Showing posts with label Personnel Surety. Show all posts
Showing posts with label Personnel Surety. Show all posts

Tuesday, September 8, 2026

GAO Publishes Report on Chemical Plant Personnel Screening

Today, the Government Accountability Office (GAO) announced the publication of their report on “Chemical Security: DHS Should Provide Options for Voluntary Vetting of Facility Personnel for Terrorist Ties”. GAO was asked to evaluate the effects of the end of the CFATS program in 2023 and the decline in CISA chemical security staffing since 2025 on chemical facility security.  

The report noted that (pg 5): 

According to CISA officials and representatives from the private sector coordinating council, the three selected chemical associations, and the six selected chemical companies we interviewed, losing the Personnel Surety Program is the most significant challenge high-risk chemical facility owners and operators have faced following the discontinuation of the CFATS program. CISA officials also stated that discontinuing the Personnel Surety Program left a gap in chemical facility security that poses significant risks. 

The Report made one recommendation (pg 16): 

Identify, evaluate, and implement voluntary options for chemical facility owners and operators to address insider terrorist security risks by vetting their personnel and unescorted visitors with access to restricted areas or critical assets, and, if necessary, seek the legislative authority to do so. 

The official CISA response to the recommendation (pg 16): 

The voluntary collection and handling of sensitive personal information necessary to conduct such vetting would raise significant legal, privacy, compliance, and resource considerations. These considerations include proper collection, use, maintenance, and protection of sensitive personal information necessary to support such activities, as well as requirements associated with safeguarding personal data and providing appropriate redress 

Saturday, February 12, 2022

CISA Publishes CFATS Personnel Surety 30-day ICR

Yesterday, CISA published a 30-day information collection request (ICR) notice in the Federal Register (87 FR 8026-8027) for “Revision of a Currently Approved Information Collection for the Chemical Facility Anti-Terrorism Standards (CFATS) Personnel Surety Program”. This is a follow-up to the 60-day notice that was published on June 23rd, 2021 (I have made the linked post on CFSN Detailed Analysis free content).

The Notice indicates that CISA had received one ‘nongermane’ comment to the 60-day Notice. That ‘comment’ is hard to read with a convoluted grammar and odd word usage. I would have to agree that the comment should have no impact on the ICR consideration.

CISA has posted the full supporting statement [.docx download link] to the OIRA web site for this ICR (1670-0029). That statement contains the justification and the burden estimate for the ICR. There are no programmatic changes being made in this ICR. Changes in the burden estimate reflect the recent history of the program.

CISA is soliciting public comments on this ICR. Comments may be submitted via the ICR site via the ‘COMMENT’ button. Comments should be submitted by March 14th, 2022.

Friday, May 29, 2015

EAP Guidance – Personnel Surety

This is part of a continuing series of blog posts on the newly released Expedited Approval Program (EAP) guidance document for Tier 3 and Tier 4 facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in the series are:


In this post I will look at the personnel surety requirements of the EAP. These are covered in section F (pg 50 and pg 86) of the EAP guidance document along with a number of other security management measures. The personnel surety program is covered under the Risk-Based Performance Standard #12 in the RBPS guidance document. In the CFATS regulations there are four personnel surety requirements at 6 CFR 27.230(12). They are:

∙ Measures designed to verify and validate identity;
∙ Measures designed to check criminal history;
∙ Measures designed to verify and validate legal authorization to work; and
∙ Measures designed to identify people with terrorist ties;

The EAP guidance document only specifically addresses the first three requirement because ISCD has yet to complete their Personnel Surety Program (PSP) that would address the method of identifying people with terrorist ties. I’ll discuss this further at the end of this post.

EAP Checklist

The EAP checklist lists eight personnel surety requirements:

∙ The facility has identified all affected individuals;
∙ The facility verifies and validates the identity of all affected individuals by a government issued ID or identification document as listed on the I-9 form;
∙ The facility conducts a criminal history check on all affected individuals through a third party background investigation company, national program, or local law enforcement agency. This background check includes national, state, and local resources for a timeframe of no fewer than five years and the report identifies all felonies, at a minimum;
∙ The facility has a process for adjudicating the results of background checks and determining access restrictions in a reasonable manner;
∙ Upon notification from DHS, the facility will implement a process to identify all affected individuals with terrorist ties;
∙ The facility escorts all visitors which do not have background investigations via an approved and trained escort; and
∙ The facility maintains documentation (at a minimum: employee name, how the required checks were conducted, and the results of the checks) of background checks for all current affected individuals in order to demonstrate compliance with personnel surety requirements.

The term ‘all affected individuals’ is specifically defined as:

∙ Facility personnel who have or are seeking access, either unescorted or otherwise [emphasis added], to restricted areas or critical assets; and
∙ Unescorted visitors who have or are seeking access to restricted areas or critical assets.

There are two items from the RBPS Metrics (pgs 99-100) that are not addressed in the EAP guidance. First Metric 12.2 for Tier 3 facilities requires that investigations “are repeated for all individuals at regular intervals”. And Metric 12.5 for all facilities requires that the background check program is audited annually.

Additional EAP Information

The discussion of the personnel surety program in the EAP guidance (pgs 50-52) provides only limited amounts of additional information. Most importantly, the guidance does make it clear that owners have some leeway in determining whether or not contractors are included in the term ‘facility personnel’.

