Showing posts with label CFATS Personnel Surety Program. Show all posts
Showing posts with label CFATS Personnel Surety Program. Show all posts

Wednesday, March 9, 2016

PSP User Manual – Miscellaneous

This is part of an on-going series of blog posts about the new Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety plan (PSP) User Manual. This manual sets forth the instructions for using the new PSP tool in the on-line Chemical Security Assessment Tool (CSAT). Other blogs in this series include:


Initial Access to PSP Tool


The Authorizer for the facility will be provided initial access to the PSP Tool once ISCD has either authorized or approved a site security plan that includes provisions for meeting the requirements of 6 CFR 27.230(a)(12)(iv). Most facilities with authorized or approved site security plans were initially approved with a condition that they would have to revise that SSP once ISCD had put processes in place for the vetting of facility personnel and unaccompanied visitors against the Terrorist Screening Database (TSDB).

So once facilities have revised their SSPs and those revised SSPs have been approved, the PSP tool will be opened for the Authorizer. Presumably all SSPs authorized and/or approved in the future will include PSP provisions so the PSP tool will be opened when the SSP is authorized or approved. Remember, facilities that used the Enhanced Approval Process did not have to go through the authorization process.

Option 3 and Option 4 Procedures


Facilities that opt to use only Option 3 (Electronically Verified TWIC) and/or Option 4 (Other DHS Vetted IDs as Flash Passes) procedures are not required to submit information on those personnel thru the PSP Tool, so access to the tool will not be provided to those facilities. For facilities that use a combination of validations process that do require access to the PSP Tool will not need to enter information on personnel vetted under Options 3 or 4.

The PSP User Manual does not include any instructions on how to implement Options 3 or 4.

Bulk Uploads


As promised by ISCD provisions have been made to allow facilities to submit lists of names under Option 1 or Option 2 via spread sheet. This is done to both reduce the time on-line and to provide an easier means for personnel to do error checking before the data is submitted to the CSAT tool. Templates (in either .XLS or .XLSX formats) can be downloaded from the respective Option 1 or Option 2 ‘Affected Individuals’ tab on the PSP tool.

There is no mention of a minimum number of personnel that have to be listed on the template to use the bulk upload procedures. It looks like that even for just a couple of entries, it might be easier to use the bulk upload technique than by inputting the information by hand.

Data Validation


Appendix B in the User Manual provides detailed descriptions and data validation requirements for each of the data elements that will be submitted. If you are using the Bulk Upload technique described above, the data validation requirements should already be part of that formatting of the templates.

Even if you are not going to be using the bulk upload technique, it might come in handy to download those templates for data collection purposes. That way the Submitter should not have to worry about data validation issues when inputting the information into the PSP tool. In fact, those templates could be used to cut and paste information into the tool if they are not going to be used for bulk uploads.

No Longer Has Access


ISCD has included a data field in the Option 1 and Option 2 data submission to allow a facility to notify ISCD when an individual no longer has access to the covered facility. Congress specifically forbade {6 USC 622(d)(2)(i)} ISCD from requiring facilities to make a second data submission on any covered individual. Having said that ISCD is encouraging facilities to submit this information as it allows ISCD to stop completing periodic verifications of TSDB status (actually lack thereof) for Option 1 individuals or continuing to periodically verifying the ID status of Option 2 individuals when those individuals who are no longer covered by the program.

ISCD did make clear in their December Federal Register notice that individuals that have left a facility where no notification to DHS has been made of their no longer being covered individuals may seek Privacy Act redress to get their names removed from the PSP Tool.

Manage Alerts


There is a tab on the PSP Tool labeled ‘Manage Alerts’. This allows the facility to select if it will receive email alerts from the system about individual status in the PSP process or if the facility will just be alerted when they sign on to the tool. Unfortunately, this has nothing to do about the facility being notified if an individual whose data was submitted to the PSP appears on the TSDB; those notifications may be handled by law enforcement or DHS at the discretion of the Department of Justice.

