Showing posts with label CFATS PSP. Show all posts
Showing posts with label CFATS PSP. Show all posts

Saturday, March 3, 2018

CFATS PSP ICR Revision Comments – 03-03-18


Back in December the DHS Infrastructure Security Compliance Division (ISCD) published a 60-day information collection request revision notice for proposed changes to the personnel surety program (PSP) for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Comments on the proposed extension of the anti-terrorist screening requirement to Tier III and Tier IV facilities were solicited. This is the second look at comments received on this ICR. The earlier comment review can be seen at:


The comments posted this last week (and the comment period officially ended on February 26th) came from four organizations representing groups of chemical manufacturers (links are for .PDF downloads):


As was noted with last week’s comments, these industry groups are generally supportive of the PSP process. There are, however, two retread arguments in this weeks comments that have been seen in responses to all of the earlier versions of this ICR; already screened individuals and notification about TSDB positives. Both of these issues were specifically dealt with when the current ICR was approved.

We continue to see calls a review of the implementation of the TSDB screening at Tier 1 and Tier 2 facilities. ISCD has almost certainly conducted an internal review as a basis for many of the changes in burden estimates included in this ICR notice. What these organizations are calling for is a more formal, published review; with some calling for an outside review. I think that a published review would be beneficial, particularly if it included anonymized data on the number of TSDB positives.

Since Congress will be (hopefully) working on the reauthorization of the CFATS program this year, such a formal review of the TSDB screening would be helpful in determining whether or not Tier III and Tier IV facilities should be impacted by this requirement. Currently, this TSDB screening is required for all covered facilities by regulation {6 CFR 27.230(a)(12)(iv)} and authorized by statute {6 USC 622(d)(2)} so I suspect that Tier III and IV facilities will be subject to the TSDB screening unless specifically excepted by Congress.

The ICR approval process for can be lengthy, particularly for controversial (read potentially expensive) programs such as this. This is due to the requirement for an essentially political review in the OMB’s Office of Information and Regulatory Affairs (OIRA). It is highly unlikely that we will see the required 30-day ICR notice (much less an approved ICR) before December 18th when the current CFATS authorization runs out. So Congress will have a chance to weigh in on the topic.

Saturday, February 24, 2018

CFATS PSP ICR Revision Comments – 02-24-18


Back in December the DHS Infrastructure Security Compliance Division (ISCD) published a 60-day information collection request revision notice for proposed changes to the personnel surety program (PSP) for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Comments on the proposed extension of the anti-terrorist screening requirement to Tier III and Tier IV facilities were solicited. The first comments were received this week.

Comments were received from (links are .PDF downloads):


Rather than the general opposition to the PSP process that marked many industry comments on earlier iterations of the PSP ICR process, these three comments raised some interesting questions (and generally provided potential solutions) arising from the expansion of the PSP terrorist vetting program.

Some detailed questions were raised about the assumptions that were made by ISCD for calculating the average burden estimate. It would seem that ISCD has a better basis for making these estimates now that they have worked closely with Tier I and Tier II facilities in implementing the PSP submissions, but legitimate questions have been raised about differences between the types of facility included in the two different risk categories of facilities.

There close of the comment period is Monday, so there is a decent chance that there will be more comments posted to the www.Regulations.gov web site for this ICR. ISCD will take some amount of time to review the comments and address them as they determine appropriate. ISCD will then publish a 30-day ICR notice before sending the ICR to OMB for approval. It could still be six months to a year or more before OMB approves the expansion of the PSP terrorist screening process. And we have to remember that Congress will have a chance to weigh in on the process (again) when they (hopefully) reauthorize the CFATS program later this year.

Friday, June 19, 2015

EO 13650 Update Webinar

As I mentioned last week the Chemical Safety and Security Working Group held a webinar earlier today to update the progress that has been made by EPA, DHS, OSHA and ATF on implementing the plan that they presented to the President last year at the conclusion of their initial work on EO 13650 Improving Chemical Facility Safety and Security.

I have the same minor complaint about this webinar as I had about the one they held last November; the four presenters basically read the information that I have already pointed out on the OSHA web site. The Working Group did not make available a copy of the slides used for the presentation, but there wasn’t much on them in any case. I would like to thank the folks over at the TaoCompliance web site for making a set of the slides available.

