Showing posts with label Heritage Foundation Report. Show all posts
Showing posts with label Heritage Foundation Report. Show all posts

Sunday, August 26, 2012

A Closer Look at the Heritage Foundation Report – Conclusions


This is the final blog in a series taking a critical look at the recent Heritage Foundation report on the problems with the CFATS program. While the report authored by Jessica Zuckerman is not up to the usual editorial standards of the Heritage Foundation it does raise some interesting issues. The earlier blog posts can be found here:




The final section of the Heritage Foundation report on the CFATS program is called “Developing Market-Oriented Chemical Security Solutions”. As one would expect with a concluding section of a report it summarizes the author’s conclusions. This post will address those conclusions and some of the other shortcomings of the report.

Report Conclusions


Here is my summary of those conclusions (okay, I stole them from the subheading in the section):

• Take a truly risk-based approach to chemical security;

• Reject calls for greater regula­tion;

• Expand SAFETY Act protec­tions to encourage greater inno­vation;

• Promote public–private part­nerships to enhance aging U.S. infrastructure; and

• Foster greater transparency and cooperation.

I have dealt with most of these conclusions in earlier the earlier posts on this report, so I will not dwell on them further here. There is one new area found in this concluding section that it not addressed anywhere else in the report and that is the one dealing with ‘aging U.S. infrastructure’. It is a shame that Ms. Zuckerman forgot to address this issue in the body of her report because she may have made a potential contribution to the discussion of chemical facility security. Unfortunately, we are left with glittering generalities such as:

“The United States’ overall critical infrastruc­ture, including the chemical sector, is inadequate and aging. Greater investment is needed not only to ensure that U.S. critical infrastructure is protected but that it is capable of bouncing back quickly when disaster strikes.” (pg 10)

In general there is more than a little truth in the description of critical infrastructure as ‘aging’ and ‘inadequate’ covers a wide range of perceived and actual problems. The conclusion that ‘greater investment is needed’ is hardly revolutionary, but it begs the question of where the money is going to come from for that investment. This issue is one that deserves a whole host of reports about specific areas of infrastructure, public and private, that could have a potential effect on chemical facility security.

Industry Response


One would be forgiven for concluding, after reading this report, that industry was widely disillusioned with the CFATS program and wanted to see it replaced with a radically different program. This is never specifically stated in the report, but Ms. Zuckerman does repeatedly talk about the burdens that the program places upon industry.

In the last couple of days, however, the chemical industry has started to respond to this report, and it hasn’t been favorable. An article over at NTI.org (Government Security Newswire, GSN) quotes representatives from two of the largest organizations representing chemical facility owners, the American Chemistry Council (ACC) and the Society of Chemical Manufacturers & Affiliates (SOCMA) as being generally supportive of continuing the CFATS program. They acknowledge problems with the current implementation, but support the basic premise and design of CFATS.

These two organizations certainly don’t represent all of the chemical facilities that are covered under CFATS, but I would be willing to bet that they cover a majority of the Tier 1 and Tier 2 facilities that are having to spend the greatest amount of money on upgrading the security measures at their facilities to comply with the program.

Now part of that support is simply fear of the unknown. Not knowing what type of program would replace CFATS, and Ms. Zuckerman provides nothing beyond glittering generalities, industry would rather deal with the devil they know than accept the potential for an entirely new program.

Given the fact that Congress has been unable to craft comprehensive chemical security legislation since 2001, it is unlikely that it would be able to do so any time in the foreseeable future. Eliminating the CFATS program would leave a void with unpredictable consequences. The GSN article notes that industry fears that an EPA based program might result in requiring IST implementation. What is even more likely is that several State and local governments, no longer restricted by the supremacy of the CFATS program, would craft a patchwork of local regulations that would leave selected facilities with onerous requirements (certainly including IST provisions in many localities) while leaving their competitors with no regulations.

Areas That Were Not Addressed


There are a number of problem areas in the CFATS program that were glossed over, minimally mentioned, or completely ignored in this report. While I have addressed most of these in some details in various posts over the years, I would like to take this opportunity to mention some of the more important ones (in my opinion) so that future researchers might have a better chance of preparing a report that deals with actual issues and problems in the CFATS implementation.

