Showing posts with label SVA-SSP. Show all posts
Showing posts with label SVA-SSP. Show all posts

Saturday, July 27, 2019

DHS Updates CFATS Manuals – July 2019


This week (apparently, DHS no longer provides ‘last published’ dates on their web pages) the DHS Cybersecurity and Infrastructure Security Agency (CISA) posted links to new versions of three manuals used by facilities covered under the Chemical Security Anti-Terrorism Standards (CFATS) program. The manuals are ‘dated’ June and July 2019, but there has been no notice of the new manuals provided on either the CFATS web site landing page nor on the CFATS Knowledge Center. The two remaining manuals for the Chemical Security Assessment Tool (CSAT) have not yet been updated.

The manuals affected are:

CSAT User Manual; and

DHS has long stopped putting change notices in their documents, so it is difficult to tell what changes, if any, have been made in the documents. One change is obvious in all three documents, they have been rebranded with a CISA front page; a branding that reflects more on the CISA cybersecurity mission than the chemical security mission of the CFATS program.

PSP Instructions


This manual has certainly been revised to reflect the recent implementation of the extension of the terrorist ties screening requirement to Tier III and IV facilities. You can tell this by the new ‘Note’ on page 4:

“For more information on RBPS 12(iv) and the Personnel Surety Program, see 84 FR 32768, Notice of Implementation Chemical Facility Anti-Terrorism Standards Personnel Surety Program published on July 9, 2019 or access the DHS Personnel Surety Program.”

Since there was no reference to the submitting facility’s tiering in the original manual, there was no need to make changes reflecting the expanded implementation. In a quick perusal of the two versions, I do not see any changes beyond pagination and layout changes, with one exception. The ‘addendums’ at the end of the 2018 manual have been renamed ‘Appendix A’, ‘Appendix B’ and the acronym list has been labeled ‘Appendix C’ in the new version.

CSAT User Manual


This User Manual has been substantially reformatted and ‘enhanced’. The table of contents page, for instance now provides a link to the indicated section and the sub-sections of the text are listed down to the X.Y.Z level where the previous version was limited to the X.Y level. The other major enhancement is that each graphic provides a textbox with additional details when the cursor is placed on the graphic; this will, of course, only be useful in the electronic version.

This manual is ‘dated’ June 2019, so it would presumably predate the PSP changes.

SVA/SSP Instructions


As one would expect this manual has been updated to reflect the expansion of the PSP program. A note similar to that in the PSP manual can be found on page 97 of the new manual.

Commentary


None of the changes that I have seen are significant; they would have no impact on a facility’s implementation of the CFATS program in general or the PSP program in particular. I have not, however, done a line by line review of any of the documents. In any case, security managers and those interested in the CFATS program should download these new manuals, just to ensure that they have the latest version available.

Oh, it is interesting to note that while the description of the SVA/SSP manual found on the CFATS Knowledge Center describe the previous version of these manual, the links take one to the newer version. This is unusual in that the URL’s for the document are completely different than those found on the CSAT web site. The links for the other two manuals on the Knowledge Center page still go to the older manuals.

Monday, October 17, 2016

CSAT 2.0 Update – 10-17-16

Today the DHS Infrastructure Security Compliance Division (ISCD) made changes to the Chemical Security Assessment Tool (CSAT) website in its further implementation of CSAT 2.0 that started earlier this month. Today’s changes included two new web pages and the publication of a link to the new SVA-SSP manual that was announced earlier on the Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center.

SVA-SSP Pages


While the initial phases of the CSAT 2.0 rollout focused on the new Top Screen, ISCD has also made significant changes to the security vulnerability assessment (SVA) process and site security plan (SSP). Since a large portion of the earlier SVA process has been shifted to the new Top Screen the SVA has been reduced in scope and essentially combined with the SSP submission.

The CSAT web page now contains links to two new pages; one for the new SVA-SSP tool, one outlining changes to the SVA and SSP portion of that tool. The first provides a brief description of the new SVA-SSP tool and provides the official link to the new manual (through the typical DHS web site transition page). The second page provides a little more detail about new questions in the SVA portion of the tool and the more extensive changes in the SSP portion of the tool.

SVA-SSP Implementation


Facilities that complete the new Top Screen will end up in one of three general categories. The first (and largest) will be the facilities that will be notified that they are not considered to be at high-risk of terrorist attack and thus not covered by the CFATS program; they will not have to worry about the SVA-SSP. The second (probably the smallest group) will not have been covered by the CFATS program on October 1st, but will now (because of new information and/or the new risk assessment process) be notified that they are required to submit an SVA-SSP within 120 days. The largest group will be facilities currently under the CFATS program (and most likely with a submitted, authorized, or approved SSP). Those facilities will have to make a facility by facility determination of whether or not they will have to revise their current SSP.

The middle group of facilities will continue to have the existing options for submission of Alternative Security Plans (ASP) or Expedited Approval Plans (EAP). Facilities notified of Tier IV ranking will be able to complete an ASP in lieu of the SVA and SSP. Facilities ranked I Tiers I thru IV may submit either an ASP or EAP in lieu of the SSP. These facilities will be given 120 days from the date of their notification letters to submit the new SVA-SSP.

Existing CFATS facilities that receive new notification letters confirming that they remain in tiered status will be told which chemicals of interest (COI) and security measures they are being tiered for. If the facilities existing SSP (submitted, authorized or approved) does not adequately cover the listed chemicals or security measures, the facility will have to submit a revision to their SSP.

In CSAT 1.0 there was an SSP revision tool and manual. There is not currently such a manual printed for CSAT 2.0. At least initially it looks like SSP revisions will be submitted using the new SVA-SSP tool. The SVA-SSP revision page notes that:

“For facilities that have previously submitted the SVA and SSP, the majority of their previously submitted information will be pre-populated into the new survey. Although CSAT 2.0 drastically reduces the number of overall questions, the tool includes some new questions and sections, which are outlined below to help facilities that fall into categories 1 and 2 above revise their surveys in an effective and efficient manner.”

New Cyber Questions


There are many new questions and I will be addressing some of them in future blog posts. Today I will briefly mention the new cybersecurity related questions for the SVA and SSP identified on the SSP Revisions page.

For the SVA portion of the tool, the new page notes that there are new questions for: “Identifying cybersecurity measures and vulnerabilities in cybersecurity”. That would be question #2.50.040. The response (pg 7) provides for a 4,000-character description of the “cybersecurity measures and any identified vulnerabilities found while doing this analysis.”

The SSP portion of the tool will retain the cybersecurity questions found in the previous SSP. Four new questions have been added; two questions addressing whether or not there are control systems and/or business systems that directly affect the security of listed COI. There is a follow-up question for each identifying the specific covered cyber systems at the facility.

For control systems question Q3.40.400 specifically notes that:

“Defining cyber control systems for your facility should be limited to those systems that have the ability to control the process and could result in a release or contamination of COI.”

For business systems question Q3.40.420 specifically notes that:

“Cyber business systems include those systems that manage ordering, shipping, receiving, and inventory of chemicals of interest and those systems that are connected to or manage physical security systems, control systems, and other critical systems.”
 
/* Use this with templates/template-twocol.html */