Showing posts with label NTAS. Show all posts
Showing posts with label NTAS. Show all posts

Friday, April 10, 2026

Review - HR 7448 Introduced – NTAS Modernization

 Back in February, Rep Pou (D,NJ) introduced HR 7448, the Modernizing and Improving the National Terrorism Advisory System Act of 2026. The bill would require DHS to develop a strategy to modernize the National Terrorism Advisory System (NTAS). No new funding would be authorized. 

Moving Forward   

Pou, and both of her cosponsors, are members of the House Homeland Security Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in committee. I see nothing in this bill that would engender any organized opposition. I suspect that the bill would receive significant bipartisan support were it considered in Committee. Whether that support would be sufficient to see the bill move to the floor of the House under the suspension of the rules process remains to be seen. 

For more information on the provisions of this bill, including a commentary on including potential asymmetric attacks and cyber-attacks in the strategy, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7448-introduced-ntas-modernization - subscription required. 

Wednesday, June 8, 2022

Review - DHS Updates NTAS Bulletin – 6-7-22

Yesterday DHS updated their National Terrorism Advisory System (NTAS) web page replacing the Bulletin that had been in effect since February 7th, 2022. The new bulletin continues to provide a broad stroke overview of the potential terrorist threats facing the United States. There are no actionable bits of information about suspected or known plans for terrorist attacks, such information would have triggered an Advisory instead of a Bulletin.

The Chemical Facility Anti-Terrorism Standards (CFATS) program includes a requirement {6 CFR 27.235(13)} for facilities to be able to escalate “the level of protective measures for periods of elevated threat”. Generally speaking, NTAS Bulletins do not constitute a warning of ‘elevated threat’, that would typically require an NTAS advisory. Facility owners should, however, read the new Bulletin and see if there is anything that might indicate a reason for increased concern at their facility. Additionally, facility owners might want to contact their Chemical Security Inspector to see if there is any additional information available from DHS that could affect their security posture.

The relatively new CISA ChemLock voluntary chemical facility program does not have anything in the way of requirements to address increased threats; it is after all a voluntary program, but the recommendation above for CFATS facilities would also apply to chemical facilities participating in the voluntary program.

If facility management sees anything in the Bulletin that may raise cause for concern at their particular facility, it is probably time to go into the enhanced security planning mode. I did a fairly detailed posting on what that should entail back in 2011 and the advice still stands today.

 

For more details about the Bulletin and some of its supporting documents, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/dhs-updates-ntas-bulletin - subscription required.

Friday, May 14, 2021

New NTAS Bulletin Published – 5-14-21

Today DHS published a new National Terrorism Advisory System (NTAS) Bulletin on the NTAS web site. While very similar to the previous Bulletin that was due to expire tomorrow, the focus of this new Bulletin has subtly changed. Still, this is a bulletin not an alert, so it does not provide and action indicators beyond ‘be aware’ and ‘if you see something, say something’. This new Bulletin expires on August 13th, 2021.

Gone from the New Bulleting

The new Bulletin does not contain the references found in the previous Bulletin to:

• Domestic Violent Extremists (DVEs) targeting individuals with opposing views engaged in First Amendment-protected, non-violent protest activity,

• Long-standing racial and ethnic tension—including opposition to immigration,

• The January 6th attack on the Capital,

• Threats of violence against critical infrastructure,

New Potential Threats

The new Bulletin adds references to:

Continued sharing of information online with the intent to incite violence,

The use of encrypted messaging by lone offenders and small violent extremist cells,

Messaging from foreign terrorist organizations, and

Nation-state adversaries increasing efforts to sow discord.

Tuesday, April 27, 2021

NTAS Bulletin Extended Until May 15th, 2021

According to the National Terrorism Advisory System (NTAS) web site, the current NTAS Bulletin issued January 27th, was extended until May 15th, 2021. The web page explains:

“National Terrorism Advisory System Bulletin - January 27, 2021; Updated April 26, 2021  |  View PDF Version (pdf, 1 page, 291.25 KB)

“The Acting Secretary of Homeland Security issued a National Terrorism Advisory System (NTAS) Bulletin, subsequently extended by the Secretary of Homeland Security, due to a heightened threat environment across the United States, which DHS believes will persist in the weeks following the successful Presidential Inauguration.  Information suggests that some ideologically-motivated violent extremists with objections to the exercise of governmental authority and the presidential transition, as well as other perceived grievances fueled by false narratives, could continue to mobilize to incite or commit violence.

“The expiration date for this Bulletin is extended from April 30, 2021 to May 15, 2021.”

No additional information was provided. For additional details about the NTAS system, see my earlier blog post.

Wednesday, January 27, 2021

DHS Publishes New NTAS Bulletin – 1-27-21

Today the Department of Homeland Security published a bulletin on the National Terrorism Advisory System (NTAS) web page. According to the NTAS page:

“The Acting Secretary of Homeland Security has issued a National Terrorism Advisory System (NTAS) Bulletin due to a heightened threat environment across the United States, which DHS believes will persist in the weeks following the successful Presidential Inauguration.  Information suggests that some ideologically-motivated violent extremists with objections to the exercise of governmental authority and the presidential transition, as well as other perceived grievances fueled by false narratives, could continue to mobilize to incite or commit violence.”

Anyone responsible for facility security needs to read the bulletin and so probably should everyone else. The bulletin is expected to remain in effect through April 30th.

NTAS System

A quick reminder about the NTAS system. It provides three different advisory levels depending on the specificity of the information available. The three different levels are:

• Bulletin - Describes current developments or general trends regarding threats of terrorism.

• Elevated Alert - Warns of a credible terrorism threat against the United States.

• Imminent Alert- Warns of a credible, specific and impending terrorism threat against the United States.

