Large Constellations of Satellites: Mitigating Environmental and Other Effects

There are almost 5,500 active satellites in orbit as of spring 2022, and one estimate predicts the launch of an additional 58,000 by 2030. Large constellations of satellites in low Earth orbit are the primary drivers of the increase. Satellites provide important services, but there are potential environmental and other effects that this trend could produce (see figure).

Potential effects from the launch, operation, and disposal of satellites

For decades, satellites have been used for GPS, communications, and remote sensing. The number of satellites has recently increased, as thousands more have been launched to provide internet access.

But this increase may be disruptive. For example, it could lead to more space debris, which can damage existing satellites used for commerce or national security. We reviewed technologies and other tools to lessen potential effects. We also looked at mitigation challenges, like unclear rules and immature technology. To help address the challenges, we developed policy options, which may help policymakers achieve a variety of goals.

GAO assessed technologies and approaches to evaluate and mitigate the following potential effects:

- Increase in orbital debris. Debris in space can damage or destroy satellites, affecting commercial services, scientific observation, and national security. Better characterizing debris, increasing adherence to operational guidelines, and removing debris are among the possible mitigations, but achieving these is challenging.
- Emissions into the upper atmosphere. Rocket launches and satellite reentries produce particles and gases that can affect atmospheric temperatures and deplete the ozone layer. Limiting use of rocket engines that produce certain harmful emissions could mitigate the effects. However, the size and significance of these effects are poorly understood due to a lack of observational data, and it is not yet clear if mitigation is warranted.
- Disruption of astronomy. Satellites can reflect sunlight and transmit radio signals that obstruct observations of natural phenomena. Satellite operators and astronomers are beginning to explore ways of mitigating these effects with technologies to darken satellites, and with tools to help astronomers avoid or filter out light reflections or radio transmissions. However, the efficacy of these techniques remains in question, and astronomers need more data about the satellites to improve mitigations.

GAO developed the following policy options to help address challenges with evaluating and mitigating the effects of large constellations of satellites. GAO developed the options by reviewing literature and documents, conducting interviews, and convening a 2-day meeting with 15 experts from government, industry, and academia. These policy options are not recommendations. GAO presents them to help policymakers consider and choose options appropriate to the goals they hope to achieve. Policymakers may include legislative bodies, government agencies, standards-setting organizations, industry, and other groups.

Policymakers may be better positioned to take action on this complex issue if they consider interrelationships among these policy options. For example, implementing the fourth option (improving organization and leadership) may improve policymakers’ ability to implement the first and second options (building knowledge, developing technologies, and improving data sharing). Similarly, implementing the first option may help with the third option (establishing standards, regulations, and agreements). More generally, trade-offs between mitigations may emerge, the ongoing increase in new constellations may introduce unexpected changes, and a large and diverse set of interests from the global community may shift over time, all of which present persistent uncertainties. To address these complexities and uncertainties, the full report presents the policy options in a framework, which may help policymakers strategically choose options to both realize the benefits and mitigate the potential effects of large constellations of satellites.

Enabled by declines in the costs of satellites and rocket launches, commercial enterprises are deploying large constellations of satellites into low Earth orbit. Satellites provide important data and services, such as communications, internet access, Earth observation, and technologies like GPS that provide positioning, navigation, and timing. However, the launch, operation, and disposal of an increasing number of satellites could cause or increase several potential effects.

This report discusses (1) the potential environmental or other effects of large constellations of satellites; (2) the current or emerging technologies and approaches to evaluate or mitigate these effects, along with challenges to developing or implementing these technologies and approaches; and (3) policy options that might help address these challenges.

To conduct this technology assessment, GAO reviewed technical studies, agency documents, and other key reports; interviewed government officials, industry representatives, and researchers; and convened a 2-day meeting of 15 experts from government, industry, academia, and a federally funded research and development center. GAO is identifying policy options in this report.

Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization

CISA, the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have released a joint Cybersecurity Advisory (CSA), Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization, highlighting advanced persistent threat (APT) activity observed on a Defense Industrial Base (DIB) Sector organization’s enterprise network. ATP actors used the open-source toolkit, Impacket, to gain a foothold within the environment and data exfiltration tool, CovalentStealer, to steal the victim’s sensitive data.

Joint Cybersecurity Advisory AA22-277A provides the APT actors tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs). CISA, FBI, and NSA recommend DIB sector and other critical infrastructure organizations implement the mitigations in this CSA to ensure they are managing and reducing the impact of APT cyber threats to their networks.

UNOCT launches five new thematic guides on Protecting Vulnerable Targets Against Terrorist Attacks

The United Nations Office of Counter-Terrorism (UNOCT) hosted a high-level virtual event to launch five new specialized guides (modules) dedicated to the protection of particularly vulnerable targets against terrorist attacks, on 6 September 2022. “Vulnerable targets” refers to public places (e.g. tourist venues, urban centers, religious sites) or critical infrastructure (e.g. public transportation systems, energy sector) which are easily accessible and relatively unprotected, and therefore vulnerable to terrorist attacks.

The online launch event was opened by the Under-Secretary-General of the United Nations Office of Counter-Terrorism (UNOCT), Mr. Vladimir Voronkov, along with the Permanent Representative of Qatar to the United Nations, H.E. Ambassador Alya Ahmed Saif Al-Thani; Acting Executive Director of the United Nations Counter-Terrorism Committee Executive Directorate (CTED), Mr. Weixiong Chen; Director of the United Nations Interregional Crime and Justice Institute (UNICRI) Ms. Antonia Marie De Meo; and Chief of Cabinet of the Under-Secretary-General of the United Nations Alliance of Civilizations (UNAOC), Ms. Nihal Saad.

The participants included decision-makers, practitioners and experts on vulnerable targets protection from Member States, international and regional organizations, the private sector, civil society and academia, including members of the United Nations Global Expert Network to Protect Vulnerable Targets against Terrorist Attacks.

The high-level opening was streamed live via UN WebTV. It will be followed by an expert session, during which Member States will share experiences, good practices and tools related to the themes of the five modules:

1. The protection of “soft" targets;
2. The protection of touristic sites;
3. The protection of religious sites and places of worship;
4. The protection of urban centres; and
5. Threats posed by unmanned aircraft systems (UAS) to vulnerable targets.

The 5 modules are published in Arabic, English, French and Russian and are presented by the United Nations Global Programme on Countering Terrorist Threats Against Vulnerable Targets, which is led by UNOCT and jointly implemented with CTED, UNICRI and UNAOC.

The new guides present the knowledge and resources and lessons learned identified during the three Expert Group Meetings held by UNOCT with partners CTED, UNAOC and UNICRI in 2021. They also complement the 2018 United Nations Compendium of Good Practices on the Protection of Critical Infrastructure (CIP) against Terrorist AttacksPDF by focusing on public places/"soft" targets as distinct types of sites worthy of a dedicated security approach. The guides feature specific case studies, good practices and recommended tools from around the world to support both the public and private sectors to further strengthen the safety and security of their public places, keeping them open and accessible and promoting shared responsibility.

New IAEA Safety Guide on Emergency Preparedness and Response for the Transport of Radioactive Material

Historically, emergencies during the transport of radioactive material have had none or very limited radiological consequences, which have been resolved quickly. However, no matter how safe packages for the transport of radioactive material are, emergencies can still occur during transit, for which prompt action is required to ensure that the public and the environment are protected effectively. A newly released IAEA Safety Guide — Specific Safety Guide on Preparedness and Response for a Nuclear or Radiological Emergency Involving the Transport of Radioactive Material — addresses a wide range of possible emergencies, including those associated with very low probability events which might have significant radiological consequences.

