Showing posts with label Chemical Facility Security. Show all posts
Showing posts with label Chemical Facility Security. Show all posts

Wednesday, December 4, 2024

Review – Chemical Facilities and Sabotage Operations

A new reader at CFSN Detailed Analysis pointed me at their article on Audacy.com “Strategic sabotage is coming to a global conflict near you”. He looks at several recent sabotage operations carried out by CIA and Special Operations forces in recent history. One story-of-note here was the development of a technique to attack glass lined chemical reaction vessels:

“At the Nevada Test Site, a demolitions expert from Delta Force began experimenting. Working with different configurations of explosives, he came across a method in which they could be arranged on the outside of the vat and detonated in a sequence, which shattered the glass lining inside the chemical weapons vat, without breaching the metal exterior.”

Such an attack would take the vessel out of production for an extended period of time since glass lined vessels are custom made.

Current federal chemical security programs (the now defunct CFATS program, chemical facilities covered under the Coast Guard’s MTSA program, and to a lesser extent the ATF’s explosive facility programs) are more targeted at preventing terrorist attacks. While security measures required under those programs would have some effect against military style attacks like those outlined in the article, the operators executing those attacks would be expected to have higher levels of training and more effective equipment than the standard terrorist cell. This means that more effective security measures would be required to prevent such attacks.

Protecting selected chemical facilities from military-sabotage type attacks is going to require more extensive protective measures, but less emphasis will probably be required for emergency response activities as the attackers will not be trying to optimize their attacks for chemical releases. And fewer facilities will need to be expected to meet these higher protection requirements.

For a more detailed discussion about the differences between potential terrorist attacks and military sabotage attacks, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemical-facilities-and-sabotage - subscription required. 

Tuesday, November 14, 2023

OSHA Walk Around Inspection Rule and CFATS

Today I read a press release from the Alliance for Chemical Distribution (formerly the National Association of Chemical Distributors) on the OSHA “Worker Walkaround Representative Designation Process” notice of proposed rulemaking (NPRM) that was published on August 30th, 2023. The comment period closed on Monday. Not surprisingly, ACD (and probably most industrial organization) have concerns about the expansion of the universe of personnel that would be approved to accompany OSHA inspectors on facility walkaround tours.

The reason that my attention was called to the press release was that one of the topics used to justify the ACD’s opposition was chemical facility security. That portion of the release states:

“The most worrisome aspect of this proposal is its requirement to force facilities to permit entry to individuals who would otherwise be forbidden from entering. ACD members house a wide range of chemicals and have various chemical processes occurring at their facilities, some of which can be dangerous. For these reasons, ACD members have long supported programs such as the Chemical Facility Anti-Terrorism Standards (CFATS) and worked closely with regulators to ensure their chemicals and processes are protected. This proposal would effectively undermine these efforts as it would force facilities to grant entry to individuals without undergoing any necessary background or other safety checks. Such individuals would be given intimate access and information regarding which chemicals are stored on the premises, where they are stored, and what they are used for. This is extremely worrying and raises significant security concerns.”

ACD/NACD has long been a supporter of the CFATS program and was generally supportive of the development of the personnel surety process that was adopted by that program. Interestingly, that program would not have been impacted by the proposed OSHA walk around rulemaking. CISA only required personnel who were going to be provided unaccompanied access to restricted areas within covered facilities to undergo the advanced vetting process. OSHA inspectors conducting walkaround inspections are going to be accompanied by company representatives, so employee representatives accompanying the inspector would, by definition, also be accompanied.

But we must remember that the CFATS program was (unfortunately past tense) a counter terrorism program. There are other types of security concerns that a facility might have that could be impacted by relatively unknown outsiders accompanying an OSHA inspector on a plant walk around; innovative process details, blend recipes, and raw material suppliers are some of the types of information that a facility might want to protect. While an active CFATS program may not be an adequate justification for avoiding outsiders from accompanying an OSHA inspector, there may very well be legitimate security concerns that should be addressed by this rulemaking.

Tuesday, July 18, 2023

Review – 7 Advisories Published – 7-18-23

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from WellinTech, GE, GeoVision, Weintek, Iagona, Keysight, and Rockwell Automation.

Advisories

WellinTech Advisory - This advisory describes two vulnerabilities in the WellinTech KingHistorian.

GE Advisory - This advisory describes a heap-based buffer overflow vulnerability in the GE Digital CIMPLICITY product.

GeoVision Advisory - This advisory describes an improper authentication vulnerability in the GeoVision GV-ADR2701 cameras.

Weintek Advisory - This advisory describes four vulnerabilities in the Weintek Weincloud product.

Iagona Advisory - This advisory describes four vulnerabilities in the Iagona ScrutisWeb ATM monitoring product.

Keysight Advisory - This advisory describes two vulnerabilities in the Keysight Geolocation Server.

Rockwell Advisory - This advisory describes an uncontrolled resource consumption vulnerability in the Rockwell Kinetix 5700 DC Bus Power Supply Series A.

 

For more details about the advisories, including links to exploits and researcher reports as well as a discussion about missing vulnerabilities, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-published-7-18-23 - subscription required.

