Showing posts with label ASP. Show all posts
Showing posts with label ASP. Show all posts

Monday, January 4, 2016

ACC and NACD Update CFATS Alternate Security Plan

Over the holidays the American Chemistry Council (ACC) and the National Association of Chemical Distributors (NACD) published a new updated version of the ACC’s Alternative Security Plan (ASP) for the CFATS program. The original version of the ASP was released three years ago as an easier way for regulated chemical facilities to submit site security plan (SSP) information for the Chemical Facility Anti-Terrorism Standards (CFATS) program.

The goal of the ASP program has been to not only make it easier to submit the information that the Infrastructure Security and Compliance Division (ISCD) of DHS needs to evaluate the SSP, but to also provide the submitting facility with a document that could actually be used in the implementation and day to day operation of the SSP.

The new program includes;

• An ASP Guidance Document (.PDF);
• An ASP Template (with instructions) (.DOCX Download); and
• A set of nine forms to be used with the ASP (.ZIP download)

A quick review of the literature associated with ASP II shows that it does include at least some information from the new legislation authorizing the CFATS program (the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014, PL 113-254), but it does not refer specifically to the new personnel surety program being rolled out by ISCD (understandable since many of the details of that program have yet to be published). It also does not address the Expedited Approval Program (EAP) initiated by ISCD this last summer as an alternative to both SSPs and ASPs.

Long time readers of this blog will undoubtedly remember that I was a big fan of the ASP when it was rolled out (see my series of blogs here). This looks like it will be a valuable update of that program. I am especially glad to see that the NACD has specifically signed on to this as a partner in the revised program.


I will be looking at this revised program in more detail in future posts.

Sunday, January 26, 2014

CFATS Document Support

I’m hearing interesting rumblings from those in the CFATS field that as more and more small chemical facilities are getting visited by DHS Chemical Security Inspectors (CSI, oh that hurts; maybe CBS should sue for copyright infringement) a new ‘security issue’ is being found with increasing regularity. While these facilities appear to be doing a yeoman’s job at actually securing the chemicals on site, they are having problems documenting their security procedures.

The Problem

As DHS moves into the site security plan authorization and approval process in the Tier 3 and Tier 4 facilities, they are encountering a large number of small facilities, frequently with less than 10 employees on site and no corporate EHS&S support. The Security Manager at these types of facilities is frequently the same person that handles all of the other regulatory compliance issues for the facility along with another full time job related to chemical production or distribution.

This routinely means that while security measures might be employed, there is little time for preparing all of the documentation that goes into supporting a real security plan. There are dozens of written procedures and processes that the CSI need to be able to see when they arrive on site to verify that the facility understands its security program and is properly implementing all of the necessary support requirements that are part and parcel of the physical security investments that have been made.

For example, there might be a bright new 10 foot security fence with razor wire topper and an automated gate that opens only to employee ID cards, but there needs to be a document that describes the processes that support that fence. That barrier plan document would include a description of:

• Who/what the fence was designed to keep out;
• How the fence is kept under observation to ensure that no one cuts or climbs over it;
• How often the fence is inspected for physical integrity;
• Who is responsible for ensuring that defects are repaired;
• What is done while a defect is awaiting repair to compensate for the deficiency;
• How the employee ID cards are issued and controlled;
• Etc.

Each and every security measure that a facility employs needs this sort of documentation that can be shown to a visiting inspector (along with supporting records that show that required periodic actions are being taken). Without that documentation, the DHS cannot really tell if a facility is really properly secured.

CSAT Tool Lacking

It looks like the original intent of the developers of the Chemical Security Assessment Tool (CSAT) was to provide an on-line data entry tool that would allow much of this type of documentation to be bypassed, making the job of security managers much less complicated. Unfortunately, by the time DHS got around to implementing the Site Security Plan (SSP) portion of the tool it became painfully obvious that there was not enough time, money or support available to prepare an SSP tool that could do more than ask some general questions about a very complicated series of security topics.

I understand that suggestions have been made that DHS Infrastructure Security Compliance Division (ISCD, the folks that run the CFATS program) provide an on-line series of templates for the various supporting plans and documents that may be needed by a facility to support their SSP. For some fairly obvious reasons, that has not been done.

First off, ISCD is already stretched pretty thin doing what it is already required to do; authorize, approve and inspect 3000+ site security plans. We can argue whether or not they should have developed such templates as part of the original SSP tool development process, but that is water under the bridge and the current management team was not in charge of that process. At this point in time they don’t have the time, money or personnel to accomplish that type of template development.

I am hearing rumors that a variety of facilities that have already been authorized and approved have offered to allow some of the documents that they have produced to be used as templates (after filing off the appropriate nameplates and serial numbers, of course). This is quite heartening and a positive sign of how well the industry accepts their general responsibility for chemical security in general.

Unfortunately, the §550 bugaboo once again rears its ugly head; “the Secretary may not disapprove a site security plan submitted under this section based on the presence or absence of a particular security measure”. ISCD has, from its very inception taken this congressional restriction very seriously (too seriously in my opinion, but then again, I don’t have to go back to Congress every year of reauthorization either). One just has to look at the repeated weasel wording in the Risk-Based Performance Standards guidance document to see how seriously the Department takes this requirement.

