Showing posts with label CFATS Quarterly. Show all posts
Showing posts with label CFATS Quarterly. Show all posts

Saturday, April 25, 2020

ISCD Publishes April 2020 CFATS Quarterly


Yesterday the CISA Infrastructure Security Compliance Division (ISCD) published an link on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center for their April 2020 CFATS Quarterly. This somewhat periodic publication provides timely information on the CFATS program. Included in this issue are short articles on:

• Short term CFATS reauthorization;
• CFATS Requirements During COVID-19;
• Maintaining Your Facility’s Security During COVID-19;
• In Development: Additional Voluntary Chemical Security Resources;
• Personnel Surety Program: Uploading Affected Individuals Under Option 1 and Option 2;
• Compliance Close-up: Resubmitting Your Top-Screen; and
• New and Updated CFATS Resources

Wednesday, February 12, 2020

ISCD Publishes CFATS Quarterly – 2-12-20


Today the CISA Infrastructure Security Compliance Division (ISCD) published a link to the January 2020 issue of the Chemical Security Quarterly. If you had previously signed up for Chemical Facility Anti-Terrorism Standards (CFATS) notifications from CISA you would have received an email version of this publication back on January 27th like I did.

Veteran readers of this blog know how much I hate corporate report type publications from government agencies. When I first opened my email, it looked like this Quarterly was going to be one since it started with a month-by-month year-in-review for 2019; you know, ‘hey look at what great things I done’. Actually, I must admit some of the tidbits were things that I missed or had forgotten about.

The Quarterly then went on to review the ‘heightened geopolitical tensions’ issues surrounding the potential conflict with Iran. It is a nice recap if you missed the January 17th notice on the CFATS Knowledge Center or either of my two blog posts (here and here) on the topic.

Probably the most valuable part of this issue is the ‘Compliance Closeup’ feature dealing with CSAT 2.0. There is a good chance that many CFATS facilities may be seeing the new SVA/SSP portion of CSAT 2.0 for the first time as they implement the Tier 3 and 4 Personnel Surety Program (PSP) requirements. ISCD has done a nice job of briefly going over some of the changes with which facilities will have to deal. And there is a companion discussion about some of the resources available for implementing the PSP.

All in all, I have to continue to give ISCD points for publishing a worthwhile document than everyone associated with the CFATS program should read.

Monday, October 14, 2019

ISCD Publishes CFATS Quarterly – 10-08-19


Last week the CISA Infrastructure Security Compliance Division (ISCD) published the latest version of their Chemical Security Quarterly. Along with a large number of informational links, this version includes articles on:

CISA Leadership Updates;
House Hearing on CFATS Reauthorization;
Close-up on the Personnel Surety Program (PSP);
National Cybersecurity Awareness Month;
Chemical Sector Security Summit Presentations;
Counter Unmanned Aircraft Systems (UAS) Authorities;

PSP


Along with the brief article on the Tier III and Tier IV implementation of the PSP terrorist screening process there is a list of frequently asked questions along with the ISCD response. The article provides a nice high-level (upper management) overview of the PSP while the FAQs provide a deeper (but not too deep) dive into the mechanics of the PSP. Finally, there is a section that includes links to a number of resources on the PSP.

One minor complaint, the Chemical Security Inspectors and Compliance Analysts is a little misleading. It is just an email link to CSAT@hq.dhs.gov. A detailed email to that address will get some sort of appropriate assistance response, but not necessarily from a CSI or compliance analyst.

Counter UAS


An interesting collection of information about UAS operations in or near critical infrastructure; unfortunately, there is nothing that directly concerns counter UAS operations at CFATS regulated facilities. The reason for this is that the legal basis for counter UAS operations is very cloudy with lots of deadly lightning bolts (to extend the ‘cloudy’ metaphor) at this point, again unfortunately, that is not made clear in this article or any of the linked information sites.

CFATS Information Updates


This section provides links to new or revised CFATS resources. In this instance the ‘new resources’ includes links to a Risk-Based Performance Standard (RBPS) 10 web page and fact sheet. This RBPS concerns maintaining all records of maintenance, testing, and calibration of security equipment, as specified in 6 CFR §27.255(a)(4).

This section notes that ISCD has revised their ‘Detect and Delay’ web site and fact sheet. The changes appear to be more editorial than substantive.

I was disappointed to see this update information here and not on the CFATS Knowledge Center page when the changes occurred. The new RBPS 10 information was apparently updated earlier this month so there was no major delay there; but the Detect and Delay information was apparently updated last May. That is hardly timely information sharing. Caveat; I am predicating my ‘timing’ information on the dates provided on the two fact sheets; there are no dates on these (or most of the) ISCD web pages.

Overall Rating – Good Job


I am typically disappointed in publications like this Quarterly report. As I have noted on numerous occasions with other agencies, they are more like Corporate Annual Reports (look how great we are) rather than information sharing efforts. ISCD continues to concentrate on information sharing rather than grandstanding.

I continue to refer to this as the ‘CFATS Quarterly’, but CISA has rebranded this the ‘Chemical Security Quarterly’. Most of the information in this issue is targeted at CFATS facilities, but the UAS article shows that CISA is trying to target this at a larger audience. I applaud them on that effort, we will see how well they expand this outreach in future editions.

