Canadian Chemical Engineering Conference Edmonton, Alberta October 30, 2007

Similar documents
2008 National Ag Safety School. Richard Gupton Vice President, Legislative Policy & Counsel Agricultural Retailers Association

The Office of Infrastructure Protection

The Office of Infrastructure Protection

The Office of Infrastructure Protection

Chemical Facility Anti- Terrorism Standards

Understanding CFATS: What It Means to Your Business Chemical Facility Anti-Terrorism Standards John C. Fannin III, CPP, LEED AP

Securing the Chemical Sector:

Chemical Facility Anti-Terrorism Standards. T. Ted Cromwell Sr. Director, Security and

Chemical Facility Anti-Terrorism Standards

The Office of Infrastructure Protection

The Office of Infrastructure Protection

How AlienVault ICS SIEM Supports Compliance with CFATS

RECENT DEVELOPMENT. Scott Goodman

Statement for the Record. Rand Beers Under Secretary National Protection and Programs Directorate Department of Homeland Security

The Office of Infrastructure Protection

SECURITY CODE. Responsible Care. American Chemistry Council. 7 April 2011

The Office of Infrastructure Protection

DHS Guidance for the Expedited Approval Program

Dr. Emadeldin Helmy Cyber Risk & Resilience Bus. Continuity Exec. Director, NTRA. The African Internet Governance Forum - AfIGF Dec 2017, Egypt

Critical Infrastructure

Actions to Improve Chemical Facility Safety and Security A Shared Commitment Report of the Federal Working Group on Executive Order 13650

EXECUTIVE ORDER Chemical Facility Safety and Security: Providing ProtecFon Reduces Risk

Written Statement of. Timothy J. Scott Chief Security Officer The Dow Chemical Company

The Ohio State University. Chemical Facility Anti-Terrorism Standards (CFATS) Program

Implementation of Chemical Facility Anti-Terrorism Standards (CFATS): Issues for Congress

Implementation of Chemical Facility Anti-Terrorism Standards (CFATS): Issues for Congress

Implementation of Chemical Facility Anti-Terrorism Standards (CFATS): Issues for Congress

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Standard CIP 007 4a Cyber Security Systems Security Management

Standard CIP 007 3a Cyber Security Systems Security Management

DHS Cybersecurity. Election Infrastructure as Critical Infrastructure. June 2017

Bradford J. Willke. 19 September 2007

Navigation and Vessel Inspection Circular (NVIC) 05-17; Guidelines for Addressing

PIPELINE SECURITY An Overview of TSA Programs

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

PD 7: Homeland Security Presidential Directive 7: Critical Infrastructure Identification, Prioritization, and Protection

IMO MEASURES TO ENHANCE MARITIME SECURITY. Outcome of the 2002 SOLAS conference. Information on the current work of the ILO

Chapter 1. Chapter 2. Chapter 3

Cybersecurity Risk and Options Considered by IMO

SAND No C Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department

DHS Cybersecurity: Services for State and Local Officials. February 2017

Standard CIP 005 4a Cyber Security Electronic Security Perimeter(s)

June 5, 2018 Independence, Ohio

National Policy and Guiding Principles

The Office of Infrastructure Protection

ELECTRICAL ENGINEERING & INSTRUMENTATION MECHANICAL ENGINEERING BIOLOGICAL & INDUSTRIAL ENGINEERING NUCLEAR ENGINEERING STRUCTURAL & CIVIL

Standard CIP 005 2a Cyber Security Electronic Security Perimeter(s)

IMPLEMENTATION OF REGDOC SECURITY OF NUCLEAR SUBSTANCES: SEALED SOURCES for category 3-5 licensees

Standard CIP Cyber Security Incident Reporting and Response Planning

The Office of Infrastructure Protection

Standard CIP Cyber Security Systems Security Management

Critical Infrastructure Sectors and DHS ICS CERT Overview

About Issues in Building the National Strategy for Cybersecurity in Vietnam

Management. Port Security. Second Edition KENNETH CHRISTOPHER. CRC Press. Taylor & Francis Group. Taylor & Francis Group,

MYTH vs. REALITY The Revised Cybersecurity Act of 2012, S. 3414

Standard Development Timeline

Standard CIP Cyber Security Systems Security Management

American Association of Port Authorities. Navigating the Cyber Domain. Homeland Security UNCLASSIFIED