There is no way that ISCD is going to provide templates for SSP support documents for fear of running afoul of this restriction. Additionally, the Department lawyers would vociferously argue against providing such templates for fear having to defend ISCD against legal complaints when facilities that used such templates were found wanting in their SSP plan implementation. Templates would have to be generally enough written that a lot would still depend on how the various blanks were filled in. Besides, chemical facilities covered under CFATS are so diverse that it is unlikely that a single template, no matter how generally written, would cover all situations.

Industry Support

It looks like Congress, reading the full language of the §550 authorization, actually thought that there would be a viable solution to this issue. We can see this in the language related to alternative security plans (ASP). They thought that the various areas of the chemical industry would come up with generic security programs tailored to the specific requirements and security issues facing that industry segment.

Unfortunately, to date only one ASP has been developed that is in wide spread use and that is the one that was introduced just over a year ago by the American Chemistry Council (ACC). The ACC’s ASP is much closer to being an actual site security plan template than is the SSP tool in CSAT. It is still, however, falls short of the actual policies and procedure documents that need to be in place at all CFATS covered facilities. And there is a good reason for this; the ASP document once submitted and authorized/approved by DHS cannot be changed without approval of DHS.

Policies and procedures supporting the ASP need to be living documents that can be changed and modified to fit changing circumstances. As long as those changes don’t materially modify the processes approved by DHS there should be no need to burden the ISCD folks with a change approval request. So the data submitted to the DHS in the ASP needs to cover much of the same information as would found in the policy and procedure documents, but not in quite so much detail. (NOTE: Finding the acceptable limits of that detail is what is taking so much time in the SSP authorization and approval process.)

In any case, it would be helpful if the various chemical industry support groups would help the smaller companies in their organizations by developing template documents for many of the security policies and procedures that facilities would have to have in place to support their SSP.

ASP Approvals

While I am on the topic of ASPs, I heard a very interesting comment from the field the other day about why DHS is not pushing the ACC ASP. Now Director Wulf has made an official statement in support of the use of the ACC ASP, but there is nothing on the DHS CFATS web sites specifically mentioning the ACC ASP, and there is certainly no link to the ASP on the DHS sites. Some are questioning this lack of support.

The comment I heard this week is that the reason for this lack of support is that the cost of the design and maintenance of the current CSAT tool would be hard to justify if there were wide spread adoption of the ACC ASP. While I would not be surprised to hear that there were individuals associated with the CSAT development that might have their feeling hurt to hear that their SSP tool was less than adequate (AND IT CERTAINLY IS THAT), I do not think that is why the current management team at ISCD has not made their support for the ACC ASP more widely known.

First off, any federal bureaucrat has to be very careful about how they endorse a commercial product. While the ACC ASP is certainly free-of-charge for use the ACC and its affiliated companies are commercial enterprises, so Director Wulf has to be careful in that respect. Also, as other ASPs hopefully come into use failure to publicly recognize and support those with the same alacrity that they supported the ACC ASP could lead them into political problems, so a measured approval is probably politically prudent.


There should be, however, a link on the SSP homepage to any and all ASPs that have been approved by DHS. If there is only one such link because only one such program has been approved by ISCD, then so be it. This should serve as an incentive for other organizations to develop their own industry specific templates.

Saturday, January 12, 2013

ACC ASP – Submitting the ASP


This is the last in a series of blog posts about the recently published American Chemistry Council Alternative Security Plan for the CFATS program. The earlier posts are listed below. This post will look at how the ASP is submitted to ISCD and address some way that this ASP might improve the CFATS SSP process.






ASP Submission


Before an organization tries to submit the ASP they must realize that they will still be completing the SSP submission via the SSP tool in CSAT. There are a number of questions that must still be completed in the SSP tool when submitting the SSP. The SSP Questions Manual describes the questions that the facility will be required to answer when submitting an SSP.

All of the questions described through page 49 must be answered by all facilities, regardless of whether or not they are submitting an ASP in lieu of the remainder of the SSP. The answers to many of those questions will already be pre-populated in the SSP tool based upon earlier submissions to ISCD via CSAT. Even if the answers are prepopulated the facility is required to review the information to ensure that it is correct. Contact the CSAT Help Desk {(866) 323-2957} for assistance in correcting invalid data.

On page 50 the manual shows that facilities wishing to submit an ASP will check the ‘Yes’ button for Q 5.6-17939. Four additional questions will then be asked about the adequacy of the ASP in meeting DHS requirements for an ASP. DHS has generally agreed that a properly executed ACC ASP will fulfill these requirements so most facilities will answer ‘Yes’ to all four questions. A ‘No’ answer to any of the four questions will require the answering of a fifth question asking if the facility really wants to submit the ASP anyway.

At that point the facility will be required to identify and describe the documents to be upload to the SSP; the process is described on page 51 of the manual. This will include the completed WORD® file downloaded as part of the ACC ASP Guidance document. Supporting diagrams, maps, photographs and supporting documents will also be uploaded at the same time.

According to the SSP Instructions Manual once the data is uploaded, the CSAT SSP tool will take the submitter to the validation portion of the submission at the end of the tool. From that point on the process will be the same as for those facilities completing the standard SSP.

