Showing posts with label Theft and Diversion. Show all posts
Showing posts with label Theft and Diversion. Show all posts

Tuesday, July 14, 2009

SSP Submission – RBPS #6 Theft and Diversion

This is another in a series of blog posting on the recently released Site Security Plan Instructions Manual and Questions Manual. The other blogs in this series are: Preparing for SSP Submission SSP Submission – Facility Data SSP Submission – Facility Security Measures SSP Submission – RBPS #1 Restrict Area Perimeter SSP Submission – RBPS #2 Secure Site Assets SSP Submission – RBPS #3 Screen and Monitor SSP Submission – RBPS #4 Deter Detect and Delay SSP Submission – RBPS #5 Shipping Receiving and Storage This posting looks at RBPS #6, Theft and Diversion. This section of the SSP looks at equipment, processes and procedures that help to reduce the risk of theft or unauthorized diversion of ‘dangerous chemicals’ including Theft COI. The Guidance document provides the same definition for ‘dangerous chemicals’ in this RBPS as was used for ‘hazardous chemicals’ in RBPS #5. There is no reason given for the use of two different terms for the same chemicals. This section of the SSP provides similar questions for both facility wide security measures and asset specific security measures. As we noted in the other sections of the SSP with similar provisions, a security measure is not reported in the asset specific questions if the security measure applies to (and was reported as) facility wide security, unless there are separate systems for the specific asset or there are substantial differences in operations of the measure at the specific asset. More Duplicate Questions This section has an even larger number of previously asked questions than we have seen in the earlier RBPS sections. Part of this may just be because there are more questions to draw from. Once again, there are no instructions in either the Questions manual or the Instructions manual about how the system deals with repeat questions. I suspect that in many cases the answers will pre-populate forward. There are two odd duplicate questions that have been significantly reworded from their earlier incarnations. I guess that means that they aren’t truly duplicates. I certainly have no idea why these two questions were picked for rewriting and reissuing. Both questions require ‘Yes’/‘No’ check-offs. The questions are:
"Does the facility have controls and procedures that restrict access to storage of potentially dangerous chemicals (including Theft COI), allowing access only to authorized individuals? "Are transportation access portals controlled and is access limited to authorized individuals?"
Unknown Carrier or Driver Questions There is a duplicate question that leads off a section of questions about procedures for how the facility will deal with an unknown carrier or driver showing up to deliver or pick-up a load. Each of the questions requires a ‘Yes’/‘No’ response. At first glance these seem to be standard questions, but there are two questions that are very similar in the way they are worded. They deal with procedures that the facility has for where truck/driver will be held while they are waiting until they are “properly vetted and approved”. One question uses the term ‘staging’ and the other uses ‘sequestering’. While there are no explanations for the differences I would assume that ‘staging’ means a holding location outside of the security perimeter while staging means an area within the security perimeter. The final question in this section is oddly worded which makes it difficult to determine how to answer the question. It reads:
Procedure for… “Notifying and contacting local law enforcement depending on the identity of the driver and identity of the load.”