Thursday, July 19, 2018

ISCD Publishes CFATS Quarterly – July 2018


Today the DHS Infrastructure Security Compliance Division (ISCD) published the latest version of their Chemical Facility Anti-Terrorism Standards (CFATS) Quarterly. It was announced on the CFATS Knowledge Center with the link provided about half-way through the ‘CFATS Quarterlies and Webinars’ section at the bottom of the page.

This periodic document provides information on what has been going on in the CFATS program. Most of the news is about publications that have been made available to help facilities manage their CFATS process; nothing new here that I have not already covered.

In fact, the only really new piece of information is that David Wulf has finally returned to his job as Director of ISCD after having spent the last 18 months as Acting Deputy Assistant Secretary for Infrastructure Protection. This is the second time that Dave has filled this temporary position during the start of a new administration.

Monday, March 26, 2018

ISCD Publishes CFATS Quarterly – March 2018


Today the DHS Infrastructure Security Compliance Division (ISCD) published a news item on their Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center that the latest issue of the CFATS Quarterly Newsletter had been released. Additionally, ISCD published a new fact sheet in their chemical protection for specific industry sector series; this one is for the pulp and paper industry.

CFATS Quarterly


This issue of the Quarterly continues the tradition of a user-focused (as opposed to agency-focused) newsletter intended to provide useable information to the regulated industry. The first and last articles address specific Risk Based Performance Standard (RBPS) issues, and both lead with interesting questions.

The first deals with the ‘know your customer’ requirements under RBPS 5. It addresses the idea of preventing a business from inadvertently shipping DHS chemical of interest (COI) to potential terrorists and, thus, obviating their need to stage a physical attack on the covered facility. There is a nice segue to the introduction of the flyer ISCD published last year reminding customers that receive COI of their potential CFATS reporting requirements. One important item missing from the RBPS 5 discussion is guidelines on reporting attempts of acquiring COI by questionable entities.

The last article of the newsletter looks at RBPS 9 and the need for building relationships with local emergency response personnel. It includes a list of possible activities that a facility might want to consider, including a fairly innovative one; “Creating a toolkit for responders that contains items like the facility emergency contacts, facility layout, access credentials or a two-way radio”. I particularly like the idea about the radio, but I doubt most facilities want to spring for providing enough radios for all of the potential response agencies. An alternative would be to have this type of tool-kit available at the front gate for responding units.

In between these two articles are additional bits of useful information and one small agency ‘look-at-me’ piece. Without pointing fingers, this is the type of publication that agencies should publish, not 3-color glossy corporate-reports.

Pulp and Paper Industry


Last year, as part of their industry outreach program, ISCD started publishing a series of CFATS fact sheets that looked at various industry groups and the chemicals used by companies in those industries that could make them subject to the CFATS program. Since the CFATS program is a chemical security, as opposed to chemical industry security, program it appears to be necessary to remind various companies of their legal reporting responsibilities under the CFATS program.

The latest version is for the Pulp and Paper industry. Most of the content of these different outreach flyers are the same, as they deal with the CFATS program requirements. The only ‘new’ information here is the listing of common chemicals in the pulp and paper industry that are listed COI and thus could trigger CFATS reporting requirements.

I do wish that ISCD had provided a link to their ‘First Steps’ factsheet in this (and all of the other industry factsheets). It provides a brief overview of how to proceed when a facility has determined that they have a CFATS reporting requirement. It would be a valuable addition to these industry factsheets.

Friday, December 15, 2017

ISCD Publishes CFATS Quarterly – 12-15-17

Today the DHS Infrastructure Security Compliance Division (ISCD) published the latest issue of the Chemical Facility Anti-Terrorism Standards (CFATS) Quarterly on the CFATS Knowledge Center. This two page newsletter provides an update on what has been going on in the CFATS program over the last quarter.

Actually, as befits a year-end issue, a goodly portion of the Quarterly provides a brief review of what has been going on in the Program over the last year. Most of the stuff included has been talked about here (and in other ISCD forums) in more detail, but there were two paragraphs that deserve special mention; a short recognition of the lessons learned during the 2017 Hurricane Season and a terse forward look at the upcoming (?) reauthorization of the CFATS program.

Other items included in this issue include:

• A very brief CFATS numbers update;
• An inspection best practices article;
• A brief (and far from comprehensive) list of CFATS program resources;
• A brief blurb on the NAS Improvised Explosives Study; and
• A list of recently published CFATS fact sheets and notices


So far, ISCD seems to be doing a good job avoiding turning this publication into a three-colored, glossy corporate report. I hope they can keep it up.

Wednesday, September 13, 2017

ISCD Publishes CFATS Quarterly

Yesterday the DHS Infrastructure Security Compliance Division (ISCD) published the latest version of their Chemical Facility Anti-Terrorism Standards (CFATS) Quarterly. According to the ‘Latest News Entry” on the CFATS Knowledge Center: “This issue highlights the CSAT 2.0 SVA/SSP surveys, cybersecurity, an update on new Chiefs of Regulatory Compliance, new resources and materials, as well as the 2017 Chemical Sector Security Summit.”