CFSI


Ms. Zuckerman briefly mentions the problem with the qualifications of Chemical Facility Security Inspectors (CFSI). The initial members of the CFSI were drafted from the Federal Protective Service. These were law enforcement personnel with a background in physical security, they had little or no background in dealing with chemical facilities. The folks at ISCD realized this problem and established a Chemical Security Academy. I did an initial blog posting on that topic a number of years ago. Since then I have done a number of other blog postings on the issues related to training of CFSI. They include topics such as:







Armed Security Forces


A number of commenters on the Anderson Memo about the problems associated with the current CFATS program have taken particular issue with the problem of current CFSI who started out as sworn law enforcement personnel wanting to continue carrying their side arms. Leaving aside for the moment the definition of enforcement in the CFATS environment, the failure of ISCD to address the issue of the use of armed security personnel to stop terrorist attacks on high-risk chemical facilities is a much unnoticed failing of the program. I have dealt with this issue in a number of blog posts:











SSP Shortcomings


The biggest current problem with ISCD is their apparent inability to effectively authorize any Site Security Plans. While many commenters have noted this problem, no one has attempted to determine the root cause. While I have not had the opportunity to do a detailed study of the problems on the ground, it is clear from the limited comments we have heard from DHS and the inspected community that there is a serious shortcoming with the current SSP tool in CSAT; it is not adequately soliciting the information needed by ISCD to conduct a paperwork evaluation of the programs at the facility.

Any security professional that looks at the questions asked in the SSP tool would realize that the level of detail required for an adequate assessment of the security plans at the facility would not be provided by those questions as asked. This has resulted in DHS establishing the Pre-Authorization Inspection program where presumably the CFSI are tasked with seeking out the necessary information.

I have addressed the ways that this problem might be addressed by facilities in submitting their SSPs, but it seems to me that the SSP tool needs a fairly extensive revision if it is ever going to provide the level of detail necessary for ISCD or its contractors to evaluate the security planning at CFATS covered facilities. Lacking that ISCD should institute a program where they send a detailed letter to the facility seeking the specific information they need to make their evaluation rather than sending the CFSI out to get the information.

Personnel Surety


While there are any number of other security related issues that might be addressed by any reasonable revamp of the administration of the CFATS program, I’ll just address one more in this posting, the lack of an approved personnel surety program. RBPS #12 requires facilities to conduct background checks on all facility employees and contractors and any visitors requiring unaccompanied access to critical areas of the facility. The provisions for checking identity, criminal history and legal authorization to work can be adequately complied with by using any of a number of commercial organizations to conduct background investigations. The one area that cannot be accomplished by such organizations is the identification of people with terrorist ties.

The failure of ISCD to come up with a reasonable program for allowing facilities to have ISCD or some other agency of DHS to vet personnel against the Terrorist Screening Database is inexcusable. Such a program should allow for the use of any of the currently available TSA vetted identification programs (TWIC, HME, etc) and/or provide a simple method of submitting individual information to ISCD for such vetting. ISCD tried to make their program much more complicated than was necessary. Since that program was recently withdrawn, ISCD’s delay in getting such a program established will continue to put off establishing a terrorist screening program for an even longer period of time.

Moving Forward


ISCD and the CFATS program have a number of challenges and problems to overcome. Documents that are purportedly comprehensive looks at the program like this Heritage Foundation report could provide a basis for the discussion of how to move proceed with developing a workable chemical security program for high-risk chemical facilities. Unfortunately, Ms. Zuckerman did little to move the discussion forward.

Thursday, August 23, 2012

A Closer Look at the Heritage Foundation Report – More Regulations


This is the third blog in a series taking a critical look at the recent Heritage Foundation report on the problems with the CFATS program. While the report authored by Jessica Zuckerman is not up to the usual editorial standards of the Heritage Foundation it does raise some interesting issues. The earlier blog posts can be found here:



In this posting I will look at the “Calls for Further Regulations” section of the Heritage Foundation report. Generally Ms. Zuckerman gets the cart before the horse in this section and jumps to early conclusions as has been her writing style throughout the report.

