Showing posts with label ISCD Problems. Show all posts
Showing posts with label ISCD Problems. Show all posts

Friday, January 18, 2013

ISCD Blog Post


Yesterday afternoon David Wulf, Director of the DHS Infrastructure Security Compliance Division {the CFATS/Ammonium Nitrate Security Program (ANSP) people} provided the folks at SOCMA with a post on their blog site. It was a brief and positive update on the progress that his folks have been making on improving the CFATS program, both accomplishments to date (200 SSPs authorized and 22 approved) and future actions.

SOCMA is to be commended for offering Mr. Wulf the opportunity as is the Director for taking advantage of the offer. Communications between the regulators and the regulated are always a good thing.

Missing Information


Now I fully understand that a single blog post is not the best way to communicate complex information (I have heard complaints about the length of some of my posts). And, the problems at ISCD are certainly complex and cover a wide range of areas. But there were a number of things not addressed in David’s post. They include (in no particular order of importance) the status of:

• The publication of the Personnel Surety Program;

• The MTSA harmonization effort;

• The update of the COI list;

• The update of the CVI rules for the Controlled Unclassified Information Initiative

• The temporary agricultural facility Top Screen exemption; and

• The publication of the Ammonium Nitrate final rule.

Personnel Issues


There are also more than a few issues dealing with personnel matters within ISCD that I would have liked to have seen addressed. I understand the reluctance to talk about internal problems, but they do affect the operations of the Division and have at least some impact on the SSP approval process. There are three that I specifically wish to see ISCD discuss in public:

• Branch Chief Status (conversion of ‘temps’ to ‘permanent’);

• Turnover in the Chemical Security Inspector ranks; and

• Training program for CSI.

Now I understand that there is some concern within the National Protection and Programs Directorate (NPPD) about the number of their employees that have been unofficially (and anonymously) contacting me about these personnel issues. I have heard rumors that Deputy Undersecretary Spaulding has directed ISCD to reach out to me about this ‘problem’.

So, I would like to take this opportunity to offer to Mr. Wulf or any of his Branch Chiefs the unrestricted opportunity to post information in my blog about any of the issues identified above (or any other of their choosing really). It can take the form of a blog post or even written responses to questions submitted by me. If anyone at ISCD thinks that they have appropriately addressed these issues in some other public venue, please point me at the links and I will publish those.

Tuesday, September 18, 2012

Follow-up on OIP Personnel Problems


A little over a week ago I did a post on some personnel issues in NPPD’s Office of Infrastructure Protection that were identified to me in a copy of an email sent to the DHS IG. As one would expect I have had problems finding someone in DHS that would talk with me about these issues on the record. Even off the record no one wants to provide any details about the alleged improprieties in OIP.

I have, however, been told by a former senior staffer from Infrastructure Protection that these types of allegations are not new. That former staffer notes:

“Jobs are given to those in favor with senior IP leadership without regard to process or to qualifications. Many if not most of the difficulties with IP programs can be traced to unqualified managers and distraught employees whose morale has been shattered by these shenanigans.”

Apparently formal complaints to the Office of the Chief Human Capital Officer of DHS go back at least 5 years. Supposedly there have been numerous specific complaints to the DHS Inspector General that have gone nowhere. Complaints have even been made to members of Congress with no apparent results. Everyone seems to want to sweep the problems under rug.

We saw last week in a Congressional oversight hearing that Congress pays little or no attention to the root cause of the problems at CFATS. It seems to me that these types of personnel issues are a sign of the underlying problem with the CFATS program and other programs being run by the Office of Infrastructure Protection.

Someone needs to start asking some hard questions of the management of NPPD. Congress will have another chance to redeem itself in its oversight responsibility on Thursday when the Homeland Security Subcommittee of the House Appropriations Committee has Deputy Undersecretary Spaulding before it in a resumption of its CFATS hearing. Maybe they will take the opportunity to ask some hard questions about the personnel issues that have led to the problems at ISCD.

Monday, September 10, 2012

More Problems at DHS OIP


Well, the problems at ISCD are not apparently the only ones that are occurring within the National Programs and Protection Directorate (NPPD) in DHS. This morning I was forwarded a copy of an email that was sent to the DHS IG, the OPM IG, and various managers in the Office of Infrastructure Protection. The email outlines specific hiring and promotion irregularities (and in my opinion, if true, illegalities) within the Infrastructure Information Collection Division (IICD) and the Infrastructure Security Compliance Division (ISCD).

The email outlines names of the beneficiaries and perpetrators of these actions. To avoid any possibility of slander complaints (since I cannot independently verify any of these claims) I will not go into any details, but there is enough here to keep a team of investigators busy for a while. The types of actions alleged include, creating positions for individuals, publicly pre-selecting individuals to newly vacated positions, blatantly ignoring veterans preferences in hiring and promotions, and an open romantic relationship between individuals in a senior-subordinate work situation.

I would encourage both Inspectors Generals (DHS and OPM) to publicly announce that they are initiating an investigation into these problems.

I was disappointed to see that no one in Congress was copied on this email, but Congress has such a good history of oversight over these programs that I really am not surprised. I will be happy to forward a copy of the email (cleansed of the link that forwarded it to me) to any congressional staffer or investigator from the Senate Homeland Security and Governmental Affairs or House Homeland Security Committee that contacts me. Hell, since there is a Subcommittee Hearing tomorrow where Under Secretary Rand Beers is appearing, I’ll even supply the information to someone from the House Energy and Commerce Committee if they ask for it.

Tuesday, August 7, 2012

Grassley and CFATS


Last Friday I asked why CBS News was quoting Sen. Grassley (R,IA) about the problems at ISCD. Today a press release on the Senator’s web site may have answered the question; it looks like former DHS Assistant Secretary Keil may have come to Grassley when it was clear that none of the oversight Committees were going to take a serious look at the ISCD problems.

Last week Grassley sent a letter to Secretary Napolitano. The letter asks the first set of detailed questions about specific problems in ISCD. Unfortunately, the questions that he asks are about relatively minor problems in the administration of the CFATS program and don’t get to the basis of the real problems at ISCD.

Locality Pay


I’m relatively sure that the Keil, or someone like him, is the unnamed whistle blower in the letter. Only a late comer to the program, with little actual knowledge of the operation of ISCD, would raise the issue of locality pay as a means to insinuate that the chemical facility security inspectors were trying to cheat the government. Field offices were set up, but it was clear that inspectors would be spending little time in them so there was initially no requirement that the inspectors move to the city where their office was located.

Due to a misunderstanding of the rules by ISCD management, inspectors were given locality pay based upon the location of their office instead of their home. According to multiple sources the Department’s recoupment of those improper payments was one of the reasons that the inspector corps sought union representation.

This was a management issue, but it doesn’t appear that it was due to any special malfeasance. In retrospect it seems clear that the management team was inadequately trained on the rules under which their employees would be operating. That couldn’t be because the people were being pulled into NPPD from all over the Department. Or spending so much time putting a new program together in a short time period with little guidance from Congress that they didn’t have time to learn the admin rules.

