Showing posts with label Site Security Plan. Show all posts
Showing posts with label Site Security Plan. Show all posts

Thursday, January 3, 2013

Reader Comment – 1-2-13 – ACC Comments on ASP


Bill Erny, the Senior Director for Regulatory and Technical Affairs at the American Chemistry Council, left an interesting comment on my first blog post (BTW: there should be at least one more posting in that series, probably this weekend) about the establishment of the Alternative Security Program (ASP) developed by that organization. While all reader comments are appreciated, it is particularly nice to have input from people directly involved in the development of important programs like this one (HINT: Is anyone in ISCD willing to comment?).

Time Savings


Bill did take exception to my comment:

“One thing is very clear to me, it is going to take much more work to complete the ACC ASP than it would be to answer the questions in the DHS SSP.”

He responded:

“However, your observation that the ASP would take more work to complete is not actually the case. In fact, the opposite was reported by several owner/operators who were involved in the pilot testing and said that the ASP saves significant time over the SSP. This is true mainly due to the amount of duplication that is eliminated in the ASP versus the SSP.”

This would certainly be true if the facility in question was already providing the level of detail really required for the proper analysis of the Site Security Plan submission. Since most facilities are not giving ISCD enough information I, think I’ll stand by my comment. But please don’t misunderstand me; this is almost certainly a good thing. A little extra time ensuring that facility submits the required information will save time in the long run as ISCD will not have to conduct Pre-Authorization Inspections with all of the follow-up delays that that has been causing.

More Useful Information


Bill makes another interesting point that should be obvious in retrospect:

“The DHS field inspectors who participated in the pilots also reported that the ACC ASP offers a significant improvement over the SSP for use during auditing.”

The data format in the current SSP data submission tool (I really do hate that DHS calls this a site security plan) is designed to be used by a computer, not people. Printing out a copy of the SSP submission has got to be one of the greatest wastes of trees in the federal bureaucracy. The ACC ASP, on the other hand should read and feel like an actual security plan for the facility. It should be a document that people at the facility should actually be able to use in the management of the plan and it will be a very helpful document for anyone that wants to audit the program.

Tuesday, July 19, 2011

Fixing the Site Security Plan – Changing Questions

In a blog post this weekend on CFATS spending, I may have mentioned in passing that ISCD is having problems with their SSP approval process. In fact, I may have mentioned the same thing in a couple of other posts as well (okay, I apologize for the sarcasm, kind of anyway). It’s always easy to criticize, so I thought that I’d try to take the high-road and suggest how that problem might be addressed in a relatively easy manner.

Background Information

But first, I’d like to suggest that my readers go to ChemicalProcessing.com and download their latest CFATS publication (actually ADT’s latest publication on their site) “CFATS: Surviving the Site Security Plan”. It provides a brief description of the current SSP situation and their recommendation for how facilities can help to overcome the problems. In particular everyone should read the short “Painting a Picture” section on page 3. To save you some time, I’ll share the first paragraph here:

“Rather than simply answering 'Yes' for a question, answer 'Other' and take the opportunity to give an expanded written answer. The information in the 'Other' boxes should describe, in detail, the facility’s security posture, including physical security as well as specific procedures and policies. Take credit for measures already in place, even if those measures do not fit perfectly within the scope of the question, and use the 'Other' box to provide sufficient detail.”
Now this is not really new information, Last December DHS published a new CFATS pamphlet, “Helpful Tips for Completing a Chemical Facility Anti-Terrorism Standards (CFATS) Site Security Plan”. It included the following as the introduction to its first tip; “Appropriate Level of Detail”:

“An SSP must include sufficient detail to allow DHS to exercise its responsibility to determine whether the SSP satisfies the CFATS risk-based performance standards (RBPS). To date, many of the SSPs submitted have provided simple Yes or No answers (or similarly brief, non-descriptive responses) to many questions in the CSAT SSP application. Such answers typically do not provide enough information for DHS to make an informed judgment on whether the facility’s security measures satisfy the applicable RBPS.”
All of this makes perfect sense if one realizes that the people making the decisions about the approval or disapproval of the SSP will probably never see the facility. The information that they need to determine whether or not the facility security measures will adequately address the Risk-Based Performance Standards (RBPS) will have to come completely from the SSP submission.

One final point that must be kept in mind is that Congress has specifically prohibited DHS from requiring specific security measures as a basis for the approval of a site security plan. This means that a simple checklist will never provide enough data to allow for an adequate evaluation.

Revise SSP Questions

All of that is good to know but DHS turns right around and does its best to insure that during the SSP submission process, they ask for less information than they need. If you look at the latest version of the SSP Question Manual published last month you’ll see what I mean.

For example turn to RBPS 1 – Restrict Area Perimeter and look at page 65. You’ll see two questions about perimeter fences. The first question asks for a description of the fence and provides selection buttons (‘Yes’, ‘Partial’, and ‘No’) for a list of common fence types. The second question addresses the Fence Top Guard installed on that fence. For both questions one of the available selections is ‘Other’. There is also a text box to provide additional information.

Unfortunately, the instructions for that box continues to read: “If ‘Other’ is selected, enter a description:”. A more reasonable instruction, given the need for the facility to ‘paint a picture’ of the fence, would be: “Enter a description of the ‘Fence Barrier’:”.

I would suggest that even that would not really insure that ISCD receives all of the information that they need to evaluate that ‘Fence Barrier’. With ‘Partial’ coverage an expected response about a particular type fence, there should also be a prompt to explain that partial coverage. Additionally, there should be a prompt to provide a basic idea what information a description of the ‘Fence Barrier’ should include.

Here is how I would write the instruction for the Fence Barrier text box.

“Describe each type of fence barrier selected. Include information on materials of construction, footings, and physical size and configuration of fence. Explain the extent of any partial coverage.”
Additionally, since everyone knows that a picture is worth a thousand words, I would add a specific provision here for uploading pictures of the Fence Barrier. Digital photography is so ubiquitous that there is no reason why one would not want to include photographs in the SSP submission. Some photos would be better than others, but a really bad photo could just be ignored by the evaluators.

There is an alternative way of looking at the information requirements for questions like this. DHS could just add an additional layer of questions. For example, if a facility selected the ‘Yes’ button for ‘Chain Link’ the following additional questions could pop up that would require a short text entry answer:

• How tall is the fence?

• How far apart are the support poles?

• How are the support poles anchored to the ground?

• Is there a top bar along the top of the fabric?

• Is there a bottom bar along the bottom of the fabric?

• Are there privacy slats in the fence fabric?
The problem with this type of questioning is that there is always just one more question that could elicit just that one last piece of additional information. For example privacy slats can go in one direction or two and bi-directional slats make it more difficult to climb or cut the fence. They can be made of metal, plastic or wood. And on and on and on.

