4
Operaons & Engineering eNewsleer February 19, 2016 A Publicaon for AGA Members Recommendations for Defending Industrial Control System Networks Recent open-source reports have circulated alleging that a December 23, 2015, power outage in Ukraine was enabled by the BlackEnergy Malware. The U.S. Department of Homeland Security (DHS) Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) is coordinang with the Ukraine CERT and internaonal partners to analyze the cause of the outage and a possible BlackEnergy link. DHS Assistant Secretary for Infrastructure Protecon Caitlin Durkovich and representaves from ICS-CERT provided an unclassified briefing of the ongoing invesgaon to the AGA Board of Directors this week. AGA would like to remind members to be diligent and make use of the following migaon recommendaons and technical indicators provided by DHS to aide in your computer network defense efforts: 1. Seven Steps to Effecvely Defend Industrial Control Systems: This paper presents seven strategies that can be implemented today to counter common exploitable weaknesses in “as-built” control systems. 2. ICS-CERT Recommended Pracces: This page lists recommended pracces for securing industrial control systems, including defense-in-depth strategies, incident response plans, cross-site scripng, patch management, and secure remote access. 3. YARA: Detecon of BlackEnergy malware should be conducted using the latest published YARA signature. The latest signatures can be downloaded at GitHub. The BlackEnergy campaign has been ongoing since at least 2011 and has been used to compromise mulple industrial control system environments. For more informaon on the BlackEnergy campaign, please see ICS-ALERT-14-281-01E. Members of the Downstream Natural Gas Informaon Sharing and Analysis Center (DNG ISAC) are strongly encouraged to log on to the portal and view the latest trend analysis provided by the DNG ISAC. Quesons, contact Rebecca Massello, [email protected]. State Regulators Confirm that the Aliso Canyon Well is Permanently Sealed AGA, the Interstate Natural Gas Associaon of America (INGAA), and the American Petroleum Instute (API) have jointly released several documents on the importance of underground natural gas storage, the industry recommended pracces that have been developed for underground natural gas storage, and underground natural gas storage facts and figures. These documents help to highlight the importance of underground natural gas storage in providing consumers with reliable service and answer quesons surrounding underground natural gas storage. The three trade associaons will connue to coordinate on communicaon and educaonal materials through a Joint Industry Task Force. If you have any quesons, please contact Rebecca Massello, [email protected]. Please refer to SoCal Gas’s website on Aliso Canyon for the latest updates: www.alisoupdates.com/main. The Importance of Underground Natural Gas Storage AGA, INGAA, and API have jointly released a brochure communicang the importance of underground natural gas storage in providing consumers with reliable service. The three trades will connue to coordinate on communicaon materials through a Joint Industry Task Force. AGA Board Revises AGA’s Commitment to Enhancing Safety Earlier this week, the AGA Board revised the AGA Commitment to Enhancing Safety to promote the use of API Recommended Pracce 1170, Design and Operaon of Soluon-mined Salt Caverns Used for Natural Gas Storage, and API Recommended Pracce 1171, Funconal Integrity of Natural Gas Storage in Depleted Hydrocarbon Reservoirs and Aquifer Reservoirs . AGA and its members were acve parcipants in the development of both recommended pracces.

Operations & Engineering eNewsletter - aga.org · Please refer to Soal Gas’s website on Aliso anyon for the latest updates: ... Regulators, pipeline operators, and service providers

  • Upload
    hatuong

  • View
    217

  • Download
    0

Embed Size (px)

Citation preview

Operations & Engineering eNewsletter

February 19, 2016 A Publication for AGA Members

Recommendations for Defending Industrial Control System Networks

Recent open-source reports have circulated alleging that a December 23, 2015, power outage in Ukraine was enabled by the BlackEnergy Malware. The U.S. Department of Homeland Security (DHS) Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) is coordinating with the Ukraine CERT and international partners to analyze the cause of the outage and a possible BlackEnergy link. DHS Assistant Secretary for Infrastructure Protection Caitlin Durkovich and representatives from ICS-CERT provided an unclassified briefing of the ongoing investigation to the AGA Board of Directors this week.