Other ASPs


While the ACC really designed their ASP for the use of their member companies, they are not stopping others from using the ASP. While I don’t see why any type of high-risk chemical facility couldn’t use the ACC ASP, I understand that there are other industry organizations that are working with DHS to get ASPs of their own design approved; designs one would expect to be tailored to facilities within that type of industry.

The one group that might have concerns with this ASP would be colleges and universities. Educational organizations have been pressing DHS to develop an ASP particularly for their ‘unique’ situation since the CFATS program was first introduced. I suspect that they will continue to have a hard time accepting that DHS actually intends for them to put significant security measures in place at their facilities that DHS has judged to be at high-risk of a terrorist attack. They will continue to hope that an ASP will be able to be used as a dispensation from the CFATS risk-based performance standards requirements. The ACC ASP will severely disappoint the scholarly community.

ISCD and the ACC ASP


I have not yet seen an official notice from the folks at ISCD that they will ‘accept’ an ACC ASP submission and part of me does not expect to. The way that the SSP tool handles the ASP submission process, there is nothing involved that would identify a submission as being made via an ACC ASP. Theoretically, a facility could submit any sort of document using the procedures that I have described above as an ASP. The SSP tool would accept it.

That, doesn’t mean, of course, that ISCD would actually use the information submitted. Scott Jenson and Bill Erny from ACC both assure me that DHS has told them that information submitted via the ACC ASP format meets the needs for their analysis. That means that ISCD knows where to look for the specific information that they need to evaluate the SSP/ASP submission. Some other format that hasn’t been pre-cleared with ISCD may not provide the needed information or may provide it in a format that is not easily decipherable by ISCD. ISCD is having a hard enough time getting the information they need from a straight SSP submission; they are not going to waste any time trying to decipher something that they don’t understand.

ISCD Improving SSP


I understand that ISCD has folks working on a plan to improve the current SSP submission process. I fully believe that they would do well to take a hard look at the format used by the ACC ASP and adapt it to an on-line submission process. They should definitely strive to have the printed document from the end of that submission process be in a format that the average corporate reader or chemical facility security inspector could readily read the document and find the information needed to implement or audit the implementation of the Site Security Plan.

Lacking that sort of fundamental change I would like to suggest that ISCD should consider including a specific template for the submission of the ACC ASP (and any other subsequently approved ASP format). If I were setting it up I would have a separate upload of each of the sub-paragraphs listed on the ASP Table of Contents page. Each sub-paragraph would be a separate file and it would be easy to parse those files to the appropriate analyst at Headquarters for the evaluation of the SSP/ASP. It would also make it easier to make subsequent changes to the SSP/ASP, requiring only a submission of the portions that will be changing.

Recommendation – Two Thumbs Up


Just in case I haven’t made it clear in my analysis to date, I really do believe that the ACC ASP is a significant improvement over the current SSP submission. The folks at ACC are to be commended for the work they have done on the document. I highly recommend that any high-risk facility that has yet to submit their SSP consider using this ASP template for their submission. Facilities that have yet to have ISCD authorize previously submitted SSP’s (and there is a large number of those) needs to contact ISCD and see if changing to the ACC template would make the approval process any easier.

Saturday, January 5, 2013

ACC ASP – Template


This is the fourth in a series of blog posts about the recently published American Chemistry Council Alternative Security Plan for the CFATS program. The earlier posts are listed below. This post will look at the “ACC ASP Template Final20121107” (Template) Word file that is imbedded in the “Alternate Security Program (ASP) Guidance for CFATS Covered Chemical Facilities” (Guidance document) that forms the core of the downloadable program.




Protective Markings


The template is essentially the same as the last twenty pages of the on the instructions that I discussed in the earlier post. There are, however, some important differences between the two. First the template includes all appropriate Chemical-Terrorism Vulnerability Instruction (CVI) markings that will have to be on the document when it is submitted to DHS, including front and rear ‘cover’ pages and a footer “warning” statement. As soon as any facility information is placed in the template it becomes a document requiring CVI protection.

Any attached documents will require the same cover pages and page markings. Cover pages can be found on the CVI web page.

Formatting


The basic format of the document is an outline based upon the outline found in the Table of Contents. The outline markings are based upon bullet points instead of letters or numbers. If you want to change it to a more classical outline that allows easy reference to the paragraphs within the sections that can easily be done in Word®. Personally I would use a numbered outline system for reasons that will be clearer shortly.

Unlike the template found in the Instruction document, the page numbering on the Table of Contents page is not actually linked to the section headers. One of the last things that you are going to want to do before submitting the completed ASP document in the DHS CSAT SSP Tool will be to put the appropriate page numbers in the Table of Contents. This will actually make it easier to copy sections from the template into separate documents to farm out the completion of the information to different people or teams. Again, remember that the CVI marking and protection rules will have to followed for those abstracted sections as soon as any facility information is entered.

Duplicate Information


There will be places in the document where the same information will be entered in different places. While DHS won’t be concerned about seeing duplicate (the key here is that it really is duplicate) information in multiple places, there is a good reason for not writing the same information in more than one place. If you have to go back and make a change to it for some reason you may miss one or more iterations.

It will be more effective to write it one time and then refer back to it in later places in the ASP documentation using conventional notations like “{See Section 5.2(a)(1)}”. This is the reason that I suggest using number (or lettered) paragraphs within each section instead of bullet points.

