Showing posts with label Chemical Safety Board. Show all posts
Showing posts with label Chemical Safety Board. Show all posts

Monday, October 28, 2019

Senate Committee Reports for HR 3055 – First Senate Minibus

The version of HR 3055 that the Senate will resume considering today is based upon four spending bills proposed by the Senate Appropriations Committee. While there may be some slight differences in the language included in Senate Amendment 948 that amendment specifically adopts the four committee reports “for purposes of determining the allocation of funds provided by, and the implementation of,’ each of the four divisions in the proposed bill.

Those reports are:

S Rept 116-127 (Div A - CJS)

S Rept 116-110 (Div B – ARD)

S Rept 116-123 (Div C – IER)

S Rept 116-109 (Div D – THUD)

As is typical for spending bills, the important details are found in these reports, not in the bill language. Below I will discuss some of the more interesting details.

Cybersecurity


Every division (and most titles) of the proposed amendment contain some sort of cybersecurity language. Mostly though those references and spending allocations pertain to protecting the IT systems of the US government.

Not unexpectedly the NIST section of the Division A report deals with supporting cybersecurity workforce training. While no specific funding is outlined the Committee “directs that no less than the fiscal year 2019 level is provided for cybersecurity research, outreach, industry partnerships, and other activities at NIST, including the National Cybersecurity Center of Excellence” (pg 23). Interestingly the Committee desires to see “a priority being placed on areas with a high concentration of Department of Defense, automotive, and health care related industries”.

NIST is also called upon to address industrial cybersecurity via Industrial Internet of Things (IIoT) cybersecurity research. The report calls for spending ‘no less than’ $2 million “to improve the sustainable security of IIoT devices in industrial settings” (pg 23). The Committee calls for comprehensive strategies that would “couple computer science and engineering, psychology, economics, cryptography, and network research to deliver significant mitigations and options for industrial adoption, as well as guidance to consumers and industry on how to manage and utilize these devices consistent with best security practices” (pg 24).

The National Science Foundation ‘Education and Human Resources’ section of the Division A report also significantly addresses cybersecurity training issues. The Committee provides $55 million (pg 169) for the CyberCorps scholarship program with $7.5 million of that going to support the two year programs at NSA sponsored Center of Academic Excellence in Information Assurance 2–Year Education [CAE2Y] program community colleges.


The DOJ portion of the Division A report addresses another aspect of cybersecurity education; computer forensics and digital investigation. The State and Local Law Enforcement and Cybercrime Prevention section includes a requirement for DOJ to allocate $2 million “for a separate competitive grant program to expand a partnership with an institution for higher learning for the purposes of furthering educational opportunities for students training in computer forensics and digital investigation” (pg 130).

There is an interesting control system cybersecurity provision in the Division D Report. The Federal Railroad Administration (FRA) portion of the DOT Title “urges FRA to prioritize funding to establish enhanced cybersecurity methods, standards, and best practices, especially as it relates to the implementation of PTC [Positive Train Control] technology and future versions of this technology” (pg 73). Specifically, the Committee directs the FRA to “work with industry to identify current vulnerabilities and prepare for threats that could arise from future updates and the migration to future designs.”

Chemical Safety


There is only one mention of chemical safety issues that I can find in the four reports. That deals with the continued funding of the Chemical Safety Board. While the initial Trump Administration budget proposed eliminating the CSB, this year’s budget proposed $10.2 million and the Committee recommends continuing the current funding level of $12 million. The report notes that “The Board has the important responsibility of independently investigating industrial chemical accidents and collaborating with industry and professional organizations to share safety lessons that can prevent catastrophic incidents and the Committee expects this work to continue.”

Moving Forward


It is looking more likely that the Senate will pass HR 3055 later this week. The bill would then have to go back to the House. The House is unlikely to accept the Senate version so the bill would have to go to conference. The conference report would also address the differences in allocations and implementation directions, essentially rewriting the two versions of the Committee Reports.

Friday, July 15, 2016

CSB Business Meeting – 07-27-16

Today the Chemical Safety Board published a meeting notice in the Federal Register (81 FR 46045) for a business meeting to be held in Washington, DC on July 27th 2016. The Board will provide an update on the 2016-2020 strategic plan, the status of Office of the Inspector General audits, open investigations, and the agency's action plan, as well as discuss financial and organizational updates. A conference call line access is being made available.


There will be a brief public comment period at the meeting. Written comments may also be submitted via email (public@csb.gov). 

Thursday, January 23, 2014

CSB Changes Anacortes Meeting

Today the Chemical Safety Board published a notice in the Federal Register (79 FR 3777-3778) changing the purpose of the meeting that they had originally advertised as a meeting to review and approve the staff report on the 2010 fire and explosion at the Anacortes, WA Tesoro Refinery.

A meeting notice published last month indicated that the CSB Staff would present their draft report at a public meeting on January 30th and after allowing for public comments on the draft, the CSB would publicly consider approving the report.

