CFATS Professionals: Slow-Moving Approval Process No Reason To Rest

Three professionals who help chemical facilities meet security responsibilities note that facility officials need to ensure that they can deliver on their site plan promises.

Chemical facilities that have submitted their site security plans (SSPs) really don't have time to relax despite the fact that the Department of Homeland Security has only been able to authorize three of the more than 3,669 submissions it has received as of Oct. 1.

SSPs are required for high-risk facilities through the Chemical Facility Anti-Terrorism Standards and a presentation on this subject was given by Michael Saad, CPP, senior director of consulting services at Huffmaster Crisis Response LLC; Wade Pinnell, CPP, vice president, Huffmaster Companies; and Evan Wolff, director, Homeland Security Practice Resources Regulatory and Environmental Law, Hunton and Williams, during ASIS 2010 in Dallas.
 
Pinnel, who has attended seven pre-authorization inspections, urged facility managers to review their plans as an inspector would.

"You need to check to see if what you told DHS you were going to do is actually in place," he said.

Pinnel also stressed that inspectors will be interviewing not only uniformed security officers, but also receptionists and anyone else who is assigned to implement security policy and procedure.

From his experience, Pinnel said that "we all submitted far too little information. Can inspectors visualize what we are doing in our facilities?"

If they can't, the security plan probably needs some work, including screening site visitors, searching vehicles, and preparing staff to take on their security roles.

Pinnel cautioned against letting technology drive security solutions.

"We need to integrate with the individuals performing the security roles," he said.

Saad took that tact a step further, urging security managers to develop relationships with law enforcement.

"Bring them to your facilities, show how you do what you do, provide site drawings and then re-engage them during training," he said.

An important aspect of planning is communicating the plan. Saad explained that planned security measures must be written into company policy and procedures. There also should be written protocols for security incident reporting, security incident investigation, training, drills, and exercises.

The key ingredients for success, Saad said, hinge on executive commitment to the programs (there is no ROI, we must comply) and a good project manager. Without someone dedicated to developing and implementing facility security under CFATS, deadlines may be missed, he noted. Realistic timelines are essential and, if those are not kept, managers must document why to discover gaps and provide information to DHS, he added.
 
From an attorney's perspective, Wolff encouraged managers to have their companies develop a corporate policy on security, a security compliance policy that establishes clear leadership and management, and a corporate inspection process.

"DHS has broad inspection authority," he said, adding that adjudication is based on the records a facility creates.

 

About the Author

L.K. Williams is the editor of Environmental Protection online.

Featured

  • Personal Liability Concerns Impact 70% of Cybersecurity Leaders

    BlackFog, provider of ransomware prevention and anti data exfiltration (ADX), recently unveiled its research conducted with UK and US IT Security decision makers. The research revealed that the majority of respondents, 70%, felt that stories of CISOs being held personally liable for cybersecurity incidents has negatively affected their opinion of the role. Read Now

  • Security Industry Association Announces the 2025 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2025 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both short- and long-term change in the global security industry. Read Now

  • Generative AI, Cybersecurity Among Top Risks for Healthcare Provider Organizations in 2025

    Overseeing the use of generative artificial intelligence, enhancing cybersecurity and ensuring compliance with a host of federal healthcare regulations headline the Top Risks health systems face in 2025, according to an annual study by Kodiak Solutions. Read Now

  • Wisconsin Shooting Likely a 'Combination of Factors'

    Following the deaths of a teacher and student at Abundant Life Christian School in, Madison, Wisc., police chief Shon Barnes indicated that the motive appears to be a “combination of factors” for a 15-year-old female student’s attack on a study hall. Read Now

    • Active Shooter
    • Incident Response

Featured Cybersecurity

Webinars

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises. 3