Showing posts with label CVI. Show all posts
Showing posts with label CVI. Show all posts

Monday, September 15, 2025

Looking Back – EO 13556

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list.

Today a blog post from November 2010 made the list, EO 13556 and CVI. It looks at the publication of EO 13556, Controlled Unclassified Information, one of the Obama EOs left in tact by President Trump. It briefly looks at how that EO would affect the then existing Chemical-Terrorism Vulnerability Information (CVI) program in the Chemical Facility Anti-Terrorism Standards (CFATS) program.

Wednesday, May 21, 2025

OMB Approves CISA’s Chemical-terrorism Vulnerability Information ICR

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an information collection request (ICR) revision for CISA’s Chemical-terrorism Vulnerability Information (CVI) program. The 60-day ICR notice for this action was published on September 13th, 2024, and the 30-day notice was published on November 21st, 2024. This ICR supports the information protection program of the now defunct Chemical Facility Anti-Terrorism Standards (CFATS) program. The continuation of the CVI program is necessary because the federal government still maintains files of sensitive but unclassified information collected during the tenure of that program.

According to the abstract on the approved ICR notice:

“The instrument will be used to allow individuals to become CVI Authorized Users and access historical records generated under the CFATS program. Prior to the lapse in CFATS authority, completion of the application to obtain CVI Authorized User status required an individual to check several CVI affirmation statements, complete a web- based CVI authorized user application, and provide responses to several identity verification questions. Upon completion of the application, the system assigned a unique CVI Authorization Number to the individual and transmitted that number to the individual. CISA maintains a record of those individuals who have completed the training and received a CVI Authorized User Number.”

Tuesday, April 8, 2025

Reader Comment – CVI and DOGE

Last night Carbon Unit left a comment on my Substack Notes announcement about my recent “Chemical Security Inspector Reduction in Force” post on Substack. The comment objected to the characterization of the DOGE access to Chemical Terrorism Vulnerability Information (CVI), noting that:

“The USDS team has been vetted and has already covered far more sensitive data than this.”

As I noted in my reply to that comment, CVI information in possession by CISA includes security plans for the 3,000+ chemical facilities that were covered by the CFATS program at the time of the program’s termination in July 2023. That is some of the most sensitive information not covered by national security classified information program in the possession of the government. In fact, according to 6 USC 623(d):

 

“In any proceeding to enforce this section, vulnerability assessments, site security plans, and other information submitted to or obtained by the Secretary under this subchapter, and related vulnerability or security information, shall be treated as if the information were classified information.”

 

Additionally, the chemical inventory data on the 300 most sensitive chemicals (from a weaponization point of view) submitted under the CFATS’ Top Screen program on over 45,000 facilities is also held on those same CVI servers.

 

While the DOGE team members may have been vetted (I am not sure what vetting process has been used, but from public reporting it does not meet the access requirements outlined for CVI access, because of the training requirements) that does not mean that they have the ‘need to know’ the facility chemical security information held by CISA.

 

CISA and the employees working in and around the CFATS program took the CVI program very seriously. Unauthorized access, and certainly unneeded access, to that information would be expected to offend the sensibilities of those employees. More importantly, it would strike fear in the facilities that provided that information to CISA in the understanding that the information would be closely held and protected by CISA.

Monday, February 3, 2025

Review - ChemLock and Chemical-Terrorism Vulnerability Information

This is part of a series of blog posts looking at the potential for the authorization of CISA’s existing ChemLock program and using it as a voluntary replacement for the now defunct Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in this series include:

CFATS is Dead,

Making ChemLock Safety Act Compliant – ChemLock Program Background,

ChemLock and Tiering,

Reader Comment – TSDB Screening for ChemLock,

ChemLock and TSDB Screening,

ChemLock and Risk Based Performance Standards.  

NOTE: Previous articles in this series have been removed from the CFSN Detailed Analysis paywall.

The CFATS program collected a great deal of sensitive information from facilities; both covered facilities and facilities submitting Top Screen information to see if they were to become covered facilities. The information provided to CISA that would be of potential interest to any terrorist organization planning on attacking the facilities. To prevent that sort of information sharing, it was protected by the Chemical-Terrorism Vulnerability Information (CVI) program.

While the CFATS program was in effect, the CVI program was authorized by 6 USC 623. The regulations concerning the program can be found at 6 CFR 27.400. CISA’s predecessor published a revised guidance manual for the program in September of 2008. When CISA stood up the ChemLock program, they made no attempt to apply CVI protections to information provided under the new program, maintaining that, since the two programs were separate and distinct, there was no statutory authorization for applying the CVI protections to the ChemLock program.

Any attempt to authorize the ChemLock program is going to have to specifically deal with the protection of controlled unclassified information submitted to and developed by that program. Adaption of the Chemical-Terrorism Vulnerability Information (CVI) program from the CFATS program would be the most obvious way of dealing with necessity.

 

For more information on the potential use of the CFATS CVI program to support the ChemLock program, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-and-chemical-terrorism-vulnerability - subscription required.

