Showing posts with label RBPS Guidance. Show all posts
Showing posts with label RBPS Guidance. Show all posts

Wednesday, July 22, 2020

What Now for CFATS?


Michael Kennedy has an interesting blog post about the recent passage of S 4148, extending the current CFATS program through July 27, 2023. He has been hip-deep in the reauthorization/extension process, and his insights are invaluable. As my readers would expect, I will add in my 2-cents worth.

Missed Opportunity


Any program, even one as lately successful as the Chemical Facility Anti-Terrorism Standards (CFATS) program, has room for improvement. This is the value of the congressional authorization process. It provides for a chance for legislators to take a look at a program; to see what it has accomplished, where it is going and most importantly what improvements are needed. Large and important programs like national defense need an annual review and adjustment process like the must pass National Defense Authorization Act. Smaller programs with more limited impact need to be reviewed less often; every three to five years.

In 2014 the CFATS program was reauthorized for five years. Changes were made to the program. Some were successful and others were less so. As Kennedy points out in his valuable CFATS reauthorization timeline, Congress tried unsuccessfully in 2018 to put together a reauthorization package. Interestingly the House and Senate were not nearly as far apart as they had been in the early years of the program, so the one-year extension passed in the closing days of the 115th Congress looked like it should provide enough time to put a compromise package together.

Unfortunately, neither HR 3256 nor S 3416 made it to the floor of their respective bodies, much less to the ‘other house’, for consideration. Instead, a couple of short-term extensions were enacted and then, Congress kicked the can down the road to the 118th Congress. Unfortunately, the new deadline, while early enough in the session to avoid election fever, is almost too early in the session for  potentially new committee leadership to craft bills and force them through the subcommittee and committee hearing process.

Expedited Approval Process


I do have to take exception to one of the points that Michael made in his blog post. He suggested that Congress could have: “Eliminated the Expedited Approval Process, which was rarely used.” First, the program was ‘rarely used’ (initially just a couple facilities) because the program was added when most facilities were almost through the site security plan approval process with most of the hard work already having been done. If the program had come out two-years earlier, I suspect that there would have been more facilities using the EAP.

But even if no facilities had ever actually used the EAP, keeping the program available would have one great benefit, it outlines in significant detail what facilities can do to meet the requirements of the Risk Based Performance Standards (RBPS). The current RBPS Guidance document is substantially deficient in this regards. This is due to DHS, in 2008/2009 when the document was written, bending over backwards to ensure that they could not be accused of trying to mandate security measures, a congressional prohibition in the original §550 authorization language.

For Tier 3 and 4 facilities the EAP guidance outlines in some detail what security measures that facilities must employ to implement a site security plan under that program. Facilities looking at potential costs of introducing their first DHS chemical of interest to a facility can use the EAP security guidance to estimate the security costs associated with that introduction. There is nothing in the RBPS Guidance that provides the same level of surety.

In the Meantime


The folks at the CISA Infrastructure Security Compliance Division (ISCD) can take a deep breath now, their program will continue for another three years. They have successfully scaled up the Personnel Surety Program to include Tier 3 and Tier 4 facilities, continued to expand their outreach efforts, and adapted to the COVID-19 enforcement environment. What new initiative can we expect to see ISCD to undertake in the absence of new congressional mandates.

First and foremost, I think, should be a rewrite of the RBPS Guidance document. It is currently over 10-years old and the GAO has already identified (and CISA acknowledged) deficiencies in the cybersecurity portions of the document. That plus old, outdated references to the old color-coded federal terrorism alert system make this document ripe for a re-write.

At this point a new feature should be added to the Guidance document; a listing of innovative techniques that companies have successfully employed to meet the RBPS standards for their site security plans. This type of information (including a modality for updating the list periodically as new information becomes available) could help to spread security innovation throughout the program.

The second thing that should be addressed is the 2014 advanced notice of proposed rulemaking (ANPRM). With no new program mandates from Congress, ISCD should be able to move this rulemaking effort to the next stage, a notice of proposed rulemaking (NPRM). There have yet to be any changes made to the CFATS regulation (6 CFR Part 27) based upon the requirements of the 2014 reauthorization bill and the ANPRM identified some interesting potential changes.