NTAS Bulletin and CFATS

There is currently nothing on either the home page for the Chemical Facility Anti-Terrorism Standards (CFATS) program or the CFATS Knowledge Center about this specific NTAS Bulletin. The CFATS Knowledge Center does have a FAQ about the NTAS system (FAQ #1724) that was most recently updated on November 24th, 2020. The response to that FAQ notes that CFATS covered facilities would have different response requirements under alerts and bulletins. Since bulletins do not provide specific threat information, that FAQ response explains that: “CFATS facilities should monitor the system for Bulletins for situational awareness and may use their best judgement to apply the information posted as applicable to the facility.”

Earlier this month I published two blog posts that address topics discussed in the “Details” portion of today’s bulletin. Those two posts are:

CFATS and the Nashville Bombing

CFATS and the ‘Insurrection’

There is a possibility that, as more specific threat information becomes available, applicable CFATS facilities could be notified directly by the CISA’s Infrastructure Security Compliance Division (ISCD) or directly through the Chemical Security Inspector responsible for oversight at the facility.

Saturday, November 11, 2017

An Early Update to the NTAS Bulletin

Earlier this week DHS updated the National Terrorism Advisory Systems (NTAS) bulletin. This has been a semi-annual activity since 2015. It has become a relatively unimportant news item because there has been little or no change in the wording of each successive bulletin; last May it did not even rate a full blog post here.

There is little change in this iteration, but there is a small change that may be of specific interest to readers of this blog:

“Some terrorist groups overseas are using battlefield experiences to pursue new technologies and tactics, such as unmanned aerial systems and chemical agents [emphasis added] that could be used outside the conflict zones. Additionally, terrorists continue to target commercial aviation and air cargo, including with concealed explosives.”


There have been a number of news articles over the last six months or so about the Isis use of UAS and chemical agents on the battlefield. It is not a great stretch to assume that such tools could be used in terrorist attacks. I would like to think, however, that DHS would not mention these attack options in this venue unless there were specific intelligence that Isis was attempting to move these technologies off the conventional battlefield and into the terrorist playbook. That may just be wishful thinking on my part.

Thursday, May 18, 2017

ISCD Updates NTAS FAQ

Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated one of the responses to a frequently asked question (FAQ) on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The change in the FAQ referring to the National Terrorism Advisory System (NTAS) is significant enough that it was specifically mentioned in the ‘Latest News’ section of the Knowledge Center.

The FAQ response to FAQ #1724 (How do National Terrorism Advisory System (NTAS) Alerts and Bulletins affect a CFATS Facilities’ RBPS 13 compliance responsibilities?) is a complete re-write and should be read by anyone responsible for security at a CFATS covered facility. The change basically delineates between the differences in facility response requirements for an NTAS Alert and an NTAS Bulletin.


Coincidentally, DHS published a new NTAS Bulletin earlier this week. As with the previous update there is nothing new here. It looks like we probably should have stuck with the earlier, color-coded version of the NTAS; at least you did not need to read anything to know that the situation was still the same.

Saturday, November 19, 2016

DHS Updated NTAS Bulletin – 11-15-16

Did you notice the homeland security uproar this week? Well, neither did I. But DHS did issue a new National Terrorism Advisory System (NTAS) bulletin on Tuesday. Why the lack of fear and consternation? It was just a continuation of the two previously issued bulletins (here and here).

An alert reader may have noticed that on Tuesday the NTAS widget on this blog (upper right side) changed from reporting a bulletin to now report ‘ACTIVE BULLETIN’. I’m sure that it caught everyone’s attention.

To be fair, DHS does have an information sharing conundrum. There is undoubtedly some level of existing threat of a terrorist attack in the United States. What real information there may be about specific threats known to the government will not be (and almost certainly shouldn’t be) shared by DHS while the government takes steps to prevent those attacks from unfolding.


But we do want them to tell us something, right? So we get another of these non-information bulletins. And it has become a non-event, as we should have expected. Not quite as ignored as the old color-coded threat levels that the NTAS replaced, but still ignored enough that when the system is used to share real information, it will probably be ignored. Of course, that won’t be a real problem because there will certainly be an official announcement that will make the news.

Wednesday, June 15, 2016

DHS Updates Terrorism Bulletin – 06-15-16

With less than a day left on the first NTAS Bulletin published on National Terrorism Advisory System (NTAS) web site DHS published a new NTAS Bulletin. With very few changes in wording between the two bulletins we are seeing essentially an extension of the first bulletin until November 15, 2016. It is beginning to look like the ‘bulletin’ addition to the NTAS is a return to the old color coded system that the NTAS supplanted because the old system provided little information and never changed.

Wednesday, December 16, 2015

DHS Publishes First NTAS Bulletin

Today DHS published their first terrorism bulletin under the National Terrorism Advisory System. In addition to providing information about the current “new phase in the global threat environment” this bulletin marks the addition of ‘Bulletins’ to the two levels of alerts (Elevated and Imminent) in the NTAS that replaced the old 9-11 based color coded alert system.

Today’s bulletin (that expires on June 16th, 2016) addresses “the rise in use by terrorist groups of  the Internet to inspire and recruit, we are concerned about the ‘self-radicalized’ actor(s) who could strike with little or no notice”. The bulletin is based in large part on data that has emerged from the investigations of recent terrorist attacks in Paris and San Bernardino.

The bulletin outlines four ‘details’ about the current threat:

• Though we know of no intelligence that is both specific and credible at this time of a plot by terrorist organizations to attack the homeland, the reality is terrorist-inspired individuals have conducted, or attempted to conduct, attacks in the United States this year.
• DHS is especially concerned that terrorist-inspired individuals and homegrown violent extremists may be encouraged or inspired to target public events or places.
• As we saw in the recent attacks in San Bernardino and Paris, terrorists will consider a diverse and wide selection of targets for attacks.
• In the current environment, DHS is also concerned about threats and violence directed at particular communities and individuals across the country, based on perceived religion, ethnicity, or nationality.

