Showing posts with label ISCD. Show all posts
Showing posts with label ISCD. Show all posts

Thursday, October 4, 2018

ISCD Publishes CFATS Update – 10-03-18


Yesterday the DHS Infrastructure Security Compliance Division (ISCD) published their monthly The number of facilities in the program continued the slight increase we saw in the previous month and there is continued, long-term improvement in the number of facilities with approved site security update of the Chemical Facility Anti-Terrorism Standards (CFATS) implementation statistics. plans.

Facility Status


The table below shows the reported status of facilities covered under the CFATS program. The decline in the number of Tiered and Authorized facilities continues to reflect the expected movement of facilities through the SSP submission and approval process.

CFATS Facility Status
Jul-18
Aug-18
Sep-18
Tiered
213
218
211
Authorized
618
562
493
Approved
2531
2586
2665
Total
3362
3366
3369

ISCD Activities


The table below shows the reported activities that the DHS chemical security inspectors (CSI) from ISCD undertook in the support of the CFATS program in September.

CFATS Activities
Jul-18
Aug-18
Sep- 18
Authorization Inspections to Date
3768
3822
3854
Authorization Inspections Month
44
68
35
Compliance Inspections to Date
3752
3819
3891
Compliance Inspections Month
59
78
71
Compliance Assistance Visits to Date
4598
4749
4897
Compliance Assistance Visits Month
103
158
126

It is hard to judge the fluctuations in the number of activities undertaken by CSI. Each facility is different and would be expected to require differing amounts of time and number of inspectors involved to complete the reported inspections or visits. Additionally, ISCD does not report on the different types of training activities that its personnel require, nor does this report show changes in the number of CSI employed by the program.


Thursday, July 19, 2018

ISCD Publishes CFATS Quarterly – July 2018


Today the DHS Infrastructure Security Compliance Division (ISCD) published the latest version of their Chemical Facility Anti-Terrorism Standards (CFATS) Quarterly. It was announced on the CFATS Knowledge Center with the link provided about half-way through the ‘CFATS Quarterlies and Webinars’ section at the bottom of the page.

This periodic document provides information on what has been going on in the CFATS program. Most of the news is about publications that have been made available to help facilities manage their CFATS process; nothing new here that I have not already covered.

In fact, the only really new piece of information is that David Wulf has finally returned to his job as Director of ISCD after having spent the last 18 months as Acting Deputy Assistant Secretary for Infrastructure Protection. This is the second time that Dave has filled this temporary position during the start of a new administration.

Friday, May 4, 2018

DHS Chemical Security Talks


As part of their revamp of the Chemical Facility Anti-Terrorism Standards (CFATS) web site earlier this week the DHS Infrastructure Security Compliance Division (ISCD) published an announcement on the new CFATS landing page about a set of regional meetings that they would be conducting on chemical security issues.

The information currently available is a little vague; just that there will be three regional (east, west and middle) events that would cover:

Chemical security regulations, including Chemical Facility Anti-Terrorism Standards (CFATS)updates
• Cyber security trends
• Security roles during a disaster
• Local resources

The dates, locations and other details will be made available at some later date.

BTW: The new CFATS landing page was updated yesterday to include a section on the CFATS Knowledge Center and contact information for the CFATS Help Desk. Good moves.

Wednesday, April 11, 2018

ISCD Publishes Propane Fact Sheet


Today the DHS Infrastructure Security Compliance Division (ISCD) published a fact sheet about how propane is treated under the Chemical Facility Anti-Terrorism Standards (CFATS) program. It would appear that this fact sheet is yet another effort in the CFATS outreach program.

This is a one-page fact sheet (as opposed to the two-page sheets that address industry groups) so the amount of information that is provided is somewhat limited. Fortunately for DHS, the internet provides a way to pack a great deal of information into that one page via links to various information sources.

Propane Concentration


There is one link to an often over looked piece of information related to propane, the Federal Register notice outlining the special status of propane when looking at the mixture rule. Appendix A clearly states that the ‘Minimum Concentration’ for propane is 1%, the same as all other flammable release DHS chemical of interest (COI). But, the Federal Register Notice from March 21, 2008 clearly states that:

“Since DHS intends the COI propane to refer to products containing at least 87.5 percent of propane, as well as other release-flammable COI, it follows that the release-flammable mixtures rule does not apply to such products. In fact, it would not make sense to apply the release-flammable mixtures rule to the combination of chemicals that constitute the COI propane because that would largely negate the intended effect of the 60,000 pound STQ and the special STQ counting rule for the COI propane.[6] By contrast, the release- flammable mixtures rule does apply to products that are a combination of less than 87.5 percent propane and other release-flammable COI, since such mixtures are not themselves the COI propane.”

