I have been mentioning for the last couple of weeks now that ISCD needs to revise the Risk-Based Performance Standards Guidance document to reflect the change from Homeland Security Advisory System (HSAS) to the new National Terrorism Advisory System (NTAS) that was implemented earlier this week. Of course it is easy to complain about someone not doing something; it is more productive to actually suggest something so that is what I am going to do.
I’m going to do a minimalist revision of the RBPS 13 section of the Guidance document; keeping as much as possible the DHS-ISCD flavor of the document. I’ll explain the changes as I make them here in the blog and then I will post the revised version on my web site. Then, I’ll open the floor to a public discussion. We’ll do the same with the Metrics at the end of the section in a separate blog.
Cut and Paste
The first thing we will do is to use the cut and paste feature of the word processing program to replace ‘Homeland Security Advisory System’ with ‘National Terrorism Advisory System’. Next we will do the same with ‘HSAS’, replacing it with ‘NTAS’. Then we will replace references to ‘Color-coded Threat Level System’ with ‘National Terrorism Advisory System’. Then we go back and remove redundant references to ‘NTAS and ‘National Terrorism Advisory System’. We also removed the changes made in the name of the ASIS reference at the end of the section.
Explanation of NTAS
Next we would remove the section describing the out-dated ‘Color-coded Threat Level System’ and replace it with a description of the NTAS Alerts from the NTAS Public Guide.
Discussion of Sample Security Measures
We will change the description of the conditions that call for the additional security measures, replacing the ‘High Condition (Orange)’ description with one reflecting an ‘Elevated Threat Alert’. The second category; ‘Severe Condition (Red)’ description will be replaced with one for ‘Imminent Threat Alert’.
Length of Period of Elevated Threat Level
One of the major changes in moving from the HSAS to the NTAS systems is the elimination of open ended periods at elevated threat levels. The NTAS system includes a requirement for specific time limits that are included in the Alert when it is issued. While it is still possible to be at an elevated threat level for a lengthy period of time (probably only measured in weeks), it will remain at the specified level only for the specified time. The discussion under the section for the ‘Length of Period of Elevated Threat Level’ will be revised to reflect this change in philosophy.
References
Finally, we will change the URL for the DHS web site for the advisory system to reflect the new URL for the new NTAS system.
Minimal Revision
The revision described here is a minimal change to the RBPS 13 section of the Risk-Based Performance Standard Guidance document. The only things changed were those necessary to properly reflect the change in the DHS advisory system from the old color-coded system to the new system of National Terrorism Advisory System Alerts
It wasn’t a difficult re-write; it took less than two hours of work. Of course in the ISCD environment there would be multiple levels of approvals that would require at least a couple of additional re-writes. Then there would be the public publishing and comment period that would extend the time necessary to actually require facilities to implement the change.
One would like to think that the work on the RBPS 13 revision was started shortly after Secretary Napolitano signed off on the revised alert system. That would have allowed for the shortest amount of time where there would be discrepancies between the provisions of the advisory system and the requirements for the CFATS site security plan. Maybe this will allow ISCD to catch up.
Showing posts with label RBPS Guidance Document. Show all posts
Showing posts with label RBPS Guidance Document. Show all posts
Friday, April 29, 2011
Monday, December 13, 2010
DHS Site Security Plan Helpful Tips
Last Friday I did a late blog posting about a new document that DHS had posted on its Chemical Security Assessment Tool (CSAT) web page for the Site Security Plan (SSP). That new document is the “Helpful Tips for Completing a Chemical Facility Anti-Terrorism Standards (CFATS) Site Security Plan” pamphlet. The tips are based upon the large number of SSP submissions that DHS has reviewed and the smaller number of pre-authorization inspections that the ISCD Chemical Facility Security Inspectors have conducted.
As I briefly mentioned in the Friday evening post, the Helpful Tips pamphlet addresses five principal areas that DHS has identified as needing additional clarification for facilities submitting SSPs. Those areas, or tips, are
Appropriate Level of Detail
In this tip DHS points out that simply checking off the responses to most of the questions is not going to provide them with an adequate level of detail for them to determine if the listed security measures meet the risk based performance standards outlined in the RBPS Guidance Document. This is the reason that there are so many text boxes scattered throughout the SSP submission pages.
Those text boxes are designed to be used by the facility to provide detailed information on the referenced part of the SSP. Apparently too many facilities are either not using the text boxes or are providing a less than adequate level of detail when they are used. Two very important text boxes in each section of the SSP are the boxes for planned and future changes to the SSP.
Identifying Specific “Assets” and “Systems”
There apparently continues to be some confusion as to which assets and systems need to be addressed in the SSP submission. Part of this confusion seems to stem from the use of similar terms in the Security Vulnerability Assessment (SVA) and SSP. In the SVA the terms were used to describe COI specific critical ‘assets’ and ‘systems’. In the SSP DHS uses a more expansive description of these terms; identifying “all systems critical to the overall security and operations of the facility” (pg 2). Facilities will almost certainly have more systems described in their SSP than were identified in the SVA.
Security Measures Appropriate to Specified Risk Levels
The DHS tiering letter notifies the facility what risk-based tiering level has been assigned to the facility. These four tiers reflect the overall risk that the facility faces from a potential terrorist attack. The security measures that the facility puts into place must meet different standards outlined in the RBPS Guidance document based upon that tier level.
Additionally DHS may decide that certain chemicals of interest (COI) present a lower risk of terrorist attack than the overall facility tier ranking. In those cases the tier ranking letter will also provide a separate, lower tier level for that COI.
In this tip DHS reminds facility security management that security measures specifically designed to protect that lower tiered COI are only required to meet the RBPS standards for that tier level. But, any security measure that applies to the facility in general or additionally protects a higher tiered COI must meet the higher RBPS standards for that tier ranking.
Facility-Wide v. Asset-Specific Security Measures
The fourth tip essentially expands on the significance of the third tip. DHS has provided each facility with the ability to describe general facility security measures and measures that protect specific assets. In this tip DHS is suggesting that many facilities are taking less than appropriate use of this potential for differentiation.
Larger facilities and facilities with multiple COI need to consider if describing asset specific security measures will make it easier to provide the level of detail that ISCD will need to evaluate the SSP. Additionally, with some assets requiring lower levels of protection, the facility might find that is can lower its security costs by adopting measures more appropriate to the tier ranking for that COI.
Year-Round View
In this tip DHS notes that security requirements for a facility might vary during the year, with some periods requiring additional security measures. Rather than providing adequate security year-round for these specific instances of increased risk, DHS suggests that a base level of security be addressed in the bulk of the SSP and then the facility identify additional security measures that might apply to those specific periods of time.
Most of us would recognize that events like shut-downs and turn-arounds might require higher levels of security that could require additional security measures due to the large number of temporary personnel and contractors on-site. DHS specifically notes in this tip that there are unplanned events that a reasonable person should consider ‘foreseeable’ for specific areas of the country (large fires, tornados, floods and hurricanes for instance), and these foreseeable unplanned events should also be addressed in the SSP.
The Sixth Tip
The ‘Helpful Tips’ pamphlet actually includes a sixth tip in the conclusion section of the document. In my opinion it may be the most helpful tip in this generally helpful document. The conclusion section makes the very valuable point that DHS ISCD really does want every facility to succeed in getting its SSP approved. To aid facilities in accomplishing that task ISCD has put into place a number of assistance tools to guide facilities to successful SSP development and approval. These are listed in the conclusion, along with the appropriate links and contact information.