OSHA-EPA Questions

The question and answer portion of the webinar provided some interesting conversations between the regulators and the regulated community and a couple of environmental activists. There were some interesting points made about the changes being made to the PSM (OSHA) and RMP (EPA) regulations that will be coming about because of the EO. What was missing from that conversation, however, was any details about the two subjects of most interest; inherently safer technology and REGAGEP. The most commitment we heard on those topics came from Mathy Stanislaus was that the EPA expected to have a formal guidance document on IST available in the fall of 2016.

The biggest disappointment came when Lisa Long (for OSHA) reminded folks that it normally takes OSHA 6 to 8 years to field a new standard. This was in response to a direct question about when OSHA expected to have their new PSM NPRM published. To be fair she did not say that the PSM update would take 6 to 8 years; she was using those figures to call for patience.

CFATS Questions

I did get a chance to ask David Wulf (Director of Infrastructure Security Compliance Division at DHS) about two chemical security issues; the final rule on ammonium nitrate security (carefully not mentioned on the OSHA update web site) and the CFATS personnel surety program (PSP). David gave the same answer that we have heard for the last two or three years; the final rule is being reviewed within the Department. In the past that has been clarified to mean outside of ISCD. So essentially the politicians and lawyers are playing with it.

The most surprising answer came with respect to my question about the PSP. David said that he expected OMB (meaning their Office of Information and Regulatory Affairs - OIRA) to approve the ICR in the near future. What escaped notice of most people on the webinar is that he could have only been referring to the controversial information collection request that was submitted to OIRA in February of last year.

I was pretty sure that the personnel surety program requirements in HR 4007 would have pre-empted that ICR. I’m absolutely certain that the authors of HR 4007 intended it to pre-empt that ICR. I am going to have to go back this weekend and make a detailed comparison between the two to see how Wulf intends to pull this off.

One thing that he did promise, and again many in Congress and industry will not be happy with this, was that once the ICR was approved ISCD would publish a notice in the Federal Register about how facilities would be implementing the PSP in accordance with that ICR (and presumably the new CFATS statute). Many in industry have been expecting this to be a rule making activity requiring the publish and comment process. Wulf (and most people at DHS) have always expected the current language of 6 CFR 27.230(a)(12) to cover the PSP requirements so that no change to the regulation is needed.


And Wulf did mention in his prepared comments that the CFATS regulation update process that was started last year with the publication of the ANPRM. He noted that ISCD is still reviewing those comments, the comments at the poorly attended public meetings, and is moving forward with preparing the NPRM. No word on when to expect it and I would have been very surprised if there had been any commitment on even a rough date.

NOTE: The audio for this webinar is now available at  https://share.dhs.gov/p7c2wwd99se/. The slides were not worth much so this audio file should pretty much duplicate the webinar except for the ability to ask questions. Updated 6-26-15 9:45 CDT

Sunday, August 10, 2014

TSA Revises STA System of Records

The DHS Transportation Security Administration (TSA) is publishing a notice in Monday’s Federal Register (79 FR 46862-46866) concerning changes being made to the DHS Privacy Act System of Records for the Security Threat Assessment (STA) program. This is the system of records that TSA uses to collect and maintain information on STA’s and employment investigations for programs like the Transportation Worker Identification Credential (TWIC) and the Hazardous Materials Endorsement (HME) for State commercial driver’s licenses.

TSA is modifying the “Purposes” portion of the system of records description to update the actual uses TSA and DHS make of the information collected in the STA program. One interesting change is moving two categories of records (‘known or suspected terrorists’ and personnel requesting redress actions) from the “Categories of individuals” to the “Categories of Records” section of the description.


Interestingly, there is still no mention in this revised description of the STA system of records for use by the Chemical Anti-Terrorism Standards (CFATS) program’s personnel surety program (PSP). The OMB’s Office of Information and Regulatory Affairs (OIRA) still has not approved the CFATS program’s personnel surety program (an very likely will not until it Congress acts or fails to act on the CFATS bill (HR 4007) now pending in the Senate.

Wednesday, August 28, 2013

CFATS PSP and TWIC

I’m hearing rumors that DHS is getting close to the point where they will be issuing their 30-day notice for the information collection request supporting the CFATS personnel surety program (PSP). I did a series of blogs (the last in the series contains links to the others) on the comments that were received when DHS published the 60-day notice. This is part of a continuing series looking at some of the issues that will need to be addressed in the 30-day notice. Earlier posts in the series were:


In this post I would like to address some of the issues with the use of the TWIC as part of the CFATS PSP. The folks at ISCD did not think that the TWIC would form a major part of the facility PSP program, but the comments received would tend to indicate otherwise. This means that ISCD will have to make some modifications to the way the PSP deals with TWIC.

