Showing posts with label ChemLock. Show all posts
Showing posts with label ChemLock. Show all posts

Wednesday, August 19, 2026

Review - ChemLock Fact Sheets – August 2026

For those of you familiar with my “Looking Back” series of blog posts (latest here), there was almost one today about a post of mine from December 2021 on “Review - ChemLock Fact Sheets”. However, after reviewing the CISA ChemLock web site, I decided that it was probably more appropriate to do a new blog post on the topic. 

Fact Sheets 

Early in the CFATS program, DHS started producing a number of short informational brochures about various chemical security topics. Typically just two pages, these Fact Sheets provided a brief look at a specific topic and provided links to other, more detailed information about the topics. They were never designed to make someone a chemical security expert, but they did form a valuable library for chemical professionals to become more aware of security issues. 

When I wrote that first blog post (CFSN version here) there were just seven fact sheets on the ChemLock web site. Now there are three separate pages listing listing 14 separate ChemLock Fact Sheets: 

Commentary  

The Office of Chemical Security continues to have a problem publicly sharing information on the ChemLock Program. While there have been training announcements from @CISAgov for various ChemLock classes (here is the most recent), I have not seen any other outreach efforts and no mentions of these new fact sheets. I understand that CISA is still recovering from the emasculation of the agency that occurred last year, but if they want to keep the ChemLock program going, they are going to have to start making more of an effort to bring facilities into the fold. Publicly talking about the program is an important part of that effort. 


For more information on these fact sheets, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-fact-sheets-august-2026 - subscription required. 

Wednesday, August 5, 2026

OMB Approves ChemLock ICR – 8-4-26

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a new information collection request (ICR) from CISA for the ChemLock Program”. The 60-day ICR notice was published on December 31st, 2024, and the 30-day ICR notice was published on June 2nd, 2026. This approved ICR now authorizes CISA to collect information in support of its voluntary chemical facility security program, ChemLock. 

The ICR reporting notice explains that:  

CISA serves as Sector Risk Management Agency (SRMA) for the Chemical Sector. CISA has established ChemLock, which is [a] voluntary program for facilities that possess dangerous chemicals. The information will support CISA’s Office of Chemical Security in providing resources tailored to the specific facilities requesting services under the ChemLock program. 

Monday, May 4, 2026

Looking Back – 12-24-21 – ChemLock Fact Sheets

 Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today blog post from December 24th, 2021, that looks at some of the Fact Sheet from the then new ChemLock program, makes the short list. Now that DHS is funded through the end of the fiscal year, the ChemLock program, CISA’s voluntary chemical facility security program, is back in operation. The fact sheets described in this post give a brief look at how the program works. 

Tuesday, January 13, 2026

Reports of the Demise of the ChemLock Program Premature

While the current Administration announced their intent to cancel the ChemLock Program, I just saw this on CISA announcement on X:


Apparently CISA expects Congress to ignore this portion of the DHS budget request and continue to provide some level of chemical security funding in FY 2026.

Tuesday, January 6, 2026

Reader Comment – FY 2026 CISA Budget

Yesterday, a long-time reader and former Chemical Security Inspector sent me a message on LinkedIn about a document he had run across. The DHS Fiscal Year 2026 Budget in Brief was published in July of last year and outlined some of the details of the President’s proposed budget for FY 2026. Even with a Republican controlled Congress, the proposed Budget was not going to survive contact with the legislators, which is why I provide so little coverage of the related documents here.

David pointed me at a specific portion of document, and I am glad that he did, and now wish that I had commented about it at the time. The paragraph is in the CISA portion of the budget summary and it reads:

“Chemical Security Anti-Terrorism Standards ... ($40.0 million), (178 full-time equivalents)

“Due to the sunsetting of the Chemical Security Anti-Terrorism Standards program and the delay in implementing the Secure Handling of Ammonium Nitrate provisions of the Homeland Security Act, this budget reduces the Chemical Security Inspectors and other Headquarters-based staff, as well as eliminates voluntary ChemLock programs.”

We knew, of course, that the CFATS funding was going to be cut, the President never liked the program (45 proposed eliminating the program in 2020.) And because of some bureaucratic games, the CSI were part of the CISA regional offices rather than in CISA proper, there was some hope for keeping some level of the chemical security expertise in those offices after CFATS died, so ‘reduces’ sounds better than ‘eliminates’.

What is most concerning to me is the clause of the quote, eliminating ChemLock. Many of us in the chemical security community hoped to see that program take up the mantel of chemical security so that facilities had some sort of federal support. I even proposed a way to make the voluntary ChemLock program more effective by providing incentives for participation. Apparently, in the Administration’s collective mind, ChemLock was too tainted by CFATS to be allowed to continue.

