Showing posts with label ACC. Show all posts
Showing posts with label ACC. Show all posts

Thursday, June 25, 2026

Looking Back – 1-12-13 – ACC ASP

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today, a blog post from January 12th, 2013, made the list. It was the final post in a series that looked at the American Chemistry Council’s Alternative Security Plan for the CFATS program. It specifically looked at how the plan documents were submitted in the CFATS Chemical Security Assessment Tool (CSAT). The lengthy post also discussed some of the benefits of the use of the ASP, both for facilities and DHS. 

Thursday, March 17, 2016

Protecting the Sky over CI

Yesterday the American Chemistry Council issued a press release commending the Senate Commerce, Science and Transportation Committee on their adoption of a much modified version of S 2658, the Federal Aviation Administration Reauthorization Act of 2016. An official copy of the bill has yet to be printed by the GPO, but a committee draft was used for mark-up process. The press release said (in part):

“ACC and its members commend Chairman Thune for his leadership on aviation safety and for working closely with Senator Blunt to include a provision to the Senate’s Federal Aviation Administration (FAA) reauthorization bill that will address the troubling gap in current policies regarding the safe operation of drones around chemical facilities. With today’s vote, Congress has taken another important step toward addressing the serious security concerns that have come with this new and rapidly growing technology.”

Background


There were over 50 amendments acted upon during that markup and most were adopted (I’ll have more on that hearing and the bill provisions in a later post). I searched through all of the amendments and could not find anything about protecting chemical plants. I then went back through the substitute language upon which the Committee actually acted. Sure enough I found the provision in §2144.

Now let me first start out by saying that this provision is not the same language that the ACC applauded last month in the House version of the FAA authorization, HR 4441. That bill was passed in committee but will apparently not work its way to the floor because of some intra-party problems.

First a procedural matter; there are a large number of provisions in S 2658 that are applicable to unmanned aircraft systems. Many of those would include additions to 49 USC in a new Chapter 448, Unmanned Aircraft Systems. The provisions of §2144 do not include instructions for adding language to Chapter 448. This may cause some minor administrative problems for the regulations that the FAA Administrator is supposed to craft, but those would be future problems of little interest to Congress. As a side note, the provision in HR 4441 would have been included in 49 USC.

Bill Provisions


Section 2144 would require the Administrator to establish new regulations within 180 days of the enactment of this bill; a very short time frame for any agency, but especially for the FAA, to complete the regulatory process. The purpose of the regulations would be to allow facilities to petition the FAA to “prohibit or otherwise limit the operation of aircraft, including an unmanned aircraft [emphasis added], over a fixed site facility” {§2144(a)}.

While the similar language in the House bill applied only to security regulated chemical facilities (CFATS and MTSA facilities) the coverage in this bill is much more expansive. It includes {§2144(b)(1)(C)}:

• Critical infrastructure;
• Oil refineries and chemical facilities;
• Amusement parks; and
• Other locations that may benefit from such restrictions

The bill provides only the broadest standards for the approval or disapproval of those applications. It allows the Administrator to consider {§2144(b)(2)(C)}:

• Aviation safety;
• Personal safety of the uninvolved public;
• National security; or
• Homeland security

The FAA is required to review those petitions within 90-days. The bill does not require the FAA to provide a notice of why the petition was denied. The Administrator, however, may allow a resubmission of the petition that addresses the reasons for its disapproval. If the petition is approved the FAA will outline {§2144(b)(2)(B)}:

• The boundaries for unmanned aircraft operation [emphasis added] near the fixed site facility; and
• Such other limitations that the Administrator determines may be appropriate.

Moving Forward


This bill is going to the floor of the Senate; the only question is when. I expect that it will get to the floor pretty quickly for the Senate. The current FAA authorization ends at the end of March, but HR 4721 was just approved by the Senate and is on its way to the President to extend that until July 15th (which just happens to be the last day the House and Senate plan to be in session before their election year lengthened summer recess). It would appear that the House and Senate committee staffs have been hard at work crafting a version of this bill that should be able to pass in both bodies.

It will probably take most of a week of floor debate and amending in the Senate. As long as there are no poisoned amendments tacked on to the bill it will pass in the House the following week. The big question is can the Senate get this to the floor before things start to get clogged up with spending bills. Hopefully, it will get to the floor in early April.

Commentary


I never can understand why staff members fail to make legislative mandates such as this a part of the US Code. It really does not make much difference, but it makes it look like this is a temporary measure that does not deserve a place in formal federal law. It does provide another problem which this section very carefully ignores, without being included in a portion of the US Code that includes key definitions, a bill should provide those definitions internally; this bill did not do that for this section.

There is an important internal disconnect in this Section of the bill. It starts off by allowing facilities to petition to limit the operation of aircraft, including an unmanned aircraft. It concludes, however, by only allowing the FAA to set the boundaries for unmanned aircraft operation. I’m pretty sure that many facility owners would prefer to include all aircraft, but the petition and approval processes should apply to the thing.

This bill also has the same severe problem that I identified with the similar provisions in HR 4441; making flight illegal does not stop the aircraft overflights. The bill does include in other sections proposals to require real-time identification of UAS and their pilots sometime in the future, there does not yet exist technology to accomplish that requirement, especially for aircraft currently in the field.

Without being able to identify aircraft violating facility airspace, the only way this prohibition can be effective is to allow the facility owner to take action to take down offending aircraft. That is currently illegal under FAA interpretation of the law that makes it illegal to interfere with an aircraft in flight in the National Air Space (NAS; with exceptions, of course, for actions by duly ordered military aircraft). To be effective, this section should provide some sort of active legal recourse to facility owners.