Friday, September 13, 2024

Review – CISA Publishes CVI 60-day ICR Renewal Notice – 9-13-24

Today CISA published a 60-day information collection request (ICR) revision notice in the Federal Register (89 FR 74975-74977) for “Revision of a Currently Approved Information Collection for

Chemical-Terrorism Vulnerability Information (CVI)”. CVI is the data protection regime for the Chemical Facility Anti-Terrorism Standards (CFATS) program. While CISA acknowledges that the authority to operate the CFATS program expired on July 28th, 20223, today’s notice explains:

“It is the Administration's position that CFATS should be reauthorized. However, even without statutory reauthorization, there is both a reason to continue collecting this information (i.e., enabling individuals with a need to know but who are not CVI Authorized Users to access historical government records safeguarded as CVI) as well as existing statutory authority to do so under 6 U.S.C. 652(e)(1)(J) [link added]. Once CFATS is reauthorized, the training and application to become a CVI Authorized User will be made accessible to the public.”

There is no change in the burden estimate for responses or burden hours, as can be seen in the table below.


The change in the burden cost estimate is due to updating the Site Security Officers (SSOs) average wage figure.

Public Comments

CISA is soliciting public comments on this ICR revision. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # CISA-2024-0023). Comments should be submitted by November 12th, 2024.

Commentary

CISA has been steadfast in their belief that Congress will reinstate the CFATS program. This ICR is another example of that continued belief, even more than a year after the authorization expired. As the end of the 118th Congress quickly approaches, I am not sure that I share the same suspension of political reality that CISA is, at least publicly, showing in their continued support for this program. Sen Paul (R,KY) is not known for changing his positions or bowing to political pressure.

 

For more information on this ICR notice, including more details about the burden estimate and a more detailed commentary, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cisa-publishes-cvi-60-day-icr-renewal - subscription required.


Saturday, March 28, 2020

ISCD Publishes 60-day CVI ICR

CISA is publishing a 60-day ICR notice in Monday’s (available online today) Federal Register (85 FR 17593-17594) for an extension of the current Chemical-Terrorism Vulnerability Information (CVI) information collection request (ICR). This would cover the information ISCD would collect on-line from personnel requesting to become a CVI authorized user.

ICR Burden


The key to estimating the burden of the ICR is to determine the number of  people that will be attempting to become CVI certified. CISA provides the last three-year data on the applications, but notes: “Due to past fluctuations and uncertainty regarding the number of future respondents, CISA believes that 20,000 continues to be a reasonable estimate.” This results in an extension of the current burden (estimate below) without change.

• Number of respondents – 20,000
• Time per respondent – 30-min
• Annual time burden – 10,000-hours

With an estimated average hourly wage for requestors being $79.75 this brings the annual cost burden to $797,474 per year.

Public Comments


CISA is soliciting public comments on this ICR notice. Comments may be solicited on the Federal eRulemaking Portal (www.Regulations.gov; Docket # CISA-2020-0002). Comments are due by May 29th, 2020.

Saturday, October 19, 2019

CFATS and a Small-Town Road Closure


It is not often that security measures under the Chemical Facility Anti-Terrorism Standards (CFATS) program make the newspaper, but they did this week in the El Dorado News-Times in El Dorado, AR. The issue was a meeting of the Union County Quorum Court where the owner of a local oil refinery was asking the County to close a portion of a public road that runs through the refinery. The owner cited the CFATS program as the reason that the road needed to be closed. According to the article:

“Ratcliff [lawyer representing the refinery] said safety standards imposed by the United States Department of Homeland Security in response to the Sept. 11, 2001 attacks on the United States are not able to be met by Lion Oil/Delek because the road is open.”

The author of the article noted that Ratcliff was referring to the CFATS program.

Security Issues


Looking at the Satellite view from Google Maps® it is easy to see what ‘security issues’ come into play with this public road. First it divides the large storage tank farm on the west side of the refinery in two. It also divides a flammable gas storage tank area just north of the larger tank farm. And many of the storage tanks (liquid and gas) are well within the blast radius of a reasonably sized vehicle-borne explosive device. There is also a tank-wagon marshalling area and a tank-wagon loading area along the road.

It is hard to tell what chemicals are stored in the large tank farm, but, given that this is a petrochemical refinery, I would reasonably assume that most of the tanks contain some sort of flammable hydrocarbon. The horizontal pressure tanks on either side of the tank farm contain some sort of flammable gas; the give away is the ‘4’ in the upper diamond on the hazard placard on the tanks.

CFATS Considerations


Neither of these tank farms are very close to any residential areas or schools. There are two small churches that the refinery is using to define the road closure limits, but I doubt that either attracts more than a couple hundred parishioners at most. What that means is that the Infrastructure Security Compliance Division (the CISA group that administers the CFATS program) probably bases their high-risk determination for this refinery on the close proximity of the operations area of the facility further to the East to residential areas of El Dorado.

ISCD give facilities a great deal of leeway in defining facility boundaries for the purposes of determining what is a covered facility. There might be a chance that, if the refinery were to be divided into two parts with the boundary between them being the creek that runs north-south through the facility, the western potion of the facility that includes Hinson Road (the road being proposed to be closed) might not be determined to be a high-risk facility and thus out of the scope of the CFATS program.

Similarly, if the western half of the facility were to be determined to be a high-risk facility, the facility could manage the large tank farm in such a way that the three tanks closest to Hanson Road would not be used for storage of chemicals that were on the list of DHS chemicals of interest (COI). This would allow the facility to exclude those three tanks from the restricted-access portion of the facility. This would leave just the flammable-gas tanks as areas of concern along the road. Security measures could be designed to specifically protect those tanks from VBIED attacks.

