Showing posts with label Chemical Sector Security Summit. Show all posts
Showing posts with label Chemical Sector Security Summit. Show all posts

Thursday, July 29, 2021

Registration for 2021 Chemical Security Seminars is Open

Yesterday, CISA’s Office for Chemical Security (OCS) published an announcement in the ‘Latest News’ section of the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center noting that the free registration is now open for the December 2021 Chemical Security Seminars. As was done last year because of the COVID-19 Pandemic, these three seminars are replacing the Chemical Sector Security Summit that is normally held in July.

 


The Chemical Security Summit web site provides additional information on the Seminars and provides links to slide presentations from last year’s Seminars and from Summits back through 2015. The Seminars will be held on December 1st, 8th, and 15th.

Last year the on-line presentations last about 4 hours each of the three days, with provisions being made to answer questions from the audience. The presentations were well done, providing a great deal of information about the CFATS program, related programs, and chemical security in general.

CISA is asking that registrations be completed by November 30th, 2021. I registered this morning.

Saturday, October 14, 2017

DHS Publishes 2017 CSSS Presentations

Yesterday DHS updated the 2017 Chemical Sector Security Summit (2017 CSSS) web page with links to some of the presentations that were made at this year’s Summit. Unfortunately, even with the Summit including web casts of several of the presentations, the links provided only provide copies of the slides used in the presentations.

The presentations available (in .PDF format) include:

How Vulnerable Are You? - Effective Strategies for Assessing Cybersecurity Risk
Global Partnerships: International Chemical Security Efforts
CTRA 4.0 – Chemical Terrorism Risk Assessment
When Disaster Strikes: Security Roles during a Disaster
A New Frontier: Unmanned Aircraft Systems (UAS)
Chemicals on the Move: Updates in Transportation Security

As I have mentioned a number of times, just providing copies of the slides, while better than nothing, are frequently frustrating. For example: in the ‘Chemicals on the Move’ presentation from the Coast Guard slide #2 is down-right cruel. In the discussion of the TWIC Reader Rule it lists one of the issues with that rule as being “Unintended consequences of Final Rule”. It would have been real interesting to hear what those consequences are as I am sure that people who attended the Summit did.

Having said that, there are some interesting bits of information included in these slides. They include:

• ‘A New Frontier’ provides a link to the “Unmanned Aircraft Systems (UAS) - Critical Infrastructure” web site;
• ‘CFATS Compliance Lessons Learned’ specifically mentions ‘cybersecurity’ as one of the things to pay attention to in the new Tiering letters being issued under CSAT 2.0;
• ‘What to Expect During a CFATS Inspection’ includes an important note: “Prepare list of attendees to the Opening Meeting. Have CVI numbers for each attendee ready.”
• ‘CTRA 4.0’ presentation notes that only 71 of the 185 chemical compounds assessed by Chemical Security Analysis Center (CSAC) are CFATS chemicals of interest (COI);
• ‘CFATS Regulatory Update’ mentions that “Will begin the Paperwork
Reduction Act process to expand [Personnel Surety Program] to Tiers 3 & 4 in the coming year”;
• ‘How Vulnerable Are You’ makes an important point: “A non-segmented network where CROWN JEWELS are not isolated will always be prone to failure from the failure of the weakest link”;

Remembering my complaint expressed above about the basic inadequacy of slides, I really do think that reviewing these presentations is worthwhile for anyone in the chemical facility security community. They do not take much time to review and there is some interesting information.

Having said that, the two most worthwhile presentations to review are the ones dealing with cybersecurity and disaster planning. As stand-alone documents, they both provide valuable and useful information. The latter is especially important (and in some ways prophetic) in light of the problems seen in the aftermath of Harvey.


One final note: The 2017 CSSS page provides a link to the page with the links to the presentation. It is odd, however, that the list of presentations is not an HTML page but rather a .PDF page. This makes loading a tad bit slow (as are the documents). And, as always, the Federal government’s reliance on .PDF documents with the attendant security issues is problematic (and more than a little ironic on a page devoted to security issues). Is there a more secure manner of presenting unalterable documents?

Wednesday, May 15, 2013

2013 Chemical Sector Security Summit


DHS, at long last, has announced that there will be a 2013 Chemical Sector Security Summit. The new web page is up (move your link to the 2012 CSSS to your historical section; it is still active and contains links to some of the more important presentations) and the dates are set for July 10th and 11th in Baltimore, MD. As with previous years there will be a set of pre-Summit workshops on Tuesday, July 9th.

