ellen_messmer
Senior Editor, Network World

The long road to security

News
Apr 25, 20055 mins

In the wake of the Sept. 11 terrorist attacks, the federal government met with chemical manufacturers and industry trade groups to discuss developing a plan to protect against physical or network-related attacks. This meeting led to the creation of the Chemical Sector Cybersecurity Program, which seeks to unite the highly diverse $450 billion chemicals industry – an employer of more than 1 million people and producer of more than 70,000 products – with one protective strategy. Christine Adams, IT staff member at Dow Chemical and director of the Chemical Sector Cybersecurity Program, recently talked with Network World Senior Editor Ellen Messmer about the program.

How did this voluntary effort get started?

Dow Chemical was approached by [then Presidential adviser] Richard Clarke at the White House to discuss the government’s expectations for cybersecurity. The CIO of Dow and the CIO of DuPont agreed to initiate an organization on behalf of the industry to improve the industry’s cybersecurity. We crafted a very high-level strategy in 2002 with help from the Chemical Industry Data Exchange [CIDX], the trade association for e-commerce standards for the chemical industry’s supply chain. Some of the same CIOs that formed CIDX also formed the cybersecurity program.

CIDX last December published “Guidance for Addressing Cybersecurity in the Chemical Sector,” a 100-page document on planning network security for corporate LANs and databases, as well as factory and supervisory control and data acquisition systems. What’s happening with this?

We have the document to offer to industry, and we’re telling the chemical companies they need to implement this cybersecurity-management policy. It’s based on the international standard ISO 17799, an excellent framework. In 2003, we conducted an extensive assessment based on ISO 17799, with help from IBM, for 14 of our leading chemical companies. The Guidance document involves how to conduct vulnerability assessment in IT and process control systems. We also have the American Chemistry Council’s Responsible Care Program for safe handling of chemical products, which was invented after [Sept. 11].

The Guidance doesn’t seem to be a mandate that the chemical companies have to follow.

It’s deliberately not a prescription because all the companies have different IT infrastructures.

So what’s expected going forward?

Trading of chemicals is now done a lot through e-marketplaces. Our focus is taking all the excellent work that CIDX has done and working with each of the trading associations to produce cybersecurity programs for their members.

What have been the biggest obstacles?

One is information sharing. It’s a cultural change for our industry to share a lot of detailed information. We never saw until now a need to share this kind of information. But we’re not unique to other sectors – we all use similar products, enterprise systems, desktop computing. We’re mostly getting hit with the same thing. The large companies contract with suppliers to watch for these attacks and help patch our systems. This year we’re doing a study on the most effective ways to share information with ourselves and the government. We’ve not yet come to a clear conclusion.

What’s the relationship with the Chemical Sector Cybersecurity Program and the Chemical Industry Information Sharing & Analysis Center? [Chem-ISAC was formed in 2002 by the Chemical Transportation Emergency Center and the National Infrastructure Protection Center, which became part of the Department of Homeland Security.]

We’re working closely with the team of people in the chemical sector ISAC. We’re also working with the DHS. For one thing, we’re working on the piloted Homeland Security Information Network. It’s a secure network used for discussion, similar to what we have in the ISAC. We’re focusing first on the physical world and anything that looks suspicious. We’re working with government to define potential types of attacks as an individual sector and as a coordinated sector, and what we need to be doing in our sectors. There can be different impacts of a cyberattack – danger to people, public health or a significant economic impact. Some people feel terrorists are just as happy destroying the economy as destroying people.

How would a cyberattack affect the chemical industry?

Short of a massive telecommunication outage, it would be difficult to have a catastrophe across the chemical industry because we aren’t connected in the way that the electric power industry might be. But there could be major interruptions to customers.

There’s a trend in the process-control system environment where we used to use proprietary software, but we’ve begun replacing that with third-party off-the-shelf software, including open systems platforms. We’re introducing a whole new set of vulnerabilities to the process-control world.

Gettingpersonal Christine Adams
Organization: Dow Chemical
Title:Director of Chemical Sector Cybersecurity Program, an industry organization formed by CIOs from Chemical, Eastman Chemical Company, DuPont De Nemours & Co., Celanese and Rohm & Hass.
Job history :Joined Dow Chemical in 1975 in business information systems in its Louisiana division; in 1977 became IS manager for Dow’s global Emulsion Polymers business.
Cybersecurity Program staff:The program uses the staff of the American Chemistry Counsel for administrative operations and legal counsel, and members of the CIO Executive Board dedicate some of their employees to the program on a volunteer basis to provide subject matter expertise and leadership on key initiatives.
Background:Born in White Castle, La., a sugarcane farming community with a population of less than 1,000 people. She received her undergraduate degree from Nicholls State University in Thibodaux, also known as the “Harvard of the Bayou.”
Fun facts:Thirty years ago, she was selected as the Louisiana State Sugar Queen. She prefaces this with “I was very young, and the contest didn’t involve a swimsuit competition.”