Showing posts with label TSDB. Show all posts
Showing posts with label TSDB. Show all posts

Wednesday, July 1, 2026

Looking Back – 12-28-29 – TSDB and TWIC

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from December 29th, 2009, Reader Comment – 12-28-09 – TSDB and MTSA, showed up on the list. This ended up being the middle post in a three-post discussion about how TWICS were supposed to keep terrorists out of critical infrastructure facilities. Those three posts were: 

TIDE vs TSDB,  

Reader Comment – 12-28-09 – TSDB and MTSA, and 

Reader Comment – 02-01-10 TSDB. 

While the three posts are over 15 years old, I see nothing in them that does not ring true today. 

Wednesday, September 24, 2025

Review – HR 4971 Introduced – TSDB Quality Control

Last month Rep Thompson (D,MS) introduced HR 4971 the Terrorist Watchlist Data Accuracy and Transparency Act. The bill would amend the Homeland Security Act of 2002, adding a new §210H, Quality assurance reviews of departmental nominations to the terrorist watchlist and other terrorism databases. The new section would require DHS to conduct quality assurance checks of all new data prior to submission to the Terrorist Screening Database (TSDB). Periodic audits would also be required. No new funding is authorized by the bill.

Moving Forward

Thompson is the Ranking Member of the House Homeland Security Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I suspect that there might be some level of bipartisan support for this bill in Committee, but I am not sure that it would be enough to move the bill to the floor of the House under the suspension of the rules process. This bill is not politically important enough to consider under regular order.

Commentary

Last month the GAO published their most recent report on “Terrorist Watchlist: Nomination and Redress Processes for U.S. Persons”. The GAO spent most of their effort reporting on the redress processes for people who feel that they have been improperly been added to the TSDB or it related databases. Many (no one is sure of how many) of those ‘in error’ listings could have been prevented from occurring if there had been data quality assurance processes in place to reduce those questionable listings.

 

For more details about the provisions of this bill, including additional commentary, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4971-introduced-tsdb-quality-control - subscription required.

Monday, January 13, 2025

Reader Comment – TSDB Screening for ChemLock

I got some feedback yesterday on LinkedIn on my weekend post on ChemLock and Tiering.  Philip Polios left a comment that suggested that ChemLock authorization should include allowing facilities to vet employees using the Terrorist Screening Database (TSDB).

The CFATS program had this as part of their personnel surety program, and lots of people in the chemical industry have commented on the lack of this vetting process since the CFATS lapse as one of the major reasons that they wanted to see the program reinstated.

I had always planned on including this in the discussion about ChemLock, but it is helps to get this sort of feedback from readers.

As always, anyone with further suggestions about this series of blog posts, or chemical security/safety in general, feel free to contact me either through my social media feeds or using my contact information on LinkedIn. 

Saturday, July 22, 2023

CRS Reports – Week of 7-15-23 – TSDB Legal Challenges

This week the Congressional Research Service (CRS) published a report on “Legal Challenges to the Terrorist Screening Database”. The report gives an annotated background for the establishment of the TSDB and many of the legal challenges that have been made against the database. While the report mentions the notorious ‘Do Not Fly’ list, the TSDB is used for vetting by several other programs, including the Transportation Workers Identification Credential (TWIC), the Hazardous Materials Endorsement (HME) for State commercial drivers’ licenses, and the Chemical Facility Anti-Terrorism Standards (CFATS) personnel surety program.

Wednesday, April 27, 2016

House Passes HR 4240 – TSDB Report

Today the House passed HR 4240, the No Fly for Foreign Fighters Act, under suspension of the rules. There was only 17-minutes of debate and the bill passed on a voice vote. The bill would require a report to Congress on the efficacy of the Terrorist Screening Database (TSDB).

While the bill would require a report to Congress it neglects to consider the single biggest problem with the TSDB; the false positive rate and the lack of a meaningful method of redress for those false positives. As the TSDB is starting to be used to verify the lack of terrorist ties of current employees of a large number of chemical facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program, the issue of false positives is likely to raise some very painful issues at a number of chemical facilities.