The full agenda is not yet available and the registration site is not yet established; I’ll be keeping an eye out for those. The new web site does provide a short list of Key Topics for this year’s Summit. They include:

• Chemical Security Regulations Update
• Chemical Facility Anti-Terrorism Standards for Tier 3 & 4 Facilities
• Cybersecurity
• Voluntary Programs
• Information Sharing

I’ve been wondering when I was going to be saying this, but with the latest data on site security plans out last week, it really does look like ISCD is going to  finally be getting around to Tier 3 and 4 Facilities, perhaps later this year. This makes the second ‘key topic’ all the more important.

Cybersecurity is of central importance at DHS this year with the upcoming publication of the Cybersecurity Framework (okay we are still waiting on the draft, but it is not yet late). CFATS is one of those regulatory programs that may be able to incorporate ‘voluntary’ cybersecurity controls into its existing requirements without specific authorization by Congress. This combined with proposed coverage of current threats and specific coverage of Industrial Control Systems will make the CSSS doubly important this year.

With the late decision to go forward with the Summit this year, even in the face of sequester cut backs, I expect that we will be seeing more information about the agenda and registration in short order. After all it is just less than two months away.

BTW: I will again start plugging my long standing suggestion that the folks at NPPD (this is after all more than just CFATS) expand the potential attendance at the Summit by web casting key portions of the program. In the current sequester environment it would allow more of the Chemical Security Inspectors to attend the Summit.

Monday, March 11, 2013

CSSS Schedule, Or not


We are almost half-way through March and there has been no announcement about the date for the 2013 Chemical Sector Security Summit. This annual meeting in/near Washington, D.C. has been running since the inception of the CFATS program, usually during the end of June, first part of July. While not run by ISCD (actually it is run by the Chemical Sector office in NPPD) it has been a gathering event for those interested in the CFATS program.

In recent years the schedule date has been published earlier and earlier, but this year is a major exception. NPPD has been pretty quiet about the program. I have sent queries to the email poc listed on the CSSS web page, but have received no replies. So I decided to contact SOCMA, the co-host for each of the CSSS to-date.

My contacts at SOCMA indicate that there is a tentative date for CSSS this year of July 9-11 at the Baltimore Hilton (Inner Harbor). What’s holding up the announcement is that the funding for the CSSS has not yet been approved. I’m afraid that sequestration may be the reason for the delay in that approval.

In some ways it would be understandable if CSSS were not held in this budget strained year. The attendance at last year’s Summit was off significantly, only about 400 people attended out of the 600 available slots. In fact, last year was the first year that CSSS organizers did not have to limit registrations to just two people per organization. Bean counters look at things like that.

Having said that, I think that not holding CSSS would be a major mistake. This is a valuable exercise in that it allows for contact between the regulated community and the people running the show. Normally, the only contact facility management has with CFATS personnel is with the Chemical Security Inspectors. It also gives the ISCD management team a chance for face-to-face contact with the people that their regulations directly impact. Both sides of that communication are a valuable part of the public-private partnership that is necessary for success of the CFATS program.

The other major purpose of the CSSS is to provide DHS with an avenue to update the regulated community about what is going on with the CFATS program. A valuable part of this has been accomplished via some of the discussion groups where industry representatives can share their experiences with the execution of the various CFATS processes.

I have long maintained that the CSSS organizers have missed a major opportunity by not making many of their presentations available live (or even time delayed) over the internet. There are a lot more than 600 people, or even 600 organizations impacted by the CFATS program. Opening more of the presentations to those organizations that cannot afford a trip to Washington would go a long way to increase participation in the program.

If there was some concern about the possible compromise of sensitive information by making the presentations available, ISCD could set up a tool within CSAT so that only registered users of the program could access the presentations. I wouldn’t like it personally because I would be excluded, but it would get the information to the regulated community which is more important than keeping gadflies like me informed.

I hope that the folks at SOCMA are correct and that we will see an announcement of the July 9th-11th dates in the near future. The CSSS is a valuable part of the CFATS process.

BTW: Chairman Shimkus, you may want to ask Under Secretary Beers about this on Thursday.