She opens her discussion by stating:

“In spite of the critical issues that have ensued after the implementa­tion of the CFATS program, there have been many calls for further regulation of the chemical sector. While generally misguided, many of these measures have received a good deal of attention in Congress.” (pgs 7-8)

Because she is a late comer to the chemical facility security issue she just doesn’t realize that all of these calls for additional regulation pre-date the formation of CFATS and form the basis for the political wrangling that delayed chemical security legislation for so long and caused the poorly conceived interim congressional authorization for the current program.

Regulation of Exempted Facilities


In this portion of the report Zuckerman identifies the five categories of facilities exempted from CFATS coverage. She ignores the current DHS efforts to harmonize chemical security coverage at two of these categories (MTSA and NRC regulated facilities) and singles out water related facilities for her examples of the errors of expanding the CFATS coverage.

She starts off her argument by stating that:

“These facilities currently fall under the regulatory authority of the Environmental Protection Agency (EPA) and are already subject to risk management and emergency plan­ning requirements under the Safe Drinking Water and Clean Water Acts.” (pg 8)

There are two problems with this tired argument. First the majority of the CFATS covered facilities also come under risk management and emergency planning requirements under a variety of EPA and OSHA regulations. Of course none of these cover prevention of terrorist attacks; that is why chemical security regulations were deemed necessary.

Secondly, the weak and unenforceable (even if EPA did have security inspectors) water security regulations only require larger water facilities (with more than 3500 customers) to conduct a security vulnerability assessment of threats to water quality. There are no security standards set with which these facilities must comply and certainly no EPA effort to regulate the security of toxic chemicals (principally chlorine gas, but a number of other toxic release hazards as well) at these facilities.

She concludes with the tired argument that “any shutdown due to regula­tory non-compliance would likely have large effects on public health and well-being” (pg 8). The suggestion that DHS would shut down non-compliant water treatment facilities is a non-argument that has been specifically addressed in every legislative effort to add water treatment facilities to the CFATS program.

Finally, Ms. Zuckerman ignores the most powerful argument against adding the water treatment industry to the CFATS program. Such coverage would more than double the number of facilities covered under the program with the vast majority of those facilities falling under Tier 1 or Tier 2 coverage. This would certainly exacerbate the current work-load problems ISCD is experiencing.

Of course, DHS is well aware of this problem and have included in all of their latest suggestions for CFATS coverage of water facilities that EPA actually take charge of the security at those facilities using the CSAT tools for the administration of that program. Unfortunately, DHS and EPA can begin working out the details of such a program but it would take specific congressional authorization to implement as EPA has even less authority to require security measures than does DHS.

Inherently Safer Technology Mandate


Zuckerman reports the rhetoric of the IST debate fairly well. Unfortunately no effort was made to examine any of the actual legislative proposals that have been submitted in either the House or the Senate over the years. The political proponents of mandating the consideration of IST implementation have been careful to moderate their proposals by having the implementation requirements to be based upon the assessment of potential methods done by facility management. Industry and its political supporters have generally been unwilling to discuss how such proposals could be modified into a workable proposal.

The report does briefly address the fact that a number of facilities have already availed themselves of IST implementation measures to remove themselves from the CFATS regulatory regime; noting that:

In fact, more than 2,000 chemical facili­ties are no longer deemed high-risk and are no longer subject to CFATS, due to voluntary risk-reduction measures.” (pg 8)

She doesn’t address, however, the problem that ISCD doesn’t have a formal mechanism for reviewing those changes to determine how those ‘risk reductions’ were achieved. Many methods of risk reduction at a facility are really nothing more than risk transfer; moving the risk to other manufacturing facilities, storage facilities or transportation nodes. Other risk reduction moves are little more than gaming the system like the industry change of a standard 20% aqueous ammonia concentration to 19% to avoid the material being covered under CFATS.