The provisions of §2144 do not explain how the limitations authorized in {§2144(b)(2)(B)} compare or interact with other restricted airspace designations that the FAA is required to maintain. Nor does it explain how the FAA should go about communicating this information to the UAS flying public. While commercial UAS pilots should be expected to have flight charts available that should allow them to avoid designated restricted air space, it is extremely unlikely that most ‘model aircraft’ UAS pilots would have them available or know how to read them. Ultimately, most experts would prefer to see these designations included in mandatory geofencing firmware within the drone, but we are a long way from being able to require that level of control system sophistication in all covered UAS, much less have a reasonable way to update that firmware with changes to restricted airspace in the NAS.


What probably needs to be added to §2144 is a few study and report provisions that would address these and other not quite so obvious problems with adding additional airspace restrictions to the operations in the NAS. If such provisions were included in this bill with a related sunshine date to force Congress to deal with the results of those studies and reports, then this would probably be a very good first step in limiting the flight of aircraft, including UAS, near critical infrastructure.

Monday, January 4, 2016

ACC and NACD Update CFATS Alternate Security Plan

Over the holidays the American Chemistry Council (ACC) and the National Association of Chemical Distributors (NACD) published a new updated version of the ACC’s Alternative Security Plan (ASP) for the CFATS program. The original version of the ASP was released three years ago as an easier way for regulated chemical facilities to submit site security plan (SSP) information for the Chemical Facility Anti-Terrorism Standards (CFATS) program.

The goal of the ASP program has been to not only make it easier to submit the information that the Infrastructure Security and Compliance Division (ISCD) of DHS needs to evaluate the SSP, but to also provide the submitting facility with a document that could actually be used in the implementation and day to day operation of the SSP.

The new program includes;

• An ASP Guidance Document (.PDF);
• An ASP Template (with instructions) (.DOCX Download); and
• A set of nine forms to be used with the ASP (.ZIP download)

A quick review of the literature associated with ASP II shows that it does include at least some information from the new legislation authorizing the CFATS program (the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014, PL 113-254), but it does not refer specifically to the new personnel surety program being rolled out by ISCD (understandable since many of the details of that program have yet to be published). It also does not address the Expedited Approval Program (EAP) initiated by ISCD this last summer as an alternative to both SSPs and ASPs.

Long time readers of this blog will undoubtedly remember that I was a big fan of the ASP when it was rolled out (see my series of blogs here). This looks like it will be a valuable update of that program. I am especially glad to see that the NACD has specifically signed on to this as a partner in the revised program.


I will be looking at this revised program in more detail in future posts.

Wednesday, February 20, 2013

ACC ASP Press Release


I got a nice email from Scott Jenson, Director of Issues Communication, American Chemistry Council, providing me with a copy of the press release about their CFATS Alternative Security Program. Reader’s will remember my detailed review of this template for submitting the information necessary for ISCD to evaluate a facility site security plan.

ISCD Endorsement

I’ve been a little disappointed that ACC hasn’t been a more proactive in publicizing this outstanding tool. Reading this press release it is clear to see why Scott and his people have held off. In the press release there is a link to a very kind letter from David Wulf, Director, Infrastructure Security Compliance Division, essentially endorsing the ACC ASP. David says, in part:

“Thank you especially for ACC's efforts to help high - risk chemical facilities meet the CFATS requirements through the development of the ACC Alternative Security Program ( ASP) Guidelines and Template . We commend your decision to make these documents available to all facilities regulated under CFATS for potential consideration and reference in the development of other ASPs.”

There is no date on the Wulf letter, but I’m assuming that as soon as ACC had this letter in hand, they started immediate work on this press release. This is a very valuable endorsement. I would like to join David in commending ACC for sharing this tool with the whole of the regulated community, not just their member organizations.

BTW: It would be nice to see some mention of this ASP somewhere on the DHS Chemical Security web page. A mention of the ACC ASP with a link to the document would make it easier for non-ACC members to avail themselves of this tool.

ISCD Promises Better SSP Performance

David takes the opportunity in this letter to address the continued slow pace of SSP approvals. He notes that ISCD has streamlined the authorizing and approval process and then reports that ISCD has set “set a goal of 400 approvals [emphasis added] by the end of 2013”. This would be a truly remarkable accomplishment since the last official number that I had seen on approvals was that only 2 had been completed. Even at this rate they will only have about 1/3 of the SSPs approved before they have to go back and start re-evaluating SSPs that were previously approved.

Actually, ISCD has not approved any SSPs yet. They have only given provisional approvals because facilities can still not comply with the Terrorist Screening Database vetting requirements of Risk-Based Performance Standard 12. Metric 12.4 for all four Tier levels states that:

“Processes are in place to provide DHS with the necessary information to allow DHS to screen individuals (e.g., employees, contractors, unescorted visitors) who have access to restricted areas or critical assets against the TSDB.”

Since ISCD has not yet even published their proposed procedures for this vetting process, facilities are not able to comply with this requirement. ISCD is over four months late (based upon a promise made by Undersecretary Beers in testimony to a Congressional Committee) in the publication of the 60-day information collection request (ICR) in the Federal Register. If this were to be published today it would still be nearly the end of the year (best case) before final OMB approval could be given to begin the collection of the information necessary for this vetting.

So it will be nearly impossible for ISCD to achieve their goal of 400 approvals by the end of the year. I’m all for setting high goals David, but they must be achievable.