I think that for most of the questions in the SSP submission it will be more than adequate to change the wording of the current ‘Other’ text boxes to solicit descriptive information for the pertinent questions. Adding provisions for photo submissions would also be a good general move. There may, however be places where there will need to be additional questions added to ensure that ISCD personnel have adequate information to conduct their evaluations.

Writing Site Security Plans

I want to take this opportunity to point out to facility security managers something that I have said on many occasions. The current DHS SSP submission is misnamed. It is not a ‘Site Security Plan’. It is just a really extensive series of questions about how the facility manages its site security.

A real ‘Site Security Plan’ would be a document that describes in even greater detail the actual structure and organization of the security of the facility. It would include the types of descriptive detail I mentioned above, but it would also assign responsibility for various parts of the plan and describe how temporary problems with the plan would be dealt with.

For example the part of the plan dealing with the perimeter barrier would:

• Describe how the barrier fits into the security program;

• Describe the actual barrier;

• Describe who is responsible for inspecting the barrier;

• Describe who is responsible for repairing the barrier;

• Describe what compensating measures will be used while the barrier repair is being scheduled and completed; and

• Describe the procedures for making changes to the barrier.
If a facility had such a detailed Site Security Plan, they could use that document to provide the information required to complete the ‘new’ text boxes that I am proposing that DHS include in their SSP submission questions.

Friday, March 12, 2010

Tips for Completing SSP

ADT Security has been a frequent source of information about CFATS implementation. Their latest offering, a white paper offering Ten Tips for Completing a Site Security Plan, can be downloaded from ChemicalProcessing.com. Unlike many white papers from chemical industry vendors, this document has almost no self-promotion. In fact, the only advertising in this document is the ADT logo on each page and a brief explanation of the services they provide on the last page.

The well written text provides details on their following ten tips:

1. Develop Your Plan Before You Begin the SSP 2. Know What Your Tier Level Means 3. Understand the Ramifications of “Release” Security Issues and “Theft & Diversion” Security Issues 4. Include All of Your Critical Assets in Your Plan 5. Apply the Concepts of Control, Deter, Detect & Delay 6. Record Your Answers & Rationale 7. Consider Using Industry Standards & Best Practices 8. Generate a List of Security Procedures 9. Generate a List of Responsible Personnel 10. Seek Help with Your Plan
There is good information on each tip, but I particularly like their 5th Tip. ADT takes the Deter, Detect and Delay information provided by DHS in the Risk Based Performance Guidance Document and adds an important new concept, Control. They describe ‘control’ this way:
“This is the ability of a facility to manage its activities and assets. Control requires that a facility have policies, procedures and technologies in place that establish rights, authorities and responsibilities and to provide monitoring and feedback. Control applies to nearly every aspect of security, from designating who has access and what they have access to, to determining how access is granted and monitoring how that access is used. Control applies to information as well as access to physical space and assets. Control also requires that a facility maintain a reporting and management structure that supports the allocation of authority and responsibility.”
I have no idea how good a job ADT does with actually helping chemical facilities with the development and implementation of site security plans, but I have been very impressed with the information provided in their webinars and now this white paper. I certainly recommend that any facility working on their Site Security Plan should download and read this free whitepaper.

Tuesday, July 14, 2009

SSP Submission – RBPS #6 Theft and Diversion

This is another in a series of blog posting on the recently released Site Security Plan Instructions Manual and Questions Manual. The other blogs in this series are: Preparing for SSP Submission SSP Submission – Facility Data SSP Submission – Facility Security Measures SSP Submission – RBPS #1 Restrict Area Perimeter SSP Submission – RBPS #2 Secure Site Assets SSP Submission – RBPS #3 Screen and Monitor SSP Submission – RBPS #4 Deter Detect and Delay SSP Submission – RBPS #5 Shipping Receiving and Storage This posting looks at RBPS #6, Theft and Diversion. This section of the SSP looks at equipment, processes and procedures that help to reduce the risk of theft or unauthorized diversion of ‘dangerous chemicals’ including Theft COI. The Guidance document provides the same definition for ‘dangerous chemicals’ in this RBPS as was used for ‘hazardous chemicals’ in RBPS #5. There is no reason given for the use of two different terms for the same chemicals. This section of the SSP provides similar questions for both facility wide security measures and asset specific security measures. As we noted in the other sections of the SSP with similar provisions, a security measure is not reported in the asset specific questions if the security measure applies to (and was reported as) facility wide security, unless there are separate systems for the specific asset or there are substantial differences in operations of the measure at the specific asset. More Duplicate Questions This section has an even larger number of previously asked questions than we have seen in the earlier RBPS sections. Part of this may just be because there are more questions to draw from. Once again, there are no instructions in either the Questions manual or the Instructions manual about how the system deals with repeat questions. I suspect that in many cases the answers will pre-populate forward. There are two odd duplicate questions that have been significantly reworded from their earlier incarnations. I guess that means that they aren’t truly duplicates. I certainly have no idea why these two questions were picked for rewriting and reissuing. Both questions require ‘Yes’/‘No’ check-offs. The questions are:
"Does the facility have controls and procedures that restrict access to storage of potentially dangerous chemicals (including Theft COI), allowing access only to authorized individuals? "Are transportation access portals controlled and is access limited to authorized individuals?"
Unknown Carrier or Driver Questions There is a duplicate question that leads off a section of questions about procedures for how the facility will deal with an unknown carrier or driver showing up to deliver or pick-up a load. Each of the questions requires a ‘Yes’/‘No’ response. At first glance these seem to be standard questions, but there are two questions that are very similar in the way they are worded. They deal with procedures that the facility has for where truck/driver will be held while they are waiting until they are “properly vetted and approved”. One question uses the term ‘staging’ and the other uses ‘sequestering’. While there are no explanations for the differences I would assume that ‘staging’ means a holding location outside of the security perimeter while staging means an area within the security perimeter. The final question in this section is oddly worded which makes it difficult to determine how to answer the question. It reads:
Procedure for… “Notifying and contacting local law enforcement depending on the identity of the driver and identity of the load.”
Presumably DHS is asking about a procedure for dealing with a driver/load that cannot be identified or vetted. This would mean that there is a serious suspicion that the driver is up to no good. Unless the facility security team has arrest authority (which would be unusual unless they are off-duty law enforcement personnel) the local law enforcement would have to be contacted to affect an arrest. Training Questions This is the first time that we have seen questions related to training in the SSP. It seems more than a little unusual since there is a complete RBPS (RPBS #11) dedicated to this subject. Additionally there appears to be a minor misprint in the Questions manual. The manual shows a list of training frequency questions followed by a typical question that would lead such a list of question. That question is:
“Does the facility require individuals granted unescorted accesses to the facility to attend security awareness training at the facility?”
Usually, such a qualifying question, if answered ‘No’ would remove the frequency questions from the SSP tool for that facility. Finding this question at the end of the section kind of defeats that purpose. These security awareness training questions ask how often the described training is conducted with responses of: monthly, quarterly, semi-annually, annually, biennially, triennially, never. All but the last question in the group asks about ‘recognizing and detecting’ a variety of threats, ranging from ‘explosive materials’ to ‘characteristics and behavioral patterns of persons who are likely to threaten security’. The last question in the section is the ‘odd man out’. Instead of ‘recognizing and detecting’ it asks about “general techniques used to circumvent security measures?” While it is slightly different from the other questions in the group it does provide some recognition of the fact that potential adversaries will be attempting to subvert or by-pass facility security procedures. Background Investigation Questions There is another set of questions that seems to be slightly out of place in the RBPS. They deal with background investigation; an area that will certainly be dealt with in more detail in RBPS #12, Personnel Surety. This final section in RBPS #6 has three questions requiring a ‘Yes’/‘No’ response. Adequacy of Procedures As noted about there are a number of questions in this RBPS section that ask if the facility has a procedure to deal with ‘X’. The answers to such question are invariably ‘Yes’/‘No’, but anyone that has ever worked with regulatory agencies knows that there may be along way between having a procedure and having an ‘acceptable’ procedure. At this point DHS in the CFATS process DHS is not asking to see a copy of the procedure mentioned in the question; it is simply asking if the facility has a procedure. When the first inspector shows up after the SSP is approved to verify that the facility is actually implementing the approved SSP, the inspector will want to see copies of each of the procedures asked about in the SSP questions. Whether the facility has separate procedures for each of the security areas identified or one massive procedure is probably of little consequence. DHS is not going to have the manpower or time available to review each of the procedures in detail. With the wide variety of types and sizes of facilities covered by the CFATS regulations each of these procedures will be unique and it would be way too time consuming to do an in depth review either at the facility or back at the ‘office’. What I would not be surprised to see is DHS developing at some time in the future would be ‘procedure’ tools under CFATS to help them do a more detailed evaluation of procedures. They would be the same type answer the questions and fill in the blank type tools that have become so familiar to CSAT users.