Facilities in and near port areas will find a large resident population that hold Transportation Worker Identification Credentials (TWIC). This will be especially true of the trades that commonly work in and around industrial facilities. Facilities will find it very helpful to include the use of the TWIC to vet contractor personnel moving in and out of the facility.

Truck drivers are another area where ISCD can expect to see wide spread use of the TWIC as part of the facility PSP. I fully expect that most facilities will require delivery drivers, particularly bulk carrier drivers who will have the most intimate access to critical areas of the facility, to present a TWIC as a prerequisite for facility entry. This will be the only way that a timely vetting of these drivers will be possible.

The 60-day notice made it clear that there will be no mandate to actually use TWIC Readers at the gate to verify the TWIC upon each entrance to the facility, but it did suggest that the TWIC could not be used purely as a flash pass either. Of course, part of the reason for any additional specificity in describing how often a TWIC would need to be verified by a Reader is the §550 prohibition on specifying the use of a particular security measure. Still ISCD will need to specifically state that electronic verification of a TWIC will (or will not) be necessary and whether or not it will have to be periodically repeated.

It is possible that ISCD may provide facilities with a dual option on the use of the TWIC. The TWIC might be allowed as a flash pass system if a listing of such TWICs (with only limited information required; name and TWIC # for instance) is provided to ISCD as part of the facility PSP data submission. Periodic use of a TWIC Reader may be allowed in lieu of such a submission. As I mentioned in the last post in this series a copy of the proposed CSAT PSP tool would go a long way to making the requirements clearer.


Actually, it may be difficult for ISCD to ‘require’ the electronic verification of the TWIC as part of the PSP until such verification is required as part of the MTSA PSP. It certainly looks like the CFATS PSP could be approved before the Coast Guard is able to get a TWIC Reader Rule published, particularly if various Congressional committees get involved.

Monday, June 10, 2013

CFATS PSP Comments – 06-08-13

This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


This last week of the comment period saw 17 submissions, almost exclusively from corporate sources or industry groups.

Third-Party Submissions

There is continued expressions of support for the provisions for allowing third-party submissions of personally identifiable information (PII). Air Liquide asks for additional details about how the third-party submitters would be identified to CSAT. GIS, a background-check provider, requests that ISCD provide a method for bulk-data submissions for third-party information providers.

48-Hour Advance Submissions

Air Liquide joins the chorus of complainers about the requirement to submit PII data on individuals 48 hour prior to their being granted unaccompanied access to critical or restricted areas of the CFATS facility. The National Association of Chemical Distributors (NACD) makes the point that there is no justification for the 48 hour submission rule if ISCD continues to refuse to notify facilities of the identification of personnel with terrorist ties. This point is clearly echoed by Rep. Thompson (D,MS) and the American Petroleum Institute (API). Allied Universal Corp. states it more bluntly: “As such, the PSP provides facilities no security value.”

The Society of Chemical Manufacturers and Affiliates (SOCMA) maintains that the possible requirement to shut down a facility because of the inability to comply with the 48-hour rule should have been addressed in the burden estimates.

PII Protection Rules

The American Coatings Association (ACA) questions whether the PSP ICR adequately addresses the various federal, state and local requirements to protect PII that will impact how facilities will collect and submit that data to DHS. The American Fuels and Petrochemical Manufacturers (AFPM) notes that this is an added burden because they are not currently required to maintain PII on contractors and visitors.

Other DHS Vetted Credentials

The ACA complains that the requirement for providing ISCD data on individuals with other TSA vetted individuals (holders of TWIC or HME for instance) defeats the purpose of using these credentials as alternatives to ISCD data submission for vetting. The Agricultural Retailers Association (ARA) maintains that “DHS should not require any further submission of information for those individuals holding federally issued credentials”.

SOCMA notes that it does not believe that DHS has the authority to compel facilities to provide information on personnel with other TSDB vetted identifications. AFPM agrees that “DHS is not authorized to impose prescriptive measures in order to comply with the performance-based rulemaking”.

Limited Implementation

The ARA supports the initial limited application of the PSP submission requirements to Tier 1 and Tier 2 facilities, noting that any future expansion to lower tiered facilities would benefit from the experiences obtained from this initial implementation.

PSP Coverage

The Edison Electric Institute complains that the ICR notice does not make it clear what employees would be covered by the PSP data submission requirement.