Fortunately, in a real twisted way, some level of chemical security spending is almost certainly going to be included in the FY 2026 spending for DHS. The reason for that is that there will not be a separate DHS spending bill (too many controversies surrounding DHS components), nor is it likely to be included in another minibus. So we are almost certainly going to see DHS funding included in a full year continuing resolution, and that CR will continue (that’s the ‘C’ in CR) spending levels set before CFATS was allowed to expire. That funding will mostly get reprogrammed (most likely to immigration enforcement), but some vestige of chemical security will get funded, including (hopefully) ChemLock.

Still, when all is said and done, we really need Congress to step up and pass some sort of chemical security authorization bill. Standing CISA back up would be difficult from both a legislative and regulatory perspectives, but maybe a formal authorization of an upgraded (but still voluntary) ChemLock program could be possible.

Thursday, April 10, 2025

Review – Chemical Security Inspector Reduction in Force – Part 4

I have been talking about the upcoming reduction in force of CISA’s Chemical Security Inspectors (CSI) this week. This will probably be the last post in this series of free posts in the series so I thought that I would try to outline what I would like to see happen. The earlier posts in this series include:

CSI RIF,

Chemical Security Inspector Reduction in Force – Part 2, and

Chemical Security Inspector Reduction in Force – Part 3

Too Late to Fix

To start with, I learned today that the CSI have been given until Monday to make their decisions about whether to take the offered ways to quit (making DHS look better than firing them would), or to stay around long enough to actually get their reduction in force (RIF) notices that everyone knows are coming. Neither option is great. Take the deferred resignation and get paid (with benefits) through the end of the fiscal year, but resignations mean that there will be no unemployment benefits. Get RIFed and they are eligible for unemployment benefits, but at much lower pay than they have been receiving. Federal medical benefits also disappear; fortunately, Obama Care is now available, not great, but better than what was available the last time I was laid off.

 

To see the alternatives that would provide a longer-term solution to the job situations for CSI and the security support for chemical facilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemical-security-inspector-reduction-7ca - free content.

Tuesday, February 25, 2025

CISA Announces ChemLock Security Awareness Training – 2-25-25

I got an email from CISA today (nothing special about me here, anyone can sign up for these emails here) about a new chemical security awareness training program being offered by the ChemLock folks. The email reported that:

“The Cybersecurity and Infrastructure Security Agency (CISA) is proud to announce the new ChemLock: Security Awareness Training, which helps employees at all levels of an organization understand the risk of dangerous chemicals, their responsibility in protecting those chemicals from malicious actors, and what to do when they recognize potential threats.”

The new program (ChemLock: Security Awareness Course) comes with its own web page that provides a program overview, and the current schedule of on-line presentations. That page notes that:

“This interactive, practical, no-cost course runs approximately 1 hour in length and is appropriate for personnel at all levels of an organization regardless of their security expertise or involvement with dangerous chemicals.”

If you have a large digital TV in your training room, you might want to schedule key personnel to participate in a group training program.

NOTE: This is the ChemLock program as it currently exists, not the enhanced program that I have been advocating since the start of the year.

Monday, February 24, 2025

Review - ChemLock and Cybersecurity

This is part of a series of blog posts looking at the potential for the authorization of CISA’s existing ChemLock program and using it as a voluntary replacement for the now defunct Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in this series include:

CFATS is Dead,

Making ChemLock Safety Act Compliant – ChemLock Program Background,

ChemLock and Tiering,

Reader Comment – TSDB Screening for ChemLock,

ChemLock and TSDB Screening,

ChemLock and Risk Based Performance Standards,

ChemLock and Chemical-Terrorism Vulnerability Information,

ChemLock and Information Sharing,

ChemLock and DHS Chemicals of Interest.

NOTE: Previous articles in this series have been removed from the CFSN Detailed Analysis paywall.

The CFATS programs was one of the first federal security programs that specifically addressed cybersecurity issues, including control systems. The issue was initially addressed in regulatory risk-based performance standards (RBPS), 6 CFR 27.230(a)(8):

“(8) Cyber. Deter cyber sabotage, including by preventing unauthorized onsite or remote access to critical process controls, such as Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS), Process Control Systems (PCS), Industrial Control Systems (ICS), critical business system, and other sensitive computerized systems;”

More details about what should be addressed in site security plans under RBPS 8 were outlined in the Risk-Based Performance Standard guidance document. While the guidance document was published in 2009 (and never updated), much of the cybersecurity discussion is applicable today. That document discussed nine categories of security measures that were applicable to cybersecurity:

• Security policy,

• Access control,

• Personnel security,

• Awareness and training,

• Monitoring and incident response,

• Disaster recovery and business continuity,

• System development and acquisition,

• Configuration management, and

• Audits

Moving Forward

As I noted in an earlier post the RBPS could form a valuable part of the ChemLock Safety Act program, but the Guidance Document for the RBPS needs updating, and the discussions dealing with cybersecurity probably need the most work because of the changes that have occurred in cybersecurity management since the 2009 publication of that guidance.