The report requirements specified in this bill have nothing to do with preventing foreign fighters from flying into or within the United States. Instead it will probably have the effect of making it easier to add unverified names to the TSDB; thereby exacerbating the problem of false positives.


The failure of Congress to even entertain questions about the false positive problem is indicative of the knee jerk reactions of our elected representatives when they see security failures. Unfortunately, this bill will probably be considered under the unanimous consent provisions in the Senate where there will be even less (actually no) debate and not even a pro-forma voice vote.

Monday, January 12, 2015

HR 48 Introduced – TSDB Review

As I mentioned earlier Rep. Jackson-Lee (D,TX) introduced HR 48, the No Fly for Foreign Fighters Act. This is a simple requirement for Attorney General to review the Terrorist Screening Database (TSDB) to ensure that anyone “who is known or suspected of being a member of a foreign terrorist organization” {§2(a)} is listed on the TSDB. There is, of course, a requirement to report to Congress on the results of the review.


This bill would certainly have a high probability of passing if it made its way to the floor of the House. It will be interesting to see how well Rep. Jackson-Lee is able work with Republican leadership to move this forward. It might be a good measurement of how well bipartisanship will work in this Congress on non-controversial bills.

Sunday, February 9, 2014

30 Day CFATS PSP ICR – Positive Match

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


One of the controversial issues in the PSP has been the DHS response to positive matches against the Terrorist Screening Database (TSDB). Industry has long expected that DHS would immediately notify them if any of the names that were submitted to the CFATS PSP returned a positive match against the TSDB. That is not, however, the Department’s stance. They have consistently stated that:

Regardless of the option, in the event that there is a potential match, the Department has procedures in place that it will follow to resolve the match and coordinate with appropriate law enforcement entities as necessary.

Information Release Controlled by Law Enforcement

In the earlier iteration of the proposal for the CFATS PSP ISCD made it clear that whenever possible, they would notify the facility as quickly as the investigative process allowed. There have been some people that have interpreted this to mean that ISCD would be handling the investigation of personnel with a positive match to the TSDB. That was specifically addressed in this notice when DHS replied:

The Department does not lead the investigation of any affected individual with terrorist ties; rather the Department supports law enforcement investigation activity.

Typically, since they own the TSDB and are responsible for counter-terrorist investigations within the United States, the FBI will be the lead investigative agency for most positive matches against the TSDB. Depending on how someone was placed on the TSDB, another federal law enforcement agency may take the lead. In any case, the lead investigative agency will be responsible for deciding when the facility management may or may not be told about a positive match by one of their employees.

The Department has made clear they understand the point of view of the facility management:

The Department recognizes the significant and vested interest the high-risk chemical facility or designee may have in ensuring an affected individual with terrorist ties does not successfully carry out a terrorist attack against or involving a high-risk chemical facility.

The Department almost certainly understands that it will look extremely bad if a terrorist attack is successfully carried out while the Department knows that the individual has been listed on the TSDB as being a suspected terrorist. It is in the best interest of the Department to provide information to the facility management as quickly as possible so that a potential threat can be removed from the facility. Still, the Department’s hands may be tied by an on-going investigation being conducted by a law enforcement agency

Other Programs

All other programs vetted through the TSA (and the TSA will be doing the actual vetting of individual information against the TSDB) have a adjudication program requirement where the individual must be informed if the TSA determines that the individual is a security threat based upon any of the background checks conducted by the TSA (the CFATS PSP is the only program that does not have TSA doing criminal background checks in addition to the TSDB vetting).

In those cases there is no imminent danger that the individual will be given unaccompanied access to a protected facility while the background check process is proceeding. This almost certainly means that a criminal investigation, if deemed necessary, would have already been initiated and probably completed by the time that the individual is informed of fact that issuance of the credential has been denied.