There is surprisingly detailed guidance as to what constitutes ‘verifying ID. It includes:

∙ Comparing the picture on the card with the owner;
∙ Comparing the physical characteristics against the person’s physical appearance;
∙ Checking for tampering;
∙ Reviewing both sides of the card; and
∙ Checking the expiration date.

Terrorist Ties Checking

There is currently no approved method for facilities to check for personnel with terrorist ties. ISCD is responsible for setting up this program and has had problems getting the PSP program approved by the Office of Management and Budget due to industry opposition to many of the program elements. The most current proposal has been under review since March of 2014.

The most vociferous critics, and certainly the most influential, have been in Congress. The CFATS statute passed last session (HR 4007) specifically addressed those congressional concerns with the PSP program {6 USC 622(d)(2)}. While that statute requires DHS to establish a CFATS program to identify personnel with terrorist ties, it also allows facility owners to use other “Federal screening program that periodically vets individuals against the terrorist screening database” {§622(d)(2)(B)(i)(I)}. Additionally it requires that a facility accept any credential from such ‘Federal screening program’ if offered by an individual as proof that a covered individual has been screened for terrorist ties.

These new requirements for the PSP program will require a substantial re-write of the program that was submitted to OMB last year. It appears that ISCD is still going to rely on the Information Collection Request (ICR) route for obtaining approval of the PSP program. A footnote on page 6 of the EAP guidance notes that:

“Compliance with RBPS 12(iv) will be required for Tiers 1 and 2 upon approval of an Information Collection Request under the Paperwork Reduction Act, and upon notification to facilities by DHS that the CFATS Personnel Surety Program (i.e., the program enabling compliance with RBPS 12(iv)) has been implemented.”

This is the same two-stage implementation plan that ISCD had proposed in its last PSP proposal. This would allow it to implement the program at the highest risk facilities (and a smaller number of facilities) first. As the bugs were worked out and ISCD had a better idea of the number of individuals that would be affected at the Tier 3 and Tier 4 facilities, ISCD would then go back with a revision to the ICR to allow application of the PSP to Tier 3 and 4 facilities. This means that it could be quite some time before Tier 3 and Tier 4 facilities have to worry about the terrorist ties vetting of their covered personnel.

Commentary

Like the cybersecurity requirements the personnel surety requirements of the EAP are rather vague and potentially allow facilities a great deal of latitude in how those requirements are met. It also means that facilities might face the very real prospect of having DHS specify particular vetting requirements that must be taken when the compliance inspection is completed. This potentially could substantially increase the cost of the personnel surety program and those new costs could come with a very short implementation period.

There is also an interesting new requirement for the Tier 3 and Tier 4 programs that was not included in the original personnel surety requirements outlined in the RPBS guidance document. It is the fifth point in the personnel surety checklist:

∙ The facility has a process for adjudicating the results of background checks and determining access restrictions in a reasonable manner;

This was undoubtedly added due to the new requirement in the CFATS statute {6 USC 622(d)(2)(A)(iii)(II)} for establishing a redress process. That requirement, however, was specifically targeted at individuals who had been vetted against the terrorist screening database via the ISCD PSP. The way it is implemented in the EAP expands that requirement (legitimately so in my opinion) to include all of the background checks in that redress program.


What is not clear is if ISCD has been ‘requiring’ such a redress program in all of the site security plans that it has been authorizing and/or approving to date. There certainly has not been anything publicly discussed about such a requirement. If not, it will be interesting to see if and how ISCD goes back to the non-EAP facilities with approved SSPs to get such a program put in place for non-PSP background checks.

Tuesday, April 29, 2014

Homeland Security Committee Publishes CFATS Substitute Language

Today the Homeland Security Committee added a note to their web page for their Wednesday markup hearing (that I discussed this weekend) reporting that Rep. Meehan (R,PA) will be offering another set of substitute language for HR 4007. Since there is not an official version of the bill as marked up by Meehan’s Subcommittee it is difficult to sort out the ‘small’ changes in the language. The big changes are easy to see.

Personnel Surety

This bill continues to try to deal with industry complaints about the personnel surety program under development by DHS. The wording gets more confusing and it seems the only intent of the new wording is to eliminate the personnel surety program. The legislation spends much more time explaining what DHS cannot do than it does defining what should be accomplished by the program.

The one positive new addition in this portion of the bill is a requirement for DHS to “to expedite the development of a common credential that screens against the terrorist screening database on a recurrent basis and meets all other screening requirements of this title” §2101(d)(3)(C)(i). Unfortunately this is a far cry from a legislative mandate for a CFATS equivalent of the MTSA TWIC. Only a clear legislative mandate will make this a program that will be accepted by the entire chemical industry.

One of the objections that the Democrats have always had with all of the personnel surety programs discussed to date for CFATS is the lack of a redress process for personnel that believe they have been incorrectly identified as having terrorist ties. New language has been added to this bill to address that concern, kind of. The new language requires the Secretary to establish a personnel surety program that provides redress to an individual “who believes that the personally identifiable information submitted to the Department for such vetting by a covered chemical facility, or its designated representative, was inaccurate” §2101(d)(3)(A)(iii). This completely ignores that possibility of being incorrectly identified as having terrorist ties due to an error on the part of the Government.

