Showing posts with label HR 4007. Show all posts
Showing posts with label HR 4007. Show all posts

Friday, July 3, 2015

PSP Congressional Mandate vs ISCD ICR

Last month I reported that ISCD Director Wulf had announced (in response to my question) during the most recent EO 13650 update that he expected the OMB’s Office of Information and Regulatory Affairs (OIRA) to approve the pending CFATS Personnel Surety Program (PSP) information collection request (ICR) sometime in the near future. He then noted that the DHS Infrastructure Security Compliance Division would then publish a guidance document outlining how Tier I and Tier II facilities would be implementing the PSP requirements.

I was surprised to hear this as I had assumed (as had most people) that the PSP requirements outlined in the new 6 USC 622 requirements from HR 4007 would have killed the current PSP program and would have required ISCD to re-start the ICR process. I am pretty sure that that was the intention of Rep. Meehan (R,PA) when he introduced HR 4007 in February of 2014, just after the 30-day ICR notice was published.

Proposed PSP Process

First let me go back and review what the PSP ICR outlined for the vetting of personnel against the Terrorist Screening Database (TSDB). ISCD outline three options that a facility would have to complete the vetting process on all facility employees (and that could include contractors at the facility’s option):

OPTION 1 – Direct vetting;
OPTION 2 – Use of vetting conducted under other DHS programs; and
OPTION 3—Electronic verification of TWIC

Actually, there is a fourth option described in the ICR. Facilities could suggest alternative methods of vetting personnel which would be reviewed by ISCD on a case-by-case basis. In this post I’ll call that Option 4.

Option 1

This is fairly uncontroversial, but the most time consuming option. The facility would have to enter into the on-line Chemical Security Assessment Tool (CSAT) into a new tool that will be released presumably after the guidance document is issued. For US citizens and legal permanent residents the information required would be:

Full Name
Date of Birth
Citizenship or Gender (Gender for US citizens)

Provisions would be made in the CSAT PSP Tool to provide additional, optional information to reduce the possibility of false positives. Facilities could enter this information or they could designate a 3rd party to submit the information for them. ISCD has also said that they would set up a system for bulk-upload of this data rather than just requiring manual data entry in the CSAT PSP Tool.

The only place where Option 1 conflicts with the new law is the requirement at §622(d)(2)(B)(i)(II)(aa) that requires a facility to accept the presentation of a DHS vetted credential from a covered individual which then preempts the requirement to provide information on those individuals to the PSP. I suppose that this would be easy enough to address in the guidance document.

Option 2

This is where the most dramatic conflicts with the new statute would apparently occur. For individuals with other credentials that include DHS vetting against the TSDB (including TWIC, HME and various Trusted Traveler Programs) ISCD proposed to require facilities to report much the same information as in Option 1 with the addition of the document number of the credential which substantiates the TSDB vetting.

This option has drawn the ire of many in the industry and Congress. The opposition insists that the mere presentation of the credential (and probably copying it for records sake) should satisfy the vetting requirement and no information should be submitted to DHS. This certainly seems to be the intent §622(d)(2)(B)(iii)(I).

ISCD has in the past responded that the information that it is requiring to be submitted to the CSAT Tool is not being used to vet the individuals against the TSDB, they are simply going to use the information to ensure that the credential being used is valid and current. This is the problem with all of the credentials being used under Option 2 (with the potential exception of the TWIC); the casual observer has no way to validate the credential or ensure that it has not been withdrawn because of subsequent investigative data.

The statute addresses this in §622(d)(2)(B)(i)(II)(bb). It requires facilities to outline in their site security plan (or authorized alternative) “the measures it will take to verify that a credential or documentation from a Federal screening program described in subclause (I) is current”. This requirement is where ISCD has an out to continue to use Option 2. Facilities could voluntarily use Option 2 as the way they fulfill the requirement described above. Facilities wishing to use some other method of verifying the credential data would annotate that in their plan, effectively Option 4. ISCD is, of course, capable of invalidating the designated process if it proves to be inadequate leaving the facility to revise Option 4 or use one of the other options.

Personally, I don’t think that there is an alternative method for facilities to verify these other credentials (other than TWIC which I’ll discuss in Option 3), so facilities are going to be forced to use Option 2 for any employee that offers one of these credentials. If any of my erudite readers knows of a legitimate verification option, please let me know.

Option 3

This option addresses the credential verification and validation process for Transportation Workers Identification Credentials (TWIC). TWICs were designed to be verified and validated on site through the use of a TWIC reader. It was originally envisioned that each MTSA covered facility or vessel would check the TWIC with a TWIC reader each time the holder entered the facility. This has yet to be required since the Coast Guard has yet to issue their final rule on TWIC Readers.

The CFATS PSP would not require daily checking of the TWIC. The ICR does not, in fact, say anything about how often TWICs should be checked. But in keeping with the requirements of the new statute, ISCD will not be requiring the submission of any information on individuals if their TWIC has been electronically verified.

Moving Forward

It looks like it would be possible for the PSP outlined in the ICR submitted to OIRA on February 10th, 2014 to be interpreted as meeting the requirements of 6 USC 622. We would still need to see the guidance document and the new CSAT Tool instruction manual to know that ISCD has included the necessary caveats and instructions so that it does not run afoul of the congressional mandate.


I am fairly certain that the legal staff at DHS is fully capable of ensuring that those documents will be appropriately worded. If not, there will almost certainly be law suits from a number of organizations to point out the errors of their ways.

Sunday, June 14, 2015

CFATS Update

Here we are half-way through the month of June and the folks at the DHS Infrastructure Security Compliance Division (ISCD) have not yet published their monthly update for the CFATS site security plan (SSP) implementation. Since April of 2013 they have been publishing this monthly compilation of the number of facilities which have had their SSP authorized and approved. If it is published on Monday it will be the latest the update was published since the congressional funding fiasco of 2013.