Saturday, January 12, 2013

ACC ASP – Submitting the ASP


This is the last in a series of blog posts about the recently published American Chemistry Council Alternative Security Plan for the CFATS program. The earlier posts are listed below. This post will look at how the ASP is submitted to ISCD and address some way that this ASP might improve the CFATS SSP process.






ASP Submission


Before an organization tries to submit the ASP they must realize that they will still be completing the SSP submission via the SSP tool in CSAT. There are a number of questions that must still be completed in the SSP tool when submitting the SSP. The SSP Questions Manual describes the questions that the facility will be required to answer when submitting an SSP.

All of the questions described through page 49 must be answered by all facilities, regardless of whether or not they are submitting an ASP in lieu of the remainder of the SSP. The answers to many of those questions will already be pre-populated in the SSP tool based upon earlier submissions to ISCD via CSAT. Even if the answers are prepopulated the facility is required to review the information to ensure that it is correct. Contact the CSAT Help Desk {(866) 323-2957} for assistance in correcting invalid data.

On page 50 the manual shows that facilities wishing to submit an ASP will check the ‘Yes’ button for Q 5.6-17939. Four additional questions will then be asked about the adequacy of the ASP in meeting DHS requirements for an ASP. DHS has generally agreed that a properly executed ACC ASP will fulfill these requirements so most facilities will answer ‘Yes’ to all four questions. A ‘No’ answer to any of the four questions will require the answering of a fifth question asking if the facility really wants to submit the ASP anyway.

At that point the facility will be required to identify and describe the documents to be upload to the SSP; the process is described on page 51 of the manual. This will include the completed WORD® file downloaded as part of the ACC ASP Guidance document. Supporting diagrams, maps, photographs and supporting documents will also be uploaded at the same time.

According to the SSP Instructions Manual once the data is uploaded, the CSAT SSP tool will take the submitter to the validation portion of the submission at the end of the tool. From that point on the process will be the same as for those facilities completing the standard SSP.

Other ASPs


While the ACC really designed their ASP for the use of their member companies, they are not stopping others from using the ASP. While I don’t see why any type of high-risk chemical facility couldn’t use the ACC ASP, I understand that there are other industry organizations that are working with DHS to get ASPs of their own design approved; designs one would expect to be tailored to facilities within that type of industry.

The one group that might have concerns with this ASP would be colleges and universities. Educational organizations have been pressing DHS to develop an ASP particularly for their ‘unique’ situation since the CFATS program was first introduced. I suspect that they will continue to have a hard time accepting that DHS actually intends for them to put significant security measures in place at their facilities that DHS has judged to be at high-risk of a terrorist attack. They will continue to hope that an ASP will be able to be used as a dispensation from the CFATS risk-based performance standards requirements. The ACC ASP will severely disappoint the scholarly community.

ISCD and the ACC ASP


I have not yet seen an official notice from the folks at ISCD that they will ‘accept’ an ACC ASP submission and part of me does not expect to. The way that the SSP tool handles the ASP submission process, there is nothing involved that would identify a submission as being made via an ACC ASP. Theoretically, a facility could submit any sort of document using the procedures that I have described above as an ASP. The SSP tool would accept it.

That, doesn’t mean, of course, that ISCD would actually use the information submitted. Scott Jenson and Bill Erny from ACC both assure me that DHS has told them that information submitted via the ACC ASP format meets the needs for their analysis. That means that ISCD knows where to look for the specific information that they need to evaluate the SSP/ASP submission. Some other format that hasn’t been pre-cleared with ISCD may not provide the needed information or may provide it in a format that is not easily decipherable by ISCD. ISCD is having a hard enough time getting the information they need from a straight SSP submission; they are not going to waste any time trying to decipher something that they don’t understand.

ISCD Improving SSP


I understand that ISCD has folks working on a plan to improve the current SSP submission process. I fully believe that they would do well to take a hard look at the format used by the ACC ASP and adapt it to an on-line submission process. They should definitely strive to have the printed document from the end of that submission process be in a format that the average corporate reader or chemical facility security inspector could readily read the document and find the information needed to implement or audit the implementation of the Site Security Plan.

Lacking that sort of fundamental change I would like to suggest that ISCD should consider including a specific template for the submission of the ACC ASP (and any other subsequently approved ASP format). If I were setting it up I would have a separate upload of each of the sub-paragraphs listed on the ASP Table of Contents page. Each sub-paragraph would be a separate file and it would be easy to parse those files to the appropriate analyst at Headquarters for the evaluation of the SSP/ASP. It would also make it easier to make subsequent changes to the SSP/ASP, requiring only a submission of the portions that will be changing.

Recommendation – Two Thumbs Up


Just in case I haven’t made it clear in my analysis to date, I really do believe that the ACC ASP is a significant improvement over the current SSP submission. The folks at ACC are to be commended for the work they have done on the document. I highly recommend that any high-risk facility that has yet to submit their SSP consider using this ASP template for their submission. Facilities that have yet to have ISCD authorize previously submitted SSP’s (and there is a large number of those) needs to contact ISCD and see if changing to the ACC template would make the approval process any easier.

Saturday, January 5, 2013

ACC ASP – Template


This is the fourth in a series of blog posts about the recently published American Chemistry Council Alternative Security Plan for the CFATS program. The earlier posts are listed below. This post will look at the “ACC ASP Template Final20121107” (Template) Word file that is imbedded in the “Alternate Security Program (ASP) Guidance for CFATS Covered Chemical Facilities” (Guidance document) that forms the core of the downloadable program.