CFATS and RBPS Guidance


The author of the article about the situation made note about the “Dept. of Homeland Security’s Chemical Facility Anti-Terrorism Standards Risk-Based Performance Standards. She picked up on the following repetitive statement in that guidance document:

“Note: This document is a “guidance document” and does not establish any legally enforceable requirements. All security measures, practices, and metrics contained herein simply are possible, nonexclusive examples for facilities to consider as part of their overall strategy to address the risk-based performance standards under the Chemical Facility Anti-Terrorism Standards and are not prerequisites to regulatory compliance.”

What most people who have not worked with the CFATS program do not understand is that the CFATS regulations (6 CFR 27.230) set 12 broadly worded risk-based performance standards (RBPS). The guidance document provides information about how facilities can meet those broad requirements. The facility and ISCD reach an understanding about what the facility will include in its site security plan (SSP) to meet the statutory requirements for that particular facility; each facility would have its own unique methods to deal with the specific security situation at that facility. Once that SSP is approved by ISCD, the requirements of that SSP are the regulatory requirements for that facility.

Public Decisions and CVI


The big problem for the refinery going forward with the road closure process is providing enough information about their security issues to the County without running afoul of the restrictions on sharing Chemical-terrorism Vulnerability Information (CVI). Security information about CFATS covered facilities are considered to be controlled unclassified information (CUI) with specific rules about how that information can be shared with local government officials; for CVI that includes requiring individuals that are being given access to have completed on-line training in how to protect CVI information.

The County rules, in this case, requiring a 3-person panel to review the information for a contested road closure seem well suited to the CVI requirements. The three people assigned to the panel could take the relatively brief training and then receive the security information from the refinery’s lawyer to consider in the road closure petition. They could then make their recommendation without including any of the specific security information.

The big problem with that is that the 3-member panel is supposed to hold public hearings to get both sides of the issue. The public is specifically excluded from having access to CVI so the refinery would be required to make their arguments without providing any of the pertinent security information. Those sanitized arguments may be inadequate to support the request.

Commentary


I would be very surprised if a large refinery were just starting the CFATS process, but I suppose that it could happen. If the facility has not yet had its SSP authorized, there are still alternatives available to closing the road through the facility. I have discussed some of them above, but there are other, probably more expensive, security measures that could be employed that would obviate the need for the road closure.

If the facility SSP has been authorized, it would seem that the facility had included as a proposed security measure the closure of the road. If that is the case the facility made a commitment to ISCD that the road would be closed. Failure to get the County to effect the closure would require the facility to renegotiate their SSP; ISCD would be upset, but I suspect that they would understand that the facility had no control over the actions of the County government.

What I suspect is happening is that the original facility SSP was negotiated by the previous owners and authorized and subsequently approved by ISCD. It would have included some expensive planned compensating controls to allow the road to remain open. Those controls would have been proposed because the owners knew that getting the County to close the road was going to be difficult at best. The new owners have no desire to spend the money necessary to implement the controls. ISCD would be in the process of threatening noncompliance sanctions and the new owners are trying hard to get the financially easier security measures in place as an ‘appropriate response’ to the non-compliance actions.

It will be interesting to see how this turns out.

Wednesday, June 19, 2019

OMB Approves NIST SP 800-171 Update


On Monday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced the approval of the National Institute of Standards and Technology’s (NIST) Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. This update was sent to OMB for approval back in February. Guidance documents are not typically listed in the Unified Agenda and there is nothing on the SP800-171 web site that indicates what types of changes are being made.

This document could be published this week, but the Trump Administration is notoriously slow to publish regulatory documents so there is no telling when this will be published.

This document establishes cybersecurity requirements for electronic systems that store, receive or send Controlled Unclassified Information (CUI). It mainly covers contractors, but facilities covered under the Chemical Facility Anti-Terrorism Standards (CFATS) program would be required to comply with these standards on systems containing Chemical-Terrorism Vulnerability Information (CVI).

Sunday, June 16, 2019

HR 3256 Introduced – CFATS Reauthorization - Part I


Earlier this week Rep. Richmond (D,LA) introduced HR 3256, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2019. Normally, I wait for the official print of the bill before I review it, but the House Homeland Security Committee has a committee print available and have scheduled a mark-up hearing of the bill on Wednesday, so I will be reviewing the committee print today.

HR 3256 would reauthorize the Chemical Facility Anti-Terrorism Standards (CFATS) program for an additional five plus years (until May 1st, 2025; §16). The bill also provide a number of amendments to the current authorization language (6 USC Subchapter XVI).

Major Additions


The following sections of the bill show the areas where significant changes would be made to the existing program:

§4. Protection and sharing of information.
§5. Civil enforcement.
§6. Whistleblower protection.
§7. Chemical Security Advisory Committee.
§12. Voluntary mechanism for reporting drones and other emerging threats.
§13. Regulations regarding specific products and mixtures containing chemicals of interest.

The following sections provide information on the studies and reports required by the bill:

§8. Implementation plan and report to Congress.
§9. Study on risks posed by excluded facilities.
§10. Study on feasibility of waiver program.
§11. Comptroller General reports.

