Showing posts with label EAP. Show all posts
Showing posts with label EAP. Show all posts

Thursday, June 16, 2022

OCS Updates CFATS FAQ – 6-15-22

Yesterday, CISA’s Office of Chemical Security (OCS) updated the responses to one of the Frequently Asked Questions (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The revision updates a URL used in the response to FAQ #1738 to provide information on the CFATS Expedited Approval Program:

FAQ #1738 What is the difference between the Expedited Approval Program (EAP) and the Chemical Facility Anti-Terrorism Standards (CFATS) program?

NOTE: The link provided for the FAQ in this post was copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ, you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The new version of the FAQ provides a ‘new’ link to the CFATS Expedited Approval Program (EAP) page. The last time that I looked at this page it had an August 14th, 2018 ‘last published date’ marked on the page. There is no date on the current page (CISA very seldom provides dates for their web site pages). The only change on that newer page is the address to be used for the notification letter:

Chemical Security, Associate Director

CISA – CHR STOP 0609

Cybersecurity and Infrastructure Security Agency

1310 N. Courthouse Rd.

Arlington, VA 20598-0609

That address was added to unrelated FAQs, in February 2021, so the new EAP page probably dates from about the same time.

Tuesday, August 27, 2019

ISCD Updates a Number of CFATS Information Documents


Recently the DHS Infrastructure Security Compliance Division (ISCD) provided links to a number of new and updated information documents related to the Chemical Facility Anti-Terrorism Standards (CFATS) program. Links were provided on either the CFATS Knowledge Center page or the CFATS Resources page.

The new or revised documents I found are:


I have not done (and probably will not do) a detailed review of the revised documents. These are ‘fact sheets’ and those are seldom (if ever) used to announce new policy. If new policy were involved, we would have seen a more formal announcement of the revised documents. I suspect that this was mainly a branding exercise for the new Cybersecurity and Infrastructure Security Administration (CISA).

The odd one on the list above was the EAP guidance document. It was not rebranded with the CISA format or logo. There is no date on the document, so I am not even sure that it was revised. It was listed on the top of the ‘User Manuals’ column of the CFATS Knowledge Center, so ISCD is apparently attempting to at least call attention to the manual. The EAP program was mandated by Congress in the first re-write of the CFATS legislation and may not survive the second re-write. It has not been used by more than a handful of facilities, but that is more because it was introduced after the vast majority of facilities had already submitted proposed Site Security Plans under the existing program than it was because of any problems with the EAP.

Most of the documents listed above have dates back in May. I am not sure when they were actually published or the links made available. A couple of years ago DHS generally stopped putting date of change notices on their web pages. With web sites that are as voluminous as the CFATS program this makes it very difficult to keep up with the changes. I had hoped with the rise of CISA (and the fall of NPPD, its predecessor) that we would see a change in this policy. Every once-in-a-while a ‘last published date’ slips in (see here), but I have not seen any indication that this is more than the action of isolated web-scriptors trying to do right.

Sunday, September 9, 2018

S 3405 CFATS Reauthorization – EAP


This is the third in a series of blog posts about S 3405, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2018, which would reauthorize the Chemical Facility Anti-Terrorism Standards (CFATS) program for five years. The other blog posts in the series include:


Expedited Approval Program (EAP)


Section 4 of the bill makes a large number of changes to 6 USC 622(c)(4), the Expedited Approval Program. This subparagraph was added by the 2014 bill as a method to allow Tier 3 and Tier 4 facilities a smoother path to having a site security plan approved by DHS. There are almost three pages of changes made to the EAP language by §4 and they are difficult to understand without looking at how the language of §622(c)(4) will actually look once these changes are put into place. So here goes; stricken language is lined through, added language is highlighted and the ‘ ’ indicates where extended portions of the language have not been changed.

(4) Expedited approval program
(A) In general  
A covered chemical facility assigned to tier 3 or 4 may meet the requirement to develop and submit a site security plan under subsection (a)(2)(D) by developing and submitting to the Secretary—
(i) a site security plan and the certification described in subparagraph (C)(i); or
(ii) a site security plan in conformance with a template authorized under subparagraph (H).
(B) Guidance for expedited approval facilities
(i) In general Not later than 180 days after December 18, 2014, the Secretary shall issue The Secretary shall maintain guidance for expedited approval facilities that identifies specific security measures that are sufficient to meet the risk-based performance standards.
(ii) Material deviation from guidance If a security measure in the site security plan of an expedited approval facility materially deviates from a security measure in the guidance for expedited approval facilities, the site security plan shall include an explanation of how such security measure meets the risk-based performance standards.
(iii) Applicability of other laws to development and issuance of initial guidance During the period before the Secretary has met the deadline under clause (i), in developing and issuing, or amending, the guidance for expedited approval facilities under this subparagraph and in collecting information from expedited approval facilities, the Secretary shall not be subject to—
(I) section 553 of title 5;
(II) subchapter I of chapter 35 of title 44; or
(III) section 627(b) of this title.
(C) Certification The owner (i) In general the owner operator of an expedited approval facility shall submit to the Secretary a certification, signed under penalty of perjury, that—
(i) (I) The owner or operator is familiar with the requirements of this subchapter and part 27 of title 6, Code of Federal Regulations, or any successor thereto, and the site security plan being submitted;
(ii) (II) the site security plan includes the security measures required by subsection (b);
(iii) (III) (I) (aa) the security measures in the site security plan do not materially deviate from the guidance for expedited approval facilities except where indicated in the site security plan;
(II) (bb) any deviations from the guidance for expedited approval facilities in the site security plan meet the risk-based performance standards for the tier to which the facility is assigned; and
(III) (cc) the owner or operator has provided an explanation of how the site security plan meets the risk-based performance standards for any material deviation;
(iv) (IV) the owner or operator has visited, examined, documented, and verified that the expedited approval facility meets the criteria set forth in the site security plan;
(v) (V) the expedited approval facility has implemented all of the required performance measures outlined in the site security plan or set out planned measures that will be implemented within a reasonable time period stated in the site security plan;
(vi) (VI) each individual responsible for implementing the site security plan has been made aware of the requirements relevant to the individual’s responsibility contained in the site security plan and has demonstrated competency to carry out those requirements;
(vii) (VII) the owner or operator has committed, or, in the case of planned measures will commit, the necessary resources to fully implement the site security plan; and
(viii) (VIII) the planned measures include an adequate procedure for addressing events beyond the control of the owner or operator in implementing any planned measures.
(ii) RISK-BASED PERFORMANCE STANDARDS.—In submitting a site security plan and certification under subparagraph (A)(i), an owner or operator of an expedited approval facility should consider using the guidance for expedited approval facilities to determine appropriate measures for the site security plan of the expedited approval facility.