Perhaps ISCD should also take the same tack with respect to the CFATS PSP; set up the program in a way that facilities could not allow employees, contractors or visitors unaccompanied access to critical areas of the facility until they have been notified by DHS that the vetting process has been completed and that there is no indication of potential terrorist ties associated with the individual. Industry has maintained, however, that that is not an acceptable method of doing business and have routinely complained about the 48 hour notice requirement in the proposed program.

Monday, August 26, 2013

CFATS PSP and Suspected Terrorists

I’m hearing rumors that DHS is getting close to the point where they will be issuing their 30-day notice for the information collection request supporting the CFATS personnel surety program. I did a series of blogs (listed below) on the comments that were received when DHS published the 60-day notice, now it is time to take a closer look at some of the issues that ISCD will have to address when they publish the 30-day notice.


Without a doubt the most controversial portion of earlier notice is the continued presence of a statement that DHS will not necessarily tell facilities if there is a positive match with the Terrorist Screening Database (TSDB). The notice states:

“Regardless of the [data submission] option, in the event that there is a potential match, the Department has procedures in place that it will follow to resolve the match and coordinate with appropriate law enforcement entities as necessary. High-risk chemical facilities may be contacted as part of law enforcement investigation activity, depending on the nature of the investigation.”

Needless to say facility owners and security managers are upset as hell that the folks at ISCD might allow a suspected terrorist to continue to continue to work at a high-risk chemical facility while some criminal investigation is underway. Almost as one industry commenters made clear that they would rather get a suspected terrorist out of their facility and risk not being able to take criminal action against them than allow them to stay and perhaps execute an actual attack while under investigation.

I am sure that David Wulf, Director of the Infrastructure Security Compliance Division, and his team of Chemical Security Inspectors (CSI, PLEASE someone change that title so we can get a different acronym) have the same concerns. I know that they realize that if a chemical facility attack happens under those circumstances that they will not be able to withstand the accusations of incompetence and malfeasance that will be leveled against them in Congress and the court of public opinion.

And those charges will be completely unjustified since it won’t be David’s call as to when facilities will be told that they have a suspected terrorist in their midst. That decision will almost certainly be made high within the ranks at the FBI or perhaps even in the office of the Attorney General. It is likely that David won’t even be told until such time as the law enforcement people have cleared the information for release.

The inevitable question that will be asked is why is it different for the TWIC? There the individual is notified if there is a positive match and there is an adjudication process in place for handling appeals. But TSA has never mentioned that they won’t tell an individual that his TWIC processing was rejected if there is a criminal investigation being conducted as a result of a TWIC submission. There will be an unexplained delay in the processing until the investigation is resolved. Then the individual will be notified of the reason, probably by an FBI SWAT Team.

It is a shame, in retrospect, that the folks at ISCD hadn’t just stood mute on the subject of criminal investigations of potential terrorist ties. If they had just said that the facility would be notified of any positive matches against the TSDB (which will eventually be the truth) things would have been fine. But no, someone decided to tell the whole story (or at least more of the whole story than had previously been done) and DHS is stuck with it.


Because, no matter how much industry legitimately complains about the risk to their facilities, the criminal justice system will not allow information about ongoing criminal investigations to be shared outside of the law enforcement community. Period, end of story.

Wednesday, April 17, 2013

Bills Introduced – 04-16-13


While the House was working on cybersecurity bills and the Senate on gun control legislation there were three bills introduced that might be of specific interest to the chemical security and cybersecurity communities. They are:

HR 1583 Latest Title: To amend the Homeland Security Act of 2002 to establish an appeal and redress process for individuals who are screened against the terrorist watchlist and wrongly delayed or prohibited from boarding a flight, or denied a right, benefit, or privilege, and for other purposes. Sponsor: Rep Clarke, Yvette D. (D,NY)

