Showing posts with label SSP Approvals. Show all posts
Showing posts with label SSP Approvals. Show all posts

Tuesday, September 8, 2015

ISCD Publishes September CFATS Fact Sheet

This morning the DHS Infrastructure Security Compliance Division (the folks that run the CFATS program) published their September CFATS Fact Sheet, providing updated information on the progress being made on the completion of the Site Security Plan (SSP) approval process.

The table below summarizes the important numbers included in the new Fact Sheet and compares it to the August and July Fact Sheet numbers (NOTE the August link is to my blog post because the August Fact Sheet is no longer available on the ISCD web site. Both the July and June Fact Sheets are):


July
August
September
Covered Facilities
3,229
3,223
3,197
Authorized SSP
3,121
3,139
3,178
Approved SSP
1,935
2,021
2,104

The relatively small increase in approved SSPs would seem to indicate that we are not yet seeing the effect of facilities submitting SSPs under the Expedited Approval Process. Since the first EAP SSP could only have been submitted on July 16th we are still well within the potential 100 day limit for DHS to disapprove an EAP submitted on that date. I expect that we will start to see an increase in numbers when the October Fact Sheet is published next month, but we won’t see the gross effects until November or December. The EAP approval process for facilities already in the CFATS program as of June 16th will not be completed until near the end of February.

The other impressive statistic in the new Fact Sheet is that we are now at about 99% on the facilities that have an authorized Site Security Plan. This is the first stage of the SSP review process and reaching that 99% point means that we are essentially at full compliance on submitting SSPs. The program will probably never reach the 100% authorization rate as new chemical facilities are being built and added to the program fairly frequently. There is a time lag between the time that a facility is notified that it is a covered facility and the time that it is required to submit an SSP.

Which, of course, leads us to one of my pet peeves; we see another unexplained drop in the number of facilities covered by the CFATS program. There are a number of legitimate reasons that a facility could be removed from the program; they could have eliminated or reduced the use/storage/manufacture of the DHS chemicals of interest (COI) that form the basis for entry into the process; or the facility could have been closed. I actually know of a covered facility that burnt to the ground (certainly no remaining security issues at that site). What bothers me is that DHS has refused to publish numbers reflecting the reasons that facilities have left the program.

The reason that I harp on this so much is that we need the numbers to intelligently discuss how ISCD is handling the verification of the changes. Without understanding why the facilities are leaving the program we can’t even ask legitimate questions about the process.


Finally, there is one other area where DHS is not sharing information about the CFATS process. We know that they started doing compliance inspections well over a year ago. We know from the latest GAO report on the CFATS program that ISCD had completed 83 such compliance inspections early this year. What we don’t know is what they have done since then. Given the problems that the GAO identified in the compliance inspection process we can be sure that Congress is going to start asking questions about this area. I don’t understand why ISCD hasn’t gotten in front of this problem by starting to publish the numbers.

Wednesday, April 2, 2014

ISCD Publishes CFATS Update for March 2014

I thought it was an April Fool’s joke last night when I saw a listing for the April 2014 CFATS update on the DHS Critical Infrastructure: Chemical Security web page and it was reinforced by the fact that the link didn’t work. I contacted DHS this morning and it was a glitch not an April Fool’s joke that provided the bad link; the page is good and is now live.

The report shows continued incremental improvement in both the authorization and approval rates.

Table 1 shows the general continued improvement in both sets of numbers.




 Table 1: Total Program Numbers

Table 2 shows the average daily rate of both authorizations and approvals for the month of March. The authorization rate picked back up significantly and is the highest rate seen to date. The approval rate is still good and is the second highest seen to date.


 Table 2: Average Daily Rate

Everyone would like to see a dramatic increase in both rates so that the current backlog could get erased. I don’t think that we will actually see this as there is only so much that can be done by the current sized inspection force. Dramatic improvement will only come about through a significant change in the way that inspections are done and that would require a significant change in the regulations I’m afraid.