One thing that certainly needs to be addressed is some of the problems with the current mixture rules. Some of these have been addressed in an ad hoc method via 2019 letter concerning a limited number of products containing sodium chlorate. I discussed this issue in some detail. The CFATS regulations should include some process under which facilities could request and ISCD would evaluate whether specific mixtures and/or products could be exempted from Top Screen reporting requirements.

Finally, I think that ISCD should consider making public their guidance documents that they provide to chemical security inspectors that are designed to ensure equivalent enforcement processes are used around the country.

Tuesday, May 19, 2020

GAO CFATS Cybersecurity Report – Outdated Guidance


Last week the Government Accountability Office published their latest report on the Chemical Facility Anti-Terrorism Standards (CFATS) program. This report specifically addresses the cybersecurity component of the CFATS program. It provides six recommendations to address cybersecurity guidance for covered facilities and cybersecurity training for chemical security inspectors (CSI).

The Recommendations


The GAO report recommended (and DHS concurred) that DHS should:

• Implement a documented process for reviewing and, if deemed necessary, revising its guidance for implementing cybersecurity measures at regularly defined intervals.
• Incorporate measures to assess the contribution that its cybersecurity training is making to program goals, such as inspector- or program specific performance improvement goals.
• Track delivery and performance data for its cybersecurity training, such as the completion of courses, webinars, and refresher trainings.
• Develop a plan to evaluate the effectiveness of its cybersecurity training, such as collecting and analyzing course evaluation forms.
• Develop a workforce plan that addresses the program’s cybersecurity related needs, which should include an analysis of any gaps in the program’s capacity and capability to perform its cybersecurity-related functions, and human capital strategies to address them.
• Maintain reliable, readily available information about the cyber integration levels of covered chemical facilities and inspector cybersecurity expertise. This could include updating the program’s inspection database system to better track facilities’ cyber integration levels.

Cybersecurity Guidance


The main complaint the GAO had with the cybersecurity guidance provided by the Cybersecurity and Infrastructure Security Agency’s (CISA) Infrastructure Security Compliance Division (ISCD) is that it is over ten years old. That guidance is found in the CFATS Risk Based Performance Standards (RBPS) Guidance document that was published in May 2009. Cybersecurity it addressed in RBPS number 8. The seven pages of ‘guidance’ is a broadly written overview of general cybersecurity provisions that might be appropriate to a high-risk chemical facility. It includes paragraphs addressing various topics in the areas of:

Security Policy,
Access Control,
Personnel Security,
Awareness and Training,
Cyber Security Controls, Monitoring, Response, and Reporting,
Disaster Recovery and Business Continuity,
System Development and Acquisition,
Configuration Management, and
Audits.

The RBPS Guidance then goes on to discuss (similarly briefly) security considerations associated with:

Potential Off-site Aspect of Cyber Security,
Interconnectivity of Critical and Seemingly Non-Critical Systems,
Impact of Risk Drivers,
Physical Security for Cyber Assets, and
Layered Security,

Finally, the RBPS Guidance cybersecurity section provides a series of metrics that ISCD would use in assessing whether or not a facility’s site security plan adequately addresses the cyber RBPS. Those metrics are keyed to the risk rating of each facility; generally speaking, higher risk facilities have to take more actions to protect the facility from potential terrorist cyber threats. The threat metrics address:

Cyber Security Policies,
Access Control
Personnel Security,
Awareness and Training,
Cyber Security Controls, Monitoring, Response, and Reporting,
Disaster Recovery and Business Continuity,
System Development and Acquisition,
Configuration Management, and
Audits

Guidance Problems


Beyond the age of the document, the biggest problem with the RBPS Guidance was not addressed by the GAO report and that is that the writers had to be careful not to be ‘too prescriptive’ in their discussions about security issues. I discussed this problem in some depth when the document was published, but in short DHS was dealing with a congressional restriction on providing any sort of one-size-fits-all facilities regulation. In my opinion, they bent over backwards in the RBPS Guidance document to avoid any sort of appearance of dictating security measures and the document is weak as a result.

Proposals for Additional Guidance


While the issues discussed in the RPBS Guidance are still appropriate cybersecurity considerations, they fail to address any of the emerging cybersecurity threats that face high-risk chemical facilities. An updated discussion would have to include discussions about:

Phishing,
Ransomware,
Advanced persistent threats,
Security Operations Centers,
Patching and vulnerability risk assessments, and
Vulnerability reporting.

