Showing posts with label FAQ. Show all posts
Showing posts with label FAQ. Show all posts

Wednesday, March 13, 2024

Review - PHMSA Publishes Latest Additions to FAQ List – HAZMAT Training

Today, the DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) published a notice I the Federal Register (89 FR 18479-18482) listing the latest additions to their list of frequently asked questions (FAQ). Back in March of 2022, PHMSA began the process of converting existing Letters of Interpretation (LOI) into frequently asked questions of broader interest to the HAZMAT community. This latest tranche of questions deals with hazardous materials safety training in support of the hazardous materials regulations. The second set of questions was published [removed from paywall] in August of 2023.

Solicitation of Public Comments

PHMSA is soliciting public comments on this proposed set of FAQ and responses. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #PHMSA-2021-0109). Comments should be submitted by April 12th, 2024.

Commentary

As I found previously, PHMSA has not apparently published the two previous sets of FAQs on their web site. There are currently two different FAQ lists (here and here). The first was updated in September of last year and the former was updated in 2019, but neither contain the FAQs previously published as part of this initiative. These FAQ’s would fit in very well with the first page of existing FAQs as it has sub-pages for different topics.

 

For more information on this notice, including a list of new FAQ questions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/phmsa-publishes-latest-additions - subscription required.

Friday, August 18, 2023

Review - PHMSA Publishes Next Set of Hazmat FAQs – 8-18-23 – Incident Reporting

Today, DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) published a notice in the Federal Register (88 FR 56702-56705) on “Hazardous Materials: Frequently Asked Questions – Incident Reporting”. This is part of a continuing effort at PHMSA to convert existing Letters of Interpretation into more broadly applicable frequently asked questions (FAQs) that was started [removed from paywall] in March of 2022.

Public Comments

PHMSA is soliciting public comments on this proposed set of FAQ and responses. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #PHMSA-2021-0109). Comments should be submitted by September 18th, 2023.

Commentary

I think that this project of converting existing historical letters of interpretation into broadly applicable FAQ’s is a commendable information sharing effort on the part of PHMSA. The only problem is I am unable to find the FAQ’s from the initial tranche published in the Federal Register by PHMSA in March of 2022 on the PHMSA website. There is a “Hazardous Materials Safety FAQs” page, but it was last updated on August 23, 2019 and contains none of the questions proposed in the earlier notice.

If PHMSA is going to continue with this program, each subsequent notice in the Federal Register should contain a link to the web site where PHMSA is going to make these FAQ’s and responses readily available to the public. And to be fair, this notice should be updated with that link.

I will be posting this commentary as a comment on this notice.

 

For more details about this notice, including a list of the proposed FAQ’s, see my article at CFSN Detailed Analysis - https://open.substack.com/pub/patrickcoyle/p/phmsa-publishes-next-set-of-hazmat - subscription required.

Friday, February 17, 2023

OCS Publishes 2 New FAQs and 3 Updated FAQ Responses – 2-17-23

Today, CISA’s Office of Chemical Security (OCS) published two new frequently asked questions (FAQs) and updated the responses to three other FAQs on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The three revised FAQ responses were for FAQs, #1275, #1557 and #1756; the first deals with facility ID changes, the second addresses Tier assignment appeals, and the third is about owner name changes. In all three cases, the change to each of the responses was to reverse the recent change in mailing addresses. The current address for all three FAQs is:

Chemical Security, Associate Director

CISA – CHR STOP 0609

Cybersecurity and Infrastructure Security Agency

1310 N. Courthouse Rd.

Arlington, VA 20598-0609


NOTE: Corrected the date in the title at 10:02 pm EST 2-17-23 

Thursday, February 16, 2023

Review – OCS Publishes 2 New FAQs and 3 Updated FAQ Responses – 2-16-23

Today, CISA’s Office of Chemical Security (OCS) published two new frequently asked questions (FAQs) and updated the responses to three other FAQs on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The two new FAQs were #1799 and #1800; one was related to restoring CSAT access issues and the other to Top Screen issues. The three revised FAQ responses were for FAQs, #641, #1275, and #1756; the first deals with Top Screen issues, the second is about facility ID changes, the third about owner name changes.

