Department of Homeland Security Logo

CFATS Update The Pre-Authorization and Authorization Inspections

In October 2006, the Department of Homeland Security Appropriations Act of 2007 became law. Section 550 of the Act ordered the Department of Homeland Security (DHS) to “...issue interim final regulations establishing risk‐based performance standards for security of chemical facilities and requiring security vulnerability assessments and the development and implementation of site security plans for chemical facilities.” Those regulations became known as the Chemical Facility Anti‐Terrorism Standards, or CFATS, and apply to “high‐risk” facilities that possess certain quantities and concentrations of chemicals.

As of July 2011, DHS has classified approximately 99 facilities as Tier 1, or highest risk, 502 facilities as final Tier 2, 1,155 facilities as final Tier 3 and 2,195 facilities as final Tier 4 facilities with the lowest risk.

In 2009, all identified facilities were required to file a Site Security Plan (SSP) with DHS via a web‐based tool called the Chemical Security Assessment Tool (CSAT). However, once DHS received and started processing SSPs, it became evident that the CSAT did not require a sufficient amount of detailed security information for DHS to fully understand each facility’s security posture.

Washington, We Have a Problem...
The way the CSAT was designed, the SSP only required facilities to respond yes or no to questions such as, “Does the facility have an emergency management team available?” and “Does the facility use the CCTV camera feature?” More detail was needed since the credibility and practicality of the regulation depended on how DHS gathered, analyzed and evaluated the required information from the industry. At that moment, DHS was at a crossroads and needed to take action. On one hand, the agency could have started from scratch and reconfigured the CSAT completely. However, those individuals who saw first‐hand the amount of effort and resources applied to the original process know that this would have caused more than a few eyebrows in the industry to rise.

Ultimately, for all Tier 1 facilities the Department decided to institute a preliminary round of site inspections called pre‐authorization inspections (PAI). How this will be addressed with the other tiers in the future is not known at this time. The PAIs were designed to provide facilities with additional guidance in writing their SSPs not included in the CSAT itself. The PAI process started in January 2010 with facilities visited by 3 to 7 inspectors over 2 to 4 days. The PAI is not an audit per se; it is not regulatory in nature and it is not mentioned in the law, but it is giving industry the chance to get a taste of what the real Authorization Inspection will look like. The inspectors will tour the facilities, will see firsthand the Chemicals Of Interest or COI, will discuss with the Facility Security Officer the applicable RBPS, and will discuss the different security assets and their nature. After that, the CSAT will re‐open and the facility will have between 20 and 45 days to re‐submit the SSP with additional and more detailed information, a daunting task.

The Authorization Inspection: Where the Rubber Meets the Road
After the PAI is completed, the revised SSP is submitted and approved by DHS, the real audit will begin. Although at this time only a handful of facilities have actually gone through an Authorization Inspection or (AI), this is a key element of the regulation. A typical AI lasts for about a week and is staffed by six inspectors on average. The aim of DHS is to validate the approved SSP during this inspection. The inspectors will -- of course -- look at obvious security measures such as the perimeter fence and the video surveillance equipment; but more important, they will evaluate less evident measures such as procedural security, training records, and security personnel screening and selection processes.

Another DHS objective is to make sure that the planned security measures identified in the SSP comply with the definition of “planned security measures” as understood by DHS. A planned security measure goes beyond an activity or investment that a plant would like to do at some point in time; this would be considered a proposed security measure and does not count towards SSP approval. A planned security measure as defined by DHS must be realistic, budgeted, under development and with a completion date in the near future. Finally, the DHS inspectors will have conversations with security personnel at the site and will evaluate their responses to questions such as: Explain your visual inspection procedures, explain the suspicious package procedures, explain and demonstrate an undercarriage inspection process, etc. Control room operators will also be interviewed at all AIs and asked about the emergency notification procedures of the facilities, shutdown procedures and worst case scenario response.

Lessons Learned
Now that several tier 1 PAIs and a handful of AIs have been completed, a few lessons can be shared with the regulated chemical industry at large. First of all, it is important to remember that inspectors will look for more than the most visible security measures when evaluating your SSP. How you do things will be as important as what you do. Procedural security, the availability of records and the intangible qualities of security personnel will play a critical role in the approval (or not) of a facility’s SSP. Therefore, the second lesson is that the security provider at your regulated facility should be a true partner during the entire CFATS process. To involve the security vendor from the beginning guarantees a more cohesive approach to the inspection process. Sophisticated security vendors can add substantial value to a facility’s security posture through the use of intelligent technologies and consulting services. The final lesson is to make sure that the facility’s security personnel are fully trained, properly screened (in accordance with RBPS 12 Personnel Surety), and bring the right traits for the job.

The inspectors are doing their job. Have you done yours?


  • Cybersecurity Awareness Month: Top Five Action Items to Elevate Your Data Security Posture Management and Secure Your Data

    October is Cybersecurity Awareness Month, and every year most tips for security hygiene and staying safe have not changed. We’ve seen them all – use strong passwords, deploy multi-factor authentication (MFA), be vigilant to spot phishing attacks, regularly update software and patch your systems. These are great recommended ongoing tips and are as relevant today as they’ve ever been. But times have changed and these best practices can no longer be the bare minimum. Read Now

  • Boosting Safety and Efficiency

    Boosting Safety and Efficiency

    In alignment with the state of Mississippi’s mission of “Empowering Mississippi citizens to stay connected and engaged with their government,” Salient's CompleteView VMS is being installed throughout more than 150 state boards, commissions and agencies in order to ensure safety for thousands of constituents who access state services daily. Read Now

  • Live From GSX: Post-Show Review

    Live From GSX: Post-Show Review

    This year’s Live From GSX program was a rousing success! Again, we’d like to thank our partners, and IPVideo, for working with us and letting us broadcast their solutions to the industry. You can follow our Live From GSX 2023 page to keep up with post-show developments and announcements. And if you’re interested in working with us in 2024, please don’t hesitate to ask about our Live From programs for ISC West in March or next year’s GSX. Read Now

    • Industry Events
    • GSX
  • People Say the Funniest Things

    People Say the Funniest Things

    By all accounts, GSX version 2023 was completely successful. Apparently, there were plenty of mix-ups with the airlines and getting aircraft from the East Coast into Big D. I am all ears when I am in a gathering of people. You never know when a nugget of information might flip out. Read Now

    • Industry Events
    • GSX

Featured Cybersecurity

New Products

  • XS4 Original+

    XS4 Original+

    The SALTO XS4 Original+ design is based on the same proven housing and mechanical mechanisms of the XS4 Original. The XS4 Original+, however, is embedded with SALTO’s BLUEnet real-time functionality and SVN-Flex capability that enables SALTO stand-alone smart XS4 Original+ locks to update user credentials directly at the door. Compatible with the array of SALTO platform solutions including SALTO Space data-on-card, SALTO KS Keys as a Service cloud-based access solution, and SALTO’s JustIn Mobile technology for digital keys. The XS4 Original+ also includes RFID Mifare DESFire, Bluetooth LE and NFC technology functionality. 3

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3