(D) Deadline (i) In general Not later than 120 days after the date described in clause (ii), the owner or operator of an expedited approval facility shall submit to the Secretary the site security plan and the certification described in subparagraph (C) subparagraph (C)(i).
(ii) Date The date described in this clause is—
(I) for an expedited approval facility that was assigned to tier 3 or 4 under existing CFATS regulations before December 18, 2014, the date that is 210 days after December 18, 2014; and
(II) for any expedited approval facility not described in subclause (I), the later of—
(aa) the date on which the expedited approval facility is assigned to tier 3 or 4 under subsection (e)(2)(A); or
(bb) the date that is 210 days after December 18, 2014.
(iii) Notice An owner or operator of an expedited approval facility shall notify the Secretary of the intent of the owner or operator to certify the site security plan for the expedited approval facility not later than 30 7 days before the date on which the owner or operator submits the site security plan and certification described in subparagraph (C) subparagraph (C)(i).
(E) • • • (no change)
(F) Amendments to site security plan (i) Requirement (I) In general If the owner or operator of an expedited approval facility amends a site security plan submitted under subparagraph (A), the owner or operator shall submit the amended site security plan and a certification relating to the amended site security plan that contains the information described in subparagraph (C) subparagraph (C)(i). • • •
(G) • • • (no change)
(H) • • • (no change)
(I) Evaluation
(i) In general Not later than 18 months after December 18, 2014, the Secretary shall take any appropriate action necessary for a full evaluation of the expedited approval program authorized under this paragraph, including conducting an appropriate number of inspections, as authorized under subsection (d), of expedited approval facilities.
(ii) Report Not later than 18 months after December 18, 2014, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Energy and Commerce of the House of Representatives a report that contains—
(I)(aa) the number of eligible facilities using the expedited approval program authorized under this paragraph; and
(bb) the number of facilities that are eligible for the expedited approval program but are using the standard process for developing and submitting a site security plan under subsection (a)(2)(D); (II) any costs and efficiencies associated with the expedited approval program;
(III) the impact of the expedited approval program on the backlog for site security plan approval and authorization inspections;
(IV) an assessment of the ability of expedited approval facilities to submit facially sufficient site security plans;
(V) an assessment of any impact of the expedited approval program on the security of chemical facilities; and
(VI) a recommendation by the Secretary on the frequency of compliance inspections that may be required for expedited approval facilities.
(I) NOTICE BY THE SECRETARY.—The Secretary shall provide notice to each covered chemical facility of the expedited approval program under this paragraph.’’.

Commentary


The basic outline of the EAP remains the same. The DHS ISCD is to maintain the current guidance document. Tier 3 and Tier 4 facilities would continue to have the option to use the EAP instead of going through the normal site security plan submission process. And ISCD would enforce the EAP in the same manner as is currently in use.

There are two administrative changes to the EAP that affect actions by ISCD. First, any revisions to be made to the guidance document will no longer be exempt from the publish, comment and response process normally used in regulatory affairs. The original EAP was exempted from that processes because facilities could choose to participate or not and Congress wanted DHS to get the EAP process up and running quickly. This change protects the small handful of facilities that are operating under the EAP from DHS making ad hoc changes to the security requirements for the program.

The second administrative requirement is that DHS would be required to notify ‘each covered chemical facility’ about the EAP process. Typically, the term ‘covered facility’ means a facility that has submitted a Top Screen and has been notified by ISCD that they are required to submit a site security plan. The EAP process remains available to only Tier 3 and Tier 4 facilities, so I do not see why Johnson would want the Tier 1 and Tier 2 facilities notified, but the provision is easy enough to comply with and could arguably already be considered completed because of the current EAP web page.

There is one change to the existing EAP process for submitting facilities that would be made by §4 of the bill. Instead of notifying ISCD 30 days before they submit an EAP security plan and certification, the bill would now only require that notification 7 days before the submission. This notification requirement was a provision that never really made much sense. As long as the facility submitted the EAP documents prior to the required date for submitting a site security plan I cannot fathom why DHS would need any additional prior notification.

There is one oddity in the §4 changes to the EAP language. The new §622(c)(4)(C)(ii) statement does not make much legislative sense. It looks like Johnson was trying to provide facilities with some wiggle room on what security measures that they could select from the EAP guidance, but the way the sub-paragraph was added it does not do that. In fact, Johnsons changing all reference to ‘subparagraph (C)’ to read ‘subparagraph (C)(i)’ specifically removes the new subparagraph (C)(ii) from having any impact on facilities or in any way modifying how ISCD enforces the program.

The one thing that I am surprised not to see in the language of §4 is a revocation of the subparagraph (H)(ii). This is the nearly identical to the language in (B)(iii) which was deleted. Since this clause is found in the section on ‘Templates’ it could be argued that it only provides DHS with an exemption to the publish comment and revise process for changes made to templates. Since DHS has not yet really published any templates (other than the ‘example’ in
Attachment 2 to the EAP guidance document), perhaps Johnson wanted to preserve the ability of DHS to formulate a formal template without having to go through the full administrative process. If that were the case, he should have revised the language in (H)(ii) because it relies on a date in (B)(iii) which would be removed by this bill.