"The field of transportation of radioactive material is one where radioactive material is intentionally moved across the public domain. Hence, transport activities involving radioactive material should be carried out in accordance with safety requirements and security guidance,” said Farid Abdelmounim, Senior Engineer at the Centre National de Radioprotection, Ministry of Health, Morocco. “This new guide addresses important emergency preparedness and response (EPR) concepts such as the protection strategy, the concept of operations and the interface with nuclear security. “

This publication, co-sponsored with the International Civil Aviation Organization and the International Maritime Organization, provides recommendations on preparedness and response for a nuclear or radiological emergency involving the transport of radioactive material.
Preparedness and response for transport emergencies

The recommendations in this guide are aimed at countries; “consignors”, who prepare shipments for transport, carriers, who transport them; “consignees”, who receive them; regulatory bodies; and, response organizations.

Each of these roles are vital in emergency preparedness and response and their responsibilities include the following:

governments, for example, should ensure that the responsibilities of national and local government for a transport emergency are clearly defined, and that the national coordinating mechanism for nuclear and radiological emergencies includes the authorities responsible for transport safety and security;

consignors and carriers have the primary responsibility to ensure that adequate emergency arrangements are in place for a given shipment, and that those arrangements follow the national emergency arrangements of all the States relevant to the shipment; and,

carriers should ensure that emergency instructions and information applicable to the consignment are carried with the consignment on the conveyance (road vehicle, train, aircraft or sea vessel) at all times, and that this information is readily available to response organizations in the event of an emergency.

“The main objectives of the publication, and the associated training, are to bring together the emergency preparedness and response community and the transport community, to exchange ideas and experiences including on how best to coordinate and integrate emergency arrangements with safety and security measures in protecting the public and the environment from harmful effects of exposure to ionizing radiation,” said Svetlana Nestoroska Madjunarova, Emergency Preparedness Coordinator at the IAEA’s Incident and Emergency Centre.
Bridging the transport and emergency preparedness and response (EPR) communities

Radioactive material has a wide range of applications, and as a result, millions of packages containing radioactive material are transported every year by rail, road, sea, air or inland waterway. This includes the movement of containers (casks) carrying spent nuclear fuel from operating and decommissioning nuclear reactors and sealed radioactive sources, which are used widely in medicine, industry, and agriculture.

Effective preparedness and response for transport emergencies involving radioactive material is thus a topic that has broad relevance for all countries, irrespective of whether they have a nuclear power programme.

To heighten awareness of this topic, two trainings on the new guide were carried out last year, with at least two more planned for 2022.

“A transport emergency is different than an emergency in a fixed facility. A transport emergency can take place anywhere, in the middle of a busy city, or in a remote location where first responders may be hours away,” said Luis Portugal, Head of the Emergency Preparedness and Response Unit of the Portuguese Environment Agency, who contributed to the development of the training in conjunction with the IAEA. “When we designed the training, we wanted to raise awareness in the emergency preparedness and response community, and the transport safety community, of the particularities of an emergency occurring during the transport of radioactive materials and how these can impact the planning for, and response to, any event,” he added.

“The transport safety regulatory requirements set out in the IAEA Safety Standard Series — SSR-6 (Rev.1) — have benefitted from continuous review and development since they were first introduced in 1961. Complemented by the IAEA safety requirements in the IAEA General Safety Requirements Part 7, they help in effective regulation of transport safety and establishment of effective emergency arrangements during the transport of radioactive material,” said Stephen Whittingham, former Head of the Transport Safety Unit in the Division of Radiation, Transport and Waste Safety. “With this Safety Guide and associated training material supporting the implementation of these two sets of safety requirements, we contribute further to their practical implementation in countries to protect the public and the environment effectively from the harmful effects of ionizing radiation.”

USDA invests more than $698,000 in critical infrastructure to combat climate change

The U.S. Department of Agriculture announced this week that USDA Rural Development will invest more than $698,000 in critical infrastructure to combat climate change across rural Missouri.

Among the funded projects is Macon Coca-Cola Bottling Company's installation of a 46.98 kilowatt solar array system. The company will use a $20,000 Rural Energy for America Program grant to replace 71,831 killowatt hours (100% of the company's energy use) per year, saving the company more than $6,000.

The investments reflect the goals of President Biden’s Inflation Reduction Act, which addresses immediate economic needs and includes the largest ever federal investment in clean energy for the future, the USDA said.

