Showing posts with label CVI Training. Show all posts
Showing posts with label CVI Training. Show all posts

Tuesday, February 23, 2016

ISCD Updates a CVI FAQ Response

Today the folks at DHS Infrastructure Security Compliance Division (ISCD) updated one of the frequently asked question (FAQ) responses on the CFATS Knowledge Center web site. It was a relatively minor change to the response to FAQ #516 dealing with the on-line training program for the Chemical-terrorism Vulnerability Information (CVI) program.

The latest revision to that FAQ response in December failed to include the “https:” in the description of the link to the CVI training web site. The older link worked perfectly well, but without the “https:” the reader did not know to expect that it was a secure website. Neither link accurately reflects the actual destination of the link which is https://csat.dhs.gov/dana/home/index.cgi.

BTW: While this change is relatively minor it does continue an apparent change in policy on the CFATS Knowledge Center of not announcing changes or additions to FAQs. This has apparently been in effect since December.

Thursday, January 31, 2013

CFATS Knowledge Center Update – 01-31-13


This morning the folks at ISCD updated the CFATS Knowledge Center with a minor change to their response to the frequently asked question (FAQ) concerning where individuals can take Chemical-terrorism Vulnerability Information (CVI) training. The new response reads:

“Go to the DHS Critical Infrastructure: Chemical Security website (http://www.dhs.gov/chemicalsecurity) and click on the link ‘Complete Chemical-terrorism Vulnerability Information (CVI) Training.’”

The only difference between this wording and the original wording from the August 23, 2007 posting is that the words “at the bottom of the page” have been removed from the end of the sentence. Those words were applicable to the old ‘Chemical Security’ web page that was discontinued when DHS updated their sites last year. This is a minor change, to be sure, but one that helps avoid some confusion on the part of facility personnel looking for information.

Interestingly, while the link provided does work, the actual website URL is http://www.dhs.gov/critical-infrastructure-chemical-security.

Wednesday, March 28, 2012

CVI Training Access Problem Solved

I just got a very nice email from the folks at the CSAT HelpDesk concerning my reported inability to access the CVI Training site. They haven’t fixed the site because they couldn’t replicate the problem; fair enough.

They didn’t let it end there, however. They suspected that the problem was with my computer and offered a suggestion to correct the problem that worked very nicely. Here is their suggestion:

“Also, if you are using Internet Explorer to access CSAT/CVI, make sure the internet security is enabled within the browser settings by performing the following actions:

- Launch Internet Explorer web browser

- Under the "Tools" menu, select "Internet Options"

- Select the "Advanced" tab

- Scroll down to the "Security" heading (towards the bottom)

- Select the following option:

-- "Use TLS 1.0." (Ensure you place a check mark in the box for the setting.)

- Select "Apply" to save this setting.”

Actually, these instructions seem very familiar; I think they used to be in one of the CSAT manuals (may still be, but I can’t find it in a quick search). Oh, yes and they work.

I suppose that I probably should have contacted the HelpDesk folks {CFATS Helpline, 866-323-2957; Monday-Friday 7:00 a.m. – 7:00 p.m., Eastern Time}, but the last time I contacted them I was told they couldn’t talk with me because I was ‘The Press’. Fair enough; that is a standard procedure for business and government; limit the people who can talk to the press so that bad (incorrect not embarrassing) information doesn’t go out in the name of the organization. Unfortunately, I no longer have a working PAO contact at ISCD; they get changed more often than Acting Directors.

If you are not the press, but a harried chemical security person at a high-risk or potentially high-risk chemical facility, you should certainly try to contact them with any CSAT/CFATS related problems that you have. They have the standard answers for standard questions, know how to fix problems like this, and can put you in touch with the appropriate person when necessary.

Thanks for the Help today.

Tuesday, March 27, 2012

CVI Training Link Still Dead

It has now been more than two weeks since I reported that the link {https://csat.dhs.gov/cvi_training/}for the ISCD Chemical-terrorism Vulnerability Information (CVI) Authorized User Training does not work. Since completion of the CVI training is a pre-requisite for using many of the CSAT tools, not having this training available is certainly going to put a crimp in many organizations’ implementation of CFATS.

Monday, March 12, 2012

ISCD Updates CVI Pages?