DHS has made a very real effort to work with facilities throughout this process. They recognize that this is a very complex and difficult process. It is of course made more difficult by the fact that many elements of the chemical industry are in a period of change due to both the current economic downturn and the more general change in the world-wide chemical economy. DHS has no interest in running facilities out of business because of the cost of security. Similarly DHS has a responsibility that minimum levels of security are established and maintained at high-risk chemical facilities. Meeting both of these sometimes conflicting requirements can only be accomplished by working with industry to adapt creative and effective security measures.
As I briefly mentioned in the Friday evening post, the Helpful Tips pamphlet addresses five principal areas that DHS has identified as needing additional clarification for facilities submitting SSPs. Those areas, or tips, are
• Appropriate Level of DetailAs promised I would like to provide a brief review of this document. This is a review and should not be considered to be a substitute for reading the tip document. That five page document probably provides a better understanding of what DHS is looking for and it provides some concrete examples to illustrate these tips.
• Identifying Specific “Assets” and “Systems”
• Security Measures Appropriate to Specified Risk Levels
• Facility-Wide v. Asset-Specific Security Measures
• Year-Round View
Appropriate Level of Detail
In this tip DHS points out that simply checking off the responses to most of the questions is not going to provide them with an adequate level of detail for them to determine if the listed security measures meet the risk based performance standards outlined in the RBPS Guidance Document. This is the reason that there are so many text boxes scattered throughout the SSP submission pages.
Those text boxes are designed to be used by the facility to provide detailed information on the referenced part of the SSP. Apparently too many facilities are either not using the text boxes or are providing a less than adequate level of detail when they are used. Two very important text boxes in each section of the SSP are the boxes for planned and future changes to the SSP.
Identifying Specific “Assets” and “Systems”
There apparently continues to be some confusion as to which assets and systems need to be addressed in the SSP submission. Part of this confusion seems to stem from the use of similar terms in the Security Vulnerability Assessment (SVA) and SSP. In the SVA the terms were used to describe COI specific critical ‘assets’ and ‘systems’. In the SSP DHS uses a more expansive description of these terms; identifying “all systems critical to the overall security and operations of the facility” (pg 2). Facilities will almost certainly have more systems described in their SSP than were identified in the SVA.
Security Measures Appropriate to Specified Risk Levels
The DHS tiering letter notifies the facility what risk-based tiering level has been assigned to the facility. These four tiers reflect the overall risk that the facility faces from a potential terrorist attack. The security measures that the facility puts into place must meet different standards outlined in the RBPS Guidance document based upon that tier level.
Additionally DHS may decide that certain chemicals of interest (COI) present a lower risk of terrorist attack than the overall facility tier ranking. In those cases the tier ranking letter will also provide a separate, lower tier level for that COI.
In this tip DHS reminds facility security management that security measures specifically designed to protect that lower tiered COI are only required to meet the RBPS standards for that tier level. But, any security measure that applies to the facility in general or additionally protects a higher tiered COI must meet the higher RBPS standards for that tier ranking.
Facility-Wide v. Asset-Specific Security Measures
The fourth tip essentially expands on the significance of the third tip. DHS has provided each facility with the ability to describe general facility security measures and measures that protect specific assets. In this tip DHS is suggesting that many facilities are taking less than appropriate use of this potential for differentiation.
Larger facilities and facilities with multiple COI need to consider if describing asset specific security measures will make it easier to provide the level of detail that ISCD will need to evaluate the SSP. Additionally, with some assets requiring lower levels of protection, the facility might find that is can lower its security costs by adopting measures more appropriate to the tier ranking for that COI.
Year-Round View
In this tip DHS notes that security requirements for a facility might vary during the year, with some periods requiring additional security measures. Rather than providing adequate security year-round for these specific instances of increased risk, DHS suggests that a base level of security be addressed in the bulk of the SSP and then the facility identify additional security measures that might apply to those specific periods of time.
Most of us would recognize that events like shut-downs and turn-arounds might require higher levels of security that could require additional security measures due to the large number of temporary personnel and contractors on-site. DHS specifically notes in this tip that there are unplanned events that a reasonable person should consider ‘foreseeable’ for specific areas of the country (large fires, tornados, floods and hurricanes for instance), and these foreseeable unplanned events should also be addressed in the SSP.
The Sixth Tip
The ‘Helpful Tips’ pamphlet actually includes a sixth tip in the conclusion section of the document. In my opinion it may be the most helpful tip in this generally helpful document. The conclusion section makes the very valuable point that DHS ISCD really does want every facility to succeed in getting its SSP approved. To aid facilities in accomplishing that task ISCD has put into place a number of assistance tools to guide facilities to successful SSP development and approval. These are listed in the conclusion, along with the appropriate links and contact information.
DHS has made a very real effort to work with facilities throughout this process. They recognize that this is a very complex and difficult process. It is of course made more difficult by the fact that many elements of the chemical industry are in a period of change due to both the current economic downturn and the more general change in the world-wide chemical economy. DHS has no interest in running facilities out of business because of the cost of security. Similarly DHS has a responsibility that minimum levels of security are established and maintained at high-risk chemical facilities. Meeting both of these sometimes conflicting requirements can only be accomplished by working with industry to adapt creative and effective security measures.
Wednesday, July 15, 2009
RBPS Guidance – RBPS #7 Sabotage
This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the:
Risk-Based Performance Standards Guidance Document
RBPS Guidance – Getting Started
RBPS Guidance – RBPS #1 Restrict Area Perimeter
RBPS Guidance – RBPS #2 Secure Site Assets
RBPS Guidance – RBPS #3 Screen and Control Access
RBPS Guidance – RBPS #4 Deter, Detect and Delay
RBPS Guidance – RBPS #5 Shipping Receipt and Storage
RBPS Guidance – RBPS #6 Theft or Diversion
This posting deals with security measures put into place to deal with sabotage. DHS defines sabotage as “deliberate action aimed at weakening an employer through subversion” and notes that it is of particular concern for “facilities that are high risk based on their production of mission-critical or economically critical chemicals” (pg 68).
Security Measures
Most of the security measures discussed for this RBPS are covered in much more detail in other RBPS. The main preventive security measure is the thorough vetting of personnel that are allowed unescorted access to critical areas of the facility (RBPS 12 and Appendix C). While the discussion does note that the depth of the background investigation should be tied to the “severity of the consequences that could occur because of sabotage” (pg 69), there is no discussion of using a two-man rule that was briefly discussed in RBPS 6.
Visitor control is another security measure that receives some treatment in this RBPS and includes a listing of the various types of visitors that might be expected at high-risk chemical facilities. The discussion briefly lists five types of control measures that might be used to mitigate the sabotage risks posed by visitors. Those control measures are:
“Positive identification of visitors; “Validation of the visit by contacting appropriate facility personnel; “The use of visitor registration forms to provide a record of the visitor and the time, location, and duration of the visit; “The use of visitor cards/badges; and “Visitor escort requirements.”Two other types of security measures are briefly addressed with the discussion pointing to other RBPS for more information. Physical security measures are mentioned with references to RBPS 1, 3 and 4. Cyber security is mentioned, noting that the previously mentioned security measures are “of limited value against cyber sabotage attempts”. The discussion then points the reader at RBPS 8. Metrics The summary metric for this RBPS has only two levels. Tier 4 facilities are expected to have procedures and security measures in place that are aimed at “deterring, detecting, delaying, and responding to sabotage” (pg 70) while the other three tiers will have procedures and security measures that are ‘effective’ in achieving the same ends. It is interesting to see the ‘responding’ requirement mentioned here since it is not addressed or even mentioned anywhere else in the RBPS. Of the three sub-metrics listed in this RBPS only one is mentioned in the discussion portion of this section, visitor control (Metric 7.3). Metric 7.1 provides a list of procedures that a facility might use to “deter, detect, delay, and respond to sabotage”, but again, none of the listed procedures includes security response or emergency response. Metric 7.2 provides a detailed listing of ‘requirements’ for Tamper Resistant Devices. In fact this is a more detailed listing than the one in RBPS 6 (Metric 6.9) where there is a discussion of tamper resistant techniques.