Presumably DHS is asking about a procedure for dealing with a driver/load that cannot be identified or vetted. This would mean that there is a serious suspicion that the driver is up to no good. Unless the facility security team has arrest authority (which would be unusual unless they are off-duty law enforcement personnel) the local law enforcement would have to be contacted to affect an arrest. Training Questions This is the first time that we have seen questions related to training in the SSP. It seems more than a little unusual since there is a complete RBPS (RPBS #11) dedicated to this subject. Additionally there appears to be a minor misprint in the Questions manual. The manual shows a list of training frequency questions followed by a typical question that would lead such a list of question. That question is:
“Does the facility require individuals granted unescorted accesses to the facility to attend security awareness training at the facility?”
Usually, such a qualifying question, if answered ‘No’ would remove the frequency questions from the SSP tool for that facility. Finding this question at the end of the section kind of defeats that purpose. These security awareness training questions ask how often the described training is conducted with responses of: monthly, quarterly, semi-annually, annually, biennially, triennially, never. All but the last question in the group asks about ‘recognizing and detecting’ a variety of threats, ranging from ‘explosive materials’ to ‘characteristics and behavioral patterns of persons who are likely to threaten security’. The last question in the section is the ‘odd man out’. Instead of ‘recognizing and detecting’ it asks about “general techniques used to circumvent security measures?” While it is slightly different from the other questions in the group it does provide some recognition of the fact that potential adversaries will be attempting to subvert or by-pass facility security procedures. Background Investigation Questions There is another set of questions that seems to be slightly out of place in the RBPS. They deal with background investigation; an area that will certainly be dealt with in more detail in RBPS #12, Personnel Surety. This final section in RBPS #6 has three questions requiring a ‘Yes’/‘No’ response. Adequacy of Procedures As noted about there are a number of questions in this RBPS section that ask if the facility has a procedure to deal with ‘X’. The answers to such question are invariably ‘Yes’/‘No’, but anyone that has ever worked with regulatory agencies knows that there may be along way between having a procedure and having an ‘acceptable’ procedure. At this point DHS in the CFATS process DHS is not asking to see a copy of the procedure mentioned in the question; it is simply asking if the facility has a procedure. When the first inspector shows up after the SSP is approved to verify that the facility is actually implementing the approved SSP, the inspector will want to see copies of each of the procedures asked about in the SSP questions. Whether the facility has separate procedures for each of the security areas identified or one massive procedure is probably of little consequence. DHS is not going to have the manpower or time available to review each of the procedures in detail. With the wide variety of types and sizes of facilities covered by the CFATS regulations each of these procedures will be unique and it would be way too time consuming to do an in depth review either at the facility or back at the ‘office’. What I would not be surprised to see is DHS developing at some time in the future would be ‘procedure’ tools under CFATS to help them do a more detailed evaluation of procedures. They would be the same type answer the questions and fill in the blank type tools that have become so familiar to CSAT users.