Wednesday, July 8, 2009

SSP Submission – RBPS #5 Shipping Receiving and Storage

This is another in a series of blog posting on the recently released Site Security Plan Instructions Manual and Questions Manual. The other blogs in this series are: Preparing for SSP Submission SSP Submission – Facility Data SSP Submission – Facility Security Measures SSP Submission – RBPS #1 Restrict Area Perimeter SSP Submission – RBPS #2 Secure Site Assets SSP Submission – RBPS #3 Screen and Monitor SSP Submission – RBPS #4 Deter Detect and Delay This section of the SSP looks at security measures, processes and procedures that specifically control shipping, receiving and storage to help facilities to “minimize the risk of theft or diversion of any of its hazardous materials” and “helps to prevent tampering or sabotage” (pg 59 RBPS Guidance document). This section applies to both facility wide security measures and measures that apply only to specific assets. After the questions about whether the facility has facility wide and asset specific security measures for RBPS #5 there are two additional generic questions that apply to facility wide measures. Each question has a potential ‘Yes’, ‘No’ and ‘Other’ responses. The ‘Other’ response makes no sense as a response to these questions. The two questions are:
“Does the facility have a ‘Know Your Customer’ program? “Does the facility have a Product Stewardship program?”
Documentation Questions The next series of questions deals with the documentation of sales and purchases of hazardous materials. These questions specifically ask about all hazardous materials (per 49 U.S.C. §§ 5101, et seq.) with the parenthetical inclusion of the phrase ‘including COI’. This ties in with the discussion in RBPS Guidance Manual that explains that DHS considers that RBPS #5 applies to all hazardous materials not just the COI listed in the notification letter. DHS does not make answering these questions very easy. When asking for a ‘quantity’ they provide three possible responses in check-off boxes. Those responses are: “All”, “Most” and “None”. The explanations for these terms are not provided, so we should be able to take them at face value. Unfortunately this leaves a potential response gap between ‘most’ (‘All’> ‘most’ > ‘half’) and ‘none’; there really should be a ‘some’ response available if DHS is not going to provide for a numerical response. I would guess that DHS wants anything less than ‘most’ to be answered ‘none’. One of the documentation questions does not refer to ‘hazardous chemicals’ or ‘COI’. It asks about shipments of ‘feed materials’ or ‘products’. The distinction is fairly clear in the wording so this must refer to all incoming raw materials (not just chemicals) and all outgoing products. In a chemical manufacturing environment this would be important because the contamination of any of the raw materials with the ‘proper’ contaminant could result in a catastrophic incident. There is an ‘odd’ pair of questions at the end of this first section. This question addresses the use of ‘numbered photo identification badges’. This is another one of those questions that has been asked earlier in the SSP; in this case in RPBS #3. Transportation Security Questions There are a number of areas within this RBPS that address transportation security. The first such area has a number of questions about the carriers that are used by the facility for outbound shipments. An interesting thing about these questions is that they don’t mention ‘hazardous materials’ or ‘COI’ or ‘covered materials’; this implies that the questions apply to all shipments made from the facility. The final series of Yes/No questions regarding transportation security deal with a variety of policies and procedures to provide transportation security for hazardous materials. They include such things as performance checklists, team drivers for long trips, procedures for vetting drivers, and redundant communications protocols. Security Measure Questions There are a couple of separate areas within this RBPS section that deal with security measures employed. The first of these areas deals with man-portable containers of ‘hazardous materials’. Nothing in the Questions manual or the RBPS Guidance document provides a definition of ‘man-portable containers’. Certainly 5-gal containers would fit that description; 30-gal containers can be man-handled relatively easily; and with a hand-truck even 55-gal drums can be moved by a single person easily. The questions about man-portable containers start with a qualifying question asking about ‘what number of hazardous materials in man-portable containers’ are provided with additional security measures. The wording of the question is odd (are we noticing a trend?); it doesn’t ask about the number of containers, but about the number of hazardous materials (again ‘including COI’). Again the answer is not a number, but the same ‘All’, ‘Most’, and ‘None’ that we have encountered in this section before. If the answer ‘None’ is selected, the Prepare will see none of the other questions in this area. There is a series of questions relating to the security techniques used to monitor hazardous materials on site. These questions briefly address such techniques as video monitoring, intrusion detections, physical security techniques. The potential answers to these questions are ‘Yes’, ‘Partial’, and ‘No’. No provisions are made for explaining ‘Partial’ responses. The final series of questions dealing with security measures ask about tamper resistance devices. These Yes/No response questions deal with the use of numbered seals on container closures, tamper resistant locks, and other techniques that would provide evidence of unauthorized access to hazardous materials. Inventory Control Questions There are a number of inventory control questions. One series of questions addresses procedures that the facility has put into place to implement a ‘know your customer’ program. Another series deals with the storage area used for hazardous chemicals and the processes used to monitor those storage areas. All of the questions in these areas are answered by selecting ‘Yes’ or ‘No’. There are a couple of ‘odd’ questions in these inventory control questions. First the facility Preparer is asked if the facility “has a written policy limiting the on-site inventory of specifically identified hazardous materials (including COI) below threshold quantities”. This question might make some sense if there was a follow-up question to ask which hazardous materials are ‘specifically identified’. Another question asks if the inventory control system provides links to the Material Safety Data Sheet (MSDS). While this is briefly mentioned in the RBPS Guidance document (pg 61), there is no explanation how such a linkage would contribute to the security of the hazardous material. An MSDS provides information about chemical safety, not chemical security.