NOTE: ISCD continues to report declines in the number of covered facilities. This month it is down to 4,172 from 4,199 last month. Still no explanation of why the number is going down while we are expecting to see an increase due to some of the EO 13650 outreach activities.

Thursday, January 30, 2014

Latest CRS Report on CFATS

Earlier this month the Congressional Research Service (CRS) published their latest version of their report on the Chemical Facility Anti-Terrorism Standards (CFATS) program. This periodic report by Dana Shea summarizes the current state of the CFATS program, explains current problems facing the program. Past reports included an analysis of various potential solutions for CFATS problems that may require Congressional action, that is missing from this version.

SSP Process

Given the on-going congressional concern about the progress being made on the Site Security Plan (SSP) front Shea takes a detailed look at that portion of the program. This discussion begins very good, concise summary of the SSP regulatory process:

“Over time, the DHS has attempted to develop a consistent nomenclature for its review and inspection process. The DHS authorizes an SSP (issuing the facility a letter of authorization) when the submitted SSP is satisfactory under CFATS. The DHS conducts an authorization inspection of a facility with an authorized SSP to compare the authorized SSP to the conditions of the facility. Following a successful authorization inspection, the DHS approves the SSP (issuing the facility a letter of approval). At a later date, expected to be one year after approval of the SSP, the DHS will conduct a compliance inspection of a facility to determine whether the facility has fully implemented its approved SSP. Compliance inspections then occur on a periodic basis depending on the risk tier to which the facility is assigned.” [Footnotes removed]

What is missed in this discussion is why such a complicated SSP process is necessary. Since Congress declared in the CFATS authorization that DHS may not specify what security measures are required for SSP approval, DHS was forced to publish a rather vague Risk-Based Performance Standards (RBPS) guidance document and facilities were left to guess what security measures to put into their proposed SSP. Since security is not a profit center, the apparent actual risk of a terrorist attack is low (no attacks to present and no reports of credible threats against chemical facilities), and security measures usually complicate day-to-day operations, facilities want to establish just the minimum security measures required to assure compliance with CFATS. As a result, there is a natural tendency to under-guess what is required for compliance.

Further complicating the process is the fact that the current SSP data submission tool in the on-line Chemical Security Assessment Tool (CSAT) uses a question/response format that solicits a limited amount of specific information about the proposed SSP and relies on the addition of narrative submissions for the bulk of the details about the program. Facility security managers have every incentive to limit the amount of information that they provide since any changes to that information after the SSP is approved will have to be vetted through DHS before it can be changed. Limiting the scope of that DHS operational veto is in the best interest of the facility management.

The disjointed and frequently duplicative organization of the information in the SSP tool further aggravates the approval process by making it difficult for inspectors to preview the submitted data before they conduct their authorization inspections. Since large chemical facilities are already complicated physically and operationally, inspectors have to become familiar with the unique operational aspects of the facility and become familiar with the proposed SSP at the same time during the scope of a three day inspection.

Digesting that inspection information and preparing a coherent report on how well the facility complies with the RBPS is a time consuming process. This is complicated by the fact that every chemical facility is unique in its surroundings, operations, hazards and susceptibility to terrorist attack. Further, the Chemical Security Inspector (CSI) needs to have an operational understanding of chemical safety, physical security, operations security, and cybersecurity to adequately understand all of the implications of the proposed SSP.

Finally, the CSI workforce is limited to about 160 personnel which include regional commanders who would be expected to spend only limited amounts of time in actual inspection activities. Authorization inspections are typically conducted by 3 to 5 inspectors depending on the size and location of the facility.

Inspection Rate

Shea spends a great deal of time analyzing the rates of authorization, inspection and approval and their inter-relationships. I would assume that this was done at the request of various Committee Chair who are legitimately concerned with the progression of that process. Looking strictly at statistical data Shea has provided detailed information about the number of actions that are necessary to complete the SSP process in a variety of time frames. Table 1 below summarizes the Shea data for the average monthly rates for achieving completion of the SSP authorizations and approvals for the facilities currently the program.