HAZMAT Suits


Grassley asks a series of questions pointing out the gross waste of taxpayer funds spent on HAZMAT suits for the CFATS inspection force. To a chemical professional like myself it is pretty clear that CFATS inspectors would probably never have any use for such equipment. Unfortunately, no one assigned to the ISCD management team had any experience with chemical manufacturing facilities.

Now anyone that has watched anything about chemical plants on TV knows that HAZMAT suits are an integral part of protecting employees at such plants; hazardous chemicals leaking at such facilities being such a common occurrence. Who would expect a government agency to provide any less protection of their employees? Okay, it was stupid, but their hearts were in the right place.

What Questions Should Have Been Asked


Because Grassley is totally unfamiliar with the CFATS program he has to rely on a whistleblower who knows even less about the program. Someone who actually knew something about the program would have asked a completely different set of problems.

Why hasn’t anyone in industry been able to submit an acceptable site security plan (SSP)? There isn’t any clear, unambiguous guidance from ISCD about what constitutes an adequate SSP.

Why hasn’t ISCD been able to tell facilities what is needed to correct their inadequate plans? Because Congress specifically prohibited them from providing such guidance.

Why hasn’t ISCD redone the questions and instructions for the on-line SSP submission tool? Because they don’t understand why the chemical community doesn’t provide the ‘necessary information’.

Has anyone independently verified that the reasons for declining the approval of any chemical facility SSP are in accordance with currently accepted security practices? Probably not.

Is there anyone in ISCD who is trained to review control system security procedures? Not hardly.

Is there anyone in ISCD with experience in emergency response planning? Probably not.

Why hasn’t ISCD gotten an approved TSDB vetting program set up yet? I don’t have any idea.

Grandstanding Senator


Oh well, we couldn’t get anyone with a background in CFATS to be concerned about the problems in the program, so I guess we’ll just have to deal with Sen. Grassley. Unfortunately, he’s getting his information from someone with an apparent ax to grind with Under Secretary Beers and Deputy Assistant Secretary Armstrong rather than from someone who actually has dealt with the CFATS program.

This is why this should be handled by the two Homeland Security Committees. They have staffs that are at least conversant with the CFATS program. Their staffs could ask the pertinent questions of the people involved in the program and learn that while the whistleblower may have some pieces of information, that those minor problems have nothing to do with the real problems being experienced by this important program.
We need much more than silly questions by a grandstanding Senator. Grandstanding? I bet he doesn’t make public the reply he has requested from the Secretary. It would make him look silly.

Friday, August 3, 2012

More ISCD Rumors


This is just a short note to report that I am hearing rumors that Rick Driggers, the former acting Director of ISCD has been appointed the Acting Assistant Director of ISCD to temporarily fill the post vacated by Wulf’s ascension to the post of Director last month. Driggers seems to keep coming back, which begs the question of where he keeps going to when someone permanent is posted.

The leadership changes at ISCD keep the CFATS program in additional turmoil, as if they didn’t already have enough problems. If Driggers is qualified for the job (and he certainly has been exposed to the problems in the Division) then why make him the acting AD, a position he would have to leave in 90 days?

CBS News Discovers ISCD Problems


Last night the folks at CBS News provided a brief look at the problems at ISCD that have been discussed here for over a year now. Nothing new here other than former DHS Assistant Secretary Todd Keil confirms what I said back in February about his being forced out because of CFATS problems.

Okay I’ll take that back. On the video (I didn’t see this on TV, who would have known) Keil claims that he requested an IG investigation, but that request was not forwarded to the IG. If there is any documentation of that request (and I really doubt that there is) then Under Secretary Beers has something to answer for. Of course someone like Keil would have known that such a request was political suicide, so if it was really made he would have gone directly to the IG as was his ‘right’ as a federal employee. More likely he mentioned that an IG investigation was needed and it was quashed with his reluctant acquiescence.

The timing on this is absolutely stupid. Congress is leaving town so they can’t (wouldn’t really any way, but now they have the excuse) do anything about it. This is a 90 second wonder that will be forgotten in the news about the campaign and political conventions.

One question for the producer at CBS; why Senator Grassley? This was the only member of Congress that they included in the piece and he has little or nothing to do with the oversight of CFATS. Why didn’t they ask Lieberman, Collins, King or Thompson? These are the people that have abdicated their oversight responsibilities for the CFATS program.

Of course, this piece by CBS, all of the hearings to-date, have ignored the basis of the problem. Congress saddled the folks at CFATS with an unenforceable program, denying them the ability to tell facilities what they needed to do to get a site security plan approved. With each facility requiring a multiple visit negotiation where one side had to remain silent ensures that the site security approval process would be time consuming at best. The fact that the folks at ISCD were less than efficient at implementing this was really just icing on the cake.

BTW: A reader pointed me at this story last night, commenting that I had been ‘scooped’ by CBS. Hardly, but CBS is over six months late covering this story; FOX News beat them with their story back in December.

Friday, July 27, 2012

CFATS Hearing Before Appropriations Committee


Yesterday’s scheduled hearing before the House Appropriations Committee’s Homeland Security Subcommittee on the problems at ISCD and CFATS was cut short by floor votes. There have been reports that it will resume sometime next week, but there is not yet anything about that on the Committee web site.

I completely missed the opening statement by Chairman Alderholt (R,AL)  and saw only the tail end of the statement by Ranking Member Price (D,NC). Unfortunately, the Appropriations Committee does not carry links to the webcast of this hearing nor copies of the opening statements. So I guess I’ll just have to give those comments the public recognition that the Committee thinks they deserve; I’ll ignore them.

GAO Report


As I promised in my earlier blog, the GAO provided the Committee with a report on the problems at ISCD. Actually, that isn’t true, at least in the publicly released version of the report. That report looks at how well ISCD is executing its action plan to correct the deficiencies that ISCD determined existed in the CFATS program execution. According to the GAO, ISCD appears to be executing the ISCD plan well.

An interesting statement is found at the bottom of page 10 of the report:

“Additional details on the human capital, mission, and administrative issues identified in the ISCD memorandum are considered ‘for official use only’.”

Hopefully that means that there is a non-public version of this report that addresses those sensitive, but important issues.

While I think there is a certain justification for keeping the details of the ‘issues identified’ by ISCD hidden from public view from a security perspective, I think that Congress, GAO and DHS have a responsibility to share more information with the public in general and the regulated industry in particular. The chemical industry has been spending millions of dollars on addressing issues related to CFATS at the direction of an apparently fundamentally flawed organization. Surely they deserve to know about the basic problems at that organization that may have caused them to waste significant amounts of that money.

The one thing that does come out in the public GAO report is that the problems that have been affecting the CFATS program are not just within the domain of ISCD. The report notes that the ISCD memo included concerns about “insufficient and inconsistent support by NPPD and IP with regard to human capital needs” (page 10). This problem is certainly removed enough from actual security implications that it can certainly be publicly discussed except that it falls within the much more tightly held classification of ‘politically sensitive’.