HR 1584 Latest Title: To amend the Homeland Security Act of 2002 to prevent terrorism, including terrorism associated with homegrown violent extremism and domestic violent extremism, and for other purposes. Sponsor: Rep Clarke, Yvette D. (D,NY) 

S 733 Latest Title: A bill to amend the Department of Energy High-End Computing Revitalization Act of 2004 to improve the high-end computing research and development program of the Department of Energy, and for other purposes. Sponsor: Sen Alexander, Lamar (R,TN)

HR 1583 might impact both the TWIC program and the new CFATS Personnel Surety Program. There is no telling exactly what efforts Ms. Clarke is proposing until we see the actual language of her bill. And Lamar’s bill might be a cybersecurity bill or it might just be a cyber bill, only a review of the actual legislation will tell.


Tuesday, July 31, 2012

The Cost of an ICR


On Sunday I responded to a Reader comment about the abbreviated CFATS hearing before the House Appropriations Committee (it was billed as a Committee hearing, but only the Chair and Ranking Member of the Homeland Security Committee were present). I mistakenly ignored the Reader’s comment about the ire of Rep. Price (D,NC) about the cost of the ICR. I reasoned that the actual cost of preparing the ICR, even the crafting of the personnel surety program that the ICR supported, just could not be that high. After all, we are already paying for the salaries of the people who worked on writing the two documents. And they were obviously not doing anything else in any case.

Then I had a conversation with a long time Reader with connections to ISCD. That Reader informed me that ISCD had made payments to TSA in two fiscal years (I forgot to ask, but I assume FY 2010 and FY 2011) for services in support of the personnel surety program; payments probably in excess of $4 million. Cognoscenti will realize that TSA, who operates the Terrorist Screening Data Base (TSDB) is required to recoup the cost of TSDB checks by charging the requesting agency or individual for those checks.

What is interesting here is not that the money was misspent (while $4 million is a lot of money to most people, it really is small change to congressional spenders), but that it was misspent twice. When ISCD published their original detailed ICR notice describing how they intended to operate the program, industry responded with a firestorm of negative comments. At this point ISCD should have realized that there were problems with their proposed personnel surety program and started doing some revising. And they should have not made any pre-payments for TSA services until the program was closer to actual operation.

A year later (which should have been time to revise the program significantly) when the second notice was published, some revisions in details were made, but the main sticking points for both industry and labor remained the same. Like a spoiled child, ISCD essentially said, we want what we want and we are going to get it. The published responses to that were even less positive than the first batch. Who knows how bad the back-channel complaints to OMB were? Actually we can guess pretty well; they were severe enough and numerous enough for OMB not to take any action on the ICR.

Hopefully, when ISCD goes back to the drawing board on this program, they will start from scratch and develop a clean program that provides a mechanism for checking employees, contractors and unaccompanied visitors against the TSDB and allows for the recognition other programs (TWIC and HME for instance) that vet individuals against that database.

Then, when the ICR is approved, ISCD can make the appropriate payment to TSA. And perhaps the Secretary might want to give them at least partial credit for the unused checks that have already been paid for.

BTW: The Appropriations Committee has yet to re-schedule their hearing on the CFATS program.

Monday, July 9, 2012

Vetting Security Contractors


Ralph Langner, of Stuxnet decoding fame, has an interesting blog post over at Langner.com about the recent ‘revelations’ in David Sanger’s book, Confront and Conceal, that Siemens was complicit in setting up the Natanz control system in Iran and subsequently acted as the Stuxnet transmission agency for the attack on that system. Now I haven’t read that book and Ralph doesn’t actually quote (I think; at least there are no quote marks) from the book and the book is apparently based upon info from politicians not technicians, so I don’t know how accurate the claim actually is.

Quis custodiet ipsos custodes? [Who guards the guardians?]