Rail Facility Exemption

DHS has long maintained that the responsibility for regulating the chemical security of rail facilities lies with TSA. This was specifically addressed in the pre-amble to the CFATS interim final rule in the Federal Register (72 FR 17688-17745) (see page 17699 for that discussion). Apparently, someone has had some concerns with the final sentence in that discussion:

“DHS may in the future, however, re-evaluate the coverage of railroads, and would issue a rulemaking to consider the matter.”

In any case §2104(c)(1), Rail Transit, makes it explicitly clear that any rail facilities regulated under 49 CFR 1580 will not be affected by the new CFATS regulation. Those facilities would certainly include designated ‘rail secure areas’ for all railroad hazmat shippers handling rail sensitive materials {§1580.107(a)(2)} and for all railroad receivers in high threat urban areas receiving rail sensitive materials {§1580.107(a)(2)}.  

Then §2104(c)(2) goes one step further and exempts all railroad facilities as defined in 1580.3 as being exempt from requirements to submit a Top Screen. That definition states:

Rail facility means a location at which rail cargo or infrastructure assets are stored, cargo is transferred between conveyances and/or modes of transportation, where transportation command and control operations are performed, or maintenance operations are performed. The term also includes, but is not limited to, passenger stations and terminals, rail yards, crew management centers, dispatching centers, transportation terminals and stations, fueling centers, and telecommunication centers.”

This would specifically exempt most crude oil train loading facilities from CFATS regulations. This is even though the security at those facilities is not regulated by TSA since crude oil is not a rail sensitive material as defined in §1580.100(b).

Other Exemptions Removed

All language exempting other facilities from the CFATS coverage has been removed from this bill. This means that the following facilities would be required to submit a Top Screen to DHS if they had one or more of the 300+ DHS chemicals of interest (COI) listed in Appendix A to 6 CFR Part 27 at or above the screening threshold quantity set for that chemical in that Appendix:

• MTSA covered facilities;
• Public water systems;
• Treatment works;
• DOD owned facilities; and
• NRC regulated facilities

The language maintaining the current CFATS statutory exemption for these facilities had been found in the definition of ‘Covered Facility’ in what is now §2101(f)(1). There is no trace of that language there, or anywhere else in the bill. This is certainly a sweeping addition of responsibility for the folks at the DHS Infrastructure Security Compliance Division (ISCD). It is particularly surprising given the new exemption for rail facilities that are not covered by any security scheme.

Still Missing

This bill is still missing any language that would allow it to be considered successfully in the Senate. There is no mention of employee participation or inherently safer technology. Without even the most stripped down language addressing these areas there is no way that this bill, no matter how quickly it is passed in the House, would ever begin to see debate in the Senate, much less pass a cloture vote.

Democrats will certainly offer such language in Wednesday’s hearing. It will be interesting to see if they can craft language that will be acceptable to the Republican majority on the panel. If they cannot, then this bill will be effectively dead.


Wednesday, April 2, 2014

Substitute Language for HR 4007

Yesterday the House Homeland Security Committee posted a link to the substitute language for HR 4007 that the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee will consider at their HR 4007 markup hearing tomorrow. A number of relatively minor changes are made but amendment in the form of a substitute does increase the length of the authorization period and includes authorization of spending for the CFATS program.
Authorization
The substitute language revises §7 extending the termination date from 2 years to 3 years after the bill becomes law. This provides a little more time for Congress to prepare a permanent comprehensive

CFATS bill. Section 9 has been added to the bill providing spending authorization for the CFATS program. The spending level is set at $87,436,000. This is up from the $81,000,000  included in the FY 2014 spending bill passed in January. The additional money may be intended to fund the Ammonium Nitrate Security Program.

Ammonium Nitrate Security Program
Section 10 would be added to the bill by this substitute language, addressing the long overdue ammonium nitrate security program. It amends 6 USC 488a adding language to subsection (a) that clarifies the activities covered by the ANSP.

Substitute language is also provided for §488a(f) that adds transportation activities to the exempted from coverage of the ANSP. It adds a specific exemption for transportation activities regulated under 49 USC Chapter 51, Transportation of Hazardous Materials, or 49 USC 114(d) which provides for TSA responsibility for all transportation related security issues.

Personnel Surety
The substitute re-writes §2(d)(3) to make it clear that DHS may not require facilities to submit any information to ISCD that have been vetted for terrorist ties under “any Federal screening program that periodically vets individuals against the terrorist screening database” {§2(d)(3)(A)},

Information Sharing

Section 3 adds a paragraph related to information sharing with first responders, at least that is the title of the paragraph. It actually requires the Secretary to provide, via the Homeland Security Information Network (HSIN), “such information as is necessary to help ensure that first responders are properly prepared and provided with the situational awareness needed to respond to incidents at covered chemical facilities” {§3(c)}. It does not actually require sharing this information with local first responders. It requires that the information be provided to State, local and regional fusion centers. There are no requirements to push that information actual first responders.

