Showing posts with label SSP Submission. Show all posts
Showing posts with label SSP Submission. Show all posts

Friday, May 22, 2009

SSP Submission – Facility Data

This is the second in a series of blog posting on the recently released Site Security Plan Instructions Manual. The first blog in this series was: Preparing for SSP Submission Regular readers of this blog will remember that I did a series of blogs earlier this year on ‘draft’ copy of the site security plan template that I had received. As part of the this series I will refer back to those blogs to correct any potentially confusing or misleading information that I provided. Today I will start with the General Facility and Facility Operations portions of the SSP and I will point out any differences between my earlier blogs and the actual instructions. General Facility Information As I noted in my earlier blog, most of this information will be pre-populated in the SSP Tool from information provided in the Top Screen and SVA submissions. The facility needs to review all of the pre-populated data to ensure that it is correct and complete. If an item of information is missing, enter the data. If the information (other than latitude and longitude) is incorrect, press the “Update Facility Information” button and correct the data. Latitude and Longitude information can only be corrected by contacting the DHS CSAT Help Desk. Earlier I described the Facility Final Notification Letter (FFNL) information that is included in this section. The Facility is responsible to ensure that the information in that letter is properly reflected in this section of the SSP. If any information from the FFNL is missing or incorrect in this section, the Facility must contact the Help Desk before proceeding with entering any further data in the SSP tool. This section also asks about the COI found at the facility. There will be a question for each of the seven security/vulnerability combinations asking if there are issues related to COI in that category. The Facility should answer yes if there are any COI listed in that security/vulnerability category listed in the FFNL. Additionally, the facility can answer yes if there are COI not included in the FFNL that they want DHS to consider in their SSP submission. See my earlier blog for an explanation why a facility might want to do this. For each positive answer in this section a list of COI from that category will appear with ‘Yes’/‘No’ check boxes to allow the facility to select the covered COI. The COI listed in the FFNL should already be selected ‘Yes’ as part of the pre-populated data. Once each of the selected security/vulnerability combinations is marked as completed a summary page of the identified security/vulnerability combinations and selected COI will appear for the Facility to review. Facility Operations In my blog on the Facility Operations section of the SSP I noted that there would be pull down menus with a variety of selections to pull from, but the Draft Template that I had did not provide the list of potential answers. It appears that the assumptions that I made in that discussion are born out by the SSP Questions manual (pgs 25-7) descriptions of the answers available. For example the SSP Questions provides the following responses to the question about facility type:
“Agricultural Chemicals Distribution, Agricultural Chemicals Manufacturing, Agricultural Products Processing, Chemical Distribution, Chemical Manufacturing, College/University, Food Distribution, Food Processing, Health Care, Mineral Extraction/Processing, Natural Gas Storage/Transfer, Petroleum Products Distribution, Petroleum Refining, Pharmaceutical Manufacturing, Power Generation, Propane Distribution, Research, Waste Management, Other”
The discussion in the earlier blog about the on- and off-site emergency response capability appears to have addressed that section pretty well. I have found an interesting error in the SSP Instructions in this area. Section 3.4.3 is inaccurately titled. The printed title is “Emergency Management Team [emphasis added] (EMT) Information”; the discussion makes it clear that it should refer to “Emergency Medical Technicians”. While I did note in the earlier blog that this section of the SSP Tool allows the facility to upload an Alternative Security Program (not ‘plan’ like I called it in that blog) I failed to note that there were five questions that the facility had to answer about the ASP before it can be uploaded. An affirmative answer to each of these five questions will automatically transfer the facility to the APS Upload Page. A negative response to any of the questions will require a facility to answer yes to the following question before being given access to that upload page:
“The ASP does not address all pertinent factors in 6 CFR 27. Do you wish to continue to upload an ASP in lieu of the CSAT SSP?”
The reason for this question is that if an ASP does not adequately address the requirements of 6 CFR §27.235 there is very little chance that the SSP will be approved. As I noted in my earlier blog, with the history of problems that facilities had with getting an ASP approved for Tier 4 Security Vulnerability Assessments, I would bet that very few, if any, ASP’s will be approved on the first submission. If a facility selects to upload an ASP in lieu of the SSP, then that facility will be done with their initial submission through the SSP tool one that upload is complete.