Friday, July 10, 2009
RBPS Guidance – RBPS #6 Theft or Diversion
This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the:
Risk-Based Performance Standards Guidance Document
RBPS Guidance – Getting Started
RBPS Guidance – RBPS #1 Restrict Area Perimeter
RBPS Guidance – RBPS #2 Secure Site Assets
RBPS Guidance – RBPS #3 Screen and Control Access
RBPS Guidance – RBPS #4 Deter, Detect and Delay
RBPS Guidance – RBPS #5 Shipping Receipt and Storage
This posting deals with the provisions of risk-based performance standard #6 and the prevention of the theft or diversion of ‘potentially dangerous chemicals’. The opening paragraph of this RBPS section explains that potentially dangerous chemicals include: “chemical weapons, chemical weapons precursors, explosives, explosive precursors, or other chemicals of interest [emphasis added] that could be used to inflict harm at a facility or off-site” (pg 64). If there are no theft/diversion COI at the facility, no special effort would be required to address this standard.
Security Measures
The first class of security measures discussed in this RBPS is Inventory Control. The text for the description is practically speaking a word-for-word copy of the similar section in RBPS #5. Interestingly there is no discussion of product stewardship or ‘know-your-customer’ programs in the discussion of security measures for this RBPS. Both would contribute the same benefits seen in RBPS #5.
A number of procedural techniques are discussed in this area that can be employed to help deter, detect and delay the theft and diversion of these dangerous chemicals. Most of the procedures have already been discussed in somewhat more detail in earlier standards. The one new measure mentioned here is the use of a two-man rule. This technique requires that areas where the dangerous chemicals are stored may not be entered by just one person. This is based on the concept familiar to the nuclear weapons security community that it is more difficult to suborn two people than just one. This measure would be appropriate where small man-portable containers of the most dangerous chemicals, chemical weapons, are stored.
Finally, the Guidance document looks at physical security measures that can be used to protect theft/diversion COI. Two categories included in this discussion, monitoring storage locations and inspecting vehicles leaving the facility were discussed in some detail in earlier standards and Appendix C. The other, briefly covered, technique in this area is the protection of man-portable containers locks and chains as well using movement sensors on individual containers. I was surprised that the use of RFID tags on containers was not identified here.
Metrics
This metric provides an excellent example of how DHS intends that the escalating risk should met by increasing security. The basic summary metric ‘requirements’ for Tier 4 state that the facility “has security measures intended to deter theft or diversion of potentially dangerous chemicals”. The Tier 3 requirements add that those measures would “reduce the likelihood” of theft/diversion. Tier 2 would add that the facility has ‘multiple’ security measures that “are effective in deterring” theft/diversion while Tier 1 facilities would have multiple ‘vigorous’ security measures that are “extremely effective” in deterring the theft/diversion of those COI.
There are a large number of sub-metrics for this standard. In fact, the only RBPS with more sub-metrics is RBPS #8, Cyber Security. Those sub-metrics are:
Metric 6.1 – Restricted Access to Potentially Dangerous Chemicals Metric 6.2 – “Know-Your-Customer” Provisions Metric 6.3 – Background Checks Metric 6.4 – Monitoring Potentially Dangerous Chemicals Metric 6.5 – Physical Security of Potentially Dangerous Chemicals Metric 6.6 – Vehicular Access Metric 6.7 – Vehicle Inspections Metric 6.8 – Inventory Control Metric 6.9 – Tamper- Evident Devices Metric 6.10 - Cyber Security for Potentially Dangerous ChemicalsWhile most of these metrics are straight forward and many are covered in previous standards it is disturbing that most received no discussion what so ever in the ‘security measures’ discussion in this section of the Guidance document. For example the RFID tags that I mentioned earlier are found in Metric 6.4 for Tier 1 and 2 facilities as a suggested security measure. Another example is that the cyber security measures in 6.10 that are not mentioned anywhere in this RBPS. While the ‘requirement’ for all Tiers that they implement “appropriate cyber security measures and procedures for business systems that manage the ordering and/or shipping of potentially dangerous chemicals” seems to be fairly straight forward the additional requirement to protect “any other cyber systems that contain personally identifiable information for those individuals who manage critical business systems or who could be exploited to steal or divert potentially dangerous chemicals” probably requires some explanation. There is one metric that will be controversial, even though it was briefly mentioned in the earlier discussion. Metric 6.3 has a single ‘standard’ for all four tiers. It includes the suggestion that drivers “transporting potentially dangerous chemicals are issued facility badges subsequent to third-party verification of background suitability”. This certainly makes sense for facilities that employ their own drivers or perhaps for those that employ a ‘captive’ trucking company to make their deliveries. Most facilities, however, will not fall into this category. One simple technique for complying with this ‘requirement’ is for the company to require that all drivers picking up loads at the facility must have a TSA issued Transportation Workers Identification Credential (TWIC). Facilities located near ports may have an easier time getting this accepted in transportation contracts. Facilities located far from port facilities will have a difficult time employing this technique, since there is unlikely to be a significant pool of driver’s with a TWIC. There are two sub-metrics that have a big ‘N/A’ for one or more Tiers. Metric 6.7 has an ‘N/A’ for Tier 4 and Metric 6.9 has the same for Tiers 3 and 4. These ‘N/A’s may provide some insight into how DHS has made their Tier rankings. I would expect that the ‘N/A’ for vehicle inspections indicates that DHS only put facilities with theft/diversion chemicals into this Tier if they did not ship those COI. The lack of requirements for tamper resistant valves on tank trucks for Tiers 3 and 4 indicates that only facilities that do not ship theft/diversion chemicals in bulk are assigned to those Tiers.
Tuesday, July 7, 2009
RBPS Guidance – RBPS #5 Shipping Receipt and Storage
This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the:
Risk-Based Performance Standards Guidance Document
RBPS Guidance – Getting Started
RBPS Guidance – RBPS #1 Restrict Area Perimeter
RBPS Guidance – RBPS #2 Secure Site Assets
RBPS Guidance – RBPS #3 Screen and Control Access
RBPS Guidance – RBPS #4 Deter, Detect and Delay
This posting looks at RBPS #5, Shipping Receipt and Storage. The provisions of this RBPS will help facilities to “minimize the risk of theft or diversion of any of its hazardous materials[emphasis added]” and “helps to prevent tampering or sabotage” (pg 59). Interestingly, DHS, in footnote 17, notes that the term hazardous materials “generally means COI as listed in Appendix A of CFATS” but may also include “other chemicals at a covered facility that pose risks comparable to, or that substantially contribute to, the risks posed by COI listed in Appendix A”.
Legally, these statements do not require facilities to address security for chemicals other than COI listed in their notification letter. As with everything else in the Guidance document, this footnote ‘does not establish any legally enforceable requirements’ (see footer on every page of RBPS Guidance Document). It does seem clear that DHS would like to see facilities extend their security measures to chemicals other than just those listed in Appendix A. DHS suggests that facilities with questions about what chemicals are covered by this RBPS may request technical assistance from DHS.
There are only two security measures addressed in this RBPS; product stewardship and inventory control.