Friday, June 10, 2016

CFATS Update

I mentioned last week that I would have some more information on the latest CFATS update. I had a chance to talk to some folks from ISCD headquarters yesterday. I don’t have the details that I had hoped for (though we may see them in the July update), but I did pick-up some interesting tidbits of information about the CFATS program.

Expedited Approval Program


Back in December 2014 when Congress updated the Chemical Facility Anti-Terrorism Standards (CFATS) authorization they included a mandate for the DHS Infrastructure Security Compliance Division (ISCD) to establish an Expedited Approval Program to help ISCD reduce the backlog of site security plan (SSP) approvals. The idea was that the EAP would provide facilities with a specific blue print for a site security plan instead of having to negotiate a site security plan with ISCD. Congress thought that this would speed up the SSP approval process.

Well, it turns out that only one facility has used the EAP to get their SSP approved to date. It is almost exactly a year since facilities could start the EAP process and only one facility decided that it was a worthwhile program. So, did ISCD waste their time in publishing the EAP guidance document? If you look at it from the number of facilities that opted to formally use the program, probably. In a larger sense, probably not.

Long time readers of this blog will know about my concerns with the Risk Based Performance Standards (RPBS) guidance documents that facilities have had to rely on for standing up their SSPs since 2009. The drafters of that document bent over backwards to ensure that they could not be accused of ‘specifying security measures’ because ISCD was prohibited from that particular committing that particular sin by the old §550 program authorization language. For facility security managers that did not have professional security training (most of them), the document was little better than no guidance. It is little wonder that virtually no first time SSP submission was approved by ISCD.

With the publication of the EAP guidance, facility security managers without security training can get a good idea what type of security measures ISCD is looking for. Facilities still have the ability to tailor their security measures to their own unique environment, but they have a clearer measure of what those measures are expected to accomplish.

BTW: When ISCD rolls out their new risk assessment/tier assignment methodology this fall it looks like they are intending to update a number of program documents to properly reflect that methodology. One of those documents is likely to be the RSBP guidance document.

Enforcement


With ISCD now spending 80% of their inspection time on compliance inspection, it is almost inevitable that there will be facilities that are not in compliance. ISCD has a long history of working with facilities to get security properly in place, and that has continued over to compliance inspections. Unfortunately, it seems that there have been some (no one is currently talking about how many) facilities that ISCD may be (have begun) taking enforcement actions against to ensure that they meet their SSP obligations. Hopefully, they will never meet a facility that is so intransigent that the Secretary will be forced to close the facility, but that is still the ultimate enforcement authority available.

BTW: It looks like ISCD will be announcing at the upcoming Chemical Sector Security Summit (CSSS #10) that they have completely cleared the back-log of SSP approvals. Not all facilities will have approved SSPs then, but SSP processing will be proceeding in regular order with no unreasonable delays between SSP submission and authorization/approval inspections.

Risk Assessment Process


DHS has taken a lot of flak since the beginning of the CFATS program about the methodology they use for determining which facilities that submit Top Screens (more than 50,000 to date) are assessed to be at high-risk for terrorist attack (and thus inclusion in the CFATS program) and then used to determine the Tier Ranking for facilities in the program. DHS was not willing to discuss the details of that assessment process and were obviously missing some information necessary to do a “real” risk assessment.

ISCD will be rolling out this fall their updated and more rigorously justified risk assessment process. ISCD has had their processes vetted by an academic review process as well as a stakeholder review process. So there should be fewer complains (anyone that expects no complaints is using too many good drugs) about the new process. One of the reasons for this is that ISCD is planning on sharing more information (NOT details) about that process with the chemical community. They realize that companies need to be able to take that risk assessment process as they plan to construct new or modify existing chemical facilities so that the security costs associated with the project can be included in the facility planning process.

We have seen the first change associated with this new risk analysis process when ISCD held their Top Screen webinar last February. Since a number of questions were moved into the new Top Screen from the Security Vulnerability Assessment, the SVA is also going to have to be changed. I think that we will see the debut of that new SVA tool at the CSSS. Hopefully ISCD will include that debut in the sessions that they share on the web.

CFATS Rulemaking


ISCD is continuing to work on their notice of proposed rulemaking for updating the CFATS regulations. That process began with their advance notice of proposed rulemaking (ANPRM) published in August 2014. The Spring 2016 Unified Agenda projects that the NPRM will be published in September. No details are available on what changes are going to be proposed for the program beyond what was discussed in the ANPRM.

Closely associated with the CFATS program (but a separate regulatory scheme) is the congressionally mandated Ammonium Nitrate Security program (6 USC 488 thru 488i). ISCD issued their NPRM for the program in August of 2011, but has failed to be able to overcome the cost-benefit questions raised about that proposed rule. Congress has taken cognizance of the problem and DHS, Congress and the potentially regulated industries have been working on a solution to the problem. One monkey wrench thrown into the works has been the significant ISIS use of improvised explosives made with other chemicals. I half-way expect to see a new congressional mandate for precursor chemicals for improvised explosive devices; especially if we see a significant domestic IED that does not use ammonium nitrate.

BTW: If there is another Oklahoma City sized ammonium-nitrate truck bomb, the problems of the cost-benefit analysis will be instantly resolved and a regulation based upon the NPRM will probably be quickly forthcoming.

Missing Questions


I did not get a chance to ask all of the interesting questions that I wanted to, maybe in future conversations. But I would like to know if/when the folks at ISCD are going to remove their current ‘temporary’ exemption for agricultural production facilities from filing Top Screens. I still think this will be a ‘minor’ regulatory burden for almost all of the facilities involved because ISCD would be unlikely to determine that they are at high-risk of terrorist attack (for their chemicals anyway; food security is an Ag Department problem). This may be addressed with the roll out of the new Top Screen.

