Showing posts with label PSP Tool. Show all posts
Showing posts with label PSP Tool. Show all posts

Monday, March 14, 2016

PSP User Manual – Potential Problem Solutions

This is part of an on-going series of blog posts about the new Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety plan (PSP) User Manual. This manual sets forth the instructions for using the new PSP tool in the on-line Chemical Security Assessment Tool (CSAT). Other blogs in this series include:


Potential Problems Identified


Back in in early January, after DHS published their PSP program notice in the Federal Register, I wrote a blog post about potential problems with the system as it was explained in that notice. The potential problem areas identified in that post include:

• Multiple facilities
• Facility turnaround contractors
• Local delivery drivers
• Electronic access
• False positives

As expected, the User Manual did not specifically address any of these problems. It did, however, provide information to help resolve three of these problems; multiple facilities, facility turnaround contractors and electronic access.

Multiple Facilities


As long as all corporate facilities all have a single authorizer (the most likely situation), the PSP can be set up so that the Corporation Group would be a single account listing all company personnel with access to any of the covered facilities within the company. The Corporate Group could have a single submitter to support all facilities or individual submitters from each of the covered facilities. The latter would allow for a person at each covered facility who was able to review all of the personnel for whom PSP data submissions had been made.

If the company set up separate Groups for each facility that would still allow the Corporate Group to be set up for personnel from headquarters that could be visiting any of the covered sites within the company and might require unaccompanied access as ‘visitors’. Unfortunately, there would be no one at the facility who could verify data submission on those personnel in the Corporate Group, because the local Submitter would not have access to the Corporate Group data and one person cannot be a Submitter in multiple Groups within the same company.

A way around this would be to make someone else at the local facility a Submitter on the Corporate Group. Another way around the problem would be for HR to forward a completed template spread sheet with the required information for those company personnel that might be visiting the covered facility for that facility Submitter to upload to the local facility Group.

Facility Turnaround Contractors


The new PSP CSAT tool provides an easy solution for the problem of facility turnaround contractors without having to require possession of a TWIC or HME. The Authorizer can set up a Group for the main contractor responsible for turnarounds with a Submitter from that contractor.

The contractor would then be responsible for uploading the individual data for all personnel who would be working on that site. The contractor could then provide a status report for that facility that showed that all personnel data had been submitted. That document would, of course, be a Chemical-terrorism Vulnerability Information (CVI) protected document. The facility could then prepare a sign-in/sign-out sheet to help keep track of the contractors on site. As long as the sheet did not reference the PSP program or PSP status, this would not be a CVI protected document.

Electronic Access

Facilities that are going to allow vendors routine electronic access to physical components of control systems, building access systems, or security monitoring systems for maintenance purposes are going to have to include the vendor personnel who will have that access in their PSP program. This would require that they be set up as a separate Group on the PSP tool. Again the Authorizer would set up a vendor employee as a Submitter for that Group and establish an oversight Submitter from the company so that there would be someone in the company that could verify that data had been submitted.

Oversight Submitter


In a couple of places above I have suggested that the Authorizer establish a company employee as an ‘oversight Submitter’ on Groups that are being used to submit data on personnel who are not company employees. The idea here is that there would be someone from the covered facility that could access the Group data on the PSP tool to verify that an individual’s data had been submitted to the PSP tool prior to allowing that person access to a covered facility.

This is somewhat complicated by the fact that a person can only be a Submitter on one group under a given Authorizer. Small facilities could quickly run out of people who could verify the PSP status on multiple contractor or vendor Groups.

What is really needed is for the tool to be modified by adding a PSP Reviewer position. A reviewer would typically be the Security Manager or person fulfilling that type role on a local basis. The Authorizer could then specify multiple Groups within the company that each reviewer would be authorized to access to verify the submission status of contractor, vendor or corporate personnel desiring unaccompanied access to the critical areas of the facility.


The way things are currently structured in the PSP tool there is only one person who has access to the PSP status of all personnel in multiple groups; the Authorizer. It does not make any kind of sense in having a corporate officer put in the position of potentially having to be available at all hours to verify that someone has been properly vetted through the PSP program.

