Showing posts with label Draft SSP Template. Show all posts
Showing posts with label Draft SSP Template. Show all posts

Monday, April 20, 2009

Draft SSP Review – Risk Based Performance Standards

This is the last in a series of blogs describing the draft SSP Template that was provided by a reader of this blog, not DHS. Just a quick reminder, this means that there might be differences between this template and the one that DHS will shortly be opening on the CSAT web site. The previous blog in the series were: Draft SSP Review – General Facility Information Draft SSP Review – Facility Operations Draft SSP Review – Facility Security Measures Draft SSP Review – Asset Security Measures The bulk of the SSP Template consists of questions and answers regarding the Risk-Based Performance Standards. Any legitimate detailed discussion of the questions will require reference back to the RBPS Guidance document. Unfortunately, the Office of Management and Budget has still not yet approved the final version of this Guidance Document. With the amount of time that it has taken to get OMB approval, it is very possible that there will be some significant required by OMB before the guidance document can be published. That would require at least some changes form the draft version of the SSP that I currently have. Even trying to divine the contents of the Guidance documents from the questions available in the draft SSP Template that I have would be difficult at best and unfair at worst. For example, one of the controversies raised in the Draft RBPS Guidance document was the issue of ‘requiring’ an on-site armed response force. Question 10.33 in RBPS # 4 asks about security force weapons. This is a legitimate question even if there is no indication in the RBPS Guidance that DHS would like to see some facilities have an armed response force. So, until the RBPS Guidance document is published, there isn’t much else I can say about the draft Site Security Plan Template.

Friday, April 17, 2009

Draft SSP Review – Asset Security Measures

This is another in a continuing series of blogs describing the draft SSP Template that was provided by a reader of this blog, not DHS. Just a quick reminder, this means that there might be differences between this template and the one that DHS will shortly be opening on the CSAT web site. The previous blog in the series was: Draft SSP Review – General Facility Information Draft SSP Review – Facility Operations Draft SSP Review – Facility Security Measures In the last blog I looked at the Facility Security Measures section of the Draft SSP Template. The next, largest, and potentially the most controversial portion of the template deals with questions supporting each of the 18 Risk-Based Performance Standards (RBPS). I am going to skip that portion for now for a look at the final section in the template; the Asset Security Measures. We will look at the specific RBPS in later blogs. Asset Security All of the discussion about security measures in the SSP so far has dealt with the security for the entire high-risk facility. In many instances it may be appropriate to provide the highest level of security protection to just a few areas of the facility where COI are stored, produced, loaded or unloaded; where that COI is most vulnerable. This targeted security is known as ‘asset security’ or critical asset protection’. Not all assets covered in this section will be specifically associated with a unique COI. The best example of this would be a control room; because of the access to control, safety and perhaps security systems available in this location this location could be expected to be a prime target in a terrorist attack on a chemical manufacturing facility. Asset Description The first thing that must be done in this section of the template is to identify the assets for which there will be asset specific security measures reported. It is not necessary to identify all assets associated with COI, just those that have unique security measures not previously identified in the Facility Security Measures section. Each asset will be given a unique name (34 character limit) and a description that includes a listing of the primary function of the asset. Once the asset is identified there will be a unique sub-section of the template produced for each of the listed assets. For each asset there will be another series of questions that relate to the COI present at the facility to determine if those COI are ‘associated’ with the asset. The term ‘associated’ does not necessarily mean present; a control room for example would be associated with any COI that can be controlled from that location. RBPS Identification The final portion of the asset identification process is the determination of what risk-based performance standards would apply to that particular asset. There are only four RBPS that could be identified for this section of the template: #2 – Secure Site Assets; #3 – Screening and Access Controls; #5 – Shipping, Receiving and Storage; and #6 – Theft and Diversion. Only those RBPS for which there will be an identifiable security measure need to be selected for a particular asset. As a practical matter, submitters might want to initially select all four RBPS for each asset described. Subsequently, if no questions are answered affirmatively for that particular asset in that RBPS, the facility can always de-select that RPBS. RBPS Questions Each of the four RBPS sections will have similar questions to those found in the Facility Security Measures section of the SSP Template. At the start of each RBPS in this section, the submitter will be given the option of pre-populating the section with the same answers provided in the main section of the SSP. This would be useful if the same type security measures used for the facility in general are duplicated at the asset. For example, if the asset is surrounded by the same type of fencing that forms the facility perimeter. But, an asset that does not have a barrier around it does not get ‘credit’ for the facility barrier in this section. This section is used only to describe security measures that are specifically protecting the described asset.