Having said that, Ralph extrapolates that claim to a very interesting point at the end of his posting:

“So it turns out that Confront and Conceal has an important real-life implication for ICS security and critical infrastructure protection: Asset owners/operators who still favor a policy of unverified trust in the cyber security posture of their contractors and vendors, no matter how large or well-reputed they might be, will from now on have to be regarded as negligent. On the plant floor, the biggest cyber security risk is associated with contractors with legitimate access to a facility’s most sensitive systems. There is absolutely no reason to assume that any specific contractor could be trusted without verification just because they say so, because they enjoy a big market share, or because they pursue a media strategy claiming that they had cyber security gotten straight – quod erat demonstrandum [QED, or end of proof].”

This has always been one of the sore points about hiring security specialists; they are given the keys to the kingdom, but there is little one can do to control their concealed actions. Owner operators need to take great care in selecting any agency to work on the facility security programs, physical and/or cyber. How one prevents the subornation of a major firm like Siemens is almost certainly beyond the control of most facilities, but facility security managers and cybersecurity managers have to take great care in selecting and vetting anyone that works on their security systems.

TSDB Checks


Typical background checks, specifically criminal background checks have to be an important part of the security vetting process. Unfortunately, those checks will be of little use when one is trying to eliminate people with terrorist ties or working for foreign intelligence services. DHS does provide a service for vetting people against the terrorist screening database (TSDB), but that is only available through TSA for transportation related personnel. CFATS covered facilities may, sooner or later, get access to that vetting process, but no other critical infrastructure organizations have, or apparently will have, that vetting option. Of course there is no FIS database.

This is one of the many shortcomings of the various cybersecurity bills; none of them make provisions for personnel surety. There are no requirements that personnel with the cyber-equivalent of ‘unaccompanied access’ have to undergo any sort of background check at critical infrastructure facilities. One would like to think that such checks were being done as a matter of course for business reasons, but it is unlikely that everyone is doing even the criminal background checks. No one is doing terrorist screening, since without a congressionally authorized DHS program for TSDB vetting the Department has no authority to conduct such terrorist background checks.

Wednesday, July 6, 2011

Another Terrorism Screening Database NPRM

Today DHS published in the Federal Register (76 FR 39315-39317) another Privacy Act notice of proposed rulemaking (NPRM) concerning their use of the Terrorist Screening Database (TSDB). This follows shortly behind their announcement about the CFATS personnel surety program that relies on the TSDB to check for potential terrorism links for facility personnel and visitors. This new NPRM describes how DHS will be able to allow more agencies to have direct access to the information contained in the TSDB.

DHS in conjunction with the Department of Justice and the FBI have “developed the DHS Watchlist Service (WLS) in order to automate and simplify the current method for transmitting TSDB records from the FBI/TSC to DHS and its components” (76 FR 39316). This system will make checking individuals against the TSDB much quicker and more efficient.

Interestingly, DHS does not apparently intend to give ISCD access to this system for their personnel surety program. They will still have to refer information submitted by the CFATS facilities to TSA for checks against the TSDB. So much for efficiency.