Information Protection and Sharing


Section 4 of the bill would make a number of changes to 6 USC 623, Protection and Sharing of Information. The first change would be to rewrite paragraph (a) to read:

(a) In general - Notwithstanding any other provision of law, with respect to information in the possession of the Department, the Secretary shall protect information developed under this subchapter, including vulnerability assessments, site security plans, and other security related information, records, and documents shall be given protections from public disclosure consistent with the protection of similar information under section 70103(d) of title 46 [link added].

Additionally, a complete rewrite of paragraph (b) includes:

(2) NONDEPARTMENTAL INFORMATION. — Information is not protected pursuant to subsection (a) if it is—
(A) not in the possession of the Department;
(B) developed under this title but has been previously produced or developed for other purposes; and
(C) is already publicly available, readily discoverable, or otherwise lawfully disclosed.

Comment: It looks like this is intended to change the Chemical-Terrorism Vulnerability Information (CVI) program to make it more like other sensitive but unclassified (SBU) information protection programs. Currently the CVI program has strict information protection rules for information held at each covered facility. Other SBU only protect information in the hands of the Federal government, its contractors, and such information shared with State, Tribal, and local governments. If that was the intent, it looks to me like the terminal ‘and’ in (2)(B) nullifies that attempt as it does not remove protections already provided in the program. DHS would not be required to change the CVI rules under these changes. If the terminal ‘and’ were changed to ‘or’ then (2)(A) would be the controlling factor for removing CVI protections for information held at facilities.

As noted above §4 also rewrites (b), changing the information sharing requirements of §623(b) to require DHS to provide information (upon request) to {new §623(b)(1)}:

State, local, and regional fusion centers (as that term is defined in section 210A(j)(i) of this Act) and State and local government officials, including law enforcement and emergency response providers;
Members of Congress;
Members of the Chemical Security Advisory Committee under [new] section 2010 of this Act; and
The Comptroller General of the United States.

The addition of fusion centers and members of Congress in this paragraph allows the bill to delete the current paragraphs (c) and (f) from §623.

Comment: This is a proforma change to appease supporters who want ‘better’ information sharing about the hazards associated with covered facilities. This really provides no new requirements for the CFATS program beyond the addition of the new Advisory Committee which will be covered in more detail later in the bill.

Civil Enforcement


Section 5 of the bill would amend §624, Civil Enforcement. The first set of amendments deals with changes to paragraph (a), Notice of noncompliance. The first change the time limits for DHS to provide a written notice of non-compliance from 14-days to 3-days. And the second changes the time limit a facility would have to comply with a DHS order to comply, from 180 days to 30 days.

The next set of changes address paragraph (b)(2) civil penalties for non-reporting chemical facilities of interest. The change clarifies that the subparagraph applies to Top Screen submission requirements or supplemental information thereto.

The third set of changes paragraph (c)(1), expanding the DHS authority for issuing emergency orders due to violations of CFATS program requirements or the risk of terrorist incidents. It now adds a vague “or other malicious act” that may affect a chemical facility of interest to the list of potential causes of “an imminent threat of death, serious illness or severe personal injury that the Secretary could attempt to prevent by requiring facility action.

Comment: This is ‘other malicious act’ is vague enough to provide authority to order cybersecurity measures or even the development of active shooter programs. The current management would be unlikely to use this authority; their emphasis is on cooperative enforcement. Who knows what could happen in the future?

Whistleblower Protections


Section 6 of the bill modifies the existing whistleblower protections found in §625. The bill expands on the existing requirements for:

• Confidentiality;
• Response to reports; and
• Opportunity for review

The bill also adds a new paragraph (c) to the section; Procedure and Remedy. It provides requirements for DHS to “establish a procedure for the review and investigation of complaints of reprisals” {new §625(c)(i)} as well as establishing remedies for violations of the same.

NOTE: I am about half-way through the major CFATS changes proposed by this new bill and we are already at about 1000 words. It is getting a bit long for a blog post; even by me. I will try to finish up by tomorrow.

Tuesday, April 30, 2019

Eliminating CVI in CFATS Reauthorization Bill?


I am hearing rumors that a CFATS reauthorization bill currently being drafted might include provisions that would eliminate the Chemical-Terrorism Vulnerability Information (CVI) program from the Chemical Facility Anti-Terrorism Standards (CFATS) program. The CVI program is authorized under 6 USC 623 and regulated under 6 CFR 27.400 and a detailed guidance document here. The CVI program protects security information about facilities in the CFATS program from public disclosure.

There have been complaints in Congress over the years that the presence of the CVI program interferes with facilities sharing information with emergency responders. Not having seen the specific wording of possible CVI removal provisions, I can only suppose that these provisions would be an attempt by congressional staffers to remove such impediments to information sharing.

CVI Background


The CVI program is one of the most unusual Controlled Unclassified Information (CUI) programs in the Federal government. Most CUI programs limit the Federal Government’s sharing of information provided to the government by the private sector or developed in house by government agencies. The CVI program, on the other hand, requires both the covered private sector organizations and the government to protect the covered information regardless of who initiates the information.

Information developed by covered facilities that is considered to be CVI (and thus protected from disclosure) includes all submissions made by the facility to DHS through the CFATS Chemical Security Assessment Tool (CSAT), copies of security vulnerability assessments and site security plans, and the working papers supporting those documents. Certain of those supporting documents are exempted from CVI classification; specifically, any records that are required to be maintained by other regulatory programs including chemical inventory information and emergency response plans are exempted from CVI protections.