Not Covered


This revised language does not address the two issues that have been responsible for the failure of Congress to be able to pass and CFATS related legislation since the §550 language was included in the FY 2007 DHS spending bill. Those two topics are the use of inherently safer technology and worker participation. Those topics do not need to be addressed to pass in the Republican controlled House, but will have to be included to be considered by the Democratic controlled Senate.

Thursday, January 30, 2014

Latest CRS Report on CFATS

Earlier this month the Congressional Research Service (CRS) published their latest version of their report on the Chemical Facility Anti-Terrorism Standards (CFATS) program. This periodic report by Dana Shea summarizes the current state of the CFATS program, explains current problems facing the program. Past reports included an analysis of various potential solutions for CFATS problems that may require Congressional action, that is missing from this version.

SSP Process

Given the on-going congressional concern about the progress being made on the Site Security Plan (SSP) front Shea takes a detailed look at that portion of the program. This discussion begins very good, concise summary of the SSP regulatory process:

“Over time, the DHS has attempted to develop a consistent nomenclature for its review and inspection process. The DHS authorizes an SSP (issuing the facility a letter of authorization) when the submitted SSP is satisfactory under CFATS. The DHS conducts an authorization inspection of a facility with an authorized SSP to compare the authorized SSP to the conditions of the facility. Following a successful authorization inspection, the DHS approves the SSP (issuing the facility a letter of approval). At a later date, expected to be one year after approval of the SSP, the DHS will conduct a compliance inspection of a facility to determine whether the facility has fully implemented its approved SSP. Compliance inspections then occur on a periodic basis depending on the risk tier to which the facility is assigned.” [Footnotes removed]

What is missed in this discussion is why such a complicated SSP process is necessary. Since Congress declared in the CFATS authorization that DHS may not specify what security measures are required for SSP approval, DHS was forced to publish a rather vague Risk-Based Performance Standards (RBPS) guidance document and facilities were left to guess what security measures to put into their proposed SSP. Since security is not a profit center, the apparent actual risk of a terrorist attack is low (no attacks to present and no reports of credible threats against chemical facilities), and security measures usually complicate day-to-day operations, facilities want to establish just the minimum security measures required to assure compliance with CFATS. As a result, there is a natural tendency to under-guess what is required for compliance.

Further complicating the process is the fact that the current SSP data submission tool in the on-line Chemical Security Assessment Tool (CSAT) uses a question/response format that solicits a limited amount of specific information about the proposed SSP and relies on the addition of narrative submissions for the bulk of the details about the program. Facility security managers have every incentive to limit the amount of information that they provide since any changes to that information after the SSP is approved will have to be vetted through DHS before it can be changed. Limiting the scope of that DHS operational veto is in the best interest of the facility management.

The disjointed and frequently duplicative organization of the information in the SSP tool further aggravates the approval process by making it difficult for inspectors to preview the submitted data before they conduct their authorization inspections. Since large chemical facilities are already complicated physically and operationally, inspectors have to become familiar with the unique operational aspects of the facility and become familiar with the proposed SSP at the same time during the scope of a three day inspection.

Digesting that inspection information and preparing a coherent report on how well the facility complies with the RBPS is a time consuming process. This is complicated by the fact that every chemical facility is unique in its surroundings, operations, hazards and susceptibility to terrorist attack. Further, the Chemical Security Inspector (CSI) needs to have an operational understanding of chemical safety, physical security, operations security, and cybersecurity to adequately understand all of the implications of the proposed SSP.

Finally, the CSI workforce is limited to about 160 personnel which include regional commanders who would be expected to spend only limited amounts of time in actual inspection activities. Authorization inspections are typically conducted by 3 to 5 inspectors depending on the size and location of the facility.

Inspection Rate

Shea spends a great deal of time analyzing the rates of authorization, inspection and approval and their inter-relationships. I would assume that this was done at the request of various Committee Chair who are legitimately concerned with the progression of that process. Looking strictly at statistical data Shea has provided detailed information about the number of actions that are necessary to complete the SSP process in a variety of time frames. Table 1 below summarizes the Shea data for the average monthly rates for achieving completion of the SSP authorizations and approvals for the facilities currently the program.


Current
1 year
2 year
5 year
10 year
Authorizations
61
284
142
57
28
Approvals
28
327
164
65
33
Table 1: SSP Authorization and Approval Rates

As I have discussed in various posts (see the latest here) about the monthly reports the Infrastructure Security Compliance Division (ISCD) has been publishing on the SSP approval process, there are a lot of things beyond the control of DHS that have caused significant month-to-month variations in the approval rates. It is also not clear how the changes in types of facilities being inspected (alluded to in the CRS report). One would think that the process would be easier at smaller less complicated facilities, but as I recently noted the lack of administrative resources at those facilities is also going to impact the approval process.

It seems likely that DHS will be able to complete the authorization process in somewhere between two and five years, particularly since that portion of the process includes only limited CSI involvement. The projection for the approval process is less sanguine. Shea notes that ISCD has recently begun the process of compliance inspections which will cut into the number of authorization inspections that the limited CSI force can conduct. Also noted as a force time-consumer is the current regulatory requirement to begin the reauthorization/re-approval process for Site Security Plans. That should begin in very limited numbers this fall.