Protective Markings


The template is essentially the same as the last twenty pages of the on the instructions that I discussed in the earlier post. There are, however, some important differences between the two. First the template includes all appropriate Chemical-Terrorism Vulnerability Instruction (CVI) markings that will have to be on the document when it is submitted to DHS, including front and rear ‘cover’ pages and a footer “warning” statement. As soon as any facility information is placed in the template it becomes a document requiring CVI protection.

Any attached documents will require the same cover pages and page markings. Cover pages can be found on the CVI web page.

Formatting


The basic format of the document is an outline based upon the outline found in the Table of Contents. The outline markings are based upon bullet points instead of letters or numbers. If you want to change it to a more classical outline that allows easy reference to the paragraphs within the sections that can easily be done in Word®. Personally I would use a numbered outline system for reasons that will be clearer shortly.

Unlike the template found in the Instruction document, the page numbering on the Table of Contents page is not actually linked to the section headers. One of the last things that you are going to want to do before submitting the completed ASP document in the DHS CSAT SSP Tool will be to put the appropriate page numbers in the Table of Contents. This will actually make it easier to copy sections from the template into separate documents to farm out the completion of the information to different people or teams. Again, remember that the CVI marking and protection rules will have to followed for those abstracted sections as soon as any facility information is entered.

Duplicate Information


There will be places in the document where the same information will be entered in different places. While DHS won’t be concerned about seeing duplicate (the key here is that it really is duplicate) information in multiple places, there is a good reason for not writing the same information in more than one place. If you have to go back and make a change to it for some reason you may miss one or more iterations.

It will be more effective to write it one time and then refer back to it in later places in the ASP documentation using conventional notations like “{See Section 5.2(a)(1)}”. This is the reason that I suggest using number (or lettered) paragraphs within each section instead of bullet points.

Detailed Information


This bears repeating, one of the main problems that DHS has encountered with their SSP authorization process has been that an inadequate amount of information describing parts of the security process for the facility has been included in the SSP submission. While the ASP process makes submitting the information easier (and subsequently more useable) there still needs to be a sufficiency of information provided.

Remember, analysts will be sitting in an office building somewhere reading the information provided by the facility trying to determine if the security measures provide an adequate measure of protection for the facility at its present tier level. Telling them in section 5.1 that there is a chain-link fence around the facility perimeter is not adequate information, they need to be told something like this:

“The facility is protected by 1,257 feet of commercial grade chain link fence. All segments of the fence are 8 foot tall with an outward-facing 18” top-guard with four strands of razor-wire. Corner posts have two top guard supports at a 90 degree angle from each other. Fence posts are set in three foot of concrete and placed at no more than 15 foot intervals. A single course of cinderblocks set in an 18 inch deep concrete footing runs under the fence fabric between each post with anchors placed no further than three feet apart to attach the fence fabric to the cinder block.”

Okay, my fence is a bit of overkill, but it is completely described.

Not Too Much Information


Remember that every detail that you put into the ASP submitted to ISCD is an inspectable part of your site security plan. To change any of those details you have to re-submit the revised ASP and hope that it passes muster with DHS. If you make changes without that pre-approval, it could cost you up to $25,000 per day, or, in the worst case, cause DHS to issue a facility closure order.

The area that will probably cause the most problem for this is not the physical plant. The more likely area will be in processes and procedures. Where possible the process or procedure documents will be maintained in documents separate from the ASP and the title of the appropriate document will be mentioned in the ASP where necessary.

For example if you use padlocks on unloading valves as part of your process to protect access to a COI you are going to have to have some method to maintain control of the keys to those locks to prevent that unauthorized access. Rather than outlining your entire key control process you could explain that: “The keys for those valve locks are maintained in the locked key box in the Shift Supervisor’s Office and are only issued in accordance with the provisions of the Facility COI Key Control Procedure.” Once part of the authorized SSP, that wording would allow a Chemical Facility Security Inspector (CFSI) to verify that the process in that procedure was being followed, but not to evaluate the details of that process.

It would probably be a good idea to maintain a list of all of the referenced processes and procedures in Section 1 of the ASP.

Key Words and Phrases


One of the things that does not receive enough emphasis in the supporting documentation for the ASP is the importance of using certain key words and phrases when describing facility security measures. These key words and phrases can be found in the RBPS Metrics for each Risk-Based Performance Standard in the RBPS Guidance document.

For example section 5.1 of the ASP calls for a description of ‘Vehicle Barriers’ and the Security Metric 1.2 for Restrict Area Perimeter (pg 29) Tiers 1 and 2 calls for “Entrances equipped with traffic control systems to slow incoming traffic…”. Given that combination I would suggest that the description start with:

“The single vehicle gate is equipped with traffic control devices to slow incoming traffic. The traffic control devices consist of ….”

Memorandum of Understanding


There are a number of references to “MOU in place” in the “Emergency Responders, Off-sit” paragraphs of Section 2 of the ASP. An MOU is a memorandum of understanding between facility management and an organization outside of the facility (local police, fire departments, or emergency medical services for instance) that is providing some sort of support to the facility Site Security Plan.

As long as the facility is relying on an outside agency as part of its SSP, it needs to be able to show that the agency is prepared to provide the necessary services. The MOU needs to specify what type of support will be provided, under what circumstances, and what type of response time could be expected. Probably the most important aspect of the MOU is that it needs to be signed by an appropriate official of the supporting agency.

One More Posting


The next and final posting in this blog series will address how the completed ASP is submitted to DHS.

