Showing posts with label Personnel Surety Program. Show all posts
Showing posts with label Personnel Surety Program. Show all posts

Friday, October 13, 2017

ISCD Publishes Personnel Surety Program Fact Sheet

Today the DHS Infrastructure Security Compliance Division (ISCD) posted a link to a new program fact sheet on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The fact sheet provides some basic data on the implementation of the personnel surety program, or the screening for terrorist ties portion of the Risk Based Performance Standard (RBPS) 12.

As with all of these Fact Sheets that ISCD has been publishing over the last year or so, there is no really new information provided. All of the information is already available on either the CFATS Personnel Surety Program web page, or in the Federal Register Notice that announced the implementation of the program. What has been done is a relatively simplified presentation has been made available that provides highlights of the program.


The most valuable knowledge condensation here is the basic list of security considerations that facilities need to address in their site security plan for the option(s) being used by the facility to screen personnel authorized unaccompanied access to security areas of covered chemical facilities. This information was explained in more detail here in the Federal Register Notice, but the table in this fact sheet provides the basic information.

Thursday, January 2, 2014

2014 and CFATS

2013 is now behind us, so this is a good time to take a look at what the future holds for the CFATS program.

Program Authorization

First, and probably most important the program will receive another extension of its temporary authorization in the next two weeks when the Congress passes another FY 2013 spending bill. If that bill covers the entire year (most likely) then the CFATS program authorization will be extended to October 4th 2014. This short term authorization will continue to color everything else about the program.

Three separate House committees (Homeland Security, Energy and Commerce, and the Appropriations Committees) will continue to pick at the leadership of the DHS Infrastructure Security Compliance Division (ISCD) about the slow pace of approvals of Site Security Plans. The improvements made in the rate of approvals will continue to be glossed over by the three Committee chairs as they continue to ignore the political and operational constraints placed upon the program by Congress.

The only Committee that has any real chance to have a real effect on the program continues to be the House Appropriations Committee. They control the purse strings and the annual re-authorization process. As long as the appropriations process remains broken, however, we can expect to see a paragraph in each spending bill for DHS include a provision extending the CFATS authorization.

There are no prospects for separate authorization for the CFATS program to be passed in either House this year. There has been no proposals for a permanent authorization made in the House and the proposal made by the late Sen. Lautenberg (S 68) will continue to be ignored by the Senate Homeland Security and Governmental Affairs Committee.

Personnel Surety Program

It has been almost 8 months since ISCD published their latest proposed version of their personnel surety program. They are closer to a program acceptable to the chemical industry than they were with 2009 proposal, but there are still a large number of industry concerns that need to be dealt with. I will not be surprised if we do not see a 30-day ICR notice on this program this year. If there is, it will almost certainly not include enough changes to make industry close to happy with program and we will not see an approval of the program by the Office of Management and Budget.

This is almost certainly going to need to see Congressional action before this program gets resolved. While this is an election year which slows down Congressional work on controversial topics, I expect that we will see legislation proposed that will extend TWIC coverage to CFATS facilities. Depending on how well crafted the bill is, it could actually get passed before November if it can make it to the floor.

Appendix A Update

The President included in his Chemical Safety and Security Executive Order (EO 13650) a requirement that DHS look at updating the DHS chemicals of interest (COI) list. As I noted in an earlier blog that requirement directed that:

The Secretary of Homeland Security shall identify a list of chemicals, including poisons and reactive substances, that should be considered for addition to the CFATS Chemicals of Interest list.

There have been on-again, off-again discussions with industry about this topic for a number of years now. I doubt that any of those discussions include listing poisons beyond the currently included release toxic COI and chemical warfare agents. The other serious toxins, including the ‘deadly ricin’ are not really weapons of mass concern and are thus inappropriate for inclusion in the Appendix A listing. The only possible exception to this would be methyl bromide and chloropicrin which I have advocated for inclusion for some time, but those were both clearly dealt with in the Appendix A regulation development.

I doubt that we will see any proposed regulatory change associated with this EO requirement.

Ammonium Nitrate Regulations

The regulation implementing the Ammonium Nitrate Security Program mandated by Congress continues to be held up by industry concerns. The biggest political stumbling block here is the concerns of the agricultural industry about the effects these regulations would have upon the use of temporary employees. ISCD will have a hard time trying to come up with a workable program for vetting migrant farm workers who are routinely expected to be picking up fertilizer grade ammonium nitrate from farm co-ops and ag chemical distribution facilities.

The agricultural lobby is still very strong in Washington and DHS has not been able to overcome their opposition to much of anything that deals with chemical security. The only exception was the inclusion of propane as a COI, but even there ISCD had to set an extremely high threshold (60,000 lbs instead of the normal 20,000 lbs for flammable COI) to overcome the objections of this lobby.

