Showing posts with label Enforcement. Show all posts
Showing posts with label Enforcement. Show all posts

Friday, June 10, 2016

CFATS Update

I mentioned last week that I would have some more information on the latest CFATS update. I had a chance to talk to some folks from ISCD headquarters yesterday. I don’t have the details that I had hoped for (though we may see them in the July update), but I did pick-up some interesting tidbits of information about the CFATS program.

Expedited Approval Program


Back in December 2014 when Congress updated the Chemical Facility Anti-Terrorism Standards (CFATS) authorization they included a mandate for the DHS Infrastructure Security Compliance Division (ISCD) to establish an Expedited Approval Program to help ISCD reduce the backlog of site security plan (SSP) approvals. The idea was that the EAP would provide facilities with a specific blue print for a site security plan instead of having to negotiate a site security plan with ISCD. Congress thought that this would speed up the SSP approval process.

Well, it turns out that only one facility has used the EAP to get their SSP approved to date. It is almost exactly a year since facilities could start the EAP process and only one facility decided that it was a worthwhile program. So, did ISCD waste their time in publishing the EAP guidance document? If you look at it from the number of facilities that opted to formally use the program, probably. In a larger sense, probably not.

Long time readers of this blog will know about my concerns with the Risk Based Performance Standards (RPBS) guidance documents that facilities have had to rely on for standing up their SSPs since 2009. The drafters of that document bent over backwards to ensure that they could not be accused of ‘specifying security measures’ because ISCD was prohibited from that particular committing that particular sin by the old §550 program authorization language. For facility security managers that did not have professional security training (most of them), the document was little better than no guidance. It is little wonder that virtually no first time SSP submission was approved by ISCD.

With the publication of the EAP guidance, facility security managers without security training can get a good idea what type of security measures ISCD is looking for. Facilities still have the ability to tailor their security measures to their own unique environment, but they have a clearer measure of what those measures are expected to accomplish.

BTW: When ISCD rolls out their new risk assessment/tier assignment methodology this fall it looks like they are intending to update a number of program documents to properly reflect that methodology. One of those documents is likely to be the RSBP guidance document.

Enforcement


With ISCD now spending 80% of their inspection time on compliance inspection, it is almost inevitable that there will be facilities that are not in compliance. ISCD has a long history of working with facilities to get security properly in place, and that has continued over to compliance inspections. Unfortunately, it seems that there have been some (no one is currently talking about how many) facilities that ISCD may be (have begun) taking enforcement actions against to ensure that they meet their SSP obligations. Hopefully, they will never meet a facility that is so intransigent that the Secretary will be forced to close the facility, but that is still the ultimate enforcement authority available.

BTW: It looks like ISCD will be announcing at the upcoming Chemical Sector Security Summit (CSSS #10) that they have completely cleared the back-log of SSP approvals. Not all facilities will have approved SSPs then, but SSP processing will be proceeding in regular order with no unreasonable delays between SSP submission and authorization/approval inspections.

Risk Assessment Process


DHS has taken a lot of flak since the beginning of the CFATS program about the methodology they use for determining which facilities that submit Top Screens (more than 50,000 to date) are assessed to be at high-risk for terrorist attack (and thus inclusion in the CFATS program) and then used to determine the Tier Ranking for facilities in the program. DHS was not willing to discuss the details of that assessment process and were obviously missing some information necessary to do a “real” risk assessment.

ISCD will be rolling out this fall their updated and more rigorously justified risk assessment process. ISCD has had their processes vetted by an academic review process as well as a stakeholder review process. So there should be fewer complains (anyone that expects no complaints is using too many good drugs) about the new process. One of the reasons for this is that ISCD is planning on sharing more information (NOT details) about that process with the chemical community. They realize that companies need to be able to take that risk assessment process as they plan to construct new or modify existing chemical facilities so that the security costs associated with the project can be included in the facility planning process.

We have seen the first change associated with this new risk analysis process when ISCD held their Top Screen webinar last February. Since a number of questions were moved into the new Top Screen from the Security Vulnerability Assessment, the SVA is also going to have to be changed. I think that we will see the debut of that new SVA tool at the CSSS. Hopefully ISCD will include that debut in the sessions that they share on the web.