This oddity means that if you have 60,000 lbs of a commercial product that is only 87.4% propane and 13.6% butane, then the standard 1% mixture rule would be in effect and both propane and butane would have to be reported on a Top Screen at 60,000 lbs. If the product were stored at less than 60,000 lbs but more than 10,000 lbs (the STQ for butane), then only butane would have to be reported on the Top Screen as the total amount stored. But, again with ‘standard commercial propane’, only the propane has to be reported on the Top Screen.

Another Propane Oddity


There is one odd piece of information that is not directly referenced in the fact sheet, the odd way that propane STQ is calculated. For any other flammable release DHS chemical of interest, the STQ is calculated by adding up the total amount of the COI that is stored on the facility or used in processes at the facility. For propane, in another move to appease the agricultural community, only propane that is stored in tanks containing more than 10,000-lbs needs to be counted towards the 60,000-lb STQ.

CFATS Outreach


One thing that is not clear from the publication of these outreach fact sheets on the CFATS Knowledge Center is how ISCD expects these fact sheets to get to the facilities that are not presently covered under the CFATS program but probably would be if they submitted a Top Screen. This is, after all, the whole purpose of the outreach program; get the word out to facilities that are required to submit a Top Screen.

For the industry fact sheets, I would suspect that ISCD is counting on (and has almost certainly asked) the various professional organizations that support the covered industries to forward the fact sheet to their members. While the same technique may be used here I would guess that ISCD is going to request that covered CFATS facilities that ship propane forward this fact sheet to their customers that hold inventories over 60,000-lbs in 10,000-lb or greater tanks.

There is an easier way to conduct this outreach effort, ISCD could always require facilities that ship COI in greater than STQ quantities to provide ISCD with a list of those customers. Then ISCD could directly contact the facilities that have not yet submitted Top Screens and require them to do so under 6 CFR 27.200(b). The authority to request a list of customers is already provided in 27.200(a):

“… the Secretary may, at any time, request information from chemical facilities that may reflect potential consequences of or vulnerabilities to a terrorist attack or incident, including questions specifically related to the nature of the business and activities conducted at the facility; information concerning the names, nature, conditions of storage, quantities, volumes, properties, customers, major uses, and other pertinent information about specific chemicals or chemicals meeting a specific criterion….” [emphasis added]

The fact that ISCD has, as of yet, not decided to take this rather drastic step is probably a matter of consideration of the business needs of the current CFATS facilities. It is, however, just a matter of time if we continue to see chemical release incidents at facilities that were, in retrospect, obviously required to submit Top Screens. Congress can politically withstand only so many West Fertilizer type incidents with ISCD saying; “Nope, never heard of them.”

Thursday, March 8, 2018

ISCD Updates CFATS Landing Page and CSAT 2.0 Manual


Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated the Chemical Facility Anti-Terrorism Standards (CFATS) program landing page. Most of the changes are related to providing links to the recently issued fact sheets that have been previously discussed here. The one major change is that links have been provided to a new version of the Chemical Security Assessment Tool (CSAT) 2.0 user manual. The manual is dated February 28th, 2018, but the page linking to it is dated March 5th, 2018. The last time that I noticed a change to this manual was in March of last year.

Unfortunately, ISCD has long since stopped putting management of change information about the new versions of their manuals and have even stopped assigning version numbers. This certainly complicates things for users (and reviewers) of these manuals. Doing a detailed review of the two Table of Contents it does not appear that there were any significant changes made in the latest version of this manual. Having said that, CFATS covered facilities will want to have the latest version on hand and I would keep an historical copy of the version that was used the last time that I made changes to any CFATS submission document.

NOTE 1: We are now a full week into March and ISCD has still not updated their CFATS Monthly Status page.



NOTE 2: Earlier this month DHS added a “Critical Infrastructure: Chemical Security News & Updates” section to the bottom of the CFATS landing page. This section provides links to newsworthy events in DHS that have some sort of relevance to chemical security. This has been seen on other DHS web sites.

Friday, February 16, 2018

ISCD Publishes Two More Industry Outreach Fact Sheets


Today the DHS Infrastructure Security Compliance Division (ISCD) published links to two new fact sheets on their Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The first is another in the recent series explaining the impact of the CFATS program on various industries; this one addresses laboratories. This is part of the ongoing ISCD outreach effort designed to connect with facilities that have not realized that they may be covered under the CFATS program. The second fact sheet outlines the first steps that a facility needs to take when it determines that it may be affected by the CFATS program.

