1 Disclaimer The following information was presented by Matthew Bettridge of the Chemical Security Compliance Division of DHS on June 12, 2007 at the 2007.

Slides:



Advertisements
Similar presentations
COSO I COSO II. Meycor COSO, a Comprehensive Solution for Enterprise Risk Management (ERM)
Advertisements

Minnesota Port and Waterway Security Working Group Meeting April 12, 2012.
Department of Homeland Security Site Assistance Visit (SAV)
- 1 - Defense Security Service Background: During the Fall of 2012 Defense Security Service will be integrating ISFD with the Identity Management (IdM)
Information Risk Management Key Component for HIPAA Security Compliance Ann Geyer Tunitas Group
Protected Critical Infrastructure Information (PCII) Program
Securing the Chemical Sector: An Outline of the Chemical Facility Anti-Terrorism Standards (CFATS) Program May 2008.
Presented at the 2007 CUPA Conference by SRM Associates, Inc. PO Box Temecula, CA (951) Chemical Site Security and Chemical.
Chemical Facility Anti-terrorism Standards (CFATS) Compliance Plan Overview prepared by The Office of Environmental Health & Safety 1.
Conversation on the Chemical Facility Anti-Terrorism Standards (CFATS) and Critical Infrastructure Protection Chemical-Terrorism Vulnerability Information.
National Protection and Programs Directorate Department of Homeland Security The Office of Infrastructure Protection Cybersecurity Brief [Date of presentation]
Planning Fundamentals  Include participation from all stakeholders in the community.  Use problem-solving process to help address the complexity and.
1 Disclaimer The following information was presented by Andrew Levy of the Office of General Counsel of DHS on June 12, 2007 at the 2007 Chemical Sector.
Chemical Security Anti-Terrorism Standards: Key questions raised by the Department of Homeland Security’s New Regulations Barry M. Hartman K&L Gates Washington,
Jack Harrah Governor’s Office of Emergency Services
Environmental Management Systems An Overview With Practical Applications.
Business Crisis and Continuity Management (BCCM) Class Session
GSA Expo 2009 Impact of Secure Flight Program on DoD Travel Mr. George Greiling GSA Expo June 2009.
Creating a Single Sign On Account. To create a Single Sign On ID please visit and select the option to create a new account.
Securing the Chemical Sector: An Overview of the Chemical Facility Anti-Terrorism Standards August 29, 2007 Ronald E. Miller Inspector.
UNCLASSIFIED User Guide Applicant. UNCLASSIFIED Table of Contents What is the SAFETY Act? Applicant Guide Help Desk.
Authorization and Inspection of Cyclotron Facilities Inspections.
Basics of OHSAS Occupational Health & Safety Management System
Independent School Process Agency of Education State Board of Education Presentation March 25, 2014.
U.S. Department of Homeland Security Chemicals of Interest Anti-terrorism Standard.
Policy and Procedure Inspector Christian Ellis. Policy Statement About Policy It is best practice to have up to date, clear and standardised policies.
ONLINE FILING WORKSHOP Presented By: The Indiana Lobby Registration Commission 1.
Enforcement Overview Melissa Cordell, P.G. Enforcement Division Office of Compliance and Enforcement Texas Commission on Environmental Quality Environmental.
1 ITSS This overview contains three main sections How to Register for ITSS Application Access Contains guidance on how to create your profile and access.
NIST Special Publication Revision 1
AUDITS What you should know - a campus perspective. Franz Lozano Director/Budget Officer (former Internal Auditor) San Francisco State University Academic.