The alerts provided in the PSP tool are limited to:

• Record – Submitted: (Option 1 and 2)
• Record – Verified: (Option 2)
• Record – Not Verified: (Option 2)
• Record – No Longer Verified: (Option 2)
• Record – Verification Pending: (Option 2)


The ‘Not Verified’ and ‘No Longer Verified’ alerts will require the facility to take actions that were outlined in the revised SSP.

Monday, March 7, 2016

PSP User Manual – Groups and Submitters

This is part of an on-going series of blog posts about the new Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety plan (PSP) User Manual. This manual sets forth the instructions for using the new PSP tool in the on-line Chemical Security Assessment Tool (CSAT). Other blogs in this series include:


Groups and Submitters Overview


Again, because the PSP tool involves the handling and access of personally identifiable information (PII) steps have to be taken to ensure that only those personnel with a need-to-know have access to that information. With the multiple ways that information may be submitted ISCD set up the PSP tool to require the formation of Groups and to only allow designated personnel to view the PII of personnel within that group. This required the establishment of PSP Submitters (separate from the Submitter used in other CSAT tools) so that a single PSP Submitter would only be able to access PII from the Group to which they are assigned.

Groups


As a default every CSAT account will initially have a single Group; called the Corporation Group. If a PSP Submitter(s) is authorized to have access to the PII on all of the affected personnel at a facility, then only the Corporation Group is necessary. However, if a facility is going to have to submit data on contractors or other companies, then it is likely that other Groups will have to be created. Or if a facility is going to use an outside company to submit data of facility personnel, but corporate HR will be submitting data on personnel from other facilities, then multiple Groups will probably have to be established.

The User Manual explains it this way:

“The Department expects an Authorizer will carefully consider the best group structure so information about affected individuals can be protected from unauthorized disclosure. Specifically, the Department expects the Authorizer will create one or more groups if needed so PSP Submitter(s) will (1) have access to only those records about affected individuals they should have access to, and (2) not have access to those records about affected individuals they should not. Several examples of how groups might be constructed to align with a facility’s (or its designees’) business operations are provided in Appendix C [pg 24]. It is also possible that the best group structure for some facilities may be to not create any additional groups at all and rely on the default “Corporation” group.”

 The User Manual provides instructions on how to:

• Create a Group (pg 11);
• Edit a Group’s Name;
• Merge a Group in to the Corporation Group; and
• Remove a Group

PSP Submitters


As I noted earlier the PSP Submitter(s) will be entering PII into the PSP tool for all data submissions under Option 1 (Full data submission) or Option 2 (Data submission on holders of DHS vetted ID). This is a separate CSAT position from the Submitter who has been submitting data in the Top Screen, Security Vulnerability Analysis (SVA) or Site Security Plan (SSP) tools in CSAT. A Submitter may be assigned to the role of PSP Submitter. For the rest of this post I will be referring to the PSP Submitter as ‘Submitter’.

When a facility first tries to access the PSP tool, the only person that will be able to effect that access is the Authorizer. The Authorizer can submit data in the Corporation Group (and only that Group) so it is possible that a facility may not need to have a Submitter. More likely, however, we would see the Authorizer designate a Submitter for the Corporation Group and any other Groups that the Authorizer sets up.

The important thing to remember is that a Submitter can only be assigned to a single Group and will only be able to see or submit data for that Group. This is going to have to be taken into account as Groups are established.

For companies that have multiple CFATS covered facilities under a single Authorizer should remember that the Corporation Group for the Authorizer would appear to apply to all facilities under that Authorizer (though this is not explicitly stated in the User Manual). Separate Submitters could be designated for each covered facility under the Corporation Group, but they would be able to see the PII for all individuals from any facility submitted under the Corporation Group.

Submitters from outside of the company may be designated. This would be useful when an outside organization is doing the data submission for a facility or when contractors/vendors are doing data submissions for their employees that would have access to the facility. The Appendix C description of Group organization would seem to suggest that DHS would prefer to see these outside organizations submitting data under separate Groups. This would certainly make sense where more than one outside organization would be submitting data, as it would limit the visibility of the PII to those for whom the organization had submitted data.

