Showing posts with label CFATS Reauthorization. Show all posts
Showing posts with label CFATS Reauthorization. Show all posts

Tuesday, January 2, 2024

Reader Comment – CFATS and Congress in 2024

A long-time reader (from a slightly different security background) messaged me today, checking up on the status of the CFATS reauthorization. When I replied that the Senate still has not gotten around to voting on the bill {HR 4470 (removed from paywall)}, her response was ‘That’s crazy”. And it is. But this is a new year, and this deserves a re-look.

HR 4470

HR 4470 is still waiting at the Desk in the Senate. It could be taken up at any time. Since this is a relatively unimportant bill (as compared to 12 spending bills, military aid packages, border security, etc) the Senate is not likely to take up the legislation under regular order with three separate cloture votes, a series of amendments and a final vote on the bill. If amendments were approved, then the bill would have to go back to the House for another vote there before it could go to the President’s desk.

A more reasonable method of taking up a bill like HR 4470 that has wide-spread support is using the unanimous consent process. This takes just minutes to complete, and the bill would go quickly to the President. Simple. But just a single Senator (like Sen Paul) can stand and say; “I object.”; and, consideration stops, waiting for a chance to be considered under regular order, or the objecting Senator to make it known that they no longer object to the consideration of the bill.

Amendment as an Alternative

One of the most common ways of getting around the lone objection road-block in the Senate is to offer the language of the bill as an amendment to some other bill. Unfortunately, the rules and customs of the Senate provide the Chair and Ranking Member of Committees with veto power over any amendment being considered if it comes under the purview of their committee. Last year, Sen Paul became the Ranking Member of the Senate Homeland Security and Governmental Affairs Committee. Thus, Paul can prevent CFATS reauthorization from being added on the floor of the Senate to some other bill as an amendment.

Spending Bill as an Option

With yet another spending deadline (actually two separate deadlines) fast approaching and no agreement in the works, it is becoming increasingly possible that whenever this gets resolved this year, some sort of a consolidated spending bill(s) is(are) going to be the ultimate route (once again) out of the spending quagmire. Adding CFATS reauthorization language to that (one of those) bill(s), is becoming a better looking bypass of the block in the Senate. The NDAA is another bill that frequently gets used as a dumping ground for miscellaneous legislation. I was very disappointed when the 2024 NDAA came out of conference with significant additions, but no CFATS language.

On a final note, I am not sure that passing HR 4470 at this point would really solve the CFATS reauthorization problem. I published a post (removed from paywall) back in October that discusses the problems that I think CISA would face in standing the program back off after this long a period of quiescence. No one else is talking about this potential problem, so maybe this can be kept on the back burner.

Friday, July 7, 2023

House Committee to Markup HR 4470 – CFATS Extension

Today, the House Homeland Security Committee announced today that it would hold a markup hearing on July 12th, 2023. One of the three bills that will be considered is HR 4470, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2023. The official version of the bill has not yet been published by the Government Printing Office, the announcement provides a link to a Committee print of the bill.

According to that Committee print, this is a clean extension of the bill through September 30th, 2025. That date is important because it allows for future extensions to be made part of DHS spending bills or continuing resolutions. This makes extensions relatively easy to accomplish while the politicians continue to workout whatever problems are arising out crafting a reauthorization bill.

No one, not CISA or industry, want to see short-term extensions of the program. Such year to year continuation of the program leaves a large measure of uncertainty about the continuation of the program which causes personnel issues for CISA and security-budgeting issues for industry. Having said that, a short-term extension is much better than allowing the program to expire.

Tuesday, June 20, 2023

Draft Report for FY 2024 DHS Spending bill

Today, the House Appropriations Committee provided committee mark versions of both its FY 2024 DHS spending bill and the report to accompany that bill. As I mentioned earlier these two draft documents will be marked up by the full Committee tomorrow, along with similar documents for the Legislative Branch spending bill. I will wait for the final version for a complete review, but I do want to look at a few items from the Report for the CISA appropriations.

First off, CISA would be getting a small ($19 million) net increase over FY 2023 spending but a decrease ($130 million) from what was requested by the Administration.

There are a bunch of cybersecurity instructions for CISA in the report. I will cover those in detail in a later post.

There is no mention of chemical security or the Chemical Facility Anti-Terrorism Standards (CFATS) program in the report. This is not terribly unusual, the CFATS program is too small to receive detailed mention unless there are problems with the program that have come to the attention of the Appropriations Committee. Having said that, with the CFATS sunset date (July 27th, 2023) quickly approaching, I was hoping to see some mention of either the CFATS program or the ammonium nitrate regulations in the Report as kind of a morale boost for the Office of Chemical Security or the regulated community. May still see something added tomorrow (but probably not).

Tuesday, June 13, 2023

Committee Asks for Information on CFATS Program – 6-12-23

Yesterday, the Chair and Ranking Member of the House Energy and Commerce Committee sent a letter to CISA Director Easterly asking for information on the Chemical Facility Anti-Terrorism Standards (CFATS) program. The letter notes that:

“On July 27, 2023, the statutory authority undergirding the entire CFATS program is scheduled to sunset. In anticipation of any congressional efforts to extend the CFATS’s program, we would like to better understand the current operation of CFATS.”

The letter then goes on to ask seven multi-part questions about the program. While Congress certainly has the right (actually the obligation) to ask such questions about existing regulatory agencies, the Committee leadership should be ashamed of the fact that they have waited until almost the last minute to ask such questions. And to make matters worse, the Energy and Commerce Committee is not the committee with primary oversight responsibility for the CFATS program in the House. At least publicly, the House Homeland Security Committee has not taken even this much effort to address their responsibility to ensure that the CFATS program continues to support the chemical community and help protect the country from potential terrorist attacks using industrial chemicals.

Director Easterly will do a much better job than I in replying to these questions in a polite and informative manner. I will instead ask these congressional leaders a set of questions of my own:

• When was the last time that your committee held a hearing to look at the progress being made in the CFATS program?

• When was the last time that your committee requested a report from the Government Accounting Office about the CFATS program.

• When was the last time that your staff or committee members drafted a piece of legislation addressing issues covered by the CFATS program?

• How can you ask CISA what they intend to do about drone activities around chemical facilities when Congress has not authorized any violations of the various statutes that prohibit anyone from taking actions against unmanned aircraft in US airspace, nor have they taken any action to require the FAA to take long-overdue congressionally-mandated action to implement regulations allowing critical infrastructure facilities (certainly including CFATS covered facilities) to request that their facilities be designated as no fly zones for unmanned aircraft?

Since they are waiting to the last minute to pretend to care about the program or its impact on the regulated community, the four signatories of this letter should immediately offer a short term extension of the CFATS program like I have proposed in a recent post. That will give the two Committees in the House and the one in the Senate a reasonable chance to do their job in reviewing the CFATS program, determining what changes are appropriate and reauthorizing the program for a reasonable amount of time (5 to 7 years would be good). Long term reauthorization will allow them to forget about the program again.

