Showing posts with label Risk Assessment. Show all posts
Showing posts with label Risk Assessment. Show all posts

Friday, June 10, 2016

CFATS Update

I mentioned last week that I would have some more information on the latest CFATS update. I had a chance to talk to some folks from ISCD headquarters yesterday. I don’t have the details that I had hoped for (though we may see them in the July update), but I did pick-up some interesting tidbits of information about the CFATS program.

Expedited Approval Program


Back in December 2014 when Congress updated the Chemical Facility Anti-Terrorism Standards (CFATS) authorization they included a mandate for the DHS Infrastructure Security Compliance Division (ISCD) to establish an Expedited Approval Program to help ISCD reduce the backlog of site security plan (SSP) approvals. The idea was that the EAP would provide facilities with a specific blue print for a site security plan instead of having to negotiate a site security plan with ISCD. Congress thought that this would speed up the SSP approval process.

Well, it turns out that only one facility has used the EAP to get their SSP approved to date. It is almost exactly a year since facilities could start the EAP process and only one facility decided that it was a worthwhile program. So, did ISCD waste their time in publishing the EAP guidance document? If you look at it from the number of facilities that opted to formally use the program, probably. In a larger sense, probably not.

Long time readers of this blog will know about my concerns with the Risk Based Performance Standards (RPBS) guidance documents that facilities have had to rely on for standing up their SSPs since 2009. The drafters of that document bent over backwards to ensure that they could not be accused of ‘specifying security measures’ because ISCD was prohibited from that particular committing that particular sin by the old §550 program authorization language. For facility security managers that did not have professional security training (most of them), the document was little better than no guidance. It is little wonder that virtually no first time SSP submission was approved by ISCD.

With the publication of the EAP guidance, facility security managers without security training can get a good idea what type of security measures ISCD is looking for. Facilities still have the ability to tailor their security measures to their own unique environment, but they have a clearer measure of what those measures are expected to accomplish.

BTW: When ISCD rolls out their new risk assessment/tier assignment methodology this fall it looks like they are intending to update a number of program documents to properly reflect that methodology. One of those documents is likely to be the RSBP guidance document.

Enforcement


With ISCD now spending 80% of their inspection time on compliance inspection, it is almost inevitable that there will be facilities that are not in compliance. ISCD has a long history of working with facilities to get security properly in place, and that has continued over to compliance inspections. Unfortunately, it seems that there have been some (no one is currently talking about how many) facilities that ISCD may be (have begun) taking enforcement actions against to ensure that they meet their SSP obligations. Hopefully, they will never meet a facility that is so intransigent that the Secretary will be forced to close the facility, but that is still the ultimate enforcement authority available.

BTW: It looks like ISCD will be announcing at the upcoming Chemical Sector Security Summit (CSSS #10) that they have completely cleared the back-log of SSP approvals. Not all facilities will have approved SSPs then, but SSP processing will be proceeding in regular order with no unreasonable delays between SSP submission and authorization/approval inspections.

Risk Assessment Process


DHS has taken a lot of flak since the beginning of the CFATS program about the methodology they use for determining which facilities that submit Top Screens (more than 50,000 to date) are assessed to be at high-risk for terrorist attack (and thus inclusion in the CFATS program) and then used to determine the Tier Ranking for facilities in the program. DHS was not willing to discuss the details of that assessment process and were obviously missing some information necessary to do a “real” risk assessment.

ISCD will be rolling out this fall their updated and more rigorously justified risk assessment process. ISCD has had their processes vetted by an academic review process as well as a stakeholder review process. So there should be fewer complains (anyone that expects no complaints is using too many good drugs) about the new process. One of the reasons for this is that ISCD is planning on sharing more information (NOT details) about that process with the chemical community. They realize that companies need to be able to take that risk assessment process as they plan to construct new or modify existing chemical facilities so that the security costs associated with the project can be included in the facility planning process.

We have seen the first change associated with this new risk analysis process when ISCD held their Top Screen webinar last February. Since a number of questions were moved into the new Top Screen from the Security Vulnerability Assessment, the SVA is also going to have to be changed. I think that we will see the debut of that new SVA tool at the CSSS. Hopefully ISCD will include that debut in the sessions that they share on the web.