Health Infrastructure Renewal Fund HIRF Program LHIN and Hospital Teleconference October 25, 2013.
Decision making process / basic options assessment Mercury Storage and Disposal LAC Two Countries Project Gustavo Solórzano Ochoa, Consultan t Montevideo,
Company: Account Requests FMCSA Portal Prioritization Phase I Release, December 2010 v1.4.
DHS Anti-Terrorism Standards for Chemical Facilities Steven Burns A&WMA Southern Section 2007 Annual Meeting and Technical Conference August 9, 2007.
Module 9 Configuring Messaging Policy and Compliance.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
CFATS Aka: Chemical Facility Anti-terrorism Standards Clyde D. Miller Director, Corporate Security June 9, 2010.
Risk Assessment and Management. Objective To enable an organisation mission accomplishment, by better securing the IT systems that store, process, or.
WATER, WATER EVERYWHERE? The Water Resources Management Committee of the American Public Works Association.
The Basics of the Effort Certification and Reporting Technology (ECRT) System.
Module 9 Configuring Messaging Policy and Compliance.
College Reviews An Overview Presented by Howard Lutwak, CIA Director of Internal Audit January 2004.
Chapter 11: Policies and Procedures Security+ Guide to Network Security Fundamentals Second Edition.
1 Washington State Critical Infrastructure Program “No security, No infrastructure” Infrastructure Protection Office Emergency Management Division Washington.
Online Loan Application CWSRF/DWSRF Project Information Form & SWIFT Abridged Application Quick Reference Guide 1.
IT Summit November 4th, 2009 Presented by: IT Internal Audit Team Leroy Amos Sue Ann Lipinski Suzanne Lopez Janice Shelton.
Global Field Operations From Vision to Value Cisco Confidential1© 2011 Cisco and/or its affiliates. All rights reserved. Access to PMC Partner Training.
Company LOGO. Company LOGO PE, PMP, PgMP, PME, MCT, PRINCE2 Practitioner.
Collecting Copyright Transfers and Disclosures via Editorial Manager™ -- Editorial Office Guide 2015.
Enforcement Overview Melissa Cordell, P.G. Enforcement Division Office of Compliance and Enforcement Texas Commission on Environmental Quality Environmental.
National Protection and Programs Directorate Department of Homeland Security The Office of Infrastructure Protection Chemical Facility Anti-Terrorism Standards.
DHS/ODP OVERVIEW The Department of Homeland Security (DHS), Office for Domestic Preparedness (ODP) implements programs designed to enhance the preparedness.
Lowell Randel Global Cold Chain Alliance/ International Institute of Ammonia Refrigeration.
ABC-MAP Act 191 of 2014 September 16, 2016 Pennsylvania’s Prescription Drug Monitoring Program (PA PDMP)
Risks and Hazards to Consider Unit 3. Visual 3.1 Unit 3 Overview This unit describes:  The importance of identifying and analyzing possible hazards that.
Creating a new Central Data Exchange (CDX) Account (to access NetDMR)
REACH 2018 Find your co-registrants and prepare to register jointly.
ERO Portal Overview & CFR Tool Training
Creating a new Central Data Exchange (CDX) Account (to access NetDMR)
ETS Submission Process for New Project Applications
Chemical Facility Anti-terrorism Standards ((CFATS)
NERC Critical Infrastructure Protection Advisory Group (CIP AG)
To the ETS – Encumbrance Online Training Course
Securing the Chemical Sector:
Securing Critical Chemical Assets: The Responsible Care® Security Code
To the ETS – Encumbrance Online Training Course
Local Public Health Implementation Project Technical Assistance
Local Public Health Implementation Project Technical Assistance
Radiation Safety Information Management System (RASIMS)
Presentation transcript:

1 Disclaimer The following information was presented by Matthew Bettridge of the Chemical Security Compliance Division of DHS on June 12, 2007 at the 2007 Chemical Sector Security Summit in Falls Church, VA. The information contained in this presentation is for information only and should not be construed as complete for compliance purposes.

Chemical Security Assessment Tool (CSAT) June 2007 Overview Chemical Security Compliance Division Office of Infrastructure Protection National Protection and Programs Directorate

3 Chemical Security Assessment Tool (CSAT) Overview Chemical Security - The Mission Requirements in Developing the CSAT CSAT Process and Applications –User registration –Screening questionnaire (Top-Screen) –Security Vulnerability Assessment tool (SVA) –Site Security Plan (SSP) template Information Protection Status / Next Steps

4 Chemical Security – The Mission P.L requires the Department to regulate chemical facilities that present a high level of security risk with priority on highest risk facilities. The IFR must: –Identify “high security risk” facilities –Develop Risk Based Performance Standards (RBPS) for security at chemical facilities –Approve and disapprove SVA and SSP –Perform Inspections to confirm facility security is in accordance with SSP –Enforce facility compliance and seek remedies –Manage objections and appeals process –Receive, manage, store, and restrict access to Chemical-terrorism Vulnerability Information –Provide Consultations and Technical Assistance upon request

5 Chemical Security Compliance Division (CSCD) Requirements in Developing CSAT Protect facility-specific and aggregated data Collect, catalog, and segregate data from a large number of chemical facilities Support and inform the determination of a facility’s regulatory status and tier ranking Enable automation whenever practical, possible, and appropriate Integrate and operate the IT system within enterprise architecture policy mandates as well as Federal constraints imposed on regulatory data collection regimes

6 High Level View – The CSAT Process Top-Screen Security Vulnerability Assessment Security Vulnerability Assessment Site Security Plan Register CSAT Users Exempted or not covered at this time or Preliminary Facility Tier Facility Tier and Asset Specific Security Issue(s) Preliminary Approval Inspection for Final Approval Validate Facility, Preparer, Submitter & Authorizer information Notify user of CVI responsibilities and restrictions Reviewer Invited by known & trusted user

7 User Registration Registration began on April 6 th and will continue for as long as the Rule is in force Go to to registerwww.dhs.gov/chemicalsecurity Regarding Authorizers, Submitters, and Preparers –Each facility must have an Authorizer, Submitter, and Preparer –The roles may be consolidated with one person or split between three people –Each user will have a unique user name and password Reviewers invited with the Top-Screen Register prior to publication of Appendix A to ensure your facility has the full 60 days to complete the Top Screen

8 Registration Process Go to Click “Register Now” Type in Captcha Complete Submitter and Authorizer information. Click “Continue to Facility Information” Complete Facility Information On the same page complete the associated Preparer information –If another facility click “ Add Another Facility ” –If no other facilities associated with the Submitter & Authorizer click “ Complete ”

9 Example User Role Structures

10 User Information Collected

11 Adding a Facility

12 Complete the Registration Process After last facility & Preparer click “complete” Download PDF Form Sign and send to DHS with username & temp password will be sent

13 User Role Consolidation Complete a new registration New users names are created Use transfer account access to consolidate user accounts

14 CSAT User Roles Responsibility May Edit May View May Invite a Reviewer Must be an Officer or Designee Must be domiciled in US May be a Consultant Authorizer Verify and validate the appropriate individuals are assigned the appropriate CSAT User Roles NoYes No Submitter Verify and validate information being submitted is correct and accurate Yes No Preparer Complete the Top-Screen based upon their intimate knowledge of the facility Yes NoYes Reviewer Support for the Preparer, Submitter, or Authorizer NoYes NoYes

15 Top Screen: Adding a Reviewer Selecting a reviewer is optional Added by a known CSAT user May be added while the Top-Screen is active May be an existing user or new user New users sent an (no PDF for signature) Subject to the same requirements as other CSAT users

16 CSAT Users & Consultants DHS expects that consultants who assist facilities in complying with 6 CFR Part 27 are CVI authorized users. If a facility wishes to have a private consulting company support them in completing CSAT the facility may register a person as the Preparer or invite the individual as a Reviewer.