The only out I see here is for ISCD to specifically adopt TWIC as a mode of vetting transportation workers picking up ammonium nitrate for direct delivery to farms. This would be an extension of the TWIC program not really authorized by Congress, but it might get by with a wink and a nod from legislators.

I will be very surprised if we see the publication of the long overdue final rule on this program this year.

Chemical Sector Security Summit

While the CSSS is not technically a CFATS meeting, it is run by the Chemical Sector Coordinating Council, this annual meeting has been an important source of information about the CFATS program since its inception. Last year funding issues delayed the announcement of the meeting dates and that contributed to the decline in the number of industry attendees.

While I keep getting assurances from DHS contacts that the Summit is important to ISCD, it seems as if that may be lip service more than an actual commitment. We still have not seen publication of the slides from the various CFATS related presentations that we have come to expect from the earlier meetings.

I expect that we will again see a very late announcement of this year’s Summit and there will be an even smaller industry turnout for the meeting. In the current spending environment, I expect that that low turnout will be used as justification for killing the Summit.

A possible way out for DHS to save the program would be to include web casts of the presentations about the CFATS program. This would greatly increase the number of possible participants and show that there is significant support within the regulated community for continuing the Summit.

Cybersecurity

The CFATS program was almost certainly one of the regulatory programs that the President had in mind when he included §10(a) requirement in the Cybersecurity Executive Order (EO 13636) for including the Cybersecurity Framework (CSF) in current regulatory requirements for critical infrastructure organizations.

Under this EO ISCD has a requirement to report to the President within 90 days of the publication of the CSF (supposed to be published in February) if they have adequate authority to include the CSF in their regulatory scheme. Broadly speaking DHS does have the authority to include the guidance from the CSF in the CFATS program. It would probably have to go through a rule making process much like that used for the Risk-Based Performance Standards guidance document. That could be a time consuming process that would only be able to be started this year.

Continue to Muddle Along

In short I don’t see any major changes being made to the CFATS program in the coming year. Director Wulf and his dedicated chemical security inspectors will continue to make incremental improvements to the approval process for site security programs. Sometime this year the actual inspection process will begin for those facilities that have an approved site security plan.


Other than that the program will continue to muddle along, handicapped by the ineptitude of Congressional authorization and oversight.

Monday, August 26, 2013

CFATS PSP and Suspected Terrorists

I’m hearing rumors that DHS is getting close to the point where they will be issuing their 30-day notice for the information collection request supporting the CFATS personnel surety program. I did a series of blogs (listed below) on the comments that were received when DHS published the 60-day notice, now it is time to take a closer look at some of the issues that ISCD will have to address when they publish the 30-day notice.


Without a doubt the most controversial portion of earlier notice is the continued presence of a statement that DHS will not necessarily tell facilities if there is a positive match with the Terrorist Screening Database (TSDB). The notice states:

“Regardless of the [data submission] option, in the event that there is a potential match, the Department has procedures in place that it will follow to resolve the match and coordinate with appropriate law enforcement entities as necessary. High-risk chemical facilities may be contacted as part of law enforcement investigation activity, depending on the nature of the investigation.”

Needless to say facility owners and security managers are upset as hell that the folks at ISCD might allow a suspected terrorist to continue to continue to work at a high-risk chemical facility while some criminal investigation is underway. Almost as one industry commenters made clear that they would rather get a suspected terrorist out of their facility and risk not being able to take criminal action against them than allow them to stay and perhaps execute an actual attack while under investigation.

I am sure that David Wulf, Director of the Infrastructure Security Compliance Division, and his team of Chemical Security Inspectors (CSI, PLEASE someone change that title so we can get a different acronym) have the same concerns. I know that they realize that if a chemical facility attack happens under those circumstances that they will not be able to withstand the accusations of incompetence and malfeasance that will be leveled against them in Congress and the court of public opinion.

And those charges will be completely unjustified since it won’t be David’s call as to when facilities will be told that they have a suspected terrorist in their midst. That decision will almost certainly be made high within the ranks at the FBI or perhaps even in the office of the Attorney General. It is likely that David won’t even be told until such time as the law enforcement people have cleared the information for release.

The inevitable question that will be asked is why is it different for the TWIC? There the individual is notified if there is a positive match and there is an adjudication process in place for handling appeals. But TSA has never mentioned that they won’t tell an individual that his TWIC processing was rejected if there is a criminal investigation being conducted as a result of a TWIC submission. There will be an unexplained delay in the processing until the investigation is resolved. Then the individual will be notified of the reason, probably by an FBI SWAT Team.