Wednesday, March 25, 2020

S 3416 – Emergency Response Information Sharing


This is part of a series of blog posts on the recently introduced S 3416, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020, which would modify and reauthorize the Chemical Facility Anti-Terrorism Standards (CFATS) program for five years. Other posts in this series include:


Information Sharing Strategy


The strategy that I discussed in yesterday’s post is also intended to address “the sharing of information with the local emergency manager, the local emergency response provider, and any on site emergency response provider for a covered chemical facility” {§6(a)}. That strategy would include “guidance on further improving outreach to the local emergency manager, the local emergency response provider, and any on site emergency response provider for a covered chemical facility” {§6(b)(3)}. That guidance would include requirements for:

• A statement of the name or title, organizational affiliation, and phone number of a local emergency manager or local emergency response provider, and any on site emergency response provider, for the covered chemical facility;
• The documented policy of the covered chemical facility to coordinate access to the facility with the local emergency manager, local emergency response provider, and any on site emergency response provider described in sub-paragraph (A), for purposes of training and pre-incident planning; and
• Written documentation by the covered chemical facility that the owner or operator has provided the local emergency manager or local emergency response provider with need to know (within the meaning of 6 CFR 27.400(e), or any successor thereto) and appropriate chemical-terrorism vulnerability information credentials the name and amount of each chemical of interest held, stored, or manufactured at the covered chemical facility.

Information Sharing Requirements


Section 15(a) amends 6 USC 622(e) by adding a paragraph (6), Sharing Information with Emergency Response Providers. This new paragraph would require DHS to “make available to State, local, and regional fusion centers and State and local government officials, including officials of State or local law enforcement agencies and emergency response providers” {new §622(e)(6)(B)} information that DHS determines is necessary “to ensure that emergency response providers are capable to effectively prepare for, respond to, and mitigate chemical security incidents at covered chemical facilities”. That information will include:

• The name of the covered chemical facility;
• The address of the covered chemical facility;
• The phone number of the covered chemical facility;.
• The name and Chemical Abstract Service number of each chemical of interest used, stored, or manufactured as specified in the Top-Screen submitted by the covered chemical facility;
• The quantity and concentration of each chemical of interest specified in the Top-Screen submitted by the covered chemical facility; and
• The name or title, organizational affiliation, and phone number of a local emergency manager or local emergency response provider for the covered chemical facility specified in the site security plan of the covered chemical facility.

The bill would require to DHS to use an existing “single information technology infrastructure, information technology platform, online platform, or website” {new §622(e)(C)(i)} for this required information sharing. Presumably this means the Infrastructure Protection Gateway that ISCD established in 2015.

DHS would be required to update this information every 90-days.

Emergency Responder Outreach


The new §622(e)(6) above would also require the Infrastructure Security Compliance Division (ISC) to conduct an outreach to local officials during compliance inspections or audits. Inspectors would be required to {new §622(e)(6)(E)}:

• Contact and notify the local emergency manager or local emergency response provider, and any on-site emergency response provider, identified by the covered chemical facility that there is a covered chemical facility in their response area; and
• Inform the response officials identified by the covered chemical facility of the available secure communications and information technology infrastructure platforms or other mechanisms to obtain additional information.

Commentary


I have two major concerns about the emergency response language in this bill; the lack of definition of key terms and the ‘need to know’ language used.

There are three new terms used in this bill about emergency responders that are unique to the bill and require definitions:

• Local emergency manager;
• Local emergency response provider; and
• On-site emergency response provider.

First-off, I think that the third term ‘on-site emergency response provider’ should be eliminated. If the facility management has not provided an on-site responder with necessary information about all of the chemicals on the site (not just those covered by the CFATS program), the facility has problems that need to be addressed by OSHA, not DHS.

Next, instead of the term ‘local emergency manager’ I would suggest that the terminology that should be used is “the head of the Local Emergency Planning Committee established under 42 USC 11001. Then, instead of ‘local emergency response provider’ the bill should use ‘the head of the fire department that provides coverage for the facility’. Actually, the second term is operationally redundant for most facilities as local fire departments are supposed to be represented on the local LEPC. But that is only true for ‘most’ facilities since there are a number of areas that have no LEPC or the LEPC is not really active.

The bill uses the phrase “with a need to know (within the meaning of section 27.400(e) of title 6, Code of Federal Regulations” to modify the term ‘emergency responders’ wherever there is a requirement to share information with those responders. Now, I understand the need to protect Chemical-terrorism Vulnerability Information (CVI) which is what §27.400 refers to, and ‘need-to-know’ is a key part of that protection.

The CVI information that DHS is required to share under the proposed §622(e)(6) is limited to:

• The name and Chemical Abstract Service number of each chemical of interest used, stored, or manufactured as specified in the Top-Screen submitted by the covered chemical facility; and
• The quantity and concentration of each chemical of interest specified in the Top-Screen submitted by the covered chemical facility

Both of these items of information should be available to the listed agencies via the Environmental Protection Agency. With that in mind, I would like to propose striking the phrase “with a need to know (within the meaning of section 27.400(e) of title 6, Code of Federal Regulations” wherever is used in §622(e)(6) and adding the following at the end of the paragraph:

(f) The information provided in (b) is presumed to be Chemical-Terrorism Vulnerability Information in accordance with 6 CFR 27.400. The individuals listed in (b) with whom that information is to be shared are deemed to have ‘need-to-know’ under §27.400(e)(i).

One final niggly bit; the inclusion of the requirements for the outreach to local emergency responders in §6 of the bill is more than a little confusing since the other part of that section deals with cybersecurity. The emergency response information share provision of § should have been included as part of §15 that proposes the addition of §622(e)(6) probably as part of §15(b).

Monday, March 23, 2020

S 3416 Introduced – CFATS Reauthorization and Cybersecurity


Earlier this month Sen. Johnson (R,WI) introduced S 3416, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020. The bill would modify and reauthorized the Chemical Facility Anti-Terrorism Standards (CFATS) program for five-years. While there are some similarities to S 3405 that Johnson introduced in the 115th Congress, it would not be fair to state that this is a re-write of that bill.

This is a complex bill that covers a wide variety of different topic related to the CFATS program. Those topics include:

• Employee input regarding security measures.
• Strategy to improve cybersecurity and outreach to local emergency responders.
• Site security plan assessments.
• Expedited approval program.
• CFATS recognition program.
• Standards for auditors and inspectors.
• Personnel surety program.
• Security risk assessment approach and corresponding tiering methodology.
• Amendments relating to Appendix A of part 27 of title 6, USC
• Bidirectional information sharing platform.
• CFATS security harmonization waiver program.

Cybersecurity


Rather than eliminate CFATS coverage of cybersecurity issues as was initially proposed in S 3405, §6 of the bill would require DHS to periodically (initially 1 year and then every 2 years) to publish “a strategy that includes the strategic and operational goals and priorities of the Department of Homeland Security for covered chemical facilities to improve the cybersecurity of covered chemical facilities” {§6(a)}. That strategy would include an assessment of cybersecurity threats to {§6(b)(1)}:

The information technology or operational technology affecting the security risk of a chemical of interest of the covered chemical facility;
Processes and operations relating to a chemical of interest (COI); and
Security measures of the covered chemical facility relating to a COI;

The strategy would also include “processes for periodic mitigation of (the) security vulnerabilities” {§6(b)(2)} affecting those areas listed above.