Wednesday, March 9, 2016

PSP User Manual – Miscellaneous

This is part of an on-going series of blog posts about the new Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety plan (PSP) User Manual. This manual sets forth the instructions for using the new PSP tool in the on-line Chemical Security Assessment Tool (CSAT). Other blogs in this series include:


Initial Access to PSP Tool


The Authorizer for the facility will be provided initial access to the PSP Tool once ISCD has either authorized or approved a site security plan that includes provisions for meeting the requirements of 6 CFR 27.230(a)(12)(iv). Most facilities with authorized or approved site security plans were initially approved with a condition that they would have to revise that SSP once ISCD had put processes in place for the vetting of facility personnel and unaccompanied visitors against the Terrorist Screening Database (TSDB).

So once facilities have revised their SSPs and those revised SSPs have been approved, the PSP tool will be opened for the Authorizer. Presumably all SSPs authorized and/or approved in the future will include PSP provisions so the PSP tool will be opened when the SSP is authorized or approved. Remember, facilities that used the Enhanced Approval Process did not have to go through the authorization process.

Option 3 and Option 4 Procedures


Facilities that opt to use only Option 3 (Electronically Verified TWIC) and/or Option 4 (Other DHS Vetted IDs as Flash Passes) procedures are not required to submit information on those personnel thru the PSP Tool, so access to the tool will not be provided to those facilities. For facilities that use a combination of validations process that do require access to the PSP Tool will not need to enter information on personnel vetted under Options 3 or 4.

The PSP User Manual does not include any instructions on how to implement Options 3 or 4.

Bulk Uploads


As promised by ISCD provisions have been made to allow facilities to submit lists of names under Option 1 or Option 2 via spread sheet. This is done to both reduce the time on-line and to provide an easier means for personnel to do error checking before the data is submitted to the CSAT tool. Templates (in either .XLS or .XLSX formats) can be downloaded from the respective Option 1 or Option 2 ‘Affected Individuals’ tab on the PSP tool.

There is no mention of a minimum number of personnel that have to be listed on the template to use the bulk upload procedures. It looks like that even for just a couple of entries, it might be easier to use the bulk upload technique than by inputting the information by hand.

Data Validation


Appendix B in the User Manual provides detailed descriptions and data validation requirements for each of the data elements that will be submitted. If you are using the Bulk Upload technique described above, the data validation requirements should already be part of that formatting of the templates.

Even if you are not going to be using the bulk upload technique, it might come in handy to download those templates for data collection purposes. That way the Submitter should not have to worry about data validation issues when inputting the information into the PSP tool. In fact, those templates could be used to cut and paste information into the tool if they are not going to be used for bulk uploads.

No Longer Has Access


ISCD has included a data field in the Option 1 and Option 2 data submission to allow a facility to notify ISCD when an individual no longer has access to the covered facility. Congress specifically forbade {6 USC 622(d)(2)(i)} ISCD from requiring facilities to make a second data submission on any covered individual. Having said that ISCD is encouraging facilities to submit this information as it allows ISCD to stop completing periodic verifications of TSDB status (actually lack thereof) for Option 1 individuals or continuing to periodically verifying the ID status of Option 2 individuals when those individuals who are no longer covered by the program.

ISCD did make clear in their December Federal Register notice that individuals that have left a facility where no notification to DHS has been made of their no longer being covered individuals may seek Privacy Act redress to get their names removed from the PSP Tool.

Manage Alerts


There is a tab on the PSP Tool labeled ‘Manage Alerts’. This allows the facility to select if it will receive email alerts from the system about individual status in the PSP process or if the facility will just be alerted when they sign on to the tool. Unfortunately, this has nothing to do about the facility being notified if an individual whose data was submitted to the PSP appears on the TSDB; those notifications may be handled by law enforcement or DHS at the discretion of the Department of Justice.

The alerts provided in the PSP tool are limited to:

• Record – Submitted: (Option 1 and 2)
• Record – Verified: (Option 2)
• Record – Not Verified: (Option 2)
• Record – No Longer Verified: (Option 2)
• Record – Verification Pending: (Option 2)


The ‘Not Verified’ and ‘No Longer Verified’ alerts will require the facility to take actions that were outlined in the revised SSP.