SVA/SSP Surveys


This brief article lists some new questions that facilities will have to answer when they first complete the CSAT 2.0 SVA/SSP. This list is a little different from the one that initially appeared on the SVA/SSP web site right after the CSAT 2.0 tool was introduced. The new list includes:

• Q3.10.050 Personnel Presence
• Q3.10.400 through Q3.10.420 Inventory Controls
• Q3.40.400 through Q3.40.430 Cyber Control and Business Systems (new)
• Q3.50.320 Personnel Surety, Types of Affected Individuals (new)
• Q3.50.710 Recordkeeping Affirmation (new)

Regulatory Compliance Managers


ISCD now has Regulatory Compliance Managers serving in each of its regional offices. The brief article notes that: “In addition to managing CFATS regional operations, CRCs will lead our regional efforts to coordinate with other federal, state, and local representatives and spearhead regional CFATS-related outreach and engagement.” The list of Compliance Managers includes contact information.

Commentary



It is interesting to compare this CFATS Quarterly to the recently published ICS-CERT Monitor. While both documents are used by the parent organization to share information about their programs with the affected public, the two publications are significantly different. The Monitor has the look and feel of a corporate annual report with a similar lack of useful information. The Quarterly is not nearly as sophisticated in its presentation, but it provides more useful information. That is especially important in a regulatory organization.

Wednesday, May 10, 2017

ISCD Publishes CFATS Quarterly

I missed this last night because of problems with accessing the CFATS Knowledge Center, but on Monday the DHS Infrastructure Security Compliance Division published the latest version of their Chemical Facility Anti-Terrorism Standards (CFATS) Quarterly. The latest version provides information on the CSAT 2.0 tiering results, an overview of facility response requirements for a new tiering letter, and a brief reminder about annual CFATS audits.

Tiering Results


Not much new information provided in what is really just a summary of the recent webinars that ISCD held concerning the tiering results. The number of new Top Screens received has been raised to 12,000 and ISCD reports that they will be continuing to send out Top Screen notification letters for 18 months for the remaining 15,000 facilities that are on the list of facilities that have previously submitted Top Screens showing the presence of DHS chemicals of interest (COI) at or above the screening threshold quantity.

Tiering Letter Response Requirements


While ISCD did briefly discuss what a facility needs to do to respond to a new Tiering Letter during their webinar, the Quarterly provides a discussion that is a bit more detailed. It is still not a definitive discussion, but ‘definitive’ is not really possible given the wide variety of facilities and circumstances involved. The final paragraph provides the solution to the lack of a definitive answer:

“DHS will assess facilities on a case-by-case basis to ensure security measures are appropriate to their level of risk. You may reach out to your Chemical Security Inspector or Compliance Case Manager if you are unsure what specific steps to take.”

CFATS Audits


There is a brief sidebar at the bottom of the second page of the Quarterly that reminds facility security managers that every CFATS covered facility with an approved site security plan (SSP) is required {6 CFR 27.225(e)} to conduct an annual audit of their compliance with that SSP. The CFATS rule does not provide detailed guidance on what such an audit will include. This brief piece in the Quarterly provides the following suggestions:

· Verification of Top-Screen and SVA data, including ensuring COI information is current;
· Confirmation of all CSAT user roles;
· Confirmation of all existing and planned measures from the SSP/ASP; and
· Review of current policies, procedures, training, etc.


I briefly addressed this issue back in December 2014 and I still think that post provides a useful look at audit requirements. A formal audit summary document certainly needs to be prepared and it needs to be made available during any compliance inspection.

Wednesday, April 20, 2016

ISCD Publishes Latest CFATS Quarterly

This morning the DHS Infrastructure Security Compliance Division (ISCD) posted a note in the ‘Latest News’ section of the CFATS Knowledge Center pointing to a link to the latest issue of the CFATS Quarterly. This web publication provides updated news on the Chemical Facility Anti-Terrorism Standards (CFATS) program.

In this issue the following topics are addressed:

• Chemical Facility Anti-Terrorism Standards Program Progress;
• CFATS Personnel Surety Program Implementation Update;
• 10th Annual 2016 Chemical Sector Security Summit;
• 2016 Global Chemical Safety and Security Summit; and
• Compliance Corner - What needs to be done when a facility is bought or sold?

Two interesting tidbits were included in the article on the PSP implementation. The first compliance inspection that included Terrorist Screening Data Base (TSDB) personnel vetting was conducted on January 28th, 2016. The first updated site security plan (SSP) for TSDB vetting was approved on March 4th. I would assume that the compliance inspection was an expedited approval facility that had included the TSDB vetting in their EAP-SSP in close coordination with their Chemical Security Inspector.

The notice about the 1st Global Chemical Safety and Security Summit was more than a little late as the last day of the conference is today.


NOTE: For some reason the December 2015 issue of CFATS Quarterly was not published on the CFATS Knowledge Center. On the other hand, I do not know that there actually was a December issue.
 
/* Use this with templates/template-twocol.html */