 

For more details about these new FAQs and revised FAQ responses, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ocs-publishes-2-new-faqs-and-3-updated - subscription required.

Wednesday, February 15, 2023

Review – OCS Publishes 2 New FAQs and Updates 2 FAQ Responses – 2-15-23

Today, CISA’s Office of Chemical Security (OCS) published two new frequently asked questions (FAQs) and updated the responses to two other FAQs on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The two new FAQs were #1797 and #1798, both were related to Top Screen issues. The two revised FAQ responses were for FAQs #641 and 1593, the first deals with Chemical-Terrorism Vulnerability Information (CVI) and the second deals with Top Screen issues.

 

For more details about the new FAQs and the revisions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ocs-publishes-2-new-faqs-and-updates - subscription required.

Wednesday, January 11, 2023

OCS Updates FAQ Response – 1-11-23

Today, CISA’s Office of Chemical Security updated a frequently asked question (FAQ) response on their Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The revision expanded on the information provided to FAQ #1392:

FAQ #1392 How do I transfer my account or reassign my user role?

NOTE: The link provided for the FAQ in this post was copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ, you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The new information addresses the situation where Authorizer (the person who would have to initiate any changes in user roles) is no longer with the company. The short answer is have the person who would be the new Authorizer contact the CSAT Help Desk (1-866-323-2957).

Thursday, June 16, 2022

OCS Updates CFATS FAQ – 6-15-22

Yesterday, CISA’s Office of Chemical Security (OCS) updated the responses to one of the Frequently Asked Questions (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The revision updates a URL used in the response to FAQ #1738 to provide information on the CFATS Expedited Approval Program:

FAQ #1738 What is the difference between the Expedited Approval Program (EAP) and the Chemical Facility Anti-Terrorism Standards (CFATS) program?

NOTE: The link provided for the FAQ in this post was copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ, you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The new version of the FAQ provides a ‘new’ link to the CFATS Expedited Approval Program (EAP) page. The last time that I looked at this page it had an August 14th, 2018 ‘last published date’ marked on the page. There is no date on the current page (CISA very seldom provides dates for their web site pages). The only change on that newer page is the address to be used for the notification letter:

Chemical Security, Associate Director

CISA – CHR STOP 0609

Cybersecurity and Infrastructure Security Agency

1310 N. Courthouse Rd.

Arlington, VA 20598-0609

That address was added to unrelated FAQs, in February 2021, so the new EAP page probably dates from about the same time.

Saturday, June 11, 2022

PHMSA Publishes FAQ Meeting Notice – 6-27-22

DOT’s Pipeline and Hazardous Materials Safety Administration published a notice in Monday’s (available on line today) Federal Register (87 FR 35874-35849) for a public informational webinar on “Hazardous Materials: Frequently Asked Questions--Applicability of the Hazardous Materials Regulations”. That notice also extends the comment period on the associated request for comments on PHMSA’s “initiative to convert historical letters of interpretation (LOI) applicable to the Hazardous Materials Regulations that have been issued to specific stakeholders into broadly applicable frequently asked questions on its website.”

The public webinar will be held on June 27th, 2022 at 11:00 am EST. Personnel wishing to participate need to register at the meeting website at https://opsweb.phmsa.dot.gov/​hm_​seminars/​faq_​webinar.asp.

The RFI comment deadline was extended from May 23rd to July 22nd, 2022. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2021-0109, Notice No. 2022-10).

Tuesday, March 22, 2022

Review - PHMSA to Establish FAQs for HMR

Today, DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) published a notice in the Federal Register (87 FR 16308-16310) requesting comments on “Hazardous Materials: Frequently Asked Questions--Applicability of the Hazardous Material Regulations.” It announces the intention of PHMSA to establish “an initiative to convert historical letters of interpretation (LOI) applicable to the Hazardous Materials Regulations that have been issued to specific stakeholders into broadly applicable frequently asked questions on its website.”