Laboratory Outreach


This fact sheet is very similar in format and information to the ones that I have previously discussed. The major difference is that the list of potentially affected chemicals is significantly different. One major difference in the list is that it includes a wide variety of chemical warfare agents. Unfortunately, ISCD failed to address the most contentious issue associated with those chemicals; the incredibly small amount (100-g) that qualifies as a screening threshold quantity (STQ) that would require reporting under CFATS.

First Steps


This fact sheet outlines the initial steps that a chemical facility needs to take when it suspects that it may be covered by the CFATS regulations (6 CFR 27), culminating in the submission of a Top Screen. The steps outlined include:

• Check your chemicals of interest (COI);
• Complete Chemical-terrorism Vulnerability Information (CVI) training;
• Register your facility; and
Submit a Top Screen

As you would expect from a ‘fact sheet’ the explanations provided for each of the steps are very brief and lacking in detail. Fortunately, links are provided to the appropriate parts of the CFATS web site for a more detailed explanation.

Commentary


There is one unusual comment in the first steps fact sheet that I do not recall having seen in any other ISCD publication to date. In the discussion of what constitutes a chemical facility under the CFATS regulations, the fact sheet notes that:

“Under CFATS, a chemical facility is any establishment, from a large facility to an individual person [emphasis added] which possesses or plans to possess at any point in time, certain COI at or above a specified quantity or concentration.”

The definition of ‘chemical facility’ under the CFATS regulations states that {§27.105}:

“Chemical Facility or facility shall mean any establishment [emphasis added] that possesses or plans to possess, at any relevant point in time, a quantity of a chemical substance determined by the Secretary to be potentially dangerous or that meets other risk-related criteria identified by the Department.”

That ‘any establishment’ term is undefined, and I suppose that it could be stretched to include an ‘individual person’. At the very least I would expect to hear some arguments from lawyers if ISCD attempted to push regulatory activity down to a personally owned laboratory not associated with a business.

Having said that, it is not beyond the bounds of possibility that there could exist personal labs (particularly in the biological, pharmaceutical or agricultural sectors) where COI could be found at or above the STQ. The fact that that such laboratories would generally be expected to have less security than a similar corporate lab or even an academic lab would be of potential concern to ISCD as a possible terrorist target.

I am not sure how ISCD would locate such labs in order to conduct outreach activities. I suspect that the most common way of identifying such labs would be as the result of investigations of chemical releases or other chemical incidents by local authorities. If it was a purely local investigation (not the CSB, EPA, or OSHA for instance), I doubt that the word would get back to ISCD.

Thursday, February 8, 2018

ISCD Publishes Truck Terminal FAQ


Today the DHS Infrastructure Security Compliance Division (ISCD) published a new frequently asked question (FAQ) on their Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center page. The new FAQ (#1789) addresses the definition of ‘truck terminals’ as they relate to coverage under the CFATS program.

On November 20th, 2007 DHS published the final rule establishing Appendix A to 6 CFR 27. In the preamble to that rule DHS stated: “DHS presently does not plan to screen truck terminals for inclusion in the Section 550 regulatory program [the earlier legislative basis for the CFATS program], and therefore DHS will not request that owners and operators of truck terminals complete the Top-Screen risk assessment methodology.”

FAQ #1789 states that:

“Truck terminals, for the purposes of CFATS, are facilities which serve as a temporary waypoint in the transportation system between a shipment’s point of origin and final destination. While at a truck terminal, the freight remains in its original shipping container and is not opened, regardless of the freight’s dwell time at a truck terminal. Truck terminals are thus distinguishable from distribution centers at which freight is removed from its original shipping container and assembled or repackaged for follow-on shipment using different inbound-outbound modes of transportation.”

This, of course, does not mean that ISCD cannot change its mind at some future date if circumstances change. If they do, however, a new rulemaking would be required; with the attendant public comment and response process.

NOTE (not covered in the FAQ): For facilities with a blended operation with parts of the facility acting as a terminal operation and other parts operating as a distribution center, if the facility owner can separate the two operations they would only be required to complete a Top Screen on the distribution center portion of the facility.

Friday, February 2, 2018

ISCD Updates Monthly Update Page – 02-02-18

Today the DHS Infrastructure Security Compliance Division (ISCD) updated the data on the Chemical Facility Anti-Terrorism Standards (CFATS) Monthly Update page. The new data for January 2018 shows the continued progress being made implementing the CFATS program.