The issue of IST as a security measure is more complex than the discussion provided in this report. It deserves a more detailed review that provides both sides with a clearer understanding of the positions of the two sides so that a compromise might be achieved in this area where there is legitimate potential for gains in absolute security for many chemical facilities.

EPA Authority Under the Clean Air Act


This final heading under the section concerning potential legislation provides Ms. Zuckerman another chance to provide a superficial examination of the rhetoric of the situation rather than address the actual issues involved. She focuses on the fact that this suggested regulation is an alternative method of enforcing IST requirements that are being politically stalled in Congress, but fails to address the precarious legal justification being used (see my more detailed discussion in my blog post on HR 6345) to forward this proposal. She also fails to mention that the proponents of this idea have gone beyond addressing a letter to the President; there are reports that a formal petition has been filed with the EPA requesting enforcement under the General Duty Clause.

The superficial discussion of the issues involved allows Ms. Zuckerman to jump to another conclusion based upon facts not addressed in the report. She closes this section by stating that:

“But, not only would the Clean Air Act proposal undermine one of the few things CFATS gets right—the restriction on the federal govern­ment from proscribing specific secu­rity measures—it would also likely impose overlapping and confusing requirements and additional cost burdens [emphasis added] on facilities already regu­lated by CFATS.” (pg 9)

While almost anyone in industry would agree with this statement by Ms. Zuckerman there is nothing in the preceding paragraphs that addresses these issues. A political commentator might be able to get away with such a leap in a blog post or editorial, it is considered ill form in a purported background information report.

Almost to the End


Well there is just one more section of this Heritage Foundation report left to look at and I’ll cover it in a later blog.

Monday, August 20, 2012

A Closer Look at the Heritage Foundation Report – Four Principles


This is the second blog in a series taking a critical look at the recent Heritage Foundation report on the problems with the CFATS program. While the report authored by Jessica Zuckerman is not up to the usual editorial standards of the Heritage Foundation it does raise some interesting issues. The earlier blog post can be found here:


In this post I will be looking at the discussion in the Report under the heading of ‘Right in Principle, Wrong in Practice’. This section looks at the program from the perspective of how well the CFATS implementation has followed the four principles outlined by Under Secretary Beers in his March 30th, 2011 testimony before the House Homeland Security Committee (Oops, it was before the House Energy and Commerce Committee on March 31st, 2011 and the link provided in the report is bad, DHS web site change not Ms. Zuckerman’s fault there, but the rest is just poor scholarship).

Cross-Collaboration


Zuckerman properly points out that the individual facilities, the Federal government as well as State and local governments all have interests in securing high-risk chemical facilities. She then takes the CFATS program to task for centralizing the responsibility for security at the Federal level. She notes that:

“The government must determine facilities’ risk lev­els, set performance standards, and assess security plans and compliance.”

Congress provided in §550 that DHS was supposed to develop a security program targeted at just those chemical facilities that were determined to be at the high risk for terrorist attack. Furthermore, the program should be risk-based with the highest risk plants getting the earliest attention. All of these require DHS to determine facility risk levels.

The performance standards were published by DHS as one would expect since they would be judging if facilities met these performance standards in the implementation of their security plans. DHS developed the standards in conjunction with industry input and published a draft of the Risk-Based Performance Standards. Extensive industry comments were received on that draft (see my blog posts from 11-28-08, 12-05-08, 12-05-08, 01-09-09 and 01-13-09) and were taken into account when the final version was published.

Furthermore, DHS worked hand-in-hand with industry in developing, fielding and modifying the Top Screen and Security Vulnerability Assessment Tools. For both of these portions of the CFATS process the first ten or so facilities to complete submissions had DHS personnel on site in the information development and submission process to work out the inevitable bugs in the system. The lessons learned in those shared submission efforts were put into modifying the tools and documentation before those systems went live for the remainder of the CFATS community. That this was not done in the SSP submission process probably goes a long way to explain the problems in that system.