Additionally, §3 of the bill would amend the stated purpose of the CFATS program in 6 USC 622 to specifically include cybersecurity. Paragraph (a)(2)(C) would be amended to read:

(C) establish risk-based performance standards designed to eliminate or mitigate physical, cybersecurity, and hybrid physical-cybersecurity vulnerabilities in order to address high levels of
security risk at covered chemical facilities; and

Cybersecurity Definitions


Section 2 of the bill would add two new cybersecurity related definitions to 6 USC 621; ‘hybrid physical-cybersecurity vulnerability’ and ‘security vulnerability assessment’.

The term ‘hybrid physical-cybersecurity vulnerability’ is defined as “a vulnerability in the security of a covered chemical facility that relates to the combination of the physical operations and cybersecurity operations of the covered chemical facility” {new §621(10)(A)}. It would also include a vulnerability of a covered chemical facility to {new §621(10)(B)}:

A physical threat to a cybersecurity operation affecting the chemical of interest of the covered chemical facility; or
A cybersecurity threat to a physical operation of the covered chemical facility.

The second term, ‘security vulnerability assessment’, is defined as an assessment of the vulnerabilities of a covered chemical facility to physical threats and cybersecurity threats to the information technology or operational technology of the covered chemical facility as those technologies relate to {new §621(12)(ii)}:

A chemical of interest;
An operation involving a chemical of interest; or
A security measure of the covered chemical facility;

Moving Forward


Johnson is the Chair of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. Typically, this would ensure that this bill would receive coverage by that Committee. The bill was initially listed as being included in the Business Meeting that occurred right after the bill was introduced, but it was removed from the agenda shortly thereafter. I discussed this in some detail in my earlier post about that hearing.

I will be very surprised if this bill does get considered in Committee. While it looks like Johnson has made several attempts to address the concerns of Democrats in this bill (more on those is subsequent posts), there are still changes that the opposition party would like to see made in this bill. If the bill is brought up, I would expect to see substitute language offered by Johnson to address at least some of those concerns.

As I mentioned earlier, the only way that this bill is going to make it to the floor of the Senate, is for it to be considered under the Senate’s unanimous consent process. A single Senator can stop that process by objecting and those objections need not have anything to do with the provisions of the bill. This has been a contentious session of Congress and the COVID-19 epidemic is not making it any less so.

The introduction of S 3506 (the language for which is still not available) by Sen. Lankford (R,OK), a Subcommittee Chair on the HGSA is, it seems to me, a clear recognition that S 3416 will not move forward.

Commentary


While I do not think that this bill will move forward, I will still be making additional posts about the provisions of this bill as it is an interesting look at the changes in Johnson’s outlook on the CFATS program.

The cybersecurity provisions are an important case in point. First off, Johnson has made a complete turnaround on his support for cybersecurity coverage in the Program from last session. Where he was prepared to eliminate cybersecurity coverage, he is now making it a key point in the purpose and scope of the program. Nothing in this bill will directly require a change in the current cybersecurity processes in the CFATS program or individual site security plans, but it does specifically require DHS to take a hard look at those processes and security measures and periodically re-address them in the future.

Second, Johnson’s emphasis on cybersecurity in this CFATS reauthorization bill (and in fact, the actual publication of the bill at all) is a direct slap at the President’s attempt to deauthorize the CFATS program and use its inspectors as additional Protective Security Advisors. If there were any thought that Congress was going to go along with this eradication of the CFATS program, this bill is certainly a clear sign that it is not going to happen without a fight.

The one odd thing about the ‘new’ cybersecurity review requirements under §6 is the conspicuous absence of the Cybersecurity and Infrastructure Security Agency (CISA). While the program is currently included under the ‘infrastructure security’ wing of the Agency, the bill keeps referring to the ‘Secretary’ as being the responsible party for effecting changes in the program. I thought that the whole purpose of elevating the old NPPD to Agency status was to raise the status and level of responsibility for the newly crowned Director.

I am particularly happy to see Johnson acknowledge that there are three components to cybersecurity at chemical facilities, IT security, OT security and Security security, the cybersecurity of facility security controls. While there are certainly those in the control system security field that will object to the use of ‘operations technology’ to describe the full gamut of the control system security realm, it is important to note that Johnson (not a techy) is apparently using the undefined term in the broadest sense. And I like the way that he spells out the dual importance of physical security of cybersecurity controls and the cybersecurity of physical security controls.

There is a lot of interesting stuff in this bill, and it is a shame that the effort currently appears to have been wasted.

Friday, March 13, 2020

HSGA Markup Hearing – No CFATS Bill – 3-11-20


Earlier this week the Senate Homeland Security and Governmental Affairs Committee held a business meeting to markup 14 pieces of legislation. S 3416, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020, was not considered. Two other bills of interest here (S 3045, Cybersecurity Vulnerability Identification and Notification Act of 2019; and S 3207, Cybersecurity State Coordinator Act of 2020) were amended and adopted by the Committee. I will discuss those revisions in separate posts.

Where was S 3416?


S 3416 was removed from the agenda early this week, shortly after the introduction of HR 6160, the House CFATS extension bill. That bill, if passed (and it will almost certainly be passed next month), would take pressure of the Committee to address the CFATS program in a more complicated fashion. That is one of the contributing factors to S 3416 not being considered on Wednesday.

The other consideration is almost certainly the inability of the Committee to come up with some sort of consensus language for S 3416. Chairman Johnson (R,WI) knows that for a bill to make it to the floor of the Senate under the unanimous consent process (the only way a stand-alone CFATS bill is going to be considered in the Senate) is with the active support of Ranking Member Peters (D,MI) and, probably more importantly, the support of Sen. Carper (D,DE) who effectively killed Johnson’s last attempt at CFATS legislation, S 3405, in the 115th Congress.

Commentary


Johnson has never been a strong supporter of the Chemical Facility Anti-Terrorism Standards (CFATS) program, basically because he does not like regulatory programs. He has voted for CFATS bills in the past because the program allows for regulatory standards to be negotiated at the facility level, so it is not a one-rule-fits-all style regulation. The fact that industry is generally supportive of the program also provides Johnson with some political cover.

With the President’s budget proposal to eliminate the CFATS program in FY 2021, Johnson was put in a tough position of trying to decide who to support, the President or industry. HR 6160 looks like his easy out, kicking the can down the road for 18 months. One thing Johnson should consider, however, is that 18 months puts the problem before the 117th Congress.

With the potential for COVID-19 tanking the economy between now and November, Johnson should not assume that he will chair the HSGA Committee next session. There is now a definite possibility that the Democrats will control the Hill and the White House next year, possibly (depending on how bad things get) with strong, veto-proof majorities. This could be Johnson’s last chance to have a major say in how the CFATS program proceeds.

