Showing posts with label SSP. Show all posts
Showing posts with label SSP. Show all posts

Sunday, October 15, 2017

ISCD Updates CSAT 2.0 Web Site

Last week the DHS Infrastructure Security Compliance Division (ISCD) updated their Chemical Security Assessment Tool (CSAT) web page; this is part of the extensive web site for the Chemical Facility Anti-Terrorism Standards (CFATS) program. The only change to the CSAT page was the addition of a link to the new CFATS Site Security Plan (SSP) Submission Tips web page.

This new web page is part of the on-going ISCD outreach program to the CFATS regulated community. It is not a substitute for the SSP manual and the Risk Based Performance Standards (RBPS) Guidance manual, but rather a highlight of those types of things that have apparently been found lacking in many SSP submissions in the past. It highlights four major areas of concern:

• Consider what security measures to address;
• Detail current security measures;
• Describe planned security measures; and
• Specify facility-wide or asset-specific security measures

 What Security Measures


Of course, facilities are going to need to address security measures in each of the 18 RBPS that are applicable to the DHS chemicals of interest (COI) identified on the facility tiering letter. This section of the web page addresses five “overarching objectives” of the SSP:

• Detection;
• Delay;
• Response;
• Cyber; and
• Security Management

These are covered in short (one paragraph) discussions and links to the four RBPS fact sheets that ISCD began issuing earlier this year:

RBPS 8, Cyber Fact Sheet  
RBPS 9, Emergency Response Fact Sheet  
RBPS 12, Personnel Surety Program Fact Sheet  
RBPS 18, Records Fact Sheet 

Current Security Measures


This section briefly covers two rather broad topics:

• Be as detailed as possible; and
• Don’t overlook safety and environmental measures already in place that contribute to security.

In my conversations with folks in the field the first point is probably the most important for a successful SSP submission. This new web page says it well and succinctly:

“The text boxes in the Chemical Security Assessment Tool’s (CSAT) (/chemical-security-assessment-tool) SSP application have been included so that facilities can more fully describe current security measures, including how the measures address the relevant RBPS. The better DHS can conceptualize and understand your approach to security measures, the better DHS can evaluate whether they meet the applicable RBPSs.”

Facility-Wide vs Asset-Specific


The discussion here is important, though more than a little simplified (to be expected in a short document like this). It boils down to this. Security measures can be quite expensive, especially as the size of a facility increases. Since different types of COI may require different types of security measures, a facility may be able to significantly reduce costs by confining certain security measures to just those areas where their listed COI are stored or handled. Provisions are made in the CFATS to allow facilities to do this.

Commentary


Again, ISCD has consistently tried to reach out to the CFATS community and provide the necessary information to successfully comply with the program requirements. This is part of that outreach. It is not (nor was it intended to be) the ultimate word in developing a successful SSP submission. It is just part of the process.

Facility security personnel will find this helpful only if they are familiar with the RBPS Guidance document and the SSP manual. Another source of useful information in this matter are two of the recently published presentations from the 2017 Chemical Sector Security Summit:


In fact, the CSSS web site has links to additional presentations from previous years that will also be helpful. The whole CSSS program is helpful for anyone interested in chemical facility security issues.


One final point, cybersecurity continues to pop up regularly in any discussions about the CFATS program. ISCD is certainly taking great pains to mention the topic whenever they discuss site security plans or compliance inspections. They have taken particular care to ensure that they try to communicate that ‘cybersecurity’ is not only important for the control systems that touch on the handling and/or storage of covered COI, but also includes cybersecurity measures to protect security controls (surveillance, intrusion detection, and access control systems) as well as business systems that affect the handling (ordering, selling or transporting), or storage of covered COI.

Wednesday, July 20, 2016

DHS Publishes CSAT 2.0 Notice

Today the DHS Infrastructure Security Compliance Division (ISCD) published a notice in the Federal Register (81 FR 47001-47004) outlining the plan for the implementation of their new risk assessment protocol and the revisions to the Chemical Security Assessment Tool that are being called CSAT 2.0. This includes the temporary suspension of requirements to submit Top Screens (TS) and Security Vulnerability Assessments (SVA) effective today.

Three-Step Process


Today’s notice outlines a three-step process that ISCD will be undertaking to implement the new risk assessment protocol and CSAT 2.0. Those steps are:

Temporarily suspend, effective July 20, 2016, the requirement for CFATS chemical facilities of interest to submit a Top-Screen and SVA;
Replace the current CSAT Top-Screen, SVA, and SSP applications with CSAT 2.0 (i.e., the revised CSAT Top-Screen, SVA, and SSP applications) in September 2016; and
Reinstate the Top-Screen and SVA submission requirements in 6 CFR 27.210(a) on October 1, 2016.

The Top Screen and SVA submission suspension affects all chemical facilities that may be required to submit either initial or resubmission Top Screens and SVAs.

Presumably the implementation of CSAT 2.0 will include the publication of new CSAT manuals during the month of September.

Facilities Not Affected


The notice makes clear that four specific classes of facilities will not be affected by the changes included in the implementation of CSAT 2.0. They include:

Agricultural production facilities and miscellaneous extensions;
• Chemical facilities of interest with reportable COI that are only present in a gasoline mixture;
• Statutorily excluded facilities; and
• Untiered facilities that previously notified the department they had no reportable COI.

TS Submission Notifications


Once CSAT 2.0 is up and running ISCD will begin notifying ‘chemical facilities of interest’ of their need to submit a Top Screen. The notice makes it clear that the term ‘chemical facilities of interest’ was used deliberately instead of ‘covered facilities’ because it includes facilities that may have already submitted a Top Screen that indicated that they possessed DHS chemicals of interest (COI) inventories at or above the Screening Threshold Quantity (STQ).

