Showing posts with label PSP. Show all posts
Showing posts with label PSP. Show all posts

Friday, September 17, 2021

CFATS PSP Note Change

Today CISA’s Office of Chemical Security (OCS) changed the ‘Latest News’ entry on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center that I reported about yesterday. It no longer mentions the ‘enhancements’ to the program, that I described in my CFSN Detailed Analysis article on the topic. The document describing the improvements is still available as of this writing.

Thursday, September 16, 2021

Review - OCS Improves Personnel Surety Program – 9-16-21

Today the CISA Office of Chemical Security (OCS) published a news item on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center announcing that they had made enhancements to the Personnel Surety Program application within the Chemical Security Assessment Tool (CSAT). They provided a link to a brief description of those enhancements and an updated PSP Instruction Manual.

As with any time that a regulatory organization changes reference documents, covered facilities need to download the new manual, even if they are ‘done’ with their initial data submission under the PSP. Old versions should be maintained to allow facilities to explain or justify what they had done before the newer manual was published.

There does not seem to be anything in this new manual that is going to require a facility to make any changes to their facility site security plan. But, if it looks like changes could be required by the new document, facilities should contact their chemical security inspector for clarification. Questions could also be submitted to the CFATS Help Desk (1-866-323-2957), but the CSI would probably be able to provide a quicker answer.

For more details on the new information, including a look at some of the changes made in the PSP manual, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ocs-improves-personnel-surety-program - subscription required.

Wednesday, June 23, 2021

Review - CISA Publishes Two CFATS ICR Revision Notices – 6-23-21

Today the DHS Cybersecurity and Infrastructure Security Agency published two information collection revision notices for the Chemical Facility Anti-Terrorism Standards (CFATS) program. CISA is soliciting public feedback on each of the notices. Both ICR revisions address editorial changes such as “updating the Agency name to conform with the Agency's new designation as CISA”. Changes in the burden estimate are being proposed in both revisions.

The two ICRs being revised are:

1670-0014Chemical Facility Anti-Terrorism Standards, and

1670-0029Chemical Facility Anti-Terrorism Standards (CFATS) Personnel Surety Program

NOTE: The first link on each line is to the Current ICR and the second is to today’s ICR notice.

CISA is soliciting public comments on both of these ICR revisions. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov, Dockets CISA-2021-0009 and CISA-2021-0003). Comments should be submitted by August 23rd, 2021.

For a more detailed look at these ICR revision requests, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cisa-publishes-two-cfats-icr-revision Subscription Required.

Monday, April 6, 2020

CFATS PSP Instructions Not Available 4-6-20


Today the Chemical Facility Anti-Terrorism Standards (CFATS) program landing page was updated with a reference to the signing into law of the  Coronavirus Aid, Relief, and Economic Security (CARES) Act. That act extended the CFATS program authorization until July 23rd, 2020. As is usual when this page is updated, I went back and reviewed some of the sub-pages to the web site, looking for changes. Instead of finding any significant changes I found that there was no longer any actual link to the Personnel Surety Program (PSP) instruction book. This would be the Chemical Security Assessment Tool (CSAT) manual for completing the PSP program submissions.

There are two different paths that people should be able to use to get to the PSP manual. Both start on the landing page. The first (and shorter path) goes:

3. Guidance Document  back to #2.

The second path goes:

5. Guidance Document back to #4

The unintended loop set up by the ‘Guidance Document’ (different links for the two apparently identical versions) in the two paths is what prevents folks from getting to the actual document. None of the other CSAT instruction manuals have a ‘Guidance Document’ link. That makes a certain amount of sense since these are not (for the most part) guidance documents, but instructions for using the on-line tools. Why the PSP instructions need the guidance document disclaimer is not clear.

I cannot tell when this manual became unavailable. For the most part DHS stopped dating their web site pages some time ago. Because of the involvement of the ‘Guidance Document’ linkage in the problem, I suspect that this dates back to the DHS implementation of Executive Order 13,891, Promoting the Rule of Law Through Improved Agency Guidance Documents, in February of this year.

By the way, I went back to the latest link that I have for the document and that returns a ‘Page Not Found’ page. This is unusual, these older links typically remain active for quite some time.

Monday, October 14, 2019

ISCD Publishes CFATS Quarterly – 10-08-19


Last week the CISA Infrastructure Security Compliance Division (ISCD) published the latest version of their Chemical Security Quarterly. Along with a large number of informational links, this version includes articles on:

CISA Leadership Updates;
House Hearing on CFATS Reauthorization;
Close-up on the Personnel Surety Program (PSP);
National Cybersecurity Awareness Month;
Chemical Sector Security Summit Presentations;
Counter Unmanned Aircraft Systems (UAS) Authorities;

PSP


Along with the brief article on the Tier III and Tier IV implementation of the PSP terrorist screening process there is a list of frequently asked questions along with the ISCD response. The article provides a nice high-level (upper management) overview of the PSP while the FAQs provide a deeper (but not too deep) dive into the mechanics of the PSP. Finally, there is a section that includes links to a number of resources on the PSP.

One minor complaint, the Chemical Security Inspectors and Compliance Analysts is a little misleading. It is just an email link to CSAT@hq.dhs.gov. A detailed email to that address will get some sort of appropriate assistance response, but not necessarily from a CSI or compliance analyst.

Counter UAS


An interesting collection of information about UAS operations in or near critical infrastructure; unfortunately, there is nothing that directly concerns counter UAS operations at CFATS regulated facilities. The reason for this is that the legal basis for counter UAS operations is very cloudy with lots of deadly lightning bolts (to extend the ‘cloudy’ metaphor) at this point, again unfortunately, that is not made clear in this article or any of the linked information sites.

CFATS Information Updates


This section provides links to new or revised CFATS resources. In this instance the ‘new resources’ includes links to a Risk-Based Performance Standard (RBPS) 10 web page and fact sheet. This RBPS concerns maintaining all records of maintenance, testing, and calibration of security equipment, as specified in 6 CFR §27.255(a)(4).

This section notes that ISCD has revised their ‘Detect and Delay’ web site and fact sheet. The changes appear to be more editorial than substantive.