Is something wrong at ISCD? Probably not. What we are probably seeing is a move to the next phase of the CFATS program implementation. After all, June 16th will mark a milestone in the CFATS program, effectively being the date that the program will make a substantial change in the way the program is authorized and implemented.

Brief CFATS History

The Chemical Facility Anti-Terrorism Standards (CFATS) was the last major anti-terrorism program that can be directly traced back to the attacks in September 2001. In 2006 Congress was finally able to put serious disagreement about how a chemical security plan would be run behind themselves long enough to establish an interim program to get some sort chemical security effort underway while the nearly theological battle in Congress proceeded.

The chemical security program was authorized in a single, short section in the FY 2007 DHS spending bill (§550, PL 109-295). It provided minimal guidance to DHS on how to establish the program and provided some significant limitations as to what DHS could require chemical facilities to do as part of the program.

DHS got off to a fast start standing up the CFATS program. In less than six months they wrote a new set of regulations establishing an innovative new regulatory program that utilized state of the art on-line data collection tools. In the next couple of years they looked at the initial reporting data from over 40,000 chemical facilities that had significant amounts of 300+ DHS chemicals of interest (COI) on hand and determined that just over 4000 of those facilities met the regulatory standard of being ‘at high risk of terrorist attack’.

Those covered facilities completed security vulnerability assessments, again submitting the data to ISCD via the on-line Chemical Security Assessment Tool (CSAT). DHS took the information provided and threat ranked the facilities into four risk tiers. ISCD developed a guidance document for how those facilities should implement the risk-based performance standards required by Congress, and then there was a major hiccup; the program stalled.

For a number of reasons, including some management issues that have not yet been fully reported to the public, the program stopped advancing. Work was being done by the ISCD staff, Chemical Security Inspectors were visiting facilities. Facilities were submitting SSPs, but effectively no site security plans were being approved by ISCD.

In early 2013 the new management team at ISCD finally started making some headway and the authorization and approval of site security plans began in earnest. The program was starting to get back on track. In April of 2007 they started reporting that progress with their monthly updates of status of the CFATS site security plan implementation.

The Fight in Congress

In the meantime Congress continued their in-fighting about how a chemical facility security program should proceed. On one hand, the Democrats (supported by labor and environmental activists) wanted to use the security program to severely limit the chemicals and processes that the industry could use. They argued that if dangerous chemicals and processes could be reduced or eliminated then the facilities would no longer be potential terrorist targets. The Republicans (supported by facility owners) countered that only the engineers and business owners could determine what chemicals and processes would be commercially viable. They argued that DHS did not have the manpower or expertise to make judgements about inherently safer technology.

The importance of this philosophical difference declined as Congress realized that the interim program that they had turned loose on the country was stalled. Their concern about the slow pace of SSP implementation finally overcame the philosophical discussion and Congress finally passed a stand-alone chemical facility security bill last December; HR 4007 was signed by the President on December 18th, 2014.

Moving Forward

The one change from HR 4007 that will most affect the site security plan implementation is the establishment of an expedited approval process for Tier 3 and Tier 4 facilities. These are the lowest risk facilities covered by the CFATS program and the last ones that DHS has started working on for the SSP implementation process. The bill gave ISCD until June 16th, 2015 to publish the guidance for this program and to establish the reporting process that the new program would use to process SSP’s for those facilities that opted to use the EAP program.

The EAP guidance document was published last month. This week we should see a new tool established in the CSAT that will allow facilities to report to ISCD their intention to use the EAP program to develop and submit their SSP. Thirty days after that intention is reported to ISCD those facilities will be able to start submitting their EAP SSPs. This will either require the modification of the current SSP tool in CSAT or the publication of a new tool. I suspect that ISCD will go with the new tool using the general format of the checklist provided in the EAP guidance document.

CFATS Updates?

ISCD is going to allow all Tier 3 and Tier 4 facilities the option to use the EAP process. Even those that already have authorized or approved site security plans. This means that the statistics that ISCD has been reporting in their monthly updates will no longer mean much from the perspective of tracking SSP implementation. Starting on Tuesday some number of currently authorized or approved SSPs will be invalidated as facilities make the decision that their SSP could be simplified or made cheaper by joining the EAP process. So tracking those numbers, at least in the short term, probably does not make much sense.

This is going to be further complicated by the fact that current CFATS facilities (as of December 18th, 2014) have until November 13th, 2015 to complete the EAP process. This means that they would have until October 14th, 2015 to notify ISCD of their intent to complete the EAP process. So, during the period of June 16th to October 14th watching the simple change in numbers of facilities with authorized or approved SSPs is going to be very confusing.

And I can’t let this topic go without at least mentioning the reporting of compliance inspection results. ISCD has been working on compliance inspections now for a little over two years. Well, they are supposed to have been anyway since compliance inspections were supposed to start one year after the SSP was approved at the facility level. Unfortunately, ISCD has not been publicly reporting any statistics on their compliance inspections.

I would assume (I know; a very dangerous word) that there have not yet been any compliance inspections at Tier 3 or Tier 4 facilities (priority was legitimately given to Tier 1 then Tier 2 facilities), but we should start to see some Tier 3 facilities become eligible for such inspections in the near future. Since those facilities have the option to opt out of their current SSPs by selecting the EAP process, future changes in compliance inspection numbers may also be misleading, at least through October 14th.

So, are we going to see a CFATS update this week or not. I don’t really know, I haven’t asked anyone at ISCD. I know that they are busy with the HR 4007 implementation process as well as the on-going SSP authorization, approval and inspection process. I don’t think that checking on a reporting system that they voluntarily started as essentially a PR exercise is really worth bothering them about.


If I had to bet, however, I would say probably not. If I were in Director Wulf’s shoes, I wouldn’t report on any data until I was called to testify about the implementation of the HR 4007 requirements later this year.