Friday, March 6, 2020

Bills Introduced – 3-5-20


Yesterday with the House and Senate preparing to head home for the weekend there were 67 bills introduced. Three of those bills may receive additional coverage in this blog:

HR 6096 To improve oversight by the Federal Communications Commission of the wireless and broadcast emergency alert systems. Rep. McNerney, Jerry [D-CA-9]

HR 6113 To establish an Advanced Research Projects Agency-Water, and for other purposes. Rep. Katko, John [R-NY-24]

S 3416 A bill to reauthorize the Chemical Facility Anti-Terrorism Standards Program of the Department of Homeland Security. Sen. Johnson, Ron [R-WI]

I will be watching both House bills for cybersecurity language and definitions; not holding my breath.

Looking forward to seeing what Johnson has come up with this session for the CFATS program. Nothing on his web site about this bill, but that is not too unusual. Earlier this week, Johnson did make a comment about CFATS program in a hearing on the DHS 2021 Budget proposal:

“Additionally, CISA provides security assessments and advisory services to the sixteen critical infrastructure sectors of our economy. For all but one sector in which CISA has oversight, CISA employs a common approach by using voluntary Protective Security Advisors. In 2006, Congress authorized a specific regulatory program for the Chemical sector — the Chemical Facility Anti-Terrorism Standards program (CFATS). CFATS is set to expire in the coming weeks, and the administration proposes to transfer CFATS Chemical Security Inspectors into the same voluntary system used for the other critical infrastructure sectors. I support this common sense approach, but am willing to work with industry, the administration, and congressional colleagues on a path forward we can hopefully all agree on.”

This bill is currently scheduled to be considered in the Senate Homeland Security and Governmental Affairs Committee next week.

Friday, February 7, 2020

CFATS Extension Complicated


Yesterday I received an interesting Tweet® from @DwightFoley:

@pjcoyle have you been following @SenRonJohnson refusal to move a bill to reauthorize #CFATS? You should”

The short answer is of course: yes I have been following these lack of developments on the CFATS reauthorization front. The longer answer is, as always, more complicated than that.

CFATS Extension


A quick recap: The current CFATS authorization language comes from the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014 (PL 113-254). The termination date in that bill was set at January 18th, 2019. Last year it was extended by the Chemical Facility Anti-Terrorism Standards Program Extension Act (PL 116-2) until April 18th, 2020.

Sen Johnson Activities


With the Republican controlled House not taking any action on the CFATS extension in the first 21 months of the 115th Congress, Sen Johnson (R,WI) introduced S 3405, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2018. This was a comprehensive reauthorization of the CFATS program about which I wrote extensively. The bill was introduced in September of 2018 and marked up and accepted by Johnson’s Homeland Security and Governmental Affairs Committee later that month.

In late November Johnson tried to get the bill to the floor of the Senate under the unanimous consent process, but was blocked by Sen Carper (D,DE).

A modified version of S 3405 was introduced in the House as HR 6992 in November of 2018, but no action was taken on that bill.

A clean extension of the CFATS program, HR 7188, was subsequently introduced in the House in December 2018. Johnson famously objected to that bill complaining that the House did not try to take any action earlier to extend the CFATS program. The bill was never considered.

Political Difficulties


The problem here is that the Republicans and Democrats, while they both generally agree on the need for a CFATS program, have substantially different outlooks on how that program should be structured. Republicans generally avoid detailed regulatory schemes as being too restrictive and costly for businesses. Democrats are more activist oriented wanting to see tighter regulatory control and wanting more recognition of worker participation efforts.

Because neither side actually controls Congress (a simple majority is not really control in either body), the Committees involved in the CFATS authorization process generally have try to reach some sort of reasonable compromise with the non-majority party to try to move legislation forward. The reason for this is that the CFATS program is not ‘important enough’ to bring to either the floor of the House or Senate under the time-consuming regular order. Those processes are reserved for essential political statements of the controlling party (which seldom actually become law), must pass authorization/spending bills, or large scale problems about which there is substantial knee-jerk consensus.

Thus, the CFATS reauthorization legislation is going to have to come to the floor under abbreviated consideration options. In the House this is the suspension of the rules process that requires a supermajority to pass. In the Senate this is the unanimous consent process where the objection of a single Senator will prohibit the bill from being considered.

Lack of Action in 116th Congress


Foley is correct that Johnson (nor any of this other 99 senate colleagues) have taken any action on CFATS authorization in the 116th Congress. Johnson figures that he made his attempt in the 115th Congress and was rebuffed. Since HR 3256, was introduced on the House side last year, he can afford to wait for that body to take action. There is no need for him to expend his political capital formulating an ‘acceptable’ compromise when the House managers are already working that issue.

Unfortunately, HR 3256 has apparently died in the House. Rep Thompson (D,MS) could not build bipartisan support for the bill in the House Homeland Security Committee, so he punted responsibility for that action to the House Energy and Commerce Committee, the second committee of jurisdiction for the bill. To date, that Committee has yet to hold a markup hearing. Hopefully this means that behind the scenes, staffers are still working out compromise language that both sides can reluctantly support to move the bill forward.

There is still time for Congress to act on HR 3256. But as April 18th gets closer, it gets more likely that another short-term reauthorization bill will be required to keep the CFATS program in operation.


Thursday, June 20, 2019

HR 3256 Amended and Adopted in Homeland Security Committee

Yesterday the House Homeland Security Committee amended and subsequently adopted HR 3256, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2019. The alternate language was adopted by a voice vote (pretty much along party lines by the sound of it) and the final action was taken by a recorded vote of 14 to 12; strictly along party lines.

The Republican opposition to the bill was voiced by Ranking Member Rogers (R,AL) and addressed predictable issues. One notable portion of that opposition narrative was voiced at 17:25 into the video when Rogers stated: “The bill enlarges the whistleblower protection program in an agency that does not have the capacity or skills to administer such a program.” Comment: This is perhaps why the Democrats felt that changes in the current whistleblower provisions were needed.

All three statements on the bill {Chairman Thompson (D,MS), Rogers, and Subcommittee Chair (and author of the bill) Richmond (D,LA)} all emphasized how important reauthorization of the CFATS program was and how hard everyone was working together to get this done. They all agreed that additional work needs to be done to bill to get it to the point where there can be strong bipartisan support for the bill when it gets to the floor of the House.

The next venue for consideration of the bill will be the House Energy and Commerce Committee. Further amendments of the bill are sure to be seen there.

Watching this hearing it was clear that it was a closely scripted proceeding with every remark read from the script to ensure that nothing was said that was out of line. Even so, there was some minor drama when it came to the final vote on the adoption of the bill due to the number of Democrats that were not able to make it to the hearing. This made the vote much closer than it would have been.

Tuesday, June 18, 2019

HR 3256 Introduced – CFATS Reauthorization – Part 2


This is the second installment of a look at HR 3256 (note: an official copy of the bill is now available), the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2019. The initial post was made on Sunday. The House Homeland Security Committee will markup this bill tomorrow and substitute language for the bill will be considered. Things are moving fast here.