The bulletin also outlines actions that DHS and the law enforcement community are taking to address the threat outlined in the bulletin. There are also specific recommendations to individuals about the part that they play in reducing the risk from the current threat. These recommendations are broken down into three categories:

• How you can help;
• Be prepared; and
• Stay informed.

The addition of bulletins to the previous alerts in the NTAS is part of the modernization effort that DHS Secretary Jeh Johnson promised earlier this month. Those earlier reports sounded like there would be a new system to replace the never used NTAS. Instead, it looks like the Department has decided to upgrade NTAS instead of effecting a wholesale replacement.


NOTE: Long time readers of my blog will note a difference today in the DHS provided NTAS widget on my blog. It now lists ‘Bulletin’ and provides a link to today’s newly released bulletin. It will be interesting to see if that listing on the widget will remain there through June 16th. If so, it will do little good if a new bulletin is released in the meantime. I hope that DHS has thought that through. Perhaps they may want to revise that widget to also show the date of the most current bulletin or alert.

Saturday, September 6, 2014

NTAS Website Updated – 09-05-14

Saturday is usually the day that I set aside to go back and look at a number of web sites that don’t change frequently, but would have information that readers of this blog might be interested in. One of those web sites is the National Terrorism Advisory System web site. Interestingly every page on that site was ‘updated’ yesterday.

Now this is not one of the sites that I keep site maps for so that I can track infinitesimal changes in the site language so I cannot tell what changes have been specifically made. In fact, it does not look like any real changes have been made to the site; but, each page carries a note at the bottom that: “Last Published Date: September 5, 2014”.

With a lot of politicians talking about the increased homeland threat from the Islamic State of Iraq and the Levant (ISIL) in recent weeks it is interesting that DHS takes the time to publicly ‘update’ its web site for issuing terrorism alerts.


Now watching this web site should not be anyone’s method of getting NTAS alerts. Watching any newsfeed will probably get you the alerts in a timely fashion, but if you want to get immediate notification the web site does provide links for following NTAS on Twitter® or on Facebook®, receiving email notifications, or putting an active link on your web site (like I have on mine).

Friday, October 11, 2013

Bills Introduced – 10-10-13

Ten days into the fiscal fiasco and Congress isn’t paying much attention to anything else. There were a total of nine pieces of legislation introduced yesterday and only two did not address spending or the debt limit. One of those may be of specific interest to readers of this blog:

HR 3283 Latest Title: To amend the Homeland Security Act of 2002 to direct the Secretary of Homeland Security to modernize and implement the national integrated public alert and warning system to disseminate homeland security information and other information, and for other purposes. Sponsor: Rep Bilirakis, Gus M. (R,FL)


It will be interesting to see if this modifies the current National Terrorism Alert System, the never used replacement to the overused color coded alert system.

Friday, September 14, 2012

"Innocence of Muslims" and the NTAS


A reader of this blog and an important ICS security researcher, Joel Langill, has asked on TWITTER a number of times over the last 24 hours (the latest here) why DHS hasn’t posted an alert on the National Terrorism Advisory System (NTAS) as a result of the Joint Intelligence Bulletin (I can’t find a link to this oft reported Bulletin) from the FBI and DHS that warns faith-based organizations in the United States and U.S. embassies abroad that “the risk of violence could increase both at home and abroad as the film continues to gain attention.”  I tried last night, unsuccessfully, to explain in 140 characters why such an alert is ‘not appropriate under the NTAS’. Since DHS isn’t going to explain, I thought that I would try again in more detail.

The Old System


To fully understand the NTAS you have to first remember the problems we had with the old color-coded. The old system would describe the current state of alert based upon a vague definition of a threat. It provided no real guidance to the public other than to be vaguely ‘alert’ to unusual or suspicious activity. And it stayed at an ‘elevated’ level for so long that it was effectively ignored.

The NTAS


When DHS brought the new NTAS into operation in April of 2011 Secretary Napolitano assured the public that the new system would only be activated when there was a clear and specific threat to the public or a substantial portion of the public. She also promised that the alert would provide specific information to the public about what actions they should take. Finally, it was made clear that any alerts issued would be for a specific, limited time-frame associated with the specific threat.

The NTAS was immediately questioned just a couple of days after its establishment when no alert was issued after the assassination of Osama Bin Laden. I noted in a blog post at the time:

“Today, and for the last five days, we have been under a new National Terrorism Advisory System that requires that “NTAS Alerts will only be issued when credible information is available.” It is way too soon to have any ‘credible information’ available on an organized threat, and much of the unorganized threat will not be planned well enough for there to be much if any chance for the intelligence community to find any credible information.”

Surprisingly there was relatively little in the way of counter-attacks by al Qaeda after Bin Laden’s death; especially here in the United States. In hind sight DHS was absolutely correct that there wasn’t any need for issuing an NTAS alert. Besides, there was more than enough communications from DHS through the media that notified people of the possibility of terrorist actions and reminding them to report suspicious activity. No alert was justified or necessary.

Consulate Attack in Libya


There are certainly initial indications that the attack on the Consulate in Bengasi, Libya was probably a planned terrorist attack specifically targeting Ambassador Stevens. He was a locally popular figure who presented a good image of the United States to the Libyans. As such he was a threat to the success of radical Islamic forces in the area. It even looks like the demonstration outside of the Consulate may have been planned and fabricated as a cover for the attack.