An additional topic for inclusion would be the ISCD’s cybersecurity integration level program. This is an internal ISCD assessment of the level of integration of cyber systems into the protection and utilization of chemicals of interest. This program was described on pages 15-17 of the GAO report. ISCD uses this assessment to assign CSI with varying levels of cybersecurity expertise to the appropriate facilities. In many ways this integration assessment would more sense than just risk levels in determining which sorts of cybersecurity controls should be in place for facilities.

Problems with Changes


ISCD has a long history of being very responsive to industry concerns with the CFATS programs. They have to be to ensure continued congressional support for the program. That support, in turn, is necessary because of the continued short-term reauthorization process for the program. This does cause some problems for the CFATS program.

ISCD would almost certainly have to go through the comment and response process that it used in the original publication of the RBPS Guidance in any revision of the document. Industry would be leery of any substantive changes to that document that might cause facilities to change their existing security procedures. This is almost certainly been one of the reasons why ISCD has been reluctant to undertake a review and update of that document. On the flip side of that, is of course, if no changes in security programs would be required, why should ISCD take the effort to update the document.

Congress needs to provide cover to ISCD in this matter. As part of the impending CFATS reauthorization, Congress should include a mandate for review and update of the RBPS Guidance. To avoid additional wrangling over what to include in the bill, specifics on what to include in the update should not be provided by congress. That should be left to the review process. Congress should, however, require ISCD to include examples of what sorts of controls could be included in a site security plan to meet the metrics provided in the Guidance.

Tuesday, August 23, 2016

ISCD Publishes CFATS Cybersecurity Guidelines

Today the DHS Infrastructure Security Compliance Division (ISCD) posted a link to the CFATS Knowledge Center providing some additional guidance on how ISCD looks at cybersecurity in the site security plans (SSP) for facilities in the Chemical Facility Anti-Terrorism Standards (CFATS) program. This is supplemental information to that found in Risk-Based Performance Standard (RBPS) 8 of the RBPS Guidance Document.

Since the CFATS program is a risk-based security program, ISCD is really only interested in cybersecurity as it relates to the security of the DHS chemicals of interest (COI) that are responsible for the facility being covered by the CFATS program. Specifically, the guidance notes that ISCD is looking at cyber systems that:

• Contain business or personal information that, if exploited, could result in the theft, diversion, or sabotage of a COI;
• Are connected to other systems that manage physical processes that contain a COI; or
• Monitor and/or control physical processes that contain a COI.

The new document provides a brief overview of the types of activities that ISCD is looking to see in facility SSPs related to three specific types of cyber systems:

• Critical business systems;
• Critical physical security systems; and
• Critical control systems.


As with all ISCD guidance, there is very little detail in this document. This is because of Congressional limitations on the ability of DHS to specify security measures under the CFATS program. Once a facility has an approved SSP, however, the measures described in the SSP are specifically enforceable by ISCD.

Friday, August 20, 2010

CFATS Inspections

There is an interesting article on ICIS.com about comments made by Dennis Deziel, acting director of the Infrastructure Security Compliance Division (ISCD), at the OPSEM2010 conference being held Austin, Tx. He told the conference that ISCD had conducted 80 on-site reviews of site security plans since the inspection process began in February. He also explained that the inspection rate is expected to increase to 30 to 40 per month. I have addressed the problems inherent in this type of inspection process. One of the reasons that the inspection process is being accelerated was identified by Deziel. He was quoted in the ICIS article as saying: “People are now starting to understand exactly what the expectations are, which helps us get quality site-security plans.” Increased Experience Level Part of the reason for this is the fact that many facilities are using a relatively limited number of security consultants to help them complete their CFATS process. This means that there is an unofficial spread of ‘lessons learned’ through these organizations. Subsequent facilities using these consultants benefit from the increased knowledge base about what DHS is actually looking for in their site security plan. Another factor that cannot be discounted is that the inspection teams are gaining experience in the process. Each time they enter a new facility they have a better understanding of what to look for, and what questions to ask. They also learn what other facilities have had success with so this adds to the suggestions that they can make. Helping DHS accelerate the inspection process is the continued increase in trained inspectors coming out of the Chemical Security Academy. Hopefully ISCD is rotating their new inspectors through experienced teams so that they can acquire the lessons learned by those teams. SSP Tool Problems One of the things that has impressed me with the CFATS process is the willingness of ISCD to take a hard look at what they are doing and make appropriate changes. The article quotes Deziel as saying: “That said, we realise (sic) that the site-security plan tool is not perfect, and there hasn’t been a lot of guidance given to facilities.” Part of the guidance problem is that DHS has bent over backwards to avoid looking like it was violating the §550 prohibition of mandating specific security measures. This brings up the interesting possibility of changes being made to the Risk Based Performance Standards Guidance document and/or the Site Security Plan Tool on CSAT. It is probably more likely to have the SSP tool changed since that doesn’t require any publication and comment period to implement. The RBPS Guidance does require a publication and comment period to implement significant changes. I have not heard any specific talk about these changes, but it would be typical for ISCD to update either of these documents to reflect the lessons learned in the process.