Ms. Zuckerman closes this section by claiming that:

“Enhancing chemical security does not mean that the private sector should yield its responsibil­ity to the federal government.” (pg 5)

Nowhere in her arguments does she show where the private sector has been required to yield its responsibility for the security of their facilities. The CFATS program does not specify how a security program should be put together, it simply provides standards by which the government will judge the success of that program. That those standards are vague at best is at least partially the responsibility of private industry. They were the ones that demanded performance based standards and complained about anything coming close to specifics in the draft version of the RBPS Guidance Document.

Risk-Based Tiering


Zuckerman takes DHS to task for not sharing the basis for the Department’s risk tiering process, a complaint that has been made a number of times over the years since the first NPRM was published for the CFATS regulations. Actually this complaint has been combined with the lack of openness about the process for establishing the ‘high-risk’ status of facilities in the first place.

The report properly notes that the details of the risk-ranking methodology is not shared with owners. This does not allow an owner to do more than to make a reasonable guess as to what actions the facility can take to have their Tier ranking lowered or even to be removed from the CFATS list all together. There is a process in place to submit information to have either the Tier ranking or CFATS listing reconsidered, but it is an iterative process at best.

While I agree with Ms. Zuckerman’s assertion in this case, she does her report ill service by not addressing, even in passing, the reasoning that DHS has used to avoid publicizing the details of their methodology. This lack of addressing opposing arguments is another of the reasons that this Heritage Foundation report is probably more useful as a political document than a real study of the issues involved.

Any discussion of the sharing of information about the security tiering or assessment process must take into account the official DHS response to such questions in the regulatory comment process. DHS outlines their position quite clearly in the preamble to the Interim Final Rule published in the Federal Register (72 FR 17700 – 17701).

Zuckerman also addresses the failure of DHS to share tiering information with State and local authorities; stating that:

“In addition, first responders and community leaders have also expressed concern about the lack of transparency of facility tiering and risk assessments, citing the fact that the lack of information sharing may impede emergency response and community preparedness.” (pg 5)

While one might suppose that State and local officials might want some input on the evaluation process of facilities within their jurisdiction, the claim of lack of transparency of the facility tiering and risk assessment process fails to address the efforts made to share that information with local authorities. DHS has made it clear that facilities have an inherent responsibility for coordinating with local emergency response officials and provides the State Homeland Security Directors with access to an online tool in CSAT to check on the CFATS status of chemical facilities within the State.

Finally, Ms. Zuckerman takes DHS to task for the problem it discovered last year in its risk model. While there should be some discussion on the internal delays in responding to the discovery of the model discrepancy, it really is disingenuous to complain about the problem with the model. Any researcher or academic knows that a model is only an approximation of reality and adjustments have to frequently be made to models to ensure their accurate reflection of reality. ISCD should be commended on monitoring their system closely enough to detect and correct the problem.

On an editorial note there are many claims of comments by unnamed industry or local government officials within this section. The footnotes to those claims almost uniformly point to the book “Chemical Facility Security” by Shea, but not a single page citation is provided. This is just another continuing example of the poor scholarship exhibited throughout this work.

Performance Standards


Zuckerman’s section on performance standards, or more appropriately the Risk-Based Performance Standards (RBPS) actually addresses the core issue of the current ISCD problems. She acknowledges that the theory behind the RBPS is good but notes that in practice “chemi­cal facilities have largely been left uncertain over what is expected of them in meeting the DHS’s stan­dards” (pg 6). Unfortunately, industry is largely to blame for these problems. They insisted on risk-based performance standards instead of concrete security measures and even convinced their politicians in Congress to prohibit DHS from specifying any security measure as being necessary for SSP approval.

As I noted earlier, when DHS published the draft of the RBPS Guidance document in October 2008, the industry comments came fast and furious. While many of the comments were constructive the vast majority were complaining that this or that was too specific and wouldn’t or shouldn’t apply to their industry or company. Once again DHS gave in to the political pressure (which is never mentioned in Ms. Zuckerman’s report), and produced a very vague RBPS Guidance document.