The other important topic that I did not get a chance to address was the progress being made in implementing the Personnel Surety Program. I think that it would be an interesting addition to the CFATS update if ISCD would include the total number of personnel that have been vetted against the terrorist screening database (TSDB). A number that we will probably never hear (for fairly legitimate reasons) is how many folks have turned up as a match against the TSDB during these checks. I personally expect that most of those positives will be false positives and that will cause problems for both ISCD, facility management and the folks improperly identified as having terrorist ties. I really hope that the number isn’t too large.


As always I appreciate the time that folks took to talk with me about the CFATS program. I have had my differences of opinion over the years with exact methodologies used by ISCD in their implementation of the CFATS program, but I have always admired how hard the folks have worked at making the process work especially how diligently they have tried to make the program a cooperative attempt to increase facility security rather than an adversarial program. Let’s hope that that can continue into the future.

Wednesday, April 13, 2016

ISCD Adds 3 New FAQs to CFATS Knowledge Center

This morning the DHS Infrastructure Security Compliance Division (ISCD) updated the frequently asked question list on the CFATS Knowledge Center. There was no accompanying notice in the ‘Latest News’ section of the landing page, but three new FAQ’s were added and an older FAQ dating back to 2008 was updated.

Two of the FAQs deal with Chemical-terrorism Vulnerability Information (CVI) and the other two deal with compliance inspections for facilities that utilized the Expedited Approval Program (EAP). The four FAQ’s in question are:


CVI FAQs


The response to #1490 deals with the fact that information is only covered under the CVI rules when it is specifically associated with the CFATS program. Much of the information submitted to ISCD via the Chemical Security Assessment Tool (CSAT) is normal business information that is routinely used outside of the CFATS program. Things like the facility address, inventory levels and the like are only considered CVI once they have been entered into the CSAT, and even then only in association with the CSAT forms (either paper or electronic copies).

Anyone that handles CVI material must be a CVI Authorized User (completed the on-line CVI training and have a need-to-know). The actual data being input to the CSAT tool is CVI so anyone doing that entry must be a CVI Authorized User. Upstream of that data entry, during the data collection process, the question is murkier so the FAQ response suggest contacting the CFATS Help Desk for help in making an exact determination.

The response to #1770 explains that CVI is exempted from disclosure under the Federal Freedom of Information Act (FOIA) as well as State and local versions of that law under provisions of 6 USC 623(e) and 6 CFR §27.400(g). It goes on to explain that State and local FOIA requests for CVI information should be forwarded to the DHS Information Management and Disclosure Office, (NPPD.FOIA@hq.dhs.gov).

EAP Compliance Inspection FAQs


The response to #1771 explains that a compliance inspection under the EAP will be looking for the same information that compliance inspection under the standard site security plan (SSP) would be looking for. Not mentioned in the ISCD response is another ISCD document that briefly outlines what to expect from a CFATS inspection.

The response to #1772 explains that while ISCD is allowed to use a mixture of governmental and non-governmental inspectors [authorized by 6 USC 622(d)(1)(B)], that they are currently only using government employees, known as Chemical Security Inspectors (CSI).


Thursday, June 18, 2015

DHS Updates CFATS Knowledge Center – 06-18-15

This morning the DHS Infrastructure Security Compliance Division (ISCD) updated the CFATS Knowledge Center web page by adding a news item about the new Expedited Approval Program (EAP) and providing a link to a fact sheet about the program.

The fact sheet does not provide any new information not already presented on the EAP web page. In fact, in at least one area, there is not as much information provided. The web site notes that the Chemical Security Assessment Tool (CSAT) may be used to provide the 30-day notice to ISCD that a facility intends to submit an EAP site security plan (SSP) as well as providing a mailing address to make that notification. The EAP fact sheet contains no mention of how the facility should go about making the notification.

I can still find nothing on the CSAT web site, or the SSP web site that provides any information about the EAP. Since the 30-day notice process officially started yesterday, ISCD still has 30-days to get the EAP SSP form into the system, but I had expected to see provisions on the CSAT page for submitting the 30-day notice.


Sunday, June 14, 2015

CFATS Update

Here we are half-way through the month of June and the folks at the DHS Infrastructure Security Compliance Division (ISCD) have not yet published their monthly update for the CFATS site security plan (SSP) implementation. Since April of 2013 they have been publishing this monthly compilation of the number of facilities which have had their SSP authorized and approved. If it is published on Monday it will be the latest the update was published since the congressional funding fiasco of 2013.

Is something wrong at ISCD? Probably not. What we are probably seeing is a move to the next phase of the CFATS program implementation. After all, June 16th will mark a milestone in the CFATS program, effectively being the date that the program will make a substantial change in the way the program is authorized and implemented.

Brief CFATS History

The Chemical Facility Anti-Terrorism Standards (CFATS) was the last major anti-terrorism program that can be directly traced back to the attacks in September 2001. In 2006 Congress was finally able to put serious disagreement about how a chemical security plan would be run behind themselves long enough to establish an interim program to get some sort chemical security effort underway while the nearly theological battle in Congress proceeded.

The chemical security program was authorized in a single, short section in the FY 2007 DHS spending bill (§550, PL 109-295). It provided minimal guidance to DHS on how to establish the program and provided some significant limitations as to what DHS could require chemical facilities to do as part of the program.

DHS got off to a fast start standing up the CFATS program. In less than six months they wrote a new set of regulations establishing an innovative new regulatory program that utilized state of the art on-line data collection tools. In the next couple of years they looked at the initial reporting data from over 40,000 chemical facilities that had significant amounts of 300+ DHS chemicals of interest (COI) on hand and determined that just over 4000 of those facilities met the regulatory standard of being ‘at high risk of terrorist attack’.

Those covered facilities completed security vulnerability assessments, again submitting the data to ISCD via the on-line Chemical Security Assessment Tool (CSAT). DHS took the information provided and threat ranked the facilities into four risk tiers. ISCD developed a guidance document for how those facilities should implement the risk-based performance standards required by Congress, and then there was a major hiccup; the program stalled.