It seems that ISCD is going through a review process on their CFATS related web pages. You can see this by observing the “This page was last reviewed / modified on ….” on the bottom of many of their pages (more on their pages than just about anywhere else in DHS). Today the review took place on the landing page for the CFATS Chemical-terrorism Vulnerability Information (CVI) program. As far as I can tell there were no substantive changes made on this page.

Now this is one of the pages that I try to check every business day, looking for updates on the program; particularly the overdue changes expected in response to President Obama’s Executive Order 13556 on Controlled Unclassified Information (CUI). I don’t typically take time to check all of the links on the page (and they are quite numerous on this particular page) unless the date on the bottom of the page changes; like today.

When I checked each link today, I found that one of those pages had been changed reviewed/changed back in January; the Training for Chemical-terrorism Vulnerability Information page. Again, I didn’t see any significant changes on this page, but I did note something of concern; all of the links to the CVI training program were dead links, returning a “Internet Explorer cannot display the webpage” notice. I don’t know if other browsers can access the sites.

Hopefully someone in ISCD will notice this problem and correct the links. Probably not, they seem to be worrying about other things lately.

Thursday, May 13, 2010

Top Screen CVI

The latest posting on the Chemical Security Action Blog by Ryan Loughin takes a look at the CFATS Top Screen. While the vast majority of initial Top Screens have already been submitted, there will be a number of new facilities submitting their first Top Screens every month. This blog will be a valuable initial source of information for those first time submitters. Having said that, I do have a tiny nit to pick with one piece of information that Ryan includes in this post. He states that “that the person filling out the Top-Screen questionnaire must be Chemical-terrorism Vulnerability Information (CVI) authorized”. Then he explains that this “means someone who has had training by DHS on the handling of sensitive material and information”. It is that last statement that I have a minor, technical problem with. According to the Top Screen Users Manual, a first time Top Screen submitter must accept the “CSAT Top-Screen Authorizing Statements” found on the initial Top Screen page to become an “authorized user of CVI for access to CVI created by the completion of the CSAT Top-Screen” (pg 12). Now the Authorizing Statements summarize the information provided in the CVI training, but they are not a substitute for completing the training. If the facility is declared a high-risk facility, the Submitter and Preparer will have to complete the actual CVI training before they are allowed into the more advanced tools in the Chemical Security Assessment Tool (CSAT). DHS set the Top Screen CVI requirements up this way to avoid having to require tens of thousands of people to complete CVI training that would never require access to CVI beyond the letter from DHS stating that they are not a covered facility under CFATS. According to the Top Screen Users Manual, now that the initial surge of Top Screen submissions is complete, the CVI requirements may be changing: “DHS expects that in the near future access to the Top-Screen will be limited to only CVI Authorized Users that have completed the CVI training and received a CVI Authorized User Number.” (pg 12) When that happens Ryan’s post will be 100% correct instead of ‘just’ 99.99% correct. Besides, completing the full CVI training is probably a good idea for the first time Top Screen user in any case.

Friday, May 8, 2009

Bullzi Security - CVI Training

As I have mentioned on a number of occasions, I really do love the internet as an information source. Yesterday one of my daily Google® searches turned up a Marketwire® report on a security company called Bullzi Security. The thing that caught my attention (and the attention of the search engine) was the report of “Creation of the Chemical-terrorism Vulnerability Information (CVI) Training Course”. I sent the company an email requesting information and was soon talking to Mike Welch, co-founder and Vice President for the company. It turns out that Bullzi is a full service security company that got involved in developing a variety of training products to support their customers. They have gone from conventional classroom instruction to a an E-learning system to optimize the delivery of their training. Their training products are compatible with a variety of learning management systems. The Marketwire report provides a short list of recently developed training program. Looking at that list it seems clear that this organization has more of a background in a variety of cyber security issues including the NERC Critical Infrastructure Protection program and the credit card industry PCI program. I asked Mike how they got involved in CFATS training. It seems one of their customers asked them to develop a training program on the DHS Chemical-Terrorism Vulnerability Information (CVI) program in CFATS. Mike described the program as a high-level, individual training program that teaches the basic requirements of the CVI program to include the identification, and marking of CVI documents, as well as the requirements for properly securing those documents. He noted that the current training program is a generic version that can be upgraded and customized for particular customer requirements. While I have not yet actually seen the training program, it sounds like this company is taking the right kind of approach to their training development. Anyone interested in additional information should contact Mike Welch by phone (1-407-562-1864) or email (mdwelch@bullzisecurity.com).
 
/* Use this with templates/template-twocol.html */