Monday, June 29, 2009

SSP Submission – RBPS #4 Deter Detect and Delay

This is another in a series of blog posting on the recently released Site Security Plan Instructions Manual and Questions Manual. The other blogs in this series are: Preparing for SSP Submission SSP Submission – Facility Data SSP Submission – Facility Security Measures SSP Submission – RBPS #1 Restrict Area Perimeter SSP Submission – RBPS #2 Secure Site Assets SSP Submission – RBPS #3 Screen and Monitor This section of the SSP looks at security measures, processes and procedures that specifically serve to deter, detect and delay potential terrorist attacks on the facility. This section only applies to facility wide security measures. It does not include provisions for answering questions about securing individual critical site assets. Previously Provided Information Many of the questions will look like they have already been answered in previous sections of the submission. It is not clear from the manuals provided by DHS if the previous responses will cause the information to be ‘pre-populated’ into these new questions. If the information does not get automatically carried forward into this section, facility Submitters are going to have to carefully review duplicative questions to make sure that consistent answers are provided. It is interesting that the questions on anti-vehicle barriers on the facility perimeter in this section were not found in support of the RBPS #1 section, but were seen earlier in the RBPS #2 section dealing with security measures for site assets. Similarly, the questions about security lighting were found in RBPS #2 but not RBPS #1. Neither sets of answers will ‘carry forward’ to this RBPS since they were directed at asset security not perimeter security. Answers from RBPS #2 questions (or any other question about asset specific security measures) should not be ‘transferred’ to questions for this RBPS. Anti-Vehicle Measures Preparers can find definitions and descriptions of the vehicle barriers in Appendix C of the Guidance document. The ‘K rating’ system is also briefly explained there. K rating data should be available from the barrier installer, though facilities should probably check with manufacturers to ensure that the installer is trained and certified in the proper techniques for installing the barriers. Many manufacturers will be able to recommend independent inspectors that will verify the installation was done in a professional manner. Proper installation is critical for insuring that the barriers meet their ‘rated’ K values. CCTV Measures Most of the CCTV questions found in this section were found in both RBPS #1 and #2. The answers from the RBPS #1 questions should be the same as the answers for these questions. This is where one might expect that a well designed system would pre-populate the answers with those provided in an earlier section. There should be no intention on the part of DHS to ‘catch’ facilities in inconsistencies. There are a couple of new questions in this RBPS section that probably should have been included in the list of questions for both RBPS #1 and #2. Two completely new questions (requiring a yes/no response) are (pg 139):
Is the surveillance system integrated with the access control system? Is the surveillance system integrated with the intrusion detection system?
These are interesting and potentially important questions. I am more than a little surprised that there are no follow-up questions regarding the details of the integration. The other ‘new’ question is more of a follow-up question to one asked in the RBPS #1 section. The earlier question (pg 74) asked about the monitoring frequency. This question asks about monitoring responsibility. The provided answers (including the obligatory ‘other’) are
System monitoring and control by dedicated control room operator. System monitoring an ancillary responsibility of control room operator. System monitoring and control by dedicated security force member. System monitoring an ancillary responsibility of security force member.
Since these questions are going to be used by DHS to evaluate the effectiveness of CCTV system (if present, of course) in detecting an attack in progress, facilities should be careful to use the ‘other’ response on this question to address any aids that the facility might use to help those monitoring detect a penetration. Automated surveillance systems should certainly be listed here. Security Forces This RBPS Section of the SSP includes a mix of new and repeated questions about the security forces. The question about security patrols is a duplicate from RBPS #1 (pg 76) and RBPS #2 (pg 104). As mentioned previously the answers from RBPS #1 should be duplicated here while straight copying of RBPS #2 may not be appropriate. The new questions here have to deal with the details of where the security forces are housed; what the Questions Manual calls ‘security structures’. First a question is asked about ‘stationary posts’. One has to assume that this question applies to stationary posts for security personnel from the listing of posts provided, but an unmanned personnel entrance that uses some sort of access control system could qualify for a ‘main personnel entrance’. I question the inclusion of ‘special posts’ along with the standard entry for ‘other’ since there is no requirement to explain what a constitutes a ‘special post’ while a response of ‘other’ requires that the facility provides a description of that type of post. There are three questions specifically about ‘security structures’; presumably this means buildings used to house one of the previously identified ‘stationary posts’. It seems redundant to ask if a facility has ‘security structures’ after asking about ‘security posts’. The next question deals with physical structure and protections associated with these security structures. This question only makes sense if it were asked for each of the structures identified in the stationary posts question since the provided answers may only pertain to one of the posts. The same could be said about the question dealing with ‘controls’ available within the security structure. While some facilities might have duplications of all security controls at all security posts, this is probably not a good idea for most facilities, particularly when it control of an isolated post might allow an attacker to control cameras and intrusion detection systems to avoid detection. There is one question that follows the security structures questions that deals with ‘process controls’ available at the facility. The question asks what ‘process controls’ are available at the facility and provides the following answers:
Both security and operational functions Security functions Operational functions Neither Security nor operational functionality Other
There is no explanation provide in the Questions Manual or Instructions Manual about what types of ‘process controls’ are being covered in this question; not even explaining if they are asking about cyber controls or manual control systems. This is especially confusing since there are no follow-up questions about locations of the controls for those systems or protections offered to such systems. Adversary Delay There are a series of questions about internal access controls and barriers used to delay potential adversaries from reaching critical assets within the facility. These questions seem to duplicate those found in RBPS #2. What should be clear here is that these are still facility wide measures and not measures dedicated to individual critical assets. Facilities that did not define critical assets in RBPS #2 should certainly include any internal controls in their response to this question. It is harder to determine what DHS is looking for if the facility did identify and report security measures for critical assets within the facility. If there are internal security measures that were not reported for individual assets, they should certainly be reported here. If security measures reported in RBPS #2 serve other critical areas within the facility they should probably be reported here. Finally, security measures unique to specific critical assets that have been reported for those assets in other areas of this SSP should probably not be reported here. Key Control There are a number of questions about the ‘key control’ procedures that the facility uses. Actually, this classic physical security process has been expanded beyond the old style key and combination control procedures. With the expansion of the use of credentials that allow access through automated access control systems, this key control section includes control of those credentials. All but one of the questions included in this section are straight forward that require little or no explanation. The one odd ‘question’ is the one that states:
Select "Yes" for all the key inventory/controls the facility has:
The available answers makes it clear the question is actually about who administers the key control process. While there is a ‘company’ and a ‘security department’ response there should probably have been a ‘facility’ response as well for those facilities that have a facility control procedure that does not managed by a security department. Security Forces The final section in this RBPS concerns the use of security forces. This is one area of the SSP that is going to be the most controversial because of the references to armed security personnel. From comments received during the draft RBPS Guidance review it is clear that many facilities are adamantly opposed to the use of armed security personnel. From the questions found in this section there is no real clue about how DHS will address this issue in their approval of the SSP. The section starts out with the typical ‘does the facility have’ question. A no answer in this case bypasses about half of the questions in the section. What is surprising is that questions about off-site armed response (presumably including police force response) are bypassed by a no response to this question. I hope that there is a disconnect between the Questions Manual and the actual SSP in this case. The question of off-site response is especially critical for facilities that have no on-site security forces. This is not the only organizational anomaly found in this section. In the section that all facilities are required to answer are two questions about ‘posted personnel’. The first question asks about the types of observation provided by posted personnel. Many facilities that answered no about the security force personnel are going to be confused about how they can answer this question. The next question provides some additional guidance by including non-security operations personnel in who may provide observation. Finally, the ‘tactical positions’ question should have been included in the portion of this section by-passed by a ‘No’ response to the initial security force question. A facility that does not have a security force is unlikely to have ‘hardened/defensive positions’ or ‘hardened fighting positions’.