Disclosures of CVI information can only be made to personnel who have received CVI Certification and have a verified ‘need-to-know’ the specific information. The ‘need-to-know’ requirements are outlined in §27.400(e) and specifically includes State and local officials.

CVI and Emergency Response Planning


Emergency response planning for chemical releases is covered briefly in the CFATS regulations as part of the Risk-Based Performance Standard #9 {§27.230(a)(9)}, but both the regulation and the CFATS RBPS Guidance document make it clear that those requirements are only response plans for security breaches, not accidental chemical releases. Even then, the CFATS planning process envisions inclusion of law enforcement personnel in preventing the attack or arresting the perpetrators, NOT fire or emergency medical technicians responding to the affects of the potential attack. That chemical emergency response is already covered under EPA regulations.

Law enforcement personnel working with facility personnel to develop security response plans at a CFATS covered facility would be expected to be covered by CVI rules including CVI training and certification requirements. Emergency medical technicians and fire fighters participating in planning for chemical releases (either accidental or deliberate) would be covered under the EPA regulations and would not require CVI clearances.

Members of a Local Emergency Response Committee (LEPC) would not require CVI certification to receive chemical inventory data from local chemical facilities covered by the CFATS program because the LEPC notification requirements are covered under the EPA regulations and are exempted from CVI classification {§27.405(1)}.

Continued Need for a CVI Process


The purpose of the CVI program is to ensure that critical security information about a CFATS covered facility is not made publicly known and thus become available to nefarious personnel who could use that information in the planning and execution of an attack on a chemical facility. The mere knowledge of the existence of an inventory of items on the DHS chemicals of interest (COI) list is not critical safety information. That information is generally already publicly available through the EPA (a discussion of the EPA’s limiting of the sharing of that information is an entirely separate topic).

I suppose that the CVI program could be replaced with another of the existing CUI programs, probably the DHS Protected Critical Infrastructure Information (PCII) program. That would also protect the information originating at the facility level from disclosure by Federal, State and local governments. What it would not do, however, is to establish standards for facility personnel to protect the required information. Without information protection requirements like those in the CVI program, it would be easy enough for attackers to get the information that terrorists need to circumvent the security procedures at CFATS covered facilities.

Rather than abolishing the CVI program, Congress might want to make clear that certain information will be freely shared with LEPCs, local law enforcement, fire departments and hospitals. Last year I suggested language for that information sharing that operates within the bounds of the CVI program. This would be in addition to any information sharing already required between facilities and LEPCs and fire departments by EPA regulations.

Saturday, February 23, 2019

NIST Sends SP 800-171 Update to OMB for Review


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received NIST Special Publication 800-171 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations) for review. This update was not listed in the Fall 2018 Unified Agenda.

The last revision of this document was published last June. It is not clear what changes that NIST is proposing to make to the document; there is nothing on the SP 800-171 web site.

This document establishes cybersecurity requirements for electronic systems that store, receive or send Controlled Unclassified Information (CUI). It mainly covers contractors, but facilities covered under the Chemical Facility Anti-Terrorism Standards (CFATS) program would be required to comply with these standards on systems containing Chemical-Terrorism Vulnerability Information (CVI).

Thursday, April 20, 2017

DHS Publishes 60-Day ICR Revision Notice for CVI Program

Yesterday the DHS National Protection and Programs Directorate (NPPD) published a 60-day information collection request (ICR) notice in the Federal Register (82 FR 18466-18468) for revisions being made to support the Chemical-Terrorism Vulnerability Information (CVI) program within the Chemical Facility Anti-Terrorism Standards (CFATS). The proposed changes reduce the number of information collections and the DHS burden estimate for that program.

Changes


Based upon the experience of the last three years, the Infrastructure Security Compliance Division (ISCD) of the NPPD is removing five information collection instruments from this ICR. They are:

• “Determination of CVI”;
• “Determination of a “Need to Know” by a Public Official”;
• “Disclosure of CVI Information;
• “Notification of Emergency or Exigent Circumstances”; and
• “Tracking Log for CVI Received”

This leaves just one ICR instrument covered by this collection, the information collected by the CVI Training web site and the subsequent CVI user application. ISCD reports that they expect a reduction in the number of respondents for this remaining instrument to decrease from 30,000 to 20,000.

Commentary


Once again it is nice to see a detailed accounting of the changes being proposed by a federal agency in the ICR process. Such details provide the data necessary to make informed comments for ultimate consideration by the OMB’s Office of Information and Regulatory Affairs.

I also commend DHS for this review of the collection instruments covered by the ICR and their intent to remove little used or unnecessary instruments. Having said that, I have concerns about the removal three of the identified instruments;

• “Disclosure of CVI Information;
• “Notification of Emergency or Exigent Circumstances”; and
• “Tracking Log for CVI Received”

All three of these instruments are still required by the DHS CVI Procedural Manual; the first with mandatory language (“must promptly report”) and the other two with permissive language (“should be kept and submitted” and “DHS encourages"). In fact, the first is required by the CFATS regulations {6 CFR 27.400(d)(7)}.