Deputy Under Secretary Spaulding


Deputy Under Secretary Spaulding is the NPPD official directly responsible for the Office of Infrastructure Protection which includes ISCD. She is certainly not responsible, however, for the problems leading up to the current fiasco since she just took that post last November. As we have come to expect, however, her prepared testimony does little to look at the actual problems involved with the CFATS, and continues in the tradition of optimistic, forward looking testimony by administration officials from two administrations.

She does report on the current status of the CFATS implementation (page 4):

“As of July 20, 2012, CFATS covers 4,425 high-risk facilities nationwide; of these 4,425 facilities, 3,662 are currently subject to final high-risk determinations and submission of an SSP or ASP. The remaining facilities are awaiting final tier determinations based on their SVA submissions. ISCD continues to issue final tier notifications to facilities across all four risk tiers as it makes additional final tier determinations.”

While she completely ignores the SSP approval process here, she does not later (page 5):

“ISCD is currently utilizing an interim SSP review process [emphasis added] to enable ISCD to move forward with SSP reviews in a consistent, reasonable, and timely fashion. At this time, ISCD has completed its initial review of all Tier 1 SSPs and has begun reviewing Tier 2 SSPs. As of July 16, 2012, of the Tier 1 SSPs reviewed, the Department has authorized or conditionally authorized SSPs for 63 facilities. Of the remaining Tier 1 SSPs reviewed by the Department, we are either validating results or reaching out to these facilities to obtain additional information or action in the hope of resolving the outstanding issues affecting their SSPs.”

If the number of ‘authorized or conditionally authorized’ SSPs seems to be rather small, we can take heart in Spaulding’s ‘pleased’ announcement that “as of July 16, 2012, ISCD has resumed authorization inspections at Tier 1 facilities” (page 6). Of course they still have no guidance on their Chemical Security web site for facilities about the interim process; that guidance was removed back in March.

She does take the Committee to task for their reduction in the funding for the CFATS program in the House passed DHS appropriations bill:

“DHS estimates that, after expending approximately $35 million for salaries and benefits for 242 FTEs, approximately $12 million would remain for implementing CFATS and completing development of the proposed Ammonium Nitrate Security Program. DHS would be forced to cease virtually all activities under CFATS other than those directly related to reviewing SSPs and performing facility inspections—which means those other activities would be significantly delayed. At the proposed $45.4 million funding level, the Department’s ability to conduct the most basic CFATS functions would be impacted. These include maintaining the CSAT and the Chemical-Security Management System information technology systems, and acquiring important technical and subject matter support. Additionally, CFATS-related outreach and engagement with the regulated community would be significantly reduced and some aspects would cease; development and implementation of the proposed Ammonium Nitrate Security Program would be significantly delayed; and many of the managerial improvements outlined in the ISCD Action Plan may be delayed or negatively impacted.”

I can understand how the budget cuts can a real management problem, but ‘significantly delay’ the development and implementation of the Ammonium Nitrate Security Program? How can it be ‘delayed’ more than missing its four year congressionally mandated deadline?

Next Week


It will be interesting to see what happens in the questioning before the Committee next week, if that hearing is actually held. It will certainly not be a friendly hearing.

Sunday, July 22, 2012

Congressional Hearings – Week of 07-23-12


With two weeks left before the long summer vacation Congress starts to look more at the bills that can pass rather than the legislation that is needed. There are only two hearings that will be of interest to the chemical security community and only S 3414 possibly on the horizon for the cybersecurity community. The two House hearings of interest are a homeland threat assessment and a CFATS Hearing.

Homeland Threat Assessment


The House Homeland Security Committee will be holding a hearing Wednesday on “Understanding the Homeland Threat Landscape”. Secretary Napolitano and the National Counterterrorism Center Director Matthew Olsen are the only witnesses currently scheduled to testify. This is scheduled as an open hearing so there won’t be anything really interesting here.

CFATS Hearing


On Thursday the House Appropriations Committee will be holding a hearing on the Chemical Facility Antiterrorism Standards (CFATS) program. It seems kind of odd timing for such a hearing before this Committee as the DHS spending bill that already passed in the House had the CFATS funding cut in half by the Committee.

Having said that it looks like this may be an important hearing for the future of the CFATS program. No one from ISCD is scheduled to testify. The DHS witness is Under Deputy Secretary Suzanne Spaulding, the number two person at NPPD. She won’t have much personal insight into the source of the problems at ISCD since she just joined NPPD in November, but the Committee will probably be pressing here for info on the steps being taken to correct the problem.

The most important witness, however, will be Director Steve Caldwell, of the GAO’s Homeland Security & Justice Issues. The report that he presents to the Committee will be the first real outside look at this program since its inception in 2007. It will certainly be the first definitive look at CFATS since its problems were publicly identified in December.

It is unfortunate that the first real look at these problems has to come from the Appropriations Committee, particularly after this year’s appropriations process has been almost completed. But the Senate Homeland Security Committee has completely ignored their oversight responsibility and the House Homeland Security and the Energy and Commerce Committees held hearings that were even less effective than the NPPD oversight of the program. So it is left to the Appropriations Committee to take care of a problem that was created in an appropriations bill.

The Appropriations Committee does have one more potential time to affect the CFATS program this session. That is when the DHS spending bill comes before the conference committee to iron out the inevitable differences between the House and Senate versions of the bill. Unless this hearing produces some news of an overwhelming turnaround at ISCD (and there has been no public performance to date that would indicate that) I would expect that this committee’s leadership will insist on their draconian cuts of the funding for the CFATS program; cuts that were not questioned in the House consideration of the bill.

S 3414


The Senate does not publish a weekly schedule of what it will be considering (it doesn’t know itself that far in advance), but it is looking increasingly likely that S 3414 may actually make it to the floor this week. News reports seem to indicate that the privacy advocates are satisfied with this revision and we have heard little from the business community. If they have no serious objections the Senate might start consideration of this bill. If they do there will be lots of amendments to be considered and I doubt that the bill will be passed this week. It still won’t be taken up by the House until after the election (if then) in any case.

Monday, March 12, 2012

ISCD Updates CVI Pages?

It seems that ISCD is going through a review process on their CFATS related web pages. You can see this by observing the “This page was last reviewed / modified on ….” on the bottom of many of their pages (more on their pages than just about anywhere else in DHS). Today the review took place on the landing page for the CFATS Chemical-terrorism Vulnerability Information (CVI) program. As far as I can tell there were no substantive changes made on this page.

Now this is one of the pages that I try to check every business day, looking for updates on the program; particularly the overdue changes expected in response to President Obama’s Executive Order 13556 on Controlled Unclassified Information (CUI). I don’t typically take time to check all of the links on the page (and they are quite numerous on this particular page) unless the date on the bottom of the page changes; like today.

When I checked each link today, I found that one of those pages had been changed reviewed/changed back in January; the Training for Chemical-terrorism Vulnerability Information page. Again, I didn’t see any significant changes on this page, but I did note something of concern; all of the links to the CVI training program were dead links, returning a “Internet Explorer cannot display the webpage” notice. I don’t know if other browsers can access the sites.