Tuesday, June 16, 2009

SSP Submission – RBPS #3 Screen and Monitor

This is another in a series of blog posting on the recently released Site Security Plan Instructions Manual and Questions Manual. The other blogs in this series are: Preparing for SSP Submission SSP Submission – Facility Data SSP Submission – Facility Security Measures SSP Submission – RBPS #1 Restrict Area Perimeter SSP Submission – RBPS #2 Secure Site Assets This posting looks at the SSP sections that deal with Screening and Monitoring access to the facility. Questions for this RBPS may be found in both the Facility and Asset level sections of the SSP. If the facility has indicated that there are asset specific security provisions at the site, they will be asked if there are RBPS #3 measures for each of the identified assets. An affirmative answer will require the answering of a series of questions about those measures. Screening Questions The first real question asks about the general level of screening conducted at the facility. With answers ranging from all vehicles and personnel entering the facility to no screening, it seems to be fairly easy to select an appropriate response. One slight draw back; the answers assume that similar levels of screening are being done for both personnel and vehicles. If one is being required to undergo a significantly higher level of screening than the other, use the “Other” response and explain the situation in the provided block. Then there will be individual questions about the use of screening on inbound and outbound vehicles and personnel. An affirmative answer to any of these questions will bring up additional detailed questions about how that screening is performed. The first question in the series asks about the methods used to perform the screening with four possible answers:
Not allowed on site Cursory inspection Random inspection Not applicable
These answers do not appear to include 100% screening, but that is misleading. If the facility were to select ‘Random inspection’ the subsequent question asking about the frequency of inspection includes an answer of ‘100%’. Thus a facility that does 100% screening should select ‘Random inspection’ for their response to the initial question. There is a special area for ‘Inbound Trucks and Railcars’. It is not clear from the information available in the Questions Manual whether these questions are limited to tank trucks and tank cars or if they also include dry-box trucks and rail cars. Looking at the earlier questions about inbound inspections, there are questions about inbound ‘delivery vehicles’ which could include dry-box trucks picking up shipments. I would probably tend to answer questions about dry-box trucks under the ‘delivery vehicle’ question and any boxcar rail shipments under the ‘Inbound Trucks and Railcars’ question. I base this assumption on the fact that both types of railcars are required to be inspected before loading under TSA rail security regulations (49 CFR §1580.107(a)) if they are being loaded with Rail Security-Sensitive Material. For facilities with Theft/Diversion COI there will be a series of question about inspections of outbound vehicles. It may seem strange to see the question about POV (personally/privately owned vehicles) outbound from ‘Theft COI Areas’, but this would be an appropriate question if POVs were allowed to be parked near warehouse areas where Theft/Diversion COI are stored or loaded onto trucks. If one of the vehicle types addressed in this section is not allowed to be parked near an area where Theft/Diversion COI are stored or handled, the appropriate answer would be ‘Not Applicable’. Similar questions are asked for a variety of personnel and their hand carried items. Again, there are separate questions for inbound and outbound inspections. The answers to these questions are essentially the same as those answered for vehicle inspections. Identification Verification The other area included in this section deals with the procedures that the facility uses to verify the identity of personnel entering the facility. The first set of questions in this section concern ‘General Identification Methods’. Two of the questions in this section seem to be out of place since they ask about checks of vehicles and hand carried items to prevent “the introduction of weapons, explosives, drugs, etc. into the facility” (pgs 116-7, Questions Manual). These questions were dealt with in great detail in the earlier ‘Screening’ section of the SSP. Most of the questions are fairly straight forward items asking about procedures for checking identification and the uses of badges and passes. One question seems a little bit odd in the way it is presented. On page 120 of the Questions Manual there is a matrix that looks at the types of badges and passes that might be used on one axis and the people that might be required to use those badges and passes on the other axis. Where the columns cross you find the typical ‘Yes’ and ‘No’ buttons. This is a an economical way of presenting these questions. The odd thing is the last entry on the ‘personnel’ axis; ‘N/A’. The only thing that I can think of is that a check in the ‘Yes’ box in the ‘N/A’ column automatically marks ‘No’ for all of the personnel responses for that ID type. Access Control System While Access Control Systems (ACS) are technically part of the ‘identification verification process’ they do deserve their own unique discussion. I was disappointed that Access Control Systems were not addressed in the RBPS Guidance document, but they are addressed here in the SSP. Unfortunately, from the information presented in the Questions Manual, it is not possible to tell if there will questions on the use of ACS in the asset security portion of this RBPS section. There are a similar series of questions to those seen in the CCTV and Alarm Systems section of the RBPS #1 questions. They ask where the ACS will be ‘controlled’, ‘administered’ and ‘monitored’. The way the ‘monitored’ question is presented (a ‘Yes’/’No’ choice for each location) that multiple answers to that question are expected. I have the same complaints about the lack of explanation for the distinction between ‘controlled’ and ‘administered’ that I expressed in the SSP RBPS #1 posting. Vehicle Restrictions The vehicle restrictions section of the RBPS #3 portion of the SSP looks at how the facility controls the movement of vehicles into and within the facility. This section uses a term that is derived from the design of European Castles; the ‘sally port’. In castle construction this was an area between the inner and outer walls of the castle where a force could assemble to ‘sally forth’ and conduct their counter attack It was distinguished by two sets of gates; one in each wall. In modern security usage it describes a protected area where an inspection can be conducted between two closed gates. Under high-threat conditions only one gate will be opened at a time. This section also includes questions about parking areas on and off site. There are questions about the parking situation allowed for a variety of classes of vehicles, including employee, contractor and visitor POVs. The other class of vehicles listed is ‘Delivery’ vehicles, so I guess this covers both pick-up and deliveries (answering a question earlier in this posting). One class of vehicles that is missing from this section is ‘Service Vehicles’; those vehicles driven by a wide variety of vendors that make deliveries and provide technical services at high-risk chemical facilities. They may include uniform, food and office supply vendors that do not typically make their deliveries to normal loading docks. They may also include a wide variety of technicians providing service to a wide range of specialty equipment. This may be especially critical since these vehicles are frequently parked in or adjacent to operational areas of chemical facilities.