Facility Status


The table below shows the facility status at the end of the month of January. As I predicted last month, we have now seen our first decline in the number of covered facilities since the implementation of CSAT 2.0 in October of 2016. Remember, facilities have every incentive to take actions to reduce/eliminate their use or inventories of DHS chemicals of interest (COI) so as to avoid being covered by the costly CFATS program.


CFATS Facility Status
Dec-17
Jan-18
Tiered
723
576
Authorized
493
600
Approved
2340
2339
Total
3556
3515

We should continue to see a decline in the number of tiered facilities now that the CSAT 2.0 implementation has essentially been completed. It is unlikely to ever drop to zero as the ISCD outreach plan continues to identify new potential facilities and changes in the chemical industries brings new facilities into the possession of COI. I suspect that in the coming months we will see the increase in the number of Authorized facilities begin to level off and eventually start to drop as more facilities complete the site security plan approval process.

ISCD Activities


The table below shows the activities that the chemical security inspectors have undertaken in support of the CFATS program.

CFATS Activities
Dec-17
Jan-18
Authorization Inspections to Date
3132
3225
Authorization Inspections Month
49
97
Compliances Inspections to Date
3112
3176
Compliances Inspections Month
77
63
Compliance Assistance Visits to Date
3799
3873
Compliance Assistance Visits Month
100
122

Once a facility receives administrative approval of their submitted site security plan (SSP) and receive their ‘Authorization Letter’ they have to pass an Authorization Inspection to receive final approval of their SSP. The Authorization Inspection checks to ensure that the facilities have all of the security measures in place that they have described in their authorized SSP. Compliance Inspections, on the other hand, is a periodic check of the facility’s compliance with the terms of their SSP, including the scheduled implementation of their ‘pending security measures’.

The comparison of the ‘to Date’ data and the January data shows a much closer match that we have been seeing. The four-inspection difference on reported numbers for authorization inspections and one-inspection difference for compliance inspections could certainly fall within the ‘glitch in the system’ that ISCD reports on the page. The not so subtle difference between the delta on ‘to Date’ Compliance Assistance Visits of 74 and the reported 122 conducted during the month of January is less easy to accept. Since this is more of a manpower utilization issue than a actual compliance issue, I’ll leave this to the DHS IG to question if they feel it is appropriate.

I will mention this, however. ISCD provides the following explanation for the Compliance Assistance Inspection:

“This metric shows the number of Compliance Assistance Visits completed. ISCD offers CAVs to CFATS-covered facilities and facilities of interest so that the facilities have an in-depth knowledge of how to meet the requirements of the CFATS regulation. These visits can perform various functions, such as assisting with determining COI reporting requirements, submitting or resubmitting a Top-Screen, developing an SSP or ASP, editing a SSP based on a change in security posture or tiering, or assistance with complying with any other part of the regulation.”

I would like to think that the “complying with any other part of the regulation” would include inspections when a facility reports that they have either reduced their COI inventory below the Screening Quantity Threshold or removed the COI entirely from the facility. All other things being equal, the reduction/removal of the COI would be a prerequisite from removal of a facility from the CFATS program.

Monday, January 22, 2018

ISCD Outreach and Shutdown

Today, the first day of the Federal Funding Fiasco 2018, the folks at DHS Infrastructure Security Compliance Division {the DHS division operating the Chemical Facility Anti-Terrorism Standards (CFATS) program} published two notes in the ‘Latest News’ section of the CFATS Knowledge Center web site. The first is a brief note about the ‘funding hiatus’ and the second is a blurb about the publication of the CFATS Outreach Implementation Plan for FY18.

Funding Hiatus


While the current federal funding authorization actually stopped at midnight last Friday, today (as the start of a ‘normal’ work week) was effectively the first day of the ‘funding hiatus’; which I prefer to call the Federal Funding Fiasco 2018. The Knowledge Center page provided the following information:

“Due to the current federal funding hiatus, some DHS personnel [emphasis added] will not be able to return emails or telephone calls until the conclusion of the funding hiatus. We appreciate your patience at this time.”

There is no specific outline of which ‘DHS Personnel’ are out of contact due to the FFF. I would have guessed that that would have included Chemical Security Inspectors, but I heard complaints during the first FFF that some inspectors were expected to work regardless. I guess the best way to tell is to try to contact folks and if they do not respond they are probably part of the ‘some DHS personnel’.