PII Liability


While all submitters are going to be governed by the Rules of Behavior (ROB; discussed in the previous post in this series) about access to the PSP Tool and the data contained in that tool, facilities will do well to remember that the data collected prior to data submission is also covered by Federal, State, and local privacy and data protection rules. Since the data that the Submitters are entering into the system is not yet covered by the ROB, the Submitters need to be fully trained about, and in compliance with, those other rules.

Commentary


For many facilities the single Corporation Group with a single Submitter will certainly be sufficient. The larger the organization the less likely that is going to be true. For companies with multiple locations and a number of contractors and vendors that require unaccompanied access to critical areas of the facility, I seriously suggest that the corporate security manager set up a meeting with all of the affected facility security managers and DHS Chemical Security Inspectors to try to work out the details of how the organization is going to organize its PSP data submission program. This meeting needs to be done early in the process; it would probably be best done before the SSP revisions are made.


Remember, it is fairly easy to set up Groups. If you end up setting up too many Groups initially, you can always reduce the number of groups by merging them later. Setting up new Groups after data submission has started will be very difficult as there is not currently any method for moving some data from one Group to another.

Wednesday, February 20, 2013

ACC ASP Press Release


I got a nice email from Scott Jenson, Director of Issues Communication, American Chemistry Council, providing me with a copy of the press release about their CFATS Alternative Security Program. Reader’s will remember my detailed review of this template for submitting the information necessary for ISCD to evaluate a facility site security plan.

ISCD Endorsement

I’ve been a little disappointed that ACC hasn’t been a more proactive in publicizing this outstanding tool. Reading this press release it is clear to see why Scott and his people have held off. In the press release there is a link to a very kind letter from David Wulf, Director, Infrastructure Security Compliance Division, essentially endorsing the ACC ASP. David says, in part:

“Thank you especially for ACC's efforts to help high - risk chemical facilities meet the CFATS requirements through the development of the ACC Alternative Security Program ( ASP) Guidelines and Template . We commend your decision to make these documents available to all facilities regulated under CFATS for potential consideration and reference in the development of other ASPs.”

There is no date on the Wulf letter, but I’m assuming that as soon as ACC had this letter in hand, they started immediate work on this press release. This is a very valuable endorsement. I would like to join David in commending ACC for sharing this tool with the whole of the regulated community, not just their member organizations.

BTW: It would be nice to see some mention of this ASP somewhere on the DHS Chemical Security web page. A mention of the ACC ASP with a link to the document would make it easier for non-ACC members to avail themselves of this tool.

ISCD Promises Better SSP Performance

David takes the opportunity in this letter to address the continued slow pace of SSP approvals. He notes that ISCD has streamlined the authorizing and approval process and then reports that ISCD has set “set a goal of 400 approvals [emphasis added] by the end of 2013”. This would be a truly remarkable accomplishment since the last official number that I had seen on approvals was that only 2 had been completed. Even at this rate they will only have about 1/3 of the SSPs approved before they have to go back and start re-evaluating SSPs that were previously approved.

Actually, ISCD has not approved any SSPs yet. They have only given provisional approvals because facilities can still not comply with the Terrorist Screening Database vetting requirements of Risk-Based Performance Standard 12. Metric 12.4 for all four Tier levels states that:

“Processes are in place to provide DHS with the necessary information to allow DHS to screen individuals (e.g., employees, contractors, unescorted visitors) who have access to restricted areas or critical assets against the TSDB.”

Since ISCD has not yet even published their proposed procedures for this vetting process, facilities are not able to comply with this requirement. ISCD is over four months late (based upon a promise made by Undersecretary Beers in testimony to a Congressional Committee) in the publication of the 60-day information collection request (ICR) in the Federal Register. If this were to be published today it would still be nearly the end of the year (best case) before final OMB approval could be given to begin the collection of the information necessary for this vetting.

So it will be nearly impossible for ISCD to achieve their goal of 400 approvals by the end of the year. I’m all for setting high goals David, but they must be achievable.