While the draft staff report has not yet been made publicly available, it was expected to include a ‘safety case’ regulatory scheme for refineries similar to the one that was discussed last week in  Richmond, CA for the Chevron Refinery accident investigation. However, since that staff report was not accepted (yet not rejected either) when two Board Members requested more staff work on investigating some of the negative public comments received on the new regulatory scheme proposal, the Board is not going to attempt to review and vote on accepting the Staff Report on the Tesoro Refinery accident at the scheduled January 30th meeting.

Instead the Staff will make a public presentation of their draft report and listen to public comments on that presentation. The Draft report will then be posted to the CSB web site and the CSB will accept comments on the proposal for 45 days. After that time they will reschedule a public meeting to  review and vote on accepting the Staffs recommendations.


To see the comments that the CSB received on the safety case issue, click here. To see the CSB responses to those comments, click here.


Monday, May 6, 2013

CSB Information on West Fertilizer


Long time readers of this blog will understand that I have long been a fan of the investigations conducted by the Chemical Safety Board (CSB). They have provided a valuable service to the chemical process industry and their neighbors by diligently digging in, finding and publicizing the root cause of serious chemical incidents.

The CSB has been a noted innovator in the use of the internet for communicating their findings on these investigations, particularly their use of YouTube videos of recreations of the cause of the accidents they investigate. With the West Fertilizer investigation still in its early stages the CSB has shown us another innovative use of the internet; the use of Facebook.

The use of Facebook by government agencies is certainly not new, but the breadth of the information that the CSB has on their WestExplosion site certainly goes far beyond the standard government Facebook fare. Links to all of the major (and many of the minor) news stories, and their related on-line discussions, about the West Fertilizer explosion make this a one-stop shop for information about this tragedy.

What really impresses me about this page is the lack of agency grandstanding about the investigation. There are bits and pieces about the CSB investigation, but very little of the photo-op spin journalism that we see on too many government web sites.

Good Job.

Monday, May 17, 2010

CSB ANPRM Comments Posted

Last June the Chemical Safety Board published an advance notice of proposed rulemaking on chemical release reporting. Comments on the ANPRM were required to be submitted to the CSB by August 4th of last year. Today, the CSB published on their Open Government web page a link to a document that compiles all 27 responses that the CSB received about that ANPRM; late is always better than never. I would expect that this means that the CSB will be considering the publication of a notice of proposed rulemaking with the actual language of their proposed rule sometime in the near future. I will be looking at these comments and will probably report on them later this week.

Thursday, April 16, 2009

Security and Safety

Anyone that worked with me while I was a process chemist in a specialty chemical manufacturing facility knows that I have always been passionate about process safety. And readers of this blog know of my passion for security. So, it should be no surprise that I am very concerned with the Chemical Safety Board (CSB) vs. Sensitive Security Information (SSI) controversy surrounding next week’s public meeting on the Bayer CropScience fatal process accident that happen last summer. Two opinion pieces yesterday, one at USAToday.com and the other at Pubs.ACS.org, paint this as a conflict between security and community-right-to-know (CRTK). I think that this is a major mistake. In the context of counter terrorism operations, security and CRTK are part and parcel of the same operation, just like security and safety. They all contribute to a piece of the puzzle to prevent a successful terrorist attack. Assume it was a Terrorist Attack Let me use the Bayer incident as an instructional aid. Let’s assume that the accident was not an accident, but actually a well planned and executed terrorist attack. Assume for a moment that the ‘process upset’ that caused the explosion had been deliberately engineered and had been just a little bit larger in size. The nearby MIC tank, instead of escaping damage, would have (in our assumed incident) been punctured by flying debris. A cloud of methyl isocyanate would have been released to the atmosphere and spread to the adjacent community. The resulting panic, injuries and deaths would have made this a very successful attack. However, if CRTK had been an integral part of the security plan for the installation, there would have been automated systems around the tank and process area to detect the slightest release of MIC. As the first sensor detected the leak, an automatic alarm would have been sent to facility and community first responders. As more sensors became ‘involved’ other automated sensors would have begun auto-dialing local residents and businesses warning them to begin to take appropriate measures. Weather sensors and an array of chemical sensors around the facility would have begun mapping the spread of the cloud and projecting concentrations beyond the fence line. Decisions would have been made about who would evacuate and who would shelter in place and the appropriate communications made. Local residents would have been told in advance how to shelter in place or where to evacuate and why one was better than the other in a particular situation. At the same time, other automated mitigation measures would go into action. Water and chemical sprays would start that would knock down the bulk of the cloud. Properly equipped emergency responders would arrive at the scene and make what ever temporary repairs were possible to stop further leakage. Off-site response personnel would arrive on the scene to provide assistance to the community near the facility, monitoring for exposure levels and getting people safely out of the area. In the CRTK scenario, the success of the terrorist attack would have been reduced because panic, deaths and injuries would have been greatly reduced. This is the reason that CRTK plans are an integral part of any successful counter-terrorism security plan, just as they are a critical part of any successful process safety plan. Working Together Unfortunately, the government’s safety, security, and CRTK people are not working together. They are in different agencies and working under separate mandates. In this case the security and safety people have worked out an accommodation, but the CRTK people are still wondering in the wilderness. Two agencies have worked together to the extent that one did not stop the other, but that is not actually cooperation. It is more like a temporary cease fire on the battlefield to collect the wounded. This is a high-risk chemical facility (both from a safety and security point of view). Until the CSB determines the actual cause of the incident (which may not happen for another six months, if ever) there is a remote possibility that this was a deliberate attack and not a process problem. Even if it were completely accidental or the result of an inadequate process design/operation there are security issues that will inevitably be identified in the thorough type investigation that the CSB conducts. In either case the Coast Guard, as the responsible security agency for the facility, should be working as part of the CSB team during the investigation. A Coast Guard investigator should be a working member of the team, reporting to the head CSB investigator. That forensics investigator would then be immediately available and up to speed on the investigation if evidence of sabotage or outside attack was discovered. Otherwise that investigator should be looking at how the existing security plans contributed to or mitigated the severity of the incident. Congressional Action Required When the Chemical Safety Board was formed ten years ago there was no Federal involvement with security at chemical facilities. As the C&EN article notes there are now about 10,000 facilities with federally regulated security measures. More will likely be added if/when the water facility exemption is removed this year. The mandate for the Chemical Safety Board needs to be updated to take this into account. On the other hand, Congress completely overlooked the issue of chemical safety and community-right-to-know when they mandated security measures at chemical facilities. That was a major political and technical mistake and one that needs to be corrected. It is fortunate that the Bayer issue comes up when it did. Congress is beginning to consider the reauthorization of the CFATS program next week. The hearing before the Government Oversight subcommittee of the Energy and Commerce Committee should be just the first such hearing to look at the safety/security issue. Both the Energy and Commerce and the Homeland Security Committees need to look at this issue as part of the CFATS reauthorization. In my not-so-humble opinion, the Chemical Safety Board needs to remain the lead agency in any major accident or incident at a chemical facility; they alone have the technical expertise to get to the root cause of the accident/incident. At facilities that fall under CFATS, DHS should provide an investigator to assist the CSB by looking into security issues. For facilities that fall under the MTSA, the Coast Guard should provide that assistance. Additionally, they could provide on-going guidance to the CSB investigators about what information they receive or uncover that would be considered to be protected information under SSI or CVI rules. In any case, there should be a classified appendix to any CSB report involving a covered chemical facility that addresses the security issues that contributed to, or mitigated, the severity of the incident. That report should be given the widest possible dissemination in the security community, including other covered facilities.