Friday, June 29, 2012

Per Organization Limit Increased for CSSS


Yesterday SOCMA, a cosponsor for next month’s Chemical Sector Security Summit (CSSS), tweeted that DHSS is temporarily opening registration for additional members from an organization to attend the CSSS. The original DHS web site notice said that, as has been the case in recent years, registration would be limited to only two people from a single organization. This had been done to allow more organizations to send representatives to the meeting.

The tweet points to the registration web site, but that page still has the note about the two attendee limit. The Chemical Sector Security Summit web page still contains the note:

“Due to space constraints, each organization, company, and agency will be limited to two (2) registrants.”

This kind of worries me because it indicates that there hasn’t been the level of registration that we have seen in prior years. If the registration isn’t oversubscribed as it has been since its inception, it will be harder to convince DHS and the industry sponsors to web cast essential parts of the meeting.

Wednesday, June 6, 2012

DHS Announces CSSS Registration


Today the folks at DHS NPPD Infrastructure Protection got around to posting information about registration for the 2012 Chemical Sector Security Summit on the CSSS web site. This comes a full week after SOCMA provided links to the same information. No new information was provided in the DHS announcement; it had all been covered in the earlier information release.

Monday, June 6, 2011

DHS Updates Chem Sector Security Summit Page

Today DHS updated their web page for the 2011 Chemical Sector Security Summit (CSSS) which will take place in Baltimore on July 6th and 7th (and 5th and 8th if you include the pre- and post-summit programs) this year. The updated information includes the agenda for the summit and procedures for getting your name on the standby list for attendance at the summit.

Agenda

The general outline of the agenda is pretty much the same that was outlined in the preliminary agenda (there is still a link to the preliminary agenda on the current page; kind of odd in a pleasantly quirky way) that I discussed in an earlier blog post. The main difference is that there is a lot more detail provided in the descriptions of the agenda items.

Given the recent reorganization of ISCD it is interesting to note that there will be some familiar faces from the old regime making presentations at this Summit. Sue Armstrong will be reprising her presentation on the status of the CFATS – Ammonium Nitrate programs and Larry Stanton will be updating his presentation from last year (and the two years before that) on Theft and Diversion Chemicals.

Recorded Presentations

There is another interesting development mentioned in this agenda that I certainly applaud. On the listing for the 9:30 session on July 6th on “DHS Voluntary Programs and Resources Panel” there is a special note; “This session may be recorded and may be posted on the Web after the Summit.” I would have preferred to see all of the sessions recorded and posted, but it is a new technique for the organizers of this Summit, so a limited trial is certainly reasonable.

I personally would have liked to see one of the other presentations used for this trial (based upon my personal interests, of course), but I do have to admit that this presentation has the largest potential audience in the chemical community. That makes this a very reasonable choice for this experiment.

Hopefully this will be a wildly successful experiment and will attract wide spread attention in the chemical security community. The more hits/views that this presentation logs in the coming months, the more likely that this will be expanded next year; providing the bulk of the chemical security community with virtual access to this Summit.

Friday, May 20, 2011

Chemical Sector Security Summit Registration Closed

This morning the DHS Office of Infrastructure Protection updated the web site for the 2011 Chemical Sector Security Summit (CSSS), notifying the chemical security community that the registration for the Summit was now closed. This was not unexpected; DHS limited registration to 2 people per organization to try to provide access to as many organizations as possible.

Once again I would like to call on DHS OIP and SOCMA (one of the industrial sponsors of the CSSS) to consider opening the presentations at this year’s Summit to on-line viewing. With only about 600 openings for attendees available, and the poor economy affecting travel budgets, there will be no other way for most members of the chemical security community to attend this meeting.

I’m sure that DHS will be posting the slides from most of the presentations on-line after the conference is over as they have in years past. This is valuable, if incomplete, information. The actual words of the speakers and the increased level of detail that they provide over the slide content would be a valuable source of information to our community.

I would prefer to see the presentations in real-time, but even posting security-edited versions on the CSSS web site after the Summit is over would be valuable.

Thursday, April 14, 2011

New Article on CFATS Knowledge Center

Yesterday the folks at ISCD updated their CFATS Knowledge Center web site, adding a note under the ‘Latest News’ heading and adding an article to the list of frequently asked questions. Both items provided information about the 2011 Chemical Sector Security Summit.

