Yesterday I noted that the ISCD folks at DHS had removed the CSAT SSP Edit Process User Guide from their CFATS Knowledge Center web page and that the link on their CSAT SSP web page for that document was dead. I also complained that there was no notice that it had been removed or why. Today the Knowledge Center web page has a note in the ‘Latest News’ section that the link had been restored to the User Guide.
There is still no explanation for the reason for the disappearance, but they did provide a note that it had been restored. The explanation for the old change is really only of historical significance. The fact that they noted it’s restoration in the ‘Latest News’ section of the page shows a renewed understanding of the necessity of pointing out these things. Few people are going to review this site in the detail that I do everyday, so this change would have gone unnoticed for the most part.
Friday, February 4, 2011
S 234 Introduced – Pipeline Safety
Last week Senators Feinstein and Boxer (D,CA) introduced S 234, the Strengthening Pipeline Safety and Enforcement Act of 2011. This is a wide ranging upgrade of various sections of the pipeline safety laws, but it does not address any of the emergency planning and communications issues identified as a result of the San Bruno gas pipeline explosion from last year. In that respect this is not a companion bill to HR 22, but more of a complimentary bill, though there is some overlap in provisions concerning pipeline inspections.
I am kind of surprised that this bill completely passes on the issues of emergency planning and hazard communication. Both areas have been clearly identified as problem areas in pipeline regulation by the results of the San Bruno incident. I would like to think that Sen. Boxer’s Environment and Public Works Committee would correct this deficiency in the hearing and mark-up process.
Increased Enforcement
Probably the most important part of this bill (§3) from an enforcement perspective is the increase in the number of PHMSA personnel to enforce pipeline safety regulations. The bill would add 100 full-time positions over the next four years to the agency for pipeline safety activities. Unfortunately, the increase in the number of pipeline inspectors will only be a relatively small part of the new positions. Most of the new positions will provide the technical, legal, and administrative support needed for enforcement activities.
Requires New Safety Regulations
The bill would require a number of new regulations to be developed by PHMSA. The new regulations would address:
The legislation would expand the coverage of existing regulations by:
Provisions in this bill (§4) would increase the maximum civil penalties for the most serious violations to $250,000 per violation per day up to a maximum of $2.5 million for a related series of violations. The same section also authorizes the imposition of civil penalties for obstructing or preventing the Department from conducting investigations or inspections under the pipeline safety rules.
The Secretary would be authorized by this bill to collect fees to recover the costs of conducting design reviews for new pipelines. Those fees would be placed into a “Pipeline Safety Design Review Fund”. Other fees would be authorized for the processing of pipeline safety waivers (for the Pipeline Safety Special Permit Fund).
Hazardous Liquid Pipeline Study
Section 18 of the bill would require the almost mandatory study that Congress is so enamored with. In this case the Secretary is required to conduct a study of:
While it is not specifically stated in the bill, it would seem fairly obvious to me that the drafters of this bill were looking to the results of this study to justify Congressional action to regulate such pipelines.
I am kind of surprised that this bill completely passes on the issues of emergency planning and hazard communication. Both areas have been clearly identified as problem areas in pipeline regulation by the results of the San Bruno incident. I would like to think that Sen. Boxer’s Environment and Public Works Committee would correct this deficiency in the hearing and mark-up process.
Increased Enforcement
Probably the most important part of this bill (§3) from an enforcement perspective is the increase in the number of PHMSA personnel to enforce pipeline safety regulations. The bill would add 100 full-time positions over the next four years to the agency for pipeline safety activities. Unfortunately, the increase in the number of pipeline inspectors will only be a relatively small part of the new positions. Most of the new positions will provide the technical, legal, and administrative support needed for enforcement activities.