Hopefully someone in ISCD will notice this problem and correct the links. Probably not, they seem to be worrying about other things lately.

Sunday, March 11, 2012

More on ISCD Hearing – Industry Suggestions

Earlier this week I noted in a blog post on the ISCD hearing held before a subcommittee of the House Homeland Security Committee on Tuesday that the industry witnesses had offered suggestions about how the CFATS implementation could be improved. None of this was directly mentioned in the oral presentations or addressed in the questioning by the Subcommittee (with the exception of one tiny inconsequential question and answer), but it was included in the written testimony of Timothy Scott (DOW/ACC) and Bill Almond (SOCMA).

There wasn’t anything that was really new in these suggestions; SOCMA and ACC have been mentioning most of these for some time now; but this was an appropriate venue to bring them up. It would have been nice if there had been more time for consideration/discussion of these suggestions, but that is a common problem with congressional hearings; just not enough time for a discussion of all of the interesting and important topics.

The suggestions fall into three broad categories:

• TWIC-Personnel Surety Program

• Alternative Security Programs

• Outside Inspectors

TWIC-Personnel Surety Program


There is one area where there is broad agreement between management and labor and Democrats and Republicans is that the personnel surety program being developed (‘being developed’ for a number of years) by ISCD for use by CFATS facilities to fulfill the requirement of the Risk-Based Performance Standard #12 should ‘give full credit’ for the TWIC and other federal identity documents that include vetting against the Terrorist Screening Database (TSDB).

What everyone (except ISCD) wants is for facilities not to be required to submit information to an ISCD Personnel Surety Tool for any employee that has a TWIC or HME (those being the two most common federal programs that would be represented by significant numbers of chemical personnel). ISCD wants information on TWIC/HME holders to be submitted so that they can check that those documents are still current; something that facility security managers can and should do. ISCD has made clear that it wants a list of everyone that is a CFATS employee or has unaccompanied access to a high-risk (CFATS) chemical facility; just not why that list is important or even necessary.

If this is all that the TWIC discussion was really about, this would be a no brainer. Congress should step in and tell DHS that the TWIC fully meets the requirements for vetting personnel against the TSDB. OOPS, congress, in their Section 550 (Department of Homeland Security Appropriations Act 2007) authorization language, specifically told DHS that they could not require any specific security measure. And Congress put nothing in that language requiring vetting against the TSDB; another of the many problems caused by the political failure of Congress to pass a comprehensive chemical facility security bill.

Another problem that has not been addressed in the discussion about TWICs is that many in the chemical industry intend to use the TWIC instead of managing their own personnel surety program. Currently ISCD intends for each facility to do its own background check on each employee and on each guest given unaccompanied access to restricted areas of the facility with ISCD only getting involved in the TSDB vetting. If a facility were to require possession of a TWIC as a condition of employment and require all site visitors and contractors to also have a TWIC, they would not have to worry about the liability issues related to conducting and evaluating criminal background checks.

Some of the facilities (perhaps even most) will reimburse employees for the cost of obtaining a TWIC. There will certainly be a significant number that will not cover that cost, thus passing a portion of the cost of their personnel surety program onto employees. Since (as I understand it) the TWIC fee is an application processing fee will any of these companies reimburse employees that cost if they are denied a TWIC?

And there is the legal issue that has yet to be resolved; TWICs are used by ‘transportation workers’ that require access to MTSA covered facilities. Each applicant is required to affirm on their application that they require access to an MTSA facility as a requirement of their job. Since CFATS facilities are, by law, not MTSA covered facilities, companies requiring TWICs as a prerequisite for employment, will be asking many people to lie when they make that affirmation, a crime under federal law.

Congressman Lungren’s (R,CA) Subcommittee would do well to hold a hearing or two about this specific TWIC/CFATS issue and craft legislation as appropriate.

Alternative Security Programs


Congress in their extensive guidance to DHS about the establishment of the CFATS program (more than just a little sarcasm here) did authorize the Secretary to “approve alternative security programs established by private sector entities, Federal, State, or local authorities, or other applicable laws if the Secretary determines that the requirements of such programs meet the requirements of this section and the interim regulations”. This sounds like a great way for DHS to reduce their review/inspection workload; however, the very next paragraph of §550 says:

“Provided further, That the Secretary shall review and approve each vulnerability assessment and site security plan required under this section” {§550(a)}.

ISCD has set-up on-line tools for submission of data to be reviewed. The Site Security Plan tool is not really a site security plan, but rather a series of questions about the SSP. The answers to those questions are supposed to allow ISCD to evaluate if the SSP meets the risk-based performance standards outlined in 6 CFR 27.230. Since facilities submitting an alternative security plan still have to meet those standards, ISCD needs to review those submittals as well.

The only difference is that there will be a different format used for that data submission. I certainly don’t see how this will make ISCD’s work load any easier to bear. Either the submission will be an actual written ASP (an actual readable document that will explain what security measures are to be in-place, how they will be implemented, and who will have what responsibilities in implementing and enforcing those measures) or it will be another questionnaire about such a plan that ISCD will use in the same manner as they use the responses to their SSP tool.

Now I suppose that it is entirely possible that the ACC, or SOCMA, or any other industry supported organization could come up with an on-line data submission tool that would collect more appropriate data and/or organize the data collected in an easier to evaluate format. If that is the case (and the current SSP tool is very incomplete and poorly organized at best) then the ASP will be helpful. The only problem is that if every different industry organization comes up with a different ASP submission format; that is going to aggravate the current training problems at ISCD. And that isn’t going to improve anything.

Outside Inspectors


There was one relatively new suggestion made by Mr. Scott in the memo attached to his prepared testimony. On page 6 of that testimony/memo he makes the following proposal:

“DHS should consider an alternative self-inspection program for lower tier facilities (Tiers 3&4) using accredited third-party auditors. This alternative inspection program could be monitored with statistical sampling (audit schedule) by DHS CFATS inspectors to verify compliance. This would help streamline the program by lessening the burden on the DHS inspection cadre and allow DHS to focus resources and attention on higher risk facilities (Tiers 1 & 2). Existing private sector programs could be leveraged under this concept including the Responsible Care Security Code Program, which is mandatory for membership in ACC and requires third-party certification by an accredited third-party auditor.”

This idea does have a certain appeal. It would cover the vast bulk of the 4,000+ facilities currently in the CFATS program and it would certainly allow inspectors to spend more time at the highest risk facilities conducting final approval inspections and periodic re-inspections to allow for assurance that the programs are being properly maintained.

This would, however, specifically violate another congressional mandate in §550:

“The Secretary of Homeland Security shall audit and inspect chemical facilities for the purposes of determining compliance with the regulations issued pursuant to this section.” {§550(e)}.

So, DHS could consider this idea, but it would require specific congressional authorization to implement. I can just hear Rep. Thompson (D,MS) complaining about ‘inherently governmental functions’ when this comes up for discussion.

Besides, this will do nothing to address the current problems that ISCD is facing in getting SSPs approved. The compliance inspections have yet to start and we have many years to go before Tier 3 and 4 facilities will have to start to worry about compliance inspections.