The note under ‘Latest News’ states:

“Registration Open for 2011 Chemical Security Summit, July 6-7, 2011, Hilton Baltimore, Baltimore, Maryland. Go to http://guest.cvent.com/d/rdqt3v for Summit information and registration. Due to space constraints, each organization, company, and agency will be limited to two (2) registrants. There is no registration fee associated with this year’s event. See the article 2011 Chemical Sector Security Summit for additional information.”
The referenced article is Article # 1720 (Sorry, the link I copied yesterday for this article does not work today due to a 'checksum' error). That article provides some of the basic information on the CSSS including links to the registration site, and the CSSS web site. None of this information is new, it can all be found on the CSSS web site and was discussed here on this blog back in late March.

This is the first time that ISCD has included information on the CSSS on the Knowledge Center. Okay, the Knowledge Center was started the week before last year’s CSSS so that doesn’t really mean much. The fact that there was never a FAQ concerning the CSSS is also relatively meaningless as this is an ‘Article’ not a FAQ (same numbering system different format).

I suppose that I shouldn’t complain about an additional source of information about the CSSS, but I do have a couple of problems with the way that this was done. First, since there is already a web site for the CSSS I don’t really think that an article is necessary. The note under the ‘Latest News’ heading was a good idea, but it probably should have just included a link to the CSSS web site instead of the registration site.

Friday, December 10, 2010

2011 Chemical Sector Security Summit Poster

For those of you who do not follow me on Twitter (http://twitter.com/pjcoyle) yesterday DHS updated their 2011 Chemical Sector Security Summit page. They added a new poster on the page for the 2011 CSSS (replacing a picture of Sec. Napolitano). It’s kind of cute (not an adjective that you’ll see in this blog too often) and reflects an increased interest in the visual arts. Whatever; it is a nice touch though.

Tuesday, November 2, 2010

Reader Comment SOCMA Podcasts

An anonymous reader posted a comment to last weeks posting about the 2011 Chemical Sector Security Summit. Anonymous was responding to my suggestion that DHS provide video coverage of presentations at next year’s Summit, writing:

“Though it's far removed from video coverage, SOCMA posts podcasts on its website conducted with key DHS officials during the summit. You may have to register for access (can't recall) but there is no fee to download it.”
Anonymous is correct, SOCMA (who co-funded the 2010 Summit) provided a link to their Summit Podcast in their post-Summit review. The podcast includes comments from some of the presenters and Summit participants. I thought that I had covered this in one of my post-Summit blogs, but I can’t find any mention in my records.

SOCMA was one of the providers of information from the Summit this year and I hope they do the same next. Tweets and blog posts helped those of us who could not attend follow what was going on. Since this is supposed to be another method for DHS to keep the chemical security community updated on the CFATS process and other chemical security programs managed by DHS, I think it is important that the information be shared in as wide a variety of means as possible. SOCMA certainly helped this year, but it is really DHS’s job to make sure that this happens.

Again, I realize that there may be issues in providing video coverage of some of the industry presentations (though I think that most PR departments would look at it as free advertising), but that would not apply to the presentations made by Federal employees. I also understand that there might be concerns about inadvertent disclosure of security sensitive materials, but I’m not asking for live broadcasts. I would be happy if DHS just posted edited videos of the presentations on the Internet after the Summit is over, much the same way that they post the slides used in those presentations.

A major reason for DHS to sponsor this Summit is to ensure that the regulated community gets the information that they need to comply with the CFATS regulations. Since it is not possible for all covered facilities to have security team members attend this Summit, DHS has a responsibility to ensure that the information provided here has the widest possible dissemination. Providing copies of the slide presentations on their web site was a good move, but those slides are only a very minor component of the presentations. We need to hear the words, the voices of the presenters.

