guide to aid first responders in (1) quickly identifying the specific or generic classification of the material(s) involved in the incident, and (2) protecting themselves and the general public during this initial response phase of the incident. This information is applicable to the private sector. Engaging the Private Sector to Promote Homeland Security: Law EnforcementPrivate Security Partnerships | PDF | U.S. Bureau of Justice Assistance This publication focuses on various partnership issues, local and regional programs and initiatives, state and local programs, federal programs, and additional resources. Federal Food and Agriculture Decontamination and Disposal and Disposal Roles and Responsibilities | PDF | U.S. Environmental Protection Agency Under the provisions of HSPD-9, this document describes federal roles and responsibilities for decontamination and disposal in response to animal, crop, and food incidents. The roles are described at the local, state, and national level. Homeland Security: Effective Regional Coordination can Enhance Preparedness | PDF | U.S. Government Accountability Office, Report #GAO-04-1009 This 46-page document provides guidelines on regional coordination, strategic planning, profiles of some federal programs on incentives for regional coordination, and case study on the National Capital Region program. Insurance, Finance, and Regulation Primer for Terrorism Risk Management in Buildings (December 2003), Federal Emergency Management Agency (FEMA) Although this document is a few years old, the 234-page publication goes into extensive detail on insurance and terrorism risk, finance and terrorism risk, building regulation and terrorism risk, due diligence: estimating vulnerability, and other resources. National Infrastructure Protection Plan (NIPP) | PDF | NIPP provides a coordinated approach to critical infrastructure and key resource protection roles and responsibilities for federal, state, local, tribal, and private sector security partners. The NIPP sets national priorities, goals, and requirements for effective distribution of funding and resources which will help ensure that our government, economy, and public services continue in the event of a terrorist attack or other disaster. (January 2006) Or you can access the U.S. Department of Homeland Security web site that provides an executive summary, overview, partnership model, risk management and the full report.
108
Additional Resources
National Policy Summit: Building Private Security / Public Policing Partnerships to Prevent and Respond to Terrorism and Public Disorder | PDF | International Association of Chiefs of Police (IACP) and ASIS International and other Organizations IACP and ASIS partnered with other organizations for a national summit to profile vital issues and provide recommendations to further enhance the relationship between law enforcement and private security. The summit profiled the challenges, along with the benefits to partnerships. Additionally, a number of recommendations were posted. The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets |PDF | U.S. Department of Homeland Security (February 2003) This 96-page document discusses guiding principles, cross sector priorities, securing CI/KR, and related information. Operation Cooperation Guidelines for Partnerships between Law Enforcement and Private Security Organizations, U.S. Bureau of Justice Assistance This program is a national initiative that encourages law enforcement-private security partnerships and discusses how to start a partnership, what makes a partnership successful, types of partnerships, and additional resources. Prepare Prevent Protect: Best Practices in Workplace Security I PDF | South Carolina Department of Labor, Licensing and Regulation This 47-page document is known as one of the better, easy to use, with charts, lists and good resource publications to review business security plans, policies, and procedures. This guide is for the small to large employer and discusses risk assessment and management, workplace security, crisis management, evacuations, and offers sample plans, as well. Protecting Building Environments from Airborne Chemical, Biological, and Radiological Attacks | PDF | National Institute for Occupational Safety and Health This 40-page report identifies actions that can enhance occupant protection, and includes recommendations, physical security, ventilation and filtration, maintenance, administration, and training. The Public Transportation System Security and Emergency Preparedness Guide | PDF | U.S. Department of Transportation This 195-page guide focuses on the transportation industry, but it nevertheless is a good resource for the emergency planning process, capabilities process, reducing threats and vulnerabilities, training and exercising, scenarios, checklists, tables, and more. Report of the Critical Infrastructure Task Force | PDF | U.S. Homeland Security Advisory Council (January 2006) This report is considered to be one of the first substantive efforts in critical infrastructure thinking since publication of a 1996 document on the same subject within the federal government. It includes recommendations, strategic guidance, governance, information sharing, and supporting information. Seven Signs of Terrorism (video), Michigan State Police, Emergency Management and Homeland Security Division and Homeland Responder This is an excellent video for
109
Additional Resources