Current
1 year
2 year
5 year
10 year
Authorizations
61
284
142
57
28
Approvals
28
327
164
65
33
Table 1: SSP Authorization and Approval Rates

As I have discussed in various posts (see the latest here) about the monthly reports the Infrastructure Security Compliance Division (ISCD) has been publishing on the SSP approval process, there are a lot of things beyond the control of DHS that have caused significant month-to-month variations in the approval rates. It is also not clear how the changes in types of facilities being inspected (alluded to in the CRS report). One would think that the process would be easier at smaller less complicated facilities, but as I recently noted the lack of administrative resources at those facilities is also going to impact the approval process.

It seems likely that DHS will be able to complete the authorization process in somewhere between two and five years, particularly since that portion of the process includes only limited CSI involvement. The projection for the approval process is less sanguine. Shea notes that ISCD has recently begun the process of compliance inspections which will cut into the number of authorization inspections that the limited CSI force can conduct. Also noted as a force time-consumer is the current regulatory requirement to begin the reauthorization/re-approval process for Site Security Plans. That should begin in very limited numbers this fall.

New Facilities

Further compounding this issue is a discrepancy between the number of covered facilities and the number of facilities with a final tier assignment. Facilities become regulated when they submit a Top Screen that DHS decides provides presumption of being at high-risk. In the initial Top Screen submissions in January of 2008 40,000+ facilities submitted Top Screens, but only about 7,000 were notified by DHS that they were preliminarily determined to be at high-risk and would have to enter the initial evaluation process of the regulated chemical companies, the Security Vulnerability Assessment (SVA).

What is not clear in Shea’s discussion is the fact that not all of those facilities submitting SVA will be confirmed as high risk and be given a tier ranking assignment. It is only at that point that the facility joins the cue of facilities in the SSP authorization/approval process. Of the original 7,000 covered facilities only about 4,000 were required to submit sight security plans, the remainder were dropped from the CFATS program because the additional data submitted demonstrated that they were not at high-risk of terrorist attack.

Shea appears to assume that all of the currently regulated facilities will be required to submit SSPs that will require future action. That is not supported by past history. Only about half of the currently regulated facilities that do not have tier assignments would be expected to have to submit SSPs.

Alternatives

What is disappointingly lacking in this version of the CRS report is a look at potential alternatives. With a new CFATS authorization bill currently in the works it would have been nice to see a look at possible congressional actions that could address this process.

The simplest action (and the least likely) is for Congress to increase the funding and authorized head count for CSI. Clearly the limited number of CSI has got to be a factor slow rate of approvals. Whether or not it is the only factor has yet to be seen. Shea acknowledges this, noting (pg  16):

“Increasing authorization inspection capacity might serve to highlight other potential issues within the CFATS process, such as delays in processing information from authorization inspections and issuing letters of approval.”

Congress is unlikely to significantly change the number of CSI. The CFATS program already has more full-time federal inspectors than does the EPA’s RMP program or OSHA’s PSM program which address similar (yet a far larger number) facilities. Federal employee costs are high and there appears to be a general reluctance to pay that cost for enforcement personnel.

Last summer I proposed another alternative to speed up the SSP authorization and approval process; adjust the standards by which those actions are reviewed for Tier 3 and Tier 4 facilities. Since these facilities are lower risk, it would seem reasonable that while the RBPS are lower the standards for review of the submissions should also be less stringent. While this would not technically need congressional approval it would certainly need congressional acquiescence.

Personnel Surety

There was one SSP issue that was completely ignored in the Shea report, technically there have been no site security plan approvals; they all have been conditional because facilities have not been able to fulfill all of the standards for RBPS # 12 Personnel Surety. The reason for this is that DHS has yet to establish a means for facilities to vet personnel given unaccompanied access to critical areas of the facility against a list of known or suspected terrorists. ISCD has been at work on this program with little success for over four years now.

I understand that this will be addressed by CFATS authorization legislation that will be introduced in the next couple of weeks. It remains to be seen whether or not that bill would, if passed (more than iffy in an election year), ease or compound the difficulties that DHS is having getting a plan that is acceptable to industry and accomplishes the requirements for personnel surety established in the current authorization.