For a number of reasons, including some management issues that have not yet been fully reported to the public, the program stopped advancing. Work was being done by the ISCD staff, Chemical Security Inspectors were visiting facilities. Facilities were submitting SSPs, but effectively no site security plans were being approved by ISCD.

In early 2013 the new management team at ISCD finally started making some headway and the authorization and approval of site security plans began in earnest. The program was starting to get back on track. In April of 2007 they started reporting that progress with their monthly updates of status of the CFATS site security plan implementation.

The Fight in Congress

In the meantime Congress continued their in-fighting about how a chemical facility security program should proceed. On one hand, the Democrats (supported by labor and environmental activists) wanted to use the security program to severely limit the chemicals and processes that the industry could use. They argued that if dangerous chemicals and processes could be reduced or eliminated then the facilities would no longer be potential terrorist targets. The Republicans (supported by facility owners) countered that only the engineers and business owners could determine what chemicals and processes would be commercially viable. They argued that DHS did not have the manpower or expertise to make judgements about inherently safer technology.

The importance of this philosophical difference declined as Congress realized that the interim program that they had turned loose on the country was stalled. Their concern about the slow pace of SSP implementation finally overcame the philosophical discussion and Congress finally passed a stand-alone chemical facility security bill last December; HR 4007 was signed by the President on December 18th, 2014.

Moving Forward

The one change from HR 4007 that will most affect the site security plan implementation is the establishment of an expedited approval process for Tier 3 and Tier 4 facilities. These are the lowest risk facilities covered by the CFATS program and the last ones that DHS has started working on for the SSP implementation process. The bill gave ISCD until June 16th, 2015 to publish the guidance for this program and to establish the reporting process that the new program would use to process SSP’s for those facilities that opted to use the EAP program.

The EAP guidance document was published last month. This week we should see a new tool established in the CSAT that will allow facilities to report to ISCD their intention to use the EAP program to develop and submit their SSP. Thirty days after that intention is reported to ISCD those facilities will be able to start submitting their EAP SSPs. This will either require the modification of the current SSP tool in CSAT or the publication of a new tool. I suspect that ISCD will go with the new tool using the general format of the checklist provided in the EAP guidance document.

CFATS Updates?

ISCD is going to allow all Tier 3 and Tier 4 facilities the option to use the EAP process. Even those that already have authorized or approved site security plans. This means that the statistics that ISCD has been reporting in their monthly updates will no longer mean much from the perspective of tracking SSP implementation. Starting on Tuesday some number of currently authorized or approved SSPs will be invalidated as facilities make the decision that their SSP could be simplified or made cheaper by joining the EAP process. So tracking those numbers, at least in the short term, probably does not make much sense.

This is going to be further complicated by the fact that current CFATS facilities (as of December 18th, 2014) have until November 13th, 2015 to complete the EAP process. This means that they would have until October 14th, 2015 to notify ISCD of their intent to complete the EAP process. So, during the period of June 16th to October 14th watching the simple change in numbers of facilities with authorized or approved SSPs is going to be very confusing.

And I can’t let this topic go without at least mentioning the reporting of compliance inspection results. ISCD has been working on compliance inspections now for a little over two years. Well, they are supposed to have been anyway since compliance inspections were supposed to start one year after the SSP was approved at the facility level. Unfortunately, ISCD has not been publicly reporting any statistics on their compliance inspections.

I would assume (I know; a very dangerous word) that there have not yet been any compliance inspections at Tier 3 or Tier 4 facilities (priority was legitimately given to Tier 1 then Tier 2 facilities), but we should start to see some Tier 3 facilities become eligible for such inspections in the near future. Since those facilities have the option to opt out of their current SSPs by selecting the EAP process, future changes in compliance inspection numbers may also be misleading, at least through October 14th.

So, are we going to see a CFATS update this week or not. I don’t really know, I haven’t asked anyone at ISCD. I know that they are busy with the HR 4007 implementation process as well as the on-going SSP authorization, approval and inspection process. I don’t think that checking on a reporting system that they voluntarily started as essentially a PR exercise is really worth bothering them about.


If I had to bet, however, I would say probably not. If I were in Director Wulf’s shoes, I wouldn’t report on any data until I was called to testify about the implementation of the HR 4007 requirements later this year.

Friday, May 29, 2015

EAP Guidance – Personnel Surety

This is part of a continuing series of blog posts on the newly released Expedited Approval Program (EAP) guidance document for Tier 3 and Tier 4 facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in the series are:


In this post I will look at the personnel surety requirements of the EAP. These are covered in section F (pg 50 and pg 86) of the EAP guidance document along with a number of other security management measures. The personnel surety program is covered under the Risk-Based Performance Standard #12 in the RBPS guidance document. In the CFATS regulations there are four personnel surety requirements at 6 CFR 27.230(12). They are:

∙ Measures designed to verify and validate identity;
∙ Measures designed to check criminal history;
∙ Measures designed to verify and validate legal authorization to work; and
∙ Measures designed to identify people with terrorist ties;

The EAP guidance document only specifically addresses the first three requirement because ISCD has yet to complete their Personnel Surety Program (PSP) that would address the method of identifying people with terrorist ties. I’ll discuss this further at the end of this post.

EAP Checklist

The EAP checklist lists eight personnel surety requirements:

∙ The facility has identified all affected individuals;
∙ The facility verifies and validates the identity of all affected individuals by a government issued ID or identification document as listed on the I-9 form;
∙ The facility conducts a criminal history check on all affected individuals through a third party background investigation company, national program, or local law enforcement agency. This background check includes national, state, and local resources for a timeframe of no fewer than five years and the report identifies all felonies, at a minimum;
∙ The facility has a process for adjudicating the results of background checks and determining access restrictions in a reasonable manner;
∙ Upon notification from DHS, the facility will implement a process to identify all affected individuals with terrorist ties;
∙ The facility escorts all visitors which do not have background investigations via an approved and trained escort; and
∙ The facility maintains documentation (at a minimum: employee name, how the required checks were conducted, and the results of the checks) of background checks for all current affected individuals in order to demonstrate compliance with personnel surety requirements.

