Showing posts with label Background Checks. Show all posts
Showing posts with label Background Checks. Show all posts

Wednesday, September 17, 2014

Bills Introduced – 09-16-14

As the first part of the pre-election recess nears the number of political posturing bills being introduced increases. Yesterday there were 55 bills introduced in the House and Senate. Amongst the posturing were two bills that may be of specific interest to readers of this blog:

HR 5482 Latest Title: To enhance the Office of Personnel Management background check system for the granting, denial, or revocation of security clearances or access to classified information of employees and contractors of the Federal Government. Sponsor: Rep Kelly, Mike (R,PA)

HR 5488 Latest Title: To require a review of the completeness of the Terrorist Screening Database (TSDB) maintained by the Federal Bureau of Investigation and the derivative terrorist watchlist utilized by the Transportation Security Administration, and for other purposes. Sponsor: Rep Jackson Lee, Sheila (D,TX)


The first may contain provisions that will affect the approval of security clearances for critical infrastructure personnel that would be necessary for obtaining intelligence information about potential threats. The second may contain provisions that would affect the security threat assessments conducted by TSA for TWIC, HME and CFATS programs.

Wednesday, April 24, 2013

Bills Introduced – 4-24-13


Yesterday there was just one bill introduced in Congress that would probably be of interest to the chemical security community. It was:

S 792 Latest Title: A bill to strengthen the enforcement of background checks with respect to the use of explosive materials. Sponsor: Sen Lautenberg, Frank R. (D,NJ)

The ATF already does background checks on people that it licenses to handle explosives so it will be interesting to see what Sen. Lautenberg is proposing to add to the mix.

Tuesday, July 6, 2010

First Responder Background Checks

In Saturday’s blog about the FAQ updates I kind of glossed over the DHS response to question 1368 since the answer wasn’t new. That question dealt with whether or not first responders like fire department personnel are required to under go background checks under the CFATS rules. The DHS response to that question was a straightforward:
“6 CFR Part 27 does not require that fire department personnel undergo background checks.”
At first glance that seems to directly contradict the CFATS regulations. Section 27.230(12) outlines the risk-based performance standards requirements for personnel surety. It explains that the facility would need to conduct “appropriate background checks on and ensure appropriate credentials for facility personnel, and as appropriate [emphasis added], for unescorted visitors with access to restricted areas or critical assets”. 

The words ‘as appropriate’ would appear to give DHS the necessary wiggle room to essentially exempt first responders from the personnel surety program coverage. The exemption would certainly seem to be reasonable. After all, when a fire truck shows up at the front gate with lights flashing on its way to a on-site fire, no one wants to slow them down to make sure that all the firemen are on an approved access list. 

The question then becomes, who else could be covered under the ‘as appropriate’ exemption. Lacking specific guidance from DHS (and that may be coming, according to rumors, in an NPRM outlining a DHS program for TSDB checks) it would be up to the facility to define in its SSP which off-site personnel would be exempt from the background check requirements of its facility personnel surety program. Of course, those exemptions would have to be approved by DHS, so the facility must be prepared to justify those listings. 

There is, of course, another class of people that are already exempted from the personnel surety program requirements, a wide variety of Federal inspectors. Section 27.405(1) makes it clear that the CFATS regulations do not supersede requirements allowing inspectors access to covered facilities.

Sunday, May 23, 2010

SCADA Vendor Support

I just finished reading an interesting article on ControlGlobal.com. It describes ABB’s (a SCADA equipment vendor) ability to provide “advanced diagnostics and data collection tools to provide levels of access and maintainability for ABB equipment or monitoring of PCs in any environment” via remote access. Reading the article it struck me that ABB, and many other SCADA vendors offering similar services, may provide security managers at high-risk facilities with an overlooked security problem. Unescorted Access The CFATS regulations require that facilities conduct a variety of background checks on “for unescorted visitors with access to restricted areas or critical assets [emphasis added]” {6 CFR 27.230(a)(12)}. It would seem to me that even the most restrictive definition of ‘critical assets’ would include SCADA and industrial control systems at CFATS covered facilities. A vendor technician working on such systems on site would certainly fall under the ‘unescorted visitors’ definition unless accompanied by some one qualified to understand what the tech was doing with the cyber system. What would make that same technician exempt from the background check requirement if they were accessing the system from off-site? Any such off-site access must be considered ‘unescorted’ access to a critical asset. Two Options Now as I see it, there are at least two options. First CFATS covered facilities could shut down the off-sit access capabilities of these vendors. There is certainly a security argument to be made for that option. Unfortunately, most facilities do not have anyone on the payroll that can conduct the appropriate diagnosis, much less make the repair and adjustments that these vendor offer. Without these on-line services, facilities would have to be shut down until a technician could physically arrive on site; very costly. The second, and more useful, option would be to have these vendors conduct the appropriate background checks for each of their employees that have the access to these systems and to certify that they have met some minimum background check requirements. Of course, this would have to include the check of the terrorist screening database (TSDB) that DHS is requiring all others with access to the CFATS facilities to undergo. The current way that DHS is considering how to implement the TSDB check would require that each facility being served by these vendors would be required to submit data on each of the vendor employees with potential access. Not only would that be time consuming for the facility, but it would raise some privacy issues as well. Additionally that would drastically inflate the number of records that would have to be processed by the DHS folks. Alternatively, DHS could set up their TSDB tool to allow the SCADA vendors to have their own accounts where they would submit the information on their employees. CFATS covered facilities would then identify the vendors that their facility uses that would be authorized off-site access to their control systems. This would allow DHS to identify who had access to the facility equipment and yet protect the privacy of the vendor’s employees. A similar technique could be employed for other companies that have employees with routine access to multiple high-risk facilities. A Not So Minor Problem One small problem with this idea; the CFATS regulations only apply to high-risk chemical companies. DHS does not have the authority to regulate the vendors and contractors that support the covered facilities. Just one more thing that needs to be added to the re-authorization of CFATS.