For example, the Act includes $14 billion in funding for USDA programs that support the expansion of biofuels and help rural businesses and electric cooperatives transition to renewable energy and zero-emission systems.

USDA is making these investments through Community Facilities Disaster Grants, Rural Energy for America Program Renewable Energy Systems & Energy Efficiency Improvement Guaranteed Loans & Grants, and Rural Energy for America Program Energy Audits and Renewable Energy Development Grants.

CISA Releases New Insight on Preparing Critical Infrastructure for the Transition to Post-Quantum Cryptography

The Cybersecurity and Infrastructure Security Agency (CISA) released a new CISA Insight, Preparing Critical Infrastructure for Post-Quantum Cryptography, which provides critical infrastructure and government network owners and operators an overview of the potential impacts from quantum computing to National Critical Functions (NCFs) and the recommended actions they should take now to begin preparing for the transition.

While quantum computing promises greater computing speed and power, it also poses new risks to critical infrastructure systems across the 55 NCFs. This CISA Insight incorporates findings from an assessment conducted on quantum vulnerabilities to the NCFs to understand the urgent vulnerabilities and NCFs that are most important to address first and the three NCF areas to prioritize for public-private engagement and collaboration.

“While post-quantum computing is expected to produce significant benefits, we must take action now to manage potential risks, including the ability to break public key encryption that U.S. networks rely on to secure sensitive information,” said Mona Harrington, acting Assistant Director National Risk Management Center, CISA. “Critical infrastructure and government leaders must be proactive and begin preparing for the transition to post-quantum cryptography now.”

In March 2021, Secretary of Homeland Security Alejandro N. Mayorkas outlined his vision for cybersecurity resilience and identified the transition to post-quantum encryption as a priority.

To ensure a smooth and efficient transition, CISA encourages all critical infrastructure owners to follow the Post-Quantum Cryptography Roadmap along with the guidance in this CISA Insight. The roadmap includes actionable steps organizations should take, such as conducting an inventory of their current cryptographic technologies, creating acquisition policies regarding post-quantum cryptography, and educating their organization’s workforce about the upcoming transition.

Emergency telecommunications preparedness: Return on investments model

In a world increasingly characterized by uncertainty, emergency preparedness is a powerful way to improve the capacity of communities and countries to withstand disasters. Investment in emergency preparedness builds resilience, thereby limiting the loss of life and protecting infrastructure.

The Emergency Telecommunications Cluster (ETC) has developed a model to assess the benefits of investment in emergency telecommunications preparedness. This will build a pool of evidence to promote preparedness, ultimately encouraging stakeholders to build disaster-resilient telecommunications in high-risk countries across the globe.

The new Return on Investment (ROI) model aims to quantify and qualify the benefits of investments in emergency telecommunications preparedness. It can be used by all humanitarian partners engaged in emergency telecommunications preparedness. It is built on the practical emergency preparedness expertise and experiences of the ETC in different countries.

IOM supports Palau to build community resilience and preparedness to natural hazards

The Republic of Palau is exposed to natural hazards such as storm surges, typhoons, earthquakes, and tsunamis that can result in localized and national emergencies as well as population displacement.

The International Organization for Migration (IOM), in partnership with the National Emergency Management Office (NEMO), has been working closely with the Government of the Republic of Palau (Palau) and community members to prepare for, and respond in a timely manner to, lifesaving needs during natural hazards and shocks.

IOM, under the Palau Emergency Preparedness and Enhanced Resilience project, funded by the United States Agency for International Development’s Bureau of Humanitarian Assistance, engaged the Government of the Republic of Palau, NEMO, Palau Red Cross Society, Ministry of Education, and community members in tabletop exercises to test emergency response plans and procedures and address operational gaps by working closely with relevant authorities.

"Employing a comprehensive approach to disaster risk management requires the contribution and engagement of various government actors as well as community group representatives at all stages of the preparedness, response and recovery process," says Salvatore Sortino, Chief of Mission to IOM Federated States of Micronesia, Republic of the Marshall Islands, and Republic of Palau.

