106.305—Facility Security Assessment (FSA) requirements.
(a) Background.
The OCS facility owner or operator must ensure that the following background information, if applicable, is provided to the person or persons who will conduct the assessment:
(6)
Threat assessments, including the purpose and methodology of the assessment, for the OCS facility's location;
(8)
Any other existing security procedures and systems, equipment, communications, and OCS facility personnel.
(b) On-scene survey.
The OCS facility owner or operator must ensure that an on-scene survey of each OCS facility is conducted. The on-scene survey examines and evaluates existing OCS facility protective measures, procedures, and operations to verify or collect the information required in paragraph (a) of this section.
(c) Analysis and recommendations.
In conducting the FSA, the OCS owner or operator must ensure that the Company Security Officer (CSO) analyzes the OCS facility background information and the on-scene survey, and considering the requirements of this part, provides recommendations to establish and prioritize the security measures that should be included in the FSP. The analysis must consider:
(v)
Measures to protect radio and telecommunication equipment, including computer systems and networks;
(x)
Any deficiencies identified following security incidents or alerts, the report of security concerns, the exercise of control measures, or audits.
(iii)
Use of a vessel interfacing with the OCS facility to carry those intending to cause a security incident and their equipment;
(iv)
Use of a vessel interfacing with the OCS facility as a weapon or as a means to cause damage or destruction; and
(v)
Effects of a nuclear, biological, radiological, explosive, or chemical attack to the OCS facility's shoreside support system;
(4)
Vulnerabilities, including human factors, in the OCS facility's infrastructure, policies and procedures;
(5)
Any particular aspects of the OCS facility, including the vessels that interface with the OCS facility, which make it likely to be the target of an attack;
(6)
Likely consequences, in terms of loss of life, damage to property, or economic disruption, of an attack on or at the OCS facility; and
(d) FSA Report.
(1)
The OCS facility owner or operator must ensure that a written FSA report is prepared and included as a part of the FSP. The report must contain:
(ii)
A description of existing security measures, including inspection, control and monitoring equipment, personnel identification documents and communication, alarm, lighting, access control, and similar systems;
(vi)
A list of identified weaknesses, including human factors, in the infrastructure, policies, and procedures of the OCS facility.
(3)
The FSA report must list the persons, activities, services, and operations that are important to protect, in each of the following categories:
(iii)
The impact of watch-keeping duties and risk of fatigue on personnel alertness and performance;
(iii)
Controlling the embarkation of OCS facility personnel and other persons and their effects (including personal effects and baggage, whether accompanied or unaccompanied);