Monday, August 17, 2009

CVI for Sales People

It is amazing where you find CFATS information on the web. Thanks to Google® I found a press release for “Henry Bros. Electronics, Inc. (Nasdaq: HBE), a turnkey provider of technology-based integrated electronic security solutions”. It is a press release announcing their second quarter results. While you would expect that they would talk about their sales into the chemical sector, they actually spent more time talking about Chemical-Terrorism Vulnerability Information (CVI). They note that:
“We are also positioning ourselves to benefit from activity coming from the new Chemical Facility Anti-Terrorism Standards (or CFATS) legislation. Before a company in our industry can even speak with a prospective CFATS client, you are required to have a CVI number, which encompasses the passing of a qualifying test to be registered. To date, 19 of our sales people have qualified for their CVI number, and we expect to focus intently on this potentially lucrative market over the next six to eight quarters.”
CVI Requirements for Contractors I’m not sure that it would be absolutely necessary for a contractor to be CVI certified to be able to sell, install and service a ‘technology-based integrated electronic security solutions’. As long as the contractor was not privy to actual SVA or SSP documents the only CVI restrictions would be those under §27.400(b)(6), “Any records required to be created or retained by a covered facility under §27.255”. Those records would be associated with training records or maintenance, calibration and testing of security equipment. If those records were maintained by facility personnel then the CVI rules would probably be met without contractor certification. Having said that, I think that a CVI certified sales force would certainly be a good sales point for a security related contractor. If I were a facility security officer, I would also probably ask about the CVI status of maintenance and back-office people since they would also have access to ‘sensitive information’ about the security systems. While records developed and maintained by this third-party are not technically covered by the CVI rules, they do contain nearly identical information to covered records maintained by the facility. This is a major loophole in the CVI rules, but one that cannot be easily closed. So it would be reasonable to ask contractors to protect this information as if it were CVI, and that would only be possible to do if they had received the CVI training. Background Checks One item that was not mentioned in the press release is the matter of background checks having been conducted on the company personnel. DHS does not currently (because it is prohibited by §550 restrictions) specify what background checks are adequate for high-risk facilities other than the review of the TSA terrorist database. If contractor personnel are not given ‘unescorted access to critical areas’ of the facility, it is not clear that CFATS rules require any level of background checks. Most security related companies have their people bonded, so some level of background checks have been done. We have not yet seen the details of the CSAT application that DHS is developing for the TSDB check, but it may not be accessible by contractors. The explanations given to date indicate that only CSAT registered facilities will have access to the TSDB check tool. This would mean that contractors would not have access because they would not be registered in CSAT. It would be helpful if DHS would make provisions for contractors to be able to access the TSDB check tool.

Monday, June 29, 2009

TSA Finalizes Background Check Regulation

In Friday’s Federal Register the Transportation Security Administration published a final rule implementing sections 1414(e) and 1522(e) of the 9/11 Act prohibiting public transportation agencies, railroad carriers, and their respective contractors and subcontractors from knowingly misrepresenting Federal guidance or regulations concerning security background checks for covered individuals. The legislature included these sections in the 9/11 Act because they were concerned that employers would use the background check requirements as a cover for personnel actions that would not be permitted under normal labor relations laws. In July of last year TSA published an interim final rule (IFR) adding §1570.13 to 49 CFR (73 FR 44665). With the publication of that IFR TSA requested public comments. No comments were filed by the time the comment period closed September 2nd, 2008. With the lack of public comments, TSA has decided to publish this final rule making permanent the provisions of 49 CFR §1570.13. This final regulation is effective as of June 26th, 2008 when it was published in the Federal Register. Since there is effectively no change being made to the rules, TSA does not need to give advance notice of the effective date for this final rule. Similar wording to §1414(e) and §1522(e) is being included in the Chemical Facility Anti-Terrorism Act of 2009 (HR 2868) because specific background check guidance is provided in that legislation. One would expect that DHS would include wording similar to §1570.13 in any revisions required to 6 CFR part 27 if HR 2868 were to pass this year.
 
/* Use this with templates/template-twocol.html */