Tuesday, March 31, 2015

The Next CFATS Update

Here it is the last day of March already and I expect that we will be seeing the next CFATS update publication from the good folks at the Infrastructure Security Compliance Division (ISCD) in the next week. I have been reporting on these updates since they were first published almost two years ago. What I would like to do today is put in my request for what I think should be included.

First off I want to say that ISCD is to be congratulated on making the effort to share this valuable information with the regulated community. They are under no legal obligation to do so which makes this doubly impressive. Please keep them coming.

Having said that, even good things can be improved. Let’s start with the data; there are two types of data that should be included in the monthly report:

Compliance inspections – With over half of the facilities now having authorized site security plans and having started the compliance inspection process on those facilities that have had approved site security plans for over a year, it is time for ISCD to start providing statistics on compliance inspections; the number of compliance inspections completed, the number of compliance inspections passed.

Facilities no longer covered by CFATS – ISCD has been reporting a declining number of facilities covered by the CFATS program and this is probably a good thing. It would be nice however to know more about how that is happening. ISCD could report the number of facilities that have gone out of business, the number that have reduced inventories to below the Screening Threshold Quantities and the number that have removed the DHS chemicals of interest from the facility.

Starting sometime in the near future ISCD is going to have to start talking about its implementation plan for the new CFATS requirements imposed by the passage of HR 4007 last year. The deadline for the publication of the expedited facility security plan certification process is fast approaching for example. It would be nice if ISCD were to explain its plan for implementing that process.

The current (dead in the water) proposal for the personnel surety program was finally killed by the provisions of HR 4007. It would be helpful if ISCD publicly acknowledged that and withdrew the current information collection request. A brief description of the plan for implementing the HR 4007 personnel surety requirements would also be helpful.


ISCD has tried to establish a reputation for communication with the regulated community. The CFATS Update is one good example of that effort. Expanding that effort to cover the implementation of the HR 4007 requirements would be very helpful.

Wednesday, February 25, 2015

DHS Updates CFATS Website

Today the folks at DHS ISCD updated some of the web sites associated with the Chemical Facility Anti-Terrorism Standards (CFATS) program. The updated pages include:


The changes were made to reflect the passage of HR 4007 during the last session. The only substantive change to date (beyond the mention of the new CFATS authorization language) is a link to a copy of 6 USC §621 et seq. This is where the new CFATS authorization language is found. Interestingly the Department had to use a congressional web site for this link since the GPO web site for the US Code is not due for the 2014 update for a couple of months yet.

There is a brief mention of the new expedited approval process for Tier 3 and Tier 4 facilities that I have previously described in some detail. No details are provided beyond mentioning that DHS “expects the guidance to be issued in the summer of 2015”. As I mentioned in an earlier post, Congress set the deadline for publishing that guidance at 180 days after passage of HR 4007 which would be July 16th.


I am surprised that DHS does not mention the grandfathering of existing site security plans (SSPs) in these updated web pages. There has still not been any official pronouncement about the status of SSPs approved after December 18th. Those approved before that date will not have to be renewed for the new CFATS authorization language by congressional mandate. Plans approved after that date do not have that official protection.

Wednesday, February 11, 2015

DHS Updates CFATS Knowledge Center


Yesterday the folks at DHS Infrastructure Security Compliance Division (ISCD) updated the CFATS Knowledge Center. They added a link in the Documentation section of the page for the February 2012 CFATS Update and removed older copies of the Update.

Interestingly there is still no mention of the passage of HR 4007 and its potential impact on the CFATS program.

Monday, January 19, 2015

First HR 4007 Deadline Passes

Saturday the first deadline for HR 4007 came and went. This marked 30 days since the President signed the bill into law. This means that 6 USC 21 is now the governing law for the Chemical Facility Anti-Terrorism Standards (CFATS) and the old §550 authorization no longer applies.

Revocation Rule Deadline

As I predicted last month the Secretary missed the deadline to publish a rule revoking those provisions of 6 CFR 27 that are “duplicative of, or conflicts with” {§2107(b)} 6 USC 21. To be fair, I still have not found any specific provisions of the CFATS regulations that fall under this requirement. So it may not have been necessary to issue any revoking language. If that had been the case, it might have been nice for ISCD to issue a statement to that effect.

Grandfathered SSPs

We still have not heard any official (or unofficial for that matter) word from DHS about the status of the Site Security Plans that have been authorized or approved since the President signed HR 4007 into law. You might recall that §2102(c)(3)(B) provides that any facilities with approved site security plans (SSPs) as of the date of the President’s signature on HR 4007 (12-18-14) cannot be required to submit new SSPs just because Title XXI has become law. Plans approved since that date do not have that legal protection.


I don’t expect that the management at ISCD will want to increase the workload of their chemical security inspectors by going back and revisiting the site security plans approved in the last month (not that that will have been a very large number because of the holidays), but legally these site security plans have not been approved under the standards set by the current law. It would be helpful (if not actually legally binding) for the Secretary to publish a notice in the Federal Register laying out the status of SSPs being approved while the new CFATS regulations are being written.

Friday, January 2, 2015

HR 4007 – Employee Involvement in CFATS

This is part of a continuing discussion of the recently passed HR 4007, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014. This post will look at provisions in the bill that address employee involvement in the CFATS process.  The previous postings in this series were:


As part of the effort to obtain bipartisan support for the bill provisions were added that were designed in increase worker participation in the CFATS process. These include a specific requirement for employee and union involvement in the development of security vulnerability assessments (SVAs) and site security plants (SSPs) and whistleblower protections.

Directed Employee Involvement

Section 2102(b)(2) deals with the mandate for employee involvement in the development of SVAs and SSPs. It states:

To the greatest extent practicable, a facility’s security vulnerability assessment and site security plan shall include input from at least 1 facility employee and, where applicable, 1 employee representative from the bargaining agent at that facility, each of whom possesses, in the determination of the facility’s security officer, relevant knowledge, experience, training, or education as pertains to matters of site security.