Thursday, September 6, 2012

EMTs and CFATS Personnel Surety


Earlier this week there was an interesting article over at NJ.com describing a situation in New Jersey where there is no requirement for Emergency Medical Technicians to have a background check to work in that State; most probably do, but it is not a requirement. The article points out some of the problems that this has caused in New Jersey, but it fails to address another serious security issue; unaccompanied access of EMTs to a high-risk chemical facility in the event of an emergency.

Background Check Requirements


When ISCD first floated their proposed rule for background checks on employees, contractors and any visitors with unaccompanied access to critical areas of high-risk chemical facilities, one of the first questions was if facilities would have to ensure that emergency response personnel would have background checks conducted by the facility. Obviously this could cause serious problems for the facility security manager and would most certainly be ignored in practice when an emergency arose at a CFATS covered facility.

ISCD addressed this in one of their frequently asked questions on their CFATS Knowledge Center web page. FAQ # 1368 (sorry there are no permanent links to FAQs; just enter the FAQ # in the search tool on the page) asks:

“Are CFATS background checks required for emergency responders prior to access to restricted areas or critical assets during emergency situations?”

The response to the question reads:

“No. During emergency situations, 6 CFR 27.230(a)(12) does not require CFATS background checks on emergency responders at the state or local level that gain unescorted access to restricted areas or critical assets.”

There is actually nothing in the language of §27.230(a)(12) that provides that exception, but it is certainly a reasonable acknowledgement of the realities of the situation. Besides, there is a basic expectation that emergency response personnel will have undergone some level of background checks as part of their hiring process. That is almost certainly the case for law enforcement and government fire departments. From this article it is apparent that it is not necessarily the case for EMTs in New Jersey (and maybe elsewhere), and I wonder if it is the case for volunteer fire departments around the country.

Potential Risk


I do not foresee ISCD changing this interpretation of the background check requirements, but it does present some rather spectacular potential security gaps.

At a typical medical emergency at any industrial facility with relatively good security, the gate guard is notified that an ambulance is enroute. As the ambulance approaches the gate, any traffic is diverted and the ambulance is waived through with nary a thought of identifying the driver or searching the vehicle. No one would expect otherwise, fearing that they would be putting the victim at risk by delaying trained medical attention.

Now if the medical emergency was staged this would be a very good method of bringing a VBIED or a small assault force well within the security perimeter. Properly planned and executed this would be a very effective attack method.

Security Management


Facility security managers at any high-risk facility (chemical or otherwise) needs to look into the vetting of local emergency response personnel. As part of their routine coordination with law enforcement, fire, and emergency medical services, they should verify the general background check requirements for responding personnel.
It is unlikely that most departments would include a Terrorist Screening Database (TSDB) check of their personnel. As part of their re-working of the CFATS personnel surety program, ISCD should consider making such screening available to agencies supporting Tier 1 and Tier 2 facilities in the CFATS program at no cost to those agencies identified in the SVA submission of those facilities.

Tuesday, July 31, 2012

The Cost of an ICR


On Sunday I responded to a Reader comment about the abbreviated CFATS hearing before the House Appropriations Committee (it was billed as a Committee hearing, but only the Chair and Ranking Member of the Homeland Security Committee were present). I mistakenly ignored the Reader’s comment about the ire of Rep. Price (D,NC) about the cost of the ICR. I reasoned that the actual cost of preparing the ICR, even the crafting of the personnel surety program that the ICR supported, just could not be that high. After all, we are already paying for the salaries of the people who worked on writing the two documents. And they were obviously not doing anything else in any case.

Then I had a conversation with a long time Reader with connections to ISCD. That Reader informed me that ISCD had made payments to TSA in two fiscal years (I forgot to ask, but I assume FY 2010 and FY 2011) for services in support of the personnel surety program; payments probably in excess of $4 million. Cognoscenti will realize that TSA, who operates the Terrorist Screening Data Base (TSDB) is required to recoup the cost of TSDB checks by charging the requesting agency or individual for those checks.