"Tabletop exercises like these are key to ensuring comprehensive understanding and full ownership of respective roles and responsibilities. We are extremely grateful to NEMO for their leadership in these exercises," Sortino added.

IOM together with key government and non-government representatives reviewed Early Warning Processes to improve early warning systems, underlining roles and responsibilities of stakeholders in the event of a natural hazard.

In Melekeok State, where tsunami preparedness systems need strengthening, IOM conducted a tabletop exercise to simulate hazard events and enable coordination on effective use of emergency communication channels, emergency evacuation routes, and school evacuation procedures among other critical aspects of tsunami response.

These tabletop exercises complement ongoing efforts to address critical needs by improving evacuation shelters and their management to minimize injury and loss of life, as well as testing government response structures and pre-positioning relief items.

IOM revamped five emergency evacuation shelters (EES) including the installation of typhoon shutters, and provision of water tanks, generators, and solar lights.

Additionally, through the project, more than 80 community representatives in five states have been trained on EES management, and five water quality management teams have been established and trained.

TSA revises and reissues cybersecurity requirements for pipeline owners and operators

The Transportation Security Administration (TSA) announced the revision and reissuance of its Security Directive regarding oil and natural gas pipeline cybersecurity. This revised directive will continue the effort to build cybersecurity resiliency for the nation’s critical pipelines.

Developed with extensive input from industry stakeholders and federal partners, including the Department’s Cybersecurity and Infrastructure Security Agency (CISA), the reissued security directive for critical pipeline companies follows the directive announced in July 2021. The directive extends cybersecurity requirements for another year, and focuses on performance-based – rather than prescriptive – measures to achieve critical cybersecurity outcomes.

“TSA is committed to keeping the nation’s transportation systems safe from cyberattacks. This revised security directive follows significant collaboration between TSA and the oil and natural gas pipeline industry. The directive establishes a new model that accommodates variance in systems and operations to meet our security requirements,” said TSA Administrator David Pekoske. “We recognize that every company is different, and we have developed an approach that accommodates that fact, supported by continuous monitoring and auditing to assess achievement of the needed cybersecurity outcomes. We will continue working with our partners in the transportation sector to increase cybersecurity resilience throughout the system and acknowledge the significant work over the past year to protect this critical infrastructure.”

Following the May 2021 ransomware attack on a major pipeline, TSA issued several security directives mandating that critical pipeline owners and operators implement several urgently needed cybersecurity measures. In the fourteen months since this attack, the threat posed to this sector has evolved and intensified. Reducing this national security risk requires significant public and private collaboration.

Through this revised and reissued security directive, TSA continues to take steps that protect transportation infrastructure from evolving cybersecurity threats. TSA also intends to begin the formal rulemaking process, which will provide the opportunity for the submission and consideration of public comments.

The reissued security directive takes an innovative, performance-based approach to enhancing security, allowing industry to leverage new technologies and be more adaptive to changing environments. The security directive requires that TSA-specified owners and operators of pipeline and liquefied natural gas facilities take action to prevent disruption and degradation to their infrastructure to achieve the following security outcomes:

- Develop network segmentation policies and controls to ensure that the Operational Technology system can continue to safely operate in the event that an Information Technology system has been compromised and vice versa;
- Create access control measures to secure and prevent unauthorized access to critical cyber systems;
- Build continuous monitoring and detection policies and procedures to detect cybersecurity threats and correct anomalies that affect critical cyber system operations; and
- Reduce the risk of exploitation of unpatched systems through the application of security patches and updates for operating systems, applications, drivers and firmware on critical cyber systems in a timely manner using a risk-based methodology.

Pipeline owners and operators are required to:

- Establish and execute a TSA-approved Cybersecurity Implementation Plan that describes the specific cybersecurity measures the pipeline owners and operators are utilizing to achieve the security outcomes set forth in the security directive.
- Develop and maintain a Cybersecurity Incident Response Plan that includes measures the pipeline owners and operators will take in the event of operational disruption or significant business degradation caused by a cybersecurity incident.
- Establish a Cybersecurity Assessment Program to proactively test and regularly audit the effectiveness of cybersecurity measures and identify and resolve vulnerabilities within devices, networks, and systems.