Inaccurate Burden Data

The API notes that the Burden Data estimates in the ICR notice are flawed because they do not rely on information already provided to ISCD via the submitted site security plans provided by all of the currently covered facilities. The American Chemistry Council estimates that the actual annualized burden costs of the PSP would be $5.22 million.

Moving Forward

This should be the last comments on the 60-day notice. DHS-ISCD will massage these comments, make changes as they deem appropriate and then issue a 30-day notice (if they ignore the suggestions to go to a rule making instead of an ICR) sometime in the next couple of months.


I’ll be looking at a couple of the issues raised in these comments in some detail in future blog posts.

Sunday, June 2, 2013

CFATS PSP Comments – 06-01-13

This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


This week there are comments from two industry organizations representing, hardly a well spring of comments as the fourteen day comment extension comes to a close. Effectively, there are just two days left in the comment period.

ISCD PSP Authority

The commentor representing terminal interests again objects to the ‘prescriptive’ nature of the PSP program proposed by ISCD and notes that this violates the §550 prohibition against the Secretary specifying any particular security measure as a prerequisite to site security plan approval. They even went so far as to include a 2012 letter they sent to the OMB after the previous attempted PSP ICR was forwarded to OMB for approval.

Alternative to PSP


The commentor representing the gas industry proposed an alternative proposal for a PSP program where individuals wishing to enter CFATS facilities submit information to a secure website for the purpose of being vetted against the Terrorist Screening Database. Once cleared, they would be given a personal identification number that they would provide to CFATS facilities to verify that they had been properly vetted against the TSDB. This is the same procedure that was proposed the week before by the chemical manufacturer.

Sunday, May 26, 2013

CFATS PSP Comments – 05-25-13

This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


We finally have some comments from the corporate sector, three from trade associations, one from a large chemical manufacturer and one from a background check provider.

Personnel Information

The background check provider calls out ISCD on a couple of paperwork issues, including:

• Maintaining PII files of information submitted to ISCD;
• PRA Notice signature requirements; and
• PII collection and storage for non-employees.

The major chemical manufacturer raises the same issues in their submission.

CSAT Requirements

The background check provider also wants to know some of the details about how the CSAT requirements for third-party submitters. They ask an interesting question, will lists of information (PII) submitted for the PSP have to be protected as Chemical-Terrorism Vulnerability Information (CVI) like the rest of the information submitted thru CSAT?

Lack of Authority to Require PSP Submissions

The chemical manufacturer and a trucking industry group question the authority of DHS to require data submissions to ISCD for local PSP. They cite the §550 stipulation that the Secretary may not require any specific security measure. They miss the loophole that was published in the 60-ICR Notice stating that facilities could propose alternative PSP measures in their Site Security Plan.

An explosives industry group agrees with the above comment and goes on to question the use of an information collection request as the vehicle for imposing essentially regulatory requirements on industry.

Alternative Visitor Process

The manufacturer notes that they had previously proposed an alternative method for submitting PII for visitors and contractors. They had proposed to NPPD that DHS could establish a secure web portal for individuals to submit the PII necessary for a Terrorist Screening Database (TSDB) search if they were going to be desiring to gain access to a covered facility. The manufacturer expresses concern that DHS has not followed up on the suggestion as promised.

TWIC, etc Procedures

The chemical manufacturer continues to complain about having to submit PII information on personnel who have a TSDB-based security identification. The explosives organization makes the same point, but further complains that ISCD is not accepting the ATF background check process that uses the same TSDB vetting.

The trucking group goes even further noting that requiring a HME holder to undergo additional security checks under federal programs is prohibited by 49 USC §5103a(g)(1)(B)(i)(I)-(II).

A training industry group supports the ISCD requirement for submitting PII for vetting personnel with other TSA supported identification, noting that a brief visual examination of the credential cannot determine if it is “expired, revoked or fraudulent”.  They additionally point to the problems with the TWIC Reader identified by GAO.

TSDB Positives

The manufacturer and the explosives group re-iterates their concern about DHS not notifying the facility if an individual is identified as having terrorist ties during the TSDB vetting.

48-Hour Submission Requirement

The chemical manufacturer objects to the 48-hour PII submission requirement for the TSDB vetting. They argue that since DHS will not routinely be informing facilities of positive TSDB matches, what difference does submitting the information 48-hours in advance of providing unescorted access make?


The trucking group notes that the 48-hour notice requirement could unnecessarily limit the availability of commercial deliveries.