I was disappointed to see this update information here and not on the CFATS Knowledge Center page when the changes occurred. The new RBPS 10 information was apparently updated earlier this month so there was no major delay there; but the Detect and Delay information was apparently updated last May. That is hardly timely information sharing. Caveat; I am predicating my ‘timing’ information on the dates provided on the two fact sheets; there are no dates on these (or most of the) ISCD web pages.

Overall Rating – Good Job


I am typically disappointed in publications like this Quarterly report. As I have noted on numerous occasions with other agencies, they are more like Corporate Annual Reports (look how great we are) rather than information sharing efforts. ISCD continues to concentrate on information sharing rather than grandstanding.

I continue to refer to this as the ‘CFATS Quarterly’, but CISA has rebranded this the ‘Chemical Security Quarterly’. Most of the information in this issue is targeted at CFATS facilities, but the UAS article shows that CISA is trying to target this at a larger audience. I applaud them on that effort, we will see how well they expand this outreach in future editions.

Saturday, July 27, 2019

DHS Updates CFATS Manuals – July 2019


This week (apparently, DHS no longer provides ‘last published’ dates on their web pages) the DHS Cybersecurity and Infrastructure Security Agency (CISA) posted links to new versions of three manuals used by facilities covered under the Chemical Security Anti-Terrorism Standards (CFATS) program. The manuals are ‘dated’ June and July 2019, but there has been no notice of the new manuals provided on either the CFATS web site landing page nor on the CFATS Knowledge Center. The two remaining manuals for the Chemical Security Assessment Tool (CSAT) have not yet been updated.

The manuals affected are:

CSAT User Manual; and

DHS has long stopped putting change notices in their documents, so it is difficult to tell what changes, if any, have been made in the documents. One change is obvious in all three documents, they have been rebranded with a CISA front page; a branding that reflects more on the CISA cybersecurity mission than the chemical security mission of the CFATS program.

PSP Instructions


This manual has certainly been revised to reflect the recent implementation of the extension of the terrorist ties screening requirement to Tier III and IV facilities. You can tell this by the new ‘Note’ on page 4:

“For more information on RBPS 12(iv) and the Personnel Surety Program, see 84 FR 32768, Notice of Implementation Chemical Facility Anti-Terrorism Standards Personnel Surety Program published on July 9, 2019 or access the DHS Personnel Surety Program.”

Since there was no reference to the submitting facility’s tiering in the original manual, there was no need to make changes reflecting the expanded implementation. In a quick perusal of the two versions, I do not see any changes beyond pagination and layout changes, with one exception. The ‘addendums’ at the end of the 2018 manual have been renamed ‘Appendix A’, ‘Appendix B’ and the acronym list has been labeled ‘Appendix C’ in the new version.

CSAT User Manual


This User Manual has been substantially reformatted and ‘enhanced’. The table of contents page, for instance now provides a link to the indicated section and the sub-sections of the text are listed down to the X.Y.Z level where the previous version was limited to the X.Y level. The other major enhancement is that each graphic provides a textbox with additional details when the cursor is placed on the graphic; this will, of course, only be useful in the electronic version.

This manual is ‘dated’ June 2019, so it would presumably predate the PSP changes.

SVA/SSP Instructions


As one would expect this manual has been updated to reflect the expansion of the PSP program. A note similar to that in the PSP manual can be found on page 97 of the new manual.

Commentary


None of the changes that I have seen are significant; they would have no impact on a facility’s implementation of the CFATS program in general or the PSP program in particular. I have not, however, done a line by line review of any of the documents. In any case, security managers and those interested in the CFATS program should download these new manuals, just to ensure that they have the latest version available.

Oh, it is interesting to note that while the description of the SVA/SSP manual found on the CFATS Knowledge Center describe the previous version of these manual, the links take one to the newer version. This is unusual in that the URL’s for the document are completely different than those found on the CSAT web site. The links for the other two manuals on the Knowledge Center page still go to the older manuals.

Thursday, July 11, 2019

DHS Publishes PSP Program Announcement – 07-09-19


On Tuesday the DHS Cybersecurity and Infrastructure Security Agency (CISA) published a notice in the Federal Register (84 FR 32768-32777) outlining the implementation process for the expansion of the Personnel Surety Program (PSP) to Tier III and IV facilities. Yesterday they updated the Chemical Facility Anti-Terrorism Standards (CFATS) program landing page with a note about that expansion that pointed at the revised PSP web site.

Overview


Back in 2016 the DHS Infrastructure Security Compliance Division (ISCD, now part of CISA) implemented the portion of the PSP that provided for identifying CFATS employees and contractors or visitors with unaccompanied access to critical areas in covered facilities that may have ties to terrorist. The initial implementation was limited to Tier I and II facilities. In late 2017, ISCD started the process to expand the PSP process to Tier III and IV facilities.

The PSP web site has an interesting graphic that conceptually explains the PSP implementation process:



First, once notified by ISCD that the facility will begin the implementation process (and that notice will start the 60-day clock implementation clock), the facility will update their site security plan to include information about how they will implement the process at their facility. This weeks’ notice provides a look at what types of information ISCD will be looking for in that SSP modification. When ISCD approves that amended SSP the clock will again start on the facility’s actual implementation of that facility specific process.

ISCD will phase this implementation in over the next two years or so. They will provide each Tier III and IV facility with a notice of when they will officially begin the implementation process and the date of that notice begins the 60-day period in which the facility must submit a revised SSP. Facilities can begin work on that SSP revision now, or they can wait until they receive the notice. Facilities can even submit the amended SSP before they receive their notice.

Tier III and IV facilities that have not yet had their SSP approved (or perhaps even authorized) should expect that their SSP will have to include PSP implementation before ISCD give approval to the plan.

PSP Options


The CFATS PSP provides four different options that facilities may use to screen individuals for possible terrorist ties; actually five since ISCD included an obligatory possibility for facilities to propose some sort of alternative that would accomplish the same thing. Facilities may use any option or combination of options that they wish.

The notice describes each of these four options (imaginatively entitled: Option 1, Option 2, Option 3 and Option 4) in some detail. In my 2016 blog post I described them this way:

Option 1 – Facility submits data and ISCD has TSA conduct screening;
Option 2 – Facility submits data on personnel with previous screening and ISCD has TSA confirm that screening is current;
Option 3 – Facility uses TWIC Reader to verify identity and screening status of Transportation Workers Identification Credential (TWIC) holder; and
Option 4 – Facility visually inspects TSDB based identity document to verify that person had been screened against TSDB.