Wednesday, June 10, 2009

SSP Submission – RBPS #2 Secure Site Assets

This is another in a series of blog posting on the recently released Site Security Plan Instructions Manual and Questions Manual. The other blogs in this series are: Preparing for SSP Submission SSP Submission – Facility Data SSP Submission – Facility Security Measures SSP Submission – RBPS #1 Restrict Area Perimeter The Final Facility Notification Letter will include a list of facility assets with the associated COI that the facility must address in their site security plan (SSP). Section 5 of the Instructions Manual provides some over-all directions for the completion of this RBPS in the SSP. Unfortunately, there seems to be a serious disconnect between how the Instruction Manual and the Questions Manual address RBPS #2. The confusion caused by this disconnect is at least partially cleared up by referring to pages 52 thru 56 of the SSP Screenshots available on the CSAT SSP web page. Given the importance of the Screenshots document in understanding this RBPS, DHS should have listed the document in the Key Documents section of the CSAT web page. Incomplete Instructions The Instruction Manual notes that “DHS expects that RBPS 2 (Secure Site Assets) typically will be applicable to all facilities at either the facility-wide level or the asset level (or both). However, a facility must address RBPS 2 for each asset whether or not facility-wide security measures were previously entered” (pg 34, IM). This implies, and later discussion confirms, that the facility will be required to identify and describe each asset. The Questions Manual only mentions identification of assets obliquely, stating after the first “Are there any security measures…” question that the Preparer should if “answering at the Asset level, write the name of the asset for which you are providing answers.” There is no indication that each asset identified in the Notification Letter must be named and described as identified in page 52 of the Screenshots. Nor is there any mention of the long list of questions about each asset that are shown on page 53 of the Screenshots. Additionally, there is no indication in RBPS #2 the Questions Manual that the facility will have to identify those RBPS that have “asset-specific security measures that are different from the facility-wide security measures” (pg 39, IM). There are brief mentions in later RBPS sections that questions may apply to either facility or specific assets. If the facility is planning on using the Questions Manual as a workbook for data collection for their SSP submission I have some suggestions for modifying that manual. Copies should be made of pages 53 thru 55 of the Screenshots; one copy for each asset identified in the Notification letter and any other assets that the facility might wish to report upon. Then the same number of copies should be made of each of the pages in the Questions Manual for the following RBPS numbers 3, 5, 6 and 7. A copy set should be labeled and grouped together for each asset and tabbed for easy access. Barriers Most of the questions dealing with barriers are very similar to the questions in RBPS #1. The reason for that is relatively simple; barriers are very much the same whether they are located on the facility perimeter or on the perimeter of a restricted area within the facility. There are some new questions such as the one dealing with skylights in roofs because the assumption was made that buildings roofs would be inside the facility perimeter. Surprisingly there are a number of new questions that probably should have been included in RBPS #1. For example there are detailed questions about anti-vehicular barriers, which certainly are applicable to internal barriers, but would also apply to facility perimeter barriers. Other questions in this category include the questions on barrier upgrades. There are two questions about internal barriers that are surprising in their sophistication. There are two internal barrier questions that deal with movable barriers utilizing ‘dispensed liquids, foams’. I have only seen these obliquely mentioned in the literature and they are not addressed at all in the RBPS Guidance document. I would certainly be interested in hearing from anyone that sells or uses such barriers. Intrusion Detection Systems The questions about intrusion detection systems for this RBPS are nearly duplicates of the ones used in RBPS #1. There are some minor changes in wording, but the intent on the questions remains the same. Given the similarity in questions it is imperative that Preparers keep in mind that they should not duplicate the answers from RBPS #1 unless there are similar sensor systems in use around internal restricted areas. Security Lighting I hadn’t noticed that there were no questions about security lighting in RBPS #1 until I read the questions on security lighting in this RBPS. I have no idea why these questions were not included the RPBS #1 Questions; the subject is certainly addressed in nearly identical language in the two RBPS sections in the Guidance document. The questions here focus on where the security lighting is, the level of lighting provided at specific areas (site perimeter, gates, and other critical locations), and the percentage of gates and critical locations that are lighted.