Initial FAQs

In this Notice, PHMSA is proposing to publish the following FAQs related to 49 CFR 171.1, Applicability of Hazardous Materials Regulations to Persons and Functions (the responses follow the question in the Notice):

(1) Question: Is a Federal, state, or local government agency subject to the HMR?

(2) Question: Are state universities subject to the HMR when transporting hazardous materials?

(3) Question: Is a hazardous material transported on private roads subject to the HMR?

(4) Question: Is a hazardous material subject to the HMR that only crosses a public road?

(5) Question: Are hazardous materials installed or used in or on a motor vehicle ( e.g., gasoline in the motor vehicle's fuel tank) subject to the HMR?

(6) Question: Is the filling of a package with a hazardous material subject to the HMR if it is not being offered for transportation in commerce?

(7) Question: Are stationary (storage) tanks containing a hazardous material such as propane subject to the HMR?

(8) Question: Are hazardous materials being transported for personal use subject to the HMR?

(9) Question: Are privately-owned SCUBA tanks that are used for diving and marked as DOT specification cylinders subject to the HMR?

(10) Question: Are government-owned hazardous materials transported for government purposes by contractor personnel subject to the HMR?

(11) Question: Are gasoline cans transported by a landscaping company by motor vehicle subject to the HMR?

(12) Question: Are household hazardous wastes that are transported by a private person to a county drop-off facility subject to the HMR?

Solicitation of Public Comments

PHMSA is soliciting public comments on this initiative. They are looking for comments on potential benefits that could be seen as a result of this program, and suggestions for future FAQ topics.

Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2021-0109). Comments should be submitted by May 23rd, 2022.

For more information on the LOI process and new FAQ initiative, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/phmsa-to-establish-faqs-for-hmr - subscription required.

Thursday, January 13, 2022

OCS Updates CFATS FAQ – 1-13-22

Today, CISA’s Office of Chemical Security (OCS) updated the responses to one of the Frequently Asked Questions (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The revision updates the civil penalty that may be assessed under the CFATS program.

The FAQ is # 1554 - Does the Cybersecurity and Infrastructure Security Agency (CISA) have enforcement authority to fine noncompliant facilities, to include shutting down a facility?

NOTE: The link provided for the FAQ in this post was copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ, you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The new version of the FAQ response lists the maximum fine that the Department may assess as $38,139 for each day the violation continues. This is an increase from the $35,486 quoted in the previous version of the FAQ response. This was increased by a DHS final rule published on January 11th, 2022. The CISA portion of that rule set the new maximum level for the CFATS program.

Wednesday, February 17, 2021

ISCD Updates 5 FAQ Responses – 2-16-21

Yesterday the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to five frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page. The same substantive change was made in each case.

The following FAQ responses were revised:

FAQ #1275 What needs to be done with the facility ID in the Chemical Security Assessment Tool (CSAT) when a covered chemical facility is bought or sold?

FAQ #1557 What should a facility do if it believes the risk-based tier determination that the Cybersecurity and Infrastructure Security Agency (CISA) has assigned it no longer reflects the actual security risk posed to the facility?

FAQ #1620 How does an individual report a possible security concern involving the Chemical Facility Anti-Terrorism Standards (CFATS) regulation at one’s facility or another facility?

FAQ #1666 Does a covered chemical facility have an obligation to notify the Cybersecurity and Infrastructure Security Agency (CISA) if the facility is closing?

FAQ #1756 What action is required if a facility needs to change owner and/or operator names when it is not related to a transfer of ownership?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The same change was made in each of the five responses, a complete change in the snail mail address for CFATS notifications. The new address is:

Chemical Security, Associate Director

CISA – CHR STOP 0609

Cybersecurity and Infrastructure Security Agency

1310 N. Courthouse Rd.

Arlington, VA 20598-0609

Interestingly, these five FAQ responses were all changed in a similar way last December.

Monday, December 21, 2020

ISCD Updates 5 FAQ Responses – 12-21-20

Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to five frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page. The same substantive change was made in each case.