Detailed Information


This bears repeating, one of the main problems that DHS has encountered with their SSP authorization process has been that an inadequate amount of information describing parts of the security process for the facility has been included in the SSP submission. While the ASP process makes submitting the information easier (and subsequently more useable) there still needs to be a sufficiency of information provided.

Remember, analysts will be sitting in an office building somewhere reading the information provided by the facility trying to determine if the security measures provide an adequate measure of protection for the facility at its present tier level. Telling them in section 5.1 that there is a chain-link fence around the facility perimeter is not adequate information, they need to be told something like this:

“The facility is protected by 1,257 feet of commercial grade chain link fence. All segments of the fence are 8 foot tall with an outward-facing 18” top-guard with four strands of razor-wire. Corner posts have two top guard supports at a 90 degree angle from each other. Fence posts are set in three foot of concrete and placed at no more than 15 foot intervals. A single course of cinderblocks set in an 18 inch deep concrete footing runs under the fence fabric between each post with anchors placed no further than three feet apart to attach the fence fabric to the cinder block.”

Okay, my fence is a bit of overkill, but it is completely described.

Not Too Much Information


Remember that every detail that you put into the ASP submitted to ISCD is an inspectable part of your site security plan. To change any of those details you have to re-submit the revised ASP and hope that it passes muster with DHS. If you make changes without that pre-approval, it could cost you up to $25,000 per day, or, in the worst case, cause DHS to issue a facility closure order.

The area that will probably cause the most problem for this is not the physical plant. The more likely area will be in processes and procedures. Where possible the process or procedure documents will be maintained in documents separate from the ASP and the title of the appropriate document will be mentioned in the ASP where necessary.

For example if you use padlocks on unloading valves as part of your process to protect access to a COI you are going to have to have some method to maintain control of the keys to those locks to prevent that unauthorized access. Rather than outlining your entire key control process you could explain that: “The keys for those valve locks are maintained in the locked key box in the Shift Supervisor’s Office and are only issued in accordance with the provisions of the Facility COI Key Control Procedure.” Once part of the authorized SSP, that wording would allow a Chemical Facility Security Inspector (CFSI) to verify that the process in that procedure was being followed, but not to evaluate the details of that process.

It would probably be a good idea to maintain a list of all of the referenced processes and procedures in Section 1 of the ASP.

Key Words and Phrases


One of the things that does not receive enough emphasis in the supporting documentation for the ASP is the importance of using certain key words and phrases when describing facility security measures. These key words and phrases can be found in the RBPS Metrics for each Risk-Based Performance Standard in the RBPS Guidance document.

For example section 5.1 of the ASP calls for a description of ‘Vehicle Barriers’ and the Security Metric 1.2 for Restrict Area Perimeter (pg 29) Tiers 1 and 2 calls for “Entrances equipped with traffic control systems to slow incoming traffic…”. Given that combination I would suggest that the description start with:

“The single vehicle gate is equipped with traffic control devices to slow incoming traffic. The traffic control devices consist of ….”

Memorandum of Understanding


There are a number of references to “MOU in place” in the “Emergency Responders, Off-sit” paragraphs of Section 2 of the ASP. An MOU is a memorandum of understanding between facility management and an organization outside of the facility (local police, fire departments, or emergency medical services for instance) that is providing some sort of support to the facility Site Security Plan.

As long as the facility is relying on an outside agency as part of its SSP, it needs to be able to show that the agency is prepared to provide the necessary services. The MOU needs to specify what type of support will be provided, under what circumstances, and what type of response time could be expected. Probably the most important aspect of the MOU is that it needs to be signed by an appropriate official of the supporting agency.

One More Posting


The next and final posting in this blog series will address how the completed ASP is submitted to DHS.

Wednesday, December 26, 2012

ACC ASP – Instructions


This is the third in a series of blog posts about the recently published American Chemistry Council Alternative Security Plan for the CFATS program. The earlier posts are listed below. This post will look at the “Alternate Security Program (ASP) Template Guidance and Instructions” (Instructions) that is imbedded in the “Alternate Security Program (ASP) Guidance for CFATS Covered Chemical Facilities” (Guidance document) that forms the core of the downloadable program.



The Instructions can be found on page 18 of the Guidance document. Click on the first ‘paperclip’ symbol on the page and you will open the file:

ACC ASP Template Guide and Instructions Final20121130.docx

The numbers at the end of the file name may change as the ACC updates and revises this program.

Chemical-Terrorism Vulnerability Information (CVI)


It was mentioned briefly in the ASP Guidance document that everyone that will be accessing the partially completed SSP/ASP document will have to be CVI trained and certified. Once any information about the security of the facility is entered into the template it becomes a document requiring CVI protection. Make sure that everyone who will be working with this information has completed the online training course and copies of their training certificates are on file.

Before You Start


Pages 2 thru 9 of the Instructions provide a general set of guidelines that should be followed when filling out the template. I strongly recommend that the entire team that will be working on the SSP/ASP preparation carefully read those 7 pages of the Instructions and be familiar with the any of the Risk Based Performance Standards (RBPS) in the RBPS Guidance document published by DHS that they may be responsible for. This familiarity will make it much easier to fill in the template with verbiage that includes the key words and phrases in the RBPS that the folks at DHS ISCD will be looking for in their evaluation of the SSP/ASP.