That there might be similar attacks planned at other consulates in Muslim countries is entirely possible. One would like to think that the State Department is taking appropriate precautions. It is unlikely that such a complex attack, however, could be executed in the United States.

Potential for Homeland Attacks


It is clear from what we have heard of the FBI/DHS Joint Intelligence Bulletin, that neither agency has any actionable intelligence about specific related attacks in the United States. What they have announced is a standard warning that this video trailer is objectionable enough to Muslims that it would not be unexpected for it to be capable of being the final straw in the radicalization of some small number of individuals here in the United States; just as was the death of Bin Laden.

That one or more of these individuals could get excited enough in the short term to execute some sort of impromptu attack on perceived targets is always possible. Even though we are unlikely to catch these types of short term attacks before they occur, neither are they expected to be overly effective. Effective attacks take planning, weapon acquisition and training, and reconnaissance. These are the activities that suspicious activity reporting (SAR) is designed to detect; not public alerts.

Save the NTAS Alerts for Expected Attacks


The NTAS is designed to notify the public when the intelligence/law enforcement folks have detected an incipient attack and need the public to take specific measures to protect itself against the specific attack. The whole point of the NTAS alert is to be so rare as it captures the public’s attention and causes widespread compliance with the directives of the alert.

If we go back to the old color code standard of initiating active alerts every time that something occurs in the world that will stir up potential radicals, we will always be under alert without being provided specific protective actions. If and when either the Department or the FBI comes up with a specific credible threat of a terrorist attack, we need the NTAS to be an appropriate and watched notification system.

Sunday, August 7, 2011

CFATS Knowledge Center Update – NTAS Info

On Friday the folks at DHS ISCD updated the CFATS Knowledge Center to provide information for the CFATS implications of the implementation of the DHS National Terrorism Advisory System (NTAS) that went into effect in May. The most obvious change was a new note under the “Latest News” heading, but it also included two new Frequently Asked Questions and a new article.

The ‘Latest News’ entry (which incidentally was placed out of date order behind ANSP NPRM notice provides a link to the following brief note about the NTAS:

“DHS has replaced the color-coded Homeland Security Advisory System (HSAS) with the new National Terrorism Advisory System, or NTAS. Further information on NTAS available at: www.DHS.gov/alerts. This new system will more effectively communicate information about terrorist threats by providing timely, detailed information to the public, government agencies, first responders, airports and other transportation hubs, and the private sector. This transition may require covered facilities to make minor adjustments to comply with applicable CFATS requirements regarding elevated threats. Generally speaking, however, a facility will not need to make a change to its submitted SSP unless it explicitly references HSAS in facility-provided explanatory text. In such a case, the facility will need to revise that text by either making a technical edit through the CSAT SSP Edit function or requesting DHS to unlock the SSP to allow the facility to make the edit. (See CSAT SSP Edit Process Users Guide).”

NTAS Article


This brief news note is good background information but, as one would expect from its brevity and identification as ‘news’, it provides little in the way of guidance. The folks at ISCD have provided that guidance in the new article provided on the page. Article 1723 (there are no permanent links to items on the CFATS Knowledge Center, go to the page and enter ‘1723’ into the search bar at the top of the page to get the current link to the article) provides a detailed discussion about the NTAS, including:

• How it relates to the old Homeland Security Advisory System;

• Related changes in the CSAT SSP questions (included in the June 2011 version of the SSP Questions manual);

• The relationship to RBPS 13 (Elevated Threats) and RBPS 14 (Specific Threats, Vulnerabilities or Risks) responses by covered facilities; and

• The requirements for changing the facility SSP submission

This is a very well done article and it should be read by anyone involved in a facility CFATS program. In fact, I would recommend printing out the .PDF version of the article and placing it in the same binder that contains the facility copy of the Risk Based Performance Standards Guidance document.

NTAS FAQs


The CFATS Knowledge Center also added two frequently asked questions (FAQ) that address specific topics about the NTAS. The information included in the two FAQs is also found within the NTAS article. The two new questions are:

• 1724: How will a CFATS facility know if it is subject to a National Terrorism Advisory System (NTAS) Alert?

• 1725: How does the change from the Homeland Security Advisory System (HSAS) to the new National Terrorism Advisory System (NTAS) impact a CFATS-covered facility’s regulatory requirements?

CFATS Specific NTAS Advisories


There are two important points that DHS makes in this new information in regards to NTAS advisories that specifically affect CFATS covered facilities. First DHS notes that “if an NTAS Alert is issued that impacts all or a portion of the CFATS-regulated community, DHS will notify CFATS facilities subject to the Alert” (FAQ 1724). DHS has contact information for each CFATS facility and will use the most appropriate method of communicating the information to the facility.

Second, DHS notes that if an NTAS alert rises to the level that the Secretary identifies a specific threat as outlined in RBPS 14, “DHS will contact the impacted facility and work with the facility to identify appropriate measures, procedures, or other activities that the facility could use to address the identified threat” (FAQ 1725).

CFATS Knowledge Center Suggestion


Once again the folks at ISCD are to be commended for using the CFATS Knowledge Center web site to communicate information to the CFATS community even if the information is a little late. In particular the new article is particularly well done. The only slight problem is that a cursory examination of the page does not obviously provide access to the information. This could be easily rectified by including the relevant Article and FAQ numbers (particularly when they are new numbers) in the ‘Latest News’ item announcing the change.

Wednesday, May 11, 2011

NTAS Changes for MTSA Facilities

Last month when DHS changed over from their old color-coded terrorist alert system to the new National Terrorism Alert System (NTAS) I did a blog about how that change would affect CFATS facilities and their preparation of site security plans. CFATS isn’t the only security program affected by this change. A couple of readers have noted that the Coast Guard’s MTSA security program also required the planning for enhanced security as the old Homeland Security Advisory System (HSAS) raised the threat level which, in turn, affected the Maritime Security (MARSEC) level.