Thursday, January 20, 2022

Armed Security at Chemical Facilities – Part 2

Back in 2008 I looked at the issue of security guards at chemical facilities that would be covered under the then new Chemical Facility Anti-Terrorism Standards (CFATS) program. Then in 2009, once the CFATS Risk-Based Performance Standard guidance document was published, I specifically looked at the issue of armed guards at CFATS facilities. In that later piece, after noting that there is no CFATS requirement for armed guards, I opined that:

“The bottom line is that if a toxic release COI is present in large enough volumes to present a threat to a relatively large off-site population, an armed response is going to be necessary to prevent a terrorist attack aimed at that COI. If the response force is on-site, it must be armed. If the response force is off-site, it may be necessary to have an on-site security force that is armed to delay the potential attack long enough for the response force to arrive and defeat the attackers.”

My analysis that led to that conclusion, I think remains true today. But does that mean that facilities without a large ‘toxic release COI’ inventory have no need for an armed security force? That is not quite so clear, in my opinion. There is an increased, site-specific, risk associated with the discharge of a firearm at a facility where chemicals are manufactured, used, or stored, so clearly, firearm discharges are something to be avoided. But does avoidance of those discharges prevent the employment of armed guards?

If management decides that there is no conceivable situation where an armed response would be justified at the facility, then the choice is clear, there is absolutely no need for armed guards. Once, however, the decision is made that there are situations where an armed response would be justified, then an armed security force is an option that must be considered. But, one thing must be clearly understood, if the facility does not employ an armed security force, and the use of force becomes necessary, the facility has no option but to use local law enforcement as the tool to employ the use of force. At that point, facility management totally looses control over the use of firearms at the facility. They will have no control over:

• The types of weapons and ammunition that may be employed,

• Restrictions on in which areas of the facility weapons may be employed, or

• The training of the armed personnel on the hazards associated with the employment of firearms at the facility.

If facility management is willing to lose that level of control, then there is no need to consider the use of an armed security force. And an armed security force is more expensive, both in the direct cost to employ them and in the additional training costs necessary to maintain an adequate level of control to reduce the risks associated with weapons discharges. If, however, maintaining some level of control, at least in the early stages of an incident, is of importance, then management is going to have to consider the option of employing an armed security force.

Tuesday, January 18, 2022

Armed Security at Chemical Facilities – Part 1

 

Earlier this week, while writing my post about the ChemLock active shooter exercises, my first thought when I read the scenario for the exercise is that it was extremely unrealistic, because such a quick end to the shooter could only have been brought about by an armed security guard, police would not react that quickly. It was unrealistic because chemical facilities do not use armed guards. If you have not worked at chemical facilities in this country, you may not realize just how nearly universal that statement is. The big reason is SAFETY.

To give you an example of how deep this runs, let me tell you a story about the time an FBI agent visited a specialty chemical facility at which I worked to provide the initial notification that we would be inspected by Chemical Weapons Convention inspection team. The Agent was brought into the Plant Manager’s Office and introduced himself. The Plant Manager asked if the Agent was armed. When informed that he was, the Manager asked if the Agent would mind locking his weapon in his vehicle. There was no question from the Agent, he just excused himself, returned to his car and then came back into the office. No more was said. He obviously had gone through this before.

The facility was in the South and the Plant Manager was not some liberal anti-gun fanatic. He was an outdoorsman and while not much of a hunter, he owned at least a couple of guns. During dear season about half of the employee vehicles parked outside the fence line because they hunted before or after (frequently both) work. Guns were not allowed inside the facility and the hunters did not complain. That was life in a chemical facility.

Why this concern about firearms? It is not worry about active shooters, per se. It is the fact that firearms are more inherently dangerous in chemical facilities. This is for two reasons, the most obvious being the bullet flying unguided through the facility are likely to puncture things that are better off not punctured, piping, chemical storage containers, and storage tank. Those punctures are likely to result in chemicals being released into the atmosphere in places they are not supposed to be and in a manner that is not easy to stop. How bad would the leaks be from a bullet? See this video (https://youtu.be/skOdPBtm-zs).

The second reason is less easy for many folks to understand, and it is related to the fact that firearms are short range flame throwers, just watch any shooting in the dark. Open flames are allowed in chemical facilities only in tightly controlled situations and gun fights are not tightly controlled.

Any chemical facility that uses, produces or stores flammable liquids and gasses takes a great deal of interest in preventing even the smallest of open flames or sparks. They even go to the extent of placing electronics and switches in sealed boxes filled with Nitrogen gas so that small electric sparks from those devices do not ignite flammable atmospheres.

A flammable atmosphere can form any time a flammable liquid or gas is exposed to the open air. This can happen when a container is opened, or a nearly empty hose is disconnected, or an unusual leak occurs. The vapors in the air can be ignited by a spark or flame, creating a fireball of varying sizes and consequences. Large enough, those fireballs can create an overpressure that damages other containers or connections releasing more flammable vapors.

So, you can see why chemical professionals do not like the idea of firearms on premises at chemical facilities.