Monday, March 7, 2016

PSP User Manual – Groups and Submitters

This is part of an on-going series of blog posts about the new Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety plan (PSP) User Manual. This manual sets forth the instructions for using the new PSP tool in the on-line Chemical Security Assessment Tool (CSAT). Other blogs in this series include:


Groups and Submitters Overview


Again, because the PSP tool involves the handling and access of personally identifiable information (PII) steps have to be taken to ensure that only those personnel with a need-to-know have access to that information. With the multiple ways that information may be submitted ISCD set up the PSP tool to require the formation of Groups and to only allow designated personnel to view the PII of personnel within that group. This required the establishment of PSP Submitters (separate from the Submitter used in other CSAT tools) so that a single PSP Submitter would only be able to access PII from the Group to which they are assigned.

Groups


As a default every CSAT account will initially have a single Group; called the Corporation Group. If a PSP Submitter(s) is authorized to have access to the PII on all of the affected personnel at a facility, then only the Corporation Group is necessary. However, if a facility is going to have to submit data on contractors or other companies, then it is likely that other Groups will have to be created. Or if a facility is going to use an outside company to submit data of facility personnel, but corporate HR will be submitting data on personnel from other facilities, then multiple Groups will probably have to be established.

The User Manual explains it this way:

“The Department expects an Authorizer will carefully consider the best group structure so information about affected individuals can be protected from unauthorized disclosure. Specifically, the Department expects the Authorizer will create one or more groups if needed so PSP Submitter(s) will (1) have access to only those records about affected individuals they should have access to, and (2) not have access to those records about affected individuals they should not. Several examples of how groups might be constructed to align with a facility’s (or its designees’) business operations are provided in Appendix C [pg 24]. It is also possible that the best group structure for some facilities may be to not create any additional groups at all and rely on the default “Corporation” group.”

 The User Manual provides instructions on how to:

• Create a Group (pg 11);
• Edit a Group’s Name;
• Merge a Group in to the Corporation Group; and
• Remove a Group

PSP Submitters


As I noted earlier the PSP Submitter(s) will be entering PII into the PSP tool for all data submissions under Option 1 (Full data submission) or Option 2 (Data submission on holders of DHS vetted ID). This is a separate CSAT position from the Submitter who has been submitting data in the Top Screen, Security Vulnerability Analysis (SVA) or Site Security Plan (SSP) tools in CSAT. A Submitter may be assigned to the role of PSP Submitter. For the rest of this post I will be referring to the PSP Submitter as ‘Submitter’.

When a facility first tries to access the PSP tool, the only person that will be able to effect that access is the Authorizer. The Authorizer can submit data in the Corporation Group (and only that Group) so it is possible that a facility may not need to have a Submitter. More likely, however, we would see the Authorizer designate a Submitter for the Corporation Group and any other Groups that the Authorizer sets up.

The important thing to remember is that a Submitter can only be assigned to a single Group and will only be able to see or submit data for that Group. This is going to have to be taken into account as Groups are established.

For companies that have multiple CFATS covered facilities under a single Authorizer should remember that the Corporation Group for the Authorizer would appear to apply to all facilities under that Authorizer (though this is not explicitly stated in the User Manual). Separate Submitters could be designated for each covered facility under the Corporation Group, but they would be able to see the PII for all individuals from any facility submitted under the Corporation Group.

Submitters from outside of the company may be designated. This would be useful when an outside organization is doing the data submission for a facility or when contractors/vendors are doing data submissions for their employees that would have access to the facility. The Appendix C description of Group organization would seem to suggest that DHS would prefer to see these outside organizations submitting data under separate Groups. This would certainly make sense where more than one outside organization would be submitting data, as it would limit the visibility of the PII to those for whom the organization had submitted data.

PII Liability


While all submitters are going to be governed by the Rules of Behavior (ROB; discussed in the previous post in this series) about access to the PSP Tool and the data contained in that tool, facilities will do well to remember that the data collected prior to data submission is also covered by Federal, State, and local privacy and data protection rules. Since the data that the Submitters are entering into the system is not yet covered by the ROB, the Submitters need to be fully trained about, and in compliance with, those other rules.

