NPSI Standards Guide 04
Series: Regulatory & Testing History
At a Glance
- ISC: created by Executive Order 12977 (1995) after the Oklahoma City bombing; chaired by DHS. Its Risk Management Process (RMP) standard governs security for nonmilitary federal facilities.
- Mechanism: each facility receives a Facility Security Level (FSL I–V); the FSL drives a baseline set of countermeasures, tailored by a facility-specific risk assessment.
- CISA: the Cybersecurity and Infrastructure Security Agency houses the ISC and publishes voluntary guidance for critical infrastructure and public gatherings, including vehicle-ramming mitigation.
- For specifiers: the RMP tells you whether and where perimeter measures are required; test standards like ASTM F2656 tell you what to buy.
Oklahoma City and the ISC
The April 1995 bombing of the Alfred P. Murrah Federal Building exposed that civilian
federal facilities had no unified security standard. Executive Order 12977, signed six
months later, created the Interagency Security Committee to fix that. Today the ISC —
chaired by the Department of Homeland Security through CISA — sets policies and standards
binding on all executive-branch, nonmilitary federal facilities, whether owned or
leased.
The Risk Management Process
The ISC's core document is The Risk Management Process for Federal Facilities
(RMP), which consolidated earlier ISC standards into one framework. Its logic:
- Facility Security Level. Every facility is assessed FSL I (lowest)
through V (highest) based on mission criticality, symbolism, population, size, and threat
environment.
- Baseline countermeasures. Each FSL maps to a baseline set of
countermeasures in the RMP's appendices — covering site, entry, interior, and security
operations. Perimeter items include standoff, vehicle barriers, and parking controls.
- Tailoring by risk assessment. The baseline is adjustable: a
facility-specific assessment can justify exceeding it or accepting documented risk where
a measure is infeasible. The paper trail is the point — deviations are decisions, not
omissions.
For a design team, the practical consequence is that the security requirement arrives as
an FSL determination and a countermeasure set, not as a crash rating. Translating
“vehicle barrier required at standoff perimeter” into an ASTM F2656 designation
with a penetration rating is the specifier's job — using threat vehicle and achievable
speed exactly as the DOD method does.
Where CISA fits
CISA plays two roles. Inside government, it chairs and staffs the ISC. Outside, it is
the national coordinator for critical infrastructure security, publishing voluntary
guidance used by commercial operators: security planning for public gatherings, active
vehicle barrier resources, and vehicle-ramming attack mitigation guidance aimed at
soft targets — stadiums, event perimeters, pedestrian zones. None of it is regulation for
the private sector, but it is the closest thing to a federal reference for commercial
perimeter decisions, and insurers and courts increasingly treat it as the standard of
care.
What the specifier should do
- On federal civilian work: obtain the FSL determination and the applicable RMP
countermeasure baseline early — they are the design criteria.
- Write the barrier line in test-standard terms (ASTM F2656 designation + P rating);
the RMP intentionally does not name products or ratings.
- On commercial work near crowds: document the CISA vehicle-ramming guidance you
followed. It strengthens both the design and its defensibility.
Sources & Further Reading
- Executive Order 12977, Interagency Security Committee (October 1995).
- Interagency Security Committee, The Risk Management Process for Federal Facilities (current edition via cisa.gov/isc).
- Interagency Security Committee, Facility Security Level Determinations standard.
- CISA, Vehicle Ramming Attack Mitigation and public gathering security guides (cisa.gov).