Monday, January 3, 2022

Review - ChemLock Exercises – An Overview

Developing a chemical facility security plan is just a time-consuming, compliance exercise until it has been tested. Instead of waiting for a real-world security incident to be the first test of a facility security plan, a smart security team will conduct a variety of exercises to evaluate the efficacy of the plan and the assumptions which drove its development. CISA’s new ChemLock program, a voluntary off-shoot of the successful Chemical Facility Anti-Terrorism Standards (CFATS) program, provides a number of exercise tools that facility security managers can use to plan, execute and evaluate a series of exercises to see how well their facility security plan stands up to a variety of security scenarios.

ChemLock Exercise Web Page

This page is the starting point for exercise planning and development. Most of (okay maybe all, but I am not sure about that) the information here was not specifically developed by the CISA Office of Chemical Security (the folks that manage the CFATS program), but rather by the wider range of offices within CISA and DHS.

There are two general options provided on this page. The first (and easiest) is a series of canned CISA Tabletop Exercises Package (CTEP). The CTEPs are no-cost to download and include the scenario-specific situation manual, planner handbook, facilitator/evaluator handbook, and assorted forms and templates. The second option is to contact the ChemLock folks to ask for assistance in planning and executing an exercise. That option is initiated by the use of the same  ChemLock Services Request Form that I have mentioned in a number of earlier posts.

Which Exercise?

In a perfect world, every facility would run every exercise as routine part of operations. Obviously, that is not going to happen in the real world. If a facility has never run an exercise of this sort, it is probably best to concentrate on one exercise and run it through a couple of iterations before trying to determine what sort of ‘exercise schedule’ will be appropriate for the facility.

I will be looking at individual exercise packages in future posts, but each facility is going to have to determine which exercise would be the most appropriate to start with. Facilities are going to want to start with something simple, but something that is a real potential threat at that facility. For example, a vehicle borne explosive device is probably not a serious threat at a facility that does not have significant inventories of toxic inhalation hazard chemicals on site unless an attacker has a particular issue with the facility.

Remember, though, the whole purpose of the ChemLock program is to help chemical facilities solve their security issues. The folks at OCS have offered to provide that assistance. So, facilities should contact the ChemLock folks with their questions about these exercise programs. Questions should be addressed via email to ChemLock@cisa.dhs.gov.

For more details about these exercise offerings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-exercises-an-overview - subscription required.

Wednesday, December 22, 2021

Review - ChemLock – Secure Your Chemicals – Cyber

NOTE: On November 18th, 2021, CISA announced their new voluntary chemical security program, ChemLock. This post is part of a deep dive into that program. Earlier posts in this series include:

CISA Announces ChemLock – Voluntary Chemical Facility Security (short version)

ChemLock and the Chemical Security Summit

ChemLock – On-Site Assessments and Assistance (short version)

ChemLock – Secure Your Chemicals – Overview (short version)

ChemLock – Secure Your Chemicals – Detect (short version)

ChemLock – Secure Your Chemicals – Delay (short version)

As is increasingly becoming obvious to organizations across the country, cyber assets are increasingly becoming a prime target for attacks on industrial organizations, including chemical facilities. Terrorists could leverage cyberattacks to cause chemical releases or to divert precursor chemicals to allow for the construction of chemical weapons or improvised explosives. With that in mind, Chapter 6 of the Secure Your Chemicals manual provides an overview of cybersecurity actions that can be taken by chemical facilities.

Cybersecurity Definition

The introduction to the chapter provides a very good, operational definition of cybersecurity:

“Cybersecurity is the capability to protect critical information, business, and control systems against damage, unauthorized on-site or remote access, modification, or exploitation.”

A key word in that definition is ‘critical’. While every piece of electronic equipment in the facility deserves protection, facility security managers are going to have to prioritize their activities to protect critical systems. Those could include systems that:

Monitor and/or control physical processes that contain a chemical.

Manage physical processes that contain a chemical which could be used to cause disruption or even destruction to the process and surrounding environment.

Contain business or personal information that, if exploited, could result in the theft, diversion, or sabotage of a chemical.

Missing Discussion

One critical cybersecurity area not addressed in this manual is the intersection of cybersecurity and process safety. Facilities that use industrial control system to control the handling, manufacturing and use of hazardous materials need to ensure that a key component of their cybersecurity response plan addresses the safe shutdown of chemical processes. Additionally, facilities must ensure that chemical process safety controls that rely on automated control systems have analog safety measures or manual controls in place to ensure an adequate response to safety incidents in the event of a loss of control systems due to a cyberattack.

And, as I mentioned in the previous posts in this series, the discussions in this section fall far short of providing facility security officers with all of the knowledge necessary to cyersecurity features in their facility security plans. It provides an overview of considerations to help FSO’s ask the right questions of CSI, vendors and integrators. This chapter does, however, point to CISA’s Cyber Essentials webpage for additional assistance on the topic.

For more details about the Cyber Chapter, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-secure-your-chemicals-269 - subscription required.