Thursday, July 22, 2010

CSSS Presentations – Personnel Surety

During the Chemical Sector Security Summit earlier this month Matt Bettridge from DHS provided an update on the status of the proposed Personnel Surety program being developed to provide high-risk chemical facilities a tool to allow them to submit information to have employees and visitors checked against the Terrorism Screening Database for ‘terrorist ties’. This check will provide covered facilities a method for meeting their obligations under §27.230(12)(iv). This proposed program has generated a great deal of controversy since it was first introduced via a 30-day information collection request (ICR) notice in the Federal Register last summer and modified by a 60-day ICR notice earlier this year. The slides for this presentation do not directly address many of the concerns raised by industry, but the tone and the details of the steps going forward should ease some of those concerns. Covered Personnel The presentation outlined the general procedures and addressed the issue of which facility personnel would be affected by the submission requirements. The slide specifically states that the program “[d]oes not affect facility personnel that do not have access to facilities’ restricted areas or critical assets” (slide 2). This apparently indicates a change in the intention of DHS to require screening all facility personnel (as understood by most commentors to the DHS 60-day notice). Rule Making Process A number of commentors on the ICR notices expressed concerns that the proposed personnel surety program should be covered by a formal rule making process rather than the less formal ICR process. The presentation partially addressed this issue by explaining that DHS would submit an notice of proposed rule making (NPRM) under the Privacy Act System of Records Notice (SORN) requirements. That NPRM would be published in the Federal Register at the same time that DHS publishes their response to the public comments received for the 60-day ICR notice. Timeline According to the presentation the “[i]nitial implementation of CFATS Personnel Surety is on pace for late fall 2010” (slide 7). DHS intends to use the same technique that they have used for the introduction of most new CSAT tools; the initial implementation will take place with a small group of select facilities. In this case they plan on using facilities that have already completed the SSP process and have approved plans. Lessons learned from that live testing will be used to perfect the tool before its general release. Unresolved Controversies There were a number of items in the presentation that do not appear to have changed since the 60-day ICR was published, even though they drew a number of adverse comments from industry. DHS still does not intend to ‘routinely notify’ the facility or the individual of a positive match in the TSDB search. I would hope that Mr. Bettridge took the opportunity to explain the reasoning for that during the presentation, but it doesn’t show on the slide presentation. The slides also indicate that DHS still intends to require facilities to “[n]otify DHS when an affected individual no longer has access to the restricted area and/or critical asset”. A number of commentors complained about the administrative burden that such a requirement would place on facilities, especially facilities that would be required to list off-site corporate personnel as having unaccompanied access. The wording on the slide seems to parallel the ICR wording that seemed to require including to which restricted area or critical asset that each submitted individual would have access. A number of commentors complained that this went far beyond the scope of requirement to check individuals against a list of known/suspected terrorists. There wasn’t any legal requirement for DHS to address these issues at this venue, but it certainly would have provided a good forum for explaining the reasoning or easing concerns of the regulated community. Now Mr. Bettridge may have actually availed himself of that opportunity, but it isn’t reflected in the slides. This is just another reason why I think that it would have been much better if DHS had provided video or even audio copies of the actual presentations on the CSSS Presentations page.

Tuesday, July 13, 2010

CSSS Web Page Update

Yesterday afternoon some time DHS updated their web page for the Chemical Sector Security Summit. It no longer shows the pre-Summit information. Instead it provides a very high-level summary of what went on. As I mentioned in last night’s blog post I expect that this will be updated again in the near future to provide a link to a new web page (like the ones for the 2008 and 2009 Summits) that will provide more information on many of the presentations made at this year’s Summit.

Monday, July 12, 2010

CSSS Reports

Well we are starting to see some reports about what went on at the Chemical Sector Security Summit last week. Earlier today the Roberts Law Group posted what appears to be the first of three blogs about the CSSS on their Homeland Security Law and Policy Blog. This short post looks at some of the numbers reported by DHS on the current status of the CFATS program. Reporting the Numbers Three important numbers here; 4110 final tiering letters sent, 887 yet to be sent, and 47 facilities that have had their initial inspections completed. The first two show that significant progress has been made on the reviews of Security Vulnerability Assessments. As we would expect, most of the ‘to be reviewed’ facilities are Tier 4 facilities and I would assume that the Tier 1 and 2 facilities in the ‘yet to be reviewed’ column were late entries. The number of inspections does not surprise me. As I have mentioned before these inspections have got to be time consuming and personnel intensive. This combined with the small inspection force means that the inspections will take time. The Roberts’ blog notes that DHS is “expected to increase PAIs to 30-40 per month” as 100 additional inspectors are added (an almost 60% increase in available inspectors). This will also be improved as the current inspectors get more proficient at conducting inspections and compiling reports (any skill gets better with practice). Also we would presume that generally speaking the chemical plants being inspected will be getting generally smaller and less complex as we move further down the Tier rankings (not always, of course, but generally speaking). More Information to Come I expect that we will be seeing more blog reports on the Summit in the coming days and weeks. The folks at SOCMA (co-sponsors of the Summit) have promised that they will be providing more information on their web site. If the previous Summits are any preview, we can expect DHS to publish copies of many of the slide presentations on the Summit Web Site in the coming weeks. I’m still hoping that they will expand that this year to videos of at least some of the presentations. I’ll certainly point out any information sources that I come across. In fact, bloggers feel free to let me know as you post about the Summit and I’ll promise plugs here on this site. I would like to suggest to the folks at DHS that they have two in-house blogs that are woefully underwritten that could be used to address CSSS information. Maybe ISCD and the Chemical Sector Office could show the rest of the Department (apologies to the TSA blog folks) how to communicate with the public.