Wednesday, December 26, 2012

ACC ASP – Instructions


This is the third in a series of blog posts about the recently published American Chemistry Council Alternative Security Plan for the CFATS program. The earlier posts are listed below. This post will look at the “Alternate Security Program (ASP) Template Guidance and Instructions” (Instructions) that is imbedded in the “Alternate Security Program (ASP) Guidance for CFATS Covered Chemical Facilities” (Guidance document) that forms the core of the downloadable program.



The Instructions can be found on page 18 of the Guidance document. Click on the first ‘paperclip’ symbol on the page and you will open the file:

ACC ASP Template Guide and Instructions Final20121130.docx

The numbers at the end of the file name may change as the ACC updates and revises this program.

Chemical-Terrorism Vulnerability Information (CVI)


It was mentioned briefly in the ASP Guidance document that everyone that will be accessing the partially completed SSP/ASP document will have to be CVI trained and certified. Once any information about the security of the facility is entered into the template it becomes a document requiring CVI protection. Make sure that everyone who will be working with this information has completed the online training course and copies of their training certificates are on file.

Before You Start


Pages 2 thru 9 of the Instructions provide a general set of guidelines that should be followed when filling out the template. I strongly recommend that the entire team that will be working on the SSP/ASP preparation carefully read those 7 pages of the Instructions and be familiar with the any of the Risk Based Performance Standards (RBPS) in the RBPS Guidance document published by DHS that they may be responsible for. This familiarity will make it much easier to fill in the template with verbiage that includes the key words and phrases in the RBPS that the folks at DHS ISCD will be looking for in their evaluation of the SSP/ASP.

RBPS


There is a brief discussion of the RBPS in the ASP Guidance document and there are two brief explanations of the RBPS in the Instructions, but both documents gloss over a very important point. While DHS may not (prohibited by Congress) specify a particular security measure they do spell out in the RBPS Guidance document the way they will measure compliance (RBPS Metrics) with each RBPS at the specific Tier level to which a facility has been assigned. The difference between the required performance metrics for two different tiers may be one word, eg: ‘routinely’ vs ‘usually’. Including these key words in the description of a security measure may make it easier for DHS analysts to understand the intent of the security plan.

Attack Scenarios


One of the more confusing ideas that DHS included in their CFATS program was the idea of “Attack Scenarios”. Security professionals initially thought that the seven scenarios proposed by DHS were the proposed design basis for the security plans, attacks that had to be prevented for the plan to be successful. That was not the intent of DHS. As the Instruction document explains (pg 3):

“Rather, the attack scenarios are analytical devices, supporting the evaluation of a facility’s security and enabling DHS to conduct comparative risk analysis across the sector.”

The Security Metrics in the RBPS explain how well the facility (at its specific tier level) must be able to deal with those scenarios. As the Instructions document explains, not all attack scenarios apply to each RBPS. But, when they do apply they should be specifically addressed in the words that are put into the template so that it is clear to the ISCD analysts that the facility has addressed the issue.

Security Approach


There is a nice discussion in the Instructions document about the differences between perimeter based and asset based security measures. Essentially, the ‘perimeter based’ approach includes the entire facility whereas the ‘asset based’ approach only provides security measures for a specific area of the facility where a COI is found. For a facility with a single high-risk COI, it may make more economic sense to confine the bulk of the security measures to the area where that COI is used/stored. For facilities with multiple COIs at varying security levels, it may make more sense to protect the facility at the level for the COI with the lowest tier ranking (provided by DHS) and reserve the more complex security arrangements for the area around the highest tier-ranked COI.

As noted on page 5 of the Instructions document:

“In the description of a specific security measure, ASP preparers should describe whether it is applied facility wide or to specific assets.”

Too Much Information


As the Instruction document alludes to, the problems that ISCD has had with not being able to authorize SSPs have been in large part due to not receiving enough information from the facility about their security plans. So generally speaking, the more the better, but there is a limit. As the Instructions document states on page 7:

“On the other hand, the preparer may wish to limit detail that does not relate to the listed COI or the performance of the specific security measure or system, to allow for minor changes without the need for ASP resubmission.”

This is an important point that needs to be clearly understood by facility management. Once the SSP/ASP is authorized by DHS it is essentially a legally binding document outlining the inspectable requirements for facility security under the CFATS program. The congressional prohibition against specifying particular security programs no longer applies. If a subsequent ISCD inspection does not find an authorized component of the SSP/ASP in place, the facility may be fined up to $25,000 per day or even shut down (an extreme case to be sure) for non-compliance. Any changes to the authorized ASP must be approved by ISCD before they are made.

One way to get around some of this problem will be to include the little details of the plan in separate documents describing specific procedures and processes. The Instructions document notes that:

“It is not necessary to include the text of every procedure that is described in the ASP.  Use an unambiguous reference that is clear to facility personnel and that inspectors can request by name for review, for example, ‘Suspicious Activity Reporting Procedure S.4.01’.”

There must be, however, enough detail in the submitted ASP to allow the ISCD analysts to determine if the RBPS Security Metrics have been met.

Take Credit for Everything


The last topic that is specifically discussed in the first nine pages of the Instruction document is a reminder to take a careful look at everything that the facility does to determine if it contributes to security. Many process safety and almost all emergency response measures already in place at the facility may contribute to the security plan, particularly the ‘Response’ RBPS. Simple things like referring to a COI by a company product name rather than an easily recognizable chemical name will make it harder for an attacker to find their target. Pages 8 and 9 of the Instruction document provides a short list of things to look at.

Just remember, though, if you take credit for it and list it in the ASP you must continue doing it until DHS gives you permission to change.