Monday, November 29, 2021

Review - ChemLock – Secure Your Chemicals – Delay

NOTE: On November 18th, 2021, CISA announced their new voluntary chemical security program, ChemLock. This post is part of a deep dive into that program. Earlier posts in this series include:

CISA Announces ChemLock – Voluntary Chemical Facility Security (short version)

ChemLock and the Chemical Security Summit

ChemLock – On-Site Assessments and Assistance (short version)

ChemLock – Secure Your Chemicals – Overview (short version)

ChemLock – Secure Your Chemicals – Detect (short version)

While early detection of an attack on the chemical facility is certainly important, the longer an attacker is delayed from reaching their chemical targets the more time the facility and its security response have react appropriately to the attack. This is the reason behind Chapter 4 of the ChemLock Secure Your Chemicals manual, ‘Delay’. This chapter provides a brief overview of:

• Perimeter and asset barriers

• Physical locking mechanisms

• Access control

• Inspections

• Screenings

• Know-your-customer program

As I mentioned in the previous post in this series, the discussions in this section fall far short of providing facility security officers with all of the knowledge necessary to implement delay features in their facility security plans. It provides an overview of considerations to help FSO’s ask the right questions of CSI, vendors and integrators.

Friday, November 26, 2021

Review - ChemLock – Secure Your Chemicals – Detection

NOTE: On November 18th, 2021, CISA announced their new voluntary chemical security program, ChemLock. This post is part of a deep dive into that program. Earlier posts in this series include:

CISA Announces ChemLock – Voluntary Chemical Facility Security (short version)

ChemLock and the Chemical Security Summit

ChemLock - On-Site Assessments and Assistance (short version)

ChemLock – Secure Your Chemicals – Overview (short version)

The first goal of any security program is ensuring that you can detect an attack as early as possible. Thus, Chapter 3 of the ChemLock Secure Your Chemicals manual discusses ‘detection’ as it relates to the physical security of the facility (detection of cyberattacks is discussed separately). This chapter provides a brief overview of:

• Intrusion detection systems (IDS),

• Camera systems,

• Employees or on-site security personnel,

• Security lighting, and

• Inventory controls

The chapter briefly discusses the importance of detecting an attack as early as possible to allow for appropriate response measures to prevent the attack or minimize the potential consequences of the attack. The discussion mentions that: “detection needs to occur prior to an attack (i.e., in the attack-planning stages)” {pg 16} but does not provide any information on what that entails. Back in 2008 I addressed the ‘Seven Signs of Terrorism’ video which is apparently no longer available, but the New Jersey Office of Homeland Security & Preparedness has a brief presentation available that covers the concept nicely.

The discussions about detection in this manual are brief looks at potential considerations and type listings. They are hardly going to make the facility security manager a subject matter expert on any of these topics. CISA’s Office of Chemical Security is offering the services of their chemical security inspectors to help facilities get a better handle on these topics, but it is going to come down to hiring physical security experts to really make these detection systems effective.

For more details about, and discussions on, the topics covered in this chapter, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-secure-your-chemicals-4f6  - subscription required.

Wednesday, November 24, 2021

Review - ChemLock – Secure Your Chemicals – Overview

NOTE: On November 18th, 2021, CISA announced their new voluntary chemical security program, ChemLock. This post is part of a deep dive into that program. ‘Short version’ links below are abbreviated posts on this blog that do not require subscriptions to my CFSN Detailed Analysis. Earlier posts in this series include:

CISA Announces ChemLock – Voluntary Chemical Facility Security (short version)

ChemLock and the Chemical Security Summit

ChemLock - On-Site Assessments and Assistance (short version)

Once a chemical facility has completed their vulnerability assessment, they are able to start preparing the facility security plan (FSP). Since the ChemLock program is a completely voluntary program, there is no requirement to involve chemical security inspectors (CSI) from CISA’s Office of Chemical Security in the development or approval of an FSP. But CSI do have years of experience in the unique security situations associated with chemical facilities and have a broad institutional knowledge of what has been tried and what works at high-risk chemical facilities. The ChemLock program makes this security plan knowledge base available to facilities that are not covered by the Chemical Facility Anti-Terrorism Standards (CFATS) program.

ChemLock Documents

The ChemLock Security Plan web page provides a starting off point for the development of facility security plan. It re-emphasizes the goals of a chemical security program that were discussed on their ChemLock Assessments page. It then provides a brief description of the process of developing an FSP and the concept of Security-in-Depth. The page also provides links to the following resources:

Secure Your Chemicals (.PDF manual),

Secure Your Chemicals Template (.docx download link), and

ChemLock Services Request Form

Moving Forward

Chemical facilities wishing assistance from CISA’s Office of Chemical Security in either establishing a new facility security plan, or having an existing plan reviewed by experienced professionals, should certainly consider contacting OCS via the new ChemLock program. I will be looking in more detail about the FSP process that ChemLock is using, as well as other support available from ChemLock, in future posts in this series.

For more details about the manuals and forms described above, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-secure-your-chemicals - subscription required

Monday, November 22, 2021

Review - ChemLock - On-Site Assessments and Assistance

NOTE: Last week, CISA announced their new voluntary chemical security program, ChemLock. This post is part a deep dive into that program. CISA’s new ChemLock program was developed upon the realization that there are literally tens of thousands of chemical facilities that house, produce or use dangerous chemicals that could be used by terrorists to effect chemical attacks here in the United States. A small percentage of those facilities are covered by the Chemical Facility Anti-Terrorism Standards (CFATS) program, but the remaining facilities have had no government assistance to help them protect their facilities from terrorist attention. ChemLock is designed to change that.