Product Stewardship
DHS notes that Product Stewardship is a concept that has been in use in the chemical industry for a number of years. Originally developed by the industry to address concerns about product safety, DHS expands the concept to include “reducing the potential for theft, contamination, or misuse of toxic or flammable chemicals” (pg 60) by allowing a facility:
To know where its product is located at all times; To ensure that the material is being delivered to or received from a known, approved individual or entity; and To help prevent the theft or diversion of materials through force or deception.A key component of the Product Stewardship responsibility is an active and documented ‘know your customer’ program. DHS suggests that such a program would require that facilities would only sell/deliver hazardous materials to pre-cleared customers that meet certain security criteria. Those criteria would include:
“Verification and/or evaluation of the customer’s on-site security, “Verification that shipping addresses are valid business locations, “Confirmation of financial status, “Establishment of normal business-to-business payment terms and methods (e.g., not allowing cash sales), and “Verification of product end-use.”Most of these criteria are already well established parts of a variety of industry product stewardship programs. The relatively new provision is the requirement to review the customer’s on-site security program. This may cause some interesting problems for facilities because of chemical-terrorism vulnerability information (CVI) requirements for CFATS covered facilities. Sharing information on facility security measures requires verification of authorized user status and need-to-know. Presumably DHS will facilitate such information exchange. Other areas of Product Stewardship that DHS expects to see impact facility security measures include:
Vehicle and shipping control procedures that are periodically tested and evaluated; Unknown vehicle/driver control procedures; Chemical shipping and receiving procedures that identify shipments in advance; Customer pick-up procedures that provide for identification and verification of orders; and Process review procedures for all shipping and receiving processes.Inventory Control DHS expects that covered facilities will be using an inventory control process appropriate to their facility. System capabilities that DHS believes are appropriate to help protect covered COI include:
Listing of all hazardous material on site; Tracking of quantity and location of all hazmat; Monitoring use of hazmat by authorized personnel; Generating reports on location/use of hazmat; Tracking containers of hazmat; Tracking disposal of hazmat and empty hazmat containers; Recording purchasing/receiving records for materials management; and Providing linkage to Material Safety Data Sheet information.DHS notes that inventory control procedures can be enhanced by the use of appropriate physical security measures to control access to covered materials. The security measures listed in this RBPS have been addressed in earlier RBPS sections. Metrics The summary metric suggests that all covered facilities will have “documented processes for securing and monitoring the shipment, receipt, and storage of hazardous materials” (pg 62). The effectiveness of these processes in preventing unauthorized personnel from gaining access to covered materials will vary according to the Tier ranking of the facility. Processes for Tier 1 facilities will such unauthorized access “make it extremely unlikely’ while Tier 2 facilities would be expected to meet an ‘unlikely’ standard. Procedures at Tier 3 and 4 facilities would “reduce the likelihood” such access. The Metric 5.1 ‘standards’ for security of transportation containers are the same for all facilities. Adequate security measures will be provided for all shipping containers not actively involved in transportation. All such containers would be stored within the facilities security perimeter and will be addressed in the facility’s SSP. This would imply that the containers or their storage area would be ‘assets’ covered under RBPS #2. Metric 5.2 require that all facilities have a ‘know our customer program’ with Tier 1, 2, and 3 facilities refusing to sell hazmat to customers not meeting prescribed criteria. Similarly Metric 5.3 requires all facilities to have procedures in place to identify and authorize vehicle access to the facility with accompanying shipping and receiving control procedures. Again all but Tier 4 facilities would include procedures for staging/vetting unexpected vehicles/drivers. Metric 5.4 addresses the requirement for procedures that address confirmation of inbound and outbound hazmat shipments. Procedures for Tier 1 and 2 facilities would address all such shipments while Tier 3 and 4 facilities would cover most shipments. Tier 1, 2 and 3 facilities are expected (Metric 5.5) to have a written procedure for verifying the receipt of orders for hazmat and controlling the sales and storage of hazardous materials. A review process to ensure the effectiveness of these procedures will be included in the procedure.
Thursday, June 18, 2009
RBPS Guidance – RBPS #4 Deter, Detect and Delay
This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the:
Risk-Based Performance Standards Guidance Document
RBPS Guidance – Getting Started
RBPS Guidance – RBPS #1 Restrict Area Perimeter
RBPS Guidance – RBPS #2 Secure Site Assets
RBPS Guidance – RBPS #3 Screen and Control Access
This posting looks at RBPS #3 which covers the facility’s ability to deter terrorists from attempting attacks on the facility, detecting an attack or potential attack early enough in the process to allow for early interdiction of the attack, and delaying an attacker from reaching critical assets long enough for security forces to get into place to interdict the attackers before they reach and successfully attack critical assets.
Security Measures
There are no security measures discussed in this RBPS that were not previously discussed in RBPSs 1, 2 or 3.
Security Considerations
The discussion of security considerations in this RBPS covers the same ground that was discussed in the three earlier RBPS.
Metrics
While the security measures and considerations for this RBPS have been previously discussed, there are some significant differences in the focus of the metrics for this RBPS. The Tier 1 Summary Metric focuses on “a series of protective security layers” that allow the process of deter, detect and delay to “allow response to thwart the adversary action before it achieves mission success” (pg 55) and only security measure that it specifically mentions is vehicle barriers.
Metric 4.1, Deterrence and Delay (General), introduces a new concept not emphasized in previous RBPS; “well-coordinated security response planning”. This reflects the realization that any security system can be penetrated by a sufficiently determined opponent. This means that there must be a well planned and coordinated response to interdict that determined opponent.
The focus of Metric 4.2 is on preventing vehicle borne attacks on critical assets at the facility through the use of anti-vehicle barrier systems.
The Detection Monitoring and Surveillance Metric (4.3) delves into the detection and surveillance system in much more depth than was done in earlier RBPS. While the discussion in Tiers 1 thru 3 focuses on electronic systems, the Tier 4 discussion specifically mentions using security patrols to affect the detection, monitoring and surveillance tasks. The other tiers focus more on all weather system capability, back-up power, and independent systems not subject to common cause failures.
Metric 4.4 focuses on detection and mentions ‘countersurveillance’ and “frustration of opportunity to observe critical assets” (pg 58) for the first time. The discussions for the two highest tiers also mention the use of a “Security Operations Center” to continuously monitor a “facility-wide intrusion detection system”.
The final metric, 4.5 – Interdiction by Security Forces or Other Means, was one of the most controversial in the draft version of the Risk-Based Performance Standard Guidance document because it firmly suggested the use of armed security forces. The discussion of the interdiction of ‘armed intruders’ still includes the potential use of a facility security force (described as “contract or proprietary, mobile or posted, armed or unarmed, or a combination thereof “ pg 58) it does place equal emphasis on the use of “sufficient delay tactics to allow local law enforcement to respond before the adversary achieves mission success” as an acceptable alternative. The other alternative that is addressed is the use of “process controls or systems that rapidly render the critical asset nonhazardous even if a breach of containment were to occur” though this is unlikely to be a widely useable option.
Monday, June 15, 2009
RBPS Guidance – RBPS #3 Screen and Control Access
This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the:
Risk-Based Performance Standards Guidance Document
RBPS Guidance – Getting Started
RBPS Guidance – RBPS #1 Restrict Area Perimeter
RBPS Guidance – RBPS #2 Secure Site Assets
This post looks at the third risk-based performance standard which deals with screening and controlling the access of personnel and vehicles into the facility or into restricted areas or critical assets within the facility. The discussion in this RBPS is predicated on the existence of a perimeter barrier system that allows entrance to the facility at only a limited number of controlled points.
Security Measures
The discussion in this section of the Guidance document focuses on five classes of security measures. They are:
Personnel identification,
Hand carried items inspection,
Vehicle identification and inspection,
Control point measures, and
Parking security measures.