Ms. Zuckerman blames the problem, in part, on the Chemical Facility Security Inspectors (CFSI’s; oh, she never does use their proper title; a small thing to be sure); noting that:

“Similarly, issues in training and hiring capable and experienced inspectors has resulted in confusing and conflicting feedback from ISCD inspectors in the course of pre-authorization visits and authorization inspections.”

I’ll address the CFSI specific issues in a later post, but this complaint (not unique to Zuckerman) misses the important point. In the pre-authorization and Authorization inspections, the inspectors are just the eyes and ears of the ISCD staff. It is that staff (and frequently contractors) that never sees the facility that makes the decision on whether or not an SSP is approved or not. Thus, the person the plant talks to is not the person making the decisions.

DHS has tried to clarify this on a number of occasions, but I seriously don’t think that it has really gotten through to the folks in the inspected facilities. Thus this reported confusion in the field.  Oh by the way, Ms. Zuckerman provides no source for her comments about ‘confusing and conflicting feedback from ISCD inspectors’.

Leveraging Existing Advancements


This section of the report deals with the usage of ‘Alternative Security Plans’ or ASPs. Ms. Zuckerman falls into the same language trap that most people do when the discuss ASPs. When most of the chemical industry talks about ASPs they mean security programs like the American Chemistry Council’s Responsible Care Security program. This is a set of standards along with a third party verification of compliance for security related issues. When industry talks about ‘accepting’ such a plan it appears that they mean the facility should be given credit for that plan when they have been certified by the third party and DHS should accept that as an approved SSP.

DHS, on the other hand misnamed their SSP; it is not a site security plan. What the SSP is is a series of questions about the security set up at a particular facility to determine if that security program meets the requirements of the Risk-Based Performance Standards. DHS doesn’t care if the security measures are part of another certified site security plan; great, just so long as your answers to the questions show the facility meets the RBPS.

The problem is that ISCD does not have the time nor the manpower to read the documents associated with a real security plan; a 100+ page document with annexes describing emergency response, personnel surety, key control, etc. Adding a variety of formats from different security programs will only add to that problem.

Ms. Zuckerman manifests her misunderstanding of the problem by stating that:

“This lack of motivation on the part of the DHS to seriously consider ASPs inhibits the ability of compa­nies to continue to employ security measures in which they have already invested time and effort, thereby discouraging the innovation and creative thinking that have been critical to the security of the private sector in the past. As such, it limits the field of security options to those rigidly established by the federal government.” (pg 6)

Nothing that DHS is doing is limiting the ability of facilities to continue to use existing security measures, either to completely or partially fulfill their compliance with the 18 risk-based performance standards set forth in the CFATS regulations. And DHS is specifically prohibited from establishing rigid security options.

What industry really wants is for the currently established voluntary security programs to be accepted without review by DHS. In essence what they want is to have these third-party certification agencies to perform the inherently governmental function of examining and approving the security plan for CFATS covered facilities. Unfortunately, DHS has been given the responsibility for performing this function and does not have authority to transfer that responsibility to a private sector entity (okay, we’ll ignore for the moment that they are using contractors for the information processing necessary to make that decision; oh, that isn’t in the Heritage Foundation report).

In the closing paragraph in this section of the report Ms. Zuckerman brings up an interesting point that I must admit I haven’t seen mentioned in reference to the CFATS program. She mentions that “the department should encourage companies to apply for certification under the Support Anti-terrorism by Fostering Effective Technologies (SAFETY) Act of 2002”. Actually I have heard of the SAFETY Act program and I seem to recall that it is run by DHS S&T, not NPPD.

Still if NPPD could identify areas where new technology would benefit facilities covered under the CFATS program, it would certainly be helpful if a SAFETY Act program could be put together to fulfill that need. Okay, I’ll remake a suggestion here; chemical facility response forces need a weapon that can be used to stop violent attackers without posing a safety hazard when used within the high-risk environment of a chemical facility. Sorry that’s a pet peeve of mine and doesn’t really have anything to do with the review of this report. It won’t happen again.