Requires New Safety Regulations
The bill would require a number of new regulations to be developed by PHMSA. The new regulations would address:
• Required installation and use in pipelines of remotely or automatically controlled valves (§6);Expand Coverage of Current Regulations
• Standards for natural gas pipeline leak detection (§7);
• Verification of maximum allowable operating pressure (§8); and
• Minimum safety standards for transportation of carbon dioxide by pipeline (§13);
The legislation would expand the coverage of existing regulations by:
• Changing requirements for designating ‘high consequence areas’(§9);Expand Fines and Fees
• Including coverage of ‘gas gathering lines’ and ‘hazardous liquid gathering lines’ (§10);
• Including coverage of ‘non-petroleum fuels’ and ‘biofuels’ as hazardous liquids (§11)
Provisions in this bill (§4) would increase the maximum civil penalties for the most serious violations to $250,000 per violation per day up to a maximum of $2.5 million for a related series of violations. The same section also authorizes the imposition of civil penalties for obstructing or preventing the Department from conducting investigations or inspections under the pipeline safety rules.
The Secretary would be authorized by this bill to collect fees to recover the costs of conducting design reviews for new pipelines. Those fees would be placed into a “Pipeline Safety Design Review Fund”. Other fees would be authorized for the processing of pipeline safety waivers (for the Pipeline Safety Special Permit Fund).
Hazardous Liquid Pipeline Study
Section 18 of the bill would require the almost mandatory study that Congress is so enamored with. In this case the Secretary is required to conduct a study of:
“…the transportation of non-petroleum hazardous liquids by pipeline for the purpose of identifying the extent to which pipelines are currently being used to transport non-petroleum hazardous liquids, such as chlorine, from chemical production facilities across land areas not owned by the producer that are accessible to the public.”The purpose of the study is to determine how well the States are regulating these pipelines. State regulation would normally be expected since these relatively short pipelines between producer and user of these hazardous chemicals rarely cross State lines. Congress has broad authority to regulate interstate commerce, but would have to show some great need to protect safety and/or security to regulate purely intra-state commerce.
While it is not specifically stated in the bill, it would seem fairly obvious to me that the drafters of this bill were looking to the results of this study to justify Congressional action to regulate such pipelines.
Thursday, February 3, 2011
SSP Edit Manual Missing
The link to the CSAT SSP Edit Process User Guide has been removed from the CFATS Knowledge Center web page, but no explanation is given nor is there any mention that it is no longer listed. The manual is still listed on the CSAT Site Security Plan web page but the link returns a ‘404 Error – The requested page was not found’ error message. (NOTE: Changed title to make subject clearer - 02-03-11 11:30 pm EST)
I understand that problems crop up in manuals from time to time, but if this manual is no longer useful, the chemical security community should be notified. I would bet that the problem (assuming there is one) is relatively limited, so most of the information would be useable. Unless, of course, the edit capability for the SSP has been removed from CSAT.
Of course, if the edit function were disabled, then one would suspect that the ‘Latest News’ section on the CFATS Knowledge Center page would no longer list the note about the SSP-Edit function, but that note is still there, except that the last sentence has been removed, the sentence referring to the User Guide.
Curiouser and curiouser…
I understand that problems crop up in manuals from time to time, but if this manual is no longer useful, the chemical security community should be notified. I would bet that the problem (assuming there is one) is relatively limited, so most of the information would be useable. Unless, of course, the edit capability for the SSP has been removed from CSAT.
Of course, if the edit function were disabled, then one would suspect that the ‘Latest News’ section on the CFATS Knowledge Center page would no longer list the note about the SSP-Edit function, but that note is still there, except that the last sentence has been removed, the sentence referring to the User Guide.
Curiouser and curiouser…
CFATS and Shutdowns
There is an interesting discussion on the Cyber Security in Real-Time Systems group on LinkedIn. It deals with a British Airways employee that got the job at BA to further his particular terrorist aims. Which of course leads to the issue of ‘insider attacks’, though to my mind, this is more of an infiltration attack’ but that is another issue. As with many discussions that I get involved in a CFATS issue was raised. In particular Joel Langill raised the following:
Shutdowns
Many large industrial facilities that run essentially 24-7 have to shut down the facility periodically for scheduled maintenance of their equipment. This is also the time for installing new equipment. Production employees are typically given block vacations. A huge crew of construction and maintenance folks takes over the facility, working around the clock to get the plant turned around. Two terms are usually used to describe this production hiatus: shutdown or turnaround.