Personnel Identification
The Guidance document provides examples of a number of potential personnel identification schemes for verifying the identity of personnel entering the facility or restricted areas within the facility ranging from checking government photo identification (drivers license for example) to sophisticated facility provided ID cards that can interact with automated access control systems. The less sophisticated systems require that someone actually looks at the ID and compares it to a list of personnel authorized access.
Not covered in the RBPS is the need to provide the security personnel at the gate with an daily list of personnel expected to arrive at the facility to make deliveries, pick-up shipments, or conduct other transitory business. The higher risk facilities may require their suppliers and customers to provide advance copies of photo IDs or other unique identifying information for their drivers delivering or picking up loads. Lower risk facilities may decide that just providing the driver’s name will be sufficient. Other, unexpected personnel not cleared in advance will need to require escorts to pick-them up at the gate.
Privacy concerns will have to be addressed when keeping records of personnel entering the facility; the more identifying information provided the more problems that will arise. Facilities will need to establish firm rules for purging personal information and ensure that they are followed to the letter. Controls will have to be put into place to ensure that access to the personal information is strictly limited.
Hand Carried Item Inspections
This section of the RBPS #3 discussion points out that while all personnel should be subject to inspection, it is reasonable to subject visitors to a higher level of inspection than trusted (and cleared) facility employees. Many facilities will find that random more detailed inspections of employees’ hand carried packages will provide an additional level of security.
The description of inspection techniques provided on page 43 naturally leads one to assume that the focus of these inspections is directed at finding explosive devices. While these would certainly be high priority search targets, facilities should also consider prohibiting/controlling people bringing cameras onto the facility. A visitor with a camera could be on a facility reconnaissance mission.
Vehicle Identification and Inspections
High-risk chemical facilities will need to inspect vehicles entering the facility. Depth and extent of the inspection may be adjusted depending on the vehicles. Just as in package inspections, employee vehicles probably will not receive the same level of inspection as unannounced delivery vehicles.
While not addressed in the Guidance document, facilities with theft/diversion COI packaged in smaller containers may want to seriously consider searching outbound vehicles for such containers. Tight controls on those filled containers may reduce the necessity for checking vehicles, random checks will provide an additional layer of security.
Control Point Measures
The Guidance document describes a number of measures that can be used to control the flow of traffic approaching the facility and near critical assets within the facility. The control point measures outside the facility received some attention in RBPS #1, but they may also help position approaching vehicles in the optimum position for vehicle searches.
Within the facility perimeter the vehicle control measures can help to keep unauthorized vehicles away from critical assets. They can also be used to control the movement of vehicles within the facility; making it unnecessary to require vehicles to be escorted when moving from the gate to loading and unloading facilities.
Parking Security Measures
The location of many facility parking lots was selected long before facility security became an issue; they are located within the facility perimeter. This creates a potential problem with controlling the movement of personal vehicles within the security perimeter. Limiting these parking areas to just employee parking may not be practical depending on the number of ‘visitors’ that the facility typically sees. Other traffic control measures to isolate the parking lots from critical facilities may be more appropriate.
A parking area that is not directly addressed in the Guidance document is the area where trailers, both dry boxes and tank wagons, are parked when they are waiting for loading or unloading. Fully loaded trailers are very difficult to search adequately. This means that the parking areas for these vehicles must be kept away from critical assets in the facility.
Allowing drivers and their tractors to remain with trailers for extended periods of time is going to create security problems. Unless the area is closely monitored, these drivers will have effective access to many areas of the facility where they do not belong. Providing separate parking area for the tractors of long-haul drivers physically separated from the facility and remotely monitored will be a good solution for many facilities. Other facilities may need to require these drivers to drop their trailers and leave the facility perimeter while they wait for loading or unloading to be completed.
Security Considerations
DHS continues to make the points in this standard that they did in the previous two; no single security measure will be adequate by itself. Layering security with complimentary measures and techniques will provide a much higher level of security. Differing environmental conditions must also be taken into account when planning for this standard; security needs to be effective in all expected situations.
Metrics
The metrics for this standard are all pretty straight forward with no concepts that weren’t introduced in either this section of Appendix C. Only one of the metrics, 3.2 – Identity Verification Systems, combines the suggested measures for two different tiers (Tiers 3 and 4). There is only one other metric, 3.3 – On Site Parking, that is not applicable to all four tiers; Tier 4 is listed as ‘N/A’.
Monday, June 8, 2009
RBPS Guidance – RBPS #2 Secure Site Assets
This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the:
Risk-Based Performance Standards Guidance Document
RBPS Guidance – Getting Started
RBPS Guidance – RBPS #1 Restrict Area Perimeter
In this posting we will look at the second Risk-Based Performance (RBPS) standard as it is outlined in the RPBS Guidance document. While many of the techniques discussed in this section were also discussed in RPBS #1, the focus of this here is on individual ‘critical assets’. Those assets may include COI storage or process units, bulk loading or unloading areas, process or security control rooms, or computer servers.
Security Objectives
With the change in focus comes a slightly different set of security objectives for this RBPS. The first RBPS was directed at “limiting the accessibility of the facility such that there is a low likelihood of an adversary successfully breaching the facility perimeter” (pg 22). The objective for this standard is “physically limiting the accessibility of the asset to reduce the likelihood of unauthorized release, theft, or sabotage” (pg 32).
Another new objective of this RBPS is to prevent insider attacks. In the overview discussion the standard notes that RBPS #2 “addresses malevolent acts perpetrated by insiders or insiders in collusion with outsiders” (pg 32).
These objectives will change how the facility plans for their particular combination of securing and monitoring techniques to fulfill the requirement to address this standard.
Perimeter Security
Even if the facility has a perimeter barrier around the entire facility perimeter, security managers might want to consider installing additional barriers around certain critical assets. While these barriers typically restrict personnel access to those assets, they may also “physically protecting the asset from the effects of explosives” (pg 32). This means that these barriers may include blast walls or blast curtains to protect particularly sensitive assets like release COI storage tanks.