New Sections Added


The substitute language is adding the following new sections:

§11. Review of tiering methodology.
§15. Voluntary program.
§16. Study on local emergency response capacity to respond to chemical security incidents.
§17. Previously approved facilities.

Changes to Previously Reported Provisions


The substitute language does change some of the provisions that I reported upon in my last post.

Section 4 of the bill is substantially changed. The new version removes the rewrite of paragraph (a) that I previously described. It also rewrites paragraph (b), but the new version (along with a small format change) revises the language on State and local government officials by clarifying that the information sharing will take place only “with respect to information on any chemical facility of interest within the jurisdiction of the official, but only if such information may not be disclosed pursuant to any State or local law” {new §623(b)(1)}. It also clarifies the information sharing with the new Chemical Security Advisory Committee will only be for the purposes of “conducting official duties and responsibilities as described in such section” {§623(b)(3)}.

Comment: These changes clearly protect the current Chemical-Terrorism Vulnerability Information (CVI) program.

No significant changes were made to the other two sections which I discussed. The remainder of this post will only deal with the provisions found in the substitute language that the Committee will markup tomorrow.

Chemical Security Advisory Committee


Section 7 of the bill would add a new section (§2110) to the Homeland Security Act of 2002 which would become (probably) 6 USC 630. The new section would require DHS to form the Chemical Security Advisory Committee. The new CSAC would consist of 12 members representing {new §630(b)(1)}:

Industry;
Academia;
Labor;
Emergency response providers;
Local emergency planners;
Environmental, community, or public health advocates, particularly for communities with high concentrations of covered chemical facilities; and
Cybersecurity and information policy.

The purpose of the CSAC is broadly written; to “advise the Secretary on the implementation of this title” {§630(a)}. The only other operational guidance provided is the recommendation that the Committee “may establish subcommittees to assesses and recommend improvements to the risk tiering methodology for chemical facilities, the risk-based performance standards for chemical facilities, risk reduction strategies, and other aspects of the program under this title as the Secretary determines appropriate” {§630(c)}.

Comment: Other advisory committees have been very helpful to their Federal Agency in providing insight and technical support for policy development. One provision that is sometimes seen (particularly for DOT advisory committees) is a requirement for the Secretary to seek advice from the committee on all proposed rulemakings under the committee’s charter. That might be a useful addendum to this section.

Review of Tiering Methodology


I generally do not worry too much about mandated studies and reports to Congress in authorization bills, but I do want to briefly mention the provisions of §11 of this bill because of one of the requirement. This section would require the DHS Cybersecurity and Infrastructure Security Agency (CISA) to conduct a review of the current tiering methodology used by the Infrastructure Security Compliance Division (ISCD) to assess the relative risk of terrorist attack at a facility covered by the CFATS program. One of the items that the review is supposed to take into account is {§11(a)(1)(c)}:

The vulnerabilities of chemical facilities to cybersecurity threats, including the vulnerabilities of facilities’ information technology and operational technology and the implications on the potential for penetration of both the physical security and cybersecurity of facilities.

Comment: I generally applaud this idea, but it would pose some significant challenges to expand the Top Screen submission to provide adequate information for ISCD to properly asses this risk. What might be need to implement this would be to go back to the requirement to submit a security vulnerability assessment report to DHS prior to ISCD making a tiering decision. That is not, however, something that the lawmakers would necessarily want to consider in requiring this review and report.

COI Mixture Appeals


Section 14 of the revised bill would require DHS to establish “a process through which the Secretary can be petitioned to exclude a product or mixture” from consideration in the risk assessment process used to establish that a facility is a covered facility or to tier the facility. The only guidance provided on this process is that the information collected will not be subject to the requirements of 44 USC Chapter 35 (presumably the information collection requirements of §3507) or the Freedom of Information Act requirements.

This requirement supports a change made to §622 {a new paragraph (f)} by §3 of the bill. That new paragraph would authorize DHS to exclude a product or mixture from the Top Screen reporting requirements if DHS determines “determines that the product or mixture does not present a terrorism risk for which the chemical of interest contained within the product or mixture was included on Appendix A [COI list for 6 CFR 27]”.

Comment: The current mixture rules used by ISCD are very broadly written and almost certainly cause reporting of mixtures that do not pose the hazards associated with the underlying DHS Chemical of Interest. I am thinking primarily of flammable liquids; a mixture containing 2% of a flammable COI may not itself be flammable. The problem is that the way (f) is written this would affect Top Screen submissions. This would require additional access to the Chemical Security Assessment Tool prior to CVI training.

Moving Forward


This bill will probably amended further tomorrow, but it will certainly be adopted by the Committee. The only question is how much support it will receive from the Republicans. It looks to me that the Democrats have moderated their changes enough that there could be some support, or at least acquiescence by the part of the business community. This would allow some of the Republicans to vote in favor of the bill.

The main problem will be in the Senate. This bill will almost certainly not be considered in the Senate Homeland Security and Governmental Affairs Committee. Sen. Johnson (R,WI) will almost certainly introduce his own legislation and the Committee will consider that instead of this bill. The question will then be how the Senate leadership decides (if it decides) to proceed; it could bring Johnson’s bill to the floor and send it to the House for consideration, consider the House bill as passed, or (more likely) consider the House bill by substituting Johnson’s language.

I do not expect the Senate to take any action of CFATS authorization until just before the current expiration next year. And that may just take the form of another extension.

Sunday, June 16, 2019

HR 3256 Introduced – CFATS Reauthorization - Part I


Earlier this week Rep. Richmond (D,LA) introduced HR 3256, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2019. Normally, I wait for the official print of the bill before I review it, but the House Homeland Security Committee has a committee print available and have scheduled a mark-up hearing of the bill on Wednesday, so I will be reviewing the committee print today.

HR 3256 would reauthorize the Chemical Facility Anti-Terrorism Standards (CFATS) program for an additional five plus years (until May 1st, 2025; §16). The bill also provide a number of amendments to the current authorization language (6 USC Subchapter XVI).

Major Additions


The following sections of the bill show the areas where significant changes would be made to the existing program:

§4. Protection and sharing of information.
§5. Civil enforcement.
§6. Whistleblower protection.
§7. Chemical Security Advisory Committee.
§12. Voluntary mechanism for reporting drones and other emerging threats.
§13. Regulations regarding specific products and mixtures containing chemicals of interest.

The following sections provide information on the studies and reports required by the bill:

§8. Implementation plan and report to Congress.
§9. Study on risks posed by excluded facilities.
§10. Study on feasibility of waiver program.
§11. Comptroller General reports.

Information Protection and Sharing


Section 4 of the bill would make a number of changes to 6 USC 623, Protection and Sharing of Information. The first change would be to rewrite paragraph (a) to read:

(a) In general - Notwithstanding any other provision of law, with respect to information in the possession of the Department, the Secretary shall protect information developed under this subchapter, including vulnerability assessments, site security plans, and other security related information, records, and documents shall be given protections from public disclosure consistent with the protection of similar information under section 70103(d) of title 46 [link added].