Tuesday, June 29, 2010

Chemical Sector Security Summit Page Update 06-28-10

Yesterday DHS updated their 2010 Chemical Sector Security Summit web page. The Summit is next Monday and Tuesday so I keep looking for last minute changes in the program. The change made yesterday is one of those changes that probably made sense to the people managing the page, but appears to be meaningless to everyone else. They re-did the ‘Contact’ section at the bottom of the page. The contact email address remains the same, but they removed the suggested reason for contacting anyone at that address. They had asked “Questions about the Summit?” and included the email address in the canned answer. Now the email address just stands alone beneath the ‘Contact’ header. They also removed the old link to the Chemical Sector-Specific Agency from the bottom of the page. That old listing was a little duplicative since the same link is provided at the top of the page. Oh well, we are still informed that more “conference details will be available soon”; so I’ll keep watching the page.

Monday, June 28, 2010

S 2996 Mark-Up?

An article over on EPOnLine.com again mentions the possibility of Sen. Collins’ (R, ME) CFATS reauthorization bill (S 2996) being marked up in the Senate Homeland Security and Governmental Affairs Committee. I mentioned an earlier claim for a mark-up being scheduled for this bill and I have also discussed what I thought would be necessary to get such a mark-up successfully completed in that Committee. It is almost too late now to get this bill (or any CFATS reauthorization bill) to the floor of the Senate before the summer recess in August, especially since we have the 4th of July ‘weekend’ (a week long weekend) coming up at the end of this week. While the Collins’ bill might get out of Committee I don’t believe that it would be considered (favorably or otherwise) on the floor of the Senate. The current level of mistrust for big chemical companies is just too high because of the BP leak in the Gulf. The rest of the article is a very interesting and readable account of the Chemical Sector Security Summit being co-sponsored by SOCMA and DHS next week. If you don’t already have confirmed reservations it’s too late. But, you can read tweeted updates by following SOCMA on Twitter®.

Thursday, June 10, 2010

Chem Sector Security Summit Update 06-10-10

Today DHS updated the web page for the Chemical Sector Security Summit that will be held next month. DHS added a link to the Summit brochure and provided some additional information on registrations. Brochure The brochure provides significantly more details about the upcoming program than had previously been available. I’m not going to list all of the programs, just the ones that I think are of special significance. Your list would be different than mine, so go look at the brochure.
● Threats to the Homeland and the Chemical Sector ● Chemical Facility Anti-Terrorism Standards (CFATS) and Ammonium Nitrate (AN) Update ● Potential Threat Actors’ Tactics, Techniques, and Procedures ● Inspections Process Lessons Learned ● Research & Development in Inherently Safer Technology (IST) ● The Future of Background Checks for the Chemical Industry ● A Congressional Perspective
There are plenty of other interesting programs and they all have a wide range of presenters and panelists. There are representatives from DHS and a variety of Executive Branch folks and Legislative Staffers. Industry is well represented and there will even be a few labor representatives. About the only group interested in ‘chemical security’ that is not represented is Greenpeace; I think it would have been good politics to include them or a Center for American Progress representative on one of the IST panels. Registration As I noted in my previous blog post on this topic, the registration has been closed since late March. This page update informs registrants that:
“Those who are registered received a confirmation email. Please remember to bring photo identification and your confirmation number with you to the Summit registration table where you will receive a badge and event materials.”
They have also provided an email point of contact for questions about registrations. The page also notes that there is going to be additional information provided in the coming days. You can sign up for email updates from DHS or you can just read about it here in the blog. Or, you could do both. I will take this opportunity to once again suggest to DHS and the Chemical Sector Coordinating Council, the co-sponsors of this summit, that many of the presentations are critically important to many more people in the chemical sector than could have registered for the summit. Especially in the current economic climate a number of interested folks in the industry just could not justify the cost of attendance. I think it would be a great idea to have many (if not all) of the presentations posted on the DHS web site after the conference is over.