New Facilities

Further compounding this issue is a discrepancy between the number of covered facilities and the number of facilities with a final tier assignment. Facilities become regulated when they submit a Top Screen that DHS decides provides presumption of being at high-risk. In the initial Top Screen submissions in January of 2008 40,000+ facilities submitted Top Screens, but only about 7,000 were notified by DHS that they were preliminarily determined to be at high-risk and would have to enter the initial evaluation process of the regulated chemical companies, the Security Vulnerability Assessment (SVA).

What is not clear in Shea’s discussion is the fact that not all of those facilities submitting SVA will be confirmed as high risk and be given a tier ranking assignment. It is only at that point that the facility joins the cue of facilities in the SSP authorization/approval process. Of the original 7,000 covered facilities only about 4,000 were required to submit sight security plans, the remainder were dropped from the CFATS program because the additional data submitted demonstrated that they were not at high-risk of terrorist attack.

Shea appears to assume that all of the currently regulated facilities will be required to submit SSPs that will require future action. That is not supported by past history. Only about half of the currently regulated facilities that do not have tier assignments would be expected to have to submit SSPs.

Alternatives

What is disappointingly lacking in this version of the CRS report is a look at potential alternatives. With a new CFATS authorization bill currently in the works it would have been nice to see a look at possible congressional actions that could address this process.

The simplest action (and the least likely) is for Congress to increase the funding and authorized head count for CSI. Clearly the limited number of CSI has got to be a factor slow rate of approvals. Whether or not it is the only factor has yet to be seen. Shea acknowledges this, noting (pg  16):

“Increasing authorization inspection capacity might serve to highlight other potential issues within the CFATS process, such as delays in processing information from authorization inspections and issuing letters of approval.”

Congress is unlikely to significantly change the number of CSI. The CFATS program already has more full-time federal inspectors than does the EPA’s RMP program or OSHA’s PSM program which address similar (yet a far larger number) facilities. Federal employee costs are high and there appears to be a general reluctance to pay that cost for enforcement personnel.

Last summer I proposed another alternative to speed up the SSP authorization and approval process; adjust the standards by which those actions are reviewed for Tier 3 and Tier 4 facilities. Since these facilities are lower risk, it would seem reasonable that while the RBPS are lower the standards for review of the submissions should also be less stringent. While this would not technically need congressional approval it would certainly need congressional acquiescence.

Personnel Surety

There was one SSP issue that was completely ignored in the Shea report, technically there have been no site security plan approvals; they all have been conditional because facilities have not been able to fulfill all of the standards for RBPS # 12 Personnel Surety. The reason for this is that DHS has yet to establish a means for facilities to vet personnel given unaccompanied access to critical areas of the facility against a list of known or suspected terrorists. ISCD has been at work on this program with little success for over four years now.

I understand that this will be addressed by CFATS authorization legislation that will be introduced in the next couple of weeks. It remains to be seen whether or not that bill would, if passed (more than iffy in an election year), ease or compound the difficulties that DHS is having getting a plan that is acceptable to industry and accomplishes the requirements for personnel surety established in the current authorization.

In any case, some sort of reauthorization/re-approval process will have to be implemented once a CFATS personnel surety program is put into place by DHS. This should be able to be an almost completely administrative review, requiring little or no CSI involvement.

Thursday, March 21, 2013

TWIC Reader NPRM and CFATS PSP Tomorrow


I don’t normally announce the publication of documents in the Federal Register the day before, but in this case we have been waiting so long for both of these programs to move forward, I’m going to make an exception.

The Coast Guard’s TWIC Reader NPRM will be published in tomorrow’s Federal Register. A pre-publication draft copy is available here. It’s not the official version and it doesn’t have the page numbers, but it is available for reading.

The same goes true for the CFATS personnel surety program (PSP) 60-day ICR notice. It can be found here.

As you might expect, I’ll be looking at both documents in some detail.

BTW: Apologies for casting aspersions on Under Secretary Beers’ announcement that these two documents had been sent to the Federal Register last week. Apparently the follow through was done in a timely manner this time.

Thursday, October 11, 2012

No Personnel Surety Notice


Last month I reported that Under Secretary Rand Beers told the Energy and  the Economy Subcommittee of the House Energy and Commerce Committee that the 60-day information collection request (ICR) notice for the new CFATS personnel surety program would be published in the Federal Register in 30 days.  Well, today is 30-days and there is no such notice in the Federal Register and there is no indication that one will be published tomorrow.

This is just another incidence of Beers promising more than his organization can produce. But then again, no one seriously expected anything different.

Tuesday, September 11, 2012

Observations on the CFATS Hearing


I didn’t get a chance to watch the entire hearing today, the split hearing because of 9/11 ceremony put a severe cramp in my schedule. I’ll have a chance to review the rest of the hearing sometime this weekend, but the initial portion of the hearing that I did see provided some interesting information.

Personnel Surety


Chairman Shimkus (R,IL) was particularly concerned about the personnel surety program, or more accurately the lack of one.  He was particularly concerned about how the Department could approve a Site Security Plan when the facility had no way to do the required check of the Terrorist Screening Database (TSDB). Under Secretary Beers explained that the two facilities (on additional one since September 4th) with approved SSP actually had ‘conditional approval’ pending the completion of the ISCDs personnel surety program development.