The term ‘facility’s security officer’ is not defined in this legislation nor is it used anywhere else in the bill.

There is enough weasel wording in the provisions of this section that a facility owner could refuse to include the ‘required’ participation based upon the ‘fact’ that none of the employees have the requisite ‘relevant knowledge, experience, training, or education as pertains to matters of site security’. Even most security guards could be excluded as they are typically not ‘facility employees’ but rather employees of a contract vendor.

Union, excuse me ‘bargaining unit’ participation will be more problematic as these organizations start to get members trained and certified by various security standards setting organizations. I would also suspect that excluded labor or

Companies for which I worked for that have been required to conduct a process hazard analysis (PHA) on covered processes have always included operators and shift supervisors in those reviews. I don’t recall a single instance when any of these employees provided any great new safety insight, but they were invaluable in providing reality checks on what the current process actually was (as opposed to ‘as designed’) or on what could reasonably be expected of an operator. I would expect that the same would be true for SVA and SSP development.

Whistleblower Provisions

Section 2105 of the bill provides a description of the whistleblower requirements of the bill. They are quite simple and fairly common. First the Secretary is given 180 days to set up a program where employees and/or contractors can confidentially submit information to DHS about “a violation of a requirement under this title” {§2105(a)(1)}. This will be one of the easiest deadlines for DHS to meet since they already have a reporting system in place on their Critical Infrastructure: Chemical Security web page; the CFATS Tip Line (877-394-4347).

The Secretary is required to keep the name of the whistleblower confidential {§2105(a)(2)}. Additionally, the owner/operator is prohibited from discharging an employee (no such protections are provided for contractors, an odd oversight) that submits a report. Nor may the owner/operator “discriminate against an employee with respect to the compensation provided to, or terms, conditions, or privileges of the employment of, the employee because the employee (or an individual acting pursuant to a request of the employee)” {§2105(a)(6)(A)}.

The whistleblower protections do not apply if the employee “knowingly and willfully makes any false, fictitious, or fraudulent statement or representation” {§2105(a)(6)(B)(i)}. This first part is prettily clearly a protection against unfounded accusations. The second part of the protection exception {§2105(a)(6)(B)(i)} is a bit more problematic because of one word;  “uses any false writing or document knowing the writing or document contains any [emphasis added] false, fictitious, or fraudulent statement or entry”. This would seem to void the whistleblower protections if even one problem statement occurred in a lengthy document.

The Secretary is not required to take any specific action with regards to the tips provided beyond the basic mandate to ‘review and consider’ the information. If action is taken against a facility under the civil enforcement provisions of the bill (§2104; to be discussed in a future post) based upon a whistleblower tip, the facility has 20 days to submit a petition of review of that enforcement action.

There is nothing specified in the bill as to what information must be provided in that petition or what basis must be established for the requested review; I expect that that will be addressed in the new regulations. DHS must determine in writing that the violation continues to exist (within 30 days of the submission of the petition) or the enforcement action will cease {§2105(a)(5)(D)}.

Publicly Available Information

Finally, it is important to note that DHS is required {§2105(a)(2)} to treat all whistleblower tips (except publicly available information) as protected information under the provisions of §2103 (also to be discussed at a later date).

Actually, the ‘publicly available information’ provision seems like it may be a bit of a problem for the Executive Branch. Anyone familiar with the rules for handling of classified information knows that classification protection requirements do not change if information becomes ‘publicly available’ without going through the declassification process. For example, people with security clearances are not supposed to discuss specific documents or information disclosed by Mr. Snowden or even have copies of such ‘publicly available’ documents in their possession.

There is a good reason for this as the public printing of a purportedly classified document does not mean that it is a true copy of that document or even that such a classified document actually exists. As long as the government can continue to maintain the fiction that the document is not real, the secret continues to be at least partially kept.

Interestingly, nothing about publicly available information not being protected information is mentioned in §2103. It will be interesting to see how regulations and policy develop out of this.

Wednesday, December 24, 2014

HR 4007 – The EAF Process

This is part of a continuing discussion of the recently passed HR 4007, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014. As promised in one of the earlier posts this post will look at the process to be used by expedited approval facilities (EAF).  The previous postings in this series were:


Establishing the Program

As I mentioned in an earlier posting DHS has 180 days to get the EAF program established. Thus, by June 16th, 2015 we should have the guidance for the program from DHS. Remember, DHS is specifically not required to go through the publish and comment cycle nor do they need to receive OMB clearance of this program, either the guidance document or the information collection request (ICR) under 44 USC 3507. This means that we are unlikely to receive much advance notice of the provisions in the guidance document.

DHS has three basic options on how they are going to proceed with this EAF program development:

● Publish a guidance document that is little more than a list of required minimum security measures that a Tier 3 and/or Tier 4 facility would have to have to obtain approval of their site security plan (SSP). Facilities would then certify compliance and submit their SSP using the current CSAT tool.

● Develop a new CSAT tool specifically for the EAF program. The tool would be a template {authorized, but not required, under §2102(c)(4)(H)} where facilities would fill in the appropriate blanks that would be a substitute for the current CSAT SSP tool and then certify compliance.

● A combination of the two above.

I would like to see the second option. It would seem to me to be the simplest way to proceed for the EAF owners, which was clearly the congressional intent. The cheapest and easiest way out for ISCD though would be the first option since it would only require publishing a new guidance document (that would have to be published in any case) and would not require any substantive changes to CSAT. I suspect that the blended approach will be what we actually see; ICSD will publish the guidance to meet their 180 day deadline and then at some future date put the CSAT template into use.