The Real Problem


These industry suggestions, and even the Anderson-Wulf report, do not address or even identify the real problem that ISCD is having with the approval of SSPs at Tier 1 facilities. These facilities are huge and complicated and even the most basic security plan for them will also be huge and complicated. ISCD really had no idea how large or complicated an oil refinery (for instance) is or how complex a security plan for such a facility would have to be.

It quickly became obvious to all involved that the SSP tool was nowhere near complex enough to gather the data necessary to determine if the SSP was adequate to cover the 18 risk-based performance standards (RBPS). This is why DHS had to institute the ‘pre-authorization’ inspection program that were never included in the original CFATS program outlined in 6 CFR Part 27. Oh, and by the way, there is no authorization or requirement in those regulations to conduct those inspections.

If (and that is always an exceedingly large word in meaning if not spelling) they now have enough information to make that evaluation they face the second basic problem with CFATS program; ISCD cannot dictate what security measures are necessary to achieve compliance with those RBPS. Thus, ISCD has to negotiate with facility management as to what security measures will meet the requirements of the CFATS program. Again, this negotiation process is not specifically spelled out in the CFATS regulations, but is an inherent result of the congressional restrictions placed on DHS.

Now, I am reasonably certain that ISCD does not have the personnel trained in both security and chemical processing necessary to determine specifically what security measures are appropriate at any given facility. So there is no way that they should be given the authority to dictate security measures. This means that we are stuck with the current, and necessarily slow, SSP authorization process.

Additional inspectors and staff review personnel may help to speed up the process some. Some additional speed will come from the experience gained in previous negotiations on both the industry and government side of the table. And additional speed will be gained when the facilities are smaller and less complex.

But none of the items under discussion in these hearings, or probably anything in the Anderson-Wulf report will address this underlying problem. Until we start discussing this issue nothing can be done to significantly improve the time that it takes to complete the SSP authorization process.

Wednesday, March 7, 2012

ISCD Hearing – Part Two

Yesterday the Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies of the House Homeland Security Committee held their first oversight hearing looking at the problems in the DHS Infrastructure Security Compliance Division (ISCD) that deal with the implementation of the CFATS program. Neither the general public nor the regulated community has yet seen the internal ISCD report on the challenges ISCD is facing in completing the final stages of the CFATS program, but it was evident that this subcommittee was better read into the nuances of the report than was the previous panel that looked at this problem.

Management Questions


It is evident that the Anderson-Wulf report (Penny Anderson, the current ISCD Director and David Wulf, her Deputy Director) has not identified any actual criminal malfeasance involved in the problems identified in the program; that is the good news (though one would like to assume that a DHS IG investigation would be in order to assure that that is the case). So it would seem that the problems identified in the report (and I would like to suggest that at least a summary of the problems and proposed solutions should be made available to the public) were mismanagement issues which, unfortunately the DHS witnesses yesterday were unable to really address.

To be fair to Anderson and Wulf, they came into their current jobs and identified the problems existing within the program. Whether or not they have done anything of substance to clean up the problems remains to be seen (publicly at least), but they can hardly be held to account for the problems of their predecessors. As Ms. Anderson noted she wasn’t there when the problems started and thus couldn’t comment on why they occurred, suggesting in passing that the appropriate people should be questioned directly.

Under Secretary Beers was responsible for ISCD for almost two years before the Anderson-Wulf report was issued, but his consistent response in the two hearings to date was that nobody told him about the problems, with three exceptions that have been pretty well glossed over in both of the hearings to date. He does continue to note that he had commissioned two other reports on the CFATS implementation during his tenure, but they did not turn up any of the problems noted by Anderson and Wulf. It would be interesting to know if Congress has been given copies of those reports.

There continue to be suggestions that Beers had mislead Congress in his various hearing appearances over the 2+ years he has been at the helm of NPPD, failing to tell Congress about the delays in implementing the CFATS Site Security Plans. As best I can tell he has accurately reported the number of inspections that had been completed to-date at each hearing and he was never pressed for an explanation as to why the delays were occurring. And he was never held to account, from one hearing to the next, as to why his assurances of future improvement were never actually seen.

And, once again, he received a pass on the same issue at this hearing. His written testimony continues to report 55 authorized or conditionally authorized Tier 1 SSPs, the same number that was reported a month ago. Under the improved and accelerated program touted as resulting from the Anderson-Wulf reports one would have assumed that there should have been at least one or two additional facilities added to that list in that time frame. Otherwise it would seem that completion of the Tier 1 SSP authorizations in this fiscal year will again not be achieved.

Union Activities


As I had noted earlier I would have like to have seen this subcommittee question at least one current or former employee of the Division, but lacking that it was reasonable to include David Wright the President of the American Federation of Government Employees Local 918 that represents the chemical facility inspection force. Since his union was reportedly included in the Anderson-Wulf report as a contributing cause to the problems at ISCD and as one of the original group of inspectors brought into the program, his input should have been invaluable.

Once again, however, he is one of a long list of people that has never seen the Anderson-Wulf report, so he was unable to tell the Subcommittee much about the problems identified in the report. He did state that he has personally assured Anderson and Beers that he and his union are fully willing and committed to work with ISCD management in helping to resolve the issues involving the chemical inspection force.

Wright did receive a sympathetic hearing of his testimony. By the time he got a chance to testify, the only Republican asking questions was Chairman Lungren (R,CA) while all four Subcommittee Democrats were actively involved in questioning the industry-labor panel.

Industry Comments


Bill Almond from SOCMA and Timothy Scott from Dow Chemical were in the dark about the actual scope of the problems in ISCD as anyone else outside of the Department, not having seen the Anderson-Wulf report either. Both made it clear in their testimony and response to questions that they did not think the management issues apparently outlined in the report reflected any inherent problems with the CFATS program. They both indicated that they thought that an important part of any resolution to the management problems was a long-term re-authorization of the program.

Their written testimony includes a number of other recommendations for moving the program forward. I’ll review those in more detail in a later blog post.

Less Politics


I was impressed by the lack of overt politics involved in the questioning by this Subcommittee. Even Ranking Member Clarke’s (D,NY) questions about reauthorization were phrased to address how the current problems might impact Congress’ decision on how to go about reauthorizing the program; legitimately asking about the role Congress should take in addressing the identified problems.

The rhetoric was not fiery or accusatory in any of the questioning by this panel. It seemed that everyone was interested in getting to the root of the problems and all of questions indicated that these congress critters, at least, had done their homework about the program. Unfortunately, the five minute question-response format of this type hearing does not really lend itself to an investigation.

For Congress to effectively get to the bottom of these problems and adequately review the potential solutions they are going to need and independent report by the GAO or the DHS Inspectors General Office. The sooner that investigation is started the better.

Monday, March 5, 2012

Congressional Hearings – Week of 3-5-12

The Senate is joining the budget hearing schedule in force this week, but the big news is the CFATS hearing before a subcommittee of the House Homeland Security Committee.