The notification letters will be sent out in a phased manner over a number of months, presumably in a manner reflecting ISCD’s potential risk assessment of the previous information provided. There is no specific language in the notice that would indicate that all facilities that have provided Top Screens to ISCD will be notified to re-submit Top Screens at this time.

Facilities that do not have current COI inventories at or above the STQ will not be required to submit Top Screens to ISCD, even if they are notified by letter to submit a Top Screen. Those facilities may either submit a zero COI Top Screen or otherwise notify ISCD that they have no COI at or above the STQ and will not be submitting a Top Screen.

The notice does state that currently covered facilities that believe that the new risk assessment methodology will result in a lower tiering may submit a Top Screen before being notified by ISCD to do so. This certainly implies that ISCD will be sharing more information about the new risk assessment methodology and that tracks with what I have heard from ISCD privately. I do not expect that they will be sharing their actual model publicly, but they will be sharing more information about how the risk assessment methodology works.

Existing SVAs and SSPs


The notices makes it clear that only completed and submitted SVAs and Site Security Plans (SSPs) will be retained in CSAT 2.0. Partially completed SVAs and SSPs will be lost when CSAT 2.0 is implemented. This is of particular importance to remember this because ISCD will continue to accept new or revised SSP/ASP up until the date of the CSAT 2.0 switch over.

New SVA/SSP Timetable


For the most part, since ISCD expects to make a tiering decision based upon the new Top Screen, there will be no need to delay the SSP submission until after the receipt of the SVA. This notice, therefore, the new SVA and SSP tools in CSAT 2.0 have been designed to have facilities submit both documents concurrently. While more details are expected when the new manuals are published in September, it would seem that there will be more direct sharing of information between the two tools that should make the submission of both documents easier.

This means that ISCD is changing the submission deadline for the SVA from the current 90 days in §27.210(a)(2) to 120 days. It is interesting to note that the current regulation specifically allows ISCD to change that deadline with a Federal Register notice rather than requiring a rulemaking. The notice also makes it clear that the same notification of high-risk and tiering that now initiates the SVA submission requirement also is being used to initiate the SSP requirement. That certainly means that ISCD will be modifying the current notification letters.

Since the SVA and SSP tools will be so closely linked, facilities that revise their SSP will now also be required to revise their SVA at the same time.

Regular Top Screen Submissions


The notice indicates that regular Top Screen submissions for facilities reporting new inventories of COI at or above the STQ will resume on October 1st, 2016. Facilities that acquire such inventories between now and then will have 60-days from October 1st to submit their Top Screen.

CSSS Update



I am sure that there will be more information available at today’s session at the Chemical Sector Security Summit presentation on “Infrastructure Security Compliance Division (ISCD) Regulatory Update”. That session will be web cast at 10:00 am EDT.

Monday, May 2, 2016

ISCD Publishes CFATS Update – May 2016

Today the DHS Infrastructure Security Compliance Division (ISCD) published their May 2016 CFATS Fact Sheet. This document provides a monthly update of the implementation of the site security plan (SSP) program in the Chemical Facility Anti-Terrorism Standards (CFATS). ISCD continues to increase the number of authorized and approved SSPs as well as a significant increase in the number of compliance inspections.


March 2016
April 2016
May 2016
Covered Facilities
3,074
3,029
3,018
Authorized SSPs
3,324
3,336
3,356
Approved SSPs
2,449
2,462
2,525
Compliance Inspections
624
726
854

We continue to see the same problems with these numbers that we have seen every month for quite some time now. We continue to see a decline in the number of covered facilities without any explanation of why the facilities are leaving the program. The number of authorized SSPs continues to increase well beyond the number of facilities that remain in the program. Finally, we continue to see a report of the number of compliance inspections conducted without any indication of the rate at which those facilities are found within compliance with their negotiated SSP requirements.


The number of approved SSPs has now reached 75% of the number of covered facilities, if there is not the same counting problem that affects the number of authorized SSPs. It would be nice, however, if additional details were included, additional numbers that could have been provided would have been the number of facilities that were approved based upon their submission of an Expedited Approval Program SSP. With the recent implementation of the Terrorist Screening Database screening portion of the Personnel Surety Program a report on the number of approved SSPs that include the TSDB vetting.

While I am glad to see that ISCD is continuing to voluntarily report these CFATS Updates, it looks like it is really just a PR ploy since there are so many problems with the data being provided. If ISCD really wants this to mean anything, they need to consider updating what they are reporting.


Thursday, March 3, 2016

ISCD Publishes March 2016 CFATS Update

This morning the folks at the DHS Infrastructure Security Compliance Division (ISCD) published their latest update information about compliance activities surrounding the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS) site security plan program. The numbers show continued improvement in the number of facilities that have approved site security plans (SSPs) and a continued increase in the number of compliance inspections the Chemical Security Inspectors (CSI) have done.


January
2016
February 2016
March 2016
Covered Facilities
3,088
3,083
3,074
Authorized SSPs
3,285
3,305
3,324
Approved SSPs
2,354
2,391
2,449
Compliance Inspections
450
532
624

ISCD is continuing to report more facilities with authorized SSPs than there are currently facilities in the program. ISCD has yet to explain whether they are continuing to report authorized SSPs for facilities that are no longer in the program or if they are just reporting multiple versions of the SSPs for the facilities that remain in the program. In either case, it makes it impossible to tell how many more SSPs that ISCD has to authorize or approve.