Monday, April 6, 2009

CSB vs Bayer CropScience – Round 2

According to news reports on WVGazette.com on Friday, the Chemical Safety Board and the Coast Guard have come to an accommodation on information that will be released at a public meeting on April 23. The CSB will conduct that meeting in Institute, WV to review the explosion at the Bayer CropScience plant just outside of that town last summer. Bayer had tried to stop disclosure of some information in such public venues because it was considered Security Sensitive Information (SSI) under the Maritime Transportation Security Act (MTSA). The CSB had scheduled their normal public hearing last month to review the status of their current investigation into the explosion that killed two people at the site. There were concerns that the explosion could have damaged a nearby methyl isocyanate (MIC) tank that could have endangered the nearby community. The CSB had to cancel that planned meeting when Bayer claimed that some of the information that was going to be discussed was SSI and prohibited from public disclosure. The CSB took their information to the Coast Guard, the agency that is responsible for the administration of the MTSA and determining what information is actually SSI for covered facilities. The Institute, WV facility is considered a ‘maritime’ facility because it is located on a navigable water way and ships and receives chemicals via river barges. The Coast Guard announced Friday that any ‘outstanding issues’ had been resolved. An earlier blog by Ken Ward, Jr. on the same web site noted that Sen. Rockefeller (D, WV) had sent a letter to Admiral Thad W. Allen, commander of the Coast Guard, outlining his concerns about the CSB vs Bayer controversy. According to the blog Sen. Rockefeller’s letter objected to the perceived use of MTSA regulation to avoid public disclosure of important aspects about the safety and security of the facility. Now, Sen. Rockefeller’s letter almost certainly had no affect on the resolution of the ‘outstanding issues’ between CSB and the Coast Guard. After all Sen. Rockefeller is just a United States Senator representing the good citizens of Institute, W.V. Oh yes, he is also a Committee Chairman of the Senate Committee on Commerce, Science, and Transportation. The fact that this committee has oversight responsibility for the Coast Guard would have had no effect on Admiral Allen. Congress still needs to resolve the issue of the conflict between the CSB’s mission to discuss lessons learned from serious chemical accidents and the DHS (the Coast Guard is a part of DHS) mission to protect SSI from disclosure to protect MTSA covered facilities from potential terrorist attack. Similar problems could arise if there were a serious incident at any of the almost 7,000 high-risk chemical facilities covered under CFATS and the Chemical-Terrorism Vulnerability Information (CVI) rules that protect much of the information about the security of those facilities. A subcommittee of the House Energy and Commerce Committee will meet the first day that Congress is due back from their Easter Recess to look at the relationship between the CSB and the potential release of SSI information. Perhaps that hearing should also look at the potential CVI issues at other facilities with a view to addressing the issues in the upcoming CFATS reauthorization legislation.
 
/* Use this with templates/template-twocol.html */