Commentary


For many facilities the single Corporation Group with a single Submitter will certainly be sufficient. The larger the organization the less likely that is going to be true. For companies with multiple locations and a number of contractors and vendors that require unaccompanied access to critical areas of the facility, I seriously suggest that the corporate security manager set up a meeting with all of the affected facility security managers and DHS Chemical Security Inspectors to try to work out the details of how the organization is going to organize its PSP data submission program. This meeting needs to be done early in the process; it would probably be best done before the SSP revisions are made.


Remember, it is fairly easy to set up Groups. If you end up setting up too many Groups initially, you can always reduce the number of groups by merging them later. Setting up new Groups after data submission has started will be very difficult as there is not currently any method for moving some data from one Group to another.

Sunday, March 6, 2016

PSP User Manual – Rules of Behavior

This is part of an on-going series of blog posts about the new Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety plan (PSP) User Manual. This manual sets forth the instructions for using the new PSP tool in the on-line Chemical Security Assessment Tool (CSAT). Other blogs in this series include:


Rules of Behavior Overview


Before we can start to talk about access to the PSP tool a new concept needs to be addressed; the DHS CSAT Personnel Surety Application Rules of Behavior (ROB). Because personnel with access to the PSP tool will be dealing with personally identifiable information there are certain rules of behavior that DHS has established as part of its Privacy Impact Assessment (PIA) that covers the operation of the PSP tool. The rules of behavior are spelled out in Attachment 3 to the PIA. Whenever an authorized user accesses the PSP tool they will be required to review and acknowledge the ROB as part of the sign-on process.

The ROB includes the following sections:

• Application access;
• Passwords;
• Data Protection; and
• Incident reporting.

Access and Passwords


The first two sections in the ROB are items about which every CSAT user should already be aware. The CSAT tool is on a Federal government computer system and access is provided for specific reasons. Unauthorized access or unauthorized use beyond what is specifically required is prohibited.

The use of a password is required to access that system and DHS has set standards for passwords and their protection. There is nothing really new here as the same passwords are used for access to all parts of the CSAT tool to which a user is authorized access.

Data Protection


CSAT users should be well versed in the information protection standards for Chemical-Terrorism Vulnerability Information (CVI). Unlike other portions of the CSAT tool, the information in the PSP tool is not specifically protected by the CVI standards. Instead the DHS rules for protecting personally identifiable information apply to the information in the PSP Tool. The DHS Handbook outlining these required protections can be found here.

That 30-page Handbook is the governing document for PII data protection but the ROB specifically highlights four specific standards:

• Encrypt or password-protect electronic files containing sensitive PII.
• When there is a need to print, copy, or extract sensitive PII from a larger data set,
limit the new data set to include only the specific data elements needed to perform
the task at hand.
• Physically secure sensitive PII (e.g., in a locked drawer, cabinet, desk, or safe)
when not in use or not otherwise under the control of a person with a need-to-know.
• If there is a need to create duplicate copies of sensitive PII (e.g., a PDF Report of
detailed PII about affected individuals) to perform a particular task or project,
delete or destroy any copies (e.g., using a shredder) when they are no longer needed.

The DHS handbook should be referred to for more details about requirements for protecting PII:

• In the office, or while traveling or teleworking
• On a portable electronic device, such as a Blackberry, laptop, or USB flash drive
• When emailing, faxing, or by other electronic transfer
• When mailing externally, overseas and inter-office
• When storing on a shared drive or SharePoint

Incident Reporting


The CFATS program has specific requirements for reporting security incidents at covered facilities. The incident reporting standards in the ROB are separate from the standard CFATS reporting requirements because the ROB, again, is dealing with separate security requirements for PII. Some of the ROB incidents may require dual reporting under both standards.

The ROB requires reporting for two types of security incidents. Both types of incidents would be reported to the CFATS Help Desk (866-323-2957). The two types of incidents are:

• IT security incidents; and
• Privacy incidents

IT security incidents involve the compromise of CSAT username and password. It appears that the only user that would have the same password for the PSP tool and other CSAT tools would be the Authorizer. That should mean that the only IT security incident under the ROB that would also be a CFATS incident would be the compromise of the Authorizer’s username and password.