No real questions were asked about the reasons that the personnel security ICR had been withdrawn as Shimkus was trying to keep the hearing moving quickly so that there was a chance for at least one round of questions; Beers would not be back when the hearing resumed. Beers did report that the new ICR would be ready for the publication of the new 60-day notice in 30 days. I’m sorry but I’ve seen so many DHS delays that I’ll be surprised to see it within 60-days.

Beers also assured Ranking Member Gene Green (D,TX) that the new personnel surety program would specifically incorporate the use of the Transportation Workers Identification Credential (TWIC).

Inspections


The Department has been touting their new training program for conducting approval inspections, the inspection to determine if the facility is actually properly implementing their authorized SSP. With 73 conditionally authorized SSPs to work on, Director Wulf informed the Subcommittee that ISCD planned on conducting 10 approval inspections in September (it’s not clear if that includes the site approved since September 4th).

When pressed, hard, for the projected rate of SSP approvals Wulf said that ISCD planned on inspecting and approving 300 SSPs in the next year. I missed the Congressman’s name who commented that it would ‘take a century’ to complete inspecting all of the covered facilities. That’s a slight exaggeration; it would only be about 15 years.

ISCD Personnel Issues


The only hard questioning came from Rep. Cassidy (R,LA) who focused his questioning on the personnel issues raised in the Anderson-Wulf memo. He repeatedly asked Wulf if anyone had been dismissed or demoted because of the issues raised in the memo. The answer was no, but Cassidy didn’t give him much chance to explain why not. The 5 minute questioning format of hearings means you have to demand short answers if you have lots of questions.

Other Issues


The Tweets from @SOCMACONNECT and @socma for the remainder of the hearing look like there might have been some interesting exchanges. Oddly enough I didn’t see anything on TWITTER about the testimony or responses from Ms. Anna Fendley (United Steel Workers) or Mr. Paul Orum (Blue-Green Coalition). I’m looking forward to having a chance to review the webcast of the rest of the hearing.

Friday, September 7, 2012

Reader Comment – 09-07-12 – Background Check Tools


There was a very interesting comment submitted by Daniel Krantz to my earlier blog about the lack of a background check requirement for EMTs in New Jersey. Apparently Mr. Krantz works for the Real-Time Technology Group (pay special attention to the ‘-‘ in the name if you are going to Google this company). They have a number of products that deal with the vetting of personnel that he mentions in his comment (with appropriate links). I know nothing about this group, so Caveat Emptor.

Comment Moderation


This is provides a good place to review the ‘rules’ that I use to moderate comments to this group. First thing to remember is that it is my blog and I make the rules. My goal is to keep comments on topic; and the Krantz comment certainly deals with the issues that I discussed in the post. I try hard to keep out unrelated SPAM; you would be surprised at the number of comments that are nothing more than ‘Great Post’ and a link to a totally unrelated site. Finally, I WILL NOT ALLOW flame wars. If you disagree with something, fine; explain your disagreement; don’t attack the other fellow personally.

I have no problem with vendors describing their products that pertain to the topic at hand; I don’t endorse products by allowing their listing in comments. I generally don’t endorse products unless I have used them enough to really know something about them. If I do endorse something it will be plain for all to see. If you don’t like some product that you see mentioned in the blog or comments feel free to say so, but see the comment above about flame wars.

Enough about comment moderation.

Background Check Services


There are any number of organizations that provide background checks as a service. As with any service, some are great (about 5%), some are cons (about 5%), and most try to do a reasonable job at what they are doing. As with any service check them out through the Better Business Bureau® and talk with their customers.

One thing that you must remember, at present, none of these organizations can vet personnel against the Terrorist Screening Database (TSDB). Currently only government run programs have access to that screening tool. Some organizations have their own ‘terrorist databases’, but if the Feds require screening against the TSDB (CFATS, TWIC, HME etc), it has to ultimately go through TSA. You should certainly think twice about spending money on having some outside agency run checks that you will ultimately have to pay TSA to run anyway.

Sunday, August 26, 2012

A Closer Look at the Heritage Foundation Report – Conclusions


This is the final blog in a series taking a critical look at the recent Heritage Foundation report on the problems with the CFATS program. While the report authored by Jessica Zuckerman is not up to the usual editorial standards of the Heritage Foundation it does raise some interesting issues. The earlier blog posts can be found here:




The final section of the Heritage Foundation report on the CFATS program is called “Developing Market-Oriented Chemical Security Solutions”. As one would expect with a concluding section of a report it summarizes the author’s conclusions. This post will address those conclusions and some of the other shortcomings of the report.

Report Conclusions


Here is my summary of those conclusions (okay, I stole them from the subheading in the section):

• Take a truly risk-based approach to chemical security;

• Reject calls for greater regula­tion;

• Expand SAFETY Act protec­tions to encourage greater inno­vation;

• Promote public–private part­nerships to enhance aging U.S. infrastructure; and

• Foster greater transparency and cooperation.