The term ‘all affected individuals’ is specifically defined as:

∙ Facility personnel who have or are seeking access, either unescorted or otherwise [emphasis added], to restricted areas or critical assets; and
∙ Unescorted visitors who have or are seeking access to restricted areas or critical assets.

There are two items from the RBPS Metrics (pgs 99-100) that are not addressed in the EAP guidance. First Metric 12.2 for Tier 3 facilities requires that investigations “are repeated for all individuals at regular intervals”. And Metric 12.5 for all facilities requires that the background check program is audited annually.

Additional EAP Information

The discussion of the personnel surety program in the EAP guidance (pgs 50-52) provides only limited amounts of additional information. Most importantly, the guidance does make it clear that owners have some leeway in determining whether or not contractors are included in the term ‘facility personnel’.

There is surprisingly detailed guidance as to what constitutes ‘verifying ID. It includes:

∙ Comparing the picture on the card with the owner;
∙ Comparing the physical characteristics against the person’s physical appearance;
∙ Checking for tampering;
∙ Reviewing both sides of the card; and
∙ Checking the expiration date.

Terrorist Ties Checking

There is currently no approved method for facilities to check for personnel with terrorist ties. ISCD is responsible for setting up this program and has had problems getting the PSP program approved by the Office of Management and Budget due to industry opposition to many of the program elements. The most current proposal has been under review since March of 2014.

The most vociferous critics, and certainly the most influential, have been in Congress. The CFATS statute passed last session (HR 4007) specifically addressed those congressional concerns with the PSP program {6 USC 622(d)(2)}. While that statute requires DHS to establish a CFATS program to identify personnel with terrorist ties, it also allows facility owners to use other “Federal screening program that periodically vets individuals against the terrorist screening database” {§622(d)(2)(B)(i)(I)}. Additionally it requires that a facility accept any credential from such ‘Federal screening program’ if offered by an individual as proof that a covered individual has been screened for terrorist ties.

These new requirements for the PSP program will require a substantial re-write of the program that was submitted to OMB last year. It appears that ISCD is still going to rely on the Information Collection Request (ICR) route for obtaining approval of the PSP program. A footnote on page 6 of the EAP guidance notes that:

“Compliance with RBPS 12(iv) will be required for Tiers 1 and 2 upon approval of an Information Collection Request under the Paperwork Reduction Act, and upon notification to facilities by DHS that the CFATS Personnel Surety Program (i.e., the program enabling compliance with RBPS 12(iv)) has been implemented.”

This is the same two-stage implementation plan that ISCD had proposed in its last PSP proposal. This would allow it to implement the program at the highest risk facilities (and a smaller number of facilities) first. As the bugs were worked out and ISCD had a better idea of the number of individuals that would be affected at the Tier 3 and Tier 4 facilities, ISCD would then go back with a revision to the ICR to allow application of the PSP to Tier 3 and 4 facilities. This means that it could be quite some time before Tier 3 and Tier 4 facilities have to worry about the terrorist ties vetting of their covered personnel.

Commentary

Like the cybersecurity requirements the personnel surety requirements of the EAP are rather vague and potentially allow facilities a great deal of latitude in how those requirements are met. It also means that facilities might face the very real prospect of having DHS specify particular vetting requirements that must be taken when the compliance inspection is completed. This potentially could substantially increase the cost of the personnel surety program and those new costs could come with a very short implementation period.

There is also an interesting new requirement for the Tier 3 and Tier 4 programs that was not included in the original personnel surety requirements outlined in the RPBS guidance document. It is the fifth point in the personnel surety checklist:

∙ The facility has a process for adjudicating the results of background checks and determining access restrictions in a reasonable manner;

This was undoubtedly added due to the new requirement in the CFATS statute {6 USC 622(d)(2)(A)(iii)(II)} for establishing a redress process. That requirement, however, was specifically targeted at individuals who had been vetted against the terrorist screening database via the ISCD PSP. The way it is implemented in the EAP expands that requirement (legitimately so in my opinion) to include all of the background checks in that redress program.


What is not clear is if ISCD has been ‘requiring’ such a redress program in all of the site security plans that it has been authorizing and/or approving to date. There certainly has not been anything publicly discussed about such a requirement. If not, it will be interesting to see if and how ISCD goes back to the non-EAP facilities with approved SSPs to get such a program put in place for non-PSP background checks.

Tuesday, May 19, 2015

EAP Guidance – Cyber Security

This is part of a continuing series of blog posts on the newly released Expedited Approval Program (EAP) guidance document for Tier 3 and Tier 4 facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in the series are:


In the next couple of posts I’ll be looking at some of the actual security requirements outlined in the new EAP. As a reminder, all of these requirements are based upon the standards set forth in the Risk-Based Performance Standards (RBPS) guidance manual issued six years ago. That document describes considerations to be used in selecting appropriate security measures to fulfill each of the 18 standards outlined in 6 CFR 27.230.

I am going to start with the requirements in the EAP for RBPS #8, Cybersecurity. The main reason that I am starting here, rather than at the more conventional starting point, it that I am also interested in how ISCD is dealing with some of the complicated issues of cybersecurity and the EAP provides a unique opportunity to look at how ISCD would like to see cybersecurity implemented in high-risk chemical facilities.

RBPS #8 Requirements

The regulatory requirements for cybersecurity are spelled out in §27.230(8); Deter cyber sabotage, including by preventing unauthorized onsite or remote access to critical process controls, critical business system, and other sensitive computerized systems. The generic discussion of how this can be done starts on page 71 of the RBPS guidance and the metrics for evaluating security measures can be found starting on page 78. In the EAP guidance document the discussion of cybersecurity measures starts on page 40 and the cybersecurity portion of the site security plan (SSP) template starts on page 82.