Wednesday, October 21, 2009

CFATS Uncertainty

As I noted last week on my personal blog, I was interviewed for two different articles on the CFATS program and the new legislation that may change that program over the next couple of years. Yesterday the first of those articles was posted on SecurityDirectorNews.com. That article by Leishen Stelter addresses the uncertainty that facilities are facing as they submit their first site security plans under CFATS. Risk Based Performance Standards The first uncertainty is due to the nature of the CFATS regulations and their authorizing legislation. Since Congress forbade DHS from specifying security measures that could be required for SSP approval, DHS was only able to outline 18 risk based performance standards (RBPS) that the facilities were required to address in their site security plan. To help facilities adequately address those performance standards, DHS published the Risk Based Performance Standards Guidance document. Because of the requirements of the authorizing legislation (§550 of the FY2007 DHS Appropriations Bill) the metrics provided for each of the 18 RBPS in the Guidance are less than precise in their specifications. Each one uses descriptive phrases to describe what must be accomplished rather than clearly measurable requirements of what must be done. This means that as each facility Submitter clicks on the ‘submit’ once their SSP submission is complete, there is an inherent uncertainty as to whether or not DHS will view the SSP as adequate. In December, DHS is scheduled to start sending inspection team to the Tier 1 facilities that completed their SSP submissions last month. If the inspectors bless the plans the facilities will know that they interpreted the Guidance document correctly. It is not clear that facilities with an unapproved SSP will receive anymore detailed guidance on how to correct their deficiencies; §550 still rules. The lower ranked tiers take little consolation from the fact that Tier 1 facilities will get their SSP’s evaluated first. Because of the Chemical-Terrorism Vulnerability Assessment rules that restrict sharing of facility security information, the follow on tiers will get little additional guidance from the inspections being conducted on the higher risk tiers. CFATA Legislation To add to that confusion, Congress is still in the process of trying to craft a permanent and ‘comprehensive’ authorization for the CFATS program. The current §550 authorization for CFATS expires on October 31st. The FY 2010 DHS Appropriations bill that was just sent to President Obama yesterday will provide an additional 11 months of extension for that authorization while Congress bangs out the details of the new legislation. What seems clear at this point in the legislative process is that the Democratic leadership of the House of Representatives is convinced that a Chemical Facility Anti-Terrorism Act should address a number of perceived deficiencies in the original authorization for CFATS. The current legislation working its way through the House committee process will result in a number of significant changes in the way that DHS will regulate chemical facility security. What those changes will be has yet to be determined by the political process. So, while high-risk chemical facilities are working hard on getting their SSP’s submitted and approved, they are also watching the political process change the landscape of their regulatory world. As they spend money on installing security equipment that may or may not be adequate for the current regulations, they face the prospect that even those vague requirements are in the process of changing. The only saving grace is that even if the current legislation were approved tomorrow, it would be at least 18 months before the new regulations will go into effect. So, the facility security teams working on their SSP need to ignore, for now, the political machinations that will affect their next iteration of the SSP process. They need to concentrate their work on finalizing their current SSP; leave upper management to worry about the final wording of the final CFATA legislation.