In any case, some sort of reauthorization/re-approval process will have to be implemented once a CFATS personnel surety program is put into place by DHS. This should be able to be an almost completely administrative review, requiring little or no CSI involvement.

Tuesday, September 11, 2012

Observations on the CFATS Hearing


I didn’t get a chance to watch the entire hearing today, the split hearing because of 9/11 ceremony put a severe cramp in my schedule. I’ll have a chance to review the rest of the hearing sometime this weekend, but the initial portion of the hearing that I did see provided some interesting information.

Personnel Surety


Chairman Shimkus (R,IL) was particularly concerned about the personnel surety program, or more accurately the lack of one.  He was particularly concerned about how the Department could approve a Site Security Plan when the facility had no way to do the required check of the Terrorist Screening Database (TSDB). Under Secretary Beers explained that the two facilities (on additional one since September 4th) with approved SSP actually had ‘conditional approval’ pending the completion of the ISCDs personnel surety program development.

No real questions were asked about the reasons that the personnel security ICR had been withdrawn as Shimkus was trying to keep the hearing moving quickly so that there was a chance for at least one round of questions; Beers would not be back when the hearing resumed. Beers did report that the new ICR would be ready for the publication of the new 60-day notice in 30 days. I’m sorry but I’ve seen so many DHS delays that I’ll be surprised to see it within 60-days.

Beers also assured Ranking Member Gene Green (D,TX) that the new personnel surety program would specifically incorporate the use of the Transportation Workers Identification Credential (TWIC).

Inspections


The Department has been touting their new training program for conducting approval inspections, the inspection to determine if the facility is actually properly implementing their authorized SSP. With 73 conditionally authorized SSPs to work on, Director Wulf informed the Subcommittee that ISCD planned on conducting 10 approval inspections in September (it’s not clear if that includes the site approved since September 4th).

When pressed, hard, for the projected rate of SSP approvals Wulf said that ISCD planned on inspecting and approving 300 SSPs in the next year. I missed the Congressman’s name who commented that it would ‘take a century’ to complete inspecting all of the covered facilities. That’s a slight exaggeration; it would only be about 15 years.

ISCD Personnel Issues


The only hard questioning came from Rep. Cassidy (R,LA) who focused his questioning on the personnel issues raised in the Anderson-Wulf memo. He repeatedly asked Wulf if anyone had been dismissed or demoted because of the issues raised in the memo. The answer was no, but Cassidy didn’t give him much chance to explain why not. The 5 minute questioning format of hearings means you have to demand short answers if you have lots of questions.

Other Issues


The Tweets from @SOCMACONNECT and @socma for the remainder of the hearing look like there might have been some interesting exchanges. Oddly enough I didn’t see anything on TWITTER about the testimony or responses from Ms. Anna Fendley (United Steel Workers) or Mr. Paul Orum (Blue-Green Coalition). I’m looking forward to having a chance to review the webcast of the rest of the hearing.

Sunday, March 11, 2012

More on ISCD Hearing – Industry Suggestions

Earlier this week I noted in a blog post on the ISCD hearing held before a subcommittee of the House Homeland Security Committee on Tuesday that the industry witnesses had offered suggestions about how the CFATS implementation could be improved. None of this was directly mentioned in the oral presentations or addressed in the questioning by the Subcommittee (with the exception of one tiny inconsequential question and answer), but it was included in the written testimony of Timothy Scott (DOW/ACC) and Bill Almond (SOCMA).

There wasn’t anything that was really new in these suggestions; SOCMA and ACC have been mentioning most of these for some time now; but this was an appropriate venue to bring them up. It would have been nice if there had been more time for consideration/discussion of these suggestions, but that is a common problem with congressional hearings; just not enough time for a discussion of all of the interesting and important topics.