Privacy incidents would include the compromise or suspected compromise of personally identifiable information entered into or copied from the PSP tool. This would include PII emailed to the facility by ISCD. It would not seem that the information collected by the facility to complete the PSP submission would be considered in privacy incidents in the ROB, though it would still be covered by Federal, State and local privacy statutes.


With this understanding of the ROB, authorized users can access the PSP tool. I’ll discuss that access in a future blog post.

Thursday, March 3, 2016

DHS Publishes PSP User’s Manual

This morning the DHS Infrastructure Security Compliance Division (ISCD) published a link on their Chemical Security landing page to the new manual for the personnel surety program tool for their on-line Chemical Security Assessment Tool (CSAT). The new manual is the CSAT Personnel Surety Program (PSP) Application Users Manual. This manual describes the new PSP tool and how it will be used by CFATS covered facilities in meeting their site security plans personnel surety requirements under 6 CFR 27.230(a)(12)(iv).

The 36-page booklet describes the new tool and how to use it. Sections include:

• Privacy;
• Getting started;
• Logging in;
• Application menu;
• User roles;
• Submitting information about affected individuals;
• Manage alerts;
• Administration of accounts; and
• User defined fields

I’ll be going into the information provided in the manual in more depth in a future post. Facility security managers need to remember that they will be informed by ISCD when their facility will be starting the implementation of the PSP program and revising the site security plan and getting that revision approved will be the first step in implementation. ISCD has also stated that they plan to make Chemical Security Inspectors readily available to assist in the implementation process.


The take away from today’s release of this important new CSAT manual is that reviewing the manual’s description of how the PSP tool will operate should make it easier for each facility to decide which combination of the four PSP processes will work best for that facility.

Monday, February 24, 2014

30 Day CFATS PSP ICR – Remote Access

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


Since control systems, security systems and business networks will likely be on the list of critical assets for most facilities (depending on which DHS chemicals of interest – COI – are present) personnel with access to these systems will almost certainly require vetting under the site personnel surety plan as it is difficult to imagine when such access would be not be considered unaccompanied.

Remote System Maintenance

Most complex cyber systems (which certainly includes control systems) now comes with the option for remote system maintenance support. CFATS covered facilities that utilize such options have an obligation to ensure that the vendor’s personnel who have such access are properly vetted under the facility’s PSP. This would appear to be another instance where the background check agency provisions (discussed in the last post in the series) of the ICR would come into play.

Since there is no way that the facility will actually know which individual is remotely accessing the facility’s computer systems there will have to be some shifting of responsibility to the vendor. This would have to be done through some formal document like a memorandum of understanding and this would have to be included in the facility’s site security plan so that ISCD could review the provisions as part of the SSP authorization and approval process. This would also mean that changes in vendors would have to be reported to ISCD as part of the ‘material change’ provisions of §27.210(d), §27.215(d) or §27.225(d)(2).

Remote Monitoring

Many facilities will opt for the use of off-site security monitoring programs. Since such monitoring programs will be a significant part of the security apparatus for the facility it will certainly fall under the critical area rule requiring vetting under RSPB #12. Again the vendor providing such services would most likely fall under the Background Check Agency provisions described earlier. Again, there would have to be some formal document in the site security plan outlining the vendor’s responsibility for conducting the vetting.


Friday, February 21, 2014

30 Day CFATS PSP ICR – Background Check Agency

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


In the previous post in the series I briefly discussed the roll of background check agencies in the PSP process as described (in passing) in the ICR. A reader asked me to expand on the idea so in this post I’ll take a more detailed look at how BGCAs will fit into the PSP processes.

Visitors

One of the major problems that many commenters have had with the PSP process outlined in the ICR is the issue of visitor’s being vetted 48 hours before they are given unescorted access to the facility. There are a wide number of folks that periodically visit chemical facilities to provide a wide variety of services. Some of these personnel are asked in on extremely short notice to provide high value services.