Friday, July 10, 2009

RBPS Guidance – RBPS #6 Theft or Diversion

This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the: Risk-Based Performance Standards Guidance Document RBPS Guidance – Getting Started RBPS Guidance – RBPS #1 Restrict Area Perimeter RBPS Guidance – RBPS #2 Secure Site Assets RBPS Guidance – RBPS #3 Screen and Control Access RBPS Guidance – RBPS #4 Deter, Detect and Delay RBPS Guidance – RBPS #5 Shipping Receipt and Storage This posting deals with the provisions of risk-based performance standard #6 and the prevention of the theft or diversion of ‘potentially dangerous chemicals’. The opening paragraph of this RBPS section explains that potentially dangerous chemicals include: “chemical weapons, chemical weapons precursors, explosives, explosive precursors, or other chemicals of interest [emphasis added] that could be used to inflict harm at a facility or off-site” (pg 64). If there are no theft/diversion COI at the facility, no special effort would be required to address this standard. Security Measures The first class of security measures discussed in this RBPS is Inventory Control. The text for the description is practically speaking a word-for-word copy of the similar section in RBPS #5. Interestingly there is no discussion of product stewardship or ‘know-your-customer’ programs in the discussion of security measures for this RBPS. Both would contribute the same benefits seen in RBPS #5. A number of procedural techniques are discussed in this area that can be employed to help deter, detect and delay the theft and diversion of these dangerous chemicals. Most of the procedures have already been discussed in somewhat more detail in earlier standards. The one new measure mentioned here is the use of a two-man rule. This technique requires that areas where the dangerous chemicals are stored may not be entered by just one person. This is based on the concept familiar to the nuclear weapons security community that it is more difficult to suborn two people than just one. This measure would be appropriate where small man-portable containers of the most dangerous chemicals, chemical weapons, are stored. Finally, the Guidance document looks at physical security measures that can be used to protect theft/diversion COI. Two categories included in this discussion, monitoring storage locations and inspecting vehicles leaving the facility were discussed in some detail in earlier standards and Appendix C. The other, briefly covered, technique in this area is the protection of man-portable containers locks and chains as well using movement sensors on individual containers. I was surprised that the use of RFID tags on containers was not identified here. Metrics This metric provides an excellent example of how DHS intends that the escalating risk should met by increasing security. The basic summary metric ‘requirements’ for Tier 4 state that the facility “has security measures intended to deter theft or diversion of potentially dangerous chemicals”. The Tier 3 requirements add that those measures would “reduce the likelihood” of theft/diversion. Tier 2 would add that the facility has ‘multiple’ security measures that “are effective in deterring” theft/diversion while Tier 1 facilities would have multiple ‘vigorous’ security measures that are “extremely effective” in deterring the theft/diversion of those COI. There are a large number of sub-metrics for this standard. In fact, the only RBPS with more sub-metrics is RBPS #8, Cyber Security. Those sub-metrics are:
Metric 6.1 – Restricted Access to Potentially Dangerous Chemicals Metric 6.2 – “Know-Your-Customer” Provisions Metric 6.3 – Background Checks Metric 6.4 – Monitoring Potentially Dangerous Chemicals Metric 6.5 – Physical Security of Potentially Dangerous Chemicals Metric 6.6 – Vehicular Access Metric 6.7 – Vehicle Inspections Metric 6.8 – Inventory Control Metric 6.9 – Tamper- Evident Devices Metric 6.10 - Cyber Security for Potentially Dangerous Chemicals
While most of these metrics are straight forward and many are covered in previous standards it is disturbing that most received no discussion what so ever in the ‘security measures’ discussion in this section of the Guidance document. For example the RFID tags that I mentioned earlier are found in Metric 6.4 for Tier 1 and 2 facilities as a suggested security measure. Another example is that the cyber security measures in 6.10 that are not mentioned anywhere in this RBPS. While the ‘requirement’ for all Tiers that they implement “appropriate cyber security measures and procedures for business systems that manage the ordering and/or shipping of potentially dangerous chemicals” seems to be fairly straight forward the additional requirement to protect “any other cyber systems that contain personally identifiable information for those individuals who manage critical business systems or who could be exploited to steal or divert potentially dangerous chemicals” probably requires some explanation. There is one metric that will be controversial, even though it was briefly mentioned in the earlier discussion. Metric 6.3 has a single ‘standard’ for all four tiers. It includes the suggestion that drivers “transporting potentially dangerous chemicals are issued facility badges subsequent to third-party verification of background suitability”. This certainly makes sense for facilities that employ their own drivers or perhaps for those that employ a ‘captive’ trucking company to make their deliveries. Most facilities, however, will not fall into this category. One simple technique for complying with this ‘requirement’ is for the company to require that all drivers picking up loads at the facility must have a TSA issued Transportation Workers Identification Credential (TWIC). Facilities located near ports may have an easier time getting this accepted in transportation contracts. Facilities located far from port facilities will have a difficult time employing this technique, since there is unlikely to be a significant pool of driver’s with a TWIC. There are two sub-metrics that have a big ‘N/A’ for one or more Tiers. Metric 6.7 has an ‘N/A’ for Tier 4 and Metric 6.9 has the same for Tiers 3 and 4. These ‘N/A’s may provide some insight into how DHS has made their Tier rankings. I would expect that the ‘N/A’ for vehicle inspections indicates that DHS only put facilities with theft/diversion chemicals into this Tier if they did not ship those COI. The lack of requirements for tamper resistant valves on tank trucks for Tiers 3 and 4 indicates that only facilities that do not ship theft/diversion chemicals in bulk are assigned to those Tiers.
 
/* Use this with templates/template-twocol.html */