The following FAQ responses were revised:

FAQ #1275 What needs to be done with the facility ID in the Chemical Security Assessment Tool (CSAT) when a covered chemical facility is bought or sold?

FAQ #1557 What should a facility do if it believes the risk-based tier determination that the Cybersecurity and Infrastructure Security Agency (CISA) has assigned it no longer reflects the actual security risk posed to the facility?

FAQ #1620 How does an individual report a possible security concern involving the Chemical Facility Anti-Terrorism Standards (CFATS) regulation at one’s facility or another facility?

FAQ #1666 Does a covered chemical facility have an obligation to notify the Cybersecurity and Infrastructure Security Agency (CISA) if the facility is closing?

FAQ #1756 What action is required if a facility needs to change owner and/or operator names when it is not related to a transfer of ownership?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The same change was made in each of the five responses, a complete change in the snail mail address for CFATS notifications. The new address is:

Chemical Security, Associate Director

CISA – SCS STOP 0390

Cybersecurity and Infrastructure Security Agency

1401 South Clark St.

Arlington, VA 20598-0390

Friday, December 4, 2020

ISCD Updates 1 FAQ Response – 12-4-20

Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to seven frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page. There was a minor change in administrative procedures made.

The following FAQ response was revised:

FAQ #1275 What needs to be done with the facility ID in the Chemical Security Assessment Tool (CSAT) when a covered chemical facility is bought or sold?

NOTE: The link provided for the FAQ in this post was copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

#1275 Minor administrative procedural change – In last paragraph added option to email or surface mail letters to ISCD where only the Fax option was included in the earlier version.

Wednesday, November 25, 2020

ISCD Updates 7 FAQ Responses – 11-24-20

Yesterday the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to seven frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page. The changes were non-substantive editorial revisions.

The following FAQ responses were revised:

FAQ #1653 If a facility is in a location where another entity provides certain security measures (e.g., industrial park, co-located facility, office park, etc.), can the facility include these security measures as part of its Security Vulnerability Assessment (SVA)/Site Security Plan (SSP)?

FAQ #1724 How do National Terrorism Advisory System (NTAS) Alerts and Bulletins affect a CFATS facility’s RBPS 13 compliance responsibilities?

FAQ #1769 My facility must perform background checks in accordance with the Risk-Based Performance Standard (RBPS) 12 Personnel Surety on affected individuals. Who is an affected individual?

FAQ #1770 How will the Cybersecurity and Infrastructure Security Agency (CISA) protect the data it collects? Can Chemical-terrorism Vulnerability Information (CVI) be released under the Freedom of Information Act (FOIA)?

FAQ #1782 Are there any facilities statutorily excluded from the Chemical Facility Anti-Terrorism Standards (CFATS) regulation?

FAQ #1785 How does the Cybersecurity and Infrastructure Security Agency (CISA) notify a facility of its tiering?

FAQ #1793 When does a covered facility under the Chemical Facility Anti-Terrorism Standards (CFATS) program need to submit a revised or updated Top-Screen?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

#1653 Editorial change in answer – Replaced “;” with “,” between “located facility” and “office park”,

#1724 Editorial change in answer – Replaced “;” with “,” between “public safety” and “and recommended” in first paragraph,

#1769 Editorial change in question and answer – Removed “-“ between “(RBPS)” and “12”,

#1770 Editorial changes in answer – Removed unnecessary “ after “CFR § 27.400(d)"” and added space in “6 CFR §§ 27.300and 27.400(j)”,

#1782 Editorial change in question – Moved “(CFATS)” from behind “regulations” to behind “Standards”,

#1785 Editorial change in answer – Removed extra “.” After “(CFATS) regulation” in first paragraph,

#1793 Editorial change in answer – Added “,” after “every two years” in paragraph 2.

Friday, November 20, 2020

ISCD Updates 5 FAQ Responses – 11-20-20

Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to 5 frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page. The changes were non-substantive editorial revisions.