Current DHS thinking does not envision every critical asset having the additional protection of asset perimeter barriers where facility perimeter security already exists. The metric for critical asset perimeter barriers only includes a description of a measure for Tier 1 assets. That metric (Metric 2.1) states:
“Where feasible and consistent with critical operational and safety considerations [emphasis added], the facility has an internal perimeter barrier (e.g., a security fence or equivalent barrier that meets industrial consensus standards) that severely restricts or delays any attempts by unauthorized persons to gain access to a Tier 1 restricted area or critical asset” (pg 38).Even for Tier 1 assets this metric acknowledges that there are considerations other than security which may affect the facility decision to provide internal perimeter barriers. While acknowledging this it provides for alternative measures including a “well-secured facility perimeter, combined with high-performance asset monitoring and strict administrative controls on asset access”. Controlling Vehicle Access While controlling general access to Tier 1 critical assets may be relatively optional, two different Metrics address the question of vehicular access to both Tier 1 and 2 critical assets. Metric 2.2 deals with general vehicle access and Metric 2.3 deals with preventing ‘access’ of VBIEDs (vehicular borne improvised explosive device) to these high risk critical assets. Metric 2.2 expects Tier 1 and 2 facilities to have security measures that would ensure that vehicles “would have a very low likelihood [Tier 2: a low likelihood] of accessing a critical asset’s restricted area by force” (pg 39). These measures would be designed to prevent vehicles from crashing into the asset and could include “bollards, berms, landscaping, ditches, drainage swales, or buried concrete anchors retaining anti-vehicle cable”. Such measures should not be necessary if a vehicle could not reach the critical asset because of being surrounded by process equipment, buildings or being contained within a building. Essentially these items would be the barrier preventing vehicular access. VBIED Access Metric 2.3 addresses the use of a VBIED to attack the critical asset. The same types of security measures could be used to prevent VBIED access. The difference would be that the distance that the vehicle would have to be kept from the asset. For a VBIED the vehicle would have to be kept far enough away “to ensure that a VBIED is extremely unlikely to be able to compromise a critical asset” pg 39. The same standard would be applied to both Tier 1 and 2 facilities. Unfortunately, there is nothing in the Guidance document that describes how to determine that distance. Typically there will have to be an assumption made as to the size of the VBIED which will vary according to the size and explosive used. Then the facility would have to know what level of blast overpressure the asset could reasonably be expected to survive. Then it becomes a relatively simple calculation as to the distance the VBIED would have to from the asset for the overpressure effects to be less than the asset could withstand. Provisions might also be made to deal with projectiles from a VBIED enhanced with nails, ball bearing, or other embedded metal. If it is not physically or practically possible to keep vehicles far enough away from the critical asset to prevent overpressure effects from significantly damaging the asset, alternative measures would be required. This could include blast walls to prevent the overpressure effects from reaching the asset. Blast curtains can be employed to prevent projectiles (and to a lesser extent the overpressure) from reaching the asset. Monitoring Site Assets Metric 2.4 is the only metric (other than the summary metric) in securing site assets that DHS considers should apply to all four tiers of high risk facilities. Even in the summary metric, the only security action that applies to all four tiers is monitoring the assets to detect “unauthorized adversary actions toward restricted areas or critical assets” (pg 38). Metric 2.4 calls for the use of (electronic or personnel) monitoring systems to “monitor restricted areas or critical assets (e.g., COI loading and unloading areas, critical valves, pipelines, manifolds, control rooms, storage facilities) to detect attempts to gain unauthorized access to, tamper with, sabotage, steal, or remove without authorization critical assets” (pg 38). The only difference across the Tiers is the frequency of monitoring (Tier 1 and 2– ‘continuously monitor’; and Tier 3 and 4 – ‘monitor’) and the ‘critical assets’ to be monitored (Tier 4 only mentions monitoring ‘loading and unloading areas’). This reflects the fact that Tier 4 facilities do not typically have release COI.
Thursday, June 4, 2009
RBPS Guidance – RBPS #1 Restrict Area Perimeter
This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the:
Risk-Based Performance Standards Guidance Document
RBPS Guidance – Getting Started
In this posting will cover the first Risk-Based Performance Standard (RBPS), Restrict Area Perimeter. Almost the entire written portion of this RBPS remains unchanged from the Draft Guidance document. The only significant differences will be found in the Metrics, but even those changes are more cosmetic than effective.
There is a great deal of overlap between this standard and RBPS 2 (Secure Site Assets), RBPS 3 (Screen and Control Access), RBPS 4 (Deter, Detect and Delay), and RBPS 10 (Monitoring). Anyone that is interested in really understanding how to fulfill the requirements of this standard needs to read those standards as well.
Perimeter vs Asset Security
One of the first things that a facility security manager is going to have to decide in developing a site security plan is how much of the facility footprint is going to be included in the security perimeter. While the first assumption that everything within the ‘fence line’ will be secured, many factors will go into that decision. The size of the facility, the COI to be protected and the facility terrain are all factors that must be considered.
The one consideration that argues for the largest possible security perimeter is the need to provide the greatest amount of time for a security response to be mounted. This is illustrated in the Guidance document in Figure 1 on page 23. This shows how much more time the security force has to respond when the attack is detected at the facility perimeter. This is especially important when a facility relies on local law enforcement for the armed component of its response.
One option for facilities with extremely large perimeters that is not adequately discussed in the Guidance document is for the facility to rely more on detection than barriers at the extreme limits of the perimeter. While this does little to stop accidental or incidental perimeter penetrations it does provide for the critical response time. It can result in more false alarms, especially if there is a lot of off-road traffic in the area.
Security Measures
The Guidance document notes that there are typically four types of security measures that are used to protect the facility perimeter. They are:
Perimeter barriers, Intrusion detection systems or other types of monitoring, Lighting, and Protective forcesThe major point made here (and elsewhere in the RBPS Guidance document) is that there is no single security tool or method that will adequate protection of the facility. A carefully considered combination of techniques using a ‘layered approach’ will usually be the most successful way to prevent successful terrorist attacks on high-risk chemical facilities. What most people with out extensive security training fail to realize is exactly how ineffective most barriers are to determined intruders. The ubiquitous chain-link fence is very easy to go over or through. That is not to say that barriers have little use in a security plan. Security planners just need to insure that barriers are under some form of observation. The importance of lighting at the facility perimeter is often overlooked. Adequate lighting not only aids in monitoring the perimeter, but it also acts as an important psychological barrier because it removes the protective cloak of darkness. Facilities with long and remote perimeters will find adequate lighting to be expensive to install and maintain, but the alternative is to use more expensive observation techniques that can operate in low ambient light levels. RBPS Metrics I still have a minor problem with the use of the term “Metrics”. This implies measurements to standards. These metrics do not actually allow ‘measurement’ because Congress prohibited DHS from specifying any security measures in their approval of Site Security Plans. To be fair, I’m not sure what word I would have used in place of ‘Metrics’ so I guess I shouldn’t complain. I am more concerned with the fact that there are terms and concepts used in the metrics to describe ‘potential’ security measures that are not discussed in the body of the RBPS chapter. Metric 1.1 mentions the use of ‘clear zones’ but there is nothing to describe what those are, how they are used, or considerations in their employment. Similarly Metric 1.3 suggests the use of ‘standoff distance’ to mitigate the effect of VBIED, but there is no discussion of how to effect that standoff and how much standoff might be necessary. Then there is no discussion of how standoff is used to protect against direct fire weapons like rocket propelled grenades. Appendix C There are additional details in Appendix C about the various security measures described in the RBPS. The discussion of barriers is especially good, though it is no where near good enough to make one an expert on barrier technology. The information in Appendix C that will probably be most valuable is the list of references at the end of each discussion.
Tuesday, May 26, 2009
RBPS Guidance – Getting Started
This is the second in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The first blog in the series was the:
Risk-Based Performance Standards Guidance Document
In this blog we will be taking a look at some of the information provided in the Guidance document before it starts discussing the actual risk-based performance standards (RBPS). This general information will provide a logical basis for the discussion of the RBPS.
Purpose
The introduction to the Guidance document provides an overview of how the document is put together and describes how DHS intends for the high-risk chemical facility to use the document. The first thing that facility security personnel must understand is that the Guidance document is not going to tell them how to secure their facility. That is the whole point of establishing performance standards; there is no single security method that is going to be applicable across the wide range of facilities that fall under the label of ‘high-risk chemical facility’.