CFATS Rulemaking


ISCD is continuing to work on their notice of proposed rulemaking for updating the CFATS regulations. That process began with their advance notice of proposed rulemaking (ANPRM) published in August 2014. The Spring 2016 Unified Agenda projects that the NPRM will be published in September. No details are available on what changes are going to be proposed for the program beyond what was discussed in the ANPRM.

Closely associated with the CFATS program (but a separate regulatory scheme) is the congressionally mandated Ammonium Nitrate Security program (6 USC 488 thru 488i). ISCD issued their NPRM for the program in August of 2011, but has failed to be able to overcome the cost-benefit questions raised about that proposed rule. Congress has taken cognizance of the problem and DHS, Congress and the potentially regulated industries have been working on a solution to the problem. One monkey wrench thrown into the works has been the significant ISIS use of improvised explosives made with other chemicals. I half-way expect to see a new congressional mandate for precursor chemicals for improvised explosive devices; especially if we see a significant domestic IED that does not use ammonium nitrate.

BTW: If there is another Oklahoma City sized ammonium-nitrate truck bomb, the problems of the cost-benefit analysis will be instantly resolved and a regulation based upon the NPRM will probably be quickly forthcoming.

Missing Questions


I did not get a chance to ask all of the interesting questions that I wanted to, maybe in future conversations. But I would like to know if/when the folks at ISCD are going to remove their current ‘temporary’ exemption for agricultural production facilities from filing Top Screens. I still think this will be a ‘minor’ regulatory burden for almost all of the facilities involved because ISCD would be unlikely to determine that they are at high-risk of terrorist attack (for their chemicals anyway; food security is an Ag Department problem). This may be addressed with the roll out of the new Top Screen.

The other important topic that I did not get a chance to address was the progress being made in implementing the Personnel Surety Program. I think that it would be an interesting addition to the CFATS update if ISCD would include the total number of personnel that have been vetted against the terrorist screening database (TSDB). A number that we will probably never hear (for fairly legitimate reasons) is how many folks have turned up as a match against the TSDB during these checks. I personally expect that most of those positives will be false positives and that will cause problems for both ISCD, facility management and the folks improperly identified as having terrorist ties. I really hope that the number isn’t too large.


As always I appreciate the time that folks took to talk with me about the CFATS program. I have had my differences of opinion over the years with exact methodologies used by ISCD in their implementation of the CFATS program, but I have always admired how hard the folks have worked at making the process work especially how diligently they have tried to make the program a cooperative attempt to increase facility security rather than an adversarial program. Let’s hope that that can continue into the future.