Coast Guard Response to NTAS

One reader sent me a copy of a Marine Safety Information Bulletin (MSIB) (I'm sorry I don't have a link for the document) published by the Captain of the Port for New Orleans on April 29th describing how MTSA covered facilities and vessels should adapt their approved security plans to the new NTAS pending specific changes to 33 CFR 101.

That MSIB provided the following policy guidance:

“1. MARSEC levels will continue to have the meaning defined by 33CFR101.105

“2. All references to the HSAS in 33CFR101 are obsolete and will no longer be used.

“3. The three MARSEC levels will continue to be used as before, except as follows. If the Secretary of Homeland Security issues an NTAS alert, the Commandant will adjust the MARSEC level if appropriate based on commensurate risk, any maritime nexus, and/or CCG consultation with the Secretary of Homeland Security.”
It also provides an abbreviated change procedure for approved security plans to reflect the change from the HSAS to NTAS system:

“Pending future regulatory changes to 33CFR101, pen and ink changes in place of submission of a formal amendment per 33CFR104.415, 105.415, and 10.415 (sic) are authorized until the plan is next revised and submitted for review.”
Flexible Response

It is nice to see a regulatory agency exercising this type of flexibility in response to changes in the regulatory environment. Of course, the Coast Guard is also a military organization and the military has always favored this kind of response to changing conditions, allowing local commanders to respond to changing situations while the bureaucratic processes catch up. This is why the MSIB comes from the Captain of the Port rather than the Commandant.

It is extremely unlikely that ISCD, under any Director, would ever provide that sort of command flexibility to their Regional commanders of the CFATS inspection force. It doesn’t have the long history, tradition and training that the Coast Guard has that provides the institution the ability to allow such responsiveness.

In the mean time, CFATS facilities are going to have to try to figure out what to do with their site security plans. Do they address the current RBPS 13 guidance on enhanced security with an adaptation for the NTAS similar to what I wrote in my RBPS 13 revision blog? Or do they take the risk that DHS and their chemical security inspectors will not accept references to the NTAS because it isn’t mentioned in the Guidance document?

I think that CFATS facilities can count on the intelligence of the inspectors to understand that security requires some measure of flexibility. If they can’t, we have bigger problems than can be solved by a document revision. Besides, DHS is required by Congress to allow individual facilities a certain measure of flexibility in determining what security measures are used to secure the facilities.

Tuesday, May 3, 2011

Link to DHS-FBI OBL Threat Bulletin

SECURITY WARNING: Based upon the ‘WIKI Leaks Doctrine’ viewing this blog or the referenced document on a government computer or by a person with federally authorized access to unclassified but sensitive information may result in Federal government reprisals including revocation of access rights. FOUO information is being discussed.

In an earlier blog about the potential terrorist threats arising in response to the assassination of Osama Bin Laden (OBL) I made reference to the National Journal’s quoting of a DHS-FBI threat bulletin. Thanks to the folks at PublicIntelligence.net, I now have access to ‘an apparent draft version’ of that bulletin that was apparently distributed within the law enforcement community.

You can see that there is not much more information than I have included in my two blog postings about the death of OBL. It certainly is clear, based upon this information, that Secretary Napolitano is correct in maintaining that the current information does not warrant an alert under the new National Terrorism Alert System (NTAS). But neither does it mean that high-risk facilities should ignore the increased possibility (how ever minor) that one or more attacks could reasonably be expected to occur (‘to be attempted’ might be a better word choice) in the next couple days.

Bin Laden Security Alerts

Early yesterday morning when I first wrote about Bin Laden’s death I wrote that DHS would not be raising the alert level under the new National Terrorism Advisory System (NTAS). In a press release later yesterday Secretary Napolitano reiterated what I said in my blog, noting that:

“We remain at a heightened state of vigilance, but the Department of Homeland Security does not intend to issue an NTAS alert at this time. I have been clear since announcing NTAS in January that we will only issue alerts when we have specific or credible information to convey to the American public. However, our security posture, which always includes a number of measures both seen and unseen, will continue to respond appropriately to protect the American people from an evolving threat picture both in the coming days and beyond.”
At the same time the National Journal was reporting that DHS and the FBI have privately communicated an alert to law enforcement personnel. They report that the communication states:

“Attacks might originate with al-Qa‘ida Core elements in the tribal areas of Pakistan, with one of their affiliates overseas, and/or with individuals in the homeland sympathetic to the cause but lacking a formal group association”.
There was even an unconfirmed TWITTER® report that the Marsec level in the Houston area chemical facilities had been increased to Marsec 2.

Does all of this mean that the new NTAS is inadequately responding to an increased threat level? That information is being withheld from the American public? I don’t think so.

Near Term Threat

First off, it is much too soon for the intelligence and law enforcement community to have developed any specific information about planned retaliatory attacks by al Qaeda or its loosely affiliated organizations. It is probably too early for any such plans to have actually been formulated, much less for them to have started their execution.

No what is of immediate concern now is the potential actions of individual wackos who are personally offended by the actions taken against Bin Laden. Since they are individuals, their planning process (such as it is) is certainly abbreviated and they are more able to quickly execute retaliatory attacks. But, then again, they are much less likely to execute effective attacks against secured facilities; not that they wouldn’t try, just that they wouldn’t be expected to be terribly effective.