The notice would appear to attempt to address these three instruments by stating that:

“The Department expects that in many instances when the Department may need or want to collect information regarding emergency and/or unauthorized disclosure of CVI, the collection would not be covered by the Paperwork Reduction Act because the information would be collected during the conduct of an investigation involving specific individuals or entities. See 44 U.S.C. 3518(c)”

That would certainly be true of the subsequent investigation of the reports in the first two instances, but not the initial reports themselves.

I would like to suggest that DHS continues to retain these three instruments in this ICR with an appropriate low number of respondents and the current estimate of burden hours and cost rates.

Public Comments


DHS is soliciting public comments about this ICR. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; DHS-2017-0015). Comments should be submitted by June 19th, 2017.

A copy of this blog post is being submitted as a comment to this ICR notice.

Friday, October 14, 2016

ISCD Updates Top Screen – CVI FAQ

Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated their response to one of their frequently asked questions (FAQ) on the CFATS Knowledge Center page. The latest update to FAQ # 1586 was a change in the URL for the Chemical Vulnerability Information (CVI) training page. That minor change is the reason that there was no new ‘Latest News’ entry for this FAQ response revision.

Change in CVI Training Requirements


The real news for this FAQ should have been a discussion when it was last revised last February. The FAQ originally (published in May 2009) described the CVI Authorizing Statement that was part of the initial sign on to the Top Screen page. That Statement was the abbreviated CVI training that was required for the Top Screen; full CVI training was not required until the facility received their initial notification letter that, as a result of the review of their Top Screen, they had been designated a covered facility under the Chemical Facility Anti-Terrorism Standards (CFATS) program.

The new Chemical Security Assessment Tool (CSAT) Portal User Manual (issued as part of the CSAT 2.0 rollout) makes it clear that completion of the CVI training is required before CSAT registration can be completed. The old manual (published in 2009) did not even mention CVI, much less require CVI training before registration. Apparently, sometime between 2009 and February of this year when FAQ #1586 was last updated, there was a change in the registration process that required CVI training before the Top Screen could be completed.

CVI-CSAT Linkage


Another interesting thing is found in a note at the bottom of the response to FAQ #1586:

“Note: The email address associated with the CVI Authorized User training record must match the email address associated with the CSAT User Account in order to complete synchronization between the user’s CVI and CSAT accounts.”

This is not mentioned in the new CSAT Portal User Manual.

This could cause some problems for people who completed their CVI training before they started work at the organization for which they are requesting CSAT access. For example, I completed my CVI training in 2007 using my personal email account. Since most organizations frown on (or outright prohibit) using personal rather than corporate email accounts for conducting company business, it looks like I would have to re-do my CVI training using a new corporate email address prior to registering as a CSAT user in a new company.


It is possible that a call to the CFATS Help Desk {(866) 323-2957} could resolve the problem if it arises.

Wednesday, September 14, 2016

NARA Publishes CUI Final Rule

Today the National Archives and Records Administration’s (NARA) Information Security Oversight Office (ISOO) published a final rule in the Federal Register (81 FR 63323-63347) to establish oversight regulations for a variety of federal controlled unclassified information (CUI) programs. The new regulation establishes policy (32 CFR 2002) for agencies on designating, safeguarding, disseminating, marking, decontrolling, and disposing of CUI, self-inspection and oversight requirements, and other facets of the Program. The effective date of this rule is November 14th, 2016.

The notice of proposed rulemaking (NPRM) for this rule was published in May 2015. I did a series of blog posts on the provisions of that NPRM. There were only 14 comments filed in response to the NPMR, but they resulted in a number of changes made in the final rule. This final rule was approved by OMB on August 9th.

This rulemaking was designed primarily to effect the CUI protection activities of federal agencies, but it also applies to all organizations (sources) that handle, possess, use, share, or receive CUI—or which operate, use, or have access to Federal information and information systems on behalf of an agency.

CUI Registry


Section 2002.10 requires that NARA (the CUI Executive Agency – CUI EA) establish a CUI Registry to act as “the authoritative central repository for all guidance, policy, instructions, and information on CUI” {§2002.10(a)(1). The CUI Registry has been established and among other things it provides the current list of non-classified information protection programs covered under this regulation. Those programs include such critical infrastructure programs as:


The programs marked with an asterisk (*) identify those programs that are codified in the U.S. Code, Code of Federal Regulations, or as a Government-wide policy. This is an important distinction for this regulation. The regulation sets minimum standards for CUI Basic programs, programs while the codifying documents for the CUI Specified programs set program standards that do not conflict with the minimum requirements of the CUI regulations. If existing CUI Specified programs do not meet the minimum security standards set forth in this rule, the programs will have to be updated to come into compliance.

NIST SP 800-171


Federal agencies holding CUI on computer systems are required to conform with the computer system requirements of FIPS Pub 199 at no less than the moderate confidentiality impact level {§2002.14(g)}. For non-federal information systems the computer security standard that must be applied is NIST SP 800-171{§2002.14(h)(2)} for systems used to process, store or transmit CUI.

Commentary


Most private sector organizations are not going to be required to process, store or transmit CUI. With one major exception, CUI information will generally be information that federal agencies will have received from non-federal agencies (including private sector companies). The CUI designation is being used to protect the information while in federal control. Security information that is subsequently shared by the federal agency may have CUI designations to protect the source of the information from public disclosure.