The Template


The remainder of the 30 page Instruction document is an annotated copy of the template. Explanatory material and completion suggestions are provided in blue type. Almost everything in black type should remain in the submitted document with appropriate additional supporting information. I’ll look at the actual template in some detail in later blog posts.

Tuesday, December 25, 2012

ACC ASP – Guidance Document


This is the second in a series of blog posts about the recently published American Chemistry Council Alternative Security Plan for the CFATS program. The initial blog post is listed below and dealt with an overview of the place of the ASP in the CFATS program. This post will look at the “Alternate Security Program (ASP) Guidance for CFATS Covered Chemical Facilities” (Guidance document) that forms the core of the downloadable program.


There are two embedded documents in the Guidance document; the template and the instructions for the ASP and they form the basis of the actual ASP that will be submitted to DHS as part of the facility site security plan. There is a significant amount of additional information available in the document.

CFATS Overview


The first five pages of the Guidance document provide a fairly detailed guide to the CFATS program. Now anyone who is in the process of considering options for submitting an ASP in lieu of an SSP should be fairly familiar with the CFATS program, so this would seem to be somewhat superfluous.

We have to remember, however, that once a facility reaches the SSP stage of the SSP process, the funding issues become rather large. The upper level management that needs to become involved in the budgeting process at this point could use a high level lesson in the requirements of the CFATS program and these five pages could form a good starting point for that discussion.

Pre-Authorization Inspection


In its discussion of the CFATS inspection process the Guidance document provides a reasonably good description of the purpose and process of the Pre-Authorization Inspection. Since DHS ISCD has yet to formally address this addition to the CFATS program in any of their written documents the following description taken from the Guidance document serves an important purpose;

“Pre-Authorization Inspections (PAI) are conducted AFTER the submission of an SSP/ASP but BEFORE a letter of authorization, in which the SSP/ASP is preliminarily approved as the regulatory standard for that facility. Pre-authorization inspections were instituted after it became clear that the CSAT SSP template was not producing enough detail to result in the issuance of letters of authorization. Their purpose is for the inspection team to establish the facts on the ground and for DHS to provide feedback for both the improvement of the detailed content of the SSP/ASP and potentially for improvements in existing security measures to meet the RBPSs.”

Of course, part of the purpose of the publication of this ASP template and instructions is to provide an initial data submission to DHS and ISCD that precludes the necessity for DHS to conduct such PAIs.

Authorization Inspection Process


The ACC Guidance document provides information on the Authorization Inspection process as well. Again this is another area where detailed information has been lacking from the folks at ISCD, unless they are providing it directly to facilities when they schedule the inspections. In any case, the information provided here will be very beneficial to any facility beginning to prepare for their authorization inspections.

The Appendixes


The Guidance document includes four appendixes that provide a variety of additional information on the CFATS program. The four appendixes are:

• Definitions and Acronyms

• Alternate Security Program Template

• CFATS RiskBased Performance Standards

• CFATS Reference Links

Of the four the second is, of course, the most important for facilities considering the submission of their SSP. It includes two imbedded Word® documents that form the basis for the ASP submission.

• ACC ASP Template Guide and Instructions Final20121130.docx

• ACC ASP Template Final20121107.docx

I’ll discuss these two documents in later blog posts in the series, but I suspect that the ACC will be a tad bit more proactive in updating these files as additional facilities use them to prepare and submit their SSP/ASP

Assessment


I think that the ACC has produced a very good CFATS summary document here. In many cases it is more informative than the formal DHS documents upon which it draws. The major drawback is that it spends almost no time discussing the preparation of the ASP. While that is covered in the imbedded instruction document, it would be helpful if there were some discussion here about some of the ASP/SSP issues.

For instance, there is nothing said about the relationship between an adequate level of information necessary for DHS assessment and the need to leave room for minor modifications in the program that won’t require a resubmission of the ASP. Too much detail and the smallest change will have to go through a long-delayed reassessment process at ISCD. Too little detail and the facility will have to go through the added problem of an AIP inspection.

Additionally, I think that there should be a little more emphasis on the fact that any security procedures, processes and equipment mentioned in the authorized SSP/ASP become a regulatory requirement for the facility in all future DHS-ISCD inspections. While DHS cannot specify which security processes need to be employed to get an SSP/ASP authorized, they can and will require strict adherence to the authorized SSP/ASP.

I’ll look at how these issues are addressed in the instructions and template in future blog posts.

All and all this is a much better document than anything that the folks at DHS have done for the SSP process.

Friday, August 26, 2011

CHEMICAL INDUSTRY PREPARED AS HURRICANE IRENE HEADS TO EAST COAST OF U.S.


NOTE: This was sent to me by Scott Jensen from the American Chemistry Council. I think that this is important enough to print verbatim. Sorry about the delay in getting this posted, but I have been on the road today driving back from a chemplant where I have been doing some contract work.



Washington, D.C. (August 26, 2011) – With another hurricane season upon us and Hurricane Irene heading toward the eastern coast of the United States, the chemical industry is prepared to build on the successful actions taken to weather previous hurricanes.

During storms like Katrina and Ike, American Chemistry Council (ACC) members’ emergency preparations worked as planned. Not one employee at a chemical facility was injured, and neither the U.S. Environmental Protection Agency (EPA) nor any state agency reported a significant chemical release from ACC member facilities in the Gulf. 

In fact, most chemical facilities returned to full operational status in a matter of days, a tribute to planning, preparation and the fundamental design of ACC members’ facilities.