Commentary


I will keep this brief today since I already said most of what I want to say back in 2016. In fact, I did an entire blog post about what problems I expected facilities to face in implementing the PSP. I have not seen anything since then that would significantly change those observations.

Most facilities are going to find that they need a blended approach using two or more of the options that ISCD has provided. I think that every facility should probably expect to use all four options at one point or another. If the initial SSP revision addresses all four options, then the facility will have the maximum amount of flexibility in the PSP implementation. It would certainly save time down the road.

Remember, facilities can (should) begin their SSP revision process before they receive their notice from ISCD. I would not recommend submitting the revised SSP before that notice is received, because the official notice is also going to trigger specific Chemical Security Inspector support for the revision process.

Saturday, June 22, 2019

OMB Approval of CFATS PSM to Tier III and IV


Earlier this week I ran into a blog post at Aradc.org (Agriculture Retailers Organization) by Andrea Mowers about the OMB’s approval of the information collection request to add Tier III and IV facilities in the Chemical Facilities Anti-Terrorism Standards (CFATS) program to the Personnel Surety Program (PSP) vetting of employees against the Terrorist Screening Data Base (TSDB). I missed the May 23rd announcement by OMB’s Office of Information and Regulatory Affairs (OIRA), but the ICR certainly was approved.

We can expect to see the DHS Infrastructure Security Compliance Division (ISCD) publish a notice in the Federal Register about the implementation of the expansion of the PSP submission requirements. I will review the details of that process when the document is issued, but we can look at the Tier I and Tier II implementation and the documentation ISCD submitted to OIRA to get a general idea of what those requirements will be.

First off, ISCD will establish some sort of internal process to spread out the requirement to first modify approved site security plans (SSP) to explain how the facility will implement the process. That implementation plan would include which of the four options (or combination of options) that the facility plans to use to screen employees, contractors and visitors (the last two with unaccompanied access to critical areas of the facility) for potential terrorist ties. Finally, once that SSP revision is approved, ISCD will provide a deadline for the implementation of the plan. Facilities can probably expect that assistance will be available from Chemical Security Inspectors (CSI) during the process.

The general plan for the phased implementation of the Tier III and IV implementation of the PSP requirements was outlined in a response (.DOCX download) to industry comments submitted to OIRA. Response 4.1.1 notes:

“The Department agrees that a flexible approach is appropriate for the rollout of the Personnel Surety Program to Tier 3 and Tier 4 covered chemical facilities. If approved, the Department plans to implement the CFATS Personnel Surety Program in a phased manner to Tier 3 and Tier 4 covered chemical facilities over a three year period.  Similar to the successful and recent retiering effort, the Department plans to consider the number of facilities assigned to a single Authorizer when notifying facilities to implement the Personnel Surety Program, as not to overwhelm a single Authorizer. The Department will also allow the flexibility for Authorizers, if desired, to complete the process for their facilities before notification by the Department.”

While ISCD will certainly be providing individual facilities with notification of the deadline by which they will have to revise their SSP, I expect that ISCD will allow facilities to begin the process before that notification is given. I do suspect, however, that they would prefer that facilities not try to begin the process before the Federal Register Notice is published. Facilities could contact their CSI or the regional office to confirm this.

One final point, questions have been raised throughout the PSP development and implementation process about DHS’s reluctance to guarantee that facilities would receive timely notification if a person is identified in the TSDB vetting process as having potential terrorist ties. If this were totally up to ISCD, I am sure that timely notifications would be made. Unfortunately, intelligence and law enforcement entities outside of the Cybersecurity and Infrastructure Security Agency (CISA), the controlling agency under which ISCD resides, will be involved in making that decision. The comment response document again addresses this issue in response 5.62:

“The Department’s design of the CFATS Program is intended to promote and enhance the security of high-risk chemical facilities; the Personnel Surety Program is one element of the larger CFATS Program. To prevent a significant threat to a facility or loss of life, a high-risk chemical facility will be contacted where appropriate and in accordance with federal law and policy, and per law enforcement and intelligence requirements.”

Monday, September 24, 2018

S 3405 CFATS Reauthorization – PSP


This is another in a series of blog posts about S 3405, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2018, which would reauthorize the Chemical Facility Anti-Terrorism Standards (CFATS) program for five years. The other blog posts in the series include:


Personnel Surety Program


Section 7 of the bill was written in response to industry concerns about the expansion of the personnel surety program reporting requirements to Tier 3 and Tier 4 facilities. It amends 6 USC 622(d)(2)(A) in two instances. The first would make participation in the terrorist screening database (TSDB) via the Chemical Security Assessment Tool (CSAT) mandatory for all Tier 1 and 2 facilities and optional (at the owner’s discretion) for Tier 3 and 4 facilities.

The second change is an additional attempt to limit the scope of the TSDB screening. It modifies the description of those covered by the requirement by adding the qualifier “who will have access to any chemical of interest”. Currently the program covers all facility employees, as well as most contractors and visitors that have unaccompanied access to critical areas of the facility.

Commentary


The big problem with both this section and the DHS effort to expand the application of the personnel surety program to Tier 3 and 4 facilities (already required, but the Infrastructure Security Compliance Division set up the implementation of the PSP in a two phased process) is that there has been no official evaluation of the efficacy of the program. I would have been much more comfortable with the section if it had prohibited ISCD from starting phase II of the PSP implementation until after the GAO had a chance to report on the first phase. Two important items would have to be included in that report, the number of people in Tier 1 and 2 facilities that were reported as being found on the TSDB and the number of those who were inappropriately identified.

One thing that Sen. Johnson appears to have not taken into account in his effort to appease the chemical industry’s ongoing complaints about the PSP is that a large proportion of the Tier 3 and Tier 4 facilities are in the CFATS program because of their possession or manufacture of chemicals that are on the list of DHS chemicals of interest (COI) because they can be used to make improvised chemical weapons or improvised explosives. This means that they are at risk, not so much for release on site, but for theft or diversion to some underground manufacturing site where they would be converted into weapons. These facilities would be prime targets for infiltration (if we had an active terrorist threat) by terrorist organizations to effect the theft or diversion of these COI.