I have dealt with most of these conclusions in earlier the earlier posts on this report, so I will not dwell on them further here. There is one new area found in this concluding section that it not addressed anywhere else in the report and that is the one dealing with ‘aging U.S. infrastructure’. It is a shame that Ms. Zuckerman forgot to address this issue in the body of her report because she may have made a potential contribution to the discussion of chemical facility security. Unfortunately, we are left with glittering generalities such as:

“The United States’ overall critical infrastruc­ture, including the chemical sector, is inadequate and aging. Greater investment is needed not only to ensure that U.S. critical infrastructure is protected but that it is capable of bouncing back quickly when disaster strikes.” (pg 10)

In general there is more than a little truth in the description of critical infrastructure as ‘aging’ and ‘inadequate’ covers a wide range of perceived and actual problems. The conclusion that ‘greater investment is needed’ is hardly revolutionary, but it begs the question of where the money is going to come from for that investment. This issue is one that deserves a whole host of reports about specific areas of infrastructure, public and private, that could have a potential effect on chemical facility security.

Industry Response


One would be forgiven for concluding, after reading this report, that industry was widely disillusioned with the CFATS program and wanted to see it replaced with a radically different program. This is never specifically stated in the report, but Ms. Zuckerman does repeatedly talk about the burdens that the program places upon industry.

In the last couple of days, however, the chemical industry has started to respond to this report, and it hasn’t been favorable. An article over at NTI.org (Government Security Newswire, GSN) quotes representatives from two of the largest organizations representing chemical facility owners, the American Chemistry Council (ACC) and the Society of Chemical Manufacturers & Affiliates (SOCMA) as being generally supportive of continuing the CFATS program. They acknowledge problems with the current implementation, but support the basic premise and design of CFATS.

These two organizations certainly don’t represent all of the chemical facilities that are covered under CFATS, but I would be willing to bet that they cover a majority of the Tier 1 and Tier 2 facilities that are having to spend the greatest amount of money on upgrading the security measures at their facilities to comply with the program.

Now part of that support is simply fear of the unknown. Not knowing what type of program would replace CFATS, and Ms. Zuckerman provides nothing beyond glittering generalities, industry would rather deal with the devil they know than accept the potential for an entirely new program.

Given the fact that Congress has been unable to craft comprehensive chemical security legislation since 2001, it is unlikely that it would be able to do so any time in the foreseeable future. Eliminating the CFATS program would leave a void with unpredictable consequences. The GSN article notes that industry fears that an EPA based program might result in requiring IST implementation. What is even more likely is that several State and local governments, no longer restricted by the supremacy of the CFATS program, would craft a patchwork of local regulations that would leave selected facilities with onerous requirements (certainly including IST provisions in many localities) while leaving their competitors with no regulations.

Areas That Were Not Addressed


There are a number of problem areas in the CFATS program that were glossed over, minimally mentioned, or completely ignored in this report. While I have addressed most of these in some details in various posts over the years, I would like to take this opportunity to mention some of the more important ones (in my opinion) so that future researchers might have a better chance of preparing a report that deals with actual issues and problems in the CFATS implementation.

CFSI


Ms. Zuckerman briefly mentions the problem with the qualifications of Chemical Facility Security Inspectors (CFSI). The initial members of the CFSI were drafted from the Federal Protective Service. These were law enforcement personnel with a background in physical security, they had little or no background in dealing with chemical facilities. The folks at ISCD realized this problem and established a Chemical Security Academy. I did an initial blog posting on that topic a number of years ago. Since then I have done a number of other blog postings on the issues related to training of CFSI. They include topics such as:







Armed Security Forces


A number of commenters on the Anderson Memo about the problems associated with the current CFATS program have taken particular issue with the problem of current CFSI who started out as sworn law enforcement personnel wanting to continue carrying their side arms. Leaving aside for the moment the definition of enforcement in the CFATS environment, the failure of ISCD to address the issue of the use of armed security personnel to stop terrorist attacks on high-risk chemical facilities is a much unnoticed failing of the program. I have dealt with this issue in a number of blog posts:











SSP Shortcomings


The biggest current problem with ISCD is their apparent inability to effectively authorize any Site Security Plans. While many commenters have noted this problem, no one has attempted to determine the root cause. While I have not had the opportunity to do a detailed study of the problems on the ground, it is clear from the limited comments we have heard from DHS and the inspected community that there is a serious shortcoming with the current SSP tool in CSAT; it is not adequately soliciting the information needed by ISCD to conduct a paperwork evaluation of the programs at the facility.

Any security professional that looks at the questions asked in the SSP tool would realize that the level of detail required for an adequate assessment of the security plans at the facility would not be provided by those questions as asked. This has resulted in DHS establishing the Pre-Authorization Inspection program where presumably the CFSI are tasked with seeking out the necessary information.

I have addressed the ways that this problem might be addressed by facilities in submitting their SSPs, but it seems to me that the SSP tool needs a fairly extensive revision if it is ever going to provide the level of detail necessary for ISCD or its contractors to evaluate the security planning at CFATS covered facilities. Lacking that ISCD should institute a program where they send a detailed letter to the facility seeking the specific information they need to make their evaluation rather than sending the CFSI out to get the information.

Personnel Surety


While there are any number of other security related issues that might be addressed by any reasonable revamp of the administration of the CFATS program, I’ll just address one more in this posting, the lack of an approved personnel surety program. RBPS #12 requires facilities to conduct background checks on all facility employees and contractors and any visitors requiring unaccompanied access to critical areas of the facility. The provisions for checking identity, criminal history and legal authorization to work can be adequately complied with by using any of a number of commercial organizations to conduct background investigations. The one area that cannot be accomplished by such organizations is the identification of people with terrorist ties.