Monday, April 29, 2013

CFATS PSP Comments – 04-27-13


This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


We are more than half way through the comment period on this ICR notice and we only added one comment in the last week bringing the total to three. I am surprised that there have been no comments to date from any chemical companies, though I do expect that will change as we get closer to the May 21st deadline for comments. We do have our first corporate comment this week, however, from AGL Resources, a natural gas distribution company.

AGL has three specific suggestions for improving the PSP dealing with:

• Vendor PSP certification;
• Bulk data submissions to the PSP; and
• Exemption from PII data sharing rules.

The issue of dealing with vetting vendor employees will be the area that will give high-risk chemical facilities the most problem with the PSP. While facility security managers are certainly going want to restrict vendor access to critical areas of the facility to the largest extent possible, there is still going to be some unaccompanied access required for selected vendors.

I don’t expect ISCD to get too specific about how this should be handled; the §550 rule about specifying security measures hangs heavy over their heads. Generally speaking, I would expect them to address this issue in the ICR by stating that each facility will have to address the issue in their site security plans which will be reviewed on an individual basis.

I really believe that the most effective way to handle this issue for most facilities is that they would require such vendors to have a TWIC that would be verified by a TWIC reader at some centralized location (security company most likely) and then checked against an approved list at the facility entrance. Larger facilities would be able to afford a TWIC reader at the gate.

Which brings up an interesting question; how long before we have a Tablet Application that scans IDs and compares them to a facility access list?

Wednesday, April 17, 2013

Bills Introduced – 04-16-13


While the House was working on cybersecurity bills and the Senate on gun control legislation there were three bills introduced that might be of specific interest to the chemical security and cybersecurity communities. They are:

HR 1583 Latest Title: To amend the Homeland Security Act of 2002 to establish an appeal and redress process for individuals who are screened against the terrorist watchlist and wrongly delayed or prohibited from boarding a flight, or denied a right, benefit, or privilege, and for other purposes. SponsorRep Clarke, Yvette D. (D,NY)

HR 1584 Latest Title: To amend the Homeland Security Act of 2002 to prevent terrorism, including terrorism associated with homegrown violent extremism and domestic violent extremism, and for other purposes. Sponsor: Rep Clarke, Yvette D. (D,NY) 

S 733 Latest Title: A bill to amend the Department of Energy High-End Computing Revitalization Act of 2004 to improve the high-end computing research and development program of the Department of Energy, and for other purposes. Sponsor: Sen Alexander, Lamar (R,TN)

HR 1583 might impact both the TWIC program and the new CFATS Personnel Surety Program. There is no telling exactly what efforts Ms. Clarke is proposing until we see the actual language of her bill. And Lamar’s bill might be a cybersecurity bill or it might just be a cyber bill, only a review of the actual legislation will tell.


Sunday, April 14, 2013

CFATS PSP Comments – 04-13-13


This is part of a continuing series of blog posts on the public comments submitted about the DHS 60-day ICR notice for the CFATS Personnel Surety Program (PSP). The other post in the series is:


There has been only a single comment filed in the last two weeks, another comment by an individual with no identified connection to a covered chemical facility. It includes discussions about the relative benefits of Options 1 and 3. Unfortunately the opening and closing paragraphs that bracket that discussion demonstrate a significant misunderstanding of the proposal (noting that there is nothing that describes what will be done with people identified with terrorist ties) and the CFATS program (noting that there is nothing in §550 or the ‘proposed rule’ that defines ‘high-risk chemical facility). Those misunderstandings severely detract from the discussion of the two options in the notice.

Thursday, April 11, 2013

CFATS Knowledge Center Update – 4-11-13


The CFATS Knowledge Center was finally updated today to reflect information about the new CFATS Personnel Surety Program (PSP) information collection request notice that was published in the Federal Register last month.

Page Changes

The ‘Latest News’ section of the page contains a brief note about the publication of the 60-day ICR notice (inappropriately identified as a “60-Day Paperwork Reduction Act Notice”). It also notes that: “A fact sheet on the Notice is available in the “Personnel Surety” section of the Knowledge Center.”

The ‘Documentation’ section of the page contains links to both the fact sheet and the Federal Register notice.

Also, Article 1721 has been removed from the CFATS Knowledge Center. I described the article this way when it was introduced in July 2011:

“Article # 1721 has been added to the list of articles maintained on the CFATS Knowledge Center. As with most of the other articles, this one provides a fairly high level summary of how the new personal surety program will work. Anyone working CFATS issues should read the article in its entirety. It provides a much more understandable description of the program than did the notices published in today’s Federal Register.”