The first requirement is to establish what computer systems are covered by the SSP. It must always be remembered that the SSP is focused on protecting the DHS chemicals-of-interest (COI) found on the site. This means that the facility is required to list all of the cyber assets that:

∙ Monitor and/or control physical processes that contain a COI;
∙ Are connected to other systems that manage physical processes that contain a COI; or
∙ Contain business or personal information that, if exploited, could result in the theft, diversion, or sabotage of a COI

Computer systems that deal with security functions like access control, surveillance and alarms are not considered under this RBPS unless they are connected to a computer system described above. They are considered during the discussion of their related security measures.

Cybersecurity Policies

The next area of the cybersecurity portion of the SSP deals with the establishment of cybersecurity policies. These policies must:

∙ Be documented, distributed and maintained with a management of change policy;
∙ Include the designation of a trained and qualified individual(s) to manage cyber security for the facility;
∙ Must require account access control to critical cyber systems utilizing the least privilege concept;
∙ Maintain access control lists, and ensure that accounts with access to critical/sensitive information or processes are modified, deleted, or de-activated in a timely manner;
∙ Establish password management protocols to ensure all default passwords have been changed (where possible), enforce password structures, and implement physical controls for cyber systems where changing default passwords is not technically feasible;
∙ Require physical access to critical cyber assets and media;
∙ Provides for cyber security training to all employees that work with critical cyber assets; and
∙ Require that the facility will report significant cyber incidents to senior management and DHS Industrial Control Systems Cyber Emergency Response Team (ICS-CERT).

Each of the bullet points listed above has its own check-off box on the EAP SSP template. There are no requirements to provide any additional information to ISCD for this area of the SSP. In general this will be true for almost all of the EAP SSP documentation. This will be the last time that I mention this check-off technique, but I will mention where the EAP requires additional information be provided to ISCD beyond the simple check the box.

There is a little more detail in the discussion portion of the EAP guidance on the topics listed above. There are only two that have any additional information of significance; the training requirements for the cybersecurity officer (pg 42) and a discussion about the documentation supporting the requirement to report significant cybersecurity incidents to ICS-CERT (pg 43).

Remote Access

Next there is a very short section on remote access to the cybersecurity assets. It requires that:

∙ The facility defines allowable remote access and rules of behavior.

In the detailed discussion there is also a requirement to capture all remote access activities on system logs.

Control Systems

The next section of the cybersecurity portion of the EAP SSP deals with control systems. For facilities that do not have control systems that impact the security of the COI there is a single box to check-off explaining that fact. The Control System section of the SSP reports that the facility:

∙ Conducts audits that measure compliance with the cyber security policies, plans, and procedures and results are reported to senior management;
∙ Documents the business need and network/system architecture for all cyber assets (systems, applications, services, and external connections);
∙ Disables all unnecessary system elements;
∙ Integrates cyber security into the system lifecycle for all critical cyber assets;
∙ Ensures that service providers and other third parties with responsibilities for cyber systems have appropriate personnel security procedures/practices in place;
∙ Identifies and documents systems boundaries and implements security controls to limit access across those boundaries:
∙ Monitors the critical networks in real-time for unauthorized or malicious access and alerts, recognizes and logs events and incidents;
∙ Has a defined incident response system for cyber incidents;
∙ Has backup power for all critical cyber systems; and
∙ Has continuity of operations plans, IT contingency plans, and/or disaster recovery plans.

Additional requirements documented in the discussion section include:

∙ Audits must be conducted at least every two years;
∙ Additions to cyber systems must be pre-approved by management;
∙ An intrusion detection system must be used.
∙ Cyber incident response must include requirement to contact a person or agency that “is trained to identify, contain, and resolve a cyber intrusion, denial-of-service attack, virus, worm attack, or other cyber incident” (pg 46).

Commentary

It is clear that the EAP guidance for cyber security is pretty much taken directly from the metrics portion of the RBPS guidance manual. As such the EAP does not provide any more specificity than does the RBPS; it does not tell facilities what cybersecurity measures must be put into place.

There are a couple of metrics from the RBPS guidance that are missing from the EAP program. They include:

8.2.1 The facility has identified and documented systems boundaries (i.e., the electronic perimeter) and has implemented security controls to limit access across those boundaries;
8.3.3 IT management, systems administration, and IT security duties are not performed by the same individual. In instances where this is not feasible, appropriate compensating security controls (e.g., administrative controls, such as review and oversight) have been implemented;
8.5.1 The facility has implemented cyber security controls to prevent malicious code from exploiting critical cyber systems, and it applies appropriate software security patches and updates to systems as soon as possible given critical operational and testing requirements;
8.5.5 Facilities with control systems that have SISs have configured the SIS so that they have no unsecured remote access and cannot be compromised through direct connections to the systems managing the processes they monitor. (For Control Systems Only)

There is no explanation given as to why these metrics do not apply to facilities submitting EAP site security plans.

For cybersecurity at least, what the EAP does is to allow a facility to take its best guess at what security measures must be put into place to meet these rather vague requirements and then certify that it has done so. As long as all of the check boxes are marked, DHS will approve the SSP. The process that now takes place during the SSP authorization and approval process will simply be transferred to compliance inspection. The difference will be that DHS will then have the authority to tell the facility what security measures must be put into place to correct any ‘facial deficiencies’ in the implementation of the site security plan {6 USC 622(c)(4)(G)(ii)(I)(aa)}.

A quick look at the RBPS sections of the EAP look to provide a great more detail into what is required of a facility site security plan (I’ll go  into some of the details in later posts). What is different about cybersecurity is that there are fewer established standards that security professionals generally agree are effective at deterring, detecting and delaying a terrorist attack.

I was hoping that ISCD was going to take a better shot at establishing such standards, but it was patently unfair to put that load on this particular organization. While there are some people with computer and even control systems backgrounds within the ranks of the chemical security inspectors, this is patently not a cybersecurity standards setting organization and certainly not one with the control system security expertise to establish ICS standards.