Saturday, September 8, 2018

ISCD Updates PSP Manual – 08-30-18


This week the DHS Infrastructure Security Compliance Division (ISCD) published a new version of their Personnel Surety Program (PSP) Instructions manual dated 8-30-18. This replaces the version printed 9-18-17. As we have seen with most of the recent rewrites of the Chemical Facility Anti-Terrorism Standards (CFATS) program manuals, most of the changes in this manual only minor changes have been made to clarify requirements.

There is some new information about the Transportation Workers Identification Credential (TWIC). The TSA began issuing a new and improved version of the TWIC to make it more difficult to counterfeit or alter. Laurie Thomas did a blog post on this TWIC change back in July. The new information in this manual is found on page 29 in the Note below the new photos.

If you are navigating the CFATS web site to find this new manual (instead of using the link above), you have to look on the Chemical Security Assessment Tool (CSAT) page under ‘Additional Resources’. Do not use the link on the CFATS Knowledge Center; that still takes you to the earlier version of the manual. NOTE: There is no notice on either page about the change in manual versions.

Monday, June 18, 2018

DHS Publishes PSP 30-day ICR Notice


Today the DHS National Protection and Programs Directorate (NPPD) published a 30-day ICR notice in the Federal Register (83 FR 28244-28251) for a proposed expansion of the current personnel surety program process for vetting personnel at facilities covered under the Chemical Facility Anti-Terrorism Standards (CFATS) program against the Terrorist Screening Database (TSDB). The 60-day notice was published in December of 2017 and comments were covered here.

This notice specifically addresses the comments submitted during the 60-day notice comment period. Those comments included:

Suggestions to delay the expansion of the PSP to Tier III and Tier IV pending further review of the efficacy of the Tier I and Tier II program;
Objections to railroad employees being subject to PSP screening;
Questions about the assumptions used in calculating the burden;
Calls for a phased implementation of the PSP implementation;
Lower risk at Tier III and Tier IV facilities obviates need for TSDB screening;
Concerns about the lack of facility notification in case of a positive TSDB screening result;

Almost all of the comments have been previously dealt with by DHS in the original CFATS rulemaking and the earlier PSP ICR process. Obviously, the commenters were not satisfied with the earlier response to those comments and are unlikely to be satisfied with the responses included in this new rebuttal.

The one relatively new objection is the one dealing with the reduced risk at Tier III and Tier IV facilities. The Department’s response is essentially that the PSP vetting against the TSDB is a requirement of  6 CFR 27.230(a)(12)(iv) for all covered facilities and thus must go forward.

DHS is soliciting public comments on this ICR. Comments should be sent electronically to dhsdeskofficer@omb.eop.gov. Comments should be submitted by July 18th, 2018.

Commentary


First, I would again like to congratulate NPPD on the amount of detail they include in their ICR notices. While people can certainly disagree with the decisions made in responding to comments, all of the ICRs in support of the CFATS program have include much more information than other agencies provide in their ICR notices. These ICR notices should be the gold-standard by which OMB measures acceptable ICR notices.

I was more than a little disappointed in the response to the issues raised about extending the PSP to Tier III and Tier IV facilities. Last week’s congressional hearings on the CFATS programs showed that there is much wider industry concern about this issue than was reflected in the comments submitted to DHS in response to the 60-day notice.

I firmly support the expansion of the TSDB screening to Tier III and Tier IV facilities, but I think that the argument that this is required by the regulation, while legally sufficient, is really rather weak. I think that the Department should have taken the opportunity presented by this ICR notice to more completely address industry concerns. While I think that most of the industry objection to this expansion is really based upon concerns about costs and manpower needs, their specific objections about the lower security risk need to be addressed.

DHS should have addressed the fact that the large bulk of facilities in Tier III and Tier IV are facilities that face a theft and/or diversion threat because of the presence of precursor chemicals that can be used to make improvised explosive or improvised chemical munitions. An insider threat at this class of facilities may actually pose a higher risk of terrorist attack because subsequently produced improvised weapons provide the terrorist organization with more flexibility in carrying out a subsequent attack on specific high-profile targets. Additionally, a terrorist participating in this type of insider attack is more likely to be able to walk away from the attack without personal harm than if attacking a facility with a release security hazard. This would expand the type of individual that would be willing to conduct an attack.

There is an unfortunate tendency in this country to conflate ‘terrorist attack’ with a jihadist suicide-bomber. At Tier I and Tier II facilities with release security issue chemicals of interest (COI) this may be a high-threat attack. At facilities with theft/diversion security issue COI this is legitimately a much lower probability attack. Almost by definition those facilities are much more susceptible to an insider attack attempting to acquire raw materials for attacks on higher profile targets. This is why the PSP terrorist screening database requirement really needs to be expanded to Tier III and Tier IV facilities, not the weak argument that regulation requires the expansion.

Wednesday, December 27, 2017

ISCD Publishes 60-day Personnel Surety ICR Revision

Today the DHS National Protection and Programs Directorate (NPPD) published a 60-day Information Collection Request (ICR) revision notice in the Federal Register (82 FR 61312-61317) for the expansion of the personnel surety program (PSP) to Tier 3 and Tier 4 facilities covered under the Chemical Facility Anti-Terrorism Standards. The PSP implements the requirement of 6 CFR 27.230(a)(12)(iv) to vet personnel with access to CFATS covered facilities “to identify people with terrorist ties”.

The NPPD’s Infrastructure Security Compliance Division (ISCD) is not proposing any changes to the four options for vetting covered personnel that were established when the current ICR was approved for Tier 1 and Tier 2 facilities.

Under this proposed revision ISCD would begin a phased notification of Tier 3 and Tier 4 facilities over a three-year period to revise their site security plan to reflect their implementation of the PSP terrorist vetting requirement. This notification would only begin once the OMB’s Office of Information and Regulatory Affairs (OIRA) approved this ICR.

ISCD has made some revisions to the ICR burden estimates in this notice based upon the data that they have received during the PSP implementation at Tier 1 and Tier 2 facilities. Generally they have reduced the number of estimated data submissions and the amount of time per submission to lower the burden estimate.


ISCD is soliciting public feedback on this ICR notice. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #DHS-2017-0037). Comments need to be submitted by 02/26/2018. This ICR notice will be followed by a 30-day notice once ISCD has a chance to respond to the comments submitted to this notice.