Now I have never worked in a facility that did this sort of operation, but I have a number of friends that do turnaround work and a number of customers of the chemical companies that I worked for had these regularly scheduled events. I think Joel’s comment implies that the hazardous chemicals are removed from the site during the shutdown, but I’m not sure that that is true in very many cases. Certainly the companies that I worked for never had to schedule post-turnaround shipments and we never took product back at the start of a customer’s turnaround.
For the sake of this discussion, let’s assume that some facilities will remove DHS chemicals of interest (COI) from the facility prior to starting a turnaround and others won’t. So, that gives us two cases to look at from CFATS perspective.
Background Checks
DHS has made it clear that they expect everyone who has unescorted access to critical assets at a high-risk chemical facility to undergo some sort of background check including (eventually) a review against the TSA’s Terrorist Screening Data Base (TSDB). We’re not sure yet (DHS personnel surety program is still in development) whether the facility must do the check or whether the contractor must do the checks for their employees working on a covered site.
Since a wide variety of contract personnel will be on site and most employees will not, there is little chance of having contract personnel escorted by covered employees. We must assume that, everything else being equal, all contractors on-site during a turnaround will have had to undergo an appropriate background screening, including TSDB (if/when DHS gets that program up and runnign).
Facilities Where COI is Not Removed
If the COI remain on-site during a turnaround, there is no question that the facility remains a covered facility with all the SSP requirements in place. In fact, it would seem to me that this is one of those periods of increased risk (because of the number of people working on site with all of the confusion that that brings) that is supposed to be addressed by RBPS #14.
Facilities are going to have to have a written plan in place for the security measures that will be instituted and modified during the turnaround. This would include provisions for the requirement to perform and document background checks, including TSDB, for most contractors. It would also include provisions for escort requirements for those without such background checks (and there will inevitably be some). Both classes of contractor employees would have to be clearly identifiable to security personnel and facility employees working on site.
Critical assets will have to be divided into at least two separate groups; those that are easy to surreptitiously sabotage (control systems come immediately to mind) and those that their sabotage is harder to disguise. The former assets will require additional security measures like requiring escort by facility personnel for any contractors working in the area. For contractors/vendors directly working on those assets, the escort must be fully knowledgeable in the operation of the equipment to be able to detect more subtle sabotage efforts.
Additional security personnel are almost certainly going to be necessary. The flow of personnel and deliveries through the gates will increase, and it would not be unusual for the contractors to use additional gates that are normally kept closed. The number and frequency of roving patrols will probably need to be increased to deal with the number of people wandering around the facility to ensure that they don’t stumble into areas where they don’t belong.
Even the number of people monitoring video surveillance systems will probably need to increase, even for facilities using automated surveillance monitoring. The large increase in the number of people moving around and the unusual areas in which they will be working will quickly overload normal monitoring capabilities.
Security training for all of the temporary folks working on site cannot be overlooked. The standard awareness training given to all employees will be necessary and the identification of critical assets and the rules associated with their access will need to be clearly covered. The added security personnel will need to be trained and the entire security force will need additional training on the changes to the security program required by the turnaround.
One final note; if the turnaround plan for RBPS #14 was not included in the approved SSP, it will have to be approved by DHS before it can be implemented. I don’t believe that DHS has a formal process yet for approving these types of temporary additions to an approved SSP, so the best bet would be to contact the Help Desk early in the planning process. For facilities without an approved SSP (and that is all but at most four facilities as I write this) a technical edit may be the easiest way to add the RPBS 14 changes. One should expect that the approval process (at least for the foreseeable future) will be a time consuming process.
COI Removed from Site
Joel’s comments assume (I think; I’m making an assumption about Joel’s assumptions, always dangerous) that the COI are removed from the site before the shutdown begins. The normal person might jump to the conclusion that that would result in the removal of the site from the high-risk chemical facility list; that may be a very dangerous assumption.