Given the 180 day standard establishment deadline set by Congress, it was foolish to think that ISCD could accomplish more in the cybersecurity realm. They will have to continue on making the system-by-system judgement to determine if the security measures in place meet the vague guidelines. Hopefully, that will be the only part of the EAP guidelines that leaves so much open to interpretation.

Thursday, May 14, 2015

EAP Guidance – SSP Status

This is part of a continuing series of blog posts on the newly released Expedited Approval Program (EAP) guidance document for Tier 3 and Tier 4 facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in the series are:


I have noted in a couple of these blog posts that it has been unclear how a Tier 3 or Tier 4 facility’s SSP status affects their ability to file an SSP under the EAP process. Obviously newly tiered facilities that have not yet submitted an SSP may choose this option. The question really applies to those facilities that have already started the SSP process; either having submitted an SSP or ASP via CSAT, have hand their SSP or ASP authorized by DHS, or even have had their SSP or ASP approved by DHS.

For informational purposes, here is the latest information available for the SSP status of Tier 3 and Tier 4 facilities


SSP Authorized
SSP Approved
Tier 3
93%
70%
Tier 4
87%
51%

I have been told that any Tier 3 or Tier 4 facility, regardless of the status of their SSP are eligible. Specifically I was told that even facilities with an approved SSP can use the EAP process. It is not yet clear how this will all be done; we will have to wait and see what new Chemical Security Assessment Tool (CSAT) applications are provided for the EAP process. It looks like we will see the first one on June 16th; that will be the tool for notification to DHS that a facility intends to apply for an EAP SSP.

What this does mean is that every Tier 3 and Tier 4 CFATS facility owes it to themselves to closely review the EAP guidance and determine if it makes sense to change their current SSP (at whatever stage in the process) to an EAP SSP.


One other thing to take into consideration is that it appears that ISCD is intending to prioritize the compliance inspections of EAP facilities. This makes a great deal of sense since no one in ISCD is actively involved in reviewing the details of the EAP SSP the way that they are during the standard SSP process. In effect, the compliance inspection will be the first time that ISCD has a chance to see how the EAP SSP is implemented at that particular facility.

Wednesday, May 13, 2015

EAP Guidance – The Process

This is part of a continuing series of blog posts on the newly released Expedited Approval Program (EAP) guidance document for Tier 3 and Tier 4 facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in the series are:


In this post I will look at how the guidance document is organized and how it is intended to be used. As I noted earlier this program was mandated by Congress as a means to allow Tier 3 and Tier 4 facilities to have an easier method of determining what security measures meet the Risk Based Performance Standards (RBPS) that are required for all facility site security plans.

Instead of having to determine what security measures might meet the appropriate standards (and then have ISCD inspectors come out and agree or disagree in the SSP authorization/approval process) Congress authorized ISCD to specify minimum security requirements that would meet those standards for Tier 3 and Tier 4 facilities. So, even if a facility decides not to use the EAP process, this document can be used to supplement the RBPS guidance to select appropriate security measures for the standard SSP process.

COI Specific Security Measures

While most security measures apply to all facilities, there are many measures that are only required if a specific category of chemical of interest (COI) is listed on the facilities security vulnerability assessment. Those security measures are clearly marked and the facility is given the option to not use those measures by indicating that the listed COI category is not found on the facility.

Deviations

In establishing these minimum security measures ISCD recognizes that there will be variations in how that measures are applied. They have defined two categories of variations, material deviations and non-material deviations. For many of the security measures specified there will be alternatives that are spelled out in the EAP that can be used to meet that requirement. The introduction to the EAP uses the example of the requirement for an intrusion detection system (IDS); the non-material deviations for that include a listing of different detectors that could be used in such a system.

Anytime that a facility chooses not to use one of the specified security measures that is considered a material deviation from the EAP. Each material deviation must be documented and an explanation given for how an alternative is used to meet the standards specified in the RPBS. This means that the metrics provided in the RBPS guidance document for that particular standard must be referenced with an explanation of how they are being met.

As part of the review process for the EAP SSP submissions, ISCD will closely look at each of the material deviations to determine whether or not the substitute measure meets the RPBS for that particular metric. If it does not, ISCD will notify the facility which material deviations were not adequate and how to correct them.

Planned Measures

A facility does not have to have all listed security measures in place when they submit their EAP SSP. The EAP provides for the use of planned measures to fulfil some requirements. A planned measure must have “a clear timeline for implementation not to exceed twelve (12) months from date of the approval” (pg 9). It is not specifically stated in the EAP, but the 12 months is probably related to the time frame after the approval of a site security plan that a facility should begin to expect a compliance inspection of that SSP by ISCD.

Planned measures have to be specifically identified in the SSP submission. That identification needs to include a description of the systems to be implemented and the time line for that implementation. If a planned measure cannot be met within that 1 year time limit, the measure becomes a material deviation from the RBPS and must be separately justified.

Certification

In addition to completing the EAP SSP documentation the facility owner or operator will also be required to certify that the SSP meets the requirements of 6 USC §622(c)(4)(C). A copy of the certification document is included as Attachment 1 of the EAP guidance document (pg 60).
Approval and Inspection

Once the facility submits the SSP documentation and certification (presumably via the CSAT tool, but that has not been officially announced yet), DHS has 100 days to approve the SSP. The only reasons for disapproval would be if a facility did not acknowledge implementing all of the appropriate security measures for the COI identified at that facility or had submitted inadequate substitute measures for one or more material deviations.

At some point at least 12 months after the site security plan is approved by DHS, the Chemical Security Inspectors from ISCD will visit the facility to conduct a compliance inspection. Theoretically, this could be the first time that the facility was visited by a CSI. In practice almost all facilities currently covered by the CFATS program have been visited by a CSI team at least once. The only possible exceptions are facilities that have been recently added to the program.


If that compliance inspection finds that any of the implemented or planned security measures reported in the SSP are insufficient to meet the requirements for the RBPS, DHS may require additional security measures to be implemented or may decertify the facility.
 
/* Use this with templates/template-twocol.html */