Friday, September 8, 2017

ISCD Updates Two CSAT Manuals

Yesterday the DHS Infrastructure Security Compliance Division updated its Chemical Facility Anti-Terrorism Security (CFATS) program web site to provide links to new versions of two of its CFATS Chemical Security Assessment Tool (CSAT) 2.0 manuals. These two new manuals are not the simple tweaks and clarifications that we have been seeing in CSAT 2.0 manuals since the program was changed last October. They are significant re-writes.

The two new versions of the manual are:

Interestingly the new manuals are dated today, not yesterday.

The Site Updates


The most obvious web site update is found on the CFATS Knowledge Center page. This page provides a notice in the ‘Latest News’ section about the two new manuals with links to the manuals found in the ‘Documentation’ section of the page. Listings for the older versions of the manuals were removed from that section.

The main landing page does not contain any mention of the new documents, but it was updated with a link to a new version of the CFATS Personnel Surety Program page. That new page does not mention any program changes and still provides a link to the old PSP Manual. The CSAT page was not changed (still dated June 21st, 2017), but the link to the CSAT Portal Users Manual now takes you to the new manual through an updated intermediate page.

PSP Manual


The new PSP manual is a complete re-write of the manual with a completely new format. This means that it will be time consuming to determine what program changes (if any) have actually been made that were reflected in the new manual. At first glance, I do not see any major changes, nor do I expect there to be any since there was no update provided on the PSP web page. There may, however, have been some changes to the way the web site is used. More on that in a future post.

CSAT Portal Manual


The changes to the Portal Manual do not involve a complete rewrite so I can take a quick look at the table of contents to initially look for changes to this manual; and there are some interesting ones. It does not look like any real policy change, but there appear to have been some additions made to the CSAT Portal tool.

I do not see any changes in the table of contents until we get to Section 9, User Management Tab. First the manual completely changes Section 9.4, Users. That section not provides the following information:

9.4.1 Export User List
9.4.2 View User Information
9.4.3 Reset Password
9.4.4 Delete User Account
9.4.5 Administrator
9.4.6 Personnel Surety Program

A completely new subsection is then added; 9.5, Groups. That subsection includes:

9.5.1 Corporation Group
9.5.2 Create Group
9.5.3 Edit Group
9.5.4 Delete Group
9.5.5 Merge Group

So far, no new policy; just some added functionality and/or better listing of capabilities already existing within the system.

Next, we find that ISCD has flipped Sections 10 and 11. The new Section 10 addresses Personnel Surety Program issues. This is a complete re-write and probably is related to the changes in the PSP manual that I mentioned in passing earlier. I’ll probably address this new section in detail when I cover the new PSP manual. In the meantime, the following new subsections were added to Section 10:

10.1 Search Affected Individuals
10.2 Affected Individuals
10.2.1 Add Individual
10.2.2 View an Affected Individual
10.2.3 Edit an Affected Individual
10.2.4 Remove Affected Individual(s)
10.2.5 Bulk Upload
10.2.6 Export to PDF
10.3 User Defined Fields
10.3.1 Create User Defined Fields
10.3.2 User Defined Field List

The new Section 11 is just the old Section 10, Manage My Account. No other changes appear to have been made.

I have not yet gone completely through the manual to see if any significant changes have been made to any of the other portions of the manual. That is fodder for a potential future blog post, if there are any changes.

Commentary


It is not unexpected to see a major rewrite of the PSP manual. ISCD has been implementing the PSP program in the hand-holding mode since its inception last year. I am sure that there have been a large number of lessons learned and hopefully this new manual accurately reflects those changes. I am more than slightly disappointed that there was not more of a formal role out of this new manual. As controversial as the PSP program has been since it was first mentioned, I would have thought that ISCD would have announced a webinar to explain what had been learned in the first year of the operation of this program.

At first glance it looks like the CSAT Portal Manual is just a routine update of both the CSAT site and the Users Manual. The only problem is that you cannot be sure about that without doing an almost line-by-line examination of the manual.

One of the things that ISCD changed when they started CSAT 2.0 was the removal of version numbers and change logs from their new publications. I suspect that this may have been a DHS wide requirement because most other DHS agencies have not been that user friendly in their publications. It does make it difficult for users of these manuals to keep up with what is going on in the program.

Most facility or corporate security managers do not hold just that job. It is an additional duty place on top of their normal corporate responsibilities. This means that they do not have the time to do the type of page-by-page analysis of new program manuals (and there are a bunch of manuals supporting the CFATS program) to ensure that they understand the changes that are being made in the program. Failure to understand those changes, however, could result in their organizations falling out of compliance with program requirements.


I hate to say this about anything involved with the government, but failure to properly document changes in program manuals is not fair. It puts an improper burden on the regulated facilities, a burden that most cannot bear, particularly the smaller facilities. DHS really needs to play fair with the CFATS community if it wants to continue to operate the program as a partnership with the chemical community rather than as an adversarial regulatory relationship.

Saturday, October 22, 2016

CSAT 2.0 Update – 10-21-16

Yesterday the DHS ICS-CERT made some additional changes to the CFATS Knowledge Center page in support of their on-going implementation of revisions to the Chemical Facility Anti-Terrorism Standards (CFATS) program’s Chemical Security Assessment Tool (CSAT) known as CSAT 2.0. Those changes centered on removing links to the older CSAT documents in the ‘Documentation’ section at the bottom of the page.

Documents Removed


The documents removed included:


This links were still good as of 7:30 EDT this morning. If you need copies of these documents for historical purposes you need to get them as soon as possible. There is no telling how long these documents will remain.

Old Documents Still Remaining


The ‘Documentation’ section of the CFATS Knowledge Center has been getting kind of bloated over time. There are a number of useful documents listed here that cannot be found anywhere else on the site without the links provided here. There are, however, a number of documents that could still be removed. Those include:



The CFATS Quarterly is not the most recent (the April 2016 issue is also listed and I have not seen anything more recent). It might be nice to have a CFATS Quarterly web page where links to all of the issues might be found, but only if these are going to be released on a routine (quarterly?) basis. The two CFATS fact sheets are from somewhere in the middle of this series of documents; a similar historical web page might be of limited use. The personnel surety program (PSP) documents are dated, they could be better listed on PSP website under an historical documents listing. And the last is a link to a website not a ‘document’ and that page is already listed on the CFATS landing page.