While the facility could get around the PSP vetting rules by providing vetted escorts for these visitors, this is frequently not a realistic option given the limited number of personnel working at many of these facilities. Relying on the escort provisions of the vetting rules would end up in many cases where there is escort in name only and facility managers are smart enough to realize this in advance of the situation arising.

Organizations that routinely provide these types of services could register with the folks at DHS as a sort of BGCA. The PII for their field support personnel would be entered into the PSP tool and would be linked with all of the covered chemical facilities that they had support contracts with. When the vendor linked an employee’s information to a covered facility, that facility would be notified by ISCD that the vetting information had been provided to DHS.

In the event that one of the employees at one of these vendors had to be assigned to a new facility on short notice, it would not be problem as long as their PII had already been submitted to ISCD. As long as there was enough time for ISCD to notify the facility that the person’s information had been submitted, the visitor would be properly vetted.

Facilities would have to have some way to identify these individuals when they arrived at the facility gate. This process could easily be established by the vendor emailing a copy of their employee’s corporate ID to the facility security manager in advance of visitor’s arrival. This information could be provided to the gate personnel as part of a daily expected visitors list. Checking the identification against that list would provide the means for closing the loop on the vetting process.

Truck Drivers

Most chemical facilities see a daily parade of local and long haul truck drivers picking up and delivering materials at the facility. In many cases it is not possible to keep those trucks away from critical areas of the facility and it is typically going to be difficult to provide an escort for a truck moving through the facility.

A large number of truck drivers already have already been vetted for their Hazardous Materials Endorsement (HME) or a Transportation Workers Identification Credential (TWIC). For reasons that I discussed in the ‘Three Options’ blog in this series ISCD is still requiring a PII submission on these folks to ensure that credential vetting is up-to-date. An alternative method is provided for the TWIC folks; no data submission is required if their TWIC is periodically validated by a TWIC Reader or checked against the Canceled Card List (CCL) and the Certificate Revocation List (CRL).

Plants fully realize that they will not be able to do the required PII submissions when a truck driver shows up at their gate. The facilities will get around this by requiring all delivery companies to ensure that their drivers have been vetted against the CFATS PSP before they will be allowed to deliver or pick-up loads at the facility. Maritime Transportation Security Act (MTSA) covered facilities are already using that tactic with requiring drivers to have TWICs for similar reasons.

Trucking companies that routinely service MTSA covered facilities are going to have little problem certifying that their drivers’ TWICs are periodically validated by TWIC Readers. For companies located further from port facilities that certification will be harder to do.

Again, the trucking company could set itself up in the CFATS PSP tool as a BGCA and register their drivers. HME and TWIC holders would be entered in one portion of the tool and the remainder of the drivers in the other portion. Those registered drivers would be linked to the facilities to which they would be expected to deliver. For driver changes, all that would be necessary would be for there to be enough time for ISCD to notify the facility that the driver’s PII had been submitted.

And again, there would have to be some way to close the loop by adequately identifying the driver to the facility. This would be accomplished in the same way that I described in the Visitor’s Section above.

Contractors

Contractor is kind of an undefined term used in the ICR and the CFATS regulations. Generally speaking there are two groups of people that fit into this category. One is a large company that provides a variety of direct services to the facility under a blanket contract. These folks will almost certainly want to avail themselves of the BGCA provisions to get their people vetted. Many of these people will be moved from facility to facility as needs change so it would provide a lot more versatility to the organization if they would not have to go through a new vetting process every time they were moved.

The second kind of contractor is usually a professional that is hired individually on a contract basis for providing a specific service for a specific amount of time. The longer the expected period of the service the more likely it will be that the individual facility will handle the vetting process. For those individuals that move between facilities more frequently, it may be worthwhile to find a BGCA that provides CFATS PSP vetting services and pay them to submit his PII. In other cases it may be more appropriate for the individual contractor to handle those BGCA activities on their own.

Site Security Plan

ISCD has made clear in the ICR discussions that they intend to provide a certain amount of creative leeway for facilities to tailor the PSP program to their situation. This means that if a facility intends to allow the use of a BGCA to vet the various non-employees that periodically show up at the facility gates to work then there will have to be a decent description of how that second-party vetting process would be conducted.