Thursday, April 16, 2009

Draft SSP Review – Facility Security Measures

This is another in a continuing series of blogs describing the draft SSP Template that was provided by a reader of this blog, not DHS. Just a quick reminder, this means that there might be differences between this template and the one that DHS will shortly be opening on the CSAT web site. The previous blog in the series was: Draft SSP Review – General Facility Information Draft SSP Review – Facility Operations This posting will be a general overview of what will undoubted be the largest portion of the Site Security Plan, the Facility Security Measures section. This section looks at overall site security measures, not measures related solely to particular assets within the facility boundary. Those asset security measures will be addressed in a later portion of the draft SSP Template. Risk-Based Performance Measure List The first thing one sees when starting the Facility Security Measure section of the SSP is a list of the 18 Risk-Based Performance Standards (RBPS). The instructions on the template read: “For each of the following RBPS, you must click on the box and then answer Yes or No as to whether the facility has any security measures for that RBPS.” For each of the RBPS marked ‘Yes’ the SSP submitter will subsequently see an extensive series of questions concerning that RBPS in a sub-section related just to that RBPS. The subsections for those RBPS that are marked ‘No’ will not appear. I would expect that the vast majority of facilities that have approvable Site Security Plans will have security measures for each RBPS. The one RBPS that might checked ‘No’ by a limited number of facilities will be RBPS #8, Cyber Security. There are still a few facilities that have no computer systems to protect. Any facility that checks ‘No’ to any RBPS should expect that they will have to fully justify that selection to DHS before DHS even starts to consider approving the Site Security Plan. I would suggest that facilities would want to initially check ‘Yes’ to each RBPS and carefully review each section to see if there is even a single question that can be answered before deciding to come back and check ‘No’ to any RBPS. Existing, Planned, or Proposed Security Measures Each RBPS subsection will be headed by the same initial question; “Does the facility have any existing, planned, or proposed security measures for RBPS X? This is a good place to discuss the difference between these three categories of security measures. The distinctions are important to the SSP approval and inspection process. An ‘existing’ security measure is obviously currently in place and operating. If DHS were to show up today, the facility would be able to show measure to the inspector. A ‘planned’ security measure is one that is not yet installed or in place but has received formal management approval and is going to be installed by a scheduled date. A ‘proposed’ security measure is one that the facility is considering for installation, but the approval process has not yet been completed. Essay Question At the end of each RBPS sub-section there is one final question. This question does not have the common ‘Yes/No’ check-off that most questions get, or even the short, fill-in-the-blank for the inevitable ‘Other’ questions. The question is long, but so is the potential answer. That is why I call this the ‘Essay Question’. Here is the question:
“Does the facility have any proposed security measures for satisfying this RBPS that it wants to share with DHS? In the response to this question, the facility may share with DHS any existing or planned security measures the facility proposes to remove or eliminate to include a general timeline for such action. In the response to this question, the facility may also identify any existing or planned security measures which the facility has identified in this RBPS section, but which the facility does not wish DHS to include in evaluating its SSP for approval. Please see section 4.1.3 and 5.1.3 of the CSAT Site Security Plan Instructions for more detail.”
As I explained in an earlier blog, the purpose of this question is to give DHS an idea of what changes are currently planned for the Site Security Plan. If the current/planned security measures are determined to be inadequate, but there are proposed measures included here, it would allow DHS to tell the facility which of the proposed measures would enable DHS to approve the plan. Asking DHS not to include reported security measures in their evaluation will serve a similar purpose; if DHS approves the program without considering these measures, the company will be free to remove these measures without effect on their SSP status. If the facility has any existing security measures that it is considering taking out of service or removing, notifying DHS of this in this question would allow DHS to comment on how this removal would affect the continued approval of the Site Security Plan. Paired with proposed improvements, this would again give DHS a chance to ‘approve’ off-setting improvements. Once again, the approved Site Security Plan will become essentially a contract with DHS. It will provide the standard by which DHS inspectors will judge the adequacy of security arrangements at the facility.

Wednesday, April 15, 2009

Draft SSP Review – Facility Operations

This is another in a continuing series of blogs describing the draft SSP Template that was provided by a reader of this blog, not DHS. Just a quick reminder, this means that there might be differences between this template and the one that DHS will shortly be opening on the CSAT web site. The previous blog in the series was:

Draft SSP Review – General Facility Information

The next portion of the Draft SSP Template will be the general facility information portion of the tool. This section of the template will require the facility management to contact a variety of local government agencies to get data. If the facility has not established a working relationship with these agencies by this point in the facility security preparations, now is a good time to do so.