17 CVI Disclaimer All CSAT Users must accept to enter Top Screen Ensures CVI tier letters may be sent to CSAT Users

18 Top Screen: What does it do? Identifies the security issue(s) at a facility using the DHS Chemicals of Interest list: -Risk to public health and safety -Potential targets for theft and/or diversion of potential chemical weapons or explosive precursor -Reactive chemicals stored in transportation containers -Concentrated capacity, the loss of which poses a risk to the economy or to the delivery of mission critical functions Enables DHS to directly inform a facility of its status and/or preliminary tier by letter

19 Top Screen: Addresses Specific Security Issues Risk to public health & safety Release: (deaths & injuries) –In-situ release of toxics chemicals –In-situ release and ignition of flammable chemicals –In-situ release/detonation of explosives chemicals Potential targets for theft or diversion: (presence of chemical) –Chemical weapons and precursors –Weapons of mass effect –IED Precursors Reactive and stored in transportation containers: (presence of chemical) –Chemicals that react with water to generate poison gasses Critical to essential government missions: (facility specific basis) Critical to the national or regional economy: (facility specific basis)

20 Top Screen: How does public health and safety tiering work? Deaths and injuries are calculated using a variation of the EPA Risk Management Program (RMP) worst case scenario methodology DHS’s approach adjusts the RMP*Comp exposed population estimate to account for the safety perspective: –Single container breach assumption –Residential population only –EPRG-2 exposure limit –25 mile cutoff limit in RMP Comp –Uniform population density DHS estimates predictable deaths and injuries that would be considered Urgent or Priority in normal medical triage Process validated through independent expert panel

21 Post Top Screen Letter from DHS DHS letter to a facility is protected under CVI and includes: -Preliminary facility tier -Chemicals at the facility to address in the SVA -Security issue associated with the identified chemical(s) -Next steps required by the facility

22 Security Vulnerability Assessment (SVA) Follows the SVA approach established by CCPS and others –Asset Characterization: assets associated with chemicals identified in the post Top-Screen letter –Threat Characterization: specific scenarios prescribed by CSAT –Consequence Analysis: potential consequence of scenarios against identified assets –Vulnerability Analysis: security measures in place to mitigate or reduce the likelihood of success of an attack on an asset Cyber vulnerability assessment included Tier 4 facilities upload ASPs for review

23 Locating Critical Assets CSAT provides up to 1m resolution Enables a facility to upload image if necessary

24 Identify Attack Location Each critical asset is identified The location of attack is identified Judgment of preparer and submitter as to impacts Reasonableness verified during inspection

25 SVA Output Informs tier of each critical asset based on potential consequences Final facility tier based on highest asset-specific tier Generates a CVI protected letter to each facility that includes: Final facility tier Asset specific tier ranking and the associated security issue Defines the next steps required by the facility Information in post-SVA letter used by facility during CSAT SSP to identify the applicable RBPS based on asset tiers and security issues

26 Site Security Plan (SSP) Content All critical assets in the post-SVA letter must be addressed in the SSP All security measures in place or planned to achieve the applicable RBPS Review of SSPs will be prioritized based upon SVA results Facilities may upload ASPs for consideration

27 Information Protection Chemical-terrorism Vulnerability Information –Handling manual, web-based training, FAQs, and Work Products Guide available soon on websitewww.dhs.gov/chemicalsecurity –CVI User Authorization Request form and Non-disclosure Agreement Form sent to CSAT helpdesk –Unique identification # will be sent to authorized users –Being a CVI Authorized User does not constitute need to know –Presently, CSAT users agree to a disclaimer statement prior to beginning the Top Screen CVI in enforcement proceedings will be treated as classified information DHS has formally classified: –Formulas, calculations, tiering thresholds –Information that would inform terrorist targeting

28 Status and Next Steps User Registration operational Top-Screen operational SVA under development; operational in late-summer SSP under development, operational in early in 2008 Follow-on capability enhancements to CSAT –Integrated RMP*Comp calculations –Management of facility user roles by Authorizer –Personnel Surety portal to Terrorism Screening Database –Improved integration of CVI & CSAT –User suggestions?

29 Top Screen Previews Small group demonstrations are available throughout the conference Sign up for the top screen demos at the main registration table Opportunity to review the Top Screen Ask questions and get answers

30 CSAT helpdesk can assist you CSCD welcomes your comments and suggestions for improvement to CSAT