Additionally, a complete rewrite of paragraph (b) includes:

(2) NONDEPARTMENTAL INFORMATION. — Information is not protected pursuant to subsection (a) if it is—
(A) not in the possession of the Department;
(B) developed under this title but has been previously produced or developed for other purposes; and
(C) is already publicly available, readily discoverable, or otherwise lawfully disclosed.

Comment: It looks like this is intended to change the Chemical-Terrorism Vulnerability Information (CVI) program to make it more like other sensitive but unclassified (SBU) information protection programs. Currently the CVI program has strict information protection rules for information held at each covered facility. Other SBU only protect information in the hands of the Federal government, its contractors, and such information shared with State, Tribal, and local governments. If that was the intent, it looks to me like the terminal ‘and’ in (2)(B) nullifies that attempt as it does not remove protections already provided in the program. DHS would not be required to change the CVI rules under these changes. If the terminal ‘and’ were changed to ‘or’ then (2)(A) would be the controlling factor for removing CVI protections for information held at facilities.

As noted above §4 also rewrites (b), changing the information sharing requirements of §623(b) to require DHS to provide information (upon request) to {new §623(b)(1)}:

State, local, and regional fusion centers (as that term is defined in section 210A(j)(i) of this Act) and State and local government officials, including law enforcement and emergency response providers;
Members of Congress;
Members of the Chemical Security Advisory Committee under [new] section 2010 of this Act; and
The Comptroller General of the United States.

The addition of fusion centers and members of Congress in this paragraph allows the bill to delete the current paragraphs (c) and (f) from §623.

Comment: This is a proforma change to appease supporters who want ‘better’ information sharing about the hazards associated with covered facilities. This really provides no new requirements for the CFATS program beyond the addition of the new Advisory Committee which will be covered in more detail later in the bill.

Civil Enforcement


Section 5 of the bill would amend §624, Civil Enforcement. The first set of amendments deals with changes to paragraph (a), Notice of noncompliance. The first change the time limits for DHS to provide a written notice of non-compliance from 14-days to 3-days. And the second changes the time limit a facility would have to comply with a DHS order to comply, from 180 days to 30 days.

The next set of changes address paragraph (b)(2) civil penalties for non-reporting chemical facilities of interest. The change clarifies that the subparagraph applies to Top Screen submission requirements or supplemental information thereto.

The third set of changes paragraph (c)(1), expanding the DHS authority for issuing emergency orders due to violations of CFATS program requirements or the risk of terrorist incidents. It now adds a vague “or other malicious act” that may affect a chemical facility of interest to the list of potential causes of “an imminent threat of death, serious illness or severe personal injury that the Secretary could attempt to prevent by requiring facility action.

Comment: This is ‘other malicious act’ is vague enough to provide authority to order cybersecurity measures or even the development of active shooter programs. The current management would be unlikely to use this authority; their emphasis is on cooperative enforcement. Who knows what could happen in the future?

Whistleblower Protections


Section 6 of the bill modifies the existing whistleblower protections found in §625. The bill expands on the existing requirements for:

• Confidentiality;
• Response to reports; and
• Opportunity for review

The bill also adds a new paragraph (c) to the section; Procedure and Remedy. It provides requirements for DHS to “establish a procedure for the review and investigation of complaints of reprisals” {new §625(c)(i)} as well as establishing remedies for violations of the same.

NOTE: I am about half-way through the major CFATS changes proposed by this new bill and we are already at about 1000 words. It is getting a bit long for a blog post; even by me. I will try to finish up by tomorrow.

Friday, June 14, 2019

Bills Introduced – 06-13-19


Yesterday with both the House and Senate preparing to leave for the weekend (and the House only about half-way through consideration of HR 2740, the first FY 2020 spending minibus) there were 104 bills introduced. Six of those bills are likely to see future consideration in this blog:

HR 3256 To amend the Homeland Security Act of 2002 to reauthorize and improve the Chemical Facility Anti-Terrorism Standards Program, and for other purposes. Rep. Richmond, Cedric L. [D-LA-2]

HR 3261 To direct the Secretary of Transportation to establish a Smart Technology Traffic Signals Grant Program, and for other purposes. Rep. Cardenas, Tony [D-CA-29] 

HR 3266 To direct the Secretary of Defense to carry out a program to enhance the preparation of students in the Junior Reserve Officers' Training Corps for careers in computer science and cybersecurity, and for other purposes. Rep. Fletcher, Lizzie [D-TX-7]

HR 3270 To amend title 18, United States Code, to provide a defense to prosecution for fraud and related activity in connection with computers for persons defending against unauthorized intrusions into their computers, and for other purposes. Rep. Graves, Tom [R-GA-14]

HR 3290 To provide for mandamus actions under chapter 601 of title 49 of the United States Code. Rep. Speier, Jackie [D-CA-14]

S 1867 A bill to amend the Homeland Security Act of 2002 to establish in the Department of Homeland Security an Unmanned Aircraft Systems Coordinator, and for other purposes.

I will be watching HR 3261 for cybersecurity requirements and HR 3266 for control system security language. HR 3270 is the ‘hack back’ bill that was in the news yesterday. Chapter 601 is the Pipeline Safety portion of the USC.

Monday, June 3, 2019

Committee Hearings – Week of 06-02-19


This week the House and Senate will both be in session. Lots of hearings in the House; of interest here are FY 2020 spending bills and HR 2500, FY 2020 NDAA, markups. Fewer hearings in the Senate, but one will address reforming CFATS.


FY 2020 Spending Bills


Tuesday, House, Full Committee, Transportation, Housing, Urban Development, and Related Agencies (THUD) Appropriations Bill;
Tuesday, House, Full Committee, Agriculture, Rural Development, Food and Drug Administration, and Related Agencies (ARF) Appropriations Bill;
Wednesday, House, Homeland Security Subcommittee, Homeland Security;

HR 2500 Markups – FY 2020 NDAA



CFATS


On Tuesday the Senate Homeland Security and Governmental Affairs Committee will hold a hearing on “Sensibly Reforming the Chemical Facility Anti-Terrorism Standards Program”. The witness list includes:

Brian Harrell, DHS;
Nathan Anderson, GAO
Matthew Fridley, Brenntag North America;
Timothy O'Brien, Detotec North America;
William Erny, American Chemistry Council;
Andrew Wright, International Liquid Terminals Association; and
John Morawetz, International Chemical Workers Union Council

I do not expect anything new here outside of an updated GAO report on the CFATS program. It is odd that Director Wulf is not sitting in for DHS, but his boss should be an interesting substitute.

Tuesday, April 30, 2019

Eliminating CVI in CFATS Reauthorization Bill?


I am hearing rumors that a CFATS reauthorization bill currently being drafted might include provisions that would eliminate the Chemical-Terrorism Vulnerability Information (CVI) program from the Chemical Facility Anti-Terrorism Standards (CFATS) program. The CVI program is authorized under 6 USC 623 and regulated under 6 CFR 27.400 and a detailed guidance document here. The CVI program protects security information about facilities in the CFATS program from public disclosure.