It is a shame, in retrospect, that the folks at ISCD hadn’t just stood mute on the subject of criminal investigations of potential terrorist ties. If they had just said that the facility would be notified of any positive matches against the TSDB (which will eventually be the truth) things would have been fine. But no, someone decided to tell the whole story (or at least more of the whole story than had previously been done) and DHS is stuck with it.


Because, no matter how much industry legitimately complains about the risk to their facilities, the criminal justice system will not allow information about ongoing criminal investigations to be shared outside of the law enforcement community. Period, end of story.

Friday, April 12, 2013

CFATS PSP – TWIC Readers


This is part of a continuing series of blog posts about the CFATS Personnel Surety Program that was described in a 60-day information collection request (ICR) notice in Friday’s Federal Register. This post will look at how TWIC Readers could be used in PSP. The earlier posts in the series are listed below.


Many high-risk chemical facilities covered by CFATS share a significant work force, corporate and contract, with MTSA covered facilities. Additionally transportation workers (truck drivers and railroad personnel) may make up a significant number of the ‘visitors’ that a site might expect to extend some level of unescorted access to critical areas of the facility. As a result there was a major level of vocal concern with the original CFATS PSP proposal because it did not provide an easy option for facilities to take advantage of the fact that TWIC holders had already been vetted against the Terrorist Screening Database (TSDB). The new ICR notice specifically addresses this concern providing for the use of TWIC Readers as one of the vetting alternatives specifically available to facility security managers.

TWIC Reader Requirements

The ICR notice does not provide any specific guidance on how the TWIC Readers would be used at a high-risk chemical facility. This is not surprising given the §550 prohibition against requiring any specific security measure for the approval of a facility’s SSP. The notice provides the following guidance:

“High-risk chemical facilities could propose, in their SSPs or ASPs, to share the costs of TWIC readers and any associated infrastructure at central locations, or high-risk chemical facilities could propose to purchase and install TWIC readers for their own use. The Department will assess the adequacy of such proposals on a facility-by-facility basis, in the course of evaluating each facility's SSP or ASP.”

TWIC Reader at the Gates

The classic implementation of the TWIC Reader would be to install readers at a gate to allow security personnel to automate the verification of identity and appropriate vetting against the TSDB. This is the type of use expected to be employed at high-risk MTSA facilities where all personnel with unescorted access to the covered facilities or vessels are required to have a TWIC.

If TWIC Readers were to be used for vetting all personnel entering a facility for unescorted access each time they entered the facility, this would be a significant extension of the vetting requirements outline in the other two vetting options provided in this ICR notice as personnel would effectively be vetted against the TSDB every time the TWIC Reader updated its access to the Canceled Card List (CCL).

For facilities that have a large number of recurring visitors that are to be given even some limited amount of unescorted access to the facility, truck drivers and delivery personnel for instance, this could simplify the vetting requirements for these personnel by simply requiring that they possess a TWIC and then validating that TWIC with a TWIC Reader each time they access the facility.

TWIC Reader at Personnel Processing Center

The other option suggested in this ICR notice is the use of the TWIC Reader at a shared central location. The most obvious example of this would be to have a TWIC Reader at the Corporate Human Resources Department where an individual’s TWIC would be validated as part of the corporate hiring process. One would suppose that ISCD would prefer to see some sort of periodic revalidation of the TWIC outlined in the SSP since they intend to do periodic rechecks against the TSDB for personnel whom facilities submit information under the PSP.

Because of the high-cost of TWIC Readers (this notice suggests that the annualized three year cost of a TWIC reader and its upkeep at $99,953.33 per reader) smaller facilities, or facilities separated from corporate HR might wish to contract out the TWIC Reader validation to a third-party such as a back-ground check vendor or security contractor. Again one would suppose that there should be some sort of periodic revalidation of those checks outlined in the facility SSP.

ISCD TWIC Expectations

ISCD clearly does not expect very many facilities to avail themselves of the TWIC Reader option for personnel vetting. According to Table 22 in the notice they only expect that four facilities will install TWIC Readers as part of their PSP, three at Tier 2 theft/diversion facilities and one at a Tier 2 Group C (distribution type facility) facility. They base that on the number of facilities that share MTSA and CFATS status. This would be the type facility that would already be intending to use the TWIC Reader because of the impending requirements under the recently published TWIC Reader NPRM.