Friday, June 5, 2009

SSP Submission – RBPS #1 Restrict Area Perimeter

This is another in a series of blog posting on the recently released Site Security Plan Instructions Manual. The other blogs in this series are: Preparing for SSP Submission SSP Submission – Facility Data SSP Submission – Facility Security Measures In this posting I’ll look at the first RBPS, Restrict Area Perimeter, following up yesterday’s blog on the discussion of this RBPS in the Guidance document. As we will see with each RBPS section in the SSP the first question (pg 58) [Note: all page references are to the Questions Manual] is: “Does the facility have any existing, planned, or proposed measures for RBPS 1?” A negative answer to that question completes this section of the SSP. DHS will evaluate the entire SSP submission to determine if the ‘No’ is an adequate method of addressing this RBPS. There certainly may be facilities that require no security measures to protect the area perimeter, but most facilities will not be able to justify such an answer. Mechanics Preparers that worked on the facility’s Top Screen or SVA submission will be familiar with how these sections of the SSP submission work. Most questions require checking off either ‘yes’ or ‘no’ responses. Frequently a yes answer will lead to more detailed questions on that security measure. Many questions will provide a list of possible responses each followed by the typical ‘yes/no’ buttons. The last answer in these lists is usually ‘Other’. A ‘yes’ response will bring up a fill in the blank box where a short description will be used to explain that ‘Other’ response. For example the first security question in RBPS #1 is: “Does the facility have a defined perimeter marked by company property, no trespassing signage, fencing, or other barriers?” There are three response buttons; ‘Yes’, ‘Partial’ and ‘No’. A ‘Yes’ or ‘Partial’ response will lead to a more detailed question about the characteristics of that perimeter. A ‘No’ answer will lead one to the next question, concerning Clear Zones. As I noted in an earlier blog, there are no ‘instructions’ for the RBPS sections of the SSP in the SSP Instructions Manual and only navigation instructions provided in the Questions Manual. This means that Preparers are going to have to make educated guesses about terms like ‘Partial’ in these questions. One would presume in this case that ‘Partial’ means that the perimeter marking does not cover the complete facility perimeter. If the preparation team has questions about terminology they should first refer to the appropriate sections in the RBPS Guidance document (including Appendix C). Most of the questions are labeled with the RBPS Metric number that they support, this should help facility personnel figure out what information is being requested. If there is still confusion contact the CFATS Helpline (866-323-2957; Monday-Friday 7:00 a.m. – 7:00 p.m., Eastern Time). Potential Problem Questions I am not going to discuss every question in the section. Most of them are straight forward with the minimum of ambiguity. Other, however, I would expect to be somewhat confusing to people that work in chemical facilities and have little background in physical security. A word of warning, I am not a trained DHS Inspector so my interpretations may not toe the DHS party line. When in doubt, call DHS. Clear zone: The ‘clear’ zone is the area adjacent to a barrier that is cleared to nearly ground level (think closely cropped lawn) that allows personnel or surveillance equipment a clear view of potential operations near the barrier. Ideally that clear zone would be on both sides of the barrier to allow for the best observation. The ideal width of the clear zone depends on many factors, particularly the terrain, but should be wide enough to allow for ready access to security and maintenance vehicles. ‘Clear zone policy’ refers to the procedures for investigation/response to the detection of movement or penetration of the clear zone. Standoff distance: ‘Standoff distance’ is the distance between a potential target and the closest allowed approach to that target. The RBPS Metric 1.3 only addresses standoff distance for VBIED (vehicle borne improvised explosive devices) suggesting “Sufficient vehicle standoff distance or alternative protective means are provided to ensure that a VBIED is extremely unlikely to be able to compromise a critical asset.” Adequate standoff distance depends on the amount of ‘overpressure’ the target is capable of withstanding and the assumed size of the VBIED. Standoff distance for direct fire weapons like rocket propelled grenades may also be considered. Barriers: There are a large number of questions about a wide variety of possible barriers that might be employed at a high-risk chemical facility. The term ‘partial’ is used for many of the answers and refers to the fact that the ‘barrier’ referred to in that question does not completely surround the facility. Access Points: The way this term is used in the single question may be misleading. It does not refer to gates or doors (those are addressed elsewhere), but instead deals with alternative/clandestine routes through the barrier system. ‘Ditches’ and ‘culverts’ are easy to understand in this context, but ‘public roadways’ is less clear. This almost certainly refers to public roads that traverse the facility. What I don’t understand is why there are no questions about security measures protecting these ‘access points’. Intrusion Detection: Again, there are a large number of detailed questions about IDS or ‘intrusion detection systems’. The ‘partial’ response to these questions means that the system being addressed only covers a portion of the facility perimeter. These questions do not concern IDS systems protecting individual assets (that would be covered in RBPS #2). While there are questions about the existence of ‘back-up power supplies’ nothing addresses the duration these back-up will work. I have no idea what ‘controlled’ and ‘administered’ mean for IDS; they are either on or off. CCTV: The closed-circuit television (video surveillance) coverage question has a ‘new’ ‘Not Applicable’ response. If a facility does not have the type of COI referenced in the question (Theft/diversion or sabotage) or loading/unloading areas the appropriate response is “Not Applicable). The ‘controlled’ and ‘administered’ questions make more sense here. ‘Controlled’ refers to the ability to move cameras or their focus to change the field of view. ‘Administered’ refers to the over-ride authority to take control of a camera. Security Personnel: The term security personnel is used with a very wide definition. This can be seen in the use of the terms ‘dedicated’ and ‘casual’ to describe types of ‘observation’. ‘Dedicated’ observation is provided by personnel with the primary job of security. ‘Casual’ observation is provided by all facility personnel that have received rudimentary security awareness training and have some means for reporting an observed security incident.

Monday, June 1, 2009

SSP Submission – Facility Security Measures

This is another in a series of blog posting on the recently released Site Security Plan Instructions Manual. The other blogs in this series are: Preparing for SSP Submission SSP Submission – Facility Data While the two earlier sections of the Site Security Plan, Facility Information and Facility Operations, were extensive (and provided essential information to DHS) we are now beginning to look at the meat of the Site Security Plan (SSP); the Facility Security Measures. This section deals with equipment and procedures that are applied to security on a facility wide basis. While specific pieces of equipment may exist at only a single location in the facility, they provide some measure of protection for the entire facility. Facilities may also have security measures designed to protect a specific asset, but those will be covered in next section of the SSP, Asset Security Measures. Risk-Based Performance Standards The Facility Security Measures section of the SSP is organized around the Risk-Based Performance Measures (RBPS) specified in 6 CFR §27.230. Each of the 18 RPBS will be addressed in turn, starting with the Restrict Area Perimeter and ending with Records. Each RBPS will have to be addressed for every facility, but how a facility addresses any RBPS will depend on the facility. As each RBPS section is opened in turn, the first question that the Preparer will encounter is “Does the facility have any existing, planned, or proposed measures for RBPS X?” If the answer to that question is ‘No’, then that RBPS has been addressed and the facility may move on to the next RBPS. DHS will determine if ‘No’ is an adequate way to address that RBPS by looking at the totality of the SSP. “Failure to provide information about security measures relevant to a given RBPS may result in the need to submit a revised SSP and, in some cases, ultimately could lead to disapproval of a facility’s SSP” (pg 33). DHS does expect that most facilities will have security measures for most of the eighteen RPBS, either in the Facility Security Measures or Asset Security Measures section of the SSP. There are two exceptions to this general rule, RBPS 6 - Theft and Diversion and RBPS 7 – Sabotage. Facilities that do not have Theft/Diversion or Sabotage COI identified on their Final Facility Notification letter will probably not have security measures for these two RBPS. Security Measures If the initial question in the RPBS section is answered affirmatively, the Preparer will be able to access a number of questions about potential security measures that could support that RBPS. The first question for each security measure asks if the facility is currently using that security measure. “Facilities are required to list and/or describe existing security measures as part of Section 4 of their CSAT SSP submissions (pg 35).” There are a number security measures identified in each RBPS with a series of questions for each measure. Most questions are answered by selecting “Yes/No” or selecting from multiple choice answers. Most multiple choice questions include an ‘Other’ selection with space provided for a description of the answer. What does appear to be missing in the lengthy list of questions about security measures is a space for identifying unique security measures that are already in place. While the listing provided is certainly extensive, I would be willing to bet that there will be a significant number of facilities that will have found or developed security measures that are not included in the list. In some cases there these measures will be able to be squeezed into the ‘Other’ selection of existing questions. If a facility runs into such a situation I would suggest that they use the “Planned Measures” block to describe these measures and carefully describe that the security measure is already in place. The “Planned Measures” is included for facilities to list security measures that are not currently ‘in-place’ but have progressed to the point that they will be in place at some predictable point in the future. The facility must be able to document their commitment to completing the installation of the ‘planned measures’; “DHS may subsequently ask the facility to produce documentation confirming the planned measure” (pg 35). DHS may consider planned measures in their evaluation of the SSP. If the planned measure is required for DHS approval of the SSP, the Letter of Approval marking final approval of the SSP will not be forthcoming until the ‘planned’ security measure is actually installed. Security Measures Not Considered While DHS is requiring all current security measures to be included in the SSP submission, they did realize that there might be existing security measures that will be phased out as newer security measures come on-line. The problem is that the submitted and approved SSP will form the basis for subsequent DHS inspections of the facility. This means that the described security measures will then be required security measures. DHS has provided an area at the end of each RBPS section where facilities can explain what security measures that it does not want to be included in the approved SSP. DHS does note that “if a facility chooses to eliminate an existing security measure that is relevant to one or more CFATS RBPS, it is possible that the facility’s SSP, as submitted, may not satisfy the applicable RBPS” (page 36). Interestingly, there is no mention in the Questions Manual of a question about security measures that the facility does not want to be considered. Neither does the Screen Shots file show a picture of a screen with such a question. This is an unfortunate oversight. Proposed Security Measures The final question in each RPBS section deals with the issue of proposed security measures. These are measures that the facility is considering installing at the facility. There has been no firm commitment to have these measures in place, so DHS will not consider them in approving the SSP. The reason that a facility might want to include these potential security measures in their submission is that it DHS might not approve their SSP. These proposed security measures might allow DHS to say that: “No the current SSP is not approved, but if this proposed security measure were put into place, DHS would probably be able to approve the plan.” Instructions Shortcomings In my opinion there is one major shortcoming with the Instructions Manual; there are no instructions for the individual RBPS questions. While the RBPS manual provides some guidance on the items to be considered, there is a dearth of detailed information. The questions, however, contain a great deal of detail. In future discussions of the individual RBPS sections, I will identify those items that I think should have included additional information in the Instructions Manual.