The following FAQ responses were revised:

FAQ #1771 What documentation will I be asked to provide or make available for the Chemical Security Inspector during an Expedited Approval Program (EAP) Compliance Inspection (CI)?

FAQ #1772 Who will conduct the Chemical Facility Anti-Terrorism Standards (CFATS) Compliance Inspections for facilities in the Expedited Approval Program (EAP)?

FAQ #1773 Solid ammonium nitrate in the chemicals of interest (COI) column of Appendix A is listed as “Ammonium nitrate, solid [nitrogen concentration of 23% nitrogen or greater]” and has a minimum concentration of 33% under the Theft/Diversion security issue. In calculating whether a facility has a screening threshold quantity (STQ) of solid ammonium nitrate in a mixture, does the facility look at the percentage of the nitrogen in the mixture or the percentage of the ammonium nitrate in the mixture?

FAQ #1777 How do I determine “need to know” under Chemical-terrorism Vulnerability Information (CVI)?

FAQ #1782 Are there any facilities statutorily excluded from the Chemical Facility Anti-Terrorism Standards regulation (CFATS)?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

#1771 Editorial change in answer – Replaced “compliance inspection” with “CI”,

#1772 Editorial change in answer – Added “(CISA)” after “Cybersecurity and Infrastructure Security Agency”,

#1773 Editorial change in answer – Changed “6 C.F.R. §” to read “6 CFR §”,

#1777 No apparent change,

#1782 Editorial change in question – Changed “CFATS?” to read “the Chemical Facility Anti-Terrorism Standards regulation (CFATS)?”

Wednesday, November 18, 2020

ISCD Updates 5 FAQ Responses – 11-17-20

Yesterday the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to 15 frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page. The changes were non-substantive editorial revisions.

The following FAQ responses were revised:

FAQ #1405 How will I know if the agricultural extension has been lifted and what to do next?

FAQ #1620 How does an individual report a possible security concern involving the Chemical Facility Anti-Terrorism Standards (CFATS) regulation at one’s facility or another facility?

FAQ #1756 What action is required if a facility needs to change owner and/or operator names when it is not related to a transfer of ownership?

FAQ #1768 When will the Cybersecurity and Infrastructure Security Agency (CISA) grant access to the Chemical Security Assessment Tool (CSAT) Personnel Surety Program application if a facility chooses to meet Risk-Based Performance Standard (RBPS) 12(iv) by selecting Option 1 or Option 2 in its Site Security Plan (SSP)/Alternative Security Program (ASP)?

FAQ #1769 My facility must perform background checks in accordance with the Risk-Based Performance Standard (RBPS) 12 - “Personnel Surety” on affected individuals. Who is an affected individual?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

#1405 Change to URL for DHS updates page, old URL goes to new site,

#1620 No apparent changes,

#1756 Editorial change in answer – Changed “Office of Chemical Security” to “Chemical Security” in snail-mail address,

#1768 Editorial change in answer – Changed “Department” to “Agency”,

#1769 Editorial change in question and answer – Removed hyphen from “(RBPS) 12 – ‘Personnel Surety’” in both.

Wednesday, November 11, 2020

ISCD Updates 15 FAQ Responses – 11-11-20

Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to 15 frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page.

The following FAQ responses were revised:

FAQ #1275 What needs to be done with the facility ID in the Chemical Security Assessment Tool (CSAT) when a covered chemical facility is bought or sold?

FAQ #1481 What factors does a facility need to account for when calculating whether a facility possesses the screening threshold quantity (STQ) for a theft/diversion chemical of interest (COI)?

FAQ #1489 Can a covered facility have contractors or lawyers fill out their Security Vulnerability Assessment (SVA)/Site Security Plan (SSP)?

FAQ #1490 Must all employees involved in filling out the Top-Screen, Security Vulnerability Assessment (SVA), or Site Security Plan (SSP) at my facility be Chemical-terrorism Vulnerability Information (CVI) Authorized Users?

FAQ #1554 Does the Cybersecurity and Infrastructure Security Agency (CISA) have enforcement authority to fine noncompliant facilities, to include shutting down a facility?