Does this mean that only those facilities will be allowed to use TWIC Readers as part of their PSP? I don’t think so. These are clearly facilities that would be expected to find the use of TWIC Readers to be most valuable since they will already be in use at certain entrances (MTSA covered areas of the facility) and virtually all personnel will already be required to possess a TWIC. But, ISCD clearly expects that the cost of the TWIC Reader will be a disincentive for its general use at facilities that are not already required to implement use of the TWIC for facility access.

Tuesday, April 9, 2013

CFATS PSP – Facility Analysis


This is part of a continuing series of blog posts about the CFATS Personnel Surety Program that was described in a 60-day information collection request (ICR) notice in Friday’s Federal Register. This post will look at the facility analysis used to calculate the regulatory burden caused by this ICR. The earlier posts in the series are listed below.


This ICR notice provides a relatively detailed look at the facilities that are included in the CFATS program; providing information that has been difficult to obtain because of the Department’s security concerns.

Categorizing Facilities

The Department has established four general descriptive categories of high-risk chemical facilities based upon the types of DHS chemicals of interest (COI) they have on site and the size of the facility. Three of the categories describe facilities where the primary security concern is based upon the possession of release hazard COI and the fourth describes facilities where theft/diversion of COI is the major security challenge.

ISCD divides the release COI facilities, ‘loss of containment’ is the term used in the notice, into three groups based upon the size of the facility:

Group A includes open facilities with 100 or more employees;
Group B includes open facilities with 99 or fewer employee; and
Group C facilities are enclosed facilities.

Table 4 in the notice provides a breakdown of the number of facilities in each category. I have provided a summary of that data in a slightly more readable format below.


Tier 1
Tier 2
Tier 3
Tier 4
Total
Group A
4
8
22
72
106
Group B
6
16
33
190
245
Group C
10
15
66
13
104
T/D
93
400
935
1683
3111
Total
113
439
1056
1958
3566
Table 1: Number of Facilities
What is very interesting is that theft/diversion facilities clearly predominate in every tier, with only a total of 455 facilities where a catastrophic on-site chemical release is the primary security challenge. The notice addresses points out that:

“In the original 2007 CFATS Regulatory Assessment, conducted prior to implementation of the CFATS Program, the Department assumed that 38 percent of all high-risk chemical facilities would be regulated due to the risk that one or more chemicals could be subject to theft or diversion for purposes of creating an explosion or producing an improvised explosive device. However, the 2012 CFATS Personnel Surety Program Analysis found that 87 percent of all currently regulated CFATS high-risk chemical facilities are regulated due to the risk that a chemical could be subject to theft or diversion for purposes of creating an explosion or producing an improvised explosive device.”

Unfortunately, that description fails to take into account that some of the COI where theft/diversion is the primary security hazard are not used to make explosive devices, but rather chemical weapons. It probably doesn’t affect any of the numbers, but it provides some misleading information.

Number of Employees

DHS makes an attempt to estimate the number of employees and resident contractors working at these facilities. This initial estimate is based upon 2007 CFATS program estimates plus some recommendations for changes included in the comments from the earlier ICR submission. The table below summarizes the data from Table 9 in the notice which provides the estimate for the average number of full time employees/contractors at a facility in the category, plus 20% for turnover (they are using this number to estimate the number of people that will undergo a personnel surety check).


Tier 1
Tier 2
Tier 3
Tier 4
Group A
3050
2176
3799
2207
Group B
50
49
68
200
Group C
201
418
409
265
T/D
46
46
46
46
Table 2: Update of 2007 CFATS personnel estimate

Looking at the numbers in the table above there seems to be some obvious problems with the models used to come up with these estimates. The variation in employee numbers from Tier to Tier within the same category is hard to explain when there is no variation in the numbers for threat/diversion facilities. With such a wide variance for data that is supposed to represent an average suggests that the standard variation within the data set is quite large. And, oh yes, the Group B definition was facilities with less than 99 employees; how did Tier 4 Group B get an average 200 employees and contractors?

One of the alternatives that ISCD mentions in the ICR notice is using data submitted by the facilities in their Top Screen submission. Table 3 below is a summary of that data reported in Table 10 in the notice. It includes the average Top Screen personnel numbers and an ACC estimate of the number of visitors to facilities (not by Tier) that will be given unescorted access requiring vetting.


Tier 1
Tier 2
Tier 3
Tier 4
ACC Visitors
Group A
719
267
713
884
1746
Group B
43
36
39
20
437
Group C
360
587
225
211
437
T/D
783
499
279
234
73
Table 3: CFATS Top Screen Personnel Data plus ACC visitor estimates

Using the data from Table 3, and plant numbers from Table 1 ISCD estimates that they would have to process 1,806,966 personnel surety screenings in the first year of the program and a three year average processing of 864,678 per year if ISCD were going to require all four tiers to participate in the personnel screening program. Since initially only Tier 1 and Tier 2 facilities will participate the numbers are reduced to 412,647 in the first year and average 191,845 per year.