CFATS Rulemaking


ISCD is continuing to work on their notice of proposed rulemaking for updating the CFATS regulations. That process began with their advance notice of proposed rulemaking (ANPRM) published in August 2014. The Spring 2016 Unified Agenda projects that the NPRM will be published in September. No details are available on what changes are going to be proposed for the program beyond what was discussed in the ANPRM.

Closely associated with the CFATS program (but a separate regulatory scheme) is the congressionally mandated Ammonium Nitrate Security program (6 USC 488 thru 488i). ISCD issued their NPRM for the program in August of 2011, but has failed to be able to overcome the cost-benefit questions raised about that proposed rule. Congress has taken cognizance of the problem and DHS, Congress and the potentially regulated industries have been working on a solution to the problem. One monkey wrench thrown into the works has been the significant ISIS use of improvised explosives made with other chemicals. I half-way expect to see a new congressional mandate for precursor chemicals for improvised explosive devices; especially if we see a significant domestic IED that does not use ammonium nitrate.

BTW: If there is another Oklahoma City sized ammonium-nitrate truck bomb, the problems of the cost-benefit analysis will be instantly resolved and a regulation based upon the NPRM will probably be quickly forthcoming.

Missing Questions


I did not get a chance to ask all of the interesting questions that I wanted to, maybe in future conversations. But I would like to know if/when the folks at ISCD are going to remove their current ‘temporary’ exemption for agricultural production facilities from filing Top Screens. I still think this will be a ‘minor’ regulatory burden for almost all of the facilities involved because ISCD would be unlikely to determine that they are at high-risk of terrorist attack (for their chemicals anyway; food security is an Ag Department problem). This may be addressed with the roll out of the new Top Screen.

The other important topic that I did not get a chance to address was the progress being made in implementing the Personnel Surety Program. I think that it would be an interesting addition to the CFATS update if ISCD would include the total number of personnel that have been vetted against the terrorist screening database (TSDB). A number that we will probably never hear (for fairly legitimate reasons) is how many folks have turned up as a match against the TSDB during these checks. I personally expect that most of those positives will be false positives and that will cause problems for both ISCD, facility management and the folks improperly identified as having terrorist ties. I really hope that the number isn’t too large.


As always I appreciate the time that folks took to talk with me about the CFATS program. I have had my differences of opinion over the years with exact methodologies used by ISCD in their implementation of the CFATS program, but I have always admired how hard the folks have worked at making the process work especially how diligently they have tried to make the program a cooperative attempt to increase facility security rather than an adversarial program. Let’s hope that that can continue into the future.

Wednesday, February 10, 2016

ISCD Top Screen Webinar

Yesterday the DHS Infrastructure Security Compliance Division (ISCD) held a meeting and webinar to preview their new Top Screen tool that will be coming out later this year. The new Top Screen tool is part of the ISCD effort to upgrade the tools used by facilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program.

Top Screen Demonstration

The webinar included a very detailed review of how the revised tool will work. Attendees were taken step-by-step through the Top Screen preparation process with a variety of chemicals of interest to allow us to see how it will be used in actual practice. It would be very helpful if ISCD included links to a demonstration like this on their Top Screen web-page when the new version of the Top Screen goes live.

The new version streamlines the data entry by ensuring that the questions that the submitter sees are the ones most likely to require responses for that facility. This is tied directly to the list of DHS chemicals of interest (COI) that form the core of the Top Screen submission requirement. When a COI is selected the tool populates a navigation menu on the left side of the screen with that COI and the security issues (release, theft diversion, sabotage, economic) of concern for that particular COI.

Clicking on a security issue for a particular COI will take you directly to the basic questions that would have to be answered for that issue and COI. Additional questions may be added to the list depending on the answers provided to the basic questions. When all of the questions for a COI/security issue are answered that will be reflected in the navigation menu.

The new tool makes use of a visual rendering of the facility based on satellite photography keyed to the latitude and longitude provided during facility registration. This is used to provide ISCD with the location of the areas of the facility with the largest concentrations of each of the listed COI. The tool allows the placement of the 170-ft circle described in the current version of the Top Screen so that it encompasses the storage locations.

RMP*Comp

I noted in an earlier post that recent changes to the EPA’s RMP*Comp tool may have been part of the reason for the development of the new Top Screen tool. That does not seem to be a major driving force, but the folks at ISCD did address the issue of past and future changes in the RMP*Comp tool by removing the requirement for facilities to use the tool to calculate the distance of concern for release toxic COI. The Top Screen tool will collect all of the information needed to make the calculation and ISCD will calculate that distance internally.