The purpose of the RBPS Guidance document is summed up well on page 13;
“High-risk chemical facilities can use this document both to help them gain a sense of what types and combinations of security measures and processes are likely to satisfy a given RBPS for a facility at their tier level and to help them identify and select processes, measures, and activities that they may choose to implement to secure their facility.”Organization The Guidance document is set-up essentially the same way as was the draft version. It is laid out into 18 chapters corresponding to each of the 18 RPBS. There are a couple of appendixes that provide additional information on specific topics including a more in depth discussion of some of the security measures that might be employed. Included in those discussions in Appendix C are lists of references that facilities can use to learn more about the technical details involved in developing their site security plan. Each RBPS discussion is arranged in much the same manner. There are three common sections; an ‘Introductory Overview’, one covering ‘Security Measures and Considerations’, and the ‘RBPS Metrics’. Many of the sections have a table that explains what attack scenarios from the SVA are addressed by that Standard. What RBPS Apply? The CFATS regulations require that each high-risk facility must “must satisfy the performance standards” outlined in §27.230. This means that all eighteen of the RBPS must be addressed in the site security plan. The Guidance document notes that each facility will be notified which security issues and COI must be addressed in their site security plan. These security issues and COI will determine the relative emphasis that will be placed on each RBPS. Additionally the Guidance notes that: “Different security measures or activities may be more or less effective depending on the specific security issues.” There is a detailed discussion on pages 17 thru 20 on how the security issue may affect the security measures selected to secure the facility. Any facility developing a site security plan would do well to read and understand that discussion. Not only is it good advice, but it is the best summation of what DHS will be looking for in approving site security plans. Facilities with more than one security issue will find that their security situation will be very complex, but understanding the reasoning that DHS applies to the individual issues will make planning a little easier. Inherently Safer Technology DHS has not addressed the issue of the use of inherently safer technology (IST) in the RBPS Guidance document. A coalition of labor, environmental and other activist groups suggested in their response to the Draft Guidance document that DHS include a discussion of IST in the Guidance. DHS replied in their recently published response to comments that:
“While facilities may voluntarily choose to consider IST solutions as part of their overall security approach, the examination or implementation of IST is not required under CFATS to satisfy the RBPSs and thus is not addressed in the Guidance. No change to the Guidance based on this comment is warranted.”Strictly speaking, IST is not a security measure. It generally falls into the category of risk elimination, risk reduction or risk mitigation measures. The first two categories are better addressed in the Top Screen portion of the CFATS process. If a facility either eliminates or substantially reduces the amount of a COI on site, both well established forms of IST, they need to re-submit the Top Screen as this may change their status as a high-risk facility by removing them from the list entirely or lowering their Tier level ranking. There actually is an IST provision mentioned in the Draft RBPS Guidance Comment document. On page 7 in response to questions about the ‘interdiction requirement’ DHS made the following comment:
“While an armed security force is one potential way of accomplishing this [delay] (and something high-risk chemical facilities may wish to consider), there are many other options for achieving this result (e.g., establishing capabilities to detect an attack early enough and delay it long enough so that local law enforcement can intervene; implementing process controls or systems that rapidly render a target non-hazardous even if an attack successfully breaches containment [emphasis added]).”While this will not be a commonly available option, the rapid conversion of a COI to a non-hazardous chemical or form would certainly fall under the heading of IST. Other risk mitigation measures that provide for automatic post-release neutralization while not strictly IST also should be considered in the development of the site security plan. Facilities that have release COI as their principal security issue need to take a hard look at the whole range of IST possibilities. Looking at the RBPS it will quickly become clear that any security plan for a release COI high-risk facility will quickly become expensive. The easiest way to reduce those potential costs may be to reduce the risk associated with the chemical used on site by using any one of a number of well established inherently safer engineering alternatives.
Tuesday, May 19, 2009
Risk-Based Performance Standards Guidance Document
Last week’s opening of the Site Security Plan Tool on the DHS CSAT web site had been held up for months while DHS waited for the Office of Management and Budget to approve the publication of the Risk-Based Performance Standards Guidance document. That document will provide high-risk chemical facilities some assistance in determining what types of security measures will allow those facilities go receive DHS approval of their Site Security Plan.
This is the first in a series of blog postings that will provide a close-up look at that document. Draft Guidance Document Review Back in October DHS posted a draft version of the Guidance document on their web site and published a notice in the Federal Register requesting public comments on that draft. I prepared a series of blog postings on those comments as they were published (listed below). Of course, those blogs were my review and my opinions on the comments, not anything approaching an official review.
Comments on Draft RBPS Guidance – 11-28-08
Comments on Draft RBPS Guidance – 12-05-08
More Comments on Draft RBPS Guidance – 12-05-08
More Comments on Draft RBPS Guidance – 01-09-09
On the SSP tool web page DHS has provided a link to an official review of the public comments. That document broke comments down into two categories; General Comments, and Comments on Specific Security Issues. Then DHS looked at each of the comments (sometimes lumping a number of comments together) and provided their reasoning for either applying or not applying the recommended changes.
There is one set of comments that I would like to address, since my submission was one of the ones to suggest that the repeated disclaimers in the draft document severely weakened the authority of the Guidance. While not going as far as I suggested, DHS did make some changes that improved the document. The Comments Received document (pg 2) explains:
Disclaimer
There is still a substantial disclaimer at the beginning of the document. The meat of that disclaimer has not changed from the one found in the draft document. The most important part states:
The writers did not limit their conformance to that restriction to just the inclusion of these disclaimers. The entire document was carefully crafted to avoid the appearance of requiring any specific security measure. The only exceptions to this are found in the discussion of RBPS #18, Records. There are specified record retention requirements listed, but, since these are not ‘security measures’ by any definition, and they come directly from the CFATS regulations (§27.255), they do not violate the Congressional prohibition.
The vast majority of the changes made from the draft Guidance document were made in the ‘metrics’ portion of the document. These metrics are misnamed because they do not really allow for measurement of compliance, which would be seen as prescriptive, but they do provide a broadly written narrative description of the type actions that DHS would like to see taken. The changes made in the final version of the document were not so much substantive, as editorial, to remove even the remote appearance of specifying a security measure.
RBPS Guidance and Enforcement
More than one commentor on the Draft Guidance document expressed their concern that the Guidance document would be used by DHS inspectors as an expression of requirements during the enforcement phase of the CFATS implementation. It may be a well founded concern, but for the wrong reason.
The wording in §550(a) of the Homeland Security Appropriations Act of 2007 (Public Law 109-295) is quite specific; “the Secretary may not disapprove a site security plan submitted under this section based on the presence or absence of a particular security measure”. The language is quite specific in referring to the ‘approval’ of the site security plan. There is no such restriction in the §550(e) wording concerning the requirement for the Secretary to “audit and inspect chemical facilities for the purposes of determining compliance with the regulations issued pursuant to this section”.
No one that I have talked to from DHS has ever mentioned this distinction. I have been told, however, that DHS will consider the approved Site Security Plan as a ‘contract’ between the facility and DHS outlining exactly what the facility is required to do to adequately secure the facility against terrorist attack. DHS may very well use the RBPS Guidance metrics as a measure of how well the facility has complied with that contract.
This is the first in a series of blog postings that will provide a close-up look at that document. Draft Guidance Document Review Back in October DHS posted a draft version of the Guidance document on their web site and published a notice in the Federal Register requesting public comments on that draft. I prepared a series of blog postings on those comments as they were published (listed below). Of course, those blogs were my review and my opinions on the comments, not anything approaching an official review.
Comments on Draft RBPS Guidance – 11-28-08
Comments on Draft RBPS Guidance – 12-05-08
More Comments on Draft RBPS Guidance – 12-05-08
More Comments on Draft RBPS Guidance – 01-09-09
On the SSP tool web page DHS has provided a link to an official review of the public comments. That document broke comments down into two categories; General Comments, and Comments on Specific Security Issues. Then DHS looked at each of the comments (sometimes lumping a number of comments together) and provided their reasoning for either applying or not applying the recommended changes.
There is one set of comments that I would like to address, since my submission was one of the ones to suggest that the repeated disclaimers in the draft document severely weakened the authority of the Guidance. While not going as far as I suggested, DHS did make some changes that improved the document. The Comments Received document (pg 2) explains:
“To make the Guidance shorter and easier to read, the Department has decided to replace most of the disclaimers and related language with a single disclaimer at the beginning and in a brief footer on every page.”Anyone that will be using the RBPS Guidance to inform their development of a site security plan (and that should include all Facility Security Officers at all high-risk chemical facilities) should take the minimal effort to read this 30 page document. Even if one hadn’t read the draft document, the explanation of the changes made to the document, as well as the changes not made, will provide additional information and guidance on what DHS is looking for in the Site Security Plan.