This is more information than was provided on this page during the ‘first FFF’ in 2013, however. There is a banner on the CFATS landing page (and other DHS pages) nearly identical to the one in the first FFF. Similarly, the DHS Blog entry to which that banner is linked has almost identical verbiage to the 2013 post (the dates have been changed to protect the innocent).

One significant difference on the CFATS web site this time around is that there in no notice that the CSAT system is off-line on either the Registration Page or the CSAT Portal page. Presumably this means that the automated CSAT tools remain up and running.

NOTE: After writing the above, I received news that the FFF has been at least temporarily suspended until February 8th. We will have to wait to see if we have a Part Deux. 

Outreach Program


The second note is about the publication of the “CFATS Outreach Implementation Plan FY 2018”. This is apparently (I have not seen any of the earlier documents) the third update of a plan by ISCD that was required by the current CFATS authorization {6 USC 629}. It provides an interesting summary of the outreach efforts that ISCD has undertaken to reach out chemical facilities that may be covered by the CFATS program, but that have not filed a Top Screen report that would allow DHS to make an actual determination whether or not they are covered by the program.

The lengthy (8 pages) Executive Summary of the program includes a multipage table that briefly outlines the activities included in the original FY 2015 outreach plan and where those efforts stand three years later. Some interesting data points taken from that table include:

• DHS analyzed 217 chemical incidents; identified 54 potential CFATS sites; had 19 Top Screens submitted, and designated 5 new CFATS covered facilities;
• Of the 27,000 or so facilities that submitted Top Screens under CSAT 2.0 1,900 were facilities that had not submitted Top Screens previously; of those, 270 were designated covered facilities;
• In FY17, DHS identified 519 facilities as potentially non-compliant; and
• Since 2014 DHS officials have contacted 1400 Local/Tribal Emergency Planning Committees (LEPC).

Appendix A of this document provides a list of materials that ISCD has published to support this outreach mission. Most of the documents have been covered in this blog. There are four exceptions to that coverage; I have not seen and thus have not reported on the following:

• CFATS Information for Laboratories (factsheet);
• CFATS Information for Wineries (factsheet);
• CFATS Information for Breweries (factsheet); and
• CFATS Information for Fisheries and Hatcheries (factsheet).

These factsheets were not mentioned on the Knowledge Center and, contrary to the claim at the top of Appendix A, I have not been able to find them on the Critical Infrastructure: Chemical Security web site. I do not expect that there was much to miss here, but it would have been interesting to see how ISCD tired to ‘personalize’ the CFATS program for these industries.

Wednesday, December 27, 2017

ISCD Publishes 60-day Personnel Surety ICR Revision

Today the DHS National Protection and Programs Directorate (NPPD) published a 60-day Information Collection Request (ICR) revision notice in the Federal Register (82 FR 61312-61317) for the expansion of the personnel surety program (PSP) to Tier 3 and Tier 4 facilities covered under the Chemical Facility Anti-Terrorism Standards. The PSP implements the requirement of 6 CFR 27.230(a)(12)(iv) to vet personnel with access to CFATS covered facilities “to identify people with terrorist ties”.

The NPPD’s Infrastructure Security Compliance Division (ISCD) is not proposing any changes to the four options for vetting covered personnel that were established when the current ICR was approved for Tier 1 and Tier 2 facilities.

Under this proposed revision ISCD would begin a phased notification of Tier 3 and Tier 4 facilities over a three-year period to revise their site security plan to reflect their implementation of the PSP terrorist vetting requirement. This notification would only begin once the OMB’s Office of Information and Regulatory Affairs (OIRA) approved this ICR.

ISCD has made some revisions to the ICR burden estimates in this notice based upon the data that they have received during the PSP implementation at Tier 1 and Tier 2 facilities. Generally they have reduced the number of estimated data submissions and the amount of time per submission to lower the burden estimate.


ISCD is soliciting public feedback on this ICR notice. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #DHS-2017-0037). Comments need to be submitted by 02/26/2018. This ICR notice will be followed by a 30-day notice once ISCD has a chance to respond to the comments submitted to this notice.

Tuesday, December 12, 2017

ISCD Changes Monthly Status Reporting

Today (okay, yesterday now on the East Coast) the DHS Infrastructure Security Compliance Division (ISCD) changed the way they are reporting progress on the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS) program. They scrapped the monthly .PDF CFATS Fact Sheet format and added a new web-page to the CFATS web-site that provides a slightly different look at the progress being made.