This change should directly address the concerns noted in last year’s GAO report on the discrepancies noted in the distance of concern information submitted by some facilities.

New Risk Assessment Model

As I noted in last Sunday’s post about this webinar, ISCD has completed work on the congressionally mandated updating of its risk analysis process. The new Top Screen tool reflects those changes, even if DHS is not yet ready to talk publicly about the details of the new model. They did move some questions from the Security Vulnerability Assessment forward to the Top Screen to make it easier to determine if a facility is to be considered at high-risk of terrorist attack and thus be covered under the CFATS program.

Gasoline Coverage in Top Screen

Last Sunday I also noted that the International Liquid Terminal Association (ITLA) had petitioned for gasoline storage facilities to be specifically exempted from the Top Screen submission requirement. This has not been done, but there have been some changes to the Top Screen questions related to flammable release COI that might alleviate some of the concerns expressed in that petition.

There seems to be more emphasis on the NFPA flammability rating of blends containing flammable release COI. Gasoline was never specifically listed as a COI, but many of the components of gasoline (Butane, pentane, etc) are listed and are found in concentrations above the 1% minimum. We won’t be able to tell for sure if the new Top Screen adequately (from the ITLA perspective) deals with the issue until Top Screens are submitted by fuel storage facilities and the results of the ISCD’s resulting risk determination are forwarded to these facilities.

Agriculture Exemption

The other Top Screen related issue that I mentioned on Sunday was the current exemption from Top Screen filing provided to agricultural production facilities. That does not appear to have been addressed in the revised Top Screen tool previewed yesterday.

Crude Oil Coverage

An interesting question was raised during the public question phase of the webinar yesterday. It came after a couple of questions about the mixture rule as it pertained to fuels. Someone (I did not catch the name) mentioned that the same things that make gasoline fall under the Top Screen (butane and pentane were specifically mentioned) could also apply to crude oil. And this is absolutely true.

It raises an interesting question about whether or not crude oil storage facilities have been completing Top Screens for their inventories of flammable gasses contained in the crude oil mixture. Now most crude oil would have a lower NFPA fire rating so that the blends would not typically be considered high risk under most risk analysis procedures. The large rail shipping facilities in the Bakken fields are typically isolated enough from surrounding communities that they would not likely be considered high-risk of terrorist attack by ISCD.

Having said that, the high gas content of some of the Bakken crudes that makes them more hazardous in shipment could also likely raise the NFPA rating of the mixture to an extent that would make them higher risk. That combined with the location of these large rail shipping yards next to main intercontinental rail lines may raise their risk of being a terrorist target to a high enough level that ISCD would cover them under the CFATS program.

Another crude oil related area of potential concern is the increasing number of facilities that separate out the flammable gasses from crude oil as a precursor to their shipment by rail. The storage of these flammable gasses as part of their separation process should result in a significant number of facilities have to have submitted Top Screens. It would be interesting to see how many of them have.


It is unlikely that most of these storage facilities have submitted Top Screens. This is just one more area that ISCD should look to reaching out to so that at the very least the appropriate data could be collected in order to make a real risk determination. Because of the impending changes in the risk determination model, ISCD may want to hold off until the new Top Screen tool is in place before requiring these facilities to complete Top Screens.

Thursday, March 14, 2013

CFATS Risk Assessment


I had received an advance copy of the testimony of Timothy J. Scott, Chief CSO at Dow Chemical for today’s CFATS hearing and one thing that I was struck by was the concerns that he stated about the way that facilities were assigned to risk-based tiers. Then last night I read the testimony of Stephen L. Caldwell, from GAO, and the latest GAO report also addressed concerns about that process. The two looked at different aspects of the problem, the transparency of the process and the effectiveness of the process. Both are important considerations.

Transparency

Scott, who is also representing the American Chemistry Council in this hearing, notes that (pg 4):

In some cases, some ACC members have questioned their tier assignment either because it does not mesh with the onsite security assessment or it is inconsistent with other similar covered facilities managed by the same company. However, when engaging DHS on their tier assignment, the typical response is that it is ‘classified’.”

In my experience the ‘it’s classified’ response is frequently intended to mask the fact that the speaker just does not want to talk about the issue. For a tier assignment methodology to be truly ‘classified’ (you know National Security, Secret, Top Secret etc) the methodology would have to use active intelligence information about a specific threat to that facility or category of facilities.