Sunday, March 31, 2013

CFATS PSP – Only Tier 1 and 2 Facilities Impacted


This is part of a continuing series of blog posts about the CFATS Personnel Surety Program that was described in a 60-day information collection request (ICR) notice in Friday’s Federal Register. This post will look at the decision to only apply this ICR to Tier 1 and Tier 2 facilities. The earlier posts in the series are listed below.


While the discussion through much of the ICR notice mentions all CFATS facilities, buried in the discussion of calculating the burden of the ICR is a statement that the ICR will only apply to Tier 1 and Tier 2 facilities.

Testing PSP
One of the suggestions that ISCD received after the last 30-day ICR notice was forwarded to OMB (and subsequently withdrawn) was that ISCD should do the same thing that it had done with most major CSAT tool deployments (excepting the SSP) and test the tool before it was officially deployed. This would allow the bugs to be worked out of the program.

While this probably would have been a good idea two years ago when the PSP was initially proposed (and before the Department started evaluating SSPs), this is no longer a reasonable prospect before the PSP ICR is submitted and approved. Too many facilities are receiving provisional authorizations for their SSP without a method being available to complete the personnel surety terrorist vetting required under RBSP #12.

Besides, even in conducting a test version of the PSP tool with live data (the only type of test that would be really worth while) would still require an approved ICR to collect the data and have it entered into the CSAT application. Thus the ICR must go forward without a live system test.

Limited PSP Implementation

ISCD has worked out a way to test the PSP application and the data collection and submission process from a variety of facilities, as well as evaluate the assumptions underlying the burden estimates in the ICR. They will limit the initial application of the PSP tool to just Tier 1 and Tier 2 facilities. They estimate that this will entail only 552 facilities and about 192,000 individual. This is compared to about 4,000 facilities and over 2 million individuals for a full deployment of the PSP.

Tier 3 and Tier 4 facilities are not being exempted from the PSP. ISCD intends that “ a subsequent ICR would be published and submitted to OMB for approval to incorporate any lessons learned and potential improvements to the CFATS Personnel Surety Program prior to collecting information from Tier 3 and Tier 4 high-risk chemical facilities” (78 FR 17696).

Friday, March 29, 2013

CFATS PSP – Other Information to be Collected


This is part of a continuing series of blog posts about the CFATS Personnel Surety Program that was described in a 60-day information collection request (ICR) notice in Friday’s Federal Register. This post will look at what additional information (in addition to the personally identifiable information (PII) previously discussed) ISCD might require a high-risk chemical facility to submit to DHS under the CFATS PSP. The earlier posts in the series are listed below.


While the bulk of the information collection covered under this ICR will be the PII used to vet personnel against the Terrorist Screening Database (TSDB), there is additional information that ISCD will be collecting in its administration of the PSP at the Department level.

Information about the High-Risk Facility

Since the Department envisions that many high-risk facilities will use third-party organizations to submit the PII required for the PSP on it facility personnel, the PSP tool in the on-line Chemical Security Assessment Tool (CSAT) will require information “ that identifies the high-risk chemical facility, or facilities, at which each affected individual has or is seeking access to restricted areas or critical assets” (78 FR 17686). From that wording it would seem that vendors and contractors supporting multiple high-risk facilities will be required to identify which facilities they routinely support as part of their data submissions in the PSP tool.

Additional information may be collected from the facility about its PSP in support of adjudications under Subchapter C of 6 CFR Part 27; in processing requests for extensions,

High-risk chemical facilities will also be required to provide ISCD with a point of contact for the collection of additional information about the facility, its PSP, and individuals who have had their PII submitted for screening.

Additional PII

The previously identified PII will be routinely collected on any individual based upon which submission option the facility chooses to use in their PSP filings. ISCD realizes that from time to time they will have to request additional information about an individual to better confirm or deny potential matches in the TSDB. ISCD and law enforcement agencies might also be expected to contact the facility for further information about individuals that have been identified as matches against the TSDB. The notice makes the point that a “request for additional information from the Department does not imply, and should not be construed to indicate, that an individual is known or suspected to be associated with terrorism” (78 FR 17686).

Additional information may be collected about individuals in the PSP as part of the adjudications under Subchapter C described above. Additionally redress requests by individuals may require facilities to provide additional information about an individual. Unfortunately, this is the only mention of ‘redress’ for individuals who feel that they are wrongly identified as having terrorist ties. This may be because the Department will not necessarily notify the facility if an individual is identified as having terrorist ties and thus individuals are unlikely to know if they are wrongly identified.