The suggestions fall into three broad categories:

• TWIC-Personnel Surety Program

• Alternative Security Programs

• Outside Inspectors

TWIC-Personnel Surety Program


There is one area where there is broad agreement between management and labor and Democrats and Republicans is that the personnel surety program being developed (‘being developed’ for a number of years) by ISCD for use by CFATS facilities to fulfill the requirement of the Risk-Based Performance Standard #12 should ‘give full credit’ for the TWIC and other federal identity documents that include vetting against the Terrorist Screening Database (TSDB).

What everyone (except ISCD) wants is for facilities not to be required to submit information to an ISCD Personnel Surety Tool for any employee that has a TWIC or HME (those being the two most common federal programs that would be represented by significant numbers of chemical personnel). ISCD wants information on TWIC/HME holders to be submitted so that they can check that those documents are still current; something that facility security managers can and should do. ISCD has made clear that it wants a list of everyone that is a CFATS employee or has unaccompanied access to a high-risk (CFATS) chemical facility; just not why that list is important or even necessary.

If this is all that the TWIC discussion was really about, this would be a no brainer. Congress should step in and tell DHS that the TWIC fully meets the requirements for vetting personnel against the TSDB. OOPS, congress, in their Section 550 (Department of Homeland Security Appropriations Act 2007) authorization language, specifically told DHS that they could not require any specific security measure. And Congress put nothing in that language requiring vetting against the TSDB; another of the many problems caused by the political failure of Congress to pass a comprehensive chemical facility security bill.

Another problem that has not been addressed in the discussion about TWICs is that many in the chemical industry intend to use the TWIC instead of managing their own personnel surety program. Currently ISCD intends for each facility to do its own background check on each employee and on each guest given unaccompanied access to restricted areas of the facility with ISCD only getting involved in the TSDB vetting. If a facility were to require possession of a TWIC as a condition of employment and require all site visitors and contractors to also have a TWIC, they would not have to worry about the liability issues related to conducting and evaluating criminal background checks.

Some of the facilities (perhaps even most) will reimburse employees for the cost of obtaining a TWIC. There will certainly be a significant number that will not cover that cost, thus passing a portion of the cost of their personnel surety program onto employees. Since (as I understand it) the TWIC fee is an application processing fee will any of these companies reimburse employees that cost if they are denied a TWIC?

And there is the legal issue that has yet to be resolved; TWICs are used by ‘transportation workers’ that require access to MTSA covered facilities. Each applicant is required to affirm on their application that they require access to an MTSA facility as a requirement of their job. Since CFATS facilities are, by law, not MTSA covered facilities, companies requiring TWICs as a prerequisite for employment, will be asking many people to lie when they make that affirmation, a crime under federal law.

Congressman Lungren’s (R,CA) Subcommittee would do well to hold a hearing or two about this specific TWIC/CFATS issue and craft legislation as appropriate.

Alternative Security Programs


Congress in their extensive guidance to DHS about the establishment of the CFATS program (more than just a little sarcasm here) did authorize the Secretary to “approve alternative security programs established by private sector entities, Federal, State, or local authorities, or other applicable laws if the Secretary determines that the requirements of such programs meet the requirements of this section and the interim regulations”. This sounds like a great way for DHS to reduce their review/inspection workload; however, the very next paragraph of §550 says:

“Provided further, That the Secretary shall review and approve each vulnerability assessment and site security plan required under this section” {§550(a)}.

ISCD has set-up on-line tools for submission of data to be reviewed. The Site Security Plan tool is not really a site security plan, but rather a series of questions about the SSP. The answers to those questions are supposed to allow ISCD to evaluate if the SSP meets the risk-based performance standards outlined in 6 CFR 27.230. Since facilities submitting an alternative security plan still have to meet those standards, ISCD needs to review those submittals as well.

The only difference is that there will be a different format used for that data submission. I certainly don’t see how this will make ISCD’s work load any easier to bear. Either the submission will be an actual written ASP (an actual readable document that will explain what security measures are to be in-place, how they will be implemented, and who will have what responsibilities in implementing and enforcing those measures) or it will be another questionnaire about such a plan that ISCD will use in the same manner as they use the responses to their SSP tool.