A number of facilities have been removed from CFATS coverage because they removed COI from the facility, or even just reduced the maximum inventory of the COI by some significant amount. If the facility has not been given their final tier assignment (had their SVA approved by DHS) the process is fairly straight forward, wait at least 60 days after the change has been made and submit a new Top Screen. When DHS reviews that new Top Screen they will either remove the facility from the CFATS list, reduce the preliminary tier ranking, or do nothing.
That “60 days” is a key element here. The Top Screen requires a facility to report the highest inventory in the last 60-days. This was included to take into account the vagaries of inventory management and reduce the number of Top Screen submissions required to keep the CFATS system up-to-date. It is obvious then that the Top Screen route will not be applicable to a normal shutdown, most shutdowns are completed in well under 60 days.
For facilities that have received their ‘final’ tiering notice (have at least started their SSP clock) the whole situation gets a great deal more complicated. While a Top Screen may be submitted, DHS has made it fairly clear that they will require a detailed explanation of why the change is being made and will conduct a formal review of the change. I don’t believe that they have specifically addressed the shutdown issue, but they certainly haven’t done so publicly.
I don’t suspect that DHS would allow for a total suspension of SSP requirements for a temporary period when there are no COI on site. I would bet that if they were told that the facility would be starting up after the shutdown period, they would maintain the facility on their list of covered facilities. I don’t believe that they would even temporarily lower the tier ranking. In fact, I would nearly wager money (something I don’t do, there’s a story about a horse race and the favorite breaking a leg 4 lengths in front on the home stretch that I won’t go into here) that DHS would require an RPBS #14 plan for such an eventuality before even considering allowing a reduction in security requirements.
The problem is that if you substantially reduce the security requirements, you make it easier for someone to sabotage the facility for later activation. Facilities with just theft/diversion COI this is not as applicable, but for any release COI facilities it would be too easy to hide a device (or virtual device in cyber systems) that would be difficult or impossible to detect prior to start up.
Shutdown Security Procedures Required
Adequate security procedures, including background checks are going to be necessary for high-risk facilities during shutdown, even if there are no COI on site. The need is there to prevent the initiation of a subtle, delayed attack on the facility during the shutdown that would culminate only after the COI returns. A detailed RBPS 14 shutdown security plan will need to be developed whether or not COI will be present.
“One aspect that sticks in my head is that this standard does not seem to specifically address the situation when the facility (or process unit) is shutdown, isolated and decontaminated for activities such as a scheduled maintenance turnaround or outage. This is when you have a lot of contractors within the facility, and reasonable exposure to equipment. I also do not think that during this time, background checks are required since the chemical threat is actually absent during the turnaround.”I made a brief reply on the discussion page, but I thought that a more detailed discussion would be appropriate here. To be sure I did a brief blog post on this a couple of years ago, but we know more about CFATS now so it is time to revisit the issue.
Shutdowns
Many large industrial facilities that run essentially 24-7 have to shut down the facility periodically for scheduled maintenance of their equipment. This is also the time for installing new equipment. Production employees are typically given block vacations. A huge crew of construction and maintenance folks takes over the facility, working around the clock to get the plant turned around. Two terms are usually used to describe this production hiatus: shutdown or turnaround.
Now I have never worked in a facility that did this sort of operation, but I have a number of friends that do turnaround work and a number of customers of the chemical companies that I worked for had these regularly scheduled events. I think Joel’s comment implies that the hazardous chemicals are removed from the site during the shutdown, but I’m not sure that that is true in very many cases. Certainly the companies that I worked for never had to schedule post-turnaround shipments and we never took product back at the start of a customer’s turnaround.
For the sake of this discussion, let’s assume that some facilities will remove DHS chemicals of interest (COI) from the facility prior to starting a turnaround and others won’t. So, that gives us two cases to look at from CFATS perspective.
Background Checks
DHS has made it clear that they expect everyone who has unescorted access to critical assets at a high-risk chemical facility to undergo some sort of background check including (eventually) a review against the TSA’s Terrorist Screening Data Base (TSDB). We’re not sure yet (DHS personnel surety program is still in development) whether the facility must do the check or whether the contractor must do the checks for their employees working on a covered site.