AGA would like to remind members to be diligent and make use of the following mitigation recommendations and technical indicators provided by DHS to aide in your computer network defense efforts:

1. Seven Steps to Effectively Defend Industrial Control Systems: This paper presents seven strategies that can be implemented today to counter common exploitable weaknesses in “as-built” control systems.

2. ICS-CERT Recommended Practices: This page lists recommended practices for securing industrial control systems, including defense-in-depth strategies, incident response plans, cross-site scripting, patch management, and secure remote access.

3. YARA: Detection of BlackEnergy malware should be conducted using the latest published YARA signature. The latest signatures can be downloaded at GitHub.

The BlackEnergy campaign has been ongoing since at least 2011 and has been used to compromise multiple industrial control system environments. For more information on the BlackEnergy campaign, please see ICS-ALERT-14-281-01E.

Members of the Downstream Natural Gas Information Sharing and Analysis Center (DNG ISAC) are strongly encouraged to log on to the portal and view the latest trend analysis provided by the DNG ISAC. Questions, contact Rebecca Massello, [email protected].

State Regulators Confirm that the Aliso Canyon Well is Permanently Sealed AGA, the Interstate Natural Gas Association of America (INGAA), and the American Petroleum Institute (API) have jointly released several documents on the importance of underground natural gas storage, the industry recommended practices that have been developed for underground natural gas storage, and underground natural gas storage facts and figures. These documents help to highlight the importance of underground natural gas storage in providing consumers with reliable service and answer questions surrounding underground natural gas storage. The three trade associations will continue to coordinate on communication and educational materials through a Joint Industry Task Force. If you have any questions, please contact Rebecca Massello, [email protected].

Please refer to SoCal Gas’s website on Aliso Canyon for the latest updates: www.alisoupdates.com/main.

The Importance of Underground Natural Gas Storage AGA, INGAA, and API have jointly released a brochure communicating the importance of underground natural gas storage in providing consumers with reliable service. The three trades will continue to coordinate on communication materials through a Joint Industry Task Force.

AGA Board Revises AGA’s Commitment to Enhancing Safety Earlier this week, the AGA Board revised the AGA Commitment to Enhancing Safety to promote the use of API Recommended Practice 1170, Design and Operation of Solution-mined Salt Caverns Used for Natural Gas Storage, and API Recommended Practice 1171, Functional Integrity of Natural Gas Storage in Depleted Hydrocarbon Reservoirs and Aquifer Reservoirs. AGA and its members were active participants in the development of both recommended practices.

Register for AGA’s PSMS Workshop The program agenda for AGA’s Pipeline Safety Management Systems Workshop is now available on the event webpage. Featuring presentations and case studies from pipeline operators, regulators and service providers, this workshop will include discussions on key issues such as implementation strategies to regulatory expectations. Regulators, pipeline operators, and service providers are all invited to participate in this forum. The workshop will begin at 8AM on Tuesday, March 1 and adjourn before noon on Wednesday, March 2. This will be followed by an operator only roundtable session from 1:00PM-4:45PM. This roundtable session will give operators the chance to discuss the presentations from the workshop and to discuss their plans for implantation of the PSMS. Visit the event page at AGA.org today for online registration and hotel information. For more information, please contact Kate Miller [email protected]

AGA/DCA Utility Contractor Workshop

On April 4-6, 2016, the Distribution Contractors Association (DCA) and American Gas Association (AGA) will conduct the third annual workshop aimed at increasing communication and cooperation between gas distribution utilities and the contractors who work for them. Last year’s workshop attracted more than 140 attendees representing gas utilities, contractors, manufacturers, labor unions, industry experts and government.

