Showing posts with label CFATA. Show all posts
Showing posts with label CFATA. Show all posts

Wednesday, October 21, 2009

CFATS Uncertainty

As I noted last week on my personal blog, I was interviewed for two different articles on the CFATS program and the new legislation that may change that program over the next couple of years. Yesterday the first of those articles was posted on SecurityDirectorNews.com. That article by Leishen Stelter addresses the uncertainty that facilities are facing as they submit their first site security plans under CFATS. Risk Based Performance Standards The first uncertainty is due to the nature of the CFATS regulations and their authorizing legislation. Since Congress forbade DHS from specifying security measures that could be required for SSP approval, DHS was only able to outline 18 risk based performance standards (RBPS) that the facilities were required to address in their site security plan. To help facilities adequately address those performance standards, DHS published the Risk Based Performance Standards Guidance document. Because of the requirements of the authorizing legislation (§550 of the FY2007 DHS Appropriations Bill) the metrics provided for each of the 18 RBPS in the Guidance are less than precise in their specifications. Each one uses descriptive phrases to describe what must be accomplished rather than clearly measurable requirements of what must be done. This means that as each facility Submitter clicks on the ‘submit’ once their SSP submission is complete, there is an inherent uncertainty as to whether or not DHS will view the SSP as adequate. In December, DHS is scheduled to start sending inspection team to the Tier 1 facilities that completed their SSP submissions last month. If the inspectors bless the plans the facilities will know that they interpreted the Guidance document correctly. It is not clear that facilities with an unapproved SSP will receive anymore detailed guidance on how to correct their deficiencies; §550 still rules. The lower ranked tiers take little consolation from the fact that Tier 1 facilities will get their SSP’s evaluated first. Because of the Chemical-Terrorism Vulnerability Assessment rules that restrict sharing of facility security information, the follow on tiers will get little additional guidance from the inspections being conducted on the higher risk tiers. CFATA Legislation To add to that confusion, Congress is still in the process of trying to craft a permanent and ‘comprehensive’ authorization for the CFATS program. The current §550 authorization for CFATS expires on October 31st. The FY 2010 DHS Appropriations bill that was just sent to President Obama yesterday will provide an additional 11 months of extension for that authorization while Congress bangs out the details of the new legislation. What seems clear at this point in the legislative process is that the Democratic leadership of the House of Representatives is convinced that a Chemical Facility Anti-Terrorism Act should address a number of perceived deficiencies in the original authorization for CFATS. The current legislation working its way through the House committee process will result in a number of significant changes in the way that DHS will regulate chemical facility security. What those changes will be has yet to be determined by the political process. So, while high-risk chemical facilities are working hard on getting their SSP’s submitted and approved, they are also watching the political process change the landscape of their regulatory world. As they spend money on installing security equipment that may or may not be adequate for the current regulations, they face the prospect that even those vague requirements are in the process of changing. The only saving grace is that even if the current legislation were approved tomorrow, it would be at least 18 months before the new regulations will go into effect. So, the facility security teams working on their SSP need to ignore, for now, the political machinations that will affect their next iteration of the SSP process. They need to concentrate their work on finalizing their current SSP; leave upper management to worry about the final wording of the final CFATA legislation.

Wednesday, June 24, 2009

CFATA Passes in Committee

The House Homeland Security Committee held their third and final markup hearing on HR 2868 yesterday. This final meeting was held so that the committee could finish voting on three amendments that were considered last week. All three amendments failed on the recorded votes. The amended bill was passed and will be reported favorably to the full house. All votes today were on straight party lines. Members will have two days to submit their comments to be included in the report to the House. This means that the committee report and the amended language will probably not be available until at least Thursday. With no hearing currently scheduled on this bill before the Energy and Commerce Committee, the full House will not take up this bill before the 4th of July recess. With the August recess fast approaching it is unlikely that this bill will be taken up in the Senate until September or October. It is certainly beginning to look like inclusion of a CFATS extension in the appropriations bill was a smart move on the part of the Administration.