Other Critical Concerns


This section deals with the issues raised in the so called Anderson memo that was made public last December. Ms. Zuckerman has had no more access to that memo than have any of the rest of us that have commented on the problems at ISCD. So I’ll give her a pass on all of the errors in this section as they are the same ones that just about everyone has made. She has no background working with this program so she can only repeat the same unfounded charges. See my blog post from last December on my reporting on the ISCD issues.

Sunday, August 19, 2012

A Closer Look at the Heritage Foundation Report – CFATS Description


As I promised earlier this week I am taking a closer look at the report issued earlier this week by the Heritage Foundation on the CFATS program. Jessica Zuckerman presents an overview of the CFATS program that presents a newspaper style review of the program problems and concludes that the program is too complex and overly burdensome. Unfortunately she is weak on the program details, glosses over some real problems, and provides little in the way of details that would actually contribute to the discussion much less justify her conclusions that the CFATS program should be eliminated.

This is the first in what is going to end up being a multi-part look at the Heritage Foundation Report and the real problems with the CFATS program.

CFATS Background


Ms. Zuckerman presents a brief history of the events leading up to the adoption of the authorization of the CFATS program by §550 of the Department of Homeland Security Appropriations Act of 2007. She starts as do most commentators with the Bhopal disaster, but only lists the 1990 Clean Air Act Amendment containing the General Duty Clause as a legislative response to that incident, ignoring the legislation dealing with community right-to-know, emergency planning and process safety management. A number of the current problems in the CFATS program can be traced back to these pieces of legislation and the government’s inability, for both technical and political reasons, to provide for proactive inspection forces to oversee the implementation of those rules.

The Report goes on to look at the political conflict that prevented the establishment of a comprehensive chemical security program. Unfortunately, Ms. Zuckerman only mentions (without ever providing the name or bill number; S 1602, the Chemical Security Act of 2001) the original legislation proposed by Sen. Corzine (D,NJ), but never mentions the alternative proposals that did not contain inherently safer technology proposals (such as Sen. Inhofe’s (R,OK) S 993, the Chemical Facilities Security Act of 2003).

Thus she provides only a one-sided view of the debate that held up passage of any chemical security legislation until §550 provided for an interim final rule (IFR) that resulted in the CFATS program. This provision for an IFR clearly indicated that Congress was cobbling together a short-term measure that would be replaced at some later date by more comprehensive legislation. Many of the problems of the current program can be traced back to this ‘interim’ nature of the legislation.

She also ignores the political implications of establishing a chemical security program through a short paragraph in an appropriations bill. This has provided for a singular lack of Congressional oversight of the program because there is no clear delineation of which House committee would be responsible for that oversight.

‘Overly Burdensome’


The Zuckerman report provides an adequate overview of the CFATS program under a section entitled ‘Overly Burdensome and Confusing Standards’. This conclusive (and misleading) section title is a perfect example of the low standards of scholarly work exhibited throughout this report. She starts in the opening paragraph by describing the current ‘chemical terrorism threat’ by claiming that:

“Indeed, of the 51 publicly known Islamist-inspired thwarted terrorist plots against the United States since 9/11, at least three have involved chemical facilities or the diversion of potentially dangerous chemicals.” (pgs 2-3)

She cites no source for these numbers nor does she even provide a footnote with a brief description of the three chemical related attacks. Now I have been following chemical security issues for some time now and I don’t recall any publicly-acknowledged thwarted-attacks on any chemical facilities. The closest that I can remember is the plot on the New York airport fuel lines, hardly a chemical facility under any of the currently accepted definitions.

Then before she can even begin to describe the current program she concludes that:

“While a degree of government oversight over chemical security is needed, current standards are exceedingly burdensome and com­plicated, and overprescribe federal solutions with which the private sec­tor must comply, threatening innova­tion and economic expansion.” (pg 3)

Zuckerman does provide a reasonably concise explanation of the four stages of the CFATS process. Her description continues to pre-judge the process, however, starting her description by stating that:

"Currently, CFATS requires that each facility undergo a complicated and often confusing four-step pro­cess, any aspect of which the facility can be required to repeat, should its chemical supplies change….” (pg 3)

This statement clearly exhibits her misunderstanding of both the CFATS process and the nature of the chemical industry and the potential threats that it faces. She clearly misunderstands that chemical facilities are not what are really at risk of terrorist attack (or at least not more so than any other critical infrastructure facility); but that terrorists would attack chemicals produced, used or stored at those facilities to achieve an even larger chemical munitions effect on the surrounding community.