RBPS


There is a brief discussion of the RBPS in the ASP Guidance document and there are two brief explanations of the RBPS in the Instructions, but both documents gloss over a very important point. While DHS may not (prohibited by Congress) specify a particular security measure they do spell out in the RBPS Guidance document the way they will measure compliance (RBPS Metrics) with each RBPS at the specific Tier level to which a facility has been assigned. The difference between the required performance metrics for two different tiers may be one word, eg: ‘routinely’ vs ‘usually’. Including these key words in the description of a security measure may make it easier for DHS analysts to understand the intent of the security plan.

Attack Scenarios


One of the more confusing ideas that DHS included in their CFATS program was the idea of “Attack Scenarios”. Security professionals initially thought that the seven scenarios proposed by DHS were the proposed design basis for the security plans, attacks that had to be prevented for the plan to be successful. That was not the intent of DHS. As the Instruction document explains (pg 3):

“Rather, the attack scenarios are analytical devices, supporting the evaluation of a facility’s security and enabling DHS to conduct comparative risk analysis across the sector.”

The Security Metrics in the RBPS explain how well the facility (at its specific tier level) must be able to deal with those scenarios. As the Instructions document explains, not all attack scenarios apply to each RBPS. But, when they do apply they should be specifically addressed in the words that are put into the template so that it is clear to the ISCD analysts that the facility has addressed the issue.

Security Approach


There is a nice discussion in the Instructions document about the differences between perimeter based and asset based security measures. Essentially, the ‘perimeter based’ approach includes the entire facility whereas the ‘asset based’ approach only provides security measures for a specific area of the facility where a COI is found. For a facility with a single high-risk COI, it may make more economic sense to confine the bulk of the security measures to the area where that COI is used/stored. For facilities with multiple COIs at varying security levels, it may make more sense to protect the facility at the level for the COI with the lowest tier ranking (provided by DHS) and reserve the more complex security arrangements for the area around the highest tier-ranked COI.

As noted on page 5 of the Instructions document:

“In the description of a specific security measure, ASP preparers should describe whether it is applied facility wide or to specific assets.”

Too Much Information


As the Instruction document alludes to, the problems that ISCD has had with not being able to authorize SSPs have been in large part due to not receiving enough information from the facility about their security plans. So generally speaking, the more the better, but there is a limit. As the Instructions document states on page 7:

“On the other hand, the preparer may wish to limit detail that does not relate to the listed COI or the performance of the specific security measure or system, to allow for minor changes without the need for ASP resubmission.”

This is an important point that needs to be clearly understood by facility management. Once the SSP/ASP is authorized by DHS it is essentially a legally binding document outlining the inspectable requirements for facility security under the CFATS program. The congressional prohibition against specifying particular security programs no longer applies. If a subsequent ISCD inspection does not find an authorized component of the SSP/ASP in place, the facility may be fined up to $25,000 per day or even shut down (an extreme case to be sure) for non-compliance. Any changes to the authorized ASP must be approved by ISCD before they are made.

One way to get around some of this problem will be to include the little details of the plan in separate documents describing specific procedures and processes. The Instructions document notes that:

“It is not necessary to include the text of every procedure that is described in the ASP.  Use an unambiguous reference that is clear to facility personnel and that inspectors can request by name for review, for example, ‘Suspicious Activity Reporting Procedure S.4.01’.”

There must be, however, enough detail in the submitted ASP to allow the ISCD analysts to determine if the RBPS Security Metrics have been met.

Take Credit for Everything


The last topic that is specifically discussed in the first nine pages of the Instruction document is a reminder to take a careful look at everything that the facility does to determine if it contributes to security. Many process safety and almost all emergency response measures already in place at the facility may contribute to the security plan, particularly the ‘Response’ RBPS. Simple things like referring to a COI by a company product name rather than an easily recognizable chemical name will make it harder for an attacker to find their target. Pages 8 and 9 of the Instruction document provides a short list of things to look at.

Just remember, though, if you take credit for it and list it in the ASP you must continue doing it until DHS gives you permission to change.

The Template


The remainder of the 30 page Instruction document is an annotated copy of the template. Explanatory material and completion suggestions are provided in blue type. Almost everything in black type should remain in the submitted document with appropriate additional supporting information. I’ll look at the actual template in some detail in later blog posts.

Tuesday, December 25, 2012

ACC ASP – Guidance Document


This is the second in a series of blog posts about the recently published American Chemistry Council Alternative Security Plan for the CFATS program. The initial blog post is listed below and dealt with an overview of the place of the ASP in the CFATS program. This post will look at the “Alternate Security Program (ASP) Guidance for CFATS Covered Chemical Facilities” (Guidance document) that forms the core of the downloadable program.


There are two embedded documents in the Guidance document; the template and the instructions for the ASP and they form the basis of the actual ASP that will be submitted to DHS as part of the facility site security plan. There is a significant amount of additional information available in the document.

CFATS Overview


The first five pages of the Guidance document provide a fairly detailed guide to the CFATS program. Now anyone who is in the process of considering options for submitting an ASP in lieu of an SSP should be fairly familiar with the CFATS program, so this would seem to be somewhat superfluous.