Disclaimer
There is still a substantial disclaimer at the beginning of the document. The meat of that disclaimer has not changed from the one found in the draft document. The most important part states:
“This Guidance reflects DHS’s current views on certain aspects of the Risk-Based Performance Standards (RBPSs) and does not establish legally enforceable requirements for facilities subject to CFATS or impose any burdens on the covered facilities. Further, the specific security measures and practices discussed in this document are neither mandatory nor necessarily the ‘preferred solution’ for complying with the RBPSs. Rather, they are examples of measures and practices that a high-risk facility may choose to consider as part of its overall strategy to address the RBPSs. High-risk facility owners/operators have the ability to choose and implement other measures to meet the RBPSs based on the facility’s circumstances, including its tier level, security issues and risks, physical and operating environments, and other appropriate factors, so long as DHS determines that the suite of measures implemented achieves the levels of performance established by the CFATS RBPSs.”Additionally, at the foot of each page is another, simpler disclaimer that essentially covers the same information. That disclaimer reads:
“Note: This document is a “guidance document” and does not establish any legally enforceable requirements. All security measures, practices, and metrics contained herein simply are possible, nonexclusive examples for facilities to consider as part of their overall strategy to address the risk-based performance standards under the Chemical Facility Anti Terrorism Standards and are not prerequisites to regulatory compliance.”These disclaimers are required because when Congress authorized DHS to write the CFATS regulations they placed a number of restrictions on that authority. The one restriction that applies here is that the §550 authorization included language that prohibits DHS from requiring any specific security measure to be included in the Site Security Plan as a prerequisite for the approval of that plan. In order to be able to provide the guidance necessary the writers had to ensure that no one could interpret the guidance as requiring any specific security measure.
The writers did not limit their conformance to that restriction to just the inclusion of these disclaimers. The entire document was carefully crafted to avoid the appearance of requiring any specific security measure. The only exceptions to this are found in the discussion of RBPS #18, Records. There are specified record retention requirements listed, but, since these are not ‘security measures’ by any definition, and they come directly from the CFATS regulations (§27.255), they do not violate the Congressional prohibition.
The vast majority of the changes made from the draft Guidance document were made in the ‘metrics’ portion of the document. These metrics are misnamed because they do not really allow for measurement of compliance, which would be seen as prescriptive, but they do provide a broadly written narrative description of the type actions that DHS would like to see taken. The changes made in the final version of the document were not so much substantive, as editorial, to remove even the remote appearance of specifying a security measure.
RBPS Guidance and Enforcement
More than one commentor on the Draft Guidance document expressed their concern that the Guidance document would be used by DHS inspectors as an expression of requirements during the enforcement phase of the CFATS implementation. It may be a well founded concern, but for the wrong reason.
The wording in §550(a) of the Homeland Security Appropriations Act of 2007 (Public Law 109-295) is quite specific; “the Secretary may not disapprove a site security plan submitted under this section based on the presence or absence of a particular security measure”. The language is quite specific in referring to the ‘approval’ of the site security plan. There is no such restriction in the §550(e) wording concerning the requirement for the Secretary to “audit and inspect chemical facilities for the purposes of determining compliance with the regulations issued pursuant to this section”.
No one that I have talked to from DHS has ever mentioned this distinction. I have been told, however, that DHS will consider the approved Site Security Plan as a ‘contract’ between the facility and DHS outlining exactly what the facility is required to do to adequately secure the facility against terrorist attack. DHS may very well use the RBPS Guidance metrics as a measure of how well the facility has complied with that contract.
Tuesday, October 28, 2008
RBPS Guidance Shortcomings
Having had a chance to review the entire Guidance document, I am afraid that I am going to have to take this opportunity to take DHS to task for the major shortcoming that I have found in this document rather than to do my normal detailed review of the provisions. I’ll get back to my normal review in my next blog entry on this document.
As I noted in my first review post (see: “RBPS Guidance – Introduction”) prominent feature of the Guidance document is the DHS Disclaimer. This is probably necessary given the Congressional mandate that DHS may not require any specific security provision in the approval process of the high-risk chemical facility Site Security Plan (SSP).
General Considerations
This non-prescriptive nature of the Guidance document is further emphasized in the discussion of the General Considerations for Selecting Security Measures (page 15) section of the document. There DHS notes that:
“In fact, Congress has expressly prohibited DHS from disapproving a Site Security Plan based on the presence or absence of a particular security measure. Accordingly, the measures and activities listed in each chapter and in Appendix C are neither mandatory nor necessarily the “preferred solution.” Nor are they the complete list of potential activities from which a high-risk facility must choose to meet each RBPS. Rather, they are some example measures that a facility may choose to implement as part of its overall strategy to address the RBPSs. Facility owners/operators may consider other solutions based on the facility, its security risks, and its security program, so long as the suite of measures implemented achieve the targeted level of performance” (emphasis added).Metrics that Do Not Measure Unfortunately, earlier in the How to Use This Guidance Document (page 13) section of the document, DHS makes this comment in the discussion of the metrics that are provided in the discussion of the individual RBPS:
“Note that the metrics included within the RBPS guidance document are for exemplary purposes only, and a facility need not necessarily meet any or all of the individual metrics to be in compliance with CFATS. Rather, the summary and individual metrics are meant to help a facility identify gaps in its own security posture and potentially mitigating activities by understanding the levels of performance that a compliant facility typically will be able to demonstrate. While a facility meeting all of the metrics is likely to be in compliance with the CFATS RBPS, the failure to meet any particular metric or summary level – or the substitution of alternative measures – does not automatically mean that a facility will not be in compliance with CFATS.”While that sounds like it is in keeping with the Congressional restrictions provided in Section 550 of the Homeland Security Appropriations Act of 2007 (P.L. 109-295) one just has to look at the metrics provided in the Guidance document to see how unnecessary that waffling is. For example, here is the Tier 1 summary metric for RBPS #1, Restrict Area Perimeter:
“The facility has an extremely vigorous perimeter security and monitoring system that enables the facility to thwart most adversary penetrations and channel personnel and vehicles to access control points; including a perimeter intrusion detection and reporting system with multiple additive detection techniques that can demonstrate an extremely low probability that perimeter penetration would be undetected.”There is clearly no requirement for specific security measures in that metric. Loop Hole Makes CFATS Unenforceable While the vast majority of the 7,000+ high-risk chemical facilities will use this Guidance document the way that it was intended, there will certainly be a significant number of facilities that will use the evasiveness of this document to deter DHS enforcement activities and delay implementing serious security measures. There will be much back-and-forth consultation until a harried DHS inspector is not careful in the wording used to ‘suggest’ an adequate security remedy. As soon as that is done the facilities lawyers will head to court to claim violation of Federal Law and Congressional Intent. And most of those claims will be upheld. In the event that DHS does levy sanctions on non-complying facilities there will be a bevy of lawyers available to argue that the vagueness of the standards makes them unenforceable. Claims will be made of inequitable enforcement and allowing too much leeway for inspector opinions. Correcting the Problem DHS needs to de-emphasize the repetitive disclaimers. The single disclaimer at the front of the document should be legally sufficient, especially since DHS uses standard type sizes and color-highlights the text box in which the disclaimer is printed. The needless repetition of the disclaimer language in the body of the Guidance document is unnecessary and should be removed. Finally, the disclaimer about the metrics found on page 13 is completely unnecessary and not required by the §550 language as long as the summary metrics do not specify security measures.
Subscribe to:
Posts (Atom)