Wednesday, June 17, 2009

HR 2868 Analysis

As I noted yesterday, Monday afternoon Chairman Thompson announced the introduction of HR 2868 (actually that announcement was of the “June 15 version of discussion draft”). Since HR 2868 is available on the GPO website (access through the Thomas Website) I downloaded a copy and compared it to the draft version that I have (06-04-09 version). I have found 24 distinct changes in the two versions. Most of the changes are not significant, but there are a few that are worth looking at. No Title II The June 4th version of the committee draft included a two line mention of Title II: Community Drinking Water Systems and that is not shown in HR 2868. Presumably the original intent was that the House Energy and Commerce Committee would be writing the Title II requirements for adding requirements for the EPA to produce rules to secure the hazardous chemicals at water treatment plants. I expect that this is still being done, but it will be a stand alone bill. One interesting point is that HR 2868 will remove all of the §550 (Homeland Security Appropriations Act of 2007 Public Law 109-295) language from the Homeland Security Act. This removes the water treatment facility exemption from the CFATS program. Since I cannot find any language in HR 2868 that exempts those facilities from CFATA 2009, those facilities will presumably be covered. I expect that the yet to be introduced water treatment facility security bill will change that. That may be a ‘risky’ move, since failure to pass that bill will put water treatment facilities under the ‘control’ of DHS. Both Chairman Waxman and Congressman Markey are co-sponsors of this bill, so I expect that they know what they are doing. Another New RBPS CFATA has always included a ‘new’ risk-based performance standard; methods to reduce consequences of a terrorist attack (the popularly named ‘IST’ provision). HR 2868 adds another new RPBS; §2101(2)(T), methods to recover or mitigate the release of a substance of concern in the event of a chemical facility terrorist incident. I am a firm believer that any emergency response plan for a chemical facility should address methods to mitigate a release of hazardous chemicals. It only makes sense then that high-risk chemical facilities should include this mitigation as part of their SSP. One point that has not been included in the discussion of the time frame for implementation for CFATA is that these two new RBPS will require a re-write of the RBPS Guidance document. That cannot really begin in earnest until the final rule is published. Both of these new RBPS will mark a completely new area of concern for the document and this could easily add another year to the implementation process. This Guidance document re-write may be more extensive than just adding two new RBPS. Since the § 550 language is being removed, there will no longer be the statutory prohibition of DHS specifying specific security measures. While I have seen no other discussion of this issue, there is a natural tendency for regulatory agencies to ‘regulate’ so some of the security measures that DHS has been ‘urging’ may slip into being required. Alternative Security Program There has been a subtle word change in §2103(d)(1). The old language stated that the Secretary may accept an ASP “in lieu of all or part of the requirements of a security vulnerability assessment and site security plan otherwise required under this section”. The new wording allows the Secretary to accept an ASP “in combination with other components of the security vulnerability assessment and site security plan”. This makes it more explicit that DHS will require that parts of the CSAT tools be completed for the SVA or SSP submission even when an ASP is being submitted. This is actually the current case, but this explicitly requires this to happen. Personnel Surety Alternate Security Program HR 2868 adds a new section, §2103(d)(4), that allows for “a personnel surety alternate security program”. There is an interesting limitation to this ASP; the wording requires that the application must come from “a non-profit, personnel surety accrediting organization acting on behalf of, and with written authorization from, the owner or operator of a covered chemical facility”. I do not understand why this excludes commercial organizations that are doing background checks. There are three other limiting restrictions included in this section. The first is nearly meaningless since the Secretary would not presumably be able to evaluate if the process is “expedited, affordable, reliable, and accurate”, but the individual facility has an incentive to ensure this. The final restriction, “is a single background check consistent with a risk-based tiered program”, will also be difficult for the Secretary to evaluate and there is no real incentive for the facility to enforce this. The middle restriction {§2103(d)(4)(B)} is probably the most important from the individual’s point of view. This requires that the process is “fully protective of the rights of covered individuals through procedures that are consistent with the privacy protections available under the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.)”. This, unfortunately, will be equally difficult for the Secretary to enforce unless there is a vetting process established to ‘approve’ these agencies in advance of their use by facilities. This vetting process could certainly be written into the resulting regulations. Training Requirements There are three additions to the training program requirements. The first, §2103(f)(2)(G), requires that ‘employee representatives’ are involved in the selection of ‘existing national voluntary consensus standards’ that are used in training. This is undoubtedly being used to encourage the use of training programs developed by a variety of labor organizations. The other two additions increase the items that must be covered in the training. Section 2103(f)(2)(J) requires coverage of the “identification and assessment of methods to reduce the consequences of a terrorist attack”. This is being done to ensure that employees have a chance to ‘verify’ that the employer has looked at all appropriate IST possibilities. Finally §2103(f)(2)(K) requires that there is a “discussion of appropriate emergency response procedures”. Anyone with any sense would train employees on ‘emergency response procedures’, but I’m sure that there would facilities would overlook this if it were not for it being included in a DHS compliance checks. It certainly isn’t being checked in OSHA or EPA compliance inspections. Threat Information There was an addition made to §2106(a). This section requires that the Secretary is to provide covered facilities with information about any terrorist threats relative to that facility. The addition requires the Secretary to provide that information to “a representative of each recognized or certified bargaining agent at the facility, if any.” I think that this is being done to insure that facilities take threat information seriously. The only problem that I see with this, and many of the other sections that require sharing of information with ‘employee representatives’ and/or employees, is that this extends the number of people that must be vetted and cleared for access to the information. There is already a problem of lack of security clearances in the private sector hampering the sharing of classified intelligence information. It will also inevitably set up labor disputes when designated labor representatives cannot be cleared for some reason. It would seem that the intent of this language is that ‘employee representatives’ receive the same information as management. If DHS treats the requirement that way and refuses to share intelligence information with properly cleared management because there are no properly cleared ‘employee representatives’ then this will hamper security efforts.