Thursday, February 12, 2009

Reader E-Mail – 02-10-09

A long time reader, Brandon Williams, sent me a couple of e-mails on Tuesday about my first blog posting of the same day; the one about enforcement activities. He used to work on the US Chemical Weapons Convention (CWC) support teams that helped facilities with the international inspection teams that came by to check CWC compliance. (Personal Note: having gone through CWC inspections at two different facilities I can attest to how professional and helpful these support teams were. As best we can tell Brandon was not on either team that I worked with). Anyway, based on his CWC team experience Brandon questioned the propriety of EPA and DHS sharing data on facilities in the manner I suggested. Brandon noted that their rules, and the supporting legislation, prohibited these CWC teams from sharing information with either EPA or OSHA. He felt that this was done to allow open communications and encourage facilities to freely share information with the assistance team. He thinks that the DHS inspectors doing the initial Site Security Plan visits (the first visits to verify the adequacy of the plan, not the later compliance audit) will need the same level of open communications that the CWC teams were able to engender at most facilities. Legality of DHS-EPA Information Sharing I could find nothing in the Section 550 authorizing language that would prohibit DHS from sharing information with either EPA or OSHA. I don’t think that Congress even considered the matter when they were preparing that abbreviated authorization. This may be something that Congress might want to consider when they write the re-authorization legislation. They could pattern the language after the following two sections of the CWC Implementation Act of 1998 (thanks to Brandon for digging up the details):
Sec 304(E)(2)(G) - Procedures for Inspections: no inspection under this Title shall extend to... "data maintained for compliance with environmental or occupational health and safety regulations" Sec 303(B)(2)(B) - Authority to Conduct Inspections: "no employee of the Environmental Protection Agency or Occupational Safety and Health Administration accompanies any inspection team visit"
Provisions like these may make the old joke, “I’m from the government, and I’m here to help you” a little less painfully true. At least the initial visit should be a true assistance visit with the inspector providing an outside view point on the facility efforts to comply with the Risk Based Performance Standards. The post-approval compliance inspection may be a different story; but until the facility’s SSP is approved, the inspection is supposed to help the facility adopt a compliant plan. Agency Level Information Sharing What I was suggesting was not inspector level sharing of inspection information. It was directorate level use of EPA developed information that is held in a publicly available data base (the data base was available on-line until shortly after 9/11, but it is still available in-person at EPA reading rooms). The data would be the list of facilities that have submitted RMP information to the EPA. It would include the RMP chemicals involved and the amount held on site. While this is publicly available information (it was used, for example, to develop the list of 101 high risk chemical facilities in the CAP Chemical Security 101 report), there might be some concerns about using this for government enforcement actions by another agency. To alleviate that concern, Congress could include language in the re-authorization legislation requiring DHS to use this data to identify facilities for DHS to contact to require a Top Screen submission. This would stop facilities from challenging enforcement actions based on a self-incrimination defense. Any subsequent enforcement actions would be based on failure to obey a directive from the Secretary to complete a Top Screen rather than failure to file based on the EPA data.

Tuesday, February 10, 2009

Jack Frost and CFATS

A recent US EPA press release highlights the government’s problem with enforcing environmental and safety regulations. The press release explains the punitive actions that the EPA took against Jack Frost Fruit Company, of Yakima, Washington for failing to fulfill the Risk Management Plan obligations required by their storage of more than 10,000 lbs of anhydrous ammonia. The question becomes did the same company avoid the requirements of CFATS for the same chemical? RMP Violations The facility was fined for not having a Risk Management Plan (RMP) for a potential accidental off-site release of anhydrous ammonia. The RMP requires a company to assess their safety systems and material handling procedures to ensure that they are reducing the risks of releases of anhydrous ammonia. Additionally, the RMP requires that the facility communicate with the local community and emergency response personnel about the presence of the chemical and the emergency response requirements in the event of a release. In addition to a fine of $20,554 the company is being required to undertake two projects to reduce the risks associated with an off-site release. The first project will be making improvements to their handling system and procedures to reduce the potential for an accidental release. The second project will help the local emergency response personnel to prepare for a potential release. The cost of the two projects will be at least $85,000. In most cases where there is no RMP at a covered facility it is because the company was not aware of, or misunderstood, the requirements for an RMP. There will also be some number of companies that were aware of the requirements but decided not to spend the money to comply with those requirements. In either case the public is left at risk for exposure to an accidental release of toxic or highly flammable chemicals. CFATS Cause for Concern Regardless of the reason for not having an RMP, it is likely that the facility without an RMP is also not complying with the CFATS regulations. Facilities that are not aware of their obligations under RMP, a long standing EPA program, are likely be to equally unaware of their CFATS obligations. Facilities that willfully avoid their RMP obligations are probably not going comply with potentially expensive CFATS requirements. CFATS Compliance Efforts While DHS certainly has its hands full in getting the CFATS program fully functional (we are still waiting for the roll out of the Site Security Plan tool in CSAT), some effort needs to be expended to ensure that all chemical facilities with a STQ quantity of one of the DHS COI have completed a Top Screen. One low cost effort would be to screen all completed EPA RMP enforcement actions against the list of facilities that have completed a Top Screen. Facilities showing up on the first, but not the second list should receive an enforcement letter from the Secretary directing the facility to complete a Top Screen. As the Site Security Plan portion of CFATS gets to the field, DHS needs to begin looking seriously at how they are going to ensure that all potentially covered facilities are aware of their obligation to submit a Top Screen submission. Techniques are going to have to be developed to identify classes of facilities that probably have DHS COI on site. This could be done by data mining the Top Screen submission data base. Commercial data bases could then be used to identify other facilities in those classes for potential enforcement actions. Potential Congressional Actions As Congress begins to look at extending the CFATS authorization or, hopefully, making the program permanent, some thought needs to be applied to providing DHS with additional tools to aid in ensuring regulatory compliance. One way to do that would be to require that EPA provide DHS with a list of all facilities that have submitted a current RMP. This would help DHS to identify some of the facilities that should have completed a Top Screen submission. Other government agencies with comparable programs that DHS used to formulate their COI list should also be required to provide similar facility lists to DHS. Congress could also consider requiring manufacturers and distributors of COI to provide to DHS lists of customers that received more than a STQ of a COI. These rules would not need to be as extensive as those being developed for ammonium nitrate manufacturers and suppliers. Such lists would provide DHS with information on facilities that should have submitted a Top Screen. Moving Forward with CFATS DHS is finishing the process of getting their CFATS program fully established. Once that is done they need to begin working on the enforcement side of the program. That enforcement will be focused on ensuring compliance with security plans at self-identified high-risk facilities. It also needs to have an enforcement component that actively looks for potential high-risk facilities that have not yet begun the CFATS process.