Since a wide variety of contract personnel will be on site and most employees will not, there is little chance of having contract personnel escorted by covered employees. We must assume that, everything else being equal, all contractors on-site during a turnaround will have had to undergo an appropriate background screening, including TSDB (if/when DHS gets that program up and runnign).
Facilities Where COI is Not Removed
If the COI remain on-site during a turnaround, there is no question that the facility remains a covered facility with all the SSP requirements in place. In fact, it would seem to me that this is one of those periods of increased risk (because of the number of people working on site with all of the confusion that that brings) that is supposed to be addressed by RBPS #14.
Facilities are going to have to have a written plan in place for the security measures that will be instituted and modified during the turnaround. This would include provisions for the requirement to perform and document background checks, including TSDB, for most contractors. It would also include provisions for escort requirements for those without such background checks (and there will inevitably be some). Both classes of contractor employees would have to be clearly identifiable to security personnel and facility employees working on site.
Critical assets will have to be divided into at least two separate groups; those that are easy to surreptitiously sabotage (control systems come immediately to mind) and those that their sabotage is harder to disguise. The former assets will require additional security measures like requiring escort by facility personnel for any contractors working in the area. For contractors/vendors directly working on those assets, the escort must be fully knowledgeable in the operation of the equipment to be able to detect more subtle sabotage efforts.
Additional security personnel are almost certainly going to be necessary. The flow of personnel and deliveries through the gates will increase, and it would not be unusual for the contractors to use additional gates that are normally kept closed. The number and frequency of roving patrols will probably need to be increased to deal with the number of people wandering around the facility to ensure that they don’t stumble into areas where they don’t belong.
Even the number of people monitoring video surveillance systems will probably need to increase, even for facilities using automated surveillance monitoring. The large increase in the number of people moving around and the unusual areas in which they will be working will quickly overload normal monitoring capabilities.
Security training for all of the temporary folks working on site cannot be overlooked. The standard awareness training given to all employees will be necessary and the identification of critical assets and the rules associated with their access will need to be clearly covered. The added security personnel will need to be trained and the entire security force will need additional training on the changes to the security program required by the turnaround.
One final note; if the turnaround plan for RBPS #14 was not included in the approved SSP, it will have to be approved by DHS before it can be implemented. I don’t believe that DHS has a formal process yet for approving these types of temporary additions to an approved SSP, so the best bet would be to contact the Help Desk early in the planning process. For facilities without an approved SSP (and that is all but at most four facilities as I write this) a technical edit may be the easiest way to add the RPBS 14 changes. One should expect that the approval process (at least for the foreseeable future) will be a time consuming process.
COI Removed from Site
Joel’s comments assume (I think; I’m making an assumption about Joel’s assumptions, always dangerous) that the COI are removed from the site before the shutdown begins. The normal person might jump to the conclusion that that would result in the removal of the site from the high-risk chemical facility list; that may be a very dangerous assumption.
A number of facilities have been removed from CFATS coverage because they removed COI from the facility, or even just reduced the maximum inventory of the COI by some significant amount. If the facility has not been given their final tier assignment (had their SVA approved by DHS) the process is fairly straight forward, wait at least 60 days after the change has been made and submit a new Top Screen. When DHS reviews that new Top Screen they will either remove the facility from the CFATS list, reduce the preliminary tier ranking, or do nothing.
That “60 days” is a key element here. The Top Screen requires a facility to report the highest inventory in the last 60-days. This was included to take into account the vagaries of inventory management and reduce the number of Top Screen submissions required to keep the CFATS system up-to-date. It is obvious then that the Top Screen route will not be applicable to a normal shutdown, most shutdowns are completed in well under 60 days.
For facilities that have received their ‘final’ tiering notice (have at least started their SSP clock) the whole situation gets a great deal more complicated. While a Top Screen may be submitted, DHS has made it fairly clear that they will require a detailed explanation of why the change is being made and will conduct a formal review of the change. I don’t believe that they have specifically addressed the shutdown issue, but they certainly haven’t done so publicly.