PSP Fact Sheet

The fact sheet mentioned above is actually entitled: “Chemical Facility Anti-Terrorism Standards (CFATS) RBPS 12 (iv) - Personnel Surety”. As with the late Article 1721, this two page document provides an overview of the PSP outlined in the Federal Register notice. An important aspect of this fact sheet it that it not only describes how the program is intended to work, but it also describes the differences between this latest version and the July 2011 version that was submitted to OMB and later withdrawn.

As with the earlier article, this fact sheet should be read by, and kept in the files of, every CFATS covered facility. 

Monday, April 1, 2013

CFATS PSP Comments – 03-30-31


A little over a week into the comment period on the CFATS Personnel Surety Program (PSP) ICR and there is a single comment in the docket on the Federal eRulemaking Portal. There are six unusual supporting documents also to be found in the docket.

Supporting Documents

After the previous version of the PSP ICR was submitted to OMB (ultimately fated to be withdrawn last summer) there were a number of comments filed on the 30-day notice that had not been previously addressed by ISCD. David Wulf, Director of ISCD, took the unusual step of replying to those comments just about 11 days before the new ICR was published in the Federal Register in letters to the commenting parties. Those letters were addressed to:


Alternative Vetting Options

In each of the letters Wulf addresses the issue of supplying information on individuals that have already been vetted by the Department in one of the other TSA executed reviews of the TSDB. He makes the point that ISCD needs a limited amount of information on these personnel to:

• Verify that the affected individuals are currently enrolled in the Department program; and
• Enable the Department to access both the original enrollment data and the results of the vetting against TSDB information already in the possession of the Department, when necessary.

In responses to similar questions in the previous ICR ISCD repeatedly made the comment that they would also use the data to periodically recheck personnel against the TSDB to see if new information had been added. That point was re-made in the letter to Dr. Constantinides when Wulf states: “Facilities must notify the Department when individuals no longer have access, so that the Department knows when to stop performing recurrent vetting on them.” (page 2) This point was reinforced in the same letter when Wulf said that the Department would not grant reciprocity to the ATF vetting because the ATF “schedule for re-processing names against information in the TSDB as part of the ATF’s licensing/permitting regime is not equivalent to the recurrent vetting for terrorist ties that the Department plans to perform as part of the CFATS Personnel Surety Program” (page 3; also seen in the IMF letter).

This raises an interesting question in regards to the use of a TWIC Reader to validate an individual’s identity and the currency and validity of the TWIC in lieu of providing vetting or vetting verification information to ISCD. There is nothing in the wording of the ICR that would indicate that the facility would have to periodically have to require TWIC holders to re-use a TWIC Reader. In fact, it seemed to me that facilities using a third party (or consolidated corporate submission) to conduct PSP screening and data submission could use the TWIC Reader to validate a person’s TWIC to fulfill the PSP terrorist screening requirements and the facility would never have to acquire a TWIC Reader. I plan on submitting a question about this to ISCD as part of a comment on the ICR.

Computer System Access and PSP

The letter to the Chamber of Commerce addressed another interesting issue with regards to computer networks that are designated as critical assets in the SSP. The Chamber had addressed the issue in their comment noting that the facility’s cyber personnel could be located any where in the United States and even in other countries. Wulf’s response noted that PSP coverage included “facility personnel and as appropriate, for unescorted visitors with access to restricted areas or critical assets” (page 3) and then added the somewhat cryptic comment: “CFATS may include individuals with access to certain networked computer systems.”

I have always maintained that anyone with remote access to a critical computer systems (like an ICS) must be covered by the facility PSP. Admittedly this would cause some problems with vendors providing system service via remote access. The latest version of the ICR seems to make this somewhat easier in that vendors have the capability to submit PSP information to ISCD for the vetting process. There is still the question of how the facility can be assured that whomever is accessing their system has been properly vetted.

This is an issue that will have to be addressed in the SSP and it would be helpful if ISCD could offer some guidelines on the types of methodology that would be acceptable (always keeping in mind that ISCD is prohibited from requiring a specific method). I would suspect that a memorandum of understanding between the facility and the vendor that all personnel accessing a particular system will be vetted by the vendor would be a minimum requirement.

Comment Filed

The one public comment on the current ICR posted to the docket was, as expected this early in the game, from an individual. It appears that the commentor was unfamiliar with the purpose of the ISCD vetting program. It was not designed, as apparently assumed, to search for the most qualified people to access restricted areas but to just ensure that people with known terrorist ties were not allowed access.
 
/* Use this with templates/template-twocol.html */