Friday, May 15, 2009

SSP-RBPS Rolled Out Today

At noon today the Department of Homeland Security rolled out the next phase of the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS). They published the Risk-Based Performance Standards Guidance (RBPS Guidance) document and opened the Site Security Plan (SSP) tool on their Chemical Security Analysis Tools (CSAT) web site. Two SSP supporting documents were also published on the CSAT site. Additionally they started the process of mailing out the notification letters that will let high-risk chemical facilities the official results of their Security Vulnerability Assessment (SVA) that were submitted last year. Finally, DHS has sent emails to the registered users of the CSAT that the RBPS Guidance has been posted on the DHS web site. RBPS Guidance The RBPS Guidance document is a more polished document than the draft that DHS published for public comment last year. It still does not spell out what a high-risk chemical facility must do to adequately secure itself from potential terrorist attack, but DHS has been prohibited by Congress from doing that. Instead it “reflects DHS’s current views on certain aspects of the Risk-Based Performance Standards (RBPSs) and does not establish legally enforceable requirements for facilities subject to CFATS or impose any burdens on the covered facilities” (RBPS Guidance, pg 7). The general layout of the document and the basic content remains the same as the draft, but the new document will require a careful reading. There are some subtle differences in the information presented. Additionally, DHS has made it clear that this is a living document. In one of many footnotes in the document the RBPS Guidance notes that “DHS is likely to periodically update this Guidance document to take into account lessons learned throughout CFATS implementation, describe new security approaches and measures that covered facilities may wish to consider implementing, and provide information on any new or revised RBPSs” (pg 8). SSP Tool As with all of the previous tools published in CSAT, access to the actual SSP tool where high-risk chemical facilities will actually submit their SSP is limited to registered CSAT users. As with each of the previously published tools the CSAT web site includes downloadable copies of two documents that will aid Preparers and Submitters with the preparation and submission of the SSP. The SSP Instructions provides detailed instructions on how to answer the very large number of questions that constitute the method of submission of the SSP. The SSP Questions provides a way for facility Preparers to collect and organize the required information to make it easier to actually enter the information into the on-line SSP tool. Each of these lengthy documents should be read carefully before trying to collect and submit the data required for the SSP. Future Blogs As I have done with all of the other CSAT tools, I will be doing a number of blog postings looking at the details of the SSP Tool, it’s supporting documents and the RBPS Guidance document. This is probably the most complex portion of the CFATS process and will take a lot of time to analyze and explain. Of course, I have the luxury of not actually having to implement this at a real chemical facility. I certainly welcome and encourage anyone with questions and comments about these new documents to send them on to me (pjcoyle@aol.com) or to post them as comments to this blog. I’ll do my best to explain things. DHS has also established a procedure for dealing with questions. You can contact the CFATS Help Desk either via e-mail at csat@dhs.gov or by phone at 866-323-2957. They also provide the name and address of a real person to whom you can “submit questions via regular mail” (pg 9):
Dennis Deziel Deputy Director Infrastructure Security Compliance Division U.S. Department of Homeland Security, Mail Stop 8100 Washington, DC, 20528

Saturday, April 25, 2009

OMB has Approved RBPS

I just heard this morning that the Office of Management and Budget (OMB) has approved (late Thursday) the Risk-Based Performance Standards Guidance document for the CFATS program. As of this morning (0900 EDT) the approved RBPS Guidance was not yet posted on the DHS web site. I expect that within the next couple of days it will be posted as will the initial information on the SSP tool. According to what I am hearing, the first Tier 1 SVA letters will be going out sometime after May 1st.