The first step in any security planning exercise is the conduct of a security assessment. While the CFATS program utilizes a suite of on-line tools for facilities to submit information to the Office of Chemical Security to conduct such an assessment, the ChemLock program avoids the requirement for facilities to submit data to CISA. In ChemLock, a facility simply requests assistance via a rather simple on-line form, and OCS will contact the facility to coordinate a visit by chemical security inspectors.

Security Assessment

The ChemLock program envisions two different types of security assessments for which they would be providing assistance:

• Security Awareness Consultation: CISA experts work with facilities to identify potentially dangerous chemicals and the security risks that those chemicals may pose.

• Security Posture Assessment: CISA experts work with facilities to assess their current security posture and identify security enhancements that are tailored to the facility’s unique circumstances and needs.

As currently configured, the ChemLock program does not require facilities to submit any information to CISA about the chemicals stored at the facility or the security measures in place at, or planned for, the facility.

Security Goals

The whole point of the ChemLock program is to provide assistance to chemical facilities so that they can achieve the following security goals:

• DETECT an attack,

• DELAY the adversary,

• RESPOND in a timely manner, and

• SECURE your cyber assets.

Conducting an appropriate security assessment, with the help of experts from CISA is a first step in achieving those goals.

For more details about these security assessments, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-on-site-assessments-and - subscription required.

Thursday, November 18, 2021

Review - CISA Announces ChemLock – Voluntary Chemical Facility Security

Today CISA announced the launch of their new voluntary chemical facility security program for chemical facilities that are not part of the Chemical Facility Anti-Terrorism Standards (CFATS) program. The new ChemLock program is an outgrowth of the CFATS program and the realization that facilities that are not considered at ‘high-risk’ for terrorist attack are at some risk of physical or cyber attack because of the chemicals stored, used or produced at the facility. The ChemLock program allows CISA to provide assistance to those facilities, based upon the long experience that the Office of Chemical Security has in overseeing the CFATS program.

Commentary

This is a voluntary chemical facility security program run out of the same office as the CFATS program. While this is not a program for facilities covered under that program, there are information sources available through this program that could be of use to CFATS facilities. Chemical facilities that are not covered by the CFATS program will find information and assistance here to determine what security measures may be applicable to their facility and how to implement those security measures.

The web site for this new program is hitting as a nearly fully formed information source for chemical facility security. The fold from OCS have used their long CFATS experience to address the basics of chemical facility security in an easy to access format. Assistance from experienced chemical facility inspectors is going to be a major selling point for this program.

Facilities that hold inventories of DHS chemicals of interest but are not currently covered by the program should certainly take a look at this program if there is any chance that there may be inventory or process changes in their future that may push them into the CFATS program. The resources available here could give facilities a head start on setting up a security program that could be readily morphed into a CFATS program site security plan.

I will be taking a closer look at this new program in future articles.

For more details about today’s announcement, including links to various pages within the new site, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cisa-announces-chemlock - subscription required.

Monday, February 8, 2021

COVID-19 Endemic and CFATS

Last March at the start of the COVID-19 pandemic I wrote a blog post about the potential effects of the pandemic on facilities covered by the Chemical Facility Anti-Terrorism Standards (CFATS) program. Looking back at that post I am really happy with many of the forward-looking comments that I made. Today, with the rollout of vaccines well (if slowly) underway I hope for the same level of prescience in looking at the next stage of the evolution of this medical problem, the COVID-19 endemic. An article on the Wall Street Journal website describes that potential evolution.

Vaccine Mandates

While there are political and legal realities that prevent the Federal government from mandating widespread COVID vaccination there has been an increasing discussion of whether or not private companies can insist that their employees get vaccinated as a condition of employment. I am certainly not an employment lawyer (not any kind of lawyer), but I suspect that there would be all sorts of problems for chemical facilities that attempted to enforce such a mandate, union contracts and employee resistance being the two most obvious.

This does not mean that management cannot take measures to encourage voluntary vaccination. The simplest and most important will likely to be to provide employees time-off to stand in the vaccination lines; larger facilities may want to consider offering monetary or material support for mass vaccination sites. All of these outreach efforts should certainly include encouraging employee families to get vaccinated.

Industry associations should become politically involved in advocating for staff at critical infrastructure facilities to be included in priority vaccination programs.

Testing

While we have lived with other endemic infections facility management needs to remember that with most of these other diseases people are most infectious after the disease is physically manifested, the same cannot be said about COVID-19. Facility management is going to have to consider the advisability of being able to conduct testing of employees as local infection rates rise. Testing and tracing are going to be a long-term requirement to contain COVID-19 outbreaks in the future. This testing could be done on-site at facilities that have professional medical staffing (typically nurses or EMTs); smaller sites may want to consider contracting testing support with their current industrial hygiene supplier.

This medical testing is going to have to comply with local, State and federal privacy regulations. Facilities need to fully understand those requirements before implementing such a program.