Now I suppose that it is entirely possible that the ACC, or SOCMA, or any other industry supported organization could come up with an on-line data submission tool that would collect more appropriate data and/or organize the data collected in an easier to evaluate format. If that is the case (and the current SSP tool is very incomplete and poorly organized at best) then the ASP will be helpful. The only problem is that if every different industry organization comes up with a different ASP submission format; that is going to aggravate the current training problems at ISCD. And that isn’t going to improve anything.

Outside Inspectors


There was one relatively new suggestion made by Mr. Scott in the memo attached to his prepared testimony. On page 6 of that testimony/memo he makes the following proposal:

“DHS should consider an alternative self-inspection program for lower tier facilities (Tiers 3&4) using accredited third-party auditors. This alternative inspection program could be monitored with statistical sampling (audit schedule) by DHS CFATS inspectors to verify compliance. This would help streamline the program by lessening the burden on the DHS inspection cadre and allow DHS to focus resources and attention on higher risk facilities (Tiers 1 & 2). Existing private sector programs could be leveraged under this concept including the Responsible Care Security Code Program, which is mandatory for membership in ACC and requires third-party certification by an accredited third-party auditor.”

This idea does have a certain appeal. It would cover the vast bulk of the 4,000+ facilities currently in the CFATS program and it would certainly allow inspectors to spend more time at the highest risk facilities conducting final approval inspections and periodic re-inspections to allow for assurance that the programs are being properly maintained.

This would, however, specifically violate another congressional mandate in §550:

“The Secretary of Homeland Security shall audit and inspect chemical facilities for the purposes of determining compliance with the regulations issued pursuant to this section.” {§550(e)}.

So, DHS could consider this idea, but it would require specific congressional authorization to implement. I can just hear Rep. Thompson (D,MS) complaining about ‘inherently governmental functions’ when this comes up for discussion.

Besides, this will do nothing to address the current problems that ISCD is facing in getting SSPs approved. The compliance inspections have yet to start and we have many years to go before Tier 3 and 4 facilities will have to start to worry about compliance inspections.

The Real Problem


These industry suggestions, and even the Anderson-Wulf report, do not address or even identify the real problem that ISCD is having with the approval of SSPs at Tier 1 facilities. These facilities are huge and complicated and even the most basic security plan for them will also be huge and complicated. ISCD really had no idea how large or complicated an oil refinery (for instance) is or how complex a security plan for such a facility would have to be.

It quickly became obvious to all involved that the SSP tool was nowhere near complex enough to gather the data necessary to determine if the SSP was adequate to cover the 18 risk-based performance standards (RBPS). This is why DHS had to institute the ‘pre-authorization’ inspection program that were never included in the original CFATS program outlined in 6 CFR Part 27. Oh, and by the way, there is no authorization or requirement in those regulations to conduct those inspections.

If (and that is always an exceedingly large word in meaning if not spelling) they now have enough information to make that evaluation they face the second basic problem with CFATS program; ISCD cannot dictate what security measures are necessary to achieve compliance with those RBPS. Thus, ISCD has to negotiate with facility management as to what security measures will meet the requirements of the CFATS program. Again, this negotiation process is not specifically spelled out in the CFATS regulations, but is an inherent result of the congressional restrictions placed on DHS.

Now, I am reasonably certain that ISCD does not have the personnel trained in both security and chemical processing necessary to determine specifically what security measures are appropriate at any given facility. So there is no way that they should be given the authority to dictate security measures. This means that we are stuck with the current, and necessarily slow, SSP authorization process.

Additional inspectors and staff review personnel may help to speed up the process some. Some additional speed will come from the experience gained in previous negotiations on both the industry and government side of the table. And additional speed will be gained when the facilities are smaller and less complex.

But none of the items under discussion in these hearings, or probably anything in the Anderson-Wulf report will address this underlying problem. Until we start discussing this issue nothing can be done to significantly improve the time that it takes to complete the SSP authorization process.
 
/* Use this with templates/template-twocol.html */