FAQ #1620 How does an individual report a possible security concern involving the Chemical Facility Anti-Terrorism Standards (CFATS) regulation at one’s facility or another facility?

FAQ #1633 What is a proposed measure and why would a facility include one in their Site Security Plan (SSP)?

FAQ #1635 The Risk-Based Performance Standards (RBPS) for "Shipping, Receipt and Storage" (RBPS 5) and for "Theft and Diversion" (RBPS 6) in the Chemical Facility Anti-Terrorism Standards (CFATS) regulation (6 CFR §§ 27.230(a)(5) and (a)(6)) refer to "hazardous materials" and to "dangerous chemicals," respectively. Do those terms include any chemicals other than chemicals of interest (COI) listed in Appendix A of the CFATS regulation?

FAQ #1653 If a facility is in a location where another entity provides certain security measures (e.g., industrial park, co-located facility: office park, etc.), can the facility include these security measures as part of its Security Vulnerability Assessment (SVA)/Site Security Plan (SSP)?

FAQ #1724 How do National Terrorism Advisory System (NTAS) Alerts and Bulletins affect a CFATS facility’s RBPS 13 compliance responsibilities?

FAQ #1735 How can a corporation with multiple facilities regulated under the Chemical Facility Anti-Terrorism Standards (CFATS) request the corporate approach and what benefits does this provide the corporation?

FAQ #1738 What is the difference between the Expedited Approval Program (EAP) and the Chemical Facility Anti-Terrorism Standards (CFATS) program?

FAQ #1745 If a facility has submitted a Site Security Plan (SSP) or an Alternative Security Program (ASP) in lieu of an SSP, but does not yet have approval, can it still be part of the Expedited Approval Program (EAP)?

FAQ #1750 What happens after I submit my Expedited Approval Program Site Security Plan (EAP SSP)?

FAQ #1751 If my facility has been issued a “letter of acceptance” through the Expedited Approval Program (EAP), but then the Cybersecurity and Infrastructure Security Agency (CISA) discovers that the measures in the Site Security Plan (SSP) insufficiently meet the risk-based performance standards (RBPS) during a Compliance Inspection, what happens?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

#1275 Editorial change to address – Changed ‘Chemical Security’ to ‘Office of Chemical Security’,

#1481 Editorial change to Question – Added ‘?’ at the end of the question,

#1489 Editorial change to Answer – Changed ‘(high risk)’ to ‘(high-risk)’,

#1490 Editorial change to Answer – In first paragraph changed ‘with regards to the SVA development’ to read ‘with regards to the development of the facility's Top-Screen, SVA, or SSP’,

#1554 Editorial change to Answer – In first paragraph changed ‘specified time frame’ to read ‘specified timeframe’,

#1620 Editorial change to Answer – In second paragraph changed type on email address to BOLD,

#1633 Editorial change to Answer – Added period at the end of each sentence in the subparagraphs,

#1635 Editorial change to Question – Changed ‘Risk-based’ to ‘Risk-Based’,

#1653 No apparent change,

#1724 Editorial change to Answer – In first paragraph changed ‘businesses and governments’ to read ‘businesses, and governments’,

#1735 Editorial change to Answer – In second paragraph changed ‘Chief of Regulatory Compliance’ to ‘Chief of Chemical Security’,

#1738 Editorial change to Answer – Changed ‘meets the applicable’ to read ‘meet the applicable’,

#1745 No apparent change,

#1750 Editorial change to Answer – In second paragraph changed ‘if DHS fails’ to read ‘if CISA fails’,

#1751 Editorial change to Question – Changed ‘Cyber Infrastructure Security Agency (CISA)’ to “Cybersecurity Infrastructure Security Agency (CISA).

Monday, November 9, 2020

ISCD Updates 4 FAQ Responses – 11-9-20

Today the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to two frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page.

The following FAQ responses were revised:

FAQ #81 How do I register for the Chemical Security Assessment Tool (CSAT)?