The reference in this ICR to redress does mention (in a footnote) a series of Privacy Act documents that the Department issued in June of 2011 as part of the original ICR submission to OMB that was subsequently withdrawn. Those documents will certainly be revised as this new ICR moves forward.

Odd Information

There is one odd paragraph in this section of the ICR; it deals with the collection of what would generally be described as file numbers. The notice states that there will be ‘blank data fields’ in the PSP tool in CSAT that will allow the facility to enter a designation or number unique to an individual so that a facility may better track the data submission. I can’t see any reason why a facility submitting information on their own employees would really need this, but it would sure come in handy for third-party submitters, vendors and contractors who might need to keep track of what facilities are associated with a particular individual.

Tuesday, March 26, 2013

CFATS PSP – Who Submits Information?


This is part of a continuing series of blog posts about the CFATS Personnel Surety Program that was described in a 60-day information collection request (ICR) notice in Friday’s Federal Register. This post will look at how ISCD expects facilities to organize the submission of the required personally identifiable information (PII). The earlier posts in the series is listed below.


Facility Responsibility

The individual high-risk chemical facility covered under the CFATS program is responsible for implementing the Personnel Surety Program (PSP) as part of their facility site security plan (SSP). That does not mean, however, that they will be submitting the personal information on all of the people that work at the facility or will have unescorted access to critical areas of the facility as visitors, contractors or vendors. DHS has provided for a number of different options for the facility to use as part of its PSP. The four basic options are:

• The facility submits information on all affected individuals for the facility;
• The parent company submits information on all affected individuals for the facility;
• Either the facility or the parent company designates a third-party to submit the information; or
• The PSP includes some combination of the three for different classes of affected personnel.

The notice explains that vendors and contractors would have essentially the same options available for vetting their personnel that would have unescorted access to critical areas of high-risk chemical facilities. What is not made clear is how the vetting done by vendors and contractors would be communicated to the facility security manager and how those records would be made available to ISCD Chemical Facility Inspectors conducting compliance inspections. Would facilities have to submit the same type of abbreviated information that it does for personnel that had already undergone a TSA security threat assessment?

CSAT Application

Anyone that is familiar with the various roles defined in the current CSAT applications will quickly realize that only one of the options outline above could be directly rolled into the current CSAT roles of Authorizer, Submitter, Preparer and Reviewer. With this in mind the notice mentions a new role for the CSAT process; the Personnel Surety Submitter (PSS). As we saw when ISCD allowed for multiple submitters with the advent of the SSP tool, the notice makes clear that they expect that many facilities will use multiple PSS.

There is not a great deal of information in the notice about the PSS, but we can expect that the PSS will have to go through a similar process of identifying and notifying ISCD of the appointment of PSS. One would also expect that when an individual is logged into CSAT in a PSS role, they will only have access to facility PSP information. What is not so readily apparent is whether or not personnel with current access to the CSAT application in existing roles will be able to access the PSP information as well. Privacy issues may require limiting access to that information.

Another thing that is not immediately clear from this discussion in the PSP notice is the CVI status of the submitted information. Currently the Registration application and the Top Screen application do require that someone with access to those CSAT applications have completed the Chemical-Terrorism Vulnerability Information (CVI) training program. The two remaining CSAT applications (Security Vulnerability Assessment – SVA – and the Site Security Plan – SSP) do require the possession of a CVI training certificate to be able to access the applications. If it is determined that PSP information is not CVI, then it is likely that ISCD will not require CVI training for personnel performing PSS duties.

The CSAT User Roles and Responsibilities section of the notice does not address how vendors and contractors that will be submitting the information on their employees fit into this CSAT application process. Will their PSS have to be appointed by the Authorizer of the supported high-risk chemical facility or will a management member from the vendor or contractor be able to appoint their own PSS?

Realistically, these details will be more suited to explication in the inevitable revision of the CSAT Registration Manual that will be necessitated by the addition of the PSS to the list of positions that require CSAT Registration.

Monday, March 25, 2013

CFATS PSP – Who Gets Screened


This is the second in a series of blog posts about the CFATS Personnel Surety Program that was described in a 60-day information collection request (ICR) notice in Friday’s Federal Register. This post will look at who ISCD expects facilities to screen via the PSP and who is not required to be vetted. The earlier post in the series is listed below.


Regulation Requires Screening

The notice explains that there are two broad groups of individuals that are covered by the Personnel Surety Program vetting requirements:

• Facility personnel who have access, either unescorted or otherwise, to restricted areas or critical assets, and
• Unescorted visitors who have access to restricted areas or critical assets.