Tier Ranking Confusion


She is a little loose in her description of the Tier ranking process, but it isn’t clear if this is because of a fundamental misunderstanding of the process or poor writing skills. In describing the Top-Screen process she states that:

“These facilities then received an ini­tial risk ranking, with Tier 1 indicat­ing the highest level of risk and Tier 4 the lowest.” (pg 3)

DHS clearly refers to this as a ‘preliminary’ Tier ranking in their discussion of the Top Screen results. The difference between ‘preliminary’ and ‘initial’ may seem to be nit-picking on my part, but she later exemplifies her apparent confusion when she states in her description of the SVA process that:

“From the submitted SVA informa­tion, the DHS ultimately determined that 4,569 of the more than 7,000 initial facilities should in fact be des­ignated high-risk, and gave them a preliminary-tier or final-tier ranking.”

A misunderstanding of such a simple yet important part of the CFATS process exemplifies a low level of process knowledge that brings the remainder of her critique into question.

SSP Preauthorization Visit


In her description of the SSP ‘Authorization and Compliance’ step of the CFATS program, Ms. Zuckerman glosses over the first indication of the current problems with the CFATS program. She describes the SSP approval process this way:

“In order for an SSP to be approved and a facility to be considered fully CFATS-compliant, the ISCD must conduct a pre-authorization visit and an authorization inspection.”

There is nothing in the CFATS regulations or SSP documentation provided by ISCD that describes the use of or requirement for a ‘pre-authorization visit’. This was a compliance tool that DHS added when it became clear that the information being submitted in the SSP process by facilities was inadequate for judging the compliance of SSP with the Risk-Based Performance Standards. The addition of this ‘visit’ as part of the compliance process was the first real indicator that we had about the current problems with the CFATS process.

Misses the Program Strengths


While Ms. Zuckerman’s description of the CFATS process is adequate, as part of a serious look at the efficacy of the regulatory regime it falls well short of being comprehensive. There is no description of the development of the Chemical Security Assessment Tool, the series of on-line tools that allow for the electronic submission of information to DHS. The success of the tools for the Registration, Top Screen and Security Vulnerability Assessment is often overlooked in critical reviews of the CFATS program.

The use of the Registration and Top Screen tools made it relatively easy for facilities that met the initial operational definition of a potentially at-risk chemical facility (possession of a significant quantity of potentially hazardous chemicals) to submit the required information to allow DHS to remove the vast bulk of those facilities from further consideration under the CFATS program.

Furthermore, the internal computer-based modeling made the complex decision-making process based upon the Top Screen information much more efficient. The process of whittling down the initial 38,000 facilities to little more than 7,000 potentially at risk facilities was accomplished in remarkably short order, a process that couldn’t have been done in nearly the same amount of time, or by the same small staff, by the old-fashioned paper-based information submissions.

The Top Screen tool and the ISCD modeling work do not get near the credit that they deserve in the CFATS process. The SVA submission tool provided another innovative information submission and analysis capability that Ms. Zuckerman can only find fault with because it might take as much as 250 hours to complete. She also notes that that is a DHS pre-implementation estimate and forgets to mention that there has been no effort to document the actual amount of time that it took facilities to complete their submissions.

Furthermore, it is clear to anyone that has looked at the CFATS process in any detail that the success of the Top Screen and Security Vulnerability Assessment tool inevitably led the leadership at ISCD to try to extend that methodology to a process that was so much more complex that the same type tools could not provide the level of information necessary to adequately judge the level of compliance with the established RBPS.

Again, Ms. Zuckerman’s misunderstanding of the strengths and weaknesses of this program weaken the importance of the conclusions that she draws; conclusions that I will address in subsequent blog posts.
 
/* Use this with templates/template-twocol.html */