employee and citizen awareness. To view the video, you can watch it at the Homeland Responder web site. To obtain a free copy, contact the Michigan State Police at (517) 336-6198. Site Emergency Planning Workbook | PDF | Michigan State Police, Emergency Management and Homeland Security Division This 95-page manual provides a structured framework for developing a site emergency plan. The manual provides processes for hazards analysis, capability assessments, records preservation, and an extensive, practical sample site emergency plan. Standing Together: An Emergency Planning Guide for Americas Communities | PDF | Joint Commission on Accreditation of Healthcare Organizations This 114-page publication provides information on risks, preparedness, response, integration, sustainability, communication, coordination, mental health, vulnerable populations, and more. U.S. Homeland Security Presidential Directive #5 (February 28, 2003) To enhance the ability of the United States to manage domestic incidents by establishing a single, comprehensive national incident management system. U.S. Homeland Security Presidential Directive #7 (December 17, 2003) This directive establishes a national policy for Federal departments and agencies to identify and prioritize United States critical infrastructure and key resources and to protect them from terrorist attacks. U.S. Homeland Security Presidential Directive # 8 (December 17, 2003) This directive establishes policies to strengthen the preparedness of the United States to prevent and respond to threatened or actual domestic terrorist attacks, major disasters, and other emergencies by requiring a national domestic all-hazards preparedness goal, establishing mechanisms for improved delivery of Federal preparedness assistance to State and local governments, and outlining actions to strengthen preparedness capabilities of Federal, State, and local entities. U.S. Homeland Security Presidential Directive # 9 (January 30, 2004) This directive establishes a national policy to defend the agriculture and food system against terrorist attacks, major disasters, and other emergencies. Virginia Business Emergency Survival Toolkit, State of Virginia This Web site is easy to use, provides clear instructions, and helps with strategic planning for emergencies. It explains types of emergencies and the problems they pose; gives information on how to prepare for them and how to recover from them; and helps put it all together in an emergency preparedness plan. Vulnerability of Concentrated Critical Infrastructure: Background and Policy Options | PDF | CRS Report for Congress, Report #RL33206 This report focuses on the grouping of critical infrastructure in geographical areas that can create a vulnerability and exposure to disasters and man-made incidents. It discusses legislation to prevent future concentrations of CI/KR development, along with policy options. (January 26, 2007)
110
Additional Resources
111
Additional Resources
Extension Disaster Education Network (EDEN) The EDEN links Extension educators from across the U.S. and various disciplines, enabling them to use and share resources to reduce the impact of disasters. This site serves primarily Extension agents and educators by providing them access to resources on disaster mitigation, preparedness, response, and recovery that will enhance their short- and long-term programming efforts. Homeland Security Institute (HSI) HSI is a Studies and Analysis Federally Funded Research and Development Center. HSI delivers independent and objective analyses and advises in core areas important to its sponsor in support of policy development, decision-making, analysis of alternative approaches, and evaluation of new ideas on issues of significance. In addition to all the services, resources they provide, HIS also publishes an on-line newsletter which is informative, educational, and applicable to critical infrastructure protection. It offers the Journal of Homeland Security. The Infrastructure Security Partnership (TISP) TISP is a national public-private partnership organization that promotes collaboration to improve the resilience of the nation's critical infrastructure against the adverse impacts of natural and man-made disasters. TISP members, representing the design, construction, operation, and maintenance communities; local, state, and federal agencies; academe; and other organizations concerned about disaster preparedness, work together to develop and implement cost-effective solutions to enhance the resilience of the nation's critical infrastructure by leveraging their collective resources, experience, technical expertise, research and development capabilities, and knowledge of public policy regarding natural and manmade disasters. Regional Disaster Resilience: A Guide for Developing an Action Plan | PDF | This is a resource that goes into detail on developing regional disaster resilience, and discusses interdependencies, risk assessment, response, recovery, supply chain, exercising, and more. The information is applicable to CI/KR protection. (June 2006) Institute for Business and Home Safety (IBHS) The Institute for Business & Home Safetys mission is to reduce the social and economic effects of natural disasters and other property losses by conducting research and advocating improved construction, maintenance, and preparation practices. Open for Business: A Disaster Planning Toolkit for the Small to the Mid-sized Business Owner | PDF | This 47-page publication provides a self-assessment process, how to protect critical business resources, and building a business continuity plan, along with a variety of forms and checklists for preparation, response, and recovery activities. Mega-Shelters: A Best Practices for Planning, Activation, Operations | PDF | The International Association of Assembly Managers (IAAM) IAAM has published guidelines in response to disasters caused by hurricanes and to help facility managers understand the activation process, shelter standards, contracting, liability exposure, and how to plan for the next storm. Memorial Institute for the Prevention of Terrorism (MIPT) MIPT is a non-profit, nationally recognized think tank of state-of-the-art knowledge bases and information sharing on terrorism.