The workshop will include panel discussion and breakouts dealing with a wide range of important topics such as workforce development, operator qualification and portability, PHMSA post inspection rule, HDD training, education and best practices. Be part of the discussion! Visit the DCA website today for online registration, hotel information and a preliminary program agenda. The registration and housing deadline is Thursday, March 10. If you have any questions regarding registration or hotel accommodations, please contact the DCA office on (972) 680-0261.

EPA Provides Additional Information on Methane Challenge Participation for Distribution Companies On February 18, 2016, EPA held a webinar to discuss the Methane Challenge best management practice (BMP) commitments for the distribution sector. EPA’s Methane Challenge allows oil and gas companies to make voluntary commitments to reduce methane emissions and be recognized for their progress. During the webinar, EPA provided details on the BMP options available for distribution emission sources, which include pipeline blowdowns, mains, cast iron and unprotected steel services, and cast iron and unprotected steel and excavation damage. EPA will post the presentation slides from the webinar on its website. EPA is also participating in a conference call with AGA members on Monday, February 22 to discuss the program.

AGA encourages members to consider participating in this program. A launch event for founding partners of Methane Challenge will be held on March 30. Please contact Pam Lacey, [email protected] or Christine Wyman, [email protected] for more information on the Methane Challenge program.

FWS Publishes Final Rule Regarding Eagle Permits The Department of Interior Fish and Wildlife Service (FWS) has published a final rule to remove provisions of regulations governing eagle non-purposeful take permits that extended the maximum term of programmatic permits to 30 years. The rule is being issued to comply with a court order that had the effect of vacating these provisions. The rule removes regulatory provisions that extended maximum programmatic permit duration to 30 years and reinstates the previous 5-year limit. For more information, please contact Pam Lacey, [email protected].

Odorization Manual Revision Update

CenterPoint Energy hosted AGA's Odorization Manual Revision Group (OMRG) this week in Houston. The OMRG is made up of 30+ subject matter experts representing distribution companies, odorant manufacturers, odorant dispensing and servicing industry vendors as well as independent consultants. During their meeting, the group reviewed the more than 500 comments received on the first revision draft of the manual that was distributed amongst Operations Section Technical Committees. The next steps for the group will include developing the next draft for distribution to the Operations Section Managing Committee. AGA will also seek comments from PHMSA and NAPSR. For more information about this and other AGA publications, please contact Ali Quraishi, [email protected].

AGA 2016 Operations Conference

Registration is open now for AGA’s 2016 Operations Conference. Join your colleagues at North America's premier technical forum of natural gas utility and pipeline operations management from across the continent and around the world. Featuring a conference program developed by operators and for operators, it's no surprise this important industry gathering continues to break attendance records!

Visit the event page at AGA.org for registration, hotel information and a preliminary program and sponsorship opportunities. Bookmark the page and check back soon for Technical Committee Agendas, mobile app download links and other event news and updates.

AGA Operations Section Spring Committee Meetings - April 18-19: The AGA Operations Section Spring Committee

Meetings will take place from Monday, April 18 to Tuesday, April 19, in conjunction with the 2016 Operations

Conference. Check with AGA committee staff executives for exact schedule details before you make travel arrangements.

CLICK HERE for preliminary technical committee agendas.

How Many Engineers Does it Take to Build a Bike? Since 2010, we’ve kicked off the Operations

Conference week by giving back to the communities we serve. This year we are proud to be partnering

once again with Bikes for Goodness Sake to help them in their mission of providing bikes to

underprivileged children in the community. This is a very special project designed to challenge the

engineer in everyone! Last year’s teams finished in record time. Can you beat them? Can you beat your

colleagues? Can you get the handlebars on the right way? (I’m looking at you Team AGA!!!) Join us onsite at the Biltmore on

Sunday, April 17 to find out. What will be a fun morning for us, will mean so much more to the children who will benefit from

our work. Sign up for this when you register, or contact Annemarie O’Donoghue ([email protected]) to update your

registration and let her know your t-shirt size.