The March numbers (actually for activities in February) show an increased rate in approvals and compliance inspections. If the rate for this last month continues, ISCD should complete the SSP approval process early next year; unless, of course, they are having the same number with counting approved SSPs that they are with authorized SSPs.

The pickup in the rate of compliance inspections is important, especially since the same folks that are doing the authorization visits and approval inspections are doing the compliance inspections. As we see fewer of the non-compliance inspections being done in the future, we should see a further increase in the rate of compliance inspections.

As the number of compliance inspections increases it is going to become more important for ISCD to correct the lack of reporting on actual compliance results. More important than just the numbers of facilities here is some indication at how well the industry is doing in complying with their negotiated SSP performance standards. Last year the GAO reported a poor pass rate on the early compliance inspections and a lack of enforcement action. It would certainly be interesting to see if that has changed.


BTW: The link on the Chemical Security landing page for this CFATS update takes you to a link for last month’s update, not the March update. I have reported the direct link to the March 2016 update.

Monday, December 28, 2015

How The Multiple Options in PSP Can Work Together

This is part of a continuing series of blog posts about the recently released Federal Register notice about the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety program (PSP). The notice outlines how the Infrastructure Security Compliance Division (ISCD) is planning to implement the vetting of covered chemical facility personnel and visitors against the FBI’s Terrorist Screening Database (TSDB) to determine if any covered personnel are suspected of having ties to terrorist organizations. Other posts in this series include:


The Four Options

ISCD’s new PSP program provides facilities with four specific options on how the facility will implement the requirements of 6 CFR 27.230(a)(12)(iv). Those four option (described in detail in the notice) can be briefly summarized this way:

Option 1 – Facility submits data and ISCD has TSA conduct screening;
Option 2 – Facility submits data on personnel with previous screening and ISCD has TSA confirm that screening is current;
Option 3 – Facility uses TWIC Reader to verify identity and screening status of Transportation Workers Identification Credential (TWIC) holder; and
Option 4 – Facility visually inspects TSDB based identity document to verify that person had been screened against TSDB.

The facility can use any of the four options or combinations of them to satisfy the terrorist ties vetting requirements of the CFATS program. In practice it looks like most facilities will be using some combination of the four options in their site security plan (SSP). As I mentioned in the previous post, adding the facility’s terrorist screening program to the SSP will be the first step in achieving compliance with the new portion of the PSP.

Option 4 – Visual Verification

I am going to start this more detailed review with what ISCD describes as the option providing the lowest amount of security, Option 4. This option provides for using visual screening of existing TSDB based identification credentials. This would include the TWIC, the Hazardous Material Endorsement to a CDL and various traveler based vetting programs. The notice provides a more detailed discussion of the problems associated with this option, but does note that it has a legitimate (and Congressionally mandated) place in the vetting program.

Actually, this option is pretty well suited to the vetting of commercial truck drivers making deliveries to the facility or picking up shipments from the facility. There is a fairly high likelihood that over-the-road drivers will already possess a TWIC or HME. MTSA covered facilities already have established the requirement that drivers coming to their facilities must possess a TWIC or the load will be refused or not allowed to be picked-up. CFATS facilities implementing Option 4 will have to notify their vendors and transportation companies of the need for TWIC or HME for all drivers entering the facility.

Facilities can increase the security of this option by requiring that vendors and trucking companies provide advance notice of the name and ID number of drivers coming to the facility.

There is a downside to this option for the trucking industry. There is already something of a shortage of long-haul truck drivers. Further limiting those be requiring a HME or TWIC (which both have criminal background check requirements) is going to further aggravate the driver shortage.

When using this option ISCD is almost certainly going to require the facility to spell out in its site security plan how facility personnel are going to be trained to visually verify the validity of the document (recognize and detect counterfeit documents) and verify the identity of the document holder. Requiring advance notice (perhaps with copy of ID) will help with that training requirement.

Option 3 – TWIC Reader

The TWIC was designed to be verified (both the document and personal identity) with a TWIC Reader. Unfortunately the Coast Guard and TSA have had problems with the TWIC reader implementation process and there is still not an approved rule for the implementation of TWIC Readers in the MTSA program. The TSA reports that it has published a list of approved TWIC Readers, but I have not been able to find such a list in an internet search, typical for all things related to TSA.

There are a couple of problems currently associated with the use of a TWIC Reader. First, and foremost, they are relatively expensive. Second they must at least periodically be connected to the Internet (or a phone line?) to update the list of expired/revoked TWICs. Finally, individuals must apply for (and pay the application fee for) the TWIC which requires a trip to one of the limited number of TWIC issuing facilities.

The TWIC Reader does not need to be used at facility entrances to be effectively used as part of the PSP. The facility could require TWIC holders to periodically (that period to be established in the SSP) present themselves to a designated office (possibly an off-site 3rd party office) where the TWIC and identity could be verified.

This option would be valuable for facilities that have a high percentage of personnel that already have a TWIC. This would also be valuable for corporations that also have MTSA covered facilities and have personnel that move between facilities. Contractors doing periodic maintenance or facility turnarounds that also serve MTSA covered facilities will have very high TWIC densities and would probably want to use this option.

The notice provides a limited amount of guidance on what ISCD would expect to see in the facility SSP for implementing the TWIC Reader option. It also outlines the security downside to the use of the TWIC, is a TWIC holder is subsequently identified as having possible terrorist ties there is nothing that will trigger an investigation of that person at the covered facility or allow for notification of the facility until the next time the periodic check is made.