CFATS Problems


The Cybersecurity, Infrastructure Protection and Security Technologies Subcommittee of the House Homeland Security Committee will be holding a hearing tomorrow on the CFATS program problems. It looks like Chairman Lungren is serious about this hearing as there will be two panels testifying. The first panel will be the management team including Under Secretary Beers, Director Anderson, and Deputy Director Wulf. The second panel will be a tad bit more interesting; Bill Almond from SOCMA, Timothy Scott from Dow Chemical, and David Wright from the American Federation of Government Employees Local 918.

I would have preferred to hear some of the lower level management and some of the inspection force testify, but a union rep will probably have to do at this point.

It will be interesting to see what questions are asked. Hopefully the congress critters will be a tad bit more prepared and knowledgeable in this hearing, not like the fiasco in the February hearing before the Energy and Economy subcommittee.

Budget Hearings


Secretary Napolitano will make two Senate appearances on March 8th to discuss the DHS budget request; one before the Senate Homeland Security and Governmental Affairs Committee and the other before the Homeland Security Subcommittee of the Senate Appropriations Committee. Nothing new expected in either hearing.

Admiral Papp will be making two Congressional appearances to discuss the Coast Guard’s budget request for FY 2013; one before the Homeland Security Subcommittee of the House Appropriations Committee tomorrow and one before the Senate Committee on Commerce, Science, and Transportation. The later hearing will be shared with the NOAA Administrator so that will certainly be a shallow hearing on the Coast Guard budget.

Monday, February 27, 2012

Congressional Hearings – Week of 02-27-12

Well Congress comes back this week from a week of celebrating President’s Day and there are some interesting hearings on this week’s schedule and two hearings already scheduled for the following week that may be of interest to the chemical and cyber security communities. This week we have a water security hearing, a cybersecurity hearing and an NPPD Budget hearing.

Water Security


Okay that may be a stretch but water facility security issues just might be mentioned in the hearing on “Local Government Perspectives on Water Infrastructure” on Tuesday being held by the Water and Wildlife Subcommittee of the Senate Environment and Public Works Committee. Local governmental officials are on the witness list. Any security related questions would come from Sen. Lautenberg (D,NJ) who has introduced legislation on water facility security issues (S 711).

Cybersecurity


On Tuesday the House Energy and Commerce Committee’s Subcommittee on Oversight and Investigations is holding a hearing on “Critical Infrastructure Cybersecurity: Assessments of Smart Grid Security.” The current witness list includes two GAO representatives (Gregory C. Wilshusen, Director of Information Security Issues and David Trimble, Director, Natural Resources and Environment) and a Congressional Research Service representative. It doesn’t sound like any control system expertise is involved; but Smart Grid isn’t about control systems is it? It’s all about personal privacy issues.

NPPD Budget


Under Secretary Rand Beers will be appearing at a closed door (classified) budget hearing before the Homeland Security Subcommittee of the House Appropriations Committee on Thursday. I have seen at least one news report that this hearing is all about the CFATS problems, but I really doubt that. The NPPD budget hearing is typically classified and the Subcommittee has too much on its plate this early in the budget cycle to concern itself in detail about the management issues in a small agency like ISCD.

No doubt that Beers will be questioned about the ISCD problems in this hearing; probably by Rep. Dent (R,PA) who has a history concern about the program and is the sponsor of the only one of the three House bills (HR 916) that has been ignored by both the Energy and Commerce Committee and the Homeland Security Committee.

I really expect that the bulk of the questions that require this classified briefing will have to deal with securing government information systems.

Preview of the Following Week


We already have two hearings on the schedule for the following week that will be of interest to readers of this blog; both will be held a week from Tuesday.

The House Homeland Security Committee’s Cybersecurity, Infrastructure Protection and Security Technologies Subcommittee will hold a CFATS oversight hearing. No witnesses are yet scheduled but we can certainly expect to see Beers and Director Anderson. It will be interesting to see if anyone else from the current or past staff of ISCD will provide testimony.

Commandant Papp will testify at a Coast Guard budget hearing before the Homeland Security Subcommittee of the House Appropriations Committee. I’m pretty sure that we will hear questions about the TWIC Reader program and possibly extending the expiration of the current TWIC cards.

Friday, February 10, 2012

Reader Comment – Hold off Blaming King

There was an almost immediate response today to my posting about how the Chairman of the House Homeland Security Committee is apparently ignoring the problems at ISCD in favor of pursing a personal agenda. While I barely mentioned reauthorization, an anonymous reader took me to task for my criticism of Rep King (R,NY); not because of a disagreement with King’s lack of focus on CFATS, but because a hearing next week might allow King to show his true resolve.

The Politics of Reauthorization


There are a couple of things wrong with that comment. Ignore for the moment that I was focusing on the issue of the problems at ISCD not reauthorization. King’s focus on reauthorization (as well as Rep Upton’s (R,MI) as Chairman of the House Energy and Commerce Committee) has not been on reauthorizing CFATS but on aggrandizing power to their respective committee. The HHSC bill (HR 901) would clearly provide CFATS oversight to HHSC, while HR 908 (the HECC bill) would continue to provide at least a portion of that oversight authority to the Energy and Commerce Committee.

The reason that neither bill has made it to the floor of the House is that the Republican leadership has not figured out which chairman it wants to piss off. If it never comes to the floor they won’t piss off either too much.

Secondly, the only hearing next week that could affect this discusson currently on the schedule for the House Homeland Security Committee is an appearance by Secretary Napolitano to answer questions about the FY 2013 budget (which apparently will be released, late as has become usual with the Obama Administration, on Monday). If CFATS comes up in that hearing at all it will be to have Ms Napolitano explain the de rigueur 1 year or 2 year extension of CFATS in the budget request. The answer will be short, sweet and essentially meaningless; explaining that the Administration expects Congress to enact a long term authorization bill, but just in case….

Besides, the Administration has made it clear in a number of hearings that they would prefer to see an expansion of the CFATS program to include water treatment facilities, some sort of IST provision and a number of slightly less contentious addendums that the current Republican Congress will never support.

The President would probably sign HR 901 (or HR 908, or S 473), but he would never actually come out in support of any them; it would anger too many already alienated members of his base. Besides it would be extremely impolitic for him to insert himself into the congressional committee power fight.

So Anonymous has me completely baffled as to why my criticism should wait until next week. Unless of course he/she knows about a hearing that is not currently on the public schedule; which is entirely possible.

It’s about Ignoring ISCD Problems


But, I wasn’t really upset about the reauthorization process in my earlier blog post (I’ve reconciled myself to the fact that until one side or the other controls both the House and has a Super Majority in the Senate, we will continue to see political posturing and routine approval of the CFATS program as part of the budget process. It could conceivably continue in this manner until someone blows up a chlorine tank somewhere; killing hundreds.

No what concerns me is that Chairman King has not made one public utterance about the problems at ISCD that I have seen. And that is not because he is reticent about sharing his opinions. He spends more time on conservative talk radio than Rush Limbaugh. It just appears that he has no interest in the CFATS program (beyond personal power over the program).