Inspection Reporting


Long-time readers of this blog will no doubt recall the monthly parsing of data that I have been doing since the CSAT 2.0 reporting began back in May of this year. With ISCD reporting inspection data both on inspections ‘since the inception of the program’ and on ‘at currently covered facilities’ I had fun trying to figure out how many inspections had actually been completed that month and how many facilities were undergoing multiple inspections due to failure to achieve compliance.

The new web page changes that reporting. It still carries on with reporting the number ‘since the inception of the program’, but it now simply reports a single number for the number of inspections (Authorization, Compliance, and Compliance Assistance) conducted during the month. The table from the November 2017 reporting is shown below.

Activity
Since Inception     
November 2017
Authorization Inspections (AIs) 
     3,102
     70
Compliance Inspections (CIs)
     3,065
     87
Compliance Assistance
Visits (CAVs)
     3,723
     92

If we try to compare the ‘since inception’ numbers from this newest report and those from the old style November report (ISCD used to name their reports for date of reporting not the month the inspections were done). It would appear that there were 87 AIs completed and 111 CIs done in November. This discrepancy may be due to reporting format changes or a couple of other possible program issues. It is hard to tell from a single data point.

Facility Status Reporting


A new set of data being reported on the web page is CFATS Facility Statuses. Kind of an ugly title but, it is an interesting new set of information. Previously, ISCD only published monthly numbers on the number of facilities covered under the CFATS program and the number of currently approved site security plans (SSPs). The new web page provides a table showing a snapshot of the current status of facilities in the program.

Status
Currently Covered
Tiered
     843
Authorized
     429
Approved
     2,276
Total
     3,548

This new table provides us with data on the number of facilities that have received Tiering Letters (Tiered) but have not yet had their site security plan authorized. It also tells us how many are pending approval of their SSPs, how many have approved SSPs and the sum of the above tells us how many facilities are currently covered by the CFATS program.

Interestingly, since the resumption of program status in May, there has been a net gain of 978 facilities in the program. Most of these, presumably, were added due to the revised risk assessment process and CSAT 2.0 resubmission of Top Screens, though ISCD has continued to vigorously reach out to the chemical community to identify facilities that should have been submitting Top Screens, but, for one reason or another, have failed to do so. This is a fall smaller number than the 1272 facilities that have not yet had their SSPs approved. It is highly unlikely that a significant number of the new facilities have had their SSPs approved since May. Thus, it looks like we may have had about 300 facilities fall-out of the CFATS program since reporting resumed in May. That would not be out of line with what ISCD reported as being the drop-out rate for the new risk assessment process.

Missing Data


I continue to have problems with the ISCD compliance inspection data. The data being reported today for ‘compliance inspections since inception’ and the numbers reported in the last monthly report show that there should have been 111 compliance inspections completed in November, not the 87 being reported here. Again, there could be a number of different explanations, but I continue to suspect that the 87 inspections being reported in November only reflects one-inspection (the latest) per facility.

In the past couple of months, I have been focusing on the potential for these re-inspections being required because of facilities failing their compliance inspection and thus requiring a re-inspection. ISCD broadly points out another category of facilities being re-inspected:

“It is also important to note that this regulatory program is cyclical in nature, meaning activities such as Compliance Inspections are recurring. ISCD began conducting recurring Compliance Inspections in March 2017.”

It would be helpful if ISCD were a little more specific what the 87 number being reported actually means. Was that the total number of compliance inspections done in November or the increase in the number of facilities with a current compliance inspection. And just to make things perfectly clear, it would be helpful to have a number of compliance inspections passed/failed as well.


Actually though, I really am impressed with the effort that ISCD takes to keep the chemical security community up-to-date on the progress that is being made in the program. And the progress really is an important reflection on the daily efforts by the 150 or so Chemical Security Inspectors working with the employees and contractors at the 3,548 CFATS sites on an on-going basis to reduce the risk of a terrorist attack on these facilities. Everyone involved is to be commended on the time and effort being put into this program.

Sunday, October 15, 2017

ISCD Updates CSAT 2.0 Web Site

Last week the DHS Infrastructure Security Compliance Division (ISCD) updated their Chemical Security Assessment Tool (CSAT) web page; this is part of the extensive web site for the Chemical Facility Anti-Terrorism Standards (CFATS) program. The only change to the CSAT page was the addition of a link to the new CFATS Site Security Plan (SSP) Submission Tips web page.