What is interesting here is not that the money was misspent (while $4 million is a lot of money to most people, it really is small change to congressional spenders), but that it was misspent twice. When ISCD published their original detailed ICR notice describing how they intended to operate the program, industry responded with a firestorm of negative comments. At this point ISCD should have realized that there were problems with their proposed personnel surety program and started doing some revising. And they should have not made any pre-payments for TSA services until the program was closer to actual operation.

A year later (which should have been time to revise the program significantly) when the second notice was published, some revisions in details were made, but the main sticking points for both industry and labor remained the same. Like a spoiled child, ISCD essentially said, we want what we want and we are going to get it. The published responses to that were even less positive than the first batch. Who knows how bad the back-channel complaints to OMB were? Actually we can guess pretty well; they were severe enough and numerous enough for OMB not to take any action on the ICR.

Hopefully, when ISCD goes back to the drawing board on this program, they will start from scratch and develop a clean program that provides a mechanism for checking employees, contractors and unaccompanied visitors against the TSDB and allows for the recognition other programs (TWIC and HME for instance) that vet individuals against that database.

Then, when the ICR is approved, ISCD can make the appropriate payment to TSA. And perhaps the Secretary might want to give them at least partial credit for the unused checks that have already been paid for.

BTW: The Appropriations Committee has yet to re-schedule their hearing on the CFATS program.

Wednesday, June 15, 2011

More Personnel Surety Changes to CFATS Knowledge Center

Two sets of changes were made today to the CFATS Knowledge Center web page. Early in the morning a new entry was placed in the ‘Latest News’ section and then later in the day a separate entry was removed from that section.

Addition to Page

The added news item today stated that: “The CFATS Personnel Surety Privacy Impact Assessment is now available.” This was a vague restatement of a note in the Article that I discussed yesterday that stated that the privacy impact assessment could be found at www.dhs.gov. Neither statement was very helpful in telling people where the document could be found.

Actually, all anyone had to do was to look at the ‘Documentation’ section at the bottom left of the page to find a link to “CFATS Personnel Surety Privacy Impact Assessment”. This link was apparently added at the same time as the ‘Latest News’ item. This section of the page has links to just about every conceivable CFATS document published by DHS.

Removed from Page

Sometime later in the day the ‘Latest News’ had the 4-13-11 item removed that had reported the opening of the registration for the Chemical Sector Security Summit. This was an appropriate removal since the registration has been closed since the 20th of May.

The article that supported that news item (Article 1720) remains on the site providing information about the CSSS.

Friday, July 31, 2009

Reader Comment – 07-29-09 – CFATS Personnel Surety

Back on Wednesday an anonymous reader posted a comment to my original blog on the DHS CSAT Personnel Surety ICR; actually I think it was partially a reply to another reader comment and my blog. Anonymous concluded the comments with the statement that: “The details aren't available in the Federal Register notice, but the department is holding meetings with an outline of what they're thinking and making that information available to these certain groups.” That sounds a little sinister, so I did some checking. DHS is certainly talking to a variety of affected industry groups about their intentions. The ICR was mentioned at the Chemical Sector Security Summit by Sue Armstrong, the head of Infrastructure Security Compliance Division of DHS. There she promised to brief members of the appropriate Sector Coordinating Councils (self-organized, self-led groups that are broadly representative of owners and operators and their associations within the sector, which are focused on homeland security and critical infrastructure protection) and listen to their input on the potential programs. Next week the ‘listening sessions’ will be held with the Oil and Natural Gas Sector Coordinating Council (8/3 at 2:00 pm) and the Chemical Sector Coordinating Council (8/5 at 10:00). I’ll see if I can get someone to get me some information on the feedback presented in those sessions. There is certainly nothing sinister about this outreach effort. The owner-operators of the chemical facilities that will be affected by the CFATS Personnel Surety Program certainly deserve to have their input into the development of that system. That was one of the main reasons that the ICR notice was published in the Federal Register in the first place. That is the main reason that I wrote about the ICR in my blog. The more publicity that the program gets the better it can become.
 
/* Use this with templates/template-twocol.html */