Over the next couple of weeks the potential threat of retaliatory threats will begin to change. Small affiliated groups and homegrown wannabe groups will start to put into place small, limited attacks that were previously conceived but not yet initiated. While these attacks will be of limited scope they will be more likely to be successful, especially when they are directed against soft targets. The intelligence and law enforcement communities are certainly watching for indicators of such attacks. DHS can be expected to release appropriate alerts when warranted, but most often the public pre-attack notification about such events will be the same reports of arrests that we have been seeing over the last couple of years.

Longer Term Retaliation Threat

The threat of real retaliatory attacks, attacks conceived and planned in response to the assassination of Bin Laden, will not start to materialize for a couple of months at least. The attackers will want to make a definitive statement, so large, well planned attacks will be increasingly likely. It is the threats from these attacks that we will, hopefully, see reflected in NTAS alerts.

Before these NTAS alerts are issued, however, security managers at high-risk chemical facilities and other high-value targets should be on increased vigilance for reconnaissance type activity that would presage a potential attack on their facility. Any successful terrorist attack, either by the professionals of the core al Qaeda group and its major affiliates or by the homegrown wannabes, will be preceded by repeated reconnaissance. Detecting that planning operation will be the key to preventing the attack.

So, while there is no specific threat that DHS can report using the NTAS, vigilance should be increased at all high-risk chemical facilities. Immediate attacks are unlikely, but reconnaissance for potential future attacks should be closely watched for.

Friday, April 29, 2011

Revising RBPS 13 for NTAS

I have been mentioning for the last couple of weeks now that ISCD needs to revise the Risk-Based Performance Standards Guidance document to reflect the change from Homeland Security Advisory System (HSAS) to the new National Terrorism Advisory System (NTAS) that was implemented earlier this week. Of course it is easy to complain about someone not doing something; it is more productive to actually suggest something so that is what I am going to do.

I’m going to do a minimalist revision of the RBPS 13 section of the Guidance document; keeping as much as possible the DHS-ISCD flavor of the document. I’ll explain the changes as I make them here in the blog and then I will post the revised version on my web site. Then, I’ll open the floor to a public discussion. We’ll do the same with the Metrics at the end of the section in a separate blog.

Cut and Paste

The first thing we will do is to use the cut and paste feature of the word processing program to replace ‘Homeland Security Advisory System’ with ‘National Terrorism Advisory System’. Next we will do the same with ‘HSAS’, replacing it with ‘NTAS’. Then we will replace references to ‘Color-coded Threat Level System’ with ‘National Terrorism Advisory System’. Then we go back and remove redundant references to ‘NTAS and ‘National Terrorism Advisory System’. We also removed the changes made in the name of the ASIS reference at the end of the section.

Explanation of NTAS

Next we would remove the section describing the out-dated ‘Color-coded Threat Level System’ and replace it with a description of the NTAS Alerts from the NTAS Public Guide.

Discussion of Sample Security Measures

We will change the description of the conditions that call for the additional security measures, replacing the ‘High Condition (Orange)’ description with one reflecting an ‘Elevated Threat Alert’. The second category; ‘Severe Condition (Red)’ description will be replaced with one for ‘Imminent Threat Alert’.

Length of Period of Elevated Threat Level

One of the major changes in moving from the HSAS to the NTAS systems is the elimination of open ended periods at elevated threat levels. The NTAS system includes a requirement for specific time limits that are included in the Alert when it is issued. While it is still possible to be at an elevated threat level for a lengthy period of time (probably only measured in weeks), it will remain at the specified level only for the specified time. The discussion under the section for the ‘Length of Period of Elevated Threat Level’ will be revised to reflect this change in philosophy.

References

Finally, we will change the URL for the DHS web site for the advisory system to reflect the new URL for the new NTAS system.

Minimal Revision

The revision described here is a minimal change to the RBPS 13 section of the Risk-Based Performance Standard Guidance document. The only things changed were those necessary to properly reflect the change in the DHS advisory system from the old color-coded system to the new system of National Terrorism Advisory System Alerts

It wasn’t a difficult re-write; it took less than two hours of work. Of course in the ISCD environment there would be multiple levels of approvals that would require at least a couple of additional re-writes. Then there would be the public publishing and comment period that would extend the time necessary to actually require facilities to implement the change.

One would like to think that the work on the RBPS 13 revision was started shortly after Secretary Napolitano signed off on the revised alert system. That would have allowed for the shortest amount of time where there would be discrepancies between the provisions of the advisory system and the requirements for the CFATS site security plan. Maybe this will allow ISCD to catch up.

Monday, April 25, 2011

NTAS and Enhanced Security Planning

This weekend I did a blog posting on enhanced security planning, or contingency planning, looking at the reasons that it is important to have these plans in place and providing some examples of what might be included in that planning. Today I would like to take a look at how enhanced security planning should work with the new National Terrorism Advisory System (NTA). For high-risk chemical facilities tying these two things together is an important component of the facility site security plan and meeting the standards (yet to be revised) of RSBP 13.

NTAS

Officially starting tomorrow, the NTAS replaces the old, and controversial, color-coded Homeland Security Advisory System. Instead of the old five levels of the HSAS, the NTAS will see DHS issuing specific alerts that will come in two levels; elevated and imminent. Then new alerts will include specific information about the duration, potential targets, and other details of the threat. An example of the alert format can be found on the NTAS website.

Copies of current alerts will be found on the NTAS website. Individuals and organizations can sign-up to receive information on these alerts via email, Twitter® and Facebook®.

Since these alerts are public information, they will not include classified information. I would like to assume that ISCD has made some sort of provisions for providing detailed information, including classified information, about threats to CFATS facilities, either by chemical, industry or specific facility. Though, since ISCD is a program enforcement organization, they might not be included in the intelligence loop. Additionally, there is the problem of sharing classified information with un-cleared personnel; I have heard nothing about efforts to obtain security clearances for security officers at CFATS facilities.

