Risk-Based Performance Standards (RBPS)


Collage of images that show computer monitors RBPS-8 Cyber and RBPS-10 Monitoring, row of binders RBPS-18 Records, and a chain fence RBPS-1 Restrict Area Perimeter.Since each chemical facility faces different security challenges, Congress explicitly directed the Department of Homeland Security to issue regulations "establishing risk-based performance standards for security at chemical facilities." The Department developed 18 Risk-Based Performance Standards (RBPS) that all chemical facilities determined to be “high-risk” must meet in their security plan (Site Security Plan [SSP] or Alternative Security Program [ASP]) in order to be in compliance with the Chemical Facility-Anti-Terrorism Standards (CFATS).

Announcement: 

July 9, 2019: CISA published a Federal Register notice (84 FR 32786) of the implementation of the CFATS Personnel Surety Program (PSP) at all covered chemical facilities—including Tier 3 and Tier 4 facilities. This implementation closes the final gap in vetting individuals with access to critical assets and restricted areas for terrorist ties. Visit the PSP page for details, PSP Toolkit, resources, and a demo video.

RBPS Guidance

The Agency recognizes that facilities have dedicated and invested time, resources, and capital to identify vulnerabilities and improve overall security. The nonprescriptive nature of a performance standard allows individual facilities the flexibility to address their unique security challenges by selecting the most cost-effective measures or activities to achieve the desired level of performance for each RBPS given the facility’s tier level. Facilities may leverage their existing security measures in working toward compliance with CFATS, and specifically the RBPS.

The CFATS RBPS Guidance assists high-risk chemical facilities in selecting security measures and activities that comply with the CFATS regulations at their tier level and are tailored to the unique considerations of each facility.

A facility must submit their SSP/ASP detailing the programs, processes, or measures they choose to implement to meet the RBPS. CISA reviews the SSP/ASP, combined with an onsite inspection, to determine if the facility meets the desired level of performance for each RBPS.

RBPS Overarching Security Guidelines

Security measures that differ from facility to facility mean that each facility’s suite of security measures present a new and unique problem for an adversary to solve. To assist chemical facilities take a holistic approach to their security posture and determine the appropriate security measures, a facility may think about RBPS through the use of five overarching security objectives: Detection, Delay, Response, Cyber, and Security Management. These guideposts are the overall security objectives that the RPBS address. Each objective spans multiple RBPS and can be satisfied through one or more of those RBPS.

Detection

The capability to identify potential attacks or precursors to an attack—hostile attack, theft, diversion, and/or sabotage of a chemical of interest—and to communicate that information, as appropriate. RBPS that fall under Detection include:

RBPS 1 – Restrict Area Perimeter; RBPS 2 – Secure Site Assets; RBPS 3 – Screen and Control Access; RBPS 4 – Deter, Detect, and Delay; RBPS 5 – Shipping, Receipt, and Storage; RBPS 6 – Theft and Diversion; RBPS 7 – Sabotage

Delay

The capability to slow down an adversary’s progress sufficiently to allow adequate protective forces to respond by the use of physical security measures, business administrative/procedural measures, and other security management processes. RBPS that fall under Delay include:

RBPS 1 – Restrict Area Perimeter; RBPS 2 – Secure Site Assets; RBPS 3 – Screen and Control Access; RBPS 4 – Deter, Detect, and Delay; RBPS 5 – Shipping, Receipt, and Storage; RBPS 6 – Theft and Diversion; RBPS 7 – Sabotage

Response

The capability to communicate, report, and manage the appropriate reaction(s) to potential attacks and/or adversary actions, and/or to reduce the effect of security related events. RBPS that fall under Response include:

RBPS 9 – Response; RBPS 11 – Training; RBPS 13 – Elevated Threats; RBPS 14 – Specific Threats, Vulnerabilities, or Risks

Cyber

The capability to secure critical cyber systems from unauthorized onsite or remote access to critical process controls. RBPS 8 – Cyber falls under Cyber.

Security Management

The capability to manage the SSP, including the development and implementation of policies, procedures, and other processes that support SSP implementation and oversight. RBPS that fall under Security Management include:

RBPS 10 – Monitoring; RBPS 11 – Training; RBPS 12 – Personnel Surety; RBPS 15 – Reporting of Significant Security Incidents; RBPS 16 – Significant Security Incidents and Suspicious Activities; RBPS 17 – Officials and Organization; RBPS 18 – Records

RBPS Resources

The CFATS RBPS Guidance and these fact sheets are tools to assist high-risk chemical facilities in selecting security measures and activities that comply with the CFATS regulations at their tier level, and are tailored to the unique considerations of each facility.

RBPS 1-7 – Detection and Delay addresses a facility’s processes, measures, and activities to identify potential attacks, to delay an attack, and to create sufficient time for security personnel to respond before the attack becomes successful.

RBPS 8 – Cyber addresses the prevention of unauthorized on-site or remote access to critical process controls, critical business systems, and other sensitive computerized systems.

RBPS 9 – Response addresses the development and exercising of an emergency plan to mitigate and respond to security incidents in a timely manner. 

RBPS 10 – Monitoring addresses the regular inspection, testing, maintenance and calibration of security systems, communications and warning systems, and other equipment to ensure their reliability.

RBPS 11 – Training addresses the security and response training, exercises, and drills a facility should perform with personnel, law enforcement, and first responders to effectively detect and delay intruders and reduce consequences of an attack.

RBPS 12 – Personnel Surety addresses the background checks facilities are required to perform on people who have access to restricted areas or critical assets.

RBPS 15 and RBPS 16 – Significant Security Incidents address the development of protocols and procedures to promptly and adequately identify, investigate, and report all significant security incidents and suspicious activities in or near the site to the appropriate facility personnel, local law enforcement, and/or CISA.

RBPS 18 – Records addresses the creation, maintenance, protection, storage, and disposal of specific security related records pursuant to 6 CFR § 27.255.

Contact Information

Visit the CFATS Knowledge Center for an online repository of FAQs, articles, and the latest CFATS news.

For more information regarding the CFATS program, please contact CFATS@hq.dhs.gov.

Was this document helpful?  Yes  |  Somewhat  |  No