ISCD also reminds folks fairly frequently in the ICR discussion that the DHS vetting against the TSDB is only one portion of the background check requirements outlined in the personnel surety Risk-Based Performance Standard. The CFATS regulations (6 CFR §27.230(12)) outline three additional types of background checks that need to be done as part of the facility PSP. Those are:

• Measures designed to verify and validate identity;
• Measures designed to check criminal history;
• Measures designed to verify and validate legal authorization to work;

The first and last of those requirements are fairly straight forward and are outlined in more general labor regulations. The second provides the facility management with a lot more leeway in what is determined to be acceptable findings in the individuals criminal history. What criminal offenses and/or times since completion of the jail time for those offenses is deemed to be disqualifying is up to the facility management.


When a facility uses a BGCA to vet some or all of their employees there needs to be clear rules spelled out for that BGCA to make those criminal history assessments. This is particularly true when non-employee vetting is being done by someone different than does the employee vetting. It would seem to be prudent to have a standard Memorandum of Understanding with each vendor, contractor or trucking company that will be serving as its own BGCA that outlines the acceptable criminal background that the facility will allow as part of its Site Security Plan.

Thursday, February 20, 2014

30 Day CFATS PSP ICR – Moving Forward

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


With less than 2 weeks left in the comment period, and no comments posted to the www.Regulations.gov web site it may be time to look at what this PSP would look like in actual practice. First, we need to remember that ISCD is only going to apply the PSP requirements to Tier 1 and Tier 2 facilities. This was done to reduce the initial work load on the new PSP system and give ISCD a chance to work the bugs out before they apply it to the bulk of the facilities. This means that another round of ICRs will be required to make that change since the current burden estimate is only based upon the participation of the Tier 1 and Tier 2 facilities.

I also understand that ICS is going to go back to their earlier rollout method of initially only requiring a limited number of Tier 1 facilities to implement the PSP. This will allow those facilities to have their Chemical Facility Inspectors (CSI) on hand during the start up to help work through any of the problems in the system. This was successfully used in the initial rollout of the Top Screen and Security Vulnerability Assessment tools.

System Design

There is going to be some time lag between the time that OMB approves the ICR and the actual implementation of the PSP tools in CSAT. This is because DHS has spent only a limited amount of time and money on developing the tools and manuals. Given the history of this program, I think that we can forgive the ISCD team for thinking that they might be required to make some changes in their current plan by the time OMB gets done with their approval process.

I think that we will see a delay of at least 60 to 90 days between the time that OMB approves the ICR and the time that ISCD announces the initial deployment of the CSAT tools and the limited initial roll out.

Registration Tool

One thing that is going to have to change is the current CSAT Registration Tool. Currently the facility registers specific people to allow them to have access to the various portions of CSAT that affects that facility. Currently the tool allows for the registration of an Authorizer (Executive responsible for CFATS implementation at the facility), Submitter (Person who actually submits completed information to ISCD via CSAT), Lead Preparer/Preparers (the folks that actually enter data into the various tools) and Reviewers (people that are authorized to look at but not touch CSAT information).

For facilities that are doing all of their own data submission in-house, there will probably be a need to add one or two folks from HR to the list of Preparers for the facility. This will not require any CSAT changes.

For facilities that are going to rely on an outside agency to handle the submission of data for their PSP, things get a bit more complicated. The easy way out (and as usual the worst way to do things) would be to authorize one person at the background check agency (BGCA) to do all of the submissions for the facility; this could be done under the current registration rules. The reason that this is the worst way to handle the registration is that we all know that there will not be just one person handling all of the data submission from the BGCA. With just one person ‘registered’ there will inevitably be login credential sharing which tends to compromise the security of the system, a system that will be handling Personally Identifiable Information (PII).

What I suspect that ISCD will do will be to allow a facility to register the use of a BGCA. The BGCA will be enrolled in the ISCD PSP and will register individual employees as Preparers for the BGCA. This will make things simpler for everybody involved. This will also allow vendors and contractors to provide information to a BGCA so that their employees that require access to CFATS facilities on a routine basis can be easily vetted for multiple facilities.