Security Measures

Security is going to be affected by the waning and surging of COVID-19. Facilities will have learned a lot of security lessons over the past ten months. While the CISA chemical security inspectors have been allowed a certain amount of leeway in accepting temporary changes to site security plans to reflect changes in staffing and operations during the uneven progress of the pandemic, that will not continue as the pandemic transforms into an endemic. Facilities need to take a concerted look at their security processes over the last year and determine which ones they want to formally memorialize in their site security plans, either as permanent changes or as optional changes when changes in the medical environment warrant.

Where a facility wants to include COVID-reactive security changes in their security plans, they need to be careful in how they describe the conditions that would require their implementation. Failure to implement those changes when the described conditions apply would then be a violation of the facility’s SSP. One thing that facilities must include in these changes is a clear delineation of responsibilities for notifying CISA’s Infrastructure Security Compliance Division of the intent to implement the changes and when those changes revert to standard procedures.

This would also be a good time for facilities to start thinking about their future plans for new pandemics. The next pandemic will probably not be COVID-2X, the virus will likely be different as will the infection rate, the timing of infection, and the mortality rates. A pandemic response plan is going to have to deal with the different scenarios dealing with those variabilities. Lessons learned from COVID will be a starting point for those plans, but those lessons should not be the endpoint. Higher mortality rates, in particular, or going to have be seriously considered as they will have major impacts on facility slowdowns and closures.

The Insurrection

While there has been a definite pull-back in operations being conducted by right-wing radicals since January 6th, the conditions that drive much of the support for those groups have not really changed. If there is another pandemic in the near future (and the timing of the next pandemic cannot be predicted), those socio-economic conditions will worsen quickly. Security planning for future pandemics will have to take that into account.

In the near term we are going to start seeing a new problem arise as federal officials really begin to look at these groups in ways that were not encouraged under the Trump administration. More people in the United States are going to be identified as being associated with various groups and a significant number of those so identified will start to show up on the lists that the TSA uses to vet people as being associated with terrorist organizations. That means that there will inevitably be current employees at CFATS facilities that will be so identified under the CFATS personnel surety program.

There is not much facility management can do in the advance of such notifications unless they are specifically aware of illegal activities being conducted on their premises. Facilities would run into all sorts of legal obstacles to firing employees for political views, even in the most ardent ‘right-to-work’ states. Facility management is going to need to have plans in place for what they intend to do when notified by ISCD that a current employee or contractor with unaccompanied access to their facility is identified by the TSA as having ‘terrorist ties’.

Wednesday, January 27, 2021

DHS Publishes New NTAS Bulletin – 1-27-21

Today the Department of Homeland Security published a bulletin on the National Terrorism Advisory System (NTAS) web page. According to the NTAS page:

“The Acting Secretary of Homeland Security has issued a National Terrorism Advisory System (NTAS) Bulletin due to a heightened threat environment across the United States, which DHS believes will persist in the weeks following the successful Presidential Inauguration.  Information suggests that some ideologically-motivated violent extremists with objections to the exercise of governmental authority and the presidential transition, as well as other perceived grievances fueled by false narratives, could continue to mobilize to incite or commit violence.”

Anyone responsible for facility security needs to read the bulletin and so probably should everyone else. The bulletin is expected to remain in effect through April 30th.

NTAS System

A quick reminder about the NTAS system. It provides three different advisory levels depending on the specificity of the information available. The three different levels are:

• Bulletin - Describes current developments or general trends regarding threats of terrorism.

• Elevated Alert - Warns of a credible terrorism threat against the United States.

• Imminent Alert- Warns of a credible, specific and impending terrorism threat against the United States.

NTAS Bulletin and CFATS

There is currently nothing on either the home page for the Chemical Facility Anti-Terrorism Standards (CFATS) program or the CFATS Knowledge Center about this specific NTAS Bulletin. The CFATS Knowledge Center does have a FAQ about the NTAS system (FAQ #1724) that was most recently updated on November 24th, 2020. The response to that FAQ notes that CFATS covered facilities would have different response requirements under alerts and bulletins. Since bulletins do not provide specific threat information, that FAQ response explains that: “CFATS facilities should monitor the system for Bulletins for situational awareness and may use their best judgement to apply the information posted as applicable to the facility.”

Earlier this month I published two blog posts that address topics discussed in the “Details” portion of today’s bulletin. Those two posts are:

CFATS and the Nashville Bombing

CFATS and the ‘Insurrection’

There is a possibility that, as more specific threat information becomes available, applicable CFATS facilities could be notified directly by the CISA’s Infrastructure Security Compliance Division (ISCD) or directly through the Chemical Security Inspector responsible for oversight at the facility.

Thursday, July 11, 2019

DHS Publishes PSP Program Announcement – 07-09-19


On Tuesday the DHS Cybersecurity and Infrastructure Security Agency (CISA) published a notice in the Federal Register (84 FR 32768-32777) outlining the implementation process for the expansion of the Personnel Surety Program (PSP) to Tier III and IV facilities. Yesterday they updated the Chemical Facility Anti-Terrorism Standards (CFATS) program landing page with a note about that expansion that pointed at the revised PSP web site.

Overview


Back in 2016 the DHS Infrastructure Security Compliance Division (ISCD, now part of CISA) implemented the portion of the PSP that provided for identifying CFATS employees and contractors or visitors with unaccompanied access to critical areas in covered facilities that may have ties to terrorist. The initial implementation was limited to Tier I and II facilities. In late 2017, ISCD started the process to expand the PSP process to Tier III and IV facilities.