For more details about the cybersecurity issues that could be improved in the RBPS guidance document, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-and-cybersecurity - subscription required.


Sunday, February 16, 2025

Review - ChemLock and DHS Chemicals of Interest

This is part of a series of blog posts looking at the potential for the authorization of CISA’s existing ChemLock program and using it as a voluntary replacement for the now defunct Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in this series include:

CFATS is Dead,

Making ChemLock Safety Act Compliant – ChemLock Program Background,

ChemLock and Tiering,

Reader Comment – TSDB Screening for ChemLock,

ChemLock and TSDB Screening,

ChemLock and Risk Based Performance Standards,

ChemLock and Chemical-Terrorism Vulnerability Information,

ChemLock and Information Sharing.

NOTE: Previous articles in this series have been removed from the CFSN Detailed Analysis paywall.

An important component of the CFATS program (possibly the most important part of the risk assessment process) is the DHS Chemicals of Interest (COI) list found in Appendix A of 6 CFR Part 27. The COI list provided a list of chemicals and concentrations that served as a basis for the requirement for chemical facilities to provide an initial Top Screen report. What is frequently forgotten about the COI list is that it also formed an important part of the risk assessment done by DHS to determine whether a facility was considered to be a high-risk facility that would be covered by the CFATS program and to which Tier Level the facility would be assigned.

While the first part of that assessment would not be required by the revamped ChemLock program being suggested by this series of blog posts (the ChemLock program is and would remain voluntary), the risk ranking and tiering would still need to be assigned to facilities seeking the Safety Act certification being proposed in this series of posts.

It seems clear that even with the death of the CFATS program, the DHS chemicals of interest list could form a valuable part of the upgraded ChemLock program being discussed here. Since the ChemLock program would remain a voluntary chemical security program, there would have to be some modifications made to how the rules provided in Appendix A would be applied to the new program. Further discussion is needed.

 

For a more detailed discussion about the COI list could be applied to the upgraded ChemLock program, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-and-dhs-chemicals-of-interest - subscription required.

Monday, February 10, 2025

Review - ChemLock and Information Sharing

This is part of a series of blog posts looking at the potential for the authorization of CISA’s existing ChemLock program and using it as a voluntary replacement for the now defunct Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in this series include:

CFATS is Dead,

Making ChemLock Safety Act Compliant – ChemLock Program Background,

ChemLock and Tiering,

Reader Comment – TSDB Screening for ChemLock,

ChemLock and TSDB Screening,

ChemLock and Risk Based Performance Standards,

ChemLock and Chemical-Terrorism Vulnerability Information.

NOTE: Previous articles in this series have been removed from the CFSN Detailed Analysis paywall.

The CFATS program handled a lot of sensitive information that was categorized as Chemical-Terrorism Vulnerability Information (CVI). In order to limit the exposure of that information, DHS established the Chemical Security Assessment Tool (CSAT) as a secure, on-line portal for facilities to share sensitive information with the regulators and provided a secure method for facilities to receive CVI information from DHS. If the ChemLock program is going to be upgraded to serve as a voluntary replacement for the CFATS program, a similar secure information sharing system will have to be employed to protect the information sharing required to implement that expanded program.

An authorized ChemLock program could use the security information sharing tool developed for the CFATS program as the backbone for the upgraded voluntary ChemLock program and provide a means for facilities and CISA to share chemical security intelligence information. While the Safety Act certification process would be a primary incentive for facilities to formally involve themselves in the ChemLock program, a secure source of chemical security information would also provide an additional incentive for facilities to join ChemLock, expanding the reach of the voluntary program.

 

For more information about using the CSAT backbone to provide an information sharing environment, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-and-information-sharing - subscription required.

Monday, February 3, 2025

Review - ChemLock and Chemical-Terrorism Vulnerability Information

This is part of a series of blog posts looking at the potential for the authorization of CISA’s existing ChemLock program and using it as a voluntary replacement for the now defunct Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in this series include:

CFATS is Dead,

Making ChemLock Safety Act Compliant – ChemLock Program Background,

ChemLock and Tiering,

Reader Comment – TSDB Screening for ChemLock,

ChemLock and TSDB Screening,

ChemLock and Risk Based Performance Standards.  

NOTE: Previous articles in this series have been removed from the CFSN Detailed Analysis paywall.

The CFATS program collected a great deal of sensitive information from facilities; both covered facilities and facilities submitting Top Screen information to see if they were to become covered facilities. The information provided to CISA that would be of potential interest to any terrorist organization planning on attacking the facilities. To prevent that sort of information sharing, it was protected by the Chemical-Terrorism Vulnerability Information (CVI) program.