Friday, December 12, 2008

Locals Look at Transportation Security Rule

There is an interesting article on SpotLightNews.net concerning how the recently published Rail Transportation Security Rule. It looks at how the new rules, which go into effect on December 26th, will affect local rail operations in Columbia County, Oregon. The most important piece of information found in this article is in the first few paragraphs. The second paragraph notes that:
“(Mike) Eyer is the sole hazardous materials compliance specialist for the Oregon Department of Transportation’s Rail Division, and the burden for making sure the state’s 200 or so handlers of hazardous cargo run safe operations over every inch of Oregon’s steel rails falls squarely on his shoulders.”
New Inspectors The article then goes on to report that Mr. Eyer is contracted to do the same inspections for the FRA, implying that he is the only hazmat compliance inspector operating in Oregon. It later notes that the inspection burden is being eased by the new regulation because the “rule provides an infusion of 200 new Federal Railroad Administration inspectors”. It would be unusual for a TSA regulation to provide for new FRA inspectors since these two organizations are in completely different cabinet departments. The only reference I can find in the rule to new inspectors is found in the discussion of comments about the chain of custody requirements. In response to a question from members of Congress about the small number of TSA inspectors available to enforce the rule, TSA reports that “TSA has deployed the 100 inspectors provided for by Congress in the Department of Homeland Security Appropriations Act for fiscal year 2005 (Pub. L. 108-90)” (page 72151). The preamble goes on to explain that these inspectors are deployed in 19 field offices and “cover the key rail and mass transit facilities in their regions”. It is clear that these inspectors will be charged with inspections and enforcement activities in support of this new rule in addition to their regular rail transport security duties. Lack of Enforcement Capability TSA identifies 241 rail hazardous materials facilities that will be affected by this regulation. This means that these facilities will fall under the inspection program for TSA for the first time. This is a significant increase in work load for those 100 TSA inspectors. This will be aggravated by the fact that the geographic distribution of these facilities almost certainly does not match the current distribution of inspectors in the 19 field offices. As the article notes, this is not an unusual situation. Congress has been remiss in authorizing an adequate head count for enforcement activities when they require that the executive branch write and enforce new regulations. The executive branch shares some culpability in that they do not request additional headcount when they submit their budget requests. In any case, come December 26th both Congress and DHS will point with a certain amount of pride at the additional layer of security that they have provided to the public with these new rules. But, without an adequate number of TSA inspectors to go out and look at hazmat rail facilities, to assist in the implementation and enforcement of these new rules, there is no assurance that these new rules will accomplish anything but add more paperwork to the system.
 
/* Use this with templates/template-twocol.html */