The one major exception is the Chemical-terrorism Vulnerability Information (CVI) program administered under the Chemical Facility Anti-Terrorism Facility Standards (CFATS) program. Again the basis of the CVI (a CUI designation) protections is CFATS security information (Top Screens, Security Vulnerability Assessments and Site Security Plans for instance) being shared by private sector entities to a government agency (DHS Infrastructure Security Compliance Division – ISCD). The CFATS regulations, however, require the originating facility to protect the information using the procedures set forth in the CVI Procedures Manual.


The CVI program is a listed CUI Specific program, so where ever the current CVI procedures meet or exceed the requirements for storage, marking, transmission, sharing, declassifying or destroying the CVI information, no change in the CVI program will be required. The one obvious area where the CVI program does not meet the CUI program requirements is in specifying the NIST 800-171 standard for computer systems used to handle CVI information. Other minor changes may also be necessary.

Friday, September 2, 2016

Top Screen 2.0 – What’s Missing

This is the second in a series of blog posts about the new Top Screen manual recently published by the DHS Infrastructure Security Compliance Division (ISCD). This manual supports changes being made to the Chemical Security Assessment Tool (CSAT). These revisions are being called CSAT 2.0 by ISCD. Earlier blog posts in the series include:


Missing Items


While there are any number of changes being made in the new Top Screen manual one of the most obvious set of changes from the previous Top Screen Questions manual (besides the type set and organization) are the elements that are missing from the new manual. They include:

• CVI Authorizing Statements;
• Paperwork Burden Notice;
• Submission Statement;
• EPA RMP Facility Identifier;
• All refinery specific questions;
• All liquefied natural gas questions;
• All gasoline storage questions;
• All mission critical chemical questions; and
• All economically critical chemical questions.

The first three items are administrative in nature and the first and last of these may actually still be on the screen in the on-line Top Screen tool; they did not really need to be mentioned in this manual. The missing Chemical-terrorism Vulnerability Information (CVI) Authorizing Statement will be discussed more completely below.

The removal of the RMP question is interesting in light of recent concerns about the lack of information sharing between DHS, EPA and OSHA on issues of chemical safety and security (see EO 13650). This question never did seem to be of much use in assessing the terrorism risk level of a facility, but its inclusion could have been useful in setting up a formal information sharing process with the EPA.

The refinery questions in the original Top Screen were related to economic considerations (capacity, market share, end-users, etc). These were included as DHS intended to include economic risk considerations in their risk analysis. They never actually got around to doing this (due to the complexity of that analysis) and it would seem that they now have little intention of doing so. This would also explain the removal of the mission critical and economically critical chemical questions which were originally intended to be used for the same purpose.

The missing liquefied natural gas and gasoline storage questions are related to more complex issues that will be dealt with in a later posting in this series. While the gasoline storage questions from the earlier version of the Top Screen were removed, ISCD did include a few new question that will be dealt with in a later discussion of Release-Flammable COI section of the Top Screen.

CVI Issues


The CVI program is a part of the CFAT program that limits the release of sensitive but unclassified information about the security of facilities covered in the CFATS program. To access CVI information individuals have to complete a CVI training program and have a legitimate need to know, or access to, the information.

Since the individual bits of information that the facility uses to complete the Top Screen are not covered under the CVI program DHS has not required individuals filling out, reviewing, or submitting the Top Screen to have completed CVI training. It is only the completed Top Screen submission or the letter from DHS subsequent to the submission of the Top Screen that is considered to be CVI protected information.

The original intent of the CVI Authorizing Statement on the Top Screen was to serve as a non-disclosure agreement between the submitting facility and ISCD. It also provided information about how to get the required CVI training to be able to access CVI protected information in the future.


Either the DHS lawyers determined that this was not an effective non-disclosure agreement, or that one was not needed. It is also possible that this CVI information is being moved to the new CSAT registration tool manual that we are expecting to see in the next couple of weeks. We will just have to wait and see.

Monday, May 23, 2016

ISCD Adds New CVI FAQ to CFATS Knowledge Center

This afternoon the DHS Infrastructure Security Compliance Division (ISCD) added a new frequently asked question (FAQ) to the CFATS Knowledge Center. The new FAQ (# 1770) relates to the relationship between the Chemical-Terrorism Vulnerability Information (CVI) program and the Freedom of Information Act (FOIA).

FAQ # 1770 asks: “Can Chemical-terrorism Vulnerability Information (CVI) be released under the Freedom of Information Act (FOIA)?”


The answer makes clear that CVI protected information may not be released under either the Federal FOIA nor any similar State or local laws. It also provides a link to the CVI Handbook for further clarification of the rules concerning the protection of CVI.

Wednesday, May 11, 2016

ISCD Updates FAQs on CFATS Knowledge Center – 05-11-16

This afternoon the DHS Infrastructure Security Compliance Division (ISCD) updated the responses to 12 Frequently Asked Questions (FAQ) on the CFATS Knowledge Center. A quick check of each of the FAQ responses indicates the ISCD is updating URLs for a number of their web sites. The revised FAQs and the affected URLs are shown below.