In the earlier release of the PSP ICR there were numerous industry objections to the requirement that facility personnel who only have escorted access should be vetted through the PSP. The ISCD response then was that this definition comes straight out of the CFATS regulations {6 CFR 27.230(a)(12)} so the Department’s hands are tied; changing the requirement would entail a rule change which is outside the scope of an ICR.

Contractors and Vendors

The question also came up concerning how facilities should deal with contractors and vendors; are they ‘facility personnel’ or are they visitors?

The ISCD response to the earlier ICR submission was:

“Individual high-risk facilities may classify particular contractors or vendors, or categories of contractors or vendors, either as “facility personnel” or as “visitors.” This determination should be a facility-specific determination, and should be based on facility security, operational requirements, and business practices.”

How facilities deal with contractors and vendors will have to be addressed in the facility site security plan. The more complex the rules set up in the SSP for dealing with this issue the harder it is going to be to justify to ISCD during the SSP authorization and approval process.

Screening Not Required

During the previous ICR review process ISCD had to answer questions about how emergency response personnel and government inspectors would have to be dealt with in the PSP. Instead of waiting for the inevitable questions to arise, this ICR notice specifically addresses the situation. It broadly defines three classes of personnel that the facility will not need to vet through the PSP:

• Federal officials that gain unescorted access to restricted areas or critical assets as part of their official duties;
• State and local law enforcement officials that gain unescorted access to restricted areas or critical assets as part of their official duties; and
• Emergency responders at the state or local level that gain unescorted access to restricted areas or critical assets during emergency situations.

There is a major difference in the way that federal officials and State and local officials are treated in this rule. The wording for federal officials is not limited to law enforcement as are the State and local officials. Thus federal regulatory personnel could be allowed unescorted access while State and local regulatory officials would have to be escorted.

The notice acknowledges that there might be emergency or exigent circumstances that require allowing other classes of people unescorted access to the to secure areas or critical areas of the facility without being able to go through the PSP vetting process. The Department notes that these situations should be addressed in the facility site security plan:

“If high-risk chemical facilities anticipate that any individuals will require access to restricted areas or critical assets without visitor escorts or without the background checks listed in RBPS 12 under exceptional circumstances, facilities may describe such situations and the types of individuals who might require access in those situations in their SSPs or ASPs. The Department will assess the appropriateness of such situations, and any security measures to mitigate the inherent vulnerability in such situations, on a case-by-case basis as it reviews each high-risk chemical facility's SSP or ASP.”

This could be used if there are State or local requirements for unannounced inspections of facilities by regulatory agencies or other State or local government regulations that require inspectors be allowed unaccompanied access to the facilities. Including these requirements in the facility SSP would allow ISCD the opportunity to make the decision as to whether or not their vetting rules pre-empted the State or local laws or regulations.

Saturday, March 23, 2013

CFATS PSP – Data Submission Options


This is the second in a series of blog posts about the CFATS Personnel Surety Program that was described in a 60-day information collection request (ICR) notice in Friday’s Federal Register. This post will look at the data submission options for vetting personnel against the Terrorist Screening Database (TSDB). The earlier post in the series is listed below.


The PSP Requirement

The CFATS program regulations require facilities to establish a personnel surety program (PSP) vetting process {6 CFR 27.230(a)(12)}. That program is required to perform four types of background checks on “facility personnel, and as appropriate, for unescorted visitors with access to restricted areas or critical assets”. Those required checks are:

• Measures designed to verify and validate identity;
• Measures designed to check criminal history;
• Measures designed to verify and validate legal authorization to work; and
• Measures designed to identify people with terrorist ties.

Facility management has a wide degree of latitude in establishing the methodology for conducting the first three types of checks. The last measure “is an inherently governmental function and necessarily requires the use of information held in government-maintained databases that are unavailable to high-risk chemical facilities” (FR 17681). It is this vetting requirement that is addressed in this ICR notice.

Data Submission

The DHS Infrastructure Security Compliance Division (ISCD) has plans to introduce a new data collection application in the Chemical Security Assessment Tool (CSAT) to allow facility security managers or their designees to submit information to ISCD to complete the vetting process. This ICR, if/when approved by the Office of Management and Budget (OMB), serves as the approval of that application to collect the required information.

DHS outlines in this notice three different options that facilities will have for conducting the vetting of personnel against the government’s TSDB. Facilities will be able to use almost any combination of the three options in the establishment of their PSP that will be outlined in the facility site security plan.