Tuesday, April 27, 2010

2010 Chemical Sector Security Summit Update

DHS updated the 2010 Chemical Sector Security Summit web page yesterday afternoon. The new page notes that the registrations for the Summit are now full. They are accepting requests to be put on a standby list. This happened last year as well. This is one of the reasons that registration was limited to just three people per organization. Perhaps DHS should consider increasing the size of the Summit; though that might decrease the opportunities for personal communications. Alternatively, they could consider holding this twice a year instead of just once. As part of the Department’s Open Government policy, DHS should give serious consideration to web casting the conference, or at least the presentations made by Department personnel. Comment to the Chemical Security Community: If you have a confirmed registration that you are not going to be using for some reason, please contact Summit organizers as early as possible so that someone on the standby list can go instead.

Monday, August 10, 2009

Tidbits from Security Summit Presentations

As I noted yesterday, DHS has posted copies of the slides used in their presentations at the 2009 Chemical Sector Security Summit on the CSSS web site. In today’s posting I’ll abstract some of the interesting (to me at least) bits of information that can be found in these slides. I still don’t have much in the way of supporting information; just the copies of the slides. Ammonium Nitrate Regulations “Background Check − Individuals registering with DHS will have their identifying information screened against information in the Terrorist Screening Database (TSDB)” “Registration Numbers – Individuals registering with DHS will generally be issued or denied registration numbers within 72 hours of receipt of a complete registration application” “Manner of storage of records − Facilities have discretion over the creation, formatting, and storage of their records, provided they contain the required data fields” “Any AN seller who has knowledge of a theft or unexplained loss of AN must report such theft or loss to Federal law enforcement within 24 hours of discovery” “For loss reporting, an individual must report any loss of AN where the loss deviates from the amount of loss that typically occurs during routine production, storage, transportation, or use of AN” “An individual who is denied an AN Registered User Number has a right to appeal that decision, and the appeal must be heard in 72 hours” “An individual who is denied an AN Registered User Number has a right to appeal that decision, and the appeal must be heard in 72 hours” “DHS expects to publish the AN NPRM this fall” “DHS will conduct extensive outreach on the AN regulations” Chemical Facility Anti-Terrorism Standards Overview “Current Preliminary Tiering – 6,400 total facilities” “Top-Screen Resubmissions – 4,002 received “123 Tiered Up (Error 72/Material Modification 31) [3%] “1,537 Tiered Down (Material Modification 1020)” [38%] [2,342 No change by my calculations – 59%] “SVA Review Process and Tiering Engine – “Subject Matter Expert (SME) reviews of each for chemical, physical and cyber security “Tiering engine assigns overall risk score (CxVxT), ensuring consistent application of methodology and appropriate final tiering demarcation points “Review process identifying facilities/companies needing immediate action” “Personnel Surety portal status (TSDB check for RBPS 12, Personnel Surety) − “Working with SCO and TSA to build portal “PRA published in FR June 10, comment period closes August 10 “Scheduled to be operational in late 2009” “DHS receives and reviews a facility’s SSP for the following: “Compliance with due date (date received vs. due date) “Administrative completeness and accuracy “Description of the Security Risk Management Program- “Quantitative review via Security Risk Engine “Qualitative review via DHS SMEs: Physical Security Analyst, Cyber Security Analyst, Chemical Analysts” “Indefinite Agricultural Production Facilities Top-Screen Extension “Issued December 20, 2007 for possession of COI solely for preparation for treatment of or during application to crops, feed, land or other areas on an agricultural production facility “Next Steps - “Use current CFATS authority to direct distributors to complete supplemental Ag-focused questions (Shared with USDA for comment week of 6/22) “Evaluate regulatory approach based upon data review (possibly set Ag COI STQs)” Chemical-terrorism Vulnerability Update “In the event of any disagreement between the facility and the public official regarding the precise CVI to be disclosed or the method of disclosure, DHS encourages the parties to refer the matter to DHS.” “In the event of any disagreement between the facility and the Federal Official regarding the disclosure of CVI or the method of disclosure, the parties to refer the matter to DHS.” Site Security Plan Development and Inspections “Preparation for Inspection “Pre-visit logistics –availability of required personnel, facilities, and site assets, etc. “Assembly of supporting documentation –procedures, plans,records, etc. that support the facility characterization, asset characterization(s), and explanation of RBPS satisfaction described in the Site Security Plan.” Site Security Plan “SSP tool allows for multiple preparers (CVI Certified) − “Identify relevant facility, company and corporate level expertise “Organize SSP team members “Clarify individual responsibilities “Schedule the SSP’s completion, validation, and submission “SSP submitters will be locked out when multiple users are loggedin “The last answer cancels the previous answer in the SSP” Theft & Diversion: Prevention and Compliance “This RBPS, especially the ‘Theft’ element, applies to some degree to virtually all covered facilities, insofar as a facility is not covered in the first place if it has no ‘potentially dangerous chemicals’.” “Diversion is the criminal act of acquiring a product (or service) by means of deception.” “DHS expects to see specific measures addressing both the “straightforward”issue of theft and the more complicated issue of diversion in some combination depending on the Tier Level.” “Another excellent source document on counter-diversion programs is the Drug Enforcement Administration's Chemical Handler’s Manual” Voluntary Practices and Industry Practices “Bi-annual Classified Briefings “The SSA sponsors classified briefings for cleared industry professionals in order to assist them with prioritizing the level and type of security measures to implement “Both physical and cyber threats are briefed and any other topics of interest to chemical supply chain professionals” “The Chemical Sector is participating in a pilot program to improve cyber information-sharing processes which includes monthly calls between small trusted cyber security group in the Chemical Sector, the National Cyber Security Division (NCSD) and Chemical SSA” “Voluntary Chemical Assessment Tool (VCAT) “The web-based tool facilitates a cost-benefit analysis allowing users to select the best combination of physical security countermeasures and mitigation strategies to reduce overall risk” “Multi-plant tours designed to give public sector partners involved with chemical security an opportunity to see firsthand the security measures at facilities” General Comments Looking at these slides, it certainly seems like the Chemical Sector Security Summit should have been a worthwhile meeting to attend. But give the fact that there are over 6,000 covered facilities there is no way that the Summit was large enough to include participation of even just a single representative of each facility. The Chemical Sector Coordinating Council and the Chemical Sector-Specific Agency, the co-sponsors of the event, need to consider web casting the presentations.