Tuesday, April 13, 2010

CFATS Personnel Surety Program ICR – 30 Day Notice

On Tuesday, April 13th, the Infrastructure Security Compliance Division folks at DHS published a 30-day information collection request (ICR) notice in the Federal Register for the CFATS Personnel Surety Program (PSP). This is a follow-up to the original notice published last summer (June 10th, 2009; 74 FR 27555), responding to the numerous public comments submitted to DHS. This proposed program would allow DHS to conduct the personnel surety checks of personnel against the TSA’s Terrorist Screening Database for high-risk chemical facilities as required by 6 CFR 27.230(a)(12)(iv). This program will not replace facility responsibilities to conduct other background checks to verify identity, check criminal history, or validate legal authority to work in the United States. CFATS Personnel Surety Program The CFATS PSP will include a potential of three different types of information submissions by high-risk chemical facilities:
Initial submissions on affected individuals; Updated/corrected information on affected individuals; or Information that previously reported individuals are no longer affected.
DHS expects that it may require facilities to submit the information listed below to allow it to adequately screen individuals against the TSDB as well as identifying those CFATS covered facilities where the individual may have access to restricted areas or critical assets.
Full name Date of birth Place of birth Gender Citizenship Passport information Visa information Alien registration number DHS Redress Number (if available) Work phone number(s) Work e-mail address(es)
Follow-up information may be requested by DHS. In order to ensure that facilities may not assume that a request for follow-up implies that an individual has been identified on the TSDB, ISCD makes it clear that there are three reasons that they might request additional information on an affected person:
Confirm that an individual is or is not a match to a known or suspected terrorist on the TSDB; Provide redress for individuals who believe that they have been improperly impacted by the PSP; or As part of a data accuracy review and auditing process.
Affected personnel are all facility personnel (employees and contractors) that have access (either escorted or unescorted) to restricted areas or critical assets, or unescorted visitors who have access to those areas. Facilities will submit the required information via a PSP tool in the existing on-line Chemical Security Assessment Tool (CSAT). ISCD expects to provide for bulk data submissions as part of the PSP tool and requests comments from industry on what forms might be most appropriate for these bulk data submissions. Additionally, ISCD intends to allow facilities to use contractors, consultants or other outside agencies to submit the required data for them. This will be done under the “Preparer” provisions already allowed under other CSAT tools. ISCD will publish a schedule in the Federal Register of when facilities will be required to submit data on affected personnel, noting that the schedule will vary according to which Tier level the facility is assigned. A proposed schedule is included in this notice (75 FR 18853). Notification of TSDB Matches ISCD will send each facility a confirmation of their submissions to the PSP to allow the facility to demonstrate to inspectors that it has complied with the terrorist background check requirements of RBPS 12. In the event of a positive match against the TSDB, the Office of Transportation Threat Assessment and Credentialing (TTAC), the office that maintains the TSDB, will notify the FBI’s Terrorist Screening Center (TSC). The TSC will make the final determination if an individual is a match to a known or suspected terrorist listed in the TSDB. The TSC will make notifications to appropriate Federal law enforcement agencies for further investigation and response. Such agencies may contact the facility as part of their investigation. The Department does not intend to routinely notify affected facilities of positive TSDB matches. In response to comments that DHS should notify covered facilities if the TSDB check indicates a match with a known or suspected terrorist this ICR notes that the precise manner in which “DHS or Federal law enforcement entities could contact high-risk chemical facilities following vetting are beyond the scope of this PRA notice” (75 FR 18856). Paperwork Reduction Act Exemption DHS is including in this ICR a request for exemption from requirements of the Paperwork Reduction Act {5 CFR 1320.8(b)(3)}. The purpose of this exemption is to avoid having to require that facilities collect signatures of affected personnel affirming that they have been advised of certain information collection rules. This will not affect the notification requirements under the Privacy Act {5 U.S.C. § 552a(e)(3)} or other Federal, State, or local privacy rules or regulations. Public Comments DHS received 17 comments on the original 60-day ICR notice. DHS includes in this notice responses to those comments (75 FR 18852-6). ISCD has made appropriate revisions to the outline of the program provided in this notice. DHS requests public comments on the program outlined in this notice. In particular DHS requests comments on:
● Respond to the Department’s interpretation of the population affected by RBPS-12 background checks, as outlined in 6 CFR 27.230(a)(12); ● Respond to fact that the Department or a Federal law enforcement agency may, if appropriate, contact the high-risk chemical facility as a part of a law enforcement investigation into terrorist ties of facility personnel; ● Respond to the Department’s intention to collect information that identifies the high-risk chemical facilities, restricted areas and critical assets to which eachaffected individual has access; and ● Respond to the Department on its intention to seek an exception to the notice requirement under 5 CFR 1320.8(b)(3).
Comments must be submitted by May 13th, 2010. Comments may be submitted electronically at www.Regulations.gov (Docket Number: DHS-2009-0026).
 
/* Use this with templates/template-twocol.html */