Preparation equals safety


Chemical companies know well to avoid the dangers of being unprepared for any threat, be it a hurricane, an accident, or something more sinister. This is why our member companies place great importance on implementing emergency plans focused on protecting the safety of employees and surrounding communities. Under Responsible Care®, our trademark health, safety, environment and security program, all ACC members have long-established emergency plans, which are activated in close coordination with local, state and national authorities, other businesses and transportation systems, along the path of the storms.

The well-rehearsed emergency plans for hurricanes involve many actions taken in advance of the storm. Depending on the severity of the storm, they include:

• Complete shutdown of facility following strict safety and operating procedures
• Evacuation of personnel
• Preparing the facility by activating generators, filling tanks and physically securing equipment
• Removal of unnecessary vehicles and other equipment

ACC members don’t just plan for severe contingencies like hurricanes, they consider them when designing and building chemical facilities to be safe. Specific construction elements can include hardened equipment, dikes and levees.

Cascading impacts on chemicals and customers


As previous storms like Katrina and Rita demonstrated, the impact of hurricanes can go well beyond the potential threat to employees and physical damage to facilities and their communities. Those storms served as a reminder of the interdependent nature of the nation’s critical infrastructure.

While most facilities did not suffer major structural damage and were operational within days, many were unable to resume normal production because of other external consequences of the storms. Extensive damage to the local infrastructure blocked the flow of key supplies, like electricity and natural gas, necessary to manufacture chemicals, while damaged roads and rail lines prevented the delivery of products to consumers.

Ultimately, this led to higher natural gas costs for everyone and curtailed the delivery of chemicals essential to producing important everyday items like clean drinking water and life-saving medicines.

Recovering from the storm


After a storm passes, specially trained teams visit the site to evaluate damage before response crews or other employees are allowed to return. Once it is deemed safe to return, employees begin the delicate process of restarting operations, which can take several days depending on the size of the facility.

As we have seen in the wake of past storms, the recovery operations of many companies extended past the fence lines of their facilities. On their own, through ACC and the state chemistry councils, and working directly with the Red Cross, Salvation Army and other organizations, America’s chemistry companies and their personnel responded compassionately, donating tens of millions of dollars for relief assistance, volunteering time and providing much-needed supplies. This industry-wide effort included companies and facilities from all parts of the nation.

In many instances, member company facilities became vital community resources, providing a wide range of support, including temporary housing and meals for employees, their families and even the broader community, in some instances. One company loaned its helicopter to the Red Cross for relief and rescue. Another facility helped run the small town where it was the only local institution with emergency power and communications.

Preparing for Irene and the Next Storm


While it is impossible to predict the exact path of Irene or the potential impact on member facilities, ACC member companies will continue to make sure all of their facilities are prepared to weather the storm and assist in the recovery.

Friday, June 24, 2011

Cybersecurity and Chemical Facilities

I got an interesting email yesterday from Scott Jensen, Director of Issues Communication at the American Chemistry Council. He was kind enough to forward a copy of the written testimony that the ACC was submitting for today’s hearing before the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee.

While typically made part of the ‘public record’, such unsolicited written testimony is seldom placed on the hearing web site. Perhaps the Homeland Security Committee can establish a new level of public information sharing by including such written testimony on their hearing web site.

Today’s hearing is another in a series of hearings on the Administration’s comprehensive cyber security proposal that I wrote about in an earlier blog. As I noted in a weekly notice on congressional hearings, this hearing today is much more likely to address the control systems security issues of probable interest to my readers and obviously the ACC.

Covered Facilities

I noted in my blog about the legislative proposal that I didn’t think that the description of covered critical infrastructure found in §3 of the proposed Cybersecurity Regulatory Framework for Covered Critical Infrastructure Act would generally effect chemical facilities because they wouldn’t normally fall under the dependency on ‘information infrastructure’ requirements of §3(b)(1)(A).

The ACC testimony seems to indicate that their review of the proposal takes a more expansive view of potentially covered critical infrastructure. Their testimony doesn’t specifically outline what they expect to be covered, but their analysis of the CFATS cyber security requirements would seem to indicate that they believe that CFATS covered facilities would be covered under this legislation.

The confusion about what types of facilities would be covered by this cyber security proposal isn’t limited to me and the ACC. In the hearing earlier this week before the Subcommittee on Crime and Terrorism of the Senate Judiciary Committee none of the witnesses could provide a clear definition of what facilities would be covered under the broad definition of ‘critical infrastructure’. The conclusion was that this would be best developed during the development of regulations implementing the law if the bill is passed. In other words, the Administration wants Congress to provide the DHS Secretary with the widest possible latitude.

It would be interesting to see if today’s hearing is able to get a clearer definition of what facilities might be covered.

Information Sharing

Information sharing between covered facilities and regulators will be a key to the effectiveness of any cyber security regulation scheme. The ACC testimony addresses one of the information sharing issues that I identified in my earlier blog. They note that one of the keys to a successful cybersecurity program is the creation of “a public/private partnership to effectively share information that is timely, specific and actionable and is properly protected from public disclosure”. They specifically recommend that “information voluntarily provided by the private sector should be adequately protected from public disclosure including Freedom of Information Act requests”.

There are currently a number of different information protection schemes that the government has established to protect such information from public disclosure. One of the most restrictive (read ‘protective’) is the Chemical-Terrorism Vulnerability Information (CVI) program for the CFATS program. This is because this program requires the most expansive sharing of information, a level comparable to what it appears that this plan will require.

The level of information protection needs to be clearly spelled out in any cyber security legislation adopted by Congress.