Tuesday, December 30, 2008

SOCMA Takes on IST

I have noted in a couple of recent blogs that the American Chemistry Council (ACC) seems to be reluctant to directly attack potential requirements for inherently safer technology (IST) in up coming legislation on securing high-risk chemical facilities. According to a recent Synthetic Organic Chemical Manufacturers Association (SOCMA) press release SOCMA does not share that reluctance. In discussing what SOCMA would like to see in the way of chemical legislation in the 111th Congress SOCMA’s apparent first priority will be the moving of the current CFATS program to permanent status “without product substitution requirements under the guise of inherently safer technology (IST)”. The press release goes on to say:
“‘The American chemical manufacturing industry practices the fundamental principles of IST every day,’ said Joe Acker, President of SOCMA. ‘It is inappropriate for Washington bureaucrats to be given authority over which chemicals to substitute for security purposes. It will also likely create dangerous unintended consequences.’”
This will put SOCMA on a collision course with the House Homeland Security Committee that included a moderate IST requirement in its Chemical Facility Anti-Terrorism Act (CFATA) of 2008 (HR 5577) last year. That legislation will probably be the forerunner of any legislation that will make it to the floor of the House early in 2009. It is unlikely that SOCMA has the political power to get Chairman Thompson to pull an IST requirement from any chemical facility security bill that will pass through his committee. Nor does it seem likely that Chairman Waxman of the House Energy and Commerce Committee will have the desire to bury chemical security legislation like his predecessor did this year. Even Rep Green from Houston, TX (a chemical facility rich district if there ever was one), chair of the important Environment and Hazardous Materials subcommittee seems to be on the CFATA band wagon after Chairman Dingell was removed as the committee chair (see: “Waxman v. Dingell Aftermath”). No, I think that the ACC tactic will allow them to successfully urge some minor modifications to the IST provisions of the current language in HR 5577. Directly attacking IST will not be successful in the current political climate in Congress. The IST proponents have done too good job in defining the discussion in the minds of the public. Some form of IST will almost certainly be included in any chemical facility security legislation that makes it to a vote.
 
/* Use this with templates/template-twocol.html */