Sponsorship Opportunities available for this event can be viewed online at AGA.org. In addition to lending your name to

this highly visible event, sponsors will have advance access to attendee lists. For additional sponsorship information, contact

Annemarie O'Donoghue at [email protected] or 202-824-7032.

Questions? For registration or sponsorship, please contact Annemarie O’Donoghue, [email protected]. For questions about the Conference program or other related topics, please contact Debbie Ellis, [email protected].

Thank you to our 2016 Confirmed Sponsors

Calendar

Discussion Groups Discussion groups are open to all AGA full & limited

members ONLY. Surveys & Data Requests

Due Feb 19: Backfill & Trench Standards

Due Feb 22: Safety Management Systems

Due Feb 29: Electrofusion QA/QC

Due Feb 29: Can't Get In / Can't Gain Access

Due Mar 1: Meter Data Collection Reliability

Available Now

For Summaries of Responses to SOS Surveys, log on to aga.org to view our searchable list of SOS summaries covering a wide range of operations related topics. If you do not already have an AGA password, or you need to reset your existing password, please click here first.

Updated! February 2016 Pipeline Safety Regulatory Update provides AGA members with the most up-to-date information we have on pending pipeline safety regulations and information collection requests from the Pipeline and Hazardous Material Association (PHMSA). It also includes notes on AGA's position, concerns, etc. on various pieces of rulemaking as well as links to internal and external resources relating to each area. Erin Kurilla

Natural Gas Market Indicators - summarizing recent developments in natural gas pricing, heating and cooling degree days statistics, underground storage, domestic gas production, rig counts, pipeline imports and exports, and international LNG issues. Contact Chris McGill or Richard Meyer.

March

1-2: Pipeline Safety Management Systems (PSMS) Workshop. Dallas, TX. Contact Kate Miller

8-10: AGA/EEI Spring Security Meetings and Joint Security Conference. Louisville, KY. Contact Kimberly Denbow

9-11: AGA Next Level Leadership Women’s Program. Washington, DC. Contact Ysabel Suarez

14-16: Gas Piping Technology Committee (GPTC) Meeting, San Antonio, TX. Contact Mike Bellman

April

4-6: AGA/DCA Utility Contractor Workshop. Chicago, IL. Contact Andrew Lu

5-6: AGA/SPE Underground Storage Operators Workshop. Evansville, IN. Contact Rebecca Massello

18-19: AGA Operations Section Spring Technical Committee Meetings. Phoenix, AZ. Contact Debbie Ellis

19-22: AGA Operations Conference. Phoenix, AZ. Contact Debbie Ellis

Member Surveys, Summaries & Updates

This document has been prepared by the American Gas Association for members. In issuing and making this publication available, AGA is not undertaking to render professional or other services for or on behalf of any person or entity. Nor is AGA undertaking to perform any duty owed by any person or entity to someone else. The statements in this publication are for general information only and it does not provide a legal opinion or legal advice for any purpose. Information on the topics covered by this publication may be available from other sources, which the user may wish to consult for additional views or information not covered by this publication.

© Copyright 2015 American Gas Association. All Rights Reserved. www.aga.org

AGA’s Operations Discussion Groups are an opportunity for

member companies to come together to address the

operational challenges. All Discussion Groups are scheduled

for 2PM EST.

Mar 8: Pipeline Safety, Compliance, Oversight. Betsy Tansey

Mar 10: Emergency Preparedness & Public Awareness.

Vanessa George

TBA: GIS/GPS and Work Management Systems. Junaid Faruq

TBA: Damage Prevention. Kofi Woodley

TBA: Compressor Operations. Erin Kurilla

TBA: Pipeline Safety Management Systems. Kate Miller

TBA: Technical Training. Andrew Lu

TBA: TIMP Risk Models. Erin Kurilla

For Discussion Group information and links to each Group

website, please CLICK HERE.