Tuesday, April 26, 2016

ISCD Updates CFATS Web Site

Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated their Chemical Facility Anti-Terrorism Security (CFATS) program web site. Links were added for two fact sheets; one dealing with the compliance inspection program and one dealing with the personnel surety program (PSP).

The compliance inspection fact sheet is the same one that I wrote about last Friday. I would not have even mentioned this except for the fact that whenever the landing page is changed, I go back and check all of the links on the page to see if there were any additional changes made since the last landing page change. In this case there was; a week ago the PSP page was changed to add a link to a new fact sheet about the relatively new identifying people with terrorist ties portion of the PSP.

The first page of the two-page fact sheet is a basic description of this new portion of the PSP program. It contains no new information and everything there has been thoroughly (in my not so humble opinion) discussed here in this blog on a number of different occasions. The second page is a short list (3) of frequently asked questions (FAQ) about the program that provide a little more emphasis and one nugget of new information about the program.

In response to an implementation timing question, the fact sheet reiterates the previous information provided that ISCD, through the facility’s Chemical Security Inspector, will notify the facility when it needs to start modifying their Site Security Plan (SSP) to include implementation of the terrorist screening portion of the PSP. They emphasize this point by stating (in bold print): “Facilities should wait to be contacted by the Department before altering their SSP/ASP or attempting to submit any information for vetting.”

The fact sheet then goes on to explain that ISCD will “provide an optional supplement [emphasis added], which discusses information the Department will consider and review in order to make a determination on the facility’s ability to satisfy RPBS 12(iv)”. Hopefully, this guidance will provide the information that I had complained about being absent from the Compliance Inspection Fact Sheet. It is more than a little disappointing that a link to this ‘optional supplement’ has not been provided on the PSP web site.

The interesting nugget of information that I referred to earlier is found in the response to the second FAQ about how ISCD will be providing the notification to begin implementing the terrorist screening portion of the PSP. It states that: “Initially, DHS will be working with certain
facilities to complete this requirement during compliance inspections.”

This helps explain the confusion raised in the latest CFATS Quarterly where ISCD explained that the first compliance inspection that included Terrorist Screening Data Base (TSDB) personnel vetting was conducted on January 28th, 2016 and the first SSP change with an updated PSP was approved a little over one-month later. This was probably the same facility in both instances.


In any case, ISCD is continuing to parcel out new information about changes in their CFATS program. I hoping, however, that they are directly notifying covered facilities about these changes in their web site. The average facility security officer (for most facilities a second job for someone) does not have time to do a daily detailed perusal of the CFATS web site to ferret out these changes. Though to be fair, ISCD does a good job of annotating when web site changes are made. That is much more than I can say for other DHS agencies, like TSA for instance.

Friday, February 12, 2016

Another New PSP FAQ Posted to CFATS Knowledge Center

This afternoon the DHS Infrastructure Security Compliance Division (ISCD) published another new frequently asked question (FAQ) on their CFATS Knowledge Center web page. As with a number of recent additions to the FAQ list, this one deals with the CFATS personnel surety program (PSP) that the Department is in the process of rolling out.

FAQ #1769 asks:

“My facility must perform background checks in accordance with the Risk-Based Performance Standard (RBPS) 12 “Personnel Surety” on affected individuals. Who is an affected individual?”

Typically, these FAQ responses quote from the appropriate portion of the CFATS regulation as the major part of the response. The appropriate part of the CFATS regulation in this case would be 6 CFR 27.230(a)(12):

“Perform appropriate background checks on and ensure appropriate credentials for facility personnel, and as appropriate, for unescorted visitors with access to restricted areas or critical assets….”

In this case the response is in two parts:

• Facility personnel who have or are seeking access, either unescorted or otherwise, to restricted areas or critical assets; and
• Unescorted visitors who have or are seeking access to restricted areas or critical assets.

They go on to explain the difference in the first part from the actual wording of the regulation by noting:

“The regulatory text makes no distinction between facility personnel who are escorted and facility personnel who are unescorted, and uses the term ‘unescorted’ to modify only the noun ‘visitors.’ As such, if facility personnel have access, either unescorted or escorted, to restricted areas or critical assets, they are deemed to be affected individuals who must be screened for the purposes of the Personnel Surety protocol.”

Commentary

The ISCD folks are being very careful with this distinction because there were a number of comments that they had received during the various information collection request comments periods that made it clear that very many people were under the misapprehension that only facility personnel that had unescorted access to critical areas would require personnel surety checks.


I am more than a little surprised that ISCD did not also take this opportunity to reinforce the other question that is closely related to this one; are contractor personnel ‘facility personnel’ or ‘visitors’? They made it clear in their Federal Register notice that they intend to give facilities the widest possible latitude in determining how contractors, even various groups of contractors will be handled for the PSP. The facility will be required to provide an explanation of how contractors are being handled in the revision to the Site Security Plan that will be made to implement the new terrorist screening portion of the RBPS #12 requirements.

Wednesday, January 6, 2016

Potential PSP Problems

This is part of a continuing series of blog posts about the recently released Federal Register notice about the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety program (PSP). The notice outlines how the Infrastructure Security Compliance Division (ISCD) is planning to implement the vetting of covered chemical facility personnel and visitors against the FBI’s Terrorist Screening Database (TSDB) to determine if any covered personnel are suspected of having ties to terrorist organizations. Other posts in this series include:


In this post I will be looking at some of the problems that can be expected to arise as the new terrorist ties portion of the CFATS Personnel Surety Program is put into operation. Some of these potential problems will have reasonable workarounds readily available and others will require programmatic changes by ISCD. This discussion, however, is predicated on my current understanding of the PSP implementation that we have not yet seen published. A lot will depend on the way that ISCD sets up the data submission tool in CSAT.

Multiple Facilities

There are a significant number of companies in the United States that have multiple facilities covered under the CFATS program. ISCD has been accommodating in the past in allowing for these types of organizations to submit data to CSAT from the corporate level that is common to two or more facilities and I suspect that they intend to continue this practice with the PSP.

ISCD has made it clear in their Notice that they would like to see individual TSDB screening tied to facilities so that if subsequent changes to the TSDB turn up terrorist ties, ISCD will be able (law enforcement rules allowing) to notify the affected facility of the problem. While most of the employees whose screening data is submitted from corporate will be tied to a particular facility, that will not be the case for all employees. There will be corporate level personnel that will need to be able to move through all of the covered facilities.