Moving Forward

Today’s hearing is just another stop on the Administration’s road show supporting their cyber security proposal. At some point in the not too distant future someone is going to have to turn the proposal into actual legislation. Then things will start to get real interesting. We can expect at least two separate bills, one for each house of Congress, probably authored by committee chair. It will be interesting to see if Congressional leaders in the two Houses can field companion bills. Actually, it will be even more interesting to see if the competing committee chairs can come up with a single bill for each body.

Wednesday, April 27, 2011

2011 ChemSecure Conference

Earlier this week the American Chemistry Council announced the publication of the agenda for next month’s ChemSecure Conference in New Orleans. The three day event (May 9th thru 11th) looks at chemical security issues from more of an industry perspective, though there will certainly be significant DHS participation. In fact, I noted that Rick Driggers will be representing ISCD in the Regulatory Update presentation, the first time since he became the Acting Director of ISCD that I have seen his name on a presentation list for ISCD.

The presentations will cover:

● Legislative update
● Regulatory update
● CFATS inspection update
● Voluntary initiatives
● Cyber security
● State and local fusion centers
● Transportation and CFATS issues
● Supply chain security
● Responsible Care Security Code
Following the wrap up presentation on Wednesday there will be a stand alone DHS presentation on explosives awareness training; separate registration is required. The session will provide information on IEDs and VBIEDs as well as how to respond to explosives incidents.

Further information and registration links can be found at the Conference web site.

Friday, February 26, 2010

ACC and Cyber Security Testimony

Earlier this week a little bird told me (okay it was a tweet from CFATS, an American Chemistry Council spokesperson) about a letter that the ACC had sent to the leaders of the Senate Committee on Commerce, Science and Transportation for that committee’s hearing this week on cyber security issues. I didn’t pay much attention to this hearing since none of the witnesses were very much concerned with SCADA or ICS security issues. While I wish that the ACC had been asked to provide a live witness for the hearing, I’m glad that they were proactive enough to send this letter. 

I fully understand that the issue of cyber security is a very broad topic that covers a number of grievous sins. The problems of denial of service attacks, identity theft, phishing, and even cyber espionage all attract a great deal of public attention because most people can understand the consequences of those problems. The potential consequences of an attack on cyber control systems or other cyber control systems incidents is more difficult for most people (including congresscriters) to understand. But, that does not diminish the seriousness of the problem. 

ACC and DHS have both been active in their work on cyber control system security issues, but these two organizations only directly touch a relatively small hand full of chemical facilities that have both hazardous chemicals and cyber control systems. ACC’s direct effect is limited to their membership and DHS has only limited enforcement authority at the CFATS covered facilities. While the DHS CERT does provide cyber security training to non-CFATS facilities, they have no regulatory authority.

ACC is to be commended on their efforts to keep this issue before our legislators. I’m sure that other organizations are doing the same (and I would be more than happy to give direct kudos if they would share information on their efforts when I don’t see it), but all of us in the chemical security community need to be proactive in our communications with our personal representatives in Congress about the need to fund programs addressing this critical issue.

Tuesday, September 22, 2009

Cyber Security at ChemITC Conference

Last week I receive an email notice via ACC@smartbrief.com that the American Chemistry Council’s ChemITC Conference at the end of this month would have a significant focus on cyber security issues. Thanks to Bridgette Bourge at ChemITC I received a copy of the just released program for that conference. It is certainly no exaggeration to say that ChemITC is working hard to keep their members up to date on the ever changing world of cyber security. The four day conference will be held September 28th thru October 1st at the IBM Executive Conference Center in Palisades, NY. Registration is still open. According to the ACC website this program will “appeal to all chemical company IT executives and their senior thought leaders”. The cyber security portion of the program does not get started until the second day of the conference and even that is mainly an introduction of the ChemITC working groups that are looking at cyber security issues for the chemical industry. There will be a brief update on the work being done by each working group. The third day of the program, however, has lots of interesting presentations on cyber security issues. The first program of the day is a one hour ‘conversation’ with FBI Supervisory Special Agent Frank Torkel from the National Cyber Investigative Joint Task Force. That conversation will look at the current state of cyber crime. DHS will provide two updates later that day, one from the National Cyber Security Division and the other from the Chemical Sector Specific Agency. There will be two industry lead discussions on cyber security issues related to CFATS. The first will be on Day 3 by Keith Lichtenwalner, from Air Products and Chemicals. The second will be on Day 4 by Mark Gandy, from Dow Corning. While this conference will not be addressing any of the nut and bolt (or should I say ‘coding’) level issues of cyber security, it will provide valuable insight into the management level issues that are important for planning and budgeting for the cyber security challenges facing high-risk chemical facilities.

Friday, February 13, 2009

ACC Cyber Security

There is a very misleading article on Sys-Con.com about the ‘recent’ release of a series of documents by American Chemistry Council on cyber security issues. The article states that: “The American Chemistry Council’s Chemical Sector Cyber Security Program has added to its suite of cyber security resources with the release of five guidance documents and two white papers”. What is misleading is that none of the documents shown on the referenced ACC web pages is really recent. One guidance document, The Protection of Intellectual Property, was released last month, but all of the other guidance documents are almost a year old. One white paper, Report of Technical Survey Results: Separating Industrial Automation and Business Systems, was released in December, but the next most recent release date was April of last year. I don’t think that this confusion was caused by the ACC. The release dates are very clear on their web site. It looks to me like an over zealous writer on Sys-Con.com was exaggerating to make the article look more important and timely than it really was.
 
/* Use this with templates/template-twocol.html */