112
Additional Resources
MIPT offers the terrorism knowledge base, terrorism information center, responder knowledge base, and the lessons learned information sharing program services. This web site, which is for public and private sector professionals, also provides the ability for individuals to discuss relevant matters on emergency preparedness response, recovery, and mitigation. National Cyber-Forensics and Training Alliance (NCFTA) NCFTA provides a neutral collaborative venue where critical confidential information about cyber incidents can be shared discreetly, and where resources can be shared among industry, academia and law enforcement. NCFTA facilitates advanced training, promotes security awareness to reduce cyber-vulnerability, and conducts forensic and predictive analysis and lab simulations. The National Fire Protection Association (NFPA) The mission of the international nonprofit NFPA is to reduce fires and other hazards by providing codes and standards, research, training, and education. NFPA focuses on fire prevention and public safety. NFPA1600 Disaster / Emergency Management and Business Continuity Programs The National Fire Protection Association (NFPA) released their 2007 edition of the NFPA1600 Standard. This resource is for those with responsibility for disaster, emergency management, and business continuity programs to assess or develop, implement, and maintain a program to mitigate, prepare for, respond to, and recover from disasters and emergencies. National Voluntary Organizations Active in Disaster (NVOAD) NVOAD coordinates planning efforts by many voluntary organizations responding to disaster. Member organizations provide more effective and less duplication in service by getting together before disasters strike. Once disasters occur, NVOAD or an affiliated state VOAD encourages members and other voluntary agencies to convene on site. This cooperative effort has proven to be the most effective way for a wide variety of volunteers and organizations to work together in a crisis. Overseas Security Advisory Council (OSAC) OSAC is a Federal Advisory Committee with a U.S. Government Charter to promote security cooperation between American business and private sector interests worldwide and the U.S. Department of State. OSAC currently encompasses the 34 member core Council, an Executive Office, over 100 Country Councils, and more than 3,500 constituent member organizations and 372 associates.
113
Additional Resources
Innovators in Supply Chain Security: Better Security Drives Business Value | PDF | The Manufacture Institute and Stanford University The goal of the study was to help companies understand the business value of supply chain security investments by identifying collateral benefits security initiatives can bring to companies, and whenever possible quantifying the level of benefits that can be realized. The study was based on inputs from eleven manufacturers and three Logistics Service Providers (LSPs) that are considered innovators in supply chain security, and clearly demonstrated that investments in supply chain security can provide business value. The National Homeland Security Knowledgebase, Homeland Security Defense Corporation The National Homeland Security Knowledgebase is a database that offers comprehensive Homeland Security information resources, Homeland Security news, Homeland Security Newsletter, Homeland Security research, Homeland Security technology sectors, Homeland Security marketplace, directories, trade shows and a collection of links on Homeland Security related topics as well as links and info relating to global security issues.
114