The PSP web site has an interesting graphic that conceptually explains the PSP implementation process:



First, once notified by ISCD that the facility will begin the implementation process (and that notice will start the 60-day clock implementation clock), the facility will update their site security plan to include information about how they will implement the process at their facility. This weeks’ notice provides a look at what types of information ISCD will be looking for in that SSP modification. When ISCD approves that amended SSP the clock will again start on the facility’s actual implementation of that facility specific process.

ISCD will phase this implementation in over the next two years or so. They will provide each Tier III and IV facility with a notice of when they will officially begin the implementation process and the date of that notice begins the 60-day period in which the facility must submit a revised SSP. Facilities can begin work on that SSP revision now, or they can wait until they receive the notice. Facilities can even submit the amended SSP before they receive their notice.

Tier III and IV facilities that have not yet had their SSP approved (or perhaps even authorized) should expect that their SSP will have to include PSP implementation before ISCD give approval to the plan.

PSP Options


The CFATS PSP provides four different options that facilities may use to screen individuals for possible terrorist ties; actually five since ISCD included an obligatory possibility for facilities to propose some sort of alternative that would accomplish the same thing. Facilities may use any option or combination of options that they wish.

The notice describes each of these four options (imaginatively entitled: Option 1, Option 2, Option 3 and Option 4) in some detail. In my 2016 blog post I described them this way:

Option 1 – Facility submits data and ISCD has TSA conduct screening;
Option 2 – Facility submits data on personnel with previous screening and ISCD has TSA confirm that screening is current;
Option 3 – Facility uses TWIC Reader to verify identity and screening status of Transportation Workers Identification Credential (TWIC) holder; and
Option 4 – Facility visually inspects TSDB based identity document to verify that person had been screened against TSDB.

Commentary


I will keep this brief today since I already said most of what I want to say back in 2016. In fact, I did an entire blog post about what problems I expected facilities to face in implementing the PSP. I have not seen anything since then that would significantly change those observations.

Most facilities are going to find that they need a blended approach using two or more of the options that ISCD has provided. I think that every facility should probably expect to use all four options at one point or another. If the initial SSP revision addresses all four options, then the facility will have the maximum amount of flexibility in the PSP implementation. It would certainly save time down the road.

Remember, facilities can (should) begin their SSP revision process before they receive their notice from ISCD. I would not recommend submitting the revised SSP before that notice is received, because the official notice is also going to trigger specific Chemical Security Inspector support for the revision process.

Wednesday, February 27, 2019

San Pedro Butane Storage Again


At today’s CFATS hearing before the House Homeland Security Committee there was an interesting exchange between Rep. Barragan (D,CA) and Director Wulf (video starting at 1:59:41) about a butane storage facility near the Port of Los Angeles. The name of the facility is not mentioned, but it sounded very familiar. I have been pouring back through my records and I think that I know why it sounded so familiar.

Back in the summer of 2013 (I have been at this for a while now) then Rep. Waxman (D,CA) sent a letter to DHS expressing concerns about the CFATS related emergency response planning at the ‘Rancho Palos Verde facility’. He explained that chemical security inspectors had accepted company reports that they had shared their emergency response plan with local first responders while the EPA was taking action against the facility for failure to do exactly that.

Barragan’s comments today were related to the specific hazards associated with the facility and whether or not those had been adequately evaluated by the CFATS program. ISCD Director Wulf assured her that those hazards were well understood by the program. She also questioned if compliance inspections were being rushed (with the implied possibility for overlooking problems) and Wulf assured her that CSI were not being administratively pushed to too quickly successfully conclude a compliance inspection.

What was not addressed in the exchange was whether or not the CFATS security program at the facility adequately protected the community. Remembering that the CFATS program is designed to help facilities protect themselves from attack, not accidents; the chemical hazard is still there. Other agencies (the EPA and OSHA) oversee the programs designed to prevent accidents. And no safety or security program is ever going to be 100% effective.

Barragan’s concerns today were not the same as those expressed six years ago by Waxman, but local communities are going to continue to be concerned about their safety when living near big and potentially dangerous chemical facilities. The fact that this local facility has twice made the national news for chemical safety reasons, without an actual incident taking place, clearly reminds us about the legitimacy of those concerns.

The other thing of interest that this facility highlights is the legitimacy of the concerns expressed today by a number of the Committee Members about how well the CFATS program ensures that information about emergency response issues is shared with the local emergency response community. It is not enough that the facility have an emergency response plan drawn up, but it must be shared with the community and should be exercised to work out any bugs in the plan well before an incident takes place. I am sure that we are going to hear more about this issue in the House before a bill is sent to the Senate.

Friday, February 8, 2019

DHS Publishes 60 ICR Revision Notice for CSAT – 02-07-19


Yesterday the DHS Cybersecurity and Infrastructure Security Agency (CISA) published a 60-day information collection request notice (ICR) in the Federal Register (84 FR 2558-2564) for the Chemical Facility Anti-Terrorism Standards (CFATS) program Chemical Security Assessment Tool (CSAT). The CSAT is an online tool that the Agency (via the Infrastructure Security Compliance Division) uses to collect information from chemical facilities to oversee the CFATS program.