The three options are:

• Option One - Direct Vetting
• Option Two - Use of Vetting Conducted Under Other DHS Programs
• Option Three - Electronic Verification of TWIC

Option One

Option One requires the most comprehensive submission of information to ISCD via the PSP application. The following information would be required for each individual vetted under Option One:

• For U.S. Persons (U.S. citizens and nationals as well as U.S. lawful permanent residents):
• Full Name
• Date of Birth
• Citizenship or Gender
• For Non-U.S. Persons:
• Full Name
• Date of Birth
• Citizenship
• Passport information and/or alien registration number

Interestingly, there is no requirement to supply biometric information (finger prints for instance) to verify the identity of the individual. Apparently ISCD believes that the identify verification requirements that the facility is already required to perform under other provisions of its PSP will be adequate to ensure that the information required above will be adequate to the task of vetting against the TSDB.

The PSP CSAT application will also allow the submission of the following information under Option One to help avoid misidentification of individuals:

• Aliases
• Gender (for Non-U.S. Persons)
• Place of Birth
• Redress Number

TSA has a program to allow people who believe that they have been improperly identified as having potential terrorist ties to have a more thorough investigation completed to correct the record. The ‘Redress Number’ provides a reference to that investigation to ensure that the same mistaken identification is not made again. This ‘Redress Number’ is probably the only item of information that the high-risk chemical facility is not already collecting in support of its personnel surety program.

Option Two

There are already a number of DHS programs that vet various people against the TSDB. Those programs include:

• Transportation Worker Identification Credential (TWIC) Program;
• Hazardous Materials Endorsement (HME) Program;
NEXUS;
Free and Secure Trade (FAST); and


If individuals have already been vetted under one of these programs DHS does not need to complete the same level of investigation to ensure that they are not listed on the TSDB. All ISCD needs to do is to verify that the previous vetting is still current and valid. To do that the following information would need to be submitted via the PSP application:

• Full Name;
• Date of Birth; and
• Program-specific information or credential information, such as unique number, or issuing entity (e.g., State for Commercial Driver's License (CDL) associated with an HME).

Again, there would be provisions for submitting additional information to help to avoid misidentification of personnel. For Option 2 these include:

• Aliases
• Gender
• Place of Birth
• Citizenship

Option Three

When the original PSP ICR was submitted a couple of years ago one of the main industry complaints was having to submit information on personnel that had a TWIC. At the time ISCD maintained that they needed to collect the information to ensure that the TWIC was still valid. While this is still the justification for the use of Option 2, the availability of TWIC readers that have been validated by TSA provides a new alternative.

Option 3 would allow a “high-risk chemical facility (or others acting on their behalf) electronically verify and validate the affected individuals' TWICs through the use of TWIC readers (or other technology that is periodically updated using the Canceled Card List)”. It is not clear from the description in the notice whether this would require daily presentation of the card at the facility or whether it could be accomplished on a less frequent basis as a personnel action.

Option Four

While there is no official Option Four the notice does mention some ways that the high-risk chemical facility can limit the number of people that have to be vetted under the PSP. This discussion in the notice does not specifically state that it applies only to visitors (and perhaps contractors) since all facility employees are required by the CFATS regulations {6 CFR 27.230(a)(12)} to be vetted, whether or not they have unescorted access to restricted or sensitive areas of the high-risk facility.

The options outlined in the notice include:

• Restricting the numbers and types of persons whom they allow to access their restricted areas and critical assets, thus limiting the number of persons who will need to be checked for terrorist ties;
• Defining the restricted areas and critical assets in the SSPs or ASPs, thus potentially limiting the number of persons who will need to be checked for terrorist ties; or
• Choosing to escort visitors to restricted areas and critical assets in lieu of performing the background checks required by RBPS 12.

Combining Options

There is nothing in the notice that would even appear to suggest that a high-risk chemical facility is limited to just one of the options in establishing the terrorist link vetting portion of their PSP. In fact there are a number of areas where it is suggested that different classes of employees or visitors may be better covered by different options.

All a facility has to do in their site security plan (or alternative site security plan) is to outline how they will determine which class of employees will be addressed by each of the three options provided by the ISCD program. It will also have to address how it will ensure that all employees, and the contractors and visitors with unescorted access to restricted or sensitive areas are vetted through at least one of the options provided.

NOTE: I have taken the liberty of lumping ‘contractors’ with visitors in the above statement. The CFATS regulations do not specify how contractors will be treated in the vetting process. An argument could certainly be made that at many high-risk chemical facilities contractors are essentially employees since they will be working at the facility on a daily basis for long periods of time. Legalistically, however, a contractor is not an employee of the facility. The distinction should be clearly made in the facility site security plan to avoid possible repercussions down the line.
 
/* Use this with templates/template-twocol.html */