Emergency Support Function #12 Energy Annex. ESF Coordinator: Support Agencies:

Statement for the Record

CYBER SECURITY BRIEF. Presented By: Curt Parkinson DCMA

Protecting Canada s Nuclear Industry THE

Standard CIP Cyber Security Electronic Security Perimeter(s)

Introduction to HSIN Basics (HSIN 101)

COMPASS FOR THE COMPLIANCE WORLD. Asia Pacific ICS Security Summit 3 December 2013

COUNTERING IMPROVISED EXPLOSIVE DEVICES

An Update on Security and Emergency Preparedness Standards for Utilities

Cybersecurity and Data Protection Developments

Standard CIP Cyber Security Electronic Security Perimeter(s)

The J100 RAMCAP Method

uanacia 1+1 MARINE SECURITY OPERATIONS BULLETIN No:

Updates to the NIST Cybersecurity Framework

Pipeline Security Guidelines. April Transportation Security Administration

Critical Information Infrastructure Protection Law

Consideration of Issues and Directives Federal Energy Regulatory Commission Order No. 791 June 2, 2014

Grid Security & NERC

New Brunswick 2018 Annual Implementation Plan Version 1

Systems Security Engineering: A Framework to Protect Hardware Down to the Last Tactical Inch

IMPROVING CYBERSECURITY AND RESILIENCE THROUGH ACQUISITION

California Code of Regulations TITLE 21. PUBLIC WORKS DIVISION 1. DEPARTMENT OF GENERAL SERVICES CHAPTER 1. OFFICE OF THE STATE ARCHITECT

EARTH Ex 2017 Middle Planning Conference

SAC PA Security Frameworks - FISMA and NIST

Gas Infrastructure Europe. Security Risk Assessment Methodology

CRITICAL INFRASTRUCTURE AND KEY RESOURCES

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

Compliance with ISPS and The Maritime Transportation Security Act of 2002

DEQ Guidance on Recordkeeping and Reporting

Cyber Security Incident Report

Standard CIP 004 3a Cyber Security Personnel and Training

Office of Infrastructure Protection Overview

NORTH AMERICAN ELECTRIC RELIABILITY CORPORATION

Critical Cyber Asset Identification Security Management Controls

STORAGE OF SSAN. Security Risk Assessment and SECURITY PLAN. (insert name of company) SUBMITTED TO REGULATORY AUTHORITY: (insert date)

Report for Congress. Safeguarding the Nation s Drinking Water: EPA and Congressional Actions. Updated March 7, 2003

NY DFS Cybersecurity Regulations August 8, 2017

Advanced IT Risk, Security management and Cybercrime Prevention

California Cybersecurity Integration Center (Cal-CSIC)

MEASURES TO ENHANCE MARITIME SECURITY. Cyber risk management in Safety Management Systems. Submitted by United States, ICS and BIMCO SUMMARY

S&T Stakeholders Conference

Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS

Transcription:

US Chemical Facility Anti-Terrorism Standards (CFATS) Overview Canadian Chemical Engineering Conference Edmonton, Alberta October 30, 2007 Dorothy Kellogg AcuTech Consulting Group Alexandria, Virginia

Agenda Purpose & Scope Elements & Process Chemical Security Assessment Tools (CSAT)

Purpose & Scope: Authority FY07 DHS Appropriations Section 550 P.L. 109-295 High Risk Chemical Facilities Security Vulnerability Assessment (SVA) Site Security Plan (SSP) Risk Based Performance Standards (RBPS)

Purpose & Scope: Effective Dates Interim Final Rule, April 9, 2007 72 Fed Reg 17688 Interim Final Rule Effective, June 8, 2007 Appendix A Chemicals of Interest (COI) List: Proposed April 9, 2007 Final October 2007 (?) Action 60 days after promulgation

Purpose & Scope: High Risk Chemical Facilities Possess Chemicals of Interest manufacture, use, store or distribute Chemical manufacturers Petroleum refineries LNG peak shaving facilities At or above the Screening Threshold Quantity (STQ) Serious Consequences from Successful Attack: Human Health & Safety Government Mission in Time of Emergency National or Regional Economy