It is conceivable that ISCD would require the information on those corporate level individuals to be submitted on each facility CSAT account. While this would not technically violate the 6 USC 622(d)(2)(A)(i) prohibition of requiring more than one data submission on an individual by a covered facility, it would certainly conflict with the Congressional intent. And it would likely put ISCD in the position of having to pay for multiple TSDB screenings of an individual.

The simplest way around this problem would be for ISCD, in allowing for corporate data submissions for multiple facilities to not tie the names submitted to an individual facility, but rather to the larger organization. That way ISCD would still have a point of contact about the individual in the event of a positive match or question about identification, but the individuals would be able to move about all of the covered facilities within the organization.

Facility Turnaround Contractors

Many chemical facilities (continuous process facilities in particular) conduct periodic facility shutdowns for maintenance called turnarounds. A contractor typically provides a large temporary workforce to quickly conduct the large scale repair, replacement and system upgrades that are part of this maintenance activity. These contractors serve multiple facilities and have a high employee turnover, especially when seen from the facility point of view.

It is extremely impractical for facilities to do individual information submissions for the contractor employees in this type of situation. Additionally, such data submissions would place an unreasonable load on the administration of the PSP at ISCD.

This would be an ideal situation for the use of Option 3. Each of the turnaround employees would be required to have a Transportation Workers Identification Credential (TWIC) and the contractor would be required to operate a TWIC Reader at the contractor entrance to the facility.

Local Delivery Drivers

While a facility may well be able to require over-the-road truck drivers delivering to the facility to have TWIC or HME for facility entrance, that is less likely for local less-than-load truck drivers, and completely beyond the bounds of reason for local deliveries from retail establishments and package delivery services.

The easiest way to deal with these drivers under the PSP program is to exclude them from the program. This can be done by setting up a specially designated delivery location outside of the facility’s restricted area or an area in clear view of the security personnel (either visually or via CCTV). They can be met there by facility personnel and if they have to enter the restricted area they would be escorted during that time.

Electronic Access

Many facilities routinely provide remote access to computer systems to a variety of folks. While employees are already covered under the PSP. A serious problem arises, however, when various outside service personnel or contractors are provided access to covered computer systems. Contractors with routine off-site access can presumably be covered in the same way as on-site contractors are but I would suspect that ISCD is going to want to see strong evidence that the facility has some sort of strong control on a contractors vetting of personnel. What is going to be much more problematic will be large vendors (and especially internationally based vendors) where the facility does not have a significant measure of economic influence on the vendor to require that they limit personnel to those that have been appropriately vetted by the PSP. ISCD is going to have to provide some clearer guidance on this issue.

False Positives

The biggest problem with the PSP program will be the issue of false positive matches with the TSDB. The TSDB is a name-based database that includes little or no biometric information on the individuals on the list. It is inevitable that there will be matches of names submitted by chemical facilities to TSDB listings that actually have no relationship to the individual on the TSDB. I suspect that the rate of false positives will be such that larger CFATS facilities will have to deal with multiple instances of receiving unfounded notifications of possible terrorist ties. All facilities must be prepared to deal with this situation when they submit their initial lists under Option 1.

After the initial data submissions this problem will be less important as most employment agreements will provide for termination of new hires that come back as positive on the TSDB screening in much the same way as drug screens and background checks call for termination and requests for redress will be handled as an individual matter. With this initial data submission for all current employees the situation is quite a bit different. When a key employee comes back with a positive TSDB match that is likely a false positive, then the organization has a stake in the redress process that is not anticipated in the ISCD privacy documentation [Note: this is the latest Privacy Impact Assessment document for the PSP]. The current redress procedures are:

“If you believe that the information submitted by [INSERT NAME OF CFATS COVERED FACILITY AND OF THEIR DESIGNEE(S) (IF APPLICABLE)] has been improperly matched by DHS to the identity of a known or suspected terrorist, you may write to the NPPD FOIA Officer at 245 Murray Lane SW, Washington, D.C. 20528-0380. You may also request an administrative adjudication under CFATS [6 CFR 27.310(a)(1)].”

Facilities are almost certainly going to need to have procedures in place in their newly revised SSP to cover how they are going to deal with the receipt of notification of a TSDB match for current personnel. Those procedures are going to have to be able to deal with a relatively new hourly worker, a well-known and respected long-time employee, and a manager coming back with a positive match. If the facility expects to keep any of these employees around during the almost certainly lengthy redress process, they are going to have to be able to convince ISCD that mitigating controls are in place to address the risk that these employees actually do have terrorist ties. I have no idea what mitigating controls other than personal escort might be acceptable to ISCD.

Other Situations Will Come Up

Facilities are going to have to take a hard look at their specific situation to see what areas of their facility are routinely entered by non-employees. Where there is little advance notice of who that non-employee is going to be, facilities are going to have to come up with ways to provide PSP vetted escorts. Where there is sufficient advance notice to provide for execution of one of the four TSDB vetting options, facilities will have to decide in advance how they are going to select the appropriate option.


As more of these complicated situations arise, I would certainly like to hear about them. I would particularly like to hear about those situations where ISCD has agreed to an innovative way of dealing with the problem.

Friday, December 18, 2015

DHS Publishes CFATS PSP Notice

Today the DHS National Protection and Programs Directorate (NPPD) published a notice in the Federal Register (80 FR 79058-79066) concerning the “Implementation of the CFATS Personnel Surety Program”. This explains how Tier I and Tier II facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program will implement the portion of the personnel surety program pertaining to vetting facility personnel and visitors with unaccompanied access to CFATS facilities against the Terrorism Screening Database (TSDB).

Requirement for Vetting

The requirement for vetting facility personnel and unescorted visitors wishing to gain access to restricted or critical areas of a CFATS covered facility can be found in 6 CFR 27.230(a)(12). Facilities with approved site security plan (SSP) have already been completing the requirements under subparagraphs (i) thru (iii). This notice pertains to the requirements under subparagraph (iv); measures designed to identify people with terrorist ties.

Additional congressional guidance on the implementation of the CFATS Personnel Surety Program was provided last year with the passage of the Protecting and Securing Chemical
Facilities from Terrorist Attacks Act of 2014 (PL 113-254). The provisions regarding the PSP were codified at 6 USC 622(d)(2).