I don’t suspect that DHS would allow for a total suspension of SSP requirements for a temporary period when there are no COI on site. I would bet that if they were told that the facility would be starting up after the shutdown period, they would maintain the facility on their list of covered facilities. I don’t believe that they would even temporarily lower the tier ranking. In fact, I would nearly wager money (something I don’t do, there’s a story about a horse race and the favorite breaking a leg 4 lengths in front on the home stretch that I won’t go into here) that DHS would require an RPBS #14 plan for such an eventuality before even considering allowing a reduction in security requirements.
The problem is that if you substantially reduce the security requirements, you make it easier for someone to sabotage the facility for later activation. Facilities with just theft/diversion COI this is not as applicable, but for any release COI facilities it would be too easy to hide a device (or virtual device in cyber systems) that would be difficult or impossible to detect prior to start up.
Shutdown Security Procedures Required
Adequate security procedures, including background checks are going to be necessary for high-risk facilities during shutdown, even if there are no COI on site. The need is there to prevent the initiation of a subtle, delayed attack on the facility during the shutdown that would culminate only after the COI returns. A detailed RBPS 14 shutdown security plan will need to be developed whether or not COI will be present.
Wednesday, February 2, 2011
Reader Comment – Cybersecurity Posters
Stephanie at Schweitzer Engineering Laboratories (SEL) left a brief comment on an earlier blog posting about cyber security posters. The earlier blog pointed viewers at some security awareness posters that SEL provided on their web site. Stephanie wanted to point out to readers of this blog that SEL had provided a new batch of posters available for free download at http://www.selinc.com/cybersecurity/posters/.
The folks at SEL have once again done an excellent job at developing these colorful posters. Putting copies of these posters in control rooms, break rooms and other areas where control system users congregate will help remind people of the important role they have in securing critical control systems.
Once again I want to congratulate SEL on the quality of these posters.
The folks at SEL have once again done an excellent job at developing these colorful posters. Putting copies of these posters in control rooms, break rooms and other areas where control system users congregate will help remind people of the important role they have in securing critical control systems.
Once again I want to congratulate SEL on the quality of these posters.
ICS-CERT Advisory for ClearSCADA
Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an advisory concerning multiple vulnerabilities in the Control Microsystems’ ClearSCADA software. The three vulnerabilities in multiple versions of the software have been addressed by the vendor.
The three vulnerabilities identified are:
ICS-CERT and Control Microsystems recommend the following mitigation measures (after appropriate system vulnerability review):
The three vulnerabilities identified are:
• Heap Overflow VulnerabilityThere are no known publicly available exploits for the first vulnerability, but there are tools available that could allow for an exploit of the other two vulnerabilities.
• Cross-site Scripting Vulnerabilities
• Insecure Web Authentication.
ICS-CERT and Control Microsystems recommend the following mitigation measures (after appropriate system vulnerability review):
• Upgrade older versions or install service packs (http://www.clearscada.com/services-support/software-updates/) for newer versions of this software.NOTE: See this post at DigitalBond.com for some interesting background on this advisory.
• Disable logons on ClearSCADA non-secure ports. Locate this setting under System Configuration => WebX in the server configuration window.
• Install a WebX security certificate from a trusted authority.
• Limit access to the server and server network to only trusted networks and users.
Tuesday, February 1, 2011
SIA CFATS Webinar
Last week the Security Industry Association held their Town Hall – CFATS Best Practices webinar that I had previously written about. I had a chance to watch this webinar and was favorably impressed (FULL DISCLOSURE: SIA waived their $35 non-member fee to allow me to participate). There were some minor technical issues (NOTE: to anyone presenting in such webinars via phone bridge; cell phones provide very broken audio; use a land-line please) but the information was very good. A copy of the slides is now available on-line.
DHS Presentation
I was slightly disappointed that DHS substituted Todd Klessman, the acting Branch Chief for the Policy and Programs Branch at ISCD for the advertised presentation by Sue Armstrong. Mr. Klessman did a fine job and I’m sure that the information presented did not change, but Ms Armstrong’s participation was advertised and, because of her position within NPPD, would have carried a stronger imprimatur; a minor disappointment that I quickly got over.