Now I understand that he is hampered by the fact that the Committee recently lost their CFATS expert (Dr. Diane Berry, whom I would love to hear from). And no one really expects a Congressman to understand the detailed workings of a program as small as the CFATS program. But for King to put getting to the bottom of the current ISCD fiasco behind getting a few soldiers a purple heart because they were targeted by some small minded coward is political grandstanding of the worst sort.

The security at the Olympic Games in London this summer is important, but it is the responsibility of the British government, not HHSC.

There are tens of thousands of people that live in the immediate danger zones of high-risk chemical facilities. The CFATS program is supposed to protect them against terrorist attacks on those facilities. Congress is supposed to ensure that their programs are implemented effectively and efficiently. The end stages of the CFATS implementation have been neither.

Representative King get your priorities in order.

Sunday, February 5, 2012

Update on ISCD Rumors

There is apparently a memo from Under Secretary Beers to people associated with NPPD announcing the resignation of Assistant Secretary Keil as of next Friday. The Acting Assistant Secretary position is going to Deputy Assistant Secretary for IP Bill Flynn according to sources that have seen the memo. There is no official word yet about the reason for the resignation and I wouldn’t expect there to be if Keil had been asked to resign over this issue..

At least one reader has noted that my observation/question about it being related to questions at Friday’s hearing about firings was certainly off base. I have been reminded that an organization like DHS cannot possibly make that kind of decision to force a resignation that fast, even if they wanted to. Too many political and legal questions that have to be resolved before something like that could be announced.

While the timing of the resignation does appear to be suspiciously related to the ISCD problems becoming public, there could be any number of reasons for the resignation. It is not unusual in the fourth year of an administration for any number of political appointees to start looking for new jobs in the public sector.

Saturday, February 4, 2012

ISCD Problem Hearing

I didn’t get a chance to watch the ISCD hearing before the Subcommittee on the Environment and the Economy either live or in real time yesterday which could have been a shame because the House Energy and Commerce Committee web site does not provide a link to the archived video (at least as of 5:30 a.m. EDT this morning). Fortunately the Minority Web site does carry a link to the video so I could see the whole disappointing mess.

We Still Don’t Know


First off, neither we the public (who are paying the bills) nor industry (who is bearing the brunt of the regulation) know much about the extent of the problems at ISCD. We do know (as I pointed out yesterday) about the poor performance of ISCD as it pertains to the completion of the reviews and authorizations of site security programs under CFATS. We don’t know why the delays have taken place and we only have vague assurances that the problems are being addressed.

Thanks to the Committee Staff memo I mentioned earlier this week, we have a listing of the five ‘programmatic challenges’ and four of the nine ‘personnel challenges’ identified in the internal ISCD report on the problem; a report that was produced within weeks of Director Anderson and Deputy Director Wulf being appointed to their positions in ISCD. Unfortunately there has been no explanation of why the Staff memo could not even list the five other personnel challenges.

To be fair there was some brief and usually vague discussion in the hearing about some of these issues. For example a number of Committee members jumped on wording in the report about inadequate controls for ordering and tracking supplies, particularly language that indicated that these lack of controls provided an environment that made fraud, waste and theft a possibility. Interestingly Under Secretary Beers made clear that an earlier NPPD report on ISCD had identified this issue and Anderson and Wulf were identifying that problem from that report. Again, we have been vaguely assured that the appropriate controls are now in place.

Poor Format for Investigation


The format for Congressional hearings is really not suited to a discovery or investigational process. Each member is allowed to make a five minute speech about their political view of the problems (including in this case two Committee Chairmen Emeritus and the Ranking Member of the Full Committee). Then there is a single round of questions limited to 5 minutes for the question and witness response from each Committee Member and hanger on.

Since most members spend much of their questioning making political speeches justifying the particular question there is little time for a real response from the witness. Yesterday, for example Rep. Capps (D,CA) stopped Beers’ response to two different questions before he could say anything so she could ask her next question. She didn’t get any information, just a couple of sound bites for local news stations back home; getting re-elected is more important than getting answers.

When Congress does conduct a real oversight hearing and asks the hard questions, the adversarial questions, it is because of investigational work by Committee Staff. It is apparent that that work was not done before yesterday’s hearing. Part of the reason is that the Staff did not get a copy of the ISCD internal report until just last week. That just doesn’t make sense; the existence of the report was made public back before Christmas. The Committee with oversight responsibility (and I still can’t believe that an environmental committee has the temerity to claim, or worse yet be allowed to claim, oversight of a purely security issue like CFATS) should have been publicly screaming for a copy of this report the day after it was identified in the Fox News story. Of course, neither Homeland Security Committee has publicly said much about the lack of information being provided to them either.

Just as obviously, the Staff had never heard about the five other reports that Beers referred to in his testimony. These were reports about NPPD reviews of the CFATS programs. It would certainly be interesting to know if those reports had even remotely identified any of the problems pointed out in the Anderson-Wulf report. It would seem to me that that would be an important oversight question to ask. If they didn’t was someone hiding actively hiding information from NPPD or were the reviews just ineffective exercises conducted by less than competent managers? If they did identify precursors to the problems then why were they allowed to get larger?

Politics


There were only three real issues that were discussed in any depth (and shallow is the operative word here); the lack of Congressional oversight and direction, the supply issue discussed above, and the ‘problem of the unionization of the chemical facility inspection force. Waxman (D,CA), Pallone (D,NJ) and Dingle (D,MI) all repeatedly made the point that the lack of comprehensive chemical security legislation like HR 2883 they ‘pushed’ through last session made it nearly impossible for ISCD to properly execute this mission in the first place. I think that is a slight exaggeration of the situation, but, as I have stated on many occasions, it has certainly contributed to the current situation.

Gardner (R, CO) and Harper (R,MS) asked a series of relatively pointed questions about the role of the CFSI unionization in causing some of the delays in the implementation of CFATS. What neither of them asked, however, was why the workforce asked for union representation in the first place. I’ve heard from a number of the inspectors that they reluctantly voted for the union because management ignored their concerns about pay and organizational issues. Congress needs to look at the unionization issue as a symptom of the problems not a cause.

NOTE: I was very surprised that neither Waxman, Dingle nor Pallone, all big time union supporters and beneficiaries of large union political donations, raised a single word of objection to the reports noting that the union was a potential part of the problem.

Oh there was one other issue that was discussed at some length, the use of TWIC as a substitute for a personnel surety program. While the report offers the currently planned (but not yet politically approved) personnel surety program as a positive step forward, both Chairman Shimkus (R,IL) and Ranking Member Green (D,TX) chastised Beers for the Department not more explicitly stating that personnel holding TWIC should not have to be screened by the personnel surety program. Beers reminded them that he didn’t own the TWIC program (it is sort of co-owned by TSA and the Coast Guard, both of which are in DHS; a fact evidently not known by the Ranking Member who kept referring to the Department of Transportation).

Disappointing Congressional Performance


All in all I was very disappointed in this hearing. I’ll take a closer look at some things that probably would have been addressed if the Committee really knew anything about the problems in DHS in future blogs.