CFATS Facilities and NTAS

Generally speaking a CFATS covered facility can expect to be affected by an NTAS alert under three circumstances; an alert for a geographical area, an alert for their industry, or an alert for their specific facility. With each alert coming in two possible levels that makes a minimum of six NTAS alert situations that need to be addressed in the RBPS 13 portion of the site security plan.

Of course the situation can get a lot more complicated for facilities with multiple COI especially if they cover more than one type of hazard. For example facilities with both a theft/diversion problem and a release toxic threat might expect to have separate enhanced plans for each under the facility specific and industry specific alerts.

Saturday, April 23, 2011

Enhanced Security Planning

Well, unless you were living way further out in the backwoods than I do, you have undoubtedly heard about the new Homeland Security National Terrorism Advisory System (NTAS) that was announced this week by Secretary Napolitano. If you’re associated with the CFATS program you will also be aware of the thundering loud silence from ISCD about how to adapt the RBPS 13 portion of your site security plan to the replacement for the old color-coded HSAS system that formed the basis for RBPS 13 in the Risk-Based Performance Standards Guidance document.

To be fair to Director Driggers, he and his staff have larger problems to deal with. Besides, there is probably no one left in the Directorate that was part of the team that wrote the guidance document in the first place. So with that in mind I’ll give a little support and update the comments that I posted earlier this week.

Why is Enhanced Security Planning Necessary?

I don’t need to tell security managers working at CFATS-covered facilities that security equipment, personnel, training and maintenance are very expensive. And with the realization that no security system is impregnable, there is always one more widget that can improve the situation. Unfortunately the rate of return (increased security/dollar spent) on those widgets also starts to fall off rather quickly.

The dark side of security planning is that security measures are a pain in the butt. A comprehensive security system interferes with the day-to-day operation of the facility in countless little ways. Sooner or later employees, especially the good ones, will find ways to circumvent the security processes to make their jobs easier. This is especially true if there seems to be no immediate prospect of an attack on the facility; I mean, what could it hurt????

So the security planner, knowing all of this, and under pressure to keep costs down because security is not a profit center, walks a fine line in trying to have enough security in place but not too much. So they look at the threat picture for chemical facilities (or whatever facility, this applies to everyone, but we are the chemical security community here) in the United States and its easy to see that the vast majority of terrorist attacks in the last ten years have been executed by less than effective terrorist wannabes.

Now this is good news as wannabes are much easier to defend against than the al Qaeda A team. To be on the safe side you plan your defenses for the Wannabe All Stars. You get that program in place, you train and practice, just to keep everyone sharp and everyone stays happy. And you have a facility security system that will deter, detect and delay the wannabes; the best of the wannabes maybe, but still wannabes.

The smart facility security officer knows, however, that the counter-wannabe security plan isn’t really good enough to prevent someone with truly evil intent, determination and a decent level of training and equipment from walking right through the security measures and capturing the flag. Hopefully it will be good enough to convince the A Team (from what ever league; trust me there are more evil doers than just al Qaeda out there) to go play at the next plant down the road with less proficient security.

No security manager worthy of the title can rest with just a defense against wannabes. They loose sleep at night worrying about what happens if they win the terrorist-site-selection lottery; if the A Team moves them to the top of their hit parade. Then the intelligence pukes (security guys and intel guys never really get along, they don’t trust each other too much) drop a message in the in-box saying that the bad guys have been talking about how lovely your facility would be with a large fireball in the center of the tank farm. Oh, and the ‘chatter’ sounds a lot like their visit is imminent. Have a nice day.

Too bad, you have a wannabe security plan in place and the pro’s are on the way. Too late to hold committee meetings, or get security upgrade requests onto the CEO’s desk for approval. Hell, the security widget salesman has heard the same news and isn’t returning your calls; he doesn’t want his product associated with a successfully attacked facility because his widget was half-installed. Besides, your insurance company is not going to pay the net-30 invoice anyway after the smoke clears.

Now, if you had a plan in place for how to deal with the pro’s; with all the approvals signed and purchase orders okayed, with everyone read in on what they had to do when you screamed ‘the A-Team is coming’; then you just might have a chance. If not, then just have them chisel your resignation letter on your headstone.

How do you do Enhanced Security Planning?

First off, you have to realize that security planning, just like any other kind of planning never stops. In production planning for instance, you formulate your plan then you monitor production and orders and modify your plan accordingly. In security planning you hope you never have to actually execute your A-Team plan. So to maintain proficiency you keep making new plans all of the time. Each new plan makes you more proficient at the planning and response process and makes you look at your overall site security plan from a slightly new perspective.

So the first thing you do is to identify your most important target at the facility. Then you determine the most common way that an A-Team terrorist would attack that target. Then you formulate a plan to counter that attack; simple enough, right? Oops, I forgot to tell you that you have to plan for 24-hour notice of the impending attack (hope you get more, pray you get at least that much), so scratch installing a new building around that target as part of your A-Team response plan.

So, you are going to have to depend on security upgrades that can be put in place quickly. Typically this is going to mean increased security personnel and changes to procedures. Installation of fixed equipment is too time consuming and expensive. If the supporting security company has portable security devices/equipment that can come into the facility when needed, this should certainly be examined. For the most part, however, the security equipment you have when you receive The Call, is what you are going to have to deter, detect and delay the attack.

Perimeter Patrolling

One good thing to remember in this planning effort; if you are within 24-hours of being attacked by the A-Team, you are under surveillance. They want to succeed real bad (at least as bad as you don’t want them to succeed) so they are not going to take chances that a small last minute security change will disrupt their attack plan; this is how they got to be the A-Team.