There have been complaints in Congress over the years that the presence of the CVI program interferes with facilities sharing information with emergency responders. Not having seen the specific wording of possible CVI removal provisions, I can only suppose that these provisions would be an attempt by congressional staffers to remove such impediments to information sharing.

CVI Background


The CVI program is one of the most unusual Controlled Unclassified Information (CUI) programs in the Federal government. Most CUI programs limit the Federal Government’s sharing of information provided to the government by the private sector or developed in house by government agencies. The CVI program, on the other hand, requires both the covered private sector organizations and the government to protect the covered information regardless of who initiates the information.

Information developed by covered facilities that is considered to be CVI (and thus protected from disclosure) includes all submissions made by the facility to DHS through the CFATS Chemical Security Assessment Tool (CSAT), copies of security vulnerability assessments and site security plans, and the working papers supporting those documents. Certain of those supporting documents are exempted from CVI classification; specifically, any records that are required to be maintained by other regulatory programs including chemical inventory information and emergency response plans are exempted from CVI protections.

Disclosures of CVI information can only be made to personnel who have received CVI Certification and have a verified ‘need-to-know’ the specific information. The ‘need-to-know’ requirements are outlined in §27.400(e) and specifically includes State and local officials.

CVI and Emergency Response Planning


Emergency response planning for chemical releases is covered briefly in the CFATS regulations as part of the Risk-Based Performance Standard #9 {§27.230(a)(9)}, but both the regulation and the CFATS RBPS Guidance document make it clear that those requirements are only response plans for security breaches, not accidental chemical releases. Even then, the CFATS planning process envisions inclusion of law enforcement personnel in preventing the attack or arresting the perpetrators, NOT fire or emergency medical technicians responding to the affects of the potential attack. That chemical emergency response is already covered under EPA regulations.

Law enforcement personnel working with facility personnel to develop security response plans at a CFATS covered facility would be expected to be covered by CVI rules including CVI training and certification requirements. Emergency medical technicians and fire fighters participating in planning for chemical releases (either accidental or deliberate) would be covered under the EPA regulations and would not require CVI clearances.

Members of a Local Emergency Response Committee (LEPC) would not require CVI certification to receive chemical inventory data from local chemical facilities covered by the CFATS program because the LEPC notification requirements are covered under the EPA regulations and are exempted from CVI classification {§27.405(1)}.

Continued Need for a CVI Process


The purpose of the CVI program is to ensure that critical security information about a CFATS covered facility is not made publicly known and thus become available to nefarious personnel who could use that information in the planning and execution of an attack on a chemical facility. The mere knowledge of the existence of an inventory of items on the DHS chemicals of interest (COI) list is not critical safety information. That information is generally already publicly available through the EPA (a discussion of the EPA’s limiting of the sharing of that information is an entirely separate topic).

I suppose that the CVI program could be replaced with another of the existing CUI programs, probably the DHS Protected Critical Infrastructure Information (PCII) program. That would also protect the information originating at the facility level from disclosure by Federal, State and local governments. What it would not do, however, is to establish standards for facility personnel to protect the required information. Without information protection requirements like those in the CVI program, it would be easy enough for attackers to get the information that terrorists need to circumvent the security procedures at CFATS covered facilities.

Rather than abolishing the CVI program, Congress might want to make clear that certain information will be freely shared with LEPCs, local law enforcement, fire departments and hospitals. Last year I suggested language for that information sharing that operates within the bounds of the CVI program. This would be in addition to any information sharing already required between facilities and LEPCs and fire departments by EPA regulations.

Thursday, April 25, 2019

CFATS Podcast


This week Dan Verton had me on his LiveSafe podcast discussing the Chemical Facility Anti-Terrorism Standards (CFATS) program reauthorization process. He discussed some of the Congressional concerns that have been raised during the reauthorization process to date and we talked about the practical aspects of some of those issues. Its well worth the listen even ignoring my contribution at the end (grin).

I have written rather extensively on the CFATS reauthorization issue. In particular, last year I did a series of blog posts on language that I would like to see included in the reauthorization bill. These posts include:


Friday, March 15, 2019

More on CFATS Hearing and Emergency Response


It is becoming increasingly obvious that the Democrats on both the House and Senate Homeland Security Committees are concerned about the role of emergency response in the Chemical Facility Anti-Terrorism Standards (CFATS) program. This means that it is becoming increasingly likely that some sort of emergency response provision will find its way into whatever final bill comes out of the 116th Congress reauthorizing the CFATS program. Thus, the topic bears more discussion.

EPCRA


The CFATS regulations are not the base law in the United States for emergency response information sharing and planning for most chemical facilities. The base law for that requirement is found in the Emergency Planning and Community Right-to-Know Act (EPCRA) codified at 42 USC Chapter 116 with the regulations established at 40 CFR 355. Among other things that Chapter establishes the Local Emergency Planning Committees, provides for the preparation of comprehensive emergency response plans, and details what facilities are covered under the provisions of EPCRA.

Under the EPCRA regulations a facility is subject to the emergency planning requirements of the regulation if they have any chemicals on either of the extremely hazardous substance lists {Appendixes A (alphabetical order) & B (CAS # order) to §355} in excess of the threshold planning quantity listed in those appendixes. For chemicals on those lists that were included in the DHS list of chemicals of interest (COI), a large portion of the toxic-release hazard chemicals on the COI list, were taken with the same TPQ (called screening threshold quantity in the CFATS program).

Most of the chemicals on the EPCRA lists were not included in the CFATS COI list. Only the most toxic chemicals from the list were included as DHS concluded that only the most toxic would form the basis for a credible terrorist attack on a facility holding those chemicals.

Interestingly, two other categories of chemicals that are included in the DHS COI as release hazard chemicals are not addressed in the EPCRA emergency planning regulations or statutes; flammable and explosive chemicals. Congress intended for the EPCRA requirements only to apply to toxic-release hazard chemicals.

Actually, the EPCRA regulations do not require companies or facilities holding extremely hazardous chemicals to do any sort of emergency planning. Those facilities are simply required to report the following types of applicable information to their Local Emergency Planning Committee (LEPC) {§355.21 table}:

• Provide notice that the facility is subject to the emergency planning requirements of EPCRA;
• Designate (and provide notice to the LEPC of) a facility representative who will participate in the local emergency planning process as a facility emergency response coordinator;
• Provide notice of any changes occurring at the facility that may be relevant to emergency planning; and
Provide any information necessary for developing or implementing the local emergency plan if requested by the LEPC.

All of the responsibility for planning, training, coordinating and exercising the emergency plan fall to the LEPC {42 USC 11003(c)}. Unfortunately, Congress has provided no funding to, or even provided provisions for funding, the LEPCs. With the Federal government providing no funding for these organizations, there is no effective way for the EPA to regulate the operation of LEPCs or their emergency planning function. Congress has essentially left that responsibility to the States.