Friday, February 3, 2012

Confirmed Rumor about ISCD Hearing

I just received an anonymous email reporting that there is a rumor circulating at DHS that Director Anderson will not be a witness at today’s hearing on the problems at ISCD, but will rather send her Deputy. A quick check of the House Energy and Commerce web site this morning shows that she has in fact been replaced on the witness list by David Wolf, the Deputy Director of ISCD. According to the Committee Staff Background Memo on that site, Wolf was a co-author of the ISCD report that triggered all of the recent attention on ISCD.

While Wolf may or may not be able to answer whatever questions maybe posed by Subcommittee members today, the fact that Anderson backed out at the last minute (and I have no idea of the reason why, she may be very ill for instance) will likely antagonize some members of Congress that are currently supportive of the CFATS process.

Even more Information on Tomorrow’s ISCD Hearing

Yesterday the House Energy and Commerce Committee took the unusual step of publishing the written testimony of the primary witness to tomorrow’s subcommittee hearing looking as the current situation in the implementation of CFATS. Typically the written testimony is provided to Committee members and staff the day before the hearing, but the testimony is not made public before the witness appears before the committee.

The Program to Date


Much of the ten page testimony by Rand Beers, Under Secretary for National Protection and Programs Directorate is the standard DHS rehash of the CFATS program; how it was started and the steps taken to get where it is at. It does provide some new numbers about the implementation. They include:
• 4,458 facilities currently covered under CFATS
• 180 preauthorization inspections have been completed
• 53 facilities have had their SSP authorized (less than ½ of Tier 1 facilities)

• 10 authorization inspections have been completed
• 0 facilities have had their SSP approved since May 2009
• 66 Administrative Orders have been issued
Very little is said in the statement about the personnel and procedural issues that have hampered the ICSD’s efforts to more effectively move forward with the SSP implementation process. Beers blames growth problems with a new agency for some of the issues and this must certainly be a contributing cause to the problems. He does use all of the current management buzz terms (“a Division mission statement, vision statement, and statement of core values”) as if establishing these window dressing tools can possibly change the culture of an organization.

The Real Questions


Here are some of the questions that I would like to see posed to Beers and Anderson (in no particular order):
• What has been the total turnover rate for all ISCD personnel since June 2008?
• What has been the turnover rate for Chemical Facility Security Inspectors (CFSI) since June 2008?
• How many people in ISCD have been with the program since June 2008?
• How long does the hiring process take from the time a job is posted on USAJobs.gov until the new employee reports to work?
• Has the site specific pay rate problem been resolved?
• Have the travel pay problems been resolved?
• How many of the 1600 facilities that have removed their COI have replaced them with nearly identical chemicals with miniscule improvements in safety/security (for example replacing 20% Aqua Ammonia with 19% Aqua Ammonia)?

• How many of the 700 facilities that have reduced their on-site inventory by increasing the number of shipments of the COI, thereby increasing the transportation security risk?
• How many of the CFSI (or ISCD staff personnel) are qualified to assesses blast protection information?
• How many of the CFSI (or ISCD staff personnel) are qualified to conduct control system security assessments?
• How many of the CFSI (or ISCD staff personnel) are qualified to assess processes for neutralizing released chemical?
• Has ISCD signed a memorandum of understanding with ICS-CERT to receive support in the evaluation of the security protections provided to critical control systems?
• Has any ISCD facility evaluation (of any sort) included contacting local emergency response personnel to see if their support for emergency response to a successful terrorist attack had been discussed with facility management?
• Has any ISCD facility evaluation (of any sort) included contacting local law enforcement personnel that would be the first armed responders on the scene have been briefed about which areas of the plant it is unsafe to discharge a firearm?
Given access to the internal report from ISCD I’m sure that I could come up with even more biting and pertinent questions to ask this panel. But, it still doesn’t appear that the Subcommittee will be asking any serious questions tomorrow. There is none of the political posturing and grandstanding preceding this hearing that would indicate that anyone seriously cares about these problems. I challenge Chairmen Shimkus (R,IL) and his Subcommittee to prove me wrong

Thursday, February 2, 2012

More Info on ISCD Hearing

The House Energy and Commerce web site now has some additional information available on their hearing about the problems at ISCD. The information includes a witness list and a Committee Staff memo on the situation.

Witness List


The witness list is predictable and yet disappointing if it is the complete list. As I predicted in my earlier blog Under Secretary Beers and Director Anderson will be the (first?) panel of witnesses. This may be predictable, but it is certainly necessary. These are the two individual with the responsibility for overseeing the operations of the Infrastructure Security Compliance Division of the Office of Infrastructure Protection. Additionally, Beers was the one to direct Anderson to conduct the project review that came to our attention via the FoxNews.com report in December.

I have received a number of personal (and mainly anonymous) contacts from personnel working in the Directorate over the last year or so. There has been a lot of dissatisfaction with the way the CFATS program has been administered. To be fair most of that pre-dates Anderson’s appointment as Director. In fact I have had at least one communication from a Chemical Facility Security Inspector that praises Director Anderson’s efforts to address the issues.

Still, I think that the voices of the work force in the Department also deserve a voice in these proceedings. As one former employee noted to me it would be difficult for Anderson to have a complete understanding of the problems of the program since she is so new to the office.

Staff Memo


I had really hoped to see a copy of Anderson’s report to Beers. Instead we have a memo from the Committee Staff outlining the current situation at ISCD. There are a couple of interesting points made in this memo. First and foremost (to my mind) is the fact that the Committee was given a copy of the memo on January 30, 2012, over a month after it was shown to Fox News reporter, Mike Levine, so much for Congressional oversight.

Another interesting point in the memo is their reporting about the ‘miss-tiering’ letter that was sent out last summer. The Staff Memo reports that problems in data entry and modeling resulted in “in improper tiering of 600 facilities”; a few more than the 400 letters I had heard about. More importantly, it seems that the problem was uncovered in 2010 and covered up until Anderson took over the Directorate.

The memo notes that the ISCD report is marked FOUO (for official use only) and is only being made available to members (and probably their staffs). It does summarize the main points (high level summary to be sure) of the report, noting that there are 5 ‘major programmatic’ challenges and 9 ‘staffing challenges’ out lined in the report.

The programmatic challenges include:

• Inadequate training capability;

• An overreliance on hired consultants for expertise;

• Inappropriate transitions for new hires;

• Uncertainty from extremely short program authorizations; and

• Issues regarding job descriptions and the presence of an employee union.

While it is a common belief in most management, inside and outside of government, the inclusion of ‘an employee union’ as a challenge will probably not endear Ms. Anderson to the current liberal administration. I do suspect that some members of this Subcommittee will jump on that ‘challenge’ in this week’s hearing.

The memo only lists four of the 9 personnel challenges;

• Inexperienced managers;

• Personnel placed in jobs for which they are not qualified:

• Inadequate internal staff control, and

• Lack of regulatory compliance expertise

I would be interesting to know what the other five personnel challenges were. Did one include Levine’s comments about carrying weapons?

Watch this space for continued coverage of these issues.
 
/* Use this with templates/template-twocol.html */