Facility Participation

Starting on June 16th CFATS covered facilities then assigned to Tier 3 or Tier 4 that do not already have approved site security plans will have 30 days to look over and assess whether or not they want to continue to attempt to have their current site security plans approved or whether they want to seek approval under the EAF program. This 30 day period could be important to facilities since they are required to give ISCD 30-days’ notice {§2102(c)(4)(D)(iii)} before submitting the certification and SSP.

Existing facilities would have until November 13th, 2015 (120 days) to submit their certification and SSP. Because of the 30-day notice requirement any current facility that has not notified ISCD by October 14th, 2015 that they intend to submit and EAF certification and SSP will have to go through the current SSP process.

While DHS will be specifying minimum security requirements in their guidance for facilities participating in the EAF program, those minimums are not set in stone. Congress has given facilities the option to use lesser security measures as long as they explain in their site security plan how those measures actually meet the requirements of the risk-based performance standards {§2102(c)(4)(B)(ii)}. But, DHS still has the final responsibility and authority to decide if those standards are met.

EAF Site Security Plan Approval

The whole purpose of the EAF program is to expedite the SSP approval process. With this in mind Congress provided a 100-day time limit for DHS to make a decision that the SSP is ‘facially deficient’ or obviously does not “address the security vulnerability assessment and the risk-based performance standards for security for the facility” {§2101(7)}. Lacking such an assessment the SSP will be approved.

Congress did not intend for chemical security inspectors to be involved in the EAF approval process, but they did not prohibit their involvement either. The decision is supposed to be made based on four factors {§2101(7)}:

● The facility’s site security plan;
● The facility’s Top-Screen;
● The facility’s security vulnerability assessment; or
● Any other information.

That ‘any other information’ is specifically and broadly defined to include any information “the facility submits to the Department; or the Department obtains from a public source or other source”. That covers just about any means the Department decides to utilize, as long as it is done within 100 days of the submission.

Disapproved EAF SSPs

If during the 100 day DHS review of the SSP, or after a compliance inspection (I’ll look at compliance inspections in more detail in a later post) of the facility after the SSP is approved, the Secretary (read ISCD) determines that the security measurements are “insufficient to meet the risk-based performance standards based on misrepresentation, omission, or an inadequate description of the site”, the Secretary has two options {§2102(c)(4)(G)(ii)(I)}:

● Require additional security measures, or
● Suspend the certification of the facility.

In either case DHS is required to provide written notice that includes “a clear

explanation of each deficiency in the site security plan”; this would include specific suggestions for additional security measures. If the deficient facility would like to remain in the EAF program they would then have 90 days to submit a new certificate and SSP and DHS would have 45 days to review the new submission. If the facility declined to resubmit an EAF certification, they would have 120 days to submit a full site security plan or an alternative site security plan.

Monday, December 22, 2014

HR 4007 – DHS Security Suggestions

This is part of a continuing discussion of the recently passed HR 4007, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014. In this post I’ll discuss the way Congress worked around the problem of DHS telling facilities what is needed for security.  The previous postings in this series were:


I have long complained about the limitation Congress placed on DHS with their requirement in the §550 authorization that “the Secretary may not disapprove a site security plan submitted under this section based on the presence or absence of a particular security measure” {§550(a)} This has been interpreted to mean that DHS cannot tell facilities what security measures can be implemented to meet the risk-based performance standards. This has been one of the reasons why it has taken so long to get site security plans approved.

Congress did include similar language in HR 4007 {§2102(c)(1)(B)(i)}, but they also required the Secretary to ‘suggest’ security measures to bring site security plans into compliance when a submitted plan is deficient. For example, when the Secretary determines that a site security plan submitted by an enhanced approval facility (EAF) is inadequate during a compliance inspection, then DHS is required to “recommend specific additional security measures that, if made part of the site security plan by the facility, would enable the Secretary to approve the site security plan” {§2102(c)(1)(G)(ii)(II)(aa)}. The key word here is “recommend” as it is made clear that the facility still has the right to not use the recommended security measures as long as their alternatives serve the same purpose.


I understand that some chemical security inspectors (CSI; PLEASE DHS change their title so we can use a different acronym) have already been making these types of recommendations to owner of smaller facilities. The new requirement will ensure that all chemical facilities get this level of assistance regardless with which CSI they work.

Saturday, December 20, 2014

HR 4007 – The Clock Starts Ticking

This is part of a continuing discussion of the recently passed HR 4007, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014. The President signed HR 4007 on Thursday so that is when the deadlines start (the important milestone dates for the program are shown below). The previous postings in this series were:


New CFATS Deadlines

January 17th, 2015

Effective Date of Title XXI;
Repeal of conflicting provisions of current regulations

March 18th, 2015

Have facility outreach program established

June 16th, 2015

Publish guidance for Expedited Approval Facility

July 16th, 2015

Start point for 120 day deadline for current Tier 3 and Tier 4 facilities to submit EAF site security plans

November 13th, 2015

Deadline for current Tier 3 and Tier 4 facilities to submit EAF site security plans

Grandfathered SSPs


All site security plans approved by DHS as of December 18th are grandfathered by law. SSPs approved between that date and the date of new CFATS regulations may be grandfathered by Secretarial discretion. 

Thursday, December 18, 2014

HR 4007 – Expedited Approval Facility

This is part of a continuing discussion of the recently passed HR 4007, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014. In this post I will be looking at new expedited approval facility provisions of HR 4007. The previous postings in this series were:


One of the suggested methods for reducing the backlog of site security plan approvals has been that there ought to be a simpler method for smaller, lower threat facilities to get their site security plan (SSP) approved. One suggested method has been to use a system similar to what the EPA uses for water treatment facility security; the facility would certify that it meets the security requirements specified in the Risk Based Performance Standards guidance document. Congress took this basic idea and made it a little bit more complicated when they created the expedited approval facility (EAF) program in §2102(c)(4).