We have to remember, however, that once a facility reaches the SSP stage of the SSP process, the funding issues become rather large. The upper level management that needs to become involved in the budgeting process at this point could use a high level lesson in the requirements of the CFATS program and these five pages could form a good starting point for that discussion.

Pre-Authorization Inspection


In its discussion of the CFATS inspection process the Guidance document provides a reasonably good description of the purpose and process of the Pre-Authorization Inspection. Since DHS ISCD has yet to formally address this addition to the CFATS program in any of their written documents the following description taken from the Guidance document serves an important purpose;

“Pre-Authorization Inspections (PAI) are conducted AFTER the submission of an SSP/ASP but BEFORE a letter of authorization, in which the SSP/ASP is preliminarily approved as the regulatory standard for that facility. Pre-authorization inspections were instituted after it became clear that the CSAT SSP template was not producing enough detail to result in the issuance of letters of authorization. Their purpose is for the inspection team to establish the facts on the ground and for DHS to provide feedback for both the improvement of the detailed content of the SSP/ASP and potentially for improvements in existing security measures to meet the RBPSs.”

Of course, part of the purpose of the publication of this ASP template and instructions is to provide an initial data submission to DHS and ISCD that precludes the necessity for DHS to conduct such PAIs.

Authorization Inspection Process


The ACC Guidance document provides information on the Authorization Inspection process as well. Again this is another area where detailed information has been lacking from the folks at ISCD, unless they are providing it directly to facilities when they schedule the inspections. In any case, the information provided here will be very beneficial to any facility beginning to prepare for their authorization inspections.

The Appendixes


The Guidance document includes four appendixes that provide a variety of additional information on the CFATS program. The four appendixes are:

• Definitions and Acronyms

• Alternate Security Program Template

• CFATS RiskBased Performance Standards

• CFATS Reference Links

Of the four the second is, of course, the most important for facilities considering the submission of their SSP. It includes two imbedded Word® documents that form the basis for the ASP submission.

• ACC ASP Template Guide and Instructions Final20121130.docx

• ACC ASP Template Final20121107.docx

I’ll discuss these two documents in later blog posts in the series, but I suspect that the ACC will be a tad bit more proactive in updating these files as additional facilities use them to prepare and submit their SSP/ASP

Assessment


I think that the ACC has produced a very good CFATS summary document here. In many cases it is more informative than the formal DHS documents upon which it draws. The major drawback is that it spends almost no time discussing the preparation of the ASP. While that is covered in the imbedded instruction document, it would be helpful if there were some discussion here about some of the ASP/SSP issues.

For instance, there is nothing said about the relationship between an adequate level of information necessary for DHS assessment and the need to leave room for minor modifications in the program that won’t require a resubmission of the ASP. Too much detail and the smallest change will have to go through a long-delayed reassessment process at ISCD. Too little detail and the facility will have to go through the added problem of an AIP inspection.

Additionally, I think that there should be a little more emphasis on the fact that any security procedures, processes and equipment mentioned in the authorized SSP/ASP become a regulatory requirement for the facility in all future DHS-ISCD inspections. While DHS cannot specify which security processes need to be employed to get an SSP/ASP authorized, they can and will require strict adherence to the authorized SSP/ASP.

I’ll look at how these issues are addressed in the instructions and template in future blog posts.

All and all this is a much better document than anything that the folks at DHS have done for the SSP process.

Sunday, December 23, 2012

ACC Publishes CFATS Alternative Security Program


On Friday the American Chemistry Council posted their “Alternate Security Program (ASP) Guidance for CFATS Covered Facilities” on their web site. This .PDF document, along with its two embedded .DOCX documents provide information and a template for submitting an alternative (this is the DHS terminology) security program to DHS in lieu of the complete Site Security Plan DHS provides on its Chemical Security Assessment Tool (CSAT) site.

ASPs


Section 550(a) of the Homeland Security Appropriations Act of 2007 specifically authorizes the DHS Secretary to “approve alternative security programs established by private sector entities, Federal, State, or local authorities, or other applicable laws if the Secretary determines that the requirements of such programs meet the requirements of this section and the interim regulations”.

In a number of Congressional hearings I have heard Congressmen incorrectly explaining to industry and DHS witnesses that the ASP allows DHS to “give industry credit for work they have already done on site security”. This is very misleading in that there are no provisions in the law or regulation that allows the approval of an ASP for a security program that does not meet the standards set forth in the Risk Based Performance Standards (RBPS) Guidelines document based upon §27.230 of the CFATS interim regulations.

Nor does the preparation of an ASP obviate the need for using the Site Security Plan tool within CSAT. The SSP tool will, in fact, be the tool used to submit the ASP. After the facility ensures that the Facility information portion of the tool has been completed, the SSP tool {Site Security Plan Instruction Manual, pg 29} will ask four questions about the potential use of an ASP:

• Does the ASP address each security/vulnerability issue identified in the facility’s SVA, and identify and describe security measures to address each such security/vulnerability issue? [Q:5.61-18413]

• Does the ASP identify and describe how security measures selected by the facility will address the risk-based performance standards and potential mode of terrorist attack? [Q:5.61-18414]

• Does the ASP identify and describe how security measures selected and utilized by the facility will address each applicable performance standard for the appropriate risk-based tier for the facility?

