DHS Official: CFATS Program More Important Now Than Ever

The Chemical Facility Anti-Terrorism Standards (CFATS) program is more important now than ever.

That was the message Wednesday from Sue Armstrong, director of the Department of Homeland Security’s Infrastructure Security Compliance Division, in her update of the CFATS program, which requires all high-risk chemical facilities to perform security vulnerability assessments and develop and implement site security plans that meet 18 risk-based performance standards established by DHS.

The program celebrated its four-year anniversary of being signed into law just more than a week ago. And, according to Armstrong, speaking at ASIS 2010 at the Dallas Convention Center, all indicators suggest that awareness of the program is higher now than in previous years --  even as the department’s implementation of its strategy continues to evolve, creating a need for more outreach to the 4,776 facilities that must comply with its regulations.

“CFATS exists for a very good reason, and that is because the threat to our country is very real,” Armstrong said, adding that terrorist factions already are within U.S. borders, where they’re being radicalized domestically first before going to other countries for further training and support. “For those of you who aren’t aware, the U.S. intelligence community has changed its estimate of that threat. . . . We are in a new threat environment domestically, and the CFATS program is here to protect our communities.”

Armstrong said that, unlike ASIS update sessions in previous years, ISCD now is “on the ground, doing inspections,” having recently filled its ranks with 92 inspectors who are roving the country in all 50 states.

She said the division has received 3,669 site security plans to date and has completed its review of 220 of those plans. Meanwhile, the division has several notices of proposed rulemaking on the boards and is instigating listening sessions with stakeholders across the country. Also, ISCD has launched an online site dedicated to training, assessment, and top-screening assistance, as well as a CFATS “Help Desk” line at 1-866-323-2957.

Dan Walters, CPP, manager of Security & Environment Risk for Terra Industries, joined Armstrong at the podium to offer a private sector perspective on implementing and maintaining a CFATS-compliant program. He recommended that even if facilities do not yet have a site security plan, officials need to review their top-screens, which are questionnaires that enable DHS to perform a basic consequence assessment that results in a facility being preliminarily considered high-risk and placed in a preliminary tier.

“Treat your plan as if it were a regulatory compliance document,” Walters said. “Develop a separate security plan to lay out requirements of those with security responsibilities.” He added that facility managers should calendar their plans with trigger points based on such elements as training audits, drills, and document retention strategies, and then adhere to those plans. “Whether you have a 3-year or 6-year document retention plan, stick to the plan. If you’re not required to keep the document after that time, don’t keep it,” because if you do, you won’t be in compliance, he said.

Walters also advised managers to conduct incident investigations of all security incidents and to notify either DHS or the FBI -- or a host of other agencies -- when incidents happen, and to watch for changes to either the CFATS rule or the Appendix A list, which Armstrong said ISCD has already initiated a review on.

Finally, Walters said, “When in doubt, utilize the CFATS Help Desk,” which can refer managers to inspectors and staff and offer direction to training modules online.

About the Author

Ronnie Rittenberry is print managing editor for Security Products and Occupational Health and Safety magazines.

Featured

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.