DHS Requirements

To start this program off, the bill requires the Secretary to accomplish two tasks within 180 days of the bill being signed into law. They are:

● Issue guidance for expedited approval facilities that identifies specific security measures that are sufficient to meet the risk-based performance standards {§2102(c)(4)(B)(i)}; and

● Develop prescriptive site security plan templates with specific security measures to meet the risk-based performance standards under subsection (a)(2)(C) for adoption and certification by a covered chemical facility assigned to tier 3 or 4 in lieu of developing and certifying its own plan.

Actually the second item is permissive not required and there is no actual time limit associated with the Department’s publication of templates. I’ve included it here for two reasons; it is specifically mentioned in the EAF program {§2102(c)(4)(A)(ii)}and Congress gave the same exemption from the regulatory approval process that it gave the Secretary for development of the EAF guidance (see the previous post in this series for more details on this exemption).

After a facility makes its site security plan submission (as described below) DHS has 100 days {§2102(c)(4)(G)(i)(II)}to make a determination that the submitted plan if ‘facially deficient’, otherwise the plan is considered approved. The term ‘facially deficient’ means that the {§2101(7)}:

(S)ite security plan that does not support a certification that the security measures in the plan address the security vulnerability assessment and the risk-based performance standards for security for the facility, based on a review of—

(A) the facility’s site security plan;
(B) the facility’s Top-Screen;
(C) the facility’s security vulnerability assessment; or
(D) any other information that—
(i) the facility submits to the Department; or
(ii) the Department obtains from a public source or other source

I’m not sure how the good folks at ISCD are going to get this review system set up, but they have been specifically authorized by this bill to employ contractors for conducting this sort of review (not making the final go/no go decision – that’s a purely governmental responsibility). Whether they can get it set up in time is a question for a future date. From the facility point of view, if they can’t get the review done in 100 days, it doesn’t matter; the plan is automatically approved.

Owner Requirements

Things get a little more complicated from the owner’s point of view. Let’s talk timelines first. The starting point for timelines for existing CFATS facilities that have had their security vulnerability assessments accepted by ISCD and have been assigned to Tiers 3 or 4 is 210 days after the bill becomes law (which is 30 days after ISCD is supposed to have their guidance document published). Facilities notified of their tier ranking after the bill is signed start on the date of their tier notification.

Facilities have 120 days to submit their site security plan and certification that the plan conforms to the guidance provided by ISCD. At least 30 days before the certification is sent, the facility must notify ISCD that they intend to certify as an expedited approval facility {§2102(c)(4)(D)(iii)}. Actually the certification is just a tad bit more complicated than that; the owner/operator certifies that {§2102(c)(4)(C)}:

(i) the owner or operator is familiar with the requirements of this title and part 27 of title 6, Code of Federal Regulations, or any successor thereto, and the site security plan being submitted;

(ii) the site security plan includes the security measures required by subsection (b);

(iii)
(I) the security measures in the site security plan do not materially deviate from the guidance for expedited approval facilities except where indicated in the site security plan;
(II) any deviations from the guidance for expedited approval facilities in the site security plan meet the risk-based performance standards for the tier to which the facility is assigned; and
(III) the owner or operator has provided an explanation of how the site security plan meets the risk based performance standards for any material deviation;

(iv) the owner or operator has visited, examined, documented, and verified that the expedited approval facility meets the criteria set forth in the site security plan;

(v) the expedited approval facility has implemented all of the required performance measures outlined in the site security plan or set out planned measures that will be implemented within a reasonable time period stated in the site security plan;

(vi) each individual responsible for implementing the site security plan has been made aware of the requirements relevant to the individual’s responsibility contained in the site security plan and has demonstrated competency to carry out those requirements;

(vii) the owner or operator has committed, or, in the case of planned measures will commit, the necessary resources to fully implement the site security plan; and

(viii) the planned measures include an adequate procedure for addressing events beyond the control of the owner or operator in implementing any planned measures.

I expect that we will see the certification as a form in CSAT with check marks in the appropriate places. Oops, maybe not as the bill clearly states that the certification must be “signed under penalty of perjury”. So I guess this will probably be another sign and send to ISCD form.

Compliance


This post is starting to get more than a little long, so I’ll look at the compliance issues in another post.

Sunday, December 14, 2014

HR 4007 – An Overview

While we are still waiting on the President to sign this bill into law (which he is fully expected to do considering the Administration’s vocal support of the measure) it would seem that this on-going discussion about HR 4007 should start with an overview of the provisions of the bill. The previous posting in this series was:


Table of Contents

The general layout of the bill includes five sections:

SEC 1. Short Title – Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014;
SEC 2. Chemical Facility Anti-Terrorism Standards Program – Codifies the CFATS program in 6 USC Title XXI;
SEC 3. Assessment; Reports – Provides for a series of reports to Congress about the performance of the program;
SEC 4. Effective Date; Conforming Repeal – Changes the authority for the CFATS program effective 30 days after this bill is signed into law; and
SEC 5. Termination – Provides for the termination (barring future Congressional action) of the CFATS program 4 years from the date the bill is signed.

The meat of the program is laid out in §2 with 9 new sections added to the US Code:

Sec. 2101. Definitions.
Sec. 2102. Chemical Facility Anti-Terrorism Standards Program.
Sec. 2103. Protection and sharing of information.–
Sec. 2104. Civil enforcement.
Sec. 2105. Whistleblower protections.
Sec. 2106. Relationship to other laws.
Sec. 2107. CFATS regulations.
Sec. 2108. Small covered chemical facilities.
Sec. 2109. Outreach to chemical facilities of interest.

What the Bill Does

First and foremost this bill codifies the CFATS program and takes it out of the annual renewal in the DHS spending bill process. It establishes a 4 year term for the program, subject to future renewals of this authorization by the Congress. In many ways it also makes it easier for Congress to make incremental changes to the program.