• Does the ASP provide other information that the Assistant Secretary has deemed necessary, through the DHS Final Notification Letter or other means, regarding facility security? [Q:5.61-18416]

Only if a submitter can answer ‘Yes’ to all four questions should the ASP be submitted.

So, if all of the work necessary to prepare an SSP has to be done anyway, why use an ASP? The answer is three-fold.

First, the document that a facility will upload to the SSP tool for their ASP (in the case of this ASP in any case) will actually be able to serve as a formal site security plan. The document will actually be able to be read and understood by both facility personnel and DHS Chemical Facility Inspectors, and the information will be readily accessible. The same cannot be said for the printed copy of the question/answer format of the DHS SSP tool.

Second, we know that the current SSP tool has proven to be totally inadequate as an effective data collection device. The routine responses to the questions asked in the tool have not provided adequate information for DHS analysts to determine if the facility site security plan adequately addresses the RBPS guidelines. This ASP does seem to me to better address the data collection needs of DHS, making for a smoother SSP approval process.

Finally, at the end of the day, the approved SSP (SSP/ASP) will serve as the standard by which the facility security program is measured in all future inspections by DHS. A formal document like the one prepared in this ASP will be a much better reference for facility personnel and DHS inspectors to go back to determine what the actual approved security program is for that facility; something that cannot be easily done with the current SSP tool format.

The ACC ASP


The American Chemistry Council is a large industry group that represents a significant portion of American chemical production companies. They developed this ASP principally as a tool for their member organizations that have facilities covered by the CFATS program. As I currently understand things the ACC will allow anyone to use their ASP. There is no log-in required to be able to download the document and the ACC has no way of know who uses their format to submit data to DHS.

As would be expected, the ACC is not making any specific claims about the use of this ASP; they have no control of the information the facility places within the document. Their guidance document clearly states that:

ACC takes no responsibility for any action taken by an individual ACC member or other party.”

The format and style has been approved by DHS. That does not mean that DHS will automatically approve an SSP submitted using this format. It simply means that DHS has worked with ACC and that the format, properly executed, should be able to provide the necessary information in a format that DHS can use to evaluate the efficacy of the facilities SSP.

According to Scott Jensen, Director for Issues Communications at the ACC, there have been at least two facilities that have used this ASP to complete their SSP filing. In both instances, the folks at DHS used a protocol that was used very successfully in the development of the Top Screen and the Security Vulnerability Assessment tools; they had folks (analysts and inspectors) on site during the submission process to see how things actually worked on the ground. Their feedback along with comments from the facility teams, allowed the ACC to do the fine tuning necessary to make this a workable ASP format.

More Work Required


One thing is very clear to me, it is going to take much more work to complete the ACC ASP than it would be to answer the questions in the DHS SSP. Writing out the information in clear and understandable prose can be hard work, much harder than clicking on boxes or preparing short answers to specific questions. On the other hand nobody has gotten a site security plan authorized based upon the submission of the SSP tool. DHS has had to come back and dig for additional information to get what they needed.

Additionally, the facility was going to have to write a useable site security plan document in any case and that was going to be duplicative work. Why not use the same document to fulfill both requirements?

Future Posts


As my long time readers will have come to expect, I’ll be taking a more detailed look at the ACC ASP in future blog posts.

Friday, January 22, 2010

Site Security Plan Article

This is an interesting period for the chemical security community. The Senate is getting ready to start working on CFATS legislation while there is a renewed interest in general on counter-terrorism issues. Tier 1 facilities are starting to go through the inspection process while the other tiers are finishing up their SSP submissions. This renewed emphasis on CFATS is reflected in a number of magazine and web articles on the process. I recently found one such article on SecurityManagement.com; “The Skinny on CFATS”. Site Security Plan This article by Joseph Straw gives a good feel for the Site Security Plan process even if it lacks on details on how the process works. It does make a good point that the name of this phase of CFATS implementation is more than a little of a misnomer. As I have mentioned in other blog postings, a ‘plan’ normally connotes an organized document that lays out objectives and explains how they will be met. As this article explains the SSP is not really a plan, but rather a lengthy questionnaire about the security measures in place at the facility. Even that is a simplification of the SSP process. Unless a facility has been hard at work in upgrading their security measures to meet the risk based performance standards (RBPS) outlined in last year’s RBPS Guidance Document, it is extremely unlikely that ‘current’ security measures in place will be enough to get an SSP approved. But DHS has a simple solution to that problem, they will give you credit in the SSP for ‘Planned Security Measures’ as long as the facility can demonstrate that there is really a plan firmly in place for implementing those measures. The article also makes the point that the SSP submission/approval process is more like a negotiation between the facility and DHS. Since DHS is prohibited by statute from specifying particular security measures in the SSP approval process, a facility just has to be able to demonstrate that their particular combination of security measures fulfills the performance criteria of the RBPS. The article does kind of gloss over one final point on the SSP process, however. Once the SSP submission is approved, DHS looks on that document as a ‘security contract’ between that facility and DHS. All subsequent inspections by DHS will be done to ensure that the facility is in compliance with that now enforceable contract. The §550 prohibition against ‘requiring specific security measures’ will no longer apply to that facility. If the facility said that it would have a security measure in place, then DHS will expect to find it in place when they come to inspect. ‘Planned Security’ measures must be proceeding according to the documented plan. Alternative Security Plans The article does mention that there is an alternative to completing the ‘1,500 questions’ in the SSP tool, the submission of an ‘alternative security plan’ (ASP). Conceived in the §550 language this was included to ensure that facilities with an already existing robust security plan would not have to re-invent their plan. DHS has expanded the idea to allow any facility to upload a security plan into the SSP tool as an alternative to answering most (certainly not all) of the questions in that tool. Given the ‘problems’ that facilities had in getting initial approval of their security vulnerability assessment (SVA) using an alternative security plan in lieu of answering the SVA tool questions, I doubt that there will be many facilities that will get initial acceptance of the ASP. That certainly does not mean that facilities, particularly those single COI facilities mentioned in the article, should not try this option. Just expect to have to answer directed questions from DHS about RBPS issues not well addressed in the ASP. Facilities planning on submitting an ASP should probably do a quick look at the SSP questions to see what type of information DHS is requesting. Ensuring that the appropriate information is in the ASP before it is submitted will help getting it approved. A large number of the questions in SSP would be expected to be answered in the negative for most facilities, those negative responses wouldn’t need to be included in the ASP. But if something is in the SSP and the facility has it as part of their security set-up it needs to be included in the ASP submittal. Other Articles This is not the only article currently out there about the CFATS program. While I may not be able to review all of them, I certainly want to point my readers at as many of these articles as possible. If I miss any, please let me know either by email or as a comment to this blog posting.