Option 2 – Data Submission on Previously Vetted Personnel

This has long been the most controversial of the vetting options proposed by ISCD. Industry has always assumed that previously vetted (via TSDB) individuals would not require data submission to DHS. ISCD has always maintained that such data submission is required to ensure that periodic vetting is accomplished and that the facility can be notified if a previously vetted individual is subsequently added to the TSDB.

ISCD also likes this option because it reduces their costs of submitting data to TSA for vetting against the TSDB. They do not have to ‘pay’ for a full initial TSDB scan, they just have to verify that the previous vetting was done. Ironically, this also means that the facility will have to provide more data for this option because they need to provide data on the previous screening program (program name, ID number, and expiration date).

Facilities using this option are going to have to include a description of the training program that they use to train the personnel that are visually verifying the legitimacy of the presented document and the identity of the person submitting the document. Not specifically mentioned in the notice, but almost certainly to be required in the SSP, is a discussion of what will be done when the existing document expires.

Facilities that have a relatively high population of personnel that have been vetted by another agency against the TSDB are going to have to weigh the higher security benefits of Option 2 against the simpler process for Option 4. ISCD would much prefer to see Option 2 used, but was required by Congress to provide option 4. I suspect that this might mean that Option 2 might not receive as close a level of scrutiny in the SSP review as would Option 4.

Option 1 – Data Submission and Screening

There is no doubt that this is the method that ISCD would prefer to see all facilities implement as it provides the best ability for the Department to conduct vetting of covered personnel and tie the resulting information back to individual facilities. I suspect that this will be translated into a very wide latitude in how the Department views SSP submissions implementing this option.

ISCD will allow data submissions from either the corporate level or the facility level (or both) and will have some system set up for mass data submissions, probably via spread sheets. Third party data submissions will also be allowed so that companies can use personnel management agencies or background check agencies to do the actual data submissions. The use of the agency that the facility is already using to do the other background and identity verification checks currently required in the PSP will obviate the need for detailed information in the SSP about the training of the personnel collecting and verifying the data being submitted to ISCD.

A Blended Program

All but the smallest facilities are probably going to find that they are going to use all four options in their SSP. Explaining how each option would be used in the implementation of the new terrorist ties vetting program will provide the facility with the widest latitude in how they start and maintain the program over the coming years. Even if the facility does not intend to initially adopt one or more of the options, putting them all in the SSP will make it easier to start using an option as situations change (no subsequent change to the SSP will be required).

Facilities are going to have to take a close look at the employees, contractors and visitors before they decide how they are going to implement the terrorist ties vetting in their personnel surety program. They are going to have to balance the security needs of the facility to prevent access by people with suspected terrorist ties with the complexity of the program that will be used to identify those people.


ISCD has committed to working closely with each Tier 1 and Tier 2 facility while they design and implement this final phase of the PSP. That means that there will be a risk-based staggering of the initial SSP update requirement. The time to start working on this, however, is now, not when ISCD provides the facility with notification of the date by which the revised SSP will have to be provided to Department.

Monday, August 3, 2015

ISCD Publishes August CFATS Fact Sheet for August 2015

This afternoon the DHS Infrastructure Security Compliance Division (ISCD) published the August 2015 Chemical Facility Anti-Terrorism Standards (CFATS) Fact Sheet. There was little change in the number of authorized Site Security Plans (SSPs) and an even smaller change in the number of covered facilities. We do see a significant continued improvement in the number of facilities with approved SSPs.

The table below provides a comparison of the numbers in the July 2015 and August 2015 Fact Sheets.


August 2015
July 2015
Covered Facilities
3,223
3,229
Authorized SSPs
3,139
3,121
Approved SSPs
2,021
1,935
CFATS Fact Sheet Data

It is too early to see any significant change in the Approved SSP numbers due to the Expedited Approval Program. Facilities were able to start submitting EAP SSPs about half-way through the month, but the folks at ISCD still have to review and approve those submissions. The Department has up to 100 days to complete that review. I suspect that we could start to see some of those approval affecting the September 2015 Fact Sheet numbers.

ISCD is still not reporting the number of compliance inspections conducted or the results of those inspections. According to a recent GAO report (pg 28), as of February of this year there had been 69 compliance inspections completed with only 35 of those facilities having passed the inspection. The GAO reported that ISCD was working with the non-compliant facilities instead of taking any of the authorized enforcement activities available to the Department.


NOTE: There had been a minor coordination issue earlier in the day with the publication of the Fact Sheet. The Critical Infrastructure: Chemical Security web page change which provided the link to the new fact sheet was published before the link became active so the page was for a short time pointing at the July 2015 Fact Sheet.

Friday, July 10, 2015

EAF SSP Submissions

The post below has incorrect information - for the correct process for submitting EAP submissions see my post at - http://chemical-facility-security-news.blogspot.com/2015/07/eap-submission-process-simplified.html  Posted 07-22-15 4:30 CDT.
 

Readers of this blog have seen me comment on the upcoming submission of expedited approval facility (EAF) site security plans (SSP) for the DHS Chemical Facility Anti-Terrorism Standards program for a couple of months now. All along I have been predicting that the Infrastructure Security Compliance Division (ISCD) would probably be establishing a new Chemical Security Assessment Tool (CSAT) tool for the on-line submission of the EAF SSP. Well, it appears that I was wrong.

I learned today that EAF facilities (starting July 16th) will be able to start submitting their EAF SSP vis the current SSP Tool. The procedure that will be used will be very similar to that used for the submission of Alternative Security Plans (ASP).