Facility Description 

There are some new questions about the facility that have not been previously required in the CFATS process. The first that the facility will see is the ‘facility type’ this provides a pull down menu with a description of various types of chemical facilities. The copy of the draft template that I have does not show the pull down options, but this should be a fairly straight forward selection process. If there is no appropriate selection there is a fill in the blank option available.

The next ‘question’ appears to be awkwardly worded; it reads: “Provide the Office of Emergency Management (OEM) authority under which the facility operates.” From the example provided in my copy of the template, “County”, it is apparent that the question refers to the lowest level of ‘Emergency Management Agency/Administration’ that services the facility area. The selection is made from another pull down menu with the standard fill-in the blank ‘other’ option.

The other two questions in this sub-section deal with the ‘locale’ of the facility and the ‘type construction’. The responses are chosen from the inevitable pull down menu with the standard ‘other’ option.

Facility Contact Information 

This sub-section requests the name and contact information for four separate ‘Security Officer’ listings; Facility Security Officer, Assistant Facility Security Officer, Corporate Security Officer, and Cyber Security Officer. I am certain that the written instructions will make abundantly clear that there must be at least two separate names provided, one for the Facility Security Officer and the Assistant. Larger facilities and multiple high-risk facility companies will almost certainly have separate names for the other two positions.

The last question in this subsection is something of a step-child, put here for the lack of a better heading. It asks: “Does the facility implement security plans required or recommended by the following agencies?” It then provides ‘Yes/No’ check-offs for TSA, DOT, Coast Guard, Customs and the ever present ‘Other’. If a facility is unsure about this question it probably does not apply.

On-Site Response Capabilities 

This next section asks a number of questions about the on-site emergency response capability for the facility. Most of the requested responses are ‘Yes/No’ check-offs with one fill-in the blank (name of facilities that share the response capability) and one fill-in the number (number of members of the on-site Emergency Management Team).

The only ‘odd’ question is the one about ‘Special Response Capabilities’. What constitutes an SRC is not clear until the next page where there is a list of ‘Capabilities’ that DHS is interested in. Some items on the list, field medical and toxic release response for example, are fairly common, but there are some exotic response capabilities listed. ‘Aviation’, ‘Hostage Rescue’ and ‘Snipers’ are three that are sure to raise some eye brows. Responses are simple ‘Yes/No’ check-offs.

Emergency Response Information 

This section starts off with two easy questions about facility shelter-in-place capability and the presence of a ‘community notification system’. Both questions require a ‘Yes/No’ check-off. The remaining questions are going to require extensive conversations with off-site emergency response agencies. While there is an added ‘Unknown’ check-off option for many of these questions, I don’t believe that DHS will (nor should) accept that answer for too many questions.

The emergency response agencies that the Draft SSP Template addresses are local police, fire department, emergency medical technicians (on-site and off-site), and mutual assistance groups. The questions deal with the name of the agency, number of full-time personnel, response times and ‘Special Response Capabilities’. The SRC section provides the same list of capabilities as found in the on-site response section.

Special Response Capabilities 

This sub-section of the Draft SSP Template should probably been called ‘Other Response Agencies’, that would have been less confusing. It looks for information on three other agencies that might be counted on to respond to an incident at the facility. These agencies are State Police, US EPA, and State EPA. Most of the questions are the same as for the previous response agency section. One new addition is the question that asks: “Is there a formal, written agreement with the responding agency?”

Facility Personnel 

The number and type of employees working at the facility are addressed in this sub-section. The questions ask for numbers of ‘Employees’ and ‘Security Officers’ in the categories of full-time, part-time, contractors, and others. There are also questions about the shift times and number of employees on each shift.

COI – Chemical Operations 

The types of operations involving the facilities listed COI are covered in this sub-section. Those operations are shipping, selling, receiving, and manufacturing. Each of the COI listed in the General Facility Information section of the template are pre-populated into this sub-section. There are ‘Yes/No’ check-offs for each of the COI to determine if the operations apply to that COI. There is also a question about what industries the facility supplies. Finally, for each COI that has been indicated as being shipped or received is listed in a separate section asking about the mode of transportation used for shipping and receiving.

Uploads 

The final two sub-sections in the Facility Operations section of the SSP deal with optional data uploads to the system. The first is the ASP upload. All high-risk facilities have the option of filing an Alternative Security Plan in lieu of completing the remainder of the SSP as long as it meets the requirements of 6 CFR § 27.225. Given the problems that facilities had with using ASP’s in lieu of filling out the DHS SVA, I doubt that many ASP’s will be approved on the first go round.