While the CFATS program was in effect, the CVI program was authorized by 6 USC 623. The regulations concerning the program can be found at 6 CFR 27.400. CISA’s predecessor published a revised guidance manual for the program in September of 2008. When CISA stood up the ChemLock program, they made no attempt to apply CVI protections to information provided under the new program, maintaining that, since the two programs were separate and distinct, there was no statutory authorization for applying the CVI protections to the ChemLock program.

Any attempt to authorize the ChemLock program is going to have to specifically deal with the protection of controlled unclassified information submitted to and developed by that program. Adaption of the Chemical-Terrorism Vulnerability Information (CVI) program from the CFATS program would be the most obvious way of dealing with necessity.

 

For more information on the potential use of the CFATS CVI program to support the ChemLock program, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-and-chemical-terrorism-vulnerability - subscription required.

Sunday, January 26, 2025

Review – ChemLock and Risk Based Performance Standards

This is part of a series of blog posts looking at the potential for the authorization of CISA’s existing ChemLock program and using it as a voluntary replacement for the now defunct Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in this series include:

CFATS is Dead,

Making ChemLock Safety Act Compliant – ChemLock Program Background,

ChemLock and Tiering,

Reader Comment – TSDB Screening for ChemLock,

ChemLock and TSDB Screening.

NOTE: Earlier articles in this series have been removed from the CFSN Detailed Analysis paywall and are available to the public.

One of the key concepts upon which the CFATS program was founded is that the diversity of chemical facilities makes it nearly impossible to establish a security program which would fit each and every facility. So, when the CFATS regulations were written, DHS attempted to describe the outcome that they wanted to see from facility security programs rather than mandate what security measures facilities would be required to use. These risk based performance standards (RBPS) were codified at 6 CFR 27.230. Any authorization of the ChemLock program should direct CISA to take the same tack in making the program Safety Act (6 USC 441 et seq) compliant.

The current ChemLock security goals, properly fleshed out, could easily become the basis for a quasi-regulatory scheme by which facilities could be judged to be eligible for SAFETY Act protections. A version of the CFATS RBPS Guidance document would have to be created, tailored to the six security goals included in the updated ChemLock program and the proposed 5 risk tiers proposed in my earlier posts.

Sunday, January 19, 2025

ChemLock and TSDB Screening

This is part of a series of blog posts looking at the potential for the authorization of CISA’s existing ChemLock program and using it as a voluntary replacement for the now defunct Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in this series include:

CFATS is Dead,

Making ChemLock Safety Act Compliant – ChemLock Program Background,

ChemLock and Tiering, and

Reader Comment – TSDB Screening for ChemLock.

NOTE: Previous articles in this series have been removed from the CFSN Detailed Analysis paywall.

TSDB Screening

One of the more controversial elements of the CFATS program was the personnel surety process. Part of the risk based performance standards outlined in 6 CFR 27.230, DHS required facilities to perform “appropriate background checks on and ensure appropriate credentials for facility personnel, and as appropriate, for unescorted visitors with access to restricted areas or critical assets”. Three of the four requirements under this paragraph {§27.230(a)(12)} are relatively standard background checks performed by many businesses. The fourth requirement {§27.230(a)(12)(iv)} was more problematic: “Measures designed to identify people with terrorist ties”.

The only relatively comprehensive data base that could be used to satisfy that requirement is the Terrorist Screening Database (TSDB) maintained by the Transportation Security Administration (TSA). Unfortunately for the CFATS program, employers do not have access to the TSDB, even for the purposes of vetting employees at designated high-risk facilities.

ChemLock and Screening

There is currently no process within CISA’s voluntary chemical security program, ChemLock, that facilities could be used to conduct a similar TSDB screening process. One of the main reasons for this is that Congress needs to specifically authorize non-governmental use of the TSDB since much of the information included in the database comes from classified sources.

As part of the congressional authorization of the ChemLock program that I am advocating for here, Congress should include in that authorization the authority for CISA to process data from chemical facilities for screening against the TSDB. Since the ChemLock program is voluntary (and will have to remain that way if there is any chance for it to be authorized in the current congressional climate) the screening of employees for terrorist ties would also have to remain voluntary.

Having said that, as part of the Safety Act (6 USC 441 et seq) tie-in that I am arguing for here, facilities that are attempting to get Security Act certification from CISA would have to conduct TSDB vetting as part of the pre-requisite for that certification. Who would have to be vetted would be directly tied to the Tier ranking that I discussed in a previous post. Facilities would be allowed to identify specific chemical security zones within the facility, and anyone being authorized unaccompanied access to those zones would be required to have been vetted through the TSDB. Facilities identified as being at a Tier 5 (the lowest threat level, not previously covered by the CFATS program) would only be authorized to vet a limited number of people in critical positions described in their site security plan.

 

For more information on the TSDB screening issue, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-and-tsdb-screening - subscription required.

 
/* Use this with templates/template-twocol.html */