Monday, November 17, 2008

RBPS Guidance – Physical Security Measures

This is the another in a series of blog posts that looks at the recently released draft DHS guidance document for implementing the Risk-Based Performance Standards (RBPS) in site security plans (SSP) for high-risk chemical facilities. The RBPS are a key component of the Chemical Facility Anti-Terrorism Standards (CFATS). This post deals with the discussion of physical security measures found in Appendix C. Earlier blogs in this series include: RBPS Guidance – Introduction RBPS Guidance Shortcomings RBPS Guidance – 18 Risk Based Performance Standards RBPS Guidance – RBPS Metrics Physical security measures are discussed in various levels of detail in a variety of RBPS, in particular RBPS 1 thru 4 contain some significant discussion on physical security measures. Since physical security measures affect all RBPS to some extent, the authors of the Guidance document elected to place a more detailed discussion of those measures in Appendix C. Appendix C to Draft RBPS Guidance Document The introduction to Appendix C (page 131), which also addresses cyber security and security procedures, reiterates a comment seen throughout the Guidance documents, that “no single measure, policy, or procedure listed below will alone satisfy the security needs of a facility”. The introduction also contains, yet again, a §550 inspired disclaimer that each facility is free to “to include any measures they think appropriate to demonstrate compliance with the RBPS in their Site Security Plans (SSP)”. The authors of Appendix C note that physical security measures are “are most useful for reducing the risks of direct, physical attacks against the facility”. The discussion looks at four main types of physical security measures:
Perimeter Barriers, Monitoring and Intrusion Detection Systems, Security Lighting, and Protective Forces
The first three physical security measures are discussed in some detail, with examples of different measures, equipment and techniques available. There is also a brief discussion of the various security considerations that must be considered when employing that type of security measure. Finally each section includes a reference list of on-line and print resources that can be used to further explore the subject. There is also a general physical security measure resource list at the end of the discussion. Perimeter Barriers The physical security measure that gets the most attention in Appendix C is the use of perimeter barriers. The introductory discussion notes that perimeter barriers can act as both a physical and a psychological barrier to unauthorized entry to the facility. It describes four general uses for perimeter barriers:
Controlling vehicular and pedestrian access Providing channeling to facility entry-control points Delaying forced entry Protecting critical assets
The perimeter barrier discussion looks at a variety of manmade and natural barriers. It provides a brief discussion of a large number of barrier systems and how they can be used to stop human and vehicle penetration of the facility perimeter. The addition of line drawings or pictures would have made those descriptions more valuable. Monitoring and Intrusion Detection Systems The next physical security measure discussed deals with monitoring. The two sentence introduction provides the most succinct description of monitoring in a physical security context that I have ever seen. It is worth quoting in its brief entirety (page 138):
“Security events are monitored through a combination of human oversight and a variety of technical sensors interfaced with electronic entry-control devices, remote surveillance imagery, and alarm reporting displays. When an event of interest to security is identified, it is either assessed directly by sending persons to that location or remotely assessed by personnel evaluating sensor inputs and surveillance imagery.”
The discussion of video monitoring is very brief and cursory. John Honovich has provided a much more extensive discussion in his eBook (see: “Video Surveillance Book – 2nd Edition”) which should be included in the reference section. The discussion of intrusion detection systems is much more useful. Security Lighting The security lighting section of the physical security measures discussion is relatively short. There is a brief discussion of the importance of adequate lighting for a variety of monitoring systems. The discussion of security considerations for security lighting is also short, but it is briefly comprehensive, identifying many of the relevant issues. Protective Forces Discussion The discussion of the last physical security measure, Protective Forces, is very poorly developed. This is probably because of the many controversies associated with the employment of security forces. Earlier this year I did a series of blogs (see: “Security Forces at Chemical Facilities – Sourcing Security”) that describes some of those controversies. The Appendix C discussion completely avoids the issues and, as a result, provides almost no information. Finally, there are no resources provided for a more detailed discussion of protective forces. This is, without a doubt, the least developed discussion in the entire draft RBPS Guidance document.