These requirements are in addition to the previously established requirement to report significant cybersecurity incidents to CISA, establish a cybersecurity point of contact and conduct an annual cybersecurity vulnerability assessment.

DOE Announces $45 Million for Power Grid Cyber Resilience

The U.S. Department of Energy (DOE) has announced $45 million to create, accelerate, and test technology that will protect the electric grid from cyber attacks.

Cyber threats to American energy systems can shut down critical energy infrastructure and disrupt energy supply, the economy, and the health of American consumers. Cybersecurity remains a priority as clean energy technologies deployed on the grid become highly automated.

Earlier this year, Supervisory Special Agent Ted P. Delacourt, a federal civilian working in the Mission Critical Engagement Unit of the Cyber Division at the Federal Bureau of Investigation, wrote that a cyber attack on one critical infrastructure sector may initiate a failure in another or cascade to the entire interconnected critical infrastructure network.

“The ubiquitous nature of these critical infrastructure sectors and the distribution of their physical and networked assets across a wide geographical area, often spanning the entire country, make them attractive targets,” Delacourt wrote for HSToday. “State, non-state, and criminal actors continually seek victims of opportunity across all critical infrastructure sectors for monetary and strategic gain.”

Delacourt warned that cyber attacks on critical infrastructure will continue to grow in number and frequency and continue to escalate in severity.

Combined with the additional grid upgrades funded in the Bipartisan Infrastructure Law and the Inflation Reduction Act, the latest DOE announcement means the United States will have an opportunity to build greater cyber defenses into its energy sector. The $45 million funding announced on August 17 will support up to 15 research, development, and demonstration (RD&D) projects that will focus on developing new cybersecurity tools and technologies designed to reduce cyber risks for energy delivery infrastructure. Building strong and secure energy infrastructure across the country is a key component of reaching President Biden’s goal of a net-zero carbon economy by 2050.

“As DOE builds out America’s clean energy infrastructure, this funding will provide the tools for a strong, resilient, and secure electricity grid that can withstand modern cyberthreats and deliver energy to every pocket of America,” said U.S. Secretary of Energy Jennifer M. Granholm. “DOE will use this investment to continue delivering on the Biden Administration’s commitment to making energy cheaper, cleaner, and more reliable.”

DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) will fund up to 15 research projects that will establish or strengthen existing research partnerships with energy sector utilities, vendors, universities, national laboratories, and service providers working toward resilient energy delivery systems. The effort will lead to the creation of next-generation tools and technologies designed to reduce cyber incident disruption to energy delivery. Researchers will aim to develop tools and technologies that enable energy systems to autonomously recognize a cyber attack, attempt to prevent it, and automatically isolate and eradicate it with no disruption to energy delivery.

There are six proposed topic areas for the projects, which include:

- Automated Cyber Attack Prevention and Mitigation: This topic area will focus on tools and technologies that enable energy systems to autonomously recognize and prevent cyber attacks from disrupting energy.
- Security and Resiliency by Design: This topic area will focus on tools and technologies that build cybersecurity and resilience features into technologies through a cybersecurity-by-design approach.
- Authentication Mechanisms for Energy Delivery Systems: This topic area will focus on tools and technologies that strengthen energy sector authentication.
- Automated Methods to Discover and Mitigate Vulnerabilities: This topic area will focus on tools and technologies that address vulnerabilities in energy delivery control system applications.
- Cybersecurity through Advanced Software Solutions: This topic area will focus on developing software tools and technologies that can be tested in a holistic testing environment that includes a development feedback cycle.
- Integration of New Concepts and Technologies with Existing Infrastructure: This topic area will require applicants to partner with energy asset owners and operators to validate and demonstrate cutting-edge cybersecurity technology that can be retrofitted into existing infrastructure.

[source: HS Today]
1 … 20 21 22 23 24 … 48