The legislation does add some new components to the current CFATS program, including (a more detailed discussion of these additions will be seen in future posts):

• An expedited approval process for site security plans at Tier 3 and Tier 4 facilities;
• The establishment of a whistleblower protection program;
• A requirement to include employee participation in the development of site security plans; and
• Special assistance programs for small chemical facilities.

Interestingly, for the two complicated new processes included in the expedited approval program the bill specifically exempts the Secretary from having to go through the ‘publish and public comment’ regulatory approval process. This is the only way that the tight timeline (180 days) for these two programs could be accomplished.

There is nothing in the bill that specifically repeals anything in the current program. It does, however, provide some more in depth guidance to clear up what has been seen as ‘problems’ within the program. These include (again more details in later posts):

• Additional guidance on the personnel surety program;
• Provision of specific authority to provide guidance on what security measures to include in a site security plan;
• Authority to use inspectors from other government agencies and contractors;
• Risk assessment methodology;
• Changes in Tiering;
• Clarification of enforcement authority; and
• Outreach to chemical facilities of interest.

What is Missing

If I had been writing this legislation there are some additional areas that I would have included to make this a truly comprehensive chemical facility security bill. These could have included:

• Guidance on updating the list of DHS Chemicals of Interest (COI; Appendix A to 6 CFR Part 27);
• Inclusion of the ammonium nitrate security program;
• Guidance on coordination with the Coast Guard on chemical security at MTSA facilities and the NRC on chemical security at nuclear power generation facilities;
• A clear definition of what railroad related facilities could be included in the facilities of interest definition;
• Some sort of discussion about cyber-security requirements; and
• Clear guidance on the status of agricultural facilities as potential facilities of interest.


What is good about the passage of HR 4007, however, is that the heavy lifting on chemical security has now been done and the details (like those mentioned above) can be dealt with on a piecemeal basis.

Saturday, December 13, 2014

HR 4007 Sent to the President

This week saw Congress take a serious step forward in helping to assure that chemical facilities across the country would be protected against a terrorist attack by passing HR 4007, the first comprehensive chemical security bill passed by Congress. As much as Democrats and Republicans have disagreed in the past about how to accomplish chemical security the votes this week were without significant debate.

To be sure there was considerable work done behind the scenes by the staffs of both the House Homeland Security Committee and the Senate Homeland Security and Governmental Affairs Committee working out compromises that both sides could live with. Even so there were some last minute changes made to the bill that ease the concerns that a few unidentified Senators had. Without those changes the bill never would have come up for a vote in the Senate and we would still have to continue limping along on an appropriations bill to appropriations bill basis for the CFATS program.

We are going to have to have at least one more extension (maybe two) of the current §550 authorization of the program to allow the new program authorized by the new ‘Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014’ once it is signed by the President (probably next week). The new legislation will not erase, or necessarily make serious changes to the current CFATS regulations under 6 CFR Part 27. Rather it will codify (under 6 USC Title XXI) most of the existing program and provide a four year authorization of the program.

In many ways the hard part is just starting. The folks at the Infrastructure Security Compliance Division (ISCD), in addition to having to continue to enforce the current regulations, will have to develop a number of new processes and guidance documents and to craft some changes to the current regulations to implement what Congress has now directed. Some of this will have to go through the normal, time consuming regulatory revision process, but significant changes have been specifically exempted from that process in the legislation so that they can be implemented in an expeditious manner. It will be interesting to see how that works out.


Over the next couple of days, I will be looking at what is included in the final legislation and how DHS might go about implementing the changes. The clock does not start on any of these changes until the President signs the bill into law, but I’m pretty sure that ISCD has already informally started work on putting a plan together to implement the new requirements.

Thursday, September 4, 2014

Senate Hold on HR 4007?

I’m hearing rumors from a couple of different sources that some unnamed business organization is shopping around trying to find a Republican Senator to put a hold on the consideration of HR 4007, the CFATS authorization bill approved by the Senate Homeland Security and Governmental Affairs Committee back in July. This seems odd since the two biggest chemical industry organizations SOCMA and the American Chemistry Council have both endorsed the bill (including the Senate changes).

Since I have not talked to anyone from this organization (I’m not sure if it is a business group or a company) I don’t know what their specific objection to the bill is, but I would guess that it is the whistleblower provisions (§2105) of the bill that raise the ire of the organization. That is a shame since the provisions in the Senate version of the bill are among the most watered down whistleblower provisions that I have seen attached to a chemical security bill.

Both homeland security committees have done an excellent job at working to get a bill that has extensive bipartisan support. This is the first time since chemical security legislation was first considered post-9/11 that there was a bill that was not sharply drawn along ideological lines. The chair of the two committees have done some excellent work on crafting a bill that could make it through the legislative process in a divided legislature. It would be a crying shame if a single organization, working through a single Senator, could prevent a comprehensive chemical facility security bill from coming to a vote in the Senate.


Don’t get me wrong. Even passage in the Senate does not make this bill a forgone conclusion. Since the Senate version is extensively different from the House version, it would still have to get through the conference process before it could head to the President. With spending bills (more probably a continuing resolution) and political posturing on the legislative agenda for the next two months (actually only 2 weeks early in September a short week late in the month), this bill could easily get lost in the political shuffle. But it won’t even have that chance if it does not come to a floor vote next week.

Friday, August 1, 2014

Senate Homeland Security Committee Rewrites and Adopts HR 4007

On Wednesday the Senate Homeland Security and Governmental Affairs Committee marked up and adopted HR 4007, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014 (NOTE: That is a name change). Substitute language was offered by Chairman Carper (D,DE) and Ranking Member Coburn (R,OK) and it was subsequently modified. The new language was adopted by a voice vote with Sen. Senator Baldwin (D,WI) voting no.