Preparation

The first thing that the facility Submitter is going to need to do is to print a hard-copy of the CSAT SSP Questions Manual. Put pages 3 thru 49 in a binder and place a CVI Cover Sheet on the front and rear of the binder. Mark each of the pages from the manual with the following:

“WARNING: This record constitutes Chemical-terrorism Vulnerability Information controlled under 6 C.F.R. § 27.400. Do not disclose to persons without a “need to know” in accordance with 6 C.F.R. § 27.400(e). Unauthorized release may result in civil penalties or other action. In any administrative or judicial proceeding, this information shall be treated as classified information in accordance with 6 C.F.R. §§ 27.400(h) and (i).”

Now fill in all of the blanks that apply to your facility. Many of these will already be filled in (pre-populated) when you get to the on-line tool, but having all of the information in one place will make things much easier when you start completing the SSP.

Next you will want to get the DHS Guidance for the Expedited Approval Program. You can either print out the blank pages 60-61 and 64 thru 91, or fill them out on your computer and then print them out. The hard copy of page 61 will have to be signed by the facility owner. They would then be scanned as a single document so that an electronic copy can be uploaded to CSAT. I would then recommend that the hard copies be put into the same binder as the SSP Questions Manual pages. Fortunately you don’t have to worry about the CVI marking of these pages, ISCD has already done that.

Finally you are going to need an electronic copy of a facility site map or diagram, the more detailed the better and electronic copies of photographs of the facility, preferably at least one overhead shot and one of each COI storage area. Since they are going to be submitted as part of your SSP they should be electronically marked as described above.

Submission

The rest is time consuming, more than a little tedious, but rather simple. Sign on to CSAT go to the SSP tool and start filling out the responses to the questions using the binder prepared above. If there is a sever discrepancy between the binder data and any data that is prepopulated in the SSP (and it appears that the on-line data is incorrect), contact the CFAT Help Desk {(866) 323-2957} before proceeding.

Once you complete answering the questions on page 49 from the SSP Questions Manual the next screen should be the ASP Questions. Or it may possibly be a new page for similar EAF program questions (I haven’t actually seen these pages now). In any case, there will be a small number of questions about the data that you are going to submit. Answer those questions and upload the EAF document and photographs. There will be a couple of ‘are you sure you want to submit this now’ questions and then you are done.

When to Submit

If your facility had received its final tiering notice before June 16th and your facility had notified ISCD on June 16th that you intended to submit an EAF SSP, then you can start submitting your EAF SSP on July 16th (next Thursday). If you notified ISCD after the 16th you have 30 days from the date of that notification.


If you had received your final tiering notification before June 16th you have until November 13th to complete your EAF SSP submission. Your EAF notification letter from ISCD will confirm the date you can begin submission and the date by which that submission must be completed.

Thursday, June 18, 2015

DHS Updates CFATS Knowledge Center – 06-18-15

This morning the DHS Infrastructure Security Compliance Division (ISCD) updated the CFATS Knowledge Center web page by adding a news item about the new Expedited Approval Program (EAP) and providing a link to a fact sheet about the program.

The fact sheet does not provide any new information not already presented on the EAP web page. In fact, in at least one area, there is not as much information provided. The web site notes that the Chemical Security Assessment Tool (CSAT) may be used to provide the 30-day notice to ISCD that a facility intends to submit an EAP site security plan (SSP) as well as providing a mailing address to make that notification. The EAP fact sheet contains no mention of how the facility should go about making the notification.

I can still find nothing on the CSAT web site, or the SSP web site that provides any information about the EAP. Since the 30-day notice process officially started yesterday, ISCD still has 30-days to get the EAP SSP form into the system, but I had expected to see provisions on the CSAT page for submitting the 30-day notice.


Sunday, June 14, 2015

CFATS Update

Here we are half-way through the month of June and the folks at the DHS Infrastructure Security Compliance Division (ISCD) have not yet published their monthly update for the CFATS site security plan (SSP) implementation. Since April of 2013 they have been publishing this monthly compilation of the number of facilities which have had their SSP authorized and approved. If it is published on Monday it will be the latest the update was published since the congressional funding fiasco of 2013.

Is something wrong at ISCD? Probably not. What we are probably seeing is a move to the next phase of the CFATS program implementation. After all, June 16th will mark a milestone in the CFATS program, effectively being the date that the program will make a substantial change in the way the program is authorized and implemented.

Brief CFATS History

The Chemical Facility Anti-Terrorism Standards (CFATS) was the last major anti-terrorism program that can be directly traced back to the attacks in September 2001. In 2006 Congress was finally able to put serious disagreement about how a chemical security plan would be run behind themselves long enough to establish an interim program to get some sort chemical security effort underway while the nearly theological battle in Congress proceeded.

The chemical security program was authorized in a single, short section in the FY 2007 DHS spending bill (§550, PL 109-295). It provided minimal guidance to DHS on how to establish the program and provided some significant limitations as to what DHS could require chemical facilities to do as part of the program.

DHS got off to a fast start standing up the CFATS program. In less than six months they wrote a new set of regulations establishing an innovative new regulatory program that utilized state of the art on-line data collection tools. In the next couple of years they looked at the initial reporting data from over 40,000 chemical facilities that had significant amounts of 300+ DHS chemicals of interest (COI) on hand and determined that just over 4000 of those facilities met the regulatory standard of being ‘at high risk of terrorist attack’.

Those covered facilities completed security vulnerability assessments, again submitting the data to ISCD via the on-line Chemical Security Assessment Tool (CSAT). DHS took the information provided and threat ranked the facilities into four risk tiers. ISCD developed a guidance document for how those facilities should implement the risk-based performance standards required by Congress, and then there was a major hiccup; the program stalled.

For a number of reasons, including some management issues that have not yet been fully reported to the public, the program stopped advancing. Work was being done by the ISCD staff, Chemical Security Inspectors were visiting facilities. Facilities were submitting SSPs, but effectively no site security plans were being approved by ISCD.