The second upload sub-section is for ‘Facility Schematics’. This allows facilities to upload aerial photographs, plot plans, drawings and system schematics to DHS. The simplest facilities probably will not need to do this, but any facility that handles multiple COI, or COI in multiple locations should probably plan on providing documents to make it easier for DHS to understand the locations of COI storage and other key locations.

 A personal recommendation; use a good security software program to scan your files for bugs, viruses, worms, etc before uploading them to the DHS system. I am very sure that DHS is going to scan these upload documents, but it looks pretty tacky if you try to upload an infected file to the DHS system.

Tuesday, April 14, 2009

Draft SSP Review – General Facility Information

As I noted in yesterday’s blog, I received this SSP template from a reader, not DHS. This being the case I am not absolutely sure that the template that I have is the one that DHS will actually use in the CSAT. To make sure that everyone remembers that distinction I am calling this a ‘Draft SSP Template’ or ‘draft submission template’. That makes this series of blogs a ‘Draft SSP Review’. Front Page Information The first page of the draft submission template provides the typical disclaimers, paperwork reduction statement, and the standard ‘true, complete, and correct to the best of my knowledge’ statements. There is, however, a description of the SSP process that bears reviewing en toto:
“The CSAT SSP tool collects information from covered facilities regarding existing and - if a covered facility so chooses - planned and proposed security measures. Facilities are required to list and/or describe existing security measures as part of their CSAT SSP submissions. However, this SSP tool will provide facilities the opportunity to propose that certain existing and/or planned security measures identified in this tool not be considered by DHS in evaluating their SSPs for approval. Of course, if a facility chooses not to provide information about an existing or planned measure that is relevant to satisfaction of one or more CFATS RBPS, it is possible that the facility’s SSP, as submitted, may not satisfy the applicable RBPS.”
Why would a facility not want a security measure considered as part of their SSP? Once a facility SSP is approved it becomes the facility’s security contract with DHS. It becomes the standard by which DHS inspectors will evaluate the adequacy of facility security measures. There could be security measures that a facility is experimenting with or evaluating that might not work out. If those measures were included in the SSP evaluation then the facility would have to get DHS approval to terminate those measures. Why would DHS want security measures reported but not considered in the SSP evaluation? If an SSP submission were deemed to be inadequate in one or more of the Risk-Based Performance Standard (RBPS), but would be adequate if the ‘reported but not considered’ performance measure had been considered, it would provide DHS with an easy suggestion for brining the SSP up to standard. The notification letter would then be able to point out the ‘quick’ way of correcting the SSP and the correction could take place with a quick SSP resubmission. Without the ‘reported but not considered’ measures DHS has no legal way to ‘suggest’ ways that the SSP can be brought into compliance without running afoul of the §550 restrictions. This could lead to multiple SSP resubmissions to get the facility into compliance. One last item of interest on the cover page; at the bottom of this page (and every page in the template) is the standard Chemical-Terrorism Vulnerability Information (CVI) warning. When this template is populated with information, it automatically becomes CVI and must be protected in accordance with the requirements of 6 CFR §26.400 and the CVI Procedures Manual. Facility Information The next several pages of the draft submission template deal with information about the facility. Most of this information should already be ‘populated’ when the facility signs into the SSP tool in CSAT. The information comes from previous (Registration, Top Screen and SVA) submissions. It still needs to be reviewed corrections made where necessary. There is one item of information that cannot be corrected without bringing DHS actively into the correction process. That is the ‘Facility Coordinates’ (latitude and longitude) section. Because so much of the DHS information and analysis of the facility security situation relies on this data, DHS does not want changes made to this without their direct involvement. If there is an error in this data, contact the Help Desk (866-323-2957). Notification Letter Information The next rather lengthy section (15 pages) covers verification of information provided in the Facility Final Notification Letter (FFNL). The FFNL is the letter that DHS sends out after reviewing the facility Security Vulnerability Assessment (SVA) and officially designates the facility as a High-Risk Chemical Facility (and thus covered under 6 CFR part 27), designates the Facility Tier Ranking (Tier 1 the highest and Tier 4 the lowest) and designates the Chemicals of Interest (COI) that the facility must ‘protect’ under its Site Security Plan. Again, this information should be pre-populated when the facility signs into CSAT. The information must be carefully reviewed and compared to the data in the FFNL. Do not rely on facility Top Screen or SVA data for this review; use the FFNL. Again, because this data is such an integral part of the CSAT process, changes can only be made by contacting the Help Desk.
 
/* Use this with templates/template-twocol.html */