Wednesday, November 12, 2008

RBPS Guidance – RBPS Metrics

This is the another in a series of blog posts that looks at the recently released draft DHS guidance document for implementing the Risk-Based Performance Standards (RBPS) in site security plans (SSP) for high-risk chemical facilities. The RBPS are a key component of the Chemical Facility Anti-Terrorism Standards (CFATS). This post deals with the RBPS Metrics provided for each RBPS. Earlier blogs in this series include:
RBPS Guidance – Introduction RBPS Guidance Shortcomings RBPS Guidance – 18 Risk Based Performance Standards
Each discussion of the eighteen Risk Based Performance Standards listed in the Guidance document ends with a table listing the ‘metrics’ that might be used to evaluate how a facility’s site security plan (SSP) addresses. The table is laid out so that there is a column for each of the four tiers of high-risk facilities. There is a summary level listing for each RBPS and a separate listing for each of the security measures discussed for that RBPS. Metrics are Only Guidelines The use of the term “metrics” is misleading in this draft Guidance document. They do not actually provide a measure of the security. DHS describes the information in these tables this way at the start of every RBPS Metrics table in the Guidance:
“The following table provides a narrative summary of the security posture of a hypothetical facility at each tier in relation to this RBPS and some example measures, activities, and/or targets a facility may seek to achieve that could be considered compliant with the RBPS. However, a facility may choose to demonstrate compliance through other measures, activities, and/or targets, provided DHS is satisfied that the measures demonstrated meet the level of performance specified in the RBPS.”
The fact that the ‘metrics’ provided in the tables are defined in qualitative terms not quantitative provides another level of difficulty for facilities trying to decide if their site security plan provisions adequately address the RBPS. What is clear from reading these guidelines is that facilities are going to have to work closely with the DHS inspectors during the SSP approval process. Levels of Protection In their SVA approval letter DHS will tell each facility their final assigned Tier level and the security issues that must be addressed in the SSP. Both of these pieces of information are important for determining the level of protection each facility must strive to achieve in addressing each of the RBPS in their SSP. Level of Protection Based on Tier Ranking To understand how this might work, lets look at the metrics for RBPS #1, Restrict Area Perimeter. First lets look at an extract from the summary metric (page 27) for each of the for Tiers (#1 is the highest risk tier):
Tier #1: “The facility has an extremely vigorous perimeter security and monitoring system that enables the facility to thwart most adversary penetrations and channel personnel and vehicles to access control points…” Tier #2: “The facility has a vigorous perimeter security and monitoring system that enables the facility to thwart or delay most adversary penetrations and channel personnel and vehicles to access control points…” Tier #3: “The facility has a perimeter security and monitoring system that enables the facility to delay a significant portion of attempted adversary penetrations and channel personnel and vehicles to access control points…” Tier #4: “The facility has a perimeter security and monitoring system that enables the facility to delay a portion of attempted adversary penetrations and channel personnel and vehicles to access control points…”
We can see the change from an ‘extremely vigorous perimeter” to a “vigorous perimeter” to just a “perimeter” from Tier 1 through 3, but there is no further decrease at Tier 4 reflecting that there must be some sort of ‘perimeter security and monitoring’ system at all high-risk chemical facilities. We can see a similar change in the required proficiency of that system. Level of Protection Based on Security Issue Again, we can look at RBPS #1 to see how the level of security required for different facilities also depends on the security issues identified for that facility. For this we can look at Metric 1.3, Standoff Distance:
Tiers #1and #2: “Sufficient vehicle standoff distance or alternative protective means are provided to ensure that vehicle-borne improvised explosive devices will not cause a breach of containment resulting in an uncontrolled release of a release chemical of interest from the nearest point of attack.” Tiers #3 and #4: “N/A”
From the wording we can see that this metric would only apply to facilities that have a security issue related to release COI. Facilities with theft/diversion or sabotage COI would not have to use this security measure to address the Restrict Area Perimeter RBPS. Additionally, we can deduce that facilities with a release COI security issue are not assigned to a Tier 3 or Tier 4 ranking since there are no metrics associated with those levels. RBPS that Transcend Security Issue or Tier Ranking Similarly we can see that some RBPS will have metrics that will not vary because of either security issue or tier ranking. We can think of these as transcendent RPBS. A good example of this can be found in RBPS #10, Cyber. The summary metric (page 81) is the same for all four tiers and carries no reference to any security issue:
Tiers #1, #2, #3, and #4: “The facility should have in place cyber security policies, procedures, and measures that result in a low risk of a successful attack on the facility’s critical cyber systems or using a facility’s critical cyber systems to carry out or facilitate an attack.”
There are some security measure metrics that vary somewhat by tier level for this RBPS. The following security measures have two levels of metrics, those for Tiers #1 and #2 and those for Tiers #3 and #4:
Metric 8.3.2 Separation of Duties Metric 8.3.3 – Access Control Lists Metric 8.4.1 – Cyber Security Training Metric 8.5.2 – Network Monitoring Metric 8.5.3 – Incident Response Metric 8.8.3 – Network/System Architecture Metric 8.9 – Audits
Metrics as an Evaluation Tool While DHS currently believes that the Section 550 language prohibiting the requiring of any specific security measure also requires the disclaimer discussed above, the metrics provided in this Guidance document will, for most facilities, provide a useful tool in evaluating their SSP. They won’t provide an absolute measure of compliance, but a facility that can provide an adequate justification to the DHS inspector of how their SSP addresses the listed metric, has a very good chance of having their SSP approved.
 
/* Use this with templates/template-twocol.html */