In early 2013 the new management team at ISCD finally started making some headway and the authorization and approval of site security plans began in earnest. The program was starting to get back on track. In April of 2007 they started reporting that progress with their monthly updates of status of the CFATS site security plan implementation.

The Fight in Congress

In the meantime Congress continued their in-fighting about how a chemical facility security program should proceed. On one hand, the Democrats (supported by labor and environmental activists) wanted to use the security program to severely limit the chemicals and processes that the industry could use. They argued that if dangerous chemicals and processes could be reduced or eliminated then the facilities would no longer be potential terrorist targets. The Republicans (supported by facility owners) countered that only the engineers and business owners could determine what chemicals and processes would be commercially viable. They argued that DHS did not have the manpower or expertise to make judgements about inherently safer technology.

The importance of this philosophical difference declined as Congress realized that the interim program that they had turned loose on the country was stalled. Their concern about the slow pace of SSP implementation finally overcame the philosophical discussion and Congress finally passed a stand-alone chemical facility security bill last December; HR 4007 was signed by the President on December 18th, 2014.

Moving Forward

The one change from HR 4007 that will most affect the site security plan implementation is the establishment of an expedited approval process for Tier 3 and Tier 4 facilities. These are the lowest risk facilities covered by the CFATS program and the last ones that DHS has started working on for the SSP implementation process. The bill gave ISCD until June 16th, 2015 to publish the guidance for this program and to establish the reporting process that the new program would use to process SSP’s for those facilities that opted to use the EAP program.

The EAP guidance document was published last month. This week we should see a new tool established in the CSAT that will allow facilities to report to ISCD their intention to use the EAP program to develop and submit their SSP. Thirty days after that intention is reported to ISCD those facilities will be able to start submitting their EAP SSPs. This will either require the modification of the current SSP tool in CSAT or the publication of a new tool. I suspect that ISCD will go with the new tool using the general format of the checklist provided in the EAP guidance document.

CFATS Updates?

ISCD is going to allow all Tier 3 and Tier 4 facilities the option to use the EAP process. Even those that already have authorized or approved site security plans. This means that the statistics that ISCD has been reporting in their monthly updates will no longer mean much from the perspective of tracking SSP implementation. Starting on Tuesday some number of currently authorized or approved SSPs will be invalidated as facilities make the decision that their SSP could be simplified or made cheaper by joining the EAP process. So tracking those numbers, at least in the short term, probably does not make much sense.

This is going to be further complicated by the fact that current CFATS facilities (as of December 18th, 2014) have until November 13th, 2015 to complete the EAP process. This means that they would have until October 14th, 2015 to notify ISCD of their intent to complete the EAP process. So, during the period of June 16th to October 14th watching the simple change in numbers of facilities with authorized or approved SSPs is going to be very confusing.

And I can’t let this topic go without at least mentioning the reporting of compliance inspection results. ISCD has been working on compliance inspections now for a little over two years. Well, they are supposed to have been anyway since compliance inspections were supposed to start one year after the SSP was approved at the facility level. Unfortunately, ISCD has not been publicly reporting any statistics on their compliance inspections.

I would assume (I know; a very dangerous word) that there have not yet been any compliance inspections at Tier 3 or Tier 4 facilities (priority was legitimately given to Tier 1 then Tier 2 facilities), but we should start to see some Tier 3 facilities become eligible for such inspections in the near future. Since those facilities have the option to opt out of their current SSPs by selecting the EAP process, future changes in compliance inspection numbers may also be misleading, at least through October 14th.

So, are we going to see a CFATS update this week or not. I don’t really know, I haven’t asked anyone at ISCD. I know that they are busy with the HR 4007 implementation process as well as the on-going SSP authorization, approval and inspection process. I don’t think that checking on a reporting system that they voluntarily started as essentially a PR exercise is really worth bothering them about.


If I had to bet, however, I would say probably not. If I were in Director Wulf’s shoes, I wouldn’t report on any data until I was called to testify about the implementation of the HR 4007 requirements later this year.

Thursday, May 14, 2015

EAP Guidance – SSP Status

This is part of a continuing series of blog posts on the newly released Expedited Approval Program (EAP) guidance document for Tier 3 and Tier 4 facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program. Other posts in the series are:


I have noted in a couple of these blog posts that it has been unclear how a Tier 3 or Tier 4 facility’s SSP status affects their ability to file an SSP under the EAP process. Obviously newly tiered facilities that have not yet submitted an SSP may choose this option. The question really applies to those facilities that have already started the SSP process; either having submitted an SSP or ASP via CSAT, have hand their SSP or ASP authorized by DHS, or even have had their SSP or ASP approved by DHS.

For informational purposes, here is the latest information available for the SSP status of Tier 3 and Tier 4 facilities


SSP Authorized
SSP Approved
Tier 3
93%
70%
Tier 4
87%
51%

I have been told that any Tier 3 or Tier 4 facility, regardless of the status of their SSP are eligible. Specifically I was told that even facilities with an approved SSP can use the EAP process. It is not yet clear how this will all be done; we will have to wait and see what new Chemical Security Assessment Tool (CSAT) applications are provided for the EAP process. It looks like we will see the first one on June 16th; that will be the tool for notification to DHS that a facility intends to apply for an EAP SSP.

What this does mean is that every Tier 3 and Tier 4 CFATS facility owes it to themselves to closely review the EAP guidance and determine if it makes sense to change their current SSP (at whatever stage in the process) to an EAP SSP.


