Checklists

Federal Transit Administration - Office of Safety and Security

bulletTransit Security Handbook (1998)
bulletFTA Safety Action Plan (2000)
bulletCritical Incident Management Guidelines (not online)

American Public Transportation Association (APTA) - Public Transportation Security

bulletChecklists for Emergency Response Planning and System Security (Original, List below Modified by Richard Collins, Dec 23, 2001)
bullet

Emergency Response Plan
bulletIdentify responsibilities of employees by function
bulletPlanning process is formalized and documented
bulletCoordination is formalized and documented
bulletTraining is formalized and documented - Regular assessments of employee proficiency conducted
bulletPrepare for multiple concurrent events
bulletService continuation, restoration / recovery plan developed
bulletEmergency drills and table-top exercises scheduled, executed, graded and adjusted on a regular basis
bulletProcedure revisions and updates incorporated into evacuation procedures; SOPs developed for signatures and distribution

bulletElements of Plan:
bulletEmergency Coordination - Emergency contacts list and procedures developed, kept current and in the hands of those affected.  Responsibilities for call-outs and backups identified.  Planning, coordination, training and mutual aid agreements: 
bulletwith Transportation Operations
bulletWith Security, transit police
bulletWith Safety Department
bulletWith Fire / rescue units
bulletwith Hospitals, Emergency Services
bulletwith Local Police, State Police, FBI, National Guard
bulletwith Federal Agencies
bulletwith Hazardous materials / Environmental agencies 
bulletwith Regional Office of Emergency Management
bulletwith Media - Formalize media relations responsibilities, information control procedures and policies
bulletwith Employees - issued quick reference guidelines for emergency and security situations
bulletSecurity training provided to all staff levels (from front-line "eyes and ears" concept to professional level security training)
bulletwith Public - Development of appropriate pre-determined public address announcements for station platforms and on-board vehicles
bulletwith families of employees and public - Support systems developed to provide post-incident support to customers and employees
bulletEmergency Drills and Exercises
bulletExercise Documentation - have a written plan, critique the plan, record recommendations, record follow-up
bulletEmergency Procedures - reviewed by Safety Management Team on a regular basis and updated as needed
bulletSecurity risk/vulnerability assessments conducted, documented and reviewed
bulletIncident Management and Planning:
bulletPre-determination of factors that would require partial or full service shut-down
bulletRegular functional testing / inspection of emergency support equipment and systems (e.g., emergency phones, CCTV, alarms, onboard/in-vehicle equipment, two-way radios, fans, pumps, generators, etc.)
bulletStandard Operating Procedures for HVAC operations in various emergency conditions
bulletContingency plans for loss of electrical power and radio or phone communications
bulletProcedure exists for alternate Operations Control Center in the event of evacuation
bulletEmergency evacuation routing for transit vehicles developed
bullet

Security Plans and Preparations
bulletSecurity Plan established to address all operations modes and contracted services, to  address multiple concurrent security incidents
bulletSystem security responsibilities and duties established
bulletSecurity task force established
bulletSecurity equipment regularly inspected, maintained and functionally tested; including personal equipment issued to security personnel
bulletSecurity SOPs reviewed on a regular basis and updates made as needed to Security Plan
bulletSecurity equipment installed, inspected, and maintained to monitor trespass activities
bulletContingency SOPs developed; drills and table-top exercises conducted for extraordinary circumstances
bulletTerrorism (including chemical/ biological agents/ weapons of mass destruction)
bulletRiot / Domestic unrest
bulletCatastrophic natural events
bulletSystem-wide communications failure
bulletComputer, Communications, Utilities failures

bulletSecurity Procedures:
bulletStandard Operating Procedures for critical incident command, control, and service continuation/ restoration
bulletAgency employees identifiable by visible identification and/or uniform
bulletPolicy and procedures in place for facilities key control
bulletVisitor, deliveries and contractor facility access procedures developed / visible identification required
bulletSafety and security coordination on trespass issues
bulletData collection established for all security issues / incidents; analysis performed and recommendations made; document control established, including follow-up
bulletBackground checks on employees and contractors (where applicable)
bulletRegular assessments of employee security proficiencies conducted
bulletAwareness, Training, Infrastructure Hardening
bulletPersonal safety awareness/education programs for passengers and employees and community outreach
bulletTrespass awareness programs, including education and signage
bulletConcepts of crime prevention through environmental design (CPTED) applied in reviews of facilities and in new design and modifications
bulletSecurity checklists developed and regularly used for verifying status of physical infrastructure and security procedures

Transportation Research Board - Transportation Security

bulletTRB Task Force A5T56 Critical Transportation Infrastructure Protection

The National Safety Council

bulletEmergency Response Plans This article outlines the general elements that should be included in your emergency response plan (ERP), including your company's responsibility for activating emergency procedures and how all members of an organization should respond to an emergency situation.
bulletClear, written policies that designate a chain of command, listing names and job titles of the people (or departments) who are responsible for making decisions, monitoring response actions and recovering back to normal operations.
bulletNames of those who are responsible for assessing the degree of risk to life and property and who should be notified for various types of emergencies.
bulletSpecific instructions for shutting down equipment and production processes and stopping business activities.
bulletFacility evacuation procedures, including a designated meeting site outside the facility and a process to account for all employees after an evacuation.
bulletProcedures for employees who are responsible for shutting down critical operations before they evacuate the facility.
bulletSpecific training and practice schedules and equipment requirements for employees who are responsible rescue operations, medical duties, hazardous responses, fire fighting and other responses specific to your work site.
bulletThe preferred means of reporting fires and other emergencies.

National Infrastructure Protection Center (NIPC)

bulletIncrease user awareness
bulletUpdate anti-virus software
bulletStop hostile attachments at the e-mail server
bulletUtilize ingress & egress filtering
bulletEstablish policy and procedures for responding and recovery
bulletwww.cert.org/security-improvement
bulletwww.microsoft.com/technet/treeview/default.asp?url=/technet/itsolutions/security/tools/
tools.asp
bulletwww.sans.org/topten.htm