ICR Data


The previous ICR for this program was initiated to allow the ISCD to implement CSAT 2.0, the revised information collection and assessment tool that was introduced in 2016. Yesterday’s ICR notice is intended to revise collection and burden estimate to reflect on-going collection requirements now that the CSAT 2.0 implementation is complete. Table 1 below provides a comparison between the currently approved ICR and the new estimate from CISA.


Current
Proposed
Total Responses
18,450
22,543
Total Burden Hours
22,239
14,359
Total Burden $
$15.3 M
$1.1 M
Table 1: Burden Comparison

The data in Table 1 is not directly provided in the ICR notice; it is compiled from the information provided for in the notice for each of the six data collection tools included in CSAT. Table 2 provides a summary of the data provided. The links in the table are to the detailed discussion in the ICR notice explaining how CISA arrived at the figures.

Responses
Hours
Dollars
       2,332
  2,553
   $203,450
       1,683
  2,083
   $166,028
       1,683
  4,582
   $365,141
     15,000
  2,500
   $199,233
       1,000
  2,500
   $199,233
          845
     141
     $11,223
Total
22,543
14,359
$1,144,308
Table 2: ICR Burden Details

Risk Identification


The one tool that may not be immediately familiar to folks in the CFATS community is the risk identification tool. Actually, the ICR notice provides a more complete title; Identification of Additional Facilities and Assets at Risk. In the currently approved ICR the document [.DOCX download] describing this data collection shows two different types of information being collected as a result of compliance inspections.

The first addresses identification of facilities at risk. At facilities that receive, or ship DHS chemicals of interest are requested to voluntarily provide data on:

• Shipping and/or receiving procedures
• Invoices and receipts
Company names and locations that COI is shipped to and/or received from

The discussion in the ICR notice would seem to indicate that CISA will only be collecting the above information from facilities that ship COI.

The second addresses assets at risk. Facilities that are identified as having “SCADA, DCS, PCS, or ICS” are requested to voluntarily provide information on:

• Details on the system(s) that controls, monitors, and/or manages small to large production systems as well as how the system(s) operates.
• If it is standalone or connected to other systems or networks and document the specific brand and name of the system(s)

This ICR notice only mentions the description of the facilities at risk data collection. Neither the 60-day ICR notice for the existing ICR nor does the supporting document [.DOCX download] provided to OMB describes either risk data collection. They only mention that the data collection is voluntary and expect that each facility providing a site security plan (SSP) will provide data under this collection.


Commentary


This ICR notice provides a look at the interesting problem agencies have in preparing their burden estimates for data collections that are not strictly periodic. When programs start up (or significant changes are made) the collection requirements are generally going to be higher as the affected entities have to put reporting (and the internal data collection) processes into place. Presumably, after that initial effort is complete, presumably the burden will decrease for subsequent data submissions.

In the detailed discussions in this notice CISA continues the established process that has been used throughout the history of the CFATS program in providing detailed information in its ICR notices. With the level of information provided, interested parties have enough information to determine if they have specific questions about the burden estimates or have suggestions on how the agency can improve those estimates. That, after all, is the whole purpose of publishing these ICR notices.

I find it interesting to see that the CFATS program attempted to gain additional information on industrial control systems used at covered facilities. This bears further investigation.

Thursday, November 1, 2018

ISCD Published CFATS Update – 11-01-18


Today the DHS Infrastructure Security Compliance Division (ISCD) revised the CFATS Statistics web page to reflect data from October 2018. The numbers show a continued increase in the number of facilities with approved site security plans (80.2%) and a resumption of the slow decline in the number of covered facilities after slight increases in the two previous months.

The first table below outlines the activities completed by the ISCD chemical facility inspectors over the last three months. The total number of reported activities continues to show a general decline since February, but it is hard to do a reasonable statistical analysis of the trend because of a clear definition of the time frame for which the data is reported. Further, trying to assess the rate of CSI utilization from this data is complicated by the fact that the number of CSI involved in any activity varies with the complexity and size of the facility involved.

CFATS Activities
Aug-18
Sep- 18
Oct-18
Authorization Inspections to Date
3822
3854
3875
Authorization Inspections Month
68
35
25
Compliance Inspections to Date
3819
3891
3995
Compliance Inspections Month
78
71
106
Compliance Assistance Visits to Date
4749
4897
5008
Compliance Assistance Visits Month
158
126
121

The second table below shows the status of facilities currently covered by the CFATS program. The recent two-month uptick in the number of covered facilities (the ‘Total’ line in the table) has been an anomalous in the history of the program; generally speaking (with notable exceptions) facilities have a number of economic incentives to minimize their chemical security risk through reducing the number of DHS chemicals of interest (COI) on the facility or reducing the maximum inventory quantity of those COI remaining.

CFATS Facility Status
Aug-18
Sep-18
Oct-18
Tiered
218
211
205
Authorized
562
493
456
Approved
2586
2665
2701
Total
3366
3369
3362

Still missing from the monthly reporting (and at this point this is practically a pro forma comment) is any information on the compliance rate for facility inspections.

 
/* Use this with templates/template-twocol.html */