One other thing to take into consideration is that it appears that ISCD is intending to prioritize the compliance inspections of EAP facilities. This makes a great deal of sense since no one in ISCD is actively involved in reviewing the details of the EAP SSP the way that they are during the standard SSP process. In effect, the compliance inspection will be the first time that ISCD has a chance to see how the EAP SSP is implemented at that particular facility.

Monday, April 6, 2015

ISCD Publishes Latest CFATS Update – 4-2-15

Today the DHS Infrastructure Security Compliance Division published the latest monthly update on the CFATS site security plan implementation. Instead of announcing the CFATS Update on the Critical Infrastructure: Chemical Security web page they directly published the link on the CFATS Knowledge Center. I am assuming that they will get around to updating the information on the Chemical Security page.

ISCD continued with the format that they have been using for the last year. The numbers of authorized and approved facility site security plans continues to improve. In fact, if the authorization pace continues at the current pace all of the currently submitted site security will be finished by this Fall.




The number of covered facilities continues to decline at about the same pace as it has for the last year. Looking at the graph below it looks like there was a significant policy change in the CFATS program in January 2014. That is where there was a noticeable increase in the rate of facilities dropping out of the program. There is still no publicly available explanation of what is driving the decline in the number of covered facilities.



It will be interesting to see what happens in June when ISCD is supposed to publish their expedited approval facility (EAF) program for Tier 3 and Tier 4 facilities. There will be very few (probably less than 300) facilities that do not have an authorized site security plan at that point, so most of the planning and submission work will already be done. Will the remaining facilities (the ones that are not newly added or promoted Tier 1 and Tier 2 facilities) simply opt for the EAF certification process (and may be required to change their SSPs to fit those requirements) or will they decide to continue with the current process? A large part of that will depend on what the program actually looks like.

NOTE: There has been an interesting change made at the bottom of nearly every page in the chemical security web site (and perhaps other parts of DHS as well, but not TSA). They have added a Question and two radio buttons for site users to respond. The question is “Was this page helpful?” A ‘yes’ response will get a simple ‘thank you’ response. A ‘no’ will bring up another comment (This page was not helpful because the content:) four new responses:

∙ Has too little information 
∙ Has too much information 
∙ Is confusing 
∙ Is out-of-date


The response to the second question also brings a ‘thank you’ response. DHS is apparently not using cookies to track the responses because the same question is there the next time you visit the page. Once again the folks at ISCD are demonstrating that their heart is in the right place. It will be interesting to see if there are any positive results from the feedback.

Wednesday, March 4, 2015

ISCD Updates CFATS Fact Sheet – 03-04-15

This afternoon the folks at DHS Infrastructure Security Compliance Division (ISCD) published an updated copy of the CFATS Fact Sheet. The Fact Sheet shows the current status of the Site Security Plans in the program. It continues to show an increasing number of facilities with authorized and approved site security plans.



Just as consistently it shows a decreasing number of facilities that are covered by the Chemical Facility Anti-Terrorism Standards (CFATS) program. There are a number of legitimate reasons that a facility could be removed from the program, but ISCD continues its policy of not explicating the reasons for the 700+ facilities that have been removed from the program in the last year.


The third leg of the SSP compliance program, the compliance inspection results, also continues to be ignored in the CFATS Fact Sheet. The compliance inspection program determines if the facility is actually living up to its obligations outlined in the authorized and approve site security plan. This is the only real measure of whether or not a facility is secured against potential terrorist attack.

Tuesday, November 4, 2014

DHS Publishes CFATS Update for October

Today the DHS Infrastructure Security Compliance Division (ISCD) published their CFATS Update for the month of October. As we have been seeing for the last year or so there is a steady increase in the number of CFATS facilities that have an authorized or approved Site Security Plan (SSP).

October’s rate is slower than August and September but that almost certainly reflects the variability of the facilities that are having their programs evaluated. Each facility has a unique security situation and plan that must be evaluated on its own merits; some facilities take more time than others to properly evaluate.






An interesting note this month; we have stopped the steady decline in the number of facilities covered by the CFATS program that we have been seeing since November. We actually had 7 more facilities on November 1st than we did on October 1st. Still no information about what is driving the changes in numbers. This month we can positively say that there were more new facilities added than dropped off, but still no indication of how many actually dropped off or why.


ISCD is still not telling us anything about the number of facilities that have undergone compliance inspections or how many have passed or failed those inspections. That will be the next item of Congressional interest.

Sunday, January 26, 2014

CFATS Document Support

I’m hearing interesting rumblings from those in the CFATS field that as more and more small chemical facilities are getting visited by DHS Chemical Security Inspectors (CSI, oh that hurts; maybe CBS should sue for copyright infringement) a new ‘security issue’ is being found with increasing regularity. While these facilities appear to be doing a yeoman’s job at actually securing the chemicals on site, they are having problems documenting their security procedures.

The Problem

As DHS moves into the site security plan authorization and approval process in the Tier 3 and Tier 4 facilities, they are encountering a large number of small facilities, frequently with less than 10 employees on site and no corporate EHS&S support. The Security Manager at these types of facilities is frequently the same person that handles all of the other regulatory compliance issues for the facility along with another full time job related to chemical production or distribution.

This routinely means that while security measures might be employed, there is little time for preparing all of the documentation that goes into supporting a real security plan. There are dozens of written procedures and processes that the CSI need to be able to see when they arrive on site to verify that the facility understands its security program and is properly implementing all of the necessary support requirements that are part and parcel of the physical security investments that have been made.