In August of this year the OMB’s Office of Information and Regulatory Affairs (OIRA) approved the CFATS Personnel Surety ICR (1670-0029) that ISCD had used to outline how it intended to implement the PSP. The version of the ICR approved by OMB included the addition of a fourth option for implementation of the vetting program that was required by the new congressional direction.

Who Must Be Vetted

Today’s notice reiterates the position of ISCD as to what the regulation means when it says “facility personnel, and as appropriate, for unescorted visitors with access to restricted areas or critical assets”. In effect the term ‘facility personnel’ mean all facility employees and those contractor personnel designated in the SSP as facility personnel for the purpose of the PSP. Visitors are only required to be vetted if they have ‘unaccompanied access’ and the facility is given certain latitude in defining in the SSP what constitutes ‘accompanied access’.

The notice also goes into some detail about specific categories of personnel that do not require vetting under any portion of the PSP (including the terrorist ties requirement outlined in today’s notice). They include:

• Federal officials who gain unescorted access to restricted areas or critical assets as part of their official duties;
• State and local law enforcement officials who gain unescorted access to restricted areas or critical assets as part of their official duties; and
• Emergency responders at the state or local level who gain unescorted access to restricted areas or critical assets during emergency situations.

TSDB Vetting Options

The notice describes four specific options that facilities have to conduct the TSDB vetting of personnel. Facilities may use any combination of the four options that they desire; they just have to be outlined in the Site Security Plan approved by ISCD (more on that later). Those options are:

Option 1 - The high-risk chemical facilities (or designee(s)) submits certain information about affected individuals to the Department through a Personnel Surety Program application in the CSAT Tool.

Option 2 – The high-risk chemical facilities (or designee(s)) submits certain information about affected individuals to the Department through the CSAT Personnel Surety Program CSAT application on personnel that have already been vetted by another Federal TSDB vetting program (TWIC, HME, SENTRI and FAST for example).

Option 3 – The high-risk chemical facilities (or designee(s)) does not submit information to ISCD, but will rather electronically verify and validate the affected individuals' TWICs through the use of TWIC readers (or other technology that is periodically updated with revoked card information).

Option 4 - The high-risk chemical facilities (or designee(s)) does not submit information to ISCD, but will rather visually inspect a credential from a Federal screening program that periodically vets individuals against the TSDB.

Facilities are reminded that they have an additional option of proposing some alternative vetting process in their SSP that may be approved by ISCD if it is found to provide an equivalent process.

The notice also provides a discussion of the relative level of security provided by each of the options described above.

When Will Vetting Have to be Completed?

The notice explains that before the vetting process can begin, the facility will have to revise their approved SSP to include a description of their terrorist screening process (more on this later). ISCD will notify each Tier I and Tier II facility when they must complete that SSP revision (ISCD is going to stagger this so that they can provide assistance from Chemical Security Inspectors throughout this process). Once that revision is approved, facilities will generally have 60-days to complete the vetting process (submitting data for Options 1 and 2) on existing employees. New employees and all visitors requiring unaccompanied access will require vetting (again, submitting data for Options 1 and 2) before they are given access to restricted or critical areas within the facility.

Privacy Notice

The notice outlines the Privacy Act provisions (and other applicable privacy regulation provisions) that the Department has complied with in developing this program. From the perspective of the Facility Security Manager, probably the most important will be the May 1st, 2014, update to the CFATS Personnel Surety Program Privacy Impact Assessment. That is because it provides a suggested copy (at Attachment 1) of the Privacy Act notification that should be provided to each person about which the facility is submitting information under Option 1 or Option 2.

The notice mentions a new update (that presumably includes mention of Option 4) that was supposed to have been printed today, but it has not yet been posted to the NPPD PIA web site.

Site Security Plan Revisions

CFATS Facilities that already have had their site security plan authorized or approved will have to revise their plan to include the terrorist screening process. The notice provides some detailed information about the types of information that they are going to expect to see in that revision.

When ISCD individually notifies each Tier 1 and Tier 2 that it is required to update their SSP, it will also include a date by which that update must be submitted for authorization/approval.

Moving Forward

I have heard that ISCD intends to work very closely with at least the first few facilities as they go through the process of changing their SSP and then submitting data (for those that intend to utilize Options 1 and/or Option 2) for the PSP. Given that the Christmas holidays are upon us, I would not be surprised to hear that ISCD will not send out the first notifications until after the first of the year. I also suspect that they may actually informally contact the early facilities to arrange times when their CSI are available before they send out the notification letters.

ISCD still has a CSAT manual to publish for the PSP data submissions and perhaps a revision to the Account Management User Guide if they are going to come up with a new data submission user role for 3rd party PSP data submissions.


We are going to see an interesting couple of months in the CFATS program as the PSP implementation moves forward.

Thursday, December 17, 2015

ISCD Publishes CFATS PSP Information

This afternoon the DHS Infrastructure Security Compliance Division (ISCD) published a link on the CFATS landing page to a new web site for their Personnel Surety Program (PSP). This is happening the day before the intended publication of their PSP notice in the Federal Register (a draft copy available here).

The new web page explains that three of the four personnel surety requirements in RBPS #12 have been in effect since the RBPS Guidance document was published six years ago. All facilities with authorized site security plans have addressed those three requirements in their SSP. The remaining requirement, vetting plant personnel and unescorted visitors for potential terrorist ties, has been held up while ISCD put together a program for screening these personnel against the Terrorist Screening Database (TSDB).

Readers of this blog will remember that back in August the OMB’s Office of Information and Regulatory Affairs (OIRA) finally approved the ISCD information collection request which authorized it to collect information from chemical facilities in support of the PSP. A little over a month later ISCD published a fact sheet outlining how the PSP program would operate for Tier I and Tier II facilities (Tiers III and IV will be added to the program at a later date).

Today’s publication of the PSP web site provides a brief overview of the four approved methods that facilities can use (alone or in combination) to complete the terrorist screening PSP requirement. Additional details will be laid out in the notice published in tomorrow’s Federal Register and the PSP User Manual that will be published in the near (hopefully) future.


I’ll have a more detailed post about the PSP notice tomorrow.
 
/* Use this with templates/template-twocol.html */