This new web page is part of the on-going ISCD outreach program to the CFATS regulated community. It is not a substitute for the SSP manual and the Risk Based Performance Standards (RBPS) Guidance manual, but rather a highlight of those types of things that have apparently been found lacking in many SSP submissions in the past. It highlights four major areas of concern:

• Consider what security measures to address;
• Detail current security measures;
• Describe planned security measures; and
• Specify facility-wide or asset-specific security measures

 What Security Measures


Of course, facilities are going to need to address security measures in each of the 18 RBPS that are applicable to the DHS chemicals of interest (COI) identified on the facility tiering letter. This section of the web page addresses five “overarching objectives” of the SSP:

• Detection;
• Delay;
• Response;
• Cyber; and
• Security Management

These are covered in short (one paragraph) discussions and links to the four RBPS fact sheets that ISCD began issuing earlier this year:

RBPS 8, Cyber Fact Sheet  
RBPS 9, Emergency Response Fact Sheet  
RBPS 12, Personnel Surety Program Fact Sheet  
RBPS 18, Records Fact Sheet 

Current Security Measures


This section briefly covers two rather broad topics:

• Be as detailed as possible; and
• Don’t overlook safety and environmental measures already in place that contribute to security.

In my conversations with folks in the field the first point is probably the most important for a successful SSP submission. This new web page says it well and succinctly:

“The text boxes in the Chemical Security Assessment Tool’s (CSAT) (/chemical-security-assessment-tool) SSP application have been included so that facilities can more fully describe current security measures, including how the measures address the relevant RBPS. The better DHS can conceptualize and understand your approach to security measures, the better DHS can evaluate whether they meet the applicable RBPSs.”

Facility-Wide vs Asset-Specific


The discussion here is important, though more than a little simplified (to be expected in a short document like this). It boils down to this. Security measures can be quite expensive, especially as the size of a facility increases. Since different types of COI may require different types of security measures, a facility may be able to significantly reduce costs by confining certain security measures to just those areas where their listed COI are stored or handled. Provisions are made in the CFATS to allow facilities to do this.

Commentary


Again, ISCD has consistently tried to reach out to the CFATS community and provide the necessary information to successfully comply with the program requirements. This is part of that outreach. It is not (nor was it intended to be) the ultimate word in developing a successful SSP submission. It is just part of the process.

Facility security personnel will find this helpful only if they are familiar with the RBPS Guidance document and the SSP manual. Another source of useful information in this matter are two of the recently published presentations from the 2017 Chemical Sector Security Summit:


In fact, the CSSS web site has links to additional presentations from previous years that will also be helpful. The whole CSSS program is helpful for anyone interested in chemical facility security issues.


One final point, cybersecurity continues to pop up regularly in any discussions about the CFATS program. ISCD is certainly taking great pains to mention the topic whenever they discuss site security plans or compliance inspections. They have taken particular care to ensure that they try to communicate that ‘cybersecurity’ is not only important for the control systems that touch on the handling and/or storage of covered COI, but also includes cybersecurity measures to protect security controls (surveillance, intrusion detection, and access control systems) as well as business systems that affect the handling (ordering, selling or transporting), or storage of covered COI.

Tuesday, September 26, 2017

ISCD Publishes CFATS Fact Sheet – October 2017

Today the DHS Infrastructure Security Compliance Division (ISCD) published their latest version of the Chemical Facility Anti-Terrorism Standards (CFATS) Fact Sheet. The data continues to show a net increase in the number of facilities covered under the program and a similar increase in the number of compliance inspections completed to date. The data still paints a confusing picture that would seem to indicate a high rate on CFATS non-compliance.

The Data


Table 1 shows the comparison between the data reported today and that reported last month for facilities currently covered by the CFATS program. For the first time since reporting resumed we see a positive month-to-month change in all of the reported categories

Current Facilities
Sept
2017
Oct
2017
Covered Facilities
3,441
3,492
+51
Authorization Inspections
2,354
2,374
+20
Approved Security Plans
2,266
2,270
+4
Compliance Inspections
2,071
2,106
+35
Table 1: Current Facility Data

Table 2 shows the similar comparison of monthly data for the total numbers for each category since the inception of the CFATS program. As expected the month-to-month change in each category is positive, but we continue to see a significant disparity between the two tables in differences (∆) for compliance inspections and both authorization inspections and approved security plans.