FAQ #1194 Are facilities, particularly colleges and universities, able to avoid reporting certain chemical(s) of interest (COI) in their Top-Screen?

FAQ #1228 How is the screening threshold quantity (STQ) calculated for ammonium nitrate (AN) [with more than 0.2 percent combustible substance, including any organic substance calculated as carbon, to the exclusion of any other added substance]?

FAQ #1274 How can a person contact the Chemical Security Assessment Tool (CSAT) Help Desk?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

FAQ #81 Editorial substitution of ‘follow’ for ‘following’ in first sentence,

FAQ #1194 Editorial addition of ‘)’ after first CFR site,

FAQ #1228 Editorial removal of second ‘.’ after “5,000 pounds” in second paragraph, and

FAQ #1274 No apparent change except for date.

Wednesday, October 14, 2020

ISCD Updates 2 FAQ Responses – 10-13-20

Yesterday the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to two frequently asked questions (FAQs) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page.

The following FAQ responses were revised:

FAQ #1770 How will the Cybersecurity and Infrastructure Security Agency (CISA) protect the data it collects? Can Chemical-terrorism Vulnerability Information (CVI) be released under the Freedom of Information Act (FOIA)?

FAQ #1784 Does a facility have to count theft/diversion chemicals of interest (COI) in transportation packaging towards the screening threshold quantity (STQ) if the COI is on or attached to motive power, to include an overnight stay?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced responses:

#1770 Complete rewrite of FAQ and response, but no change in policy or procedure.

#1784 Provides links to regulation and Federal Register cites.

For reference purposes, here is what the language of FAQ 1770 and its response read before yesterday’s changes:

Question: Can Chemical-terrorism Vulnerability Information (CVI) be released under the Freedom of Information Act (FOIA)? 

Answer: No. Notwithstanding the Freedom of Information Act or FOIA (5 U.S.C. 552), the Privacy Act (5 U.S.C.552a), and other laws, in accordance with the Homeland Security Act as amended by the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014, Public Law 113-254, and 6 C.F.R. § 27.400(g), records containing CVI are not available for public inspection or copying, and the Department does not release such records to persons without a need to know.

Further, as provided in 6 C.F.R. § 27.405, no law, regulation, or administrative action of a State or political subdivision thereof shall have any effect if such law or regulation conflicts with the Chemical Facility Anti-Terrorism Standards (CFATS). Requests for CVI under State or local FOIA or open records laws should be referred to the DHS National Protection and Programs Directorate (NPPD) Information Management and Disclosure Office, NPPD.FOIA@hq.dhs.gov.

If a record contains both information that may not be disclosed under Public Law 113-254 and information that may be disclosed, the latter information may be provided in response to a FOIA request, provided that the record is not otherwise exempt from disclosure under FOIA and that it is practical to redact the protected CVI from the requested record.

Note: Please refer to the “Safeguarding Information Designated as Chemical-terrorism Vulnerability Information (CVI) Handbook” for more information. The Handbook is available at https://www.dhs.gov/publication/safeguardinginformation-cvi-manual.

Saturday, October 10, 2020

ISCD Updates 1 FAQ Response – 10-9-20

Yesterday the CISA Infrastructure Security Compliance Division (ISCD) updated the responses to one frequently asked question (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center web page. None of the changes were substantive nor did they reflect policy changes.

The following FAQ response was revised:

FAQ #1785 How does the Cybersecurity and Infrastructure Security Agency (CISA) notify a facility of its tiering?

NOTE: The links provided for the FAQs in this post were copied from the CFATS Knowledge Center but may not work when followed from your machine. This is an artifact of that web site. If the links do not take you to the referenced FAQ you will have to use the ‘Advanced Search’ function on the page to link to the FAQ or download the ‘All FAQs’ document at the bottom of the ‘Advanced Search’ page.

The following changes were made in the referenced response:

#1785 Replace ‘DHS’ with ‘CISA’, added regulatory links and replaced URLs with links.

 
/* Use this with templates/template-twocol.html */