Changes

Most news reports have identified only two changes to the bill; a new expedited approval program for Tier 3 and Tier 4 facilities and an expansion of the whistleblower protections. These were the two really major changes (and will be discussed in more detail in a subsequent post), but the substitute language was a major re-write of the bill passed by the House. Most of the changes were language and formatting changes (this version does read cleaner), but there were other changes that will significantly change the Department’s actions resulting from this modified bill.

The changes include:

• Specifically allows the Secretary to suggest improvements to an alternative security plan to allow its approval {§2102(c)(2)(A)(ii)};
• Specifically authorizes the use of contractors (nongovernment personnel) to support the audit and inspection program {§2102(d)(1)(C)};
• Specifically authorizes the use of nondepartment personnel to conduct audits and inspection (EPA-RMP and/or OSHA-PSM presumably) {§2102(d)(1)(C)};
• Limits site security plan approval authority to DHS personnel {§2102(d)(1)(D)(iii)};
• Replaces requirement of nongovernment inspectors to have a Secret security clearance with the possession of a CVI certificate {§2102(d)(1)(e)};
• In two places where ‘consultation’ is required adds requirement for consulting with ‘public and private labor organizations’ {§2102(e)(1) and §2109};
• Adds a requirement for semi-annual reports to Congress about retiering and removal of facilities from CFATS program {§2102(e)(4)};
• Removes phrase ‘if such information may not be disclosed pursuant to any State or local law’ from paragraph about sharing with States and local governments {§2103(b)};
• Removes requirement to share information through ‘Homeland Security Information Network or the Homeland Secure Data Network’ {§2103(c)};
• Added specific exemption from disclosure under the Freedom of Information Act (5 USC 552) {§2103(e)};
• Expanded ‘Civil Penalties’ section to include ‘Civil Enforcement’ activities {§2104};
• Added ‘Non-reporting chemical facilities of interest’ under Civil Penalties {§2104(b)};
• Specifically limits rights of enforcement action under the program to the Secretary of DHS {§2104(d)};
• Specifically allows that “each existing CFATS regulation shall remain in effect unless the Secretary amends, consolidates, or repeals the regulation” {§2107(b)};
• Gives Secretary 30 days to “repeal any existing CFATS regulation that the Secretary determines is duplicative of, or conflicts with, this title” {§2107(b)(2};
• Lowers maximum number of employees to 100 at facility and adds ‘small business concern’ (15 USC 632 for definition) to definition of Small Covered Facility {§2108(a)};
• Expands assistance that may be provided to Small Covered Facilities to include “cybersecurity, recordkeeping, and reporting procedures” {§2108(b)};
• Specifically repeals Section 550 upon effective date of this bill {§4(b)}; and
• Sets 4 year termination of program {§5};

In addition to the above changes there were three things that were specifically removed from the bill:

• References to ‘Security Screening Coordination Office’ {Old §2101(d)(3)(C)};
• The rail transit exemption language {Old §2105(c)}; and
• The entire spending authorization section {Old §2110}.

Security Plan Suggestions

One of the problems that has plagued the enforcement of the current CFATS regulations is the interpretation that the prohibition against requiring specific security measures for approval of site security plans also applied to DHS providing suggestions to facilities about how to get their programs within compliance. Some inspectors have been more aggressive than others in limiting their suggestions to avoid the appearance of requiring a security measure and this makes it harder for facilities to know what changes need to be made to get their SSP authorized.

The language of {§2102(c)(2)(A)(ii)} will certainly make this clearer for facilities submitting alternative security plans (ASP) and I think that most inspectors (and inspectees) will assume that it is okay for an inspector to let a facility know what types of things have been used at other facilities to respond to a specific security situation.

Consultation with Labor Organizations

The language of §2102(e)(1) and §2109 could have only been added in the Democrat controlled Senate. Having said that, since the relationship with the labor organizations is only consultative, this language should not raise any significant ire in the Republican controlled House. There were lots of other labor inspired additions that could have been added to the bill that could have interfered with its adoption by the House.

Moving Forward


The earlier in September that this bill comes to the floor of the Senate for a vote (which will almost certainly have bipartisan support) the better the bill’s chances of getting through Conference before the November elections.

Monday, July 28, 2014

Congressional Hearings – Week of 7-27-14

This is the start of the last week currently scheduled for the House and Senate to be in Washington until after the Labor Day Weekend. There is only one hearing currently scheduled that is of specific interest to readers of this blog; a Senate markup hearing that looks at a number of interesting bills including CFATS.

Senate Markup Hearing

On Wednesday the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting to cover a wide range of nominations and legislation. Included in the list of bills to be addressed are:

HR 4007, the Chemical Facility Anti-Terrorism Standards Program Authorization and Accountability Act of 2014;
S 2547, the RESPONSE Act of 2014; and
S 2664, a public alert and warning system bill yet to be published.

HR 4007 is, of course, the bill of biggest interest here. The Committee leadership has been talking about writing their own bill since the first of the year, but has failed to reach a consensus on that language. There has been recent talk about Chairman Carper (D,DE) wanting to see language added that would allow Tier 4 facilities to ‘self-certify’ compliance with the site security plan requirements. That amendment would probably be acceptable to the House. Anything more complicated than that might derail passage of this bill.

House Floor

Today the House will consider a number of bills under suspension of rules. Four of them will be of interest to readers of this blog:

HR 2952 - The Critical Infrastructure Research and Development Act;
HR 3107 - The Homeland Security Cybersecurity Boots-on-the-Ground Act;
HR 3202 - The Essential Transportation Worker Identification Credential Assessment Act; and
HR 3696 - The National Cybersecurity and Critical Infrastructure Protection Act.


The House leadership has determined that these bills have enough bipartisan support to ensure their passage with a 2/3 vote. I’m kind of surprised that HR 3696 made that cut considering the number of organizations that still have problems with privacy issues in the bill. We will see if they get surprised on this vote; it does happen periodically.
 
/* Use this with templates/template-twocol.html */