Friday, May 15, 2009

SSP-RBPS Rolled Out Today

At noon today the Department of Homeland Security rolled out the next phase of the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS). They published the Risk-Based Performance Standards Guidance (RBPS Guidance) document and opened the Site Security Plan (SSP) tool on their Chemical Security Analysis Tools (CSAT) web site. Two SSP supporting documents were also published on the CSAT site. Additionally they started the process of mailing out the notification letters that will let high-risk chemical facilities the official results of their Security Vulnerability Assessment (SVA) that were submitted last year. Finally, DHS has sent emails to the registered users of the CSAT that the RBPS Guidance has been posted on the DHS web site. RBPS Guidance The RBPS Guidance document is a more polished document than the draft that DHS published for public comment last year. It still does not spell out what a high-risk chemical facility must do to adequately secure itself from potential terrorist attack, but DHS has been prohibited by Congress from doing that. Instead it “reflects DHS’s current views on certain aspects of the Risk-Based Performance Standards (RBPSs) and does not establish legally enforceable requirements for facilities subject to CFATS or impose any burdens on the covered facilities” (RBPS Guidance, pg 7). The general layout of the document and the basic content remains the same as the draft, but the new document will require a careful reading. There are some subtle differences in the information presented. Additionally, DHS has made it clear that this is a living document. In one of many footnotes in the document the RBPS Guidance notes that “DHS is likely to periodically update this Guidance document to take into account lessons learned throughout CFATS implementation, describe new security approaches and measures that covered facilities may wish to consider implementing, and provide information on any new or revised RBPSs” (pg 8). SSP Tool As with all of the previous tools published in CSAT, access to the actual SSP tool where high-risk chemical facilities will actually submit their SSP is limited to registered CSAT users. As with each of the previously published tools the CSAT web site includes downloadable copies of two documents that will aid Preparers and Submitters with the preparation and submission of the SSP. The SSP Instructions provides detailed instructions on how to answer the very large number of questions that constitute the method of submission of the SSP. The SSP Questions provides a way for facility Preparers to collect and organize the required information to make it easier to actually enter the information into the on-line SSP tool. Each of these lengthy documents should be read carefully before trying to collect and submit the data required for the SSP. Future Blogs As I have done with all of the other CSAT tools, I will be doing a number of blog postings looking at the details of the SSP Tool, it’s supporting documents and the RBPS Guidance document. This is probably the most complex portion of the CFATS process and will take a lot of time to analyze and explain. Of course, I have the luxury of not actually having to implement this at a real chemical facility. I certainly welcome and encourage anyone with questions and comments about these new documents to send them on to me (pjcoyle@aol.com) or to post them as comments to this blog. I’ll do my best to explain things. DHS has also established a procedure for dealing with questions. You can contact the CFATS Help Desk either via e-mail at csat@dhs.gov or by phone at 866-323-2957. They also provide the name and address of a real person to whom you can “submit questions via regular mail” (pg 9):
Dennis Deziel Deputy Director Infrastructure Security Compliance Division U.S. Department of Homeland Security, Mail Stop 8100 Washington, DC, 20528

Monday, April 13, 2009

Answers to Security Questions

Back at the end of February I did a brief posting about a then upcoming article in Control magazine that was going to look at two questions, or aspects of control system security. The Editor of the magazine was asking for answers to two questions that would then be used as a jumping off point to look at SCADA security and compliance. Those questions were:
How much security do you need to be really secure? What’s the difference between "compliance" and "security"?
Well, last week the article (A Distinction with a Difference in Functional Security, pgs 37-9) came out in the April issue of the print magazine. The article is also available at ControlGlobal.com. Additionally, the editors posted a separate listing of answers that they received to their query on the web site that is not available in the print addition (space limitations are not as important on the web). While the article is certainly well worth the read (I recommend it highly), the actual responses they received from their wide cast net is even more instructive. The responses from a wide variety of experts in the field (though they did include my response and I am hardly a SCADA expert) show a surprising consensus on the distinction between compliance and security. As the chemical security community waits for the release of the Risk-Based Performance Standards Guidance document and the opening of the Site Security Plan Tool on CSAT, this would be a good time for security managers to read both documents on the ControlGlobal.com web site. As facilities begin to respond to their compliance duties with the next phase of CFATS, it would be good to be reminded that CFATS compliance does not insure adequate security. Both security and compliance need to be addressed during the development of the Site Security Plan.

Monday, March 23, 2009

SSP-RBPS Status 03-23-09

Everyone in the chemical security community is wondering when DHS will be rolling out the CFATS Site Security Plan and Risk-Based Performance Standards Guideline documents. Over a month ago it was being reported that it would be rolled out in February. That didn’t pan out too well. It seems that OMB is still looking over the RBPS Guidelines. Once those are approved, DHS is prepared to move forward with the SSP Tool on their CFATS web site. No telling when OMB will be done with their review. Remember President Obama has had them re-looking at all in-process rules and redefining the regulation approval process. Needless to say this will upset the ACC people at ChemSecure this week. There were supposed to be some DHS explanations of both the SSP and RBPS this week at that conference. I doubt that much information will be forth coming until the official role out. Oh well, we wait and watch.
 
/* Use this with templates/template-twocol.html */