Wednesday, February 18, 2009

CFATS and Research Labs

An alert reader sent me a copy of a portion of a newsletter sent from the Council on Government Relations (COGR) to its member colleges and universities (see page 9 of the complete document). It discusses the results of a couple of meetings between DHS and a variety of organizations representing colleges and universities about the level of compliance of educational laboratories with the reporting requirements of CFATS. DHS was aware early on that there would be a number of college and university labs that would fall under the CFATS definition of a chemical facility. Because of the chemical and biological research done at some of these facilities it was inevitable that a significant number of these facilities would be required to submit a Top Screen because they had more than a STQ of one or more DHS chemicals of interest (COI) on site. And, because of the potential threat presented by these chemicals, some of those facilities would be declared by the Secretary to be high-risk chemical facilities that would have continued responsibilities under CFATS. Top Screen Submissions According to this newsletter a total of 380 college and university facilities submitted initial Top Screens. Of these 204 were declared high-risk facilities. The tier rankings are provided below. It should be noted that the Tier 1 facilities are the highest risk facilities in the rankings.
Tier 4 112 Tier 3 56 Tier 2 30 Tier 1 6
It should be noted that that this is a much higher ‘high-risk’ rate than the general run of Top Screen Submissions. There were a total of about 35,000 Top Screens resulting in a little over 7,000 high-risk facilities or one-in-five. School labs had a closer to one-in-two rate. The reason is probably related to the fact that most of the COI found at these labs above the STQ were theft/diversion COI instead of release COI. Compliance Outreach The newsletter goes on to say that DHS believes that the number of Top Screen submissions was significantly lower than what it should have been. Apparently DHS made it clear that they did not believe this was due to willful non-compliance, but rather an inadequate understanding of the requirements. COGR claims that DHS plans to do a pilot program of compliance checks on select schools in New York and New Jersey. First they would look in the literature for the types of research being done at high-risk labs. They would then look for schools with similar research programs that did not submit Top Screens. Those schools would get ‘on-site’ visits to determine if the school did not understand the requirement, or that they made a legitimate determination that they did not need to file a Top Screen. Interestingly the folks at DHS claim that they have no such plans. My sources explain that DHS has informed COGR that they reserved the right to call any site, university or otherwise, to ask why they did not do a Top-Screen. It would seem like the COGR plan would be an expensive effort, especially while the SSP roll-out was still pending. Besides, there are almost certainly more risky facilities out there than the odd college lab; that’s where I would bet that DHS would expend its limited inspector force looking for non-compliant facilities. Facility Description Complications One of the problems that DHS is certainly going to run into is how to define what a chemical facility is in a college or university setting. In the preamble to the final rule, DHS made it clear that they did not expect the facility to be defined as the entire campus and would allow schools a large measure of latitude in how they defined their facilities. Potentially, a school could take this to an extreme and count each individual laboratory as a separate facility; this would greatly reduce the number of potential facilities with an STQ of a COI. Looking Ahead to SSP The two hundred some odd high-risk labs identified so far are looking forward with some trepidation to developing their site security plans. The educational institutions have a number of concerns about the draft guidance document issued in November and its impact on their SSP’s. They are concerned that the interpretation of the risk-based performance measures outlined in that document was targeted at industrial rather than research facilities. This newsletter briefly addresses these concerns. The COGR notes that the Campus Safety Health Environmental Management Association (CSHEMA) is in continuing discussions with DHS to try to “integrate the Performance Standards into an Alternative Security Plan that is flexible enough to be used as a template by institutions”. This was not the original intent of the ASP program. Again going back to the final rule preamble, DHS intended for facilities that had already developed and implemented a site security plan that conformed to the Center for Chemical Process Safety (CCPS) guidelines to be able to use that plan in lieu of the CSAT based format. DHS might find it expedient to allow the laboratory community to come up with such a template.
 
/* Use this with templates/template-twocol.html */