#1275 What needs to be done when a facility is bought or sold? Corrected URL for chemical security landing page.
#1405 How will I know the agricultural extension has been lifted and what to do next? Corrected URL for chemical security landing page.
#1450 What is the URL to the CSAT Web Portal? Corrected URL for CSAT Web Portal.
#1485 What do I need to have available in order to complete Top Screen? Corrected URL for chemical security landing page.

The CVI Training landing page was also updated today to show the new URL for the actual CVI Training program.

NOTE 1: The old URLs are still linking to the correct pages. No telling when DHS will cut-off the old URLs.


NOTE 2: There are currently some difficulties connecting to the CSAT Web Portal and the CVI Training Program. I expect that they will both be working tomorrow.

Tuesday, May 10, 2016

ISCD Updates Three CFATS FAQ Responses – 05-10-16

Today the DHS Infrastructure Security Compliance Division (ISCD) updated the responses for three Frequently Asked Questions (FAQ) on the CFATS Knowledge Center. All three FAQs deal with Chemical-Terrorism Vulnerability Information (CVI) issues.

The three FAQ are:


Recently, ISCD changed the URL for the actual CVI training web site. This is reflected in the change to FAQ #516. As has been the case for a couple of years now the printed link shown in the FAQ is not the actual URL for the training web site; that URL is https://cvi.dhs.gov/dana-na/auth/url_61/welcome.cgi. Unfortunately, the CVI Training web page (linked to in FAQ #1606) has yet to be updated with the correct URL to the actual training site.

Both FAQ #1606 and #1763 deal with the need for synchronizing ones CSAT login and CVI authorization number. This is needed to allow access to CVI information available on the CSAT tool. You can either do this when you finish the CVI training or when you sign into the CSAT web site.

FAQ #1763 includes the very important note (and it should probably have been included in the response to FAQ #1606):

“Note: The email address from the CVI Authorized User training record must match the email address associated with the CSAT User Account in order to complete synchronization between the CVI and CSAT accounts.”

For people that may have moved around since they completed their CVI training this may cause something of a problem. There are two ways to resolve this, re-take the CVI training using the newer email address, or contacting the CFATS Help Desk ((866) 323-2957) for assistance.


Wednesday, April 13, 2016

ISCD Adds 3 New FAQs to CFATS Knowledge Center

This morning the DHS Infrastructure Security Compliance Division (ISCD) updated the frequently asked question list on the CFATS Knowledge Center. There was no accompanying notice in the ‘Latest News’ section of the landing page, but three new FAQ’s were added and an older FAQ dating back to 2008 was updated.

Two of the FAQs deal with Chemical-terrorism Vulnerability Information (CVI) and the other two deal with compliance inspections for facilities that utilized the Expedited Approval Program (EAP). The four FAQ’s in question are:


CVI FAQs


The response to #1490 deals with the fact that information is only covered under the CVI rules when it is specifically associated with the CFATS program. Much of the information submitted to ISCD via the Chemical Security Assessment Tool (CSAT) is normal business information that is routinely used outside of the CFATS program. Things like the facility address, inventory levels and the like are only considered CVI once they have been entered into the CSAT, and even then only in association with the CSAT forms (either paper or electronic copies).

Anyone that handles CVI material must be a CVI Authorized User (completed the on-line CVI training and have a need-to-know). The actual data being input to the CSAT tool is CVI so anyone doing that entry must be a CVI Authorized User. Upstream of that data entry, during the data collection process, the question is murkier so the FAQ response suggest contacting the CFATS Help Desk for help in making an exact determination.

The response to #1770 explains that CVI is exempted from disclosure under the Federal Freedom of Information Act (FOIA) as well as State and local versions of that law under provisions of 6 USC 623(e) and 6 CFR §27.400(g). It goes on to explain that State and local FOIA requests for CVI information should be forwarded to the DHS Information Management and Disclosure Office, (NPPD.FOIA@hq.dhs.gov).

EAP Compliance Inspection FAQs


The response to #1771 explains that a compliance inspection under the EAP will be looking for the same information that compliance inspection under the standard site security plan (SSP) would be looking for. Not mentioned in the ISCD response is another ISCD document that briefly outlines what to expect from a CFATS inspection.

The response to #1772 explains that while ISCD is allowed to use a mixture of governmental and non-governmental inspectors [authorized by 6 USC 622(d)(1)(B)], that they are currently only using government employees, known as Chemical Security Inspectors (CSI).


Thursday, October 8, 2015

DHS Updates CFATS Web Site

Today the folks at DHS Infrastructure Security Compliance Division (ISCD) updated the Critical Infrastructure: Chemical Security web site. This web site is essentially the web site for the Chemical Facility Anti-Terrorism Standards (CFATS) program. The most obvious change was to provide a link to the October 2015 CFATS Fact Sheet that I discussed yesterday. Additionally ISCD updated almost every page with links on this site.

For most of the pages the updates were mostly cosmetic; bringing a unified format to the pages and adding links to provide more depth to the discussion. There were some significant changes (typically providing more information) made to the following pages:



There was one page that was putatively included in today’s update but still remains woefully out of date. That is the Chemical Security Laws and Regulations page. While the ‘date published’ was changed at the bottom of the page, the page still does not include any reference or link to the current statute authorizing the CFATS program; the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014 (PL 113-254). This is the second time that this page has been “updated” this year without including mention of the new authorization statute.
 
/* Use this with templates/template-twocol.html */