For example, there might be a bright new 10 foot security fence with razor wire topper and an automated gate that opens only to employee ID cards, but there needs to be a document that describes the processes that support that fence. That barrier plan document would include a description of:

• Who/what the fence was designed to keep out;
• How the fence is kept under observation to ensure that no one cuts or climbs over it;
• How often the fence is inspected for physical integrity;
• Who is responsible for ensuring that defects are repaired;
• What is done while a defect is awaiting repair to compensate for the deficiency;
• How the employee ID cards are issued and controlled;
• Etc.

Each and every security measure that a facility employs needs this sort of documentation that can be shown to a visiting inspector (along with supporting records that show that required periodic actions are being taken). Without that documentation, the DHS cannot really tell if a facility is really properly secured.

CSAT Tool Lacking

It looks like the original intent of the developers of the Chemical Security Assessment Tool (CSAT) was to provide an on-line data entry tool that would allow much of this type of documentation to be bypassed, making the job of security managers much less complicated. Unfortunately, by the time DHS got around to implementing the Site Security Plan (SSP) portion of the tool it became painfully obvious that there was not enough time, money or support available to prepare an SSP tool that could do more than ask some general questions about a very complicated series of security topics.

I understand that suggestions have been made that DHS Infrastructure Security Compliance Division (ISCD, the folks that run the CFATS program) provide an on-line series of templates for the various supporting plans and documents that may be needed by a facility to support their SSP. For some fairly obvious reasons, that has not been done.

First off, ISCD is already stretched pretty thin doing what it is already required to do; authorize, approve and inspect 3000+ site security plans. We can argue whether or not they should have developed such templates as part of the original SSP tool development process, but that is water under the bridge and the current management team was not in charge of that process. At this point in time they don’t have the time, money or personnel to accomplish that type of template development.

I am hearing rumors that a variety of facilities that have already been authorized and approved have offered to allow some of the documents that they have produced to be used as templates (after filing off the appropriate nameplates and serial numbers, of course). This is quite heartening and a positive sign of how well the industry accepts their general responsibility for chemical security in general.

Unfortunately, the §550 bugaboo once again rears its ugly head; “the Secretary may not disapprove a site security plan submitted under this section based on the presence or absence of a particular security measure”. ISCD has, from its very inception taken this congressional restriction very seriously (too seriously in my opinion, but then again, I don’t have to go back to Congress every year of reauthorization either). One just has to look at the repeated weasel wording in the Risk-Based Performance Standards guidance document to see how seriously the Department takes this requirement.

There is no way that ISCD is going to provide templates for SSP support documents for fear of running afoul of this restriction. Additionally, the Department lawyers would vociferously argue against providing such templates for fear having to defend ISCD against legal complaints when facilities that used such templates were found wanting in their SSP plan implementation. Templates would have to be generally enough written that a lot would still depend on how the various blanks were filled in. Besides, chemical facilities covered under CFATS are so diverse that it is unlikely that a single template, no matter how generally written, would cover all situations.

Industry Support

It looks like Congress, reading the full language of the §550 authorization, actually thought that there would be a viable solution to this issue. We can see this in the language related to alternative security plans (ASP). They thought that the various areas of the chemical industry would come up with generic security programs tailored to the specific requirements and security issues facing that industry segment.

Unfortunately, to date only one ASP has been developed that is in wide spread use and that is the one that was introduced just over a year ago by the American Chemistry Council (ACC). The ACC’s ASP is much closer to being an actual site security plan template than is the SSP tool in CSAT. It is still, however, falls short of the actual policies and procedure documents that need to be in place at all CFATS covered facilities. And there is a good reason for this; the ASP document once submitted and authorized/approved by DHS cannot be changed without approval of DHS.

Policies and procedures supporting the ASP need to be living documents that can be changed and modified to fit changing circumstances. As long as those changes don’t materially modify the processes approved by DHS there should be no need to burden the ISCD folks with a change approval request. So the data submitted to the DHS in the ASP needs to cover much of the same information as would found in the policy and procedure documents, but not in quite so much detail. (NOTE: Finding the acceptable limits of that detail is what is taking so much time in the SSP authorization and approval process.)

In any case, it would be helpful if the various chemical industry support groups would help the smaller companies in their organizations by developing template documents for many of the security policies and procedures that facilities would have to have in place to support their SSP.

ASP Approvals

While I am on the topic of ASPs, I heard a very interesting comment from the field the other day about why DHS is not pushing the ACC ASP. Now Director Wulf has made an official statement in support of the use of the ACC ASP, but there is nothing on the DHS CFATS web sites specifically mentioning the ACC ASP, and there is certainly no link to the ASP on the DHS sites. Some are questioning this lack of support.

The comment I heard this week is that the reason for this lack of support is that the cost of the design and maintenance of the current CSAT tool would be hard to justify if there were wide spread adoption of the ACC ASP. While I would not be surprised to hear that there were individuals associated with the CSAT development that might have their feeling hurt to hear that their SSP tool was less than adequate (AND IT CERTAINLY IS THAT), I do not think that is why the current management team at ISCD has not made their support for the ACC ASP more widely known.

First off, any federal bureaucrat has to be very careful about how they endorse a commercial product. While the ACC ASP is certainly free-of-charge for use the ACC and its affiliated companies are commercial enterprises, so Director Wulf has to be careful in that respect. Also, as other ASPs hopefully come into use failure to publicly recognize and support those with the same alacrity that they supported the ACC ASP could lead them into political problems, so a measured approval is probably politically prudent.


There should be, however, a link on the SSP homepage to any and all ASPs that have been approved by DHS. If there is only one such link because only one such program has been approved by ISCD, then so be it. This should serve as an incentive for other organizations to develop their own industry specific templates.
 
/* Use this with templates/template-twocol.html */