This means that visible up-grades to perimeter security are almost always a good idea. The fastest, easiest and cheapest security upgrade is increased patrolling inside and outside of the perimeter. The folks outside should be looking for the watchers; identify them, catch them, or disrupt them. If they are more worried about their own security than upgrades to your security you have probably prevented a successful attack. Oh, and don’t forget to include increased police patrols as part of your outside the perimeter patrol plan; they are very cost effective.

The increased interior patrols will make it harder for the A-Team to avoid early detection in their penetration of the facility perimeter. Just remember to keep your patrols following random routes and random patrol frequencies. This makes it harder to figure timing necessary to avoid even the increased patrols. You’re never going to have the funds or manpower necessary to eliminate all patrol gaps; adequately (not perfectly; see my blog on randomizing security patrols) randomize your patrols so that the attacker can only identify an adequate patrol gap after it has effectively closed.

Interior Patrolling and Guard Posts

Most high-risk facilities, in a low-risk, wannabe-threat environment are not going to need security patrols roving through operational areas of the facility. Nor will they typically feel a need to have much in the way of internal guard posts. These security tools are just too much of an intrusion into production areas and get in the way. They also require much more in the way of chemical hazard communications training for the guard force.

With the A-Team outside the gates, however, this is going to be the only real cost-effective way of increasing the delay factor inside of the facility perimeter. Again, you have to remember that you are being watched. In this case the counter surveillance tactics work just a little bit different. You probably want the A-Team to know that you have increased the number of security personnel inside the perimeter; have the new security personnel show up in a van or bus for instance. You almost certainly don’t want them to know where the security personnel are at or what they are doing. If you are using internal patrols, the patrol plan needs to try to keep them invisible from outside of the security perimeter as much as possible.

If you are going to use security patrols in the operational areas of the plant, they need to be adequately protected against the production hazards found in those areas. This will mean the proper issue, fitting and use of personal protective equipment as well as being trained to be able to detect the specific hazards associated with the areas in which they are operating. This argues for not using new security personnel for this type duty. There are two obvious solutions; first use the newbie augmentation personnel on perimeter duty and facility experienced personnel for internal patrols; or have production personnel accompany these internal patrols to help keep them out of operational harms way.

Internal guard posts are much trickier to use than it would seem at first glance. Putting a guard out in the middle of nowhere, even with communications, is inherently ineffective. A guard post is only going to be effective when there is a physical structure that naturally channels attacking forces through that point and the guard has some way of controlling movement through that area of restricted movement. Typically, this is a locked door or gate that the guard controls.

If an attacker must mover through that portal to effectively complete their assault, this makes the security guard an obvious target. Protecting the guard from attack increases the effectiveness of the portal at preventing unauthorized access. Using video cameras and electrically operated locks makes a door monitor in the security control room effectively a guard post at that portal.

One last thing to remember, to a trained combatant, a wall is just slightly more of an impediment to entry than a closed, unlocked door. If you’ve ever seen a violent drunk put a fist through a wall, you have a good idea of what I mean.

Executing the Plan

Now there are certainly other tools and techniques that can be used for enhanced security measures and I’ll discuss some of them in upcoming blogs. I certainly would like to hear from the community on their unique ideas about temporary security measures that can be easily put into place at relatively short notice during periods of high threat. But for the purposes of this discussion this should be enough to take a look at how these increased patrolling measures can be put into a enhanced security plan and executed when The Call is received.

First off, the resources to implement the plan need to be carefully determined. Lets say that it will require two three-man patrol teams and a patrol supervisor on each shift to execute the enhanced perimeter patrol plan. Every facility that I have seen uses an outside security company to provide their security guards. The security company contract would then need to be modified to include the responsibility for providing the augmented security force on some sort of minimal notice. I would also include provisions for periodic implementation for short periods to exercise the augmentation plan for training and evaluation purposes.

Where increased police patrols are made a part of the external patrol plan the same sort of agreement needs to be reached with the local police department. One doesn’t normally contract for these services (someone please correct me if I’m wrong), but some sort of written agreement is certainly in order, if just to clarify the requirements.

Then when the call comes in, the facility security manager makes a single call to the security company and says ‘execute security augmentation plan 14’ or something simple like that that allows for immediate movement without a lot of discussion. A similar call is made to the local police department. And everyone starts to move into the higher security mode called for in the facility site security plan.

A Fast Response is better than the Right Response

OOPS. The Call says that it is a group of radical defenders of the lives of Rainbow Darters in a nearby stream that will be attacking not al Qaeda. This group is not interested in attacking your tank of tetramethyldeath (the tank that you identified as your number one target), rather they are after a storage tank where you store a flammable chemical that interferes with the breeding instincts of the Rainbow Darter. The Call goes on to explain that this is the A Team of radical environmentalists with skills and training comparable to anyone that the radical jihadists could send at you.

Oh my, that tank was never considered to be an enhanced target. Oh my, what to do? Don’t sweat it. Initiate the plan for the tetramethyldeath storage tank. Get the cavalry on the way. You can modify the internal patrol plan as necessary (if it was considered necessary in the first place) and the perimeter patrol plan is almost certainly fine without modification other than to tell everyone to look out for hippies in t-shirts and ratty-jeans instead of ‘arabs in flowing desert robes’ (Oh, you didn’t assume that al Qaueda would look like someone out of Lawrence of Arabia? Good for You).

There is an old military adage that says “No plan survives contact with the enemy”. No plan is going to properly predict what the attacker is going to do. The important thing to remember about any sort of contingency planning is that it is easier to modify an existing plan than it is to start a plan from scratch. The important thing is to get people responding and moving. Just the arrival of additional security personnel on the site may be enough to prevent an attack from taking place. This is why enhanced security planning is so important.
 
/* Use this with templates/template-twocol.html */