Mr. Klessman did provide an update on the status of the implementation of CFATS. Interestingly the number of CFATS covered facilities has dropped once again, to 4,755. Long time readers will remember that the initial number was more than 6,000. It would be interesting to have ISCD report on the reasons for the changes, how many were the results of deliberate changes in COI inventory to avoid regulation (and consequently reduce the potential threat to local communities) and how much was due to the current economic conditions. That information could have an impact on the (now muted) IST debate.
Mr. Klessman did touch briefly on the new Pre-Authorization Inspection (PAI) program. It’s not actually a new program as it was begun last January. I’m calling it new here because it was not part of the original CFATS implementation plan. It was a response to the less than adequate information being included in SSP submissions. DHS is not actually blaming facilities for the inadequate information, which is good since it appears to be more the result of a shortcoming in the SSP Tool in CSAT. I’ll talk more about that later.
The DHS provided data shows that ISCD Chemical Facility Security Inspectors (CFSI) have conducted only 150 PAI and a miniscule 4 Authorization Inspections. This slow progress in the implementation of the CFATS program is due to a number of issues (in my opinion, Mr. Klessman did not make any excuses in his presentation), including under-estimation of the complexity of the SSP submission and inspection processes; and the slow funding process for new hires (like the three continuing resolutions for FY 2011 and still no action on a final budget).
Mr. Klessman also vaguely (no details or firm mention of any expected dates – vaguely) mentioned a number of other CFATS related programs, including:
The two corporate presenters (Gregory Eatmon, Baker Hughes; and Clyde Miller, BASF) both gave excellent presentations. Mr. Eatmon gave an excellent overview of the PAI process noting that the PAI’s that his facilities have seen were three-person teams that were on-site for three days. He also noted that once the PAI was over, DHS unlocked the SSP submission for a technical edit and gave the facility 45 days to re-submit the SSP.
Both presenters had good things to say about the professionalism of the CFSI, mentioning how helpful they were in explaining the SSP deficiencies that resulted in the PAI and helping the facility to understand how those could be corrected.
The most important point that both presenters made (and I have heard elsewhere) is that the reason for the lack of information included in the SSP submission was that Submitters were checking the provided ‘Yes’ boxes where appropriate and moving on. What DHS apparently really needs to have done so that they can get the information necessary to properly evaluate the SSP is for the facility to ignore the ‘Yes’ box, checking instead the ‘Other’ box and then explaining in detail what the security measure entails at their facility. You have to ignore the ‘Yes’ box because the text boxes only become accessible if you check the ‘Other’ box.
So, apparently the addition of the PAI process is not a result of facility problems but an inadequately designed SSP. That is not necessarily a slam against the SSP designers, first design passes at complex tools like CSAT are seldom the most effective. I am disappointed that DHS has not made this problem clearer earlier. They could have saved themselves a great deal of time and effort if they had gone back and modified the programming for those text boxes, making them available at all times. Then they would have been able to tell the CFATS community to go back and re-do their SSP by adding supporting details in the narrative box for all ‘Yes’ answers.
To be fair, the SSP is a very complex piece of software and DHS-ISCD does have limited resources. Even so, in my not-so-humble opinion that would have been the most efficient way of doing things. As it is the almost 4,000 SSP’s submitted will all have this problem. DHS needs to rely on more than just this type webinar to get the word out to all of the affected facilities to communicate this short-coming to the regulated community.
Future SIA Webinars
According to an email that I received from SIA, they are planning a couple more CFATS related seminars. At least one of these will address RBPS #8, Cyber Security. I have yet to hear anything about how the CFSI are dealing with ICS security issues, so I look forward to that.
DHS Presentation
I was slightly disappointed that DHS substituted Todd Klessman, the acting Branch Chief for the Policy and Programs Branch at ISCD for the advertised presentation by Sue Armstrong. Mr. Klessman did a fine job and I’m sure that the information presented did not change, but Ms Armstrong’s participation was advertised and, because of her position within NPPD, would have carried a stronger imprimatur; a minor disappointment that I quickly got over.