PSP Tool

With the use of BGCA I suspect that we will see effectively a dual PSP tool; one for facilities and one for BGCAs. I think that it may be listed as a single tool, but depending on how one signs in you will see two different sets tools. The basic data being submitted will be exactly the same set of PII, but there will have to be some way for the BGCA to indicate for which facility that PII will be submitted.

I would like to make a suggestion here. I think that it would be much simpler (and eliminate a number of potential errors). The BGCA should be allowed to enter an individual’s PII into the ISCD PSP tool without a chemical facility initially being listed. As they were notified by their clients (vendors, contractors and potentially even individuals) that a person was going to need to have access to a facility, they would add a facility identification number to that individual’s PSP information. Since that person would already be vetted through the PSP, the 48 hour notice would not be necessary and ISCD could send a message to the facility that the person had been vetted through the PSP.

How Long?

On March 5th, barring some unforeseen eventuality, the folks at NPPD will submit this PSP ICR request to the OMB’s Office of Information and Regulatory Affairs (OIRA). The big question is how long the approval process will take at OIRA. I have seen ICRs approved on the day of their submission, but those were either entirely non-controversial simple exercises or they were politically driven by the Administration. Neither of those applies to the CFATS PSP ICR.

A large part of the inevitable delay in OIRA is trying to work out the political bugs in the program. The more people (or the more powerful the people) that complain about an ICR the longer it will take.

I expect that we will see some negative comments from the same people that complained about the 60-day ICR. Some will go through the eRulemaking Portal, but most will go directly to OIRA outside of public scrutiny. Many of those will be politely ignored and OIRA will try to iron out compromise solutions with the complainer and NPPD/ISCD. How long that will take is anybody’s guess.


I will be very surprised if it takes less than 60 days and I would not be very surprised if it takes six month. The longer it takes past six months, however, the more likely it will be that NPPD will again have to withdraw the ICR and start all over again. I give that about a 40% chance of occurring.

Tuesday, August 27, 2013

Reader Email – PSP Terrorist Match Notifications

A long time reader with more than a little experience in government regulatory affairs sent me a brief email yesterday about my recent blog post on the CFATS personnel surety program (PSP). While agreeing with much of what I said he made the following very important observation:

However, what the public, especially industry DOES have a right to is a specific, clear SOP that the govt will follow in the event of a positive match.  There is no reason on earth why ISCD cannot provide the SOP as part of the public information package on this.  Knowing how a positive match will be handled will go a long way toward assuaging the concerns of an increasingly skeptical workforce (and public). 

I am not sure what kind of detail such an SOP would entail since much of it would depend on the response of the TSA and the FBI to each particular instance of a positive Terrorist Screening Database (TSDB) match,  but I agree that the publication of such a document would at least provide a better understanding of how the Department would address their response to such a match. That would allow for a more intelligent conversation on the topic if nothing else.

This brings up another of the frequently heard complaints about the PSP process to date. The use of the information collection request (ICR) process to introduce the program of necessity leaves a number of questions unanswered. To be fair the 60-day notice is one of the most comprehensive ICR notices that I have seen, but it is not a rulemaking notice. It certainly provides most of the information one would expect in an notice of proposed rulemaking, but it does not address all of the legal technicalities of the rule making process. I am sure that the Department’s legal staff has vetted this process, but an NPRM (which would include the ICR notice) would have made the industry feel better about the process.

I think that the folks at ISCD could make things go a lot smoother upon the publication of their 30-day ICR notice (which I expect – hopefully – in the next couple of months) if they put up a CFATS-PSP web site that showed the proposed PSP tool for CSAT, a positive match response plan, and a more detailed discussion of how TWICs would be expected to be used for both facility personnel and ‘visitors’ like truck drivers and train crews.

The more information that ISCD can provide in advance of the 30-day ICR notice the fewer and less vociferous will be complaints sent to the OMB about the ICR. Everyone has to remember that the typical OMB response to ICR complaints is foot dragging in the approval process. That would not benefit anyone, ISCD or industry, in this case. We need a way, sooner rather than later, for facilities to ensure that their workforce and visitors do not include known or suspected terrorists. 
 
/* Use this with templates/template-twocol.html */