Purpose & Scope: High Risk Chemical Facilities (cont.) High Risk Chemical Facilities -- Exemptions MTSA facilities* Public Drinking Water Systems* Waste Water Treatment Facilities* DOE & DOD facilities NRC-regulated facilities* * Parsed Facilities Portion of facility subject to MTSA On-site water treatment facility Small radioactive sources

Elements & Process: Process Flow 1 Identify Candidate Sites 2 PerformTop- Screen High Risk Facility? Yes 3 Assign Preliminary Tier 4 PerformSVA 5 Assign Final Tier 6 Develop SSP 7 ReviewSSP 8 Implement SSP 9 Perform Inspection No Non-covered facilities Risk-Based Performance Standards DHS Responsibility Owner/Operator Responsibility

Elements & Process: Chemicals of Interest Over 300 chemicals on draft Appendix A 3 Human Health Security Issues: Release: : Toxics, Flammables, Explosives Theft/Diversion: Chemical Weapons/Precursors Weapons of Mass Effect (WME) PIH Gasses Explosives/IED Precursors Sabotage/Contamination: : Water Reactive PIH Gas Final: Chemicals of Concern with STQ s Response to Public Comments

Elements & Process: Risk-Based Performance Standards 1. Restricted Area Perimeter 2. Securing Site Assets 3. Screening and Access Controls 4. Deter, Detect, and Delay 5. Shipping, Receipt, and Storage 6. Theft and Diversion 7. Sabotage 8. Cyber 9. Response 10. Monitoring 11. Training 12. Personnel Surety 13. Elevated Threats 14. Specific Threats, Vulnerabilities, or Risks 15. Security Incidents 16. Suspicious Activities 17. Officials and Organizations 18. Records 19. Others as determined by DHS

Elements & Process: Chemical-terrorism Vulnerability Information (CVI) Must be CVI Trained to handle CVI material Private sector: generate, review, submit, manage Public sector: receive, use, manage On-line training www.dhs.gov/chemicalsecurity Receive CVI Certificate & Unique Number CVI Authorized Need to Know CVI in enforcement proceedings treated as classified

Chemical Security Assessment Tools: Process Notify user of CVI responsibilities and restrictions Register Register CSAT CSAT Users Users Top-Screen Top-Screen Security Security Vulnerability Vulnerability Assessment Assessment Site Site Security Security Plan Plan Validate Facility, Preparer, Submitter & Authorizer information Exempted or not covered at this time or Preliminary Facility Tier Facility Tier and Asset Specific Security Issue(s) Preliminary Approval Reviewer Invited by known & trusted user Inspection for Final Approval

CSAT Top-Screen Preliminary facility tier based on potential consequence Human Health & Safety Government Mission Economic Criticality Post Top-Screen Letter (CVI) Specific chemicals and security issues for SVA Based on human health & safety Subsequent notification for Mission or Economic criticality

CSAT SVA Elements Asset Characterization: : assets associated with chemicals identified in the post Top-Screen letter Threat Characterization: : CSAT prescribed scenarios Consequence Analysis: : potential consequence of scenarios against assets Vulnerability Analysis: security measures in place Countermeasures Analysis: : strategies to reduce the probability of a successful attack Physical & cyber vulnerabilities

CSAT SVA Specific assets and security issues Explicit attack scenarios provided VBIED Maritime Aircraft Theft (Insider/Outsider) Sabotage (Insider/Outsider) Assault Team Cyber

CSAT SVA Output Post SVA Letter (CVI): Final facility tier Tier for each asset of interest Next steps and deadlines for the facility Applicable RBPS based on asset tiers and security issues

CSAT Site Security Plan (SSP) Security measures in place or planned to achieve the applicable RBPS All critical assets & security issue in the post- SVA letter must be addressed in the SSP DHS on-site validation Facilities may submit ASP for consideration

Summary Chemical security challenge dangerous but critical Partnership between government & asset owners in a regulatory construct Risk-based Consequence-driven Adaptable regulatory

Further Information Resources: www.dhs.gov/chemicalsecurity Including: General CFATS Information User Registration & Registration Instructions Top-Screen Questions and User Manual CSAT FAQ s General CVI Information CVI On-Line Training

Thank You Questions? Dorothy Kellogg dkellogg@acutech-conslting.com conslting.com 703-399 399-7452