Thursday, August 6, 2009

Chemical Sector Security Summit Update

Earlier this week the DHS Office of Infrastructure Protection updated the 2009 Chemical Sector Security Summit web page. The new page reflects the fact that the 2009 Summit was successfully held earlier this summer. It also provides a link to a new web page containing a listing of the various DHS presentations that were made at this year’s summit. That listing provides links to a .PDF version of the slides used in the presentations. I’ve only had a chance to quickly glance through each of the slide shows, but there is certainly a great deal of interesting information contained in the presentations. I’ll prepare a more detailed listing of the interesting stuff, but for right now here are the presentations that are available: Ammonium Nitrate Regulations Chemical Facility Anti-Terrorism Standards Overview Chemical-terrorism Vulnerability Update Site Security Plan Development and Inspections Site Security Plan Theft & Diversion: Prevention and Compliance Voluntary Practices and Industry Practices On a special note, it looks like the Site Security Plan presentation is the same set of slides used in the webinar I reported on last month. I was a little disappointed to see only DHS presentations on the page for this year’s summit. Last year DHS did post one private sector presentation. As I noted in last year’s blog on the same topic I suspect that the copy write issues may be responsible for the government only postings. Copies of some of the private sector presentations would certainly provide a clearer picture of the information shared at the summit. Once again, I must warn the reader that the presentations listed above are actually only the Power Point® slides for the presentations. This means that the information is abbreviated. There are also some acronyms used in the slides that were surely explained in the oral presentation, but are now just collections of letters. I’ll see if I can get some explanation for some of the more arcane acronyms. I made the point last year that I thought that DHS should consider web casting these presentations. It would certainly make them available to a much wider audience. They did not get around to doing that this year. Maybe next year the Secretary’s public outreach program through the web will extend to web casting at least the department presentations. On major improvement over last year can be seen in the drastically shorter time to get these documents posted to the web site. Last year it was September 15th before the presentations were up on the web site. This year it was August 4th; much better.
 
/* Use this with templates/template-twocol.html */