Total Facilities
Sept
2017
Oct
2017
Authorization Inspections
2,946
2975
+29
Approved Security Plans
2,756
2766
+10
Compliance Inspections
2644
2807
+163
Table 2: Total Facility Data

Compliance Inspections


If I update the graph that I used last month to include the current data (Graph 1) we can see the sharp differences between the rate of change in current approved site security plans (a pre-requisite for having a compliance inspection), the total number of compliance inspections completed to date, and the current compliance inspection numbers.


Graph 2: Compliance Inspection Data

As with last month, it is hard to come up with any explanation of the data presented by ISCD other than to conclude that ISCD is finding a disturbing number of facilities non-compliant with the implementation of their site security plans. What makes this so disturbing is that facilities negotiated with ISCD on setting the content of their site security plans, so it is hard to believe that they were ‘not aware of program requirements’.

Security of Non-Compliant Facilities


The big question that this raises is how secure are these non-compliant facilities? That is a question that is next to impossible to answer from the data that ICSD is allowed to share with the public. ISCD is not about to, nor can they legally, share any data about the security of covered facilities.

Of course, I am under no restrictions about the conjectures that I raise in attempting to answer this question. So here goes an uninformed, but educated guess as to what is going on…

First, I think that basic security measures are in place to deter, detect and delay terrorists desiring to attack these facilities. Those are all fairly straightforward and would have been in place before ISCD authorized or approved the site security plans (SSP) under which these facilities operate. I suspect that the non-compliances fall into three categories:

• Planned security measure failures;
• Changes is security posture; and
• Cybersecurity

Planned Security Measures


The first category covers those high-expense capital expenditures that facilities could not immediately implement because of budgeting constraints. ISCD gave facilities credit for these security measures when approving the SSP, because specific plans and budgeting approvals were in place. As with any plan, things can go wrong and those plans may not have been at an appropriate level of completion when the Chemical Security Inspectors (CSI) showed up for the compliance inspection will be a problem. Those would certainly make the facility non-compliant.

How badly that would affect the actual security of the facility is hard to tell without knowing the details. ISCD would have required some sort of interim compensatory controls to be in place to mitigate the vulnerabilities while the planned action is implemented. So, while there may be a hole in the security plan, it should not be gaping nor readily identifiable.

I do know that ISCD has no quota of non-compliances to issue and would I would bet that, if facilities in this situation had previously talked with ISCD about the problem they were having with their planned security measures, they would have been able (in most reasonable cases) negotiate a new time frame for implementation. When the inspector gets there, it is certainly too late.

Material Modifications


I suspect that the second category is probably the most common reason for non-compliance. The CFATS program requires {6 CFR 27.210(d)} facilities to submit a new Top Screen whenever it “makes material modifications to its operations or site”. This allows ISCD to determine if a new or revised security plan is required to mitigate any security vulnerabilities associated with those changes. Since ‘material modifications’ is not a defined term in 6 CFR 27, it would not be surprising to hear that facility or operational changes that the facility made without an apparent security purpose might be considered a ‘material modification’ in light of the undisclosed risk assessment process that ISCD uses to evaluate facilities for program coverage and risk tiering.

CFATS covered facilities need to take a hard look at any facility, chemical process, or business procedures changes with a specific eye to its potential effect on the efficacy of the site security plan. This especially applies to any procedure or device specifically mentioned in the SSP. This is one of the reasons why it is important to have a site security manager who is an integral member of the facility management team.

Cybersecurity


The final category is more of a stretch of my intuition, but with an increasing focus across DHS on cybersecurity issues, it would not be hard to guess that implementing Risk Based Performance Standard (RBPS) 8, Cybersecurity, would be an item on specific interest on compliance inspections. Facilities with access to a well-trained cybersecurity team, would probably have no problems implementing the agreed upon cybersecurity measures in the SSP. Facilities without such support would have a much more difficult time in meeting the cybersecurity requirements of a reasonable cybersecurity plan.

This is the one area that I am not as confident in the overall security posture of non-compliant facilities. Again, it would depend in large part about the chemicals of interest involved and how much control systems and inventory controls played in the security of those COI at the site. But, there are so many ways that either informational or operational computer systems could impact security plans that I suspect that this is the area with the widest variation in actual the security of dangerous chemicals across the country. Which would be why ISCD would be specifically focusing on the security of these systems in any compliance inspection.

Moving Forward



We are a little more than a year away from the current expiration of the CFATS program (12-18-18). Congress is likely to start looking at this program again as they consider reauthorizing the program. If ISCD is having the high non-conformance rate that I think the current data indicates, there will certainly be questions asked on the Hill about this topic. I hope ISCD has some good answers.
 
/* Use this with templates/template-twocol.html */