Mr. Klessman did provide an update on the status of the implementation of CFATS. Interestingly the number of CFATS covered facilities has dropped once again, to 4,755. Long time readers will remember that the initial number was more than 6,000. It would be interesting to have ISCD report on the reasons for the changes, how many were the results of deliberate changes in COI inventory to avoid regulation (and consequently reduce the potential threat to local communities) and how much was due to the current economic conditions. That information could have an impact on the (now muted) IST debate.
Mr. Klessman did touch briefly on the new Pre-Authorization Inspection (PAI) program. It’s not actually a new program as it was begun last January. I’m calling it new here because it was not part of the original CFATS implementation plan. It was a response to the less than adequate information being included in SSP submissions. DHS is not actually blaming facilities for the inadequate information, which is good since it appears to be more the result of a shortcoming in the SSP Tool in CSAT. I’ll talk more about that later.
The DHS provided data shows that ISCD Chemical Facility Security Inspectors (CFSI) have conducted only 150 PAI and a miniscule 4 Authorization Inspections. This slow progress in the implementation of the CFATS program is due to a number of issues (in my opinion, Mr. Klessman did not make any excuses in his presentation), including under-estimation of the complexity of the SSP submission and inspection processes; and the slow funding process for new hires (like the three continuing resolutions for FY 2011 and still no action on a final budget).
Mr. Klessman also vaguely (no details or firm mention of any expected dates – vaguely) mentioned a number of other CFATS related programs, including:
● Appendix A ReviewIndustry Presenters
● CSAT Tool Updates
● CFATS/MTSA Harmonization
● Ag Facility CFATS ‘Temporary’ Exemption
● Personnel Surety Program
The two corporate presenters (Gregory Eatmon, Baker Hughes; and Clyde Miller, BASF) both gave excellent presentations. Mr. Eatmon gave an excellent overview of the PAI process noting that the PAI’s that his facilities have seen were three-person teams that were on-site for three days. He also noted that once the PAI was over, DHS unlocked the SSP submission for a technical edit and gave the facility 45 days to re-submit the SSP.
Both presenters had good things to say about the professionalism of the CFSI, mentioning how helpful they were in explaining the SSP deficiencies that resulted in the PAI and helping the facility to understand how those could be corrected.
The most important point that both presenters made (and I have heard elsewhere) is that the reason for the lack of information included in the SSP submission was that Submitters were checking the provided ‘Yes’ boxes where appropriate and moving on. What DHS apparently really needs to have done so that they can get the information necessary to properly evaluate the SSP is for the facility to ignore the ‘Yes’ box, checking instead the ‘Other’ box and then explaining in detail what the security measure entails at their facility. You have to ignore the ‘Yes’ box because the text boxes only become accessible if you check the ‘Other’ box.
So, apparently the addition of the PAI process is not a result of facility problems but an inadequately designed SSP. That is not necessarily a slam against the SSP designers, first design passes at complex tools like CSAT are seldom the most effective. I am disappointed that DHS has not made this problem clearer earlier. They could have saved themselves a great deal of time and effort if they had gone back and modified the programming for those text boxes, making them available at all times. Then they would have been able to tell the CFATS community to go back and re-do their SSP by adding supporting details in the narrative box for all ‘Yes’ answers.
To be fair, the SSP is a very complex piece of software and DHS-ISCD does have limited resources. Even so, in my not-so-humble opinion that would have been the most efficient way of doing things. As it is the almost 4,000 SSP’s submitted will all have this problem. DHS needs to rely on more than just this type webinar to get the word out to all of the affected facilities to communicate this short-coming to the regulated community.
Future SIA Webinars
According to an email that I received from SIA, they are planning a couple more CFATS related seminars. At least one of these will address RBPS #8, Cyber Security. I have yet to hear anything about how the CFSI are dealing with ICS security issues, so I look forward to that.
Subscribe to:
Posts (Atom)