Monday, May 18, 2009

Preparing for SSP Submission

Now that the CSAT SSP tool is open and available for SSP submissions high-risk chemical facilities will need to get serious about completing their site security plans and preparing for SSP submission. Facilities cannot begin the submission process until they receive their Final Notification Letter (FNL) from DHS officially designating them a High-Risk Facility, assigning them to a Tier level, defining the chemicals of interest (COI) that must be covered in the SSP, and outlining the security/vulnerability issues that must be addressed by the Risk-Based Performance Standards (RBPS) listed in 6 CFR §27.230. The letter also provides the submission deadline that marks the end of the 120-day submission requirement. Facility CSAT Personnel Roles All facilities that receive an FNL will have already submitted two documents using the Chemical Security Assessment Tool (CSAT). The Preparer, Submitter, Reviewer and Authorizer roles from those earlier submissions will be the same for the SSP Submission. The Preparers will typically be responsible for data entry. Reviewers will be able to look at the SSP submission on-line, but will not be able make any changes to the data. The Submitter will be responsible for the final facility review and actually submitting the completed SSP to DHS. The Authorizer will have no direct role in the SSP submission beyond verifying to DHS any changes made to the Preparers or Submitter. Facilities may authorize a single person to have multiple roles with the exception of Reviewers; no one designated a Reviewer will be allowed to be a Preparer or Submitter. Typically those individuals who were assigned to Preparer, Submitter, Reviewer roles in earlier CSAT submissions will be performing the same roles during the SSP submission. This is not, however, required by DHS. Facilities may make changes to any of these roles at the start of the SSP submission process. Additionally, multiple Preparers and Reviewers may be added for each facility. Facilities must remember that anyone accessing the facility records in CSAT must have completed the on-line CVI training and is an Authorized CVI User. Multiple Preparers DHS has added provisions for facilities to use multiple Preparers, something new for the SSP Tool. They recognize that there will be a number of facilities that will be using people variety of technical skills and backgrounds for preparation of the SSP. The decision was made to allow facilities to decide to allow those subject matter experts to help prepare the SSP submission in their respective specialty areas. The SSP Instructions manual implies that multiple Preparers may be working on the SSP at the same time when it says (page 9): “When multiple preparers are updating the same SSP, changes made by one will be visible to the others as soon as those changes are saved (by clicking Save, Next or Back).” This appears to be misleading because the same document later notes that SSP must be completed sequentially. On page 11 it explains that:
“That is, when you jump back to a previous section, all preceding sections will become un-highlighted [inaccessible] and you will be required to page through all the subsequent pages of the SSP tool. This is necessary because the SSP tool adapts the pages presented for completion based on answers on previous pages and a change within one section might require you to answer additional/different questions later.”
Given that subsequent pages may affected when data is entered into an SSP page, it will be a good idea for facilities to coordinate the data entry efforts made by multiple Preparers. When changes have to be made on previously completed sections it will certainly be a good idea for Preparers to review subsequent sections that have already been completed. This will make the review job of the Submitter much easier and reduce the number of SSPs rejected by DHS. Data Preparation The Instructions manual (page 5) provides a fairly comprehensive list of resources that facilities will need to complete the SSP submission process. The DHS list includes such things as copies of the CFATS regulations, the facility Top Screen and SVA submission, a copy of the FNL, among other things. All of the things on the list will undoubtedly be valuable for the Preparers and Submitter have readily at hand during the preparation for the SSP submission. In fact, it would make things much simpler if all of this material were maintained in a lockable office set up just for CFATS administration at the facility. This would make it much easier to comply with rules for safekeeping of CVI. A number of the items on the DHS list of resources are CVI and draft documents that the facility compiles for the purpose of SSP submission will be CVI as well. A dedicated room to which only CVI authorized personnel will have access to will make the required CVI security procedures much less intrusive to the SSP preparation and submission process. One invaluable resource that is not included on the DHS list is the SSP Questions manual. This manual provides a list of the questions found on the SSP tool. With room available to record answers and write notes this manual can serve as a workbook for the off-line preparation of the SSP submission. Again, as soon as any facility information is added to this manual it becomes CVI and only CVI Authorized Users may have access to the annotated document. The manual can also be used as a management tool for assigning responsibility for collecting and developing submission data. The manual can be printed and taken apart to provide teams or responsible individuals as an assignment template. This will allow them to work on portions that they are most familiar with. This will also provide for management review and approval of the data before it is added to the on-line tool. This will also make the Submitters review easier before the SSP is actually submitted to DHS. Once again, these partial documents will become CVI as soon as facility information is added. This means that marking and security provisions will apply to these portions of the manual and only CVI Authorized Users may work with them.
 
/* Use this with templates/template-twocol.html */