Showing posts with label Security Settings. Show all posts
Showing posts with label Security Settings. Show all posts

Friday, June 30, 2017

ISCD Updates CSAT Site Access FAQ

Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated one of the responses to a frequently asked question (FAQ) on their Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center. The FAQ was #81:


In addition to adding the “2.0” in the question to reflect the new and improved CSAT tool two additions were made to the FAQ response:

• Added a clickable link to the CSAT 2.0 web site; and
• Added instructions for setting the TLS 1.0 security setting when using Chrome®.

This FAQ was previously changed in February when the Firefox TLS setting instructions were added.

BTW: I just noticed that the February changes to the Knowledge Center that I previously mentioned included removing at least three long standing FAQs (dated August 8th, 2008) and their responses. Those FAQs were:

• FAQ #42 Is DHS seeking to pre-empt State chemical security regulations with the new Federal regulations?
• FAQ #54 What role did private industry play in developing this rule?
• FAQ #55 Will there be fees involved for the chemical companies?

These FAQs were probably superfluous, but they provided some interesting insights into the early development of the CFATS program. I find it interesting that the response to FAQ #55 indicated that DHS had considered a number of fees to be associated with the program and kept the door open for their possible future application.


Monday, August 20, 2012

CSAT Security Settings to Change


There is an interesting article over on PCWorld.com about a pending change in the NIST standards for federal web site security protocols. The current standard is the use of Transport Layer Security (TLS 1.0). NIST is expected to change that to TLS 1.1 and/or 1.2. Now most Federal web sites do not require security settings as they are one-way information providers. Sites providing secure communications (like the CSAT tool) will be affected by this change.

We can be fairly sure that the folks at ISCD will make an announcement when this change is applied to their CSAT sites. In the meantime it makes sense to verify that the computers that you used to communicate with CSAT are all capable of using TLS 1.1 or 1.2. Check the “Security Settings” under the “Advanced” tab on the Internet Options on Internet Explorer (I’m sorry I don’t know the technique for other browsers; I continue my love-hate relationship with MS).

More when this actually comes to pass.
 
/* Use this with templates/template-twocol.html */