CFATS


The CFATS regulations (6 CFR part 27) were originally authorized as part of a DHS spending bill over 10 years ago, but have been more recently been authorized by 6 USC Part XVI. Nothing in the current authorizing statute specifically mentions ‘emergency response planning’ at CFATS covered facilities. That is addressed, very briefly, in the CFATS regulations at §27.230(a)(9) as part of the risk-based performance standards used to develop and evaluate site security plans. That sub-paragraph states:

“Response. Develop and exercise an emergency plan to respond to security incidents internally and with assistance of local law enforcement and first responders”

The CFATS Risk-Based Performance Standards Guidance manual emphasizes that RBPS #9, Response, is targeted at the response to a security situation and that ‘emergency response’ is only a relatively small part of the response obligation of the facility under the CFATS program. The manual explains the difference this way (pg 84):

“It is important not to confuse a “security response” intended to engage and hopefully neutralize the adversaries with the broader “emergency response” that follows an attack and attempts to reduce the severity of the event and lessen the consequences in terms of loss of life and destruction of property or production capability. The initial “security response” has tactical considerations addressed in RBPS 4 – Deter, Detect, and Delay, whereas the “emergency response” relates to the more traditional efforts to contain the damage and lessen the consequences after a security event. These planning considerations overlap to some degree, and both involve establishing strong, functional, relationships with the various response organizations and personnel that may be needed to support this performance standard. It should be noted that individuals involved in security response activities also often have an integral role in emergency response, and this dual role should be taken into consideration when developing comprehensive crisis management plans.”

In the metrics included at the end of the RBPS 9 that facilities and DHS use to evaluate a CFATS site security plan (SSP), there are only mentions of ‘emergency response’ (Metric 9.1; pg 85):

“Documented agreements and/or written procedures for emergency response, including off-site responder services, such as ambulance support, explosive device disposal support, firefighting support, hazardous material spill/recovery support, and medical support.”

There are other requirements within the RBPS 9 metrics for outreach to ‘local law enforcement and emergency responders’ (including LEPCs), but these are not planning requirements; though the metric does note that facilities can fulfill this measure by participation “in incident response drills and exercises in conjunction with off-site responder organizations” (Metric 9.4; pg 86).

Problems With Current Models


The two regulatory models described above take two different approaches to the emergency response planning problem. The EPA model calls for unfunded agencies, the LEPCs, to conduct the emergency response planning for all facilities in their operations area. The CFATS model calls places the planning responsibility with the covered facility. Both models contain serious disconnects from reality.

The first problem common to both models is the funding issue. Emergency response planning takes time and expertise to accomplish the frontend work; develop the plan. That requires money to pay for the expert’s time. Even if the expert is volunteering their time there is the cost of the time lost to that expert’s normal job. Next, in order to be an effective plan, the plan must be reviewed, revised, exercised, reviewed and revised on a periodic basis. Again, the time involved in the process is costly and limited. LEPCs in large urban areas may be able to absorb this cost by having a full-time professional planner on staff with a local agency, but that is not going to be an option for most communities.

For large CFATS facilities, it may be possible to have a full-time emergency response planner on staff or finances may be available to pay for an emergency response contractor to undertake the planning necessary. At some point, however, as facility’s decrease in size that professional capability is going to be impossible to afford. But even where the facility has the financial resources to fund a planner, the community is still going to have to fund the review and exercise portion of the emergency planning process. Again, smaller communities are going to find this extremely difficult or impossible to afford.

The second problem is the information sharing issue. At first glance, in the EPA model this does not seem to be much of a problem. Facilities are required to provide LEPCs with the required information, either directly by law or by response to requests from the LEPC. Unfortunately, the amount required directly by statute is relatively limited and the LEPC can only request the information that it knows that it needs. There is no incentive for facilities to share additional information such as the presence of other chemicals on site that may complicate the emergency response process.

For CFATS covered facilities this problem is aggravated by the statutory restrictions on the sharing of Chemical-Terrorism Vulnerability Information (CVI). Now the information about CFATS facility holdings of the toxic-release hazard chemicals covered under the EPCRA rules is not generally going to be classified as CVI, at least as that information relates to the type, amount and location of the Highly Hazardous Chemicals listed in the EPCRA regulations. As noted earlier, however, flammable and explosive release hazard chemicals covered under CFATS are not addressed in EPCRA and the sharing of information about those chemicals (which also need emergency response planning under CFATS) is limited to only those individuals that have been trained in handling of CVI materials and have the appropriate means to protect that information. Again, there is a time cost associated with receiving the CVI training (the training is free) and the cost of the physical security and cybersecurity for protecting that information is not negligible.

And the final problem with the current models is that both EPA and DHS have made it difficult to share information with the potentially affected neighbors about the emergency response planning. Both agencies have done this with the intent to deny information to potential attackers. The EPA restricts access to the facility data to people who physically access an EPA reading room (limited locations), and DHS prohibits sharing of CVI information with the public. While done with the best of motives, both agencies have ensured that in most cases the public does not have access to the necessary information to promptly respond to an emergency response situation.

Fixing the Problem


Because of the size of the universe of EPCRA covered facilities, I do not foresee Congress attempting to provide enough funding to allow LEPCs to fix the emergency response planning problems identified above. If they are fixed it will be on a case by case basis where either the local community or large chemical facility is able to provide the necessary funding.

Because the CFATS covered facility universe is much smaller (3,330 as of March 1st) some of these issues may be more tractable. I have addressed in some detail how I would modify the current authorization in a blog post from last year. The money issue still remains, my suggestion to allow (gently require) FEMA to use grant funds for emergency response planning for CFATS covered facilities only partially addresses the issue due to the limited nature of those funds and I did not propose increasing them because that would increase the problems with getting the reauthorization bill passed. Realistically, FEMA needs a specific emergency response planning grant authority and is probably going to have to be required (and funded) to provide professionals to help LEPCs conduct both the planning and exercises of those plans. That will almost certainly have to be addressed in separate legislation.

Finally, none of my suggestions in the earlier post address the issue of information sharing with the local, potentially directly affected population. It is easy to say that information must be shared but legislating that in an effective manner is going to be difficult. Defining who the potentially affected population is will be hard enough. Crafting language describing an effective outreach program that will overcome what is unfortunately in many cases a mistrust of the chemical industry based upon decades of poor, incomplete and often misleading information is going to be difficult.

The best I can suggest at this point is adding an additional sub-paragraph to the end of §636(b) proposed in that earlier blog post:

(6) Conduct an annual outreach class for the immediate neighbors potentially affected by a full release of any toxic-release COI on the facility describing:

(A) What such a release might look and or sound like;
(B) What measures the facility has in place to warn neighbors of such a release;
(C) What immediate actions neighbors should take to best protect themselves in the event of such a waring;
(D) How neighbors will be made aware of an all-clear status after an incident;
(E) What medical treatment should be sought after such a release.
(F) A point of contact for reporting suspicious activities in the neighborhood that may be directed at the facility.

 
/* Use this with templates/template-twocol.html */