The failure of ISCD to come up with a reasonable program for allowing facilities to have ISCD or some other agency of DHS to vet personnel against the Terrorist Screening Database is inexcusable. Such a program should allow for the use of any of the currently available TSA vetted identification programs (TWIC, HME, etc) and/or provide a simple method of submitting individual information to ISCD for such vetting. ISCD tried to make their program much more complicated than was necessary. Since that program was recently withdrawn, ISCD’s delay in getting such a program established will continue to put off establishing a terrorist screening program for an even longer period of time.

Moving Forward


ISCD and the CFATS program have a number of challenges and problems to overcome. Documents that are purportedly comprehensive looks at the program like this Heritage Foundation report could provide a basis for the discussion of how to move proceed with developing a workable chemical security program for high-risk chemical facilities. Unfortunately, Ms. Zuckerman did little to move the discussion forward.

Saturday, July 21, 2012

OMB Announces Withdrawal of CFATS Personnel Surety ICR


Yesterday the Office of Management and Budget (OMB) announced that DHS/NPPD had withdrawn the information collection request (ICR) necessary to implement the CFATS personnel surety program. This is the program that would have ISCD collect personnel information on facility personnel and visitors with unaccompanied access to high-risk chemical facilities to check those personnel against the Terrorist Screening Database (TSDB). This check is required for Risk-Based Performance Standard #12.

There was no indication in the notice why the ICR had been withdrawn, but this ICR has been opposed by industry as overreaching. It has also been criticized by many members of Congress on both sides of the aisle for not utilizing the TWIC, or at least formally recognizing the TWIC, as the method of vetting personnel with unaccompanied access to high risk chemical facilities. One would hesitate to suggest that political considerations were behind the NPPD action.

One would like to think that the formal withdrawal of this ICR would be an indication that the Infrastructure Security Compliance Division (ISCD) has a new personnel surety program ready for release in the near future. Perhaps there will be an announcement about this program that will be made in association with the Chemical Sector Security Summit at the end of the month.

Of course the problems that we have been seeing with the failure to release new guidance on the SSP implementation process probably argues against any quick resolution to the personnel surety problem. ISCD is getting further and further behind and it is fast reaching the point where if significant progress is not seen in the near future, we should seriously consider disbanding ISCD and re-starting the CFATS program from scratch.

Monday, July 9, 2012

Vetting Security Contractors


Ralph Langner, of Stuxnet decoding fame, has an interesting blog post over at Langner.com about the recent ‘revelations’ in David Sanger’s book, Confront and Conceal, that Siemens was complicit in setting up the Natanz control system in Iran and subsequently acted as the Stuxnet transmission agency for the attack on that system. Now I haven’t read that book and Ralph doesn’t actually quote (I think; at least there are no quote marks) from the book and the book is apparently based upon info from politicians not technicians, so I don’t know how accurate the claim actually is.

Quis custodiet ipsos custodes? [Who guards the guardians?]


Having said that, Ralph extrapolates that claim to a very interesting point at the end of his posting:

“So it turns out that Confront and Conceal has an important real-life implication for ICS security and critical infrastructure protection: Asset owners/operators who still favor a policy of unverified trust in the cyber security posture of their contractors and vendors, no matter how large or well-reputed they might be, will from now on have to be regarded as negligent. On the plant floor, the biggest cyber security risk is associated with contractors with legitimate access to a facility’s most sensitive systems. There is absolutely no reason to assume that any specific contractor could be trusted without verification just because they say so, because they enjoy a big market share, or because they pursue a media strategy claiming that they had cyber security gotten straight – quod erat demonstrandum [QED, or end of proof].”

This has always been one of the sore points about hiring security specialists; they are given the keys to the kingdom, but there is little one can do to control their concealed actions. Owner operators need to take great care in selecting any agency to work on the facility security programs, physical and/or cyber. How one prevents the subornation of a major firm like Siemens is almost certainly beyond the control of most facilities, but facility security managers and cybersecurity managers have to take great care in selecting and vetting anyone that works on their security systems.

TSDB Checks


Typical background checks, specifically criminal background checks have to be an important part of the security vetting process. Unfortunately, those checks will be of little use when one is trying to eliminate people with terrorist ties or working for foreign intelligence services. DHS does provide a service for vetting people against the terrorist screening database (TSDB), but that is only available through TSA for transportation related personnel. CFATS covered facilities may, sooner or later, get access to that vetting process, but no other critical infrastructure organizations have, or apparently will have, that vetting option. Of course there is no FIS database.

This is one of the many shortcomings of the various cybersecurity bills; none of them make provisions for personnel surety. There are no requirements that personnel with the cyber-equivalent of ‘unaccompanied access’ have to undergo any sort of background check at critical infrastructure facilities. One would like to think that such checks were being done as a matter of course for business reasons, but it is unlikely that everyone is doing even the criminal background checks. No one is doing terrorist screening, since without a congressionally authorized DHS program for TSDB vetting the Department has no authority to conduct such terrorist background checks.
 
/* Use this with templates/template-twocol.html */