Scott refers to this when he says: “However, other tiering factors such as local threat information are not shared with the facility.”

Scott goes on to make the point that no one has more of a ‘need to know’ about local threat information than the facility security manager who “has the ultimate responsibility for the safety and security of its operations, and he or she also has the authority to make informed risk mitigation and security investment decisions”. As I have mentioned before ISCD must establish a methodology for sharing threat information with facilities.

Risk Assessment

Now, having said all of that, according to the GAO report, maybe the ‘its classified’ really is ‘we don’t want to talk about it’. According to the GAO (pg 7):

• ISCD is inconsistent in how it assesses threat using the different models because while it considers threat for the 10 percent of facilities tiered because of the risk of release or sabotage, it does not consider threat for the approximately 90 percent of facilities that are tiered because of the risk of theft or diversion; and

• ISCD does not use current threat data for the 10 percent of facilities tiered because of the risk of release or sabotage.

Why isn’t ISCD using current threat data for at least the release and sabotage tiered facilities? The GAO investigation reveals that:

“ISCD officials said they do not use the information because it is “self-reported” by facilities [on the SVA submission] and they have observed that it tends to overstate or understate vulnerability”.

Which means, of course, that ISCD doesn’t have any specific threat information to share. It also means that the ‘it’s classified’ response is a pure smoke screen. The good news is that they don’t have to waste time setting up an intelligence sharing effort.

No Economic Risk

The current Security Vulnerability Assessment (SVA) tool in the CFATS program asks a limited number of questions about the economic importance of the facility. The reason is that one of the factors that should be considered in a risk assessment is the economic consequences of a successful terrorist attack on the facility. The destruction of a facility that would cripple the economy is certainly a high-risk facility even if only a limited number of people would be affected by the direct physical consequences of the attack.

Again, according to the GAO (pg 6):

“Our review of ISCD’s risk assessment approach and discussions with ISCD officials shows that the approach is currently limited to focusing on one component of consequences—human casualties associated with a terrorist attack involving a chemical of interest—and does not consider consequences associated with economic criticality.”

Why aren’t the economic consequences considered? It will require additional work; work that was just recently started. Sandia Labs has been commissioned to develop the information about “how ISCD could gather needed information and determine the risk associated with economic impact”. That information won’t be available until June of next year. Who knows how long it will take to convert the information to action.

Moving Forward

I’m sure that there will be some questions today about this risk evaluation process in the Environment and the Economy Subcommittee CFATS hearing. It would seem to me that this topic is important enough to require its own separate hearing. Companies are spending lots of money on security solutions for these high-risk chemical facilities. In most cases the amount of money is directly related to the tier rankings arrived at by the flawed risk assessment process currently in use by ISCD.

Monday, December 31, 2012

Reader Comment – 12-30-12 – Vulnerable Facilities


Dale Peterson, a long time reader and cybersecurity blogger/expert, left an interesting comment on yesterday’s post about industrial feedlot vulnerabilities. He noted that:

“A lot of control systems may not be critical infrastructure but have a big impact on an individual or business if compromised.
“A few years back we did an assessment at a prominent University. One of their big concerns was a multi-hour electrical outage or HVAC failure could wipe out numerous grad and doctoral students' research projects.”

Dale is absolutely correct; everyone that owns any kind of control system has something to lose if that control system is compromised, even if it is nothing more than the inconvenience of not being able to open your garage door. Of course, the same could be said about concerns about the general reliability of the system.

Risk Assessment


This is the reason that all control system owners, down to the garage-door opener owners, need to conduct a risk assessment for their systems. I think that a realistic risk appraisal by most ICS system owners would not show a high threat of terrorist attack. Critical infrastructure facilities would probably be an exception and some other facilities where a specific group would have an ax to grind with facility owner/operator (our feedlot example for instance). On the whole, however, most facility owners do not have to worry about terrorist cyber-attacks.

Two other types of outsider cyber-attacks should be considered in any reasonable risk assessment; electronic thieves and ruthless competitors. Electronic thieves may be after anything of value including ‘protection payments’ for not shutting down the control system. Ruthless competitors (and that includes some nation-states) could be after process information or be trying to compromise the integrity of the control system to put competitive production at a disadvantage.

There is one other form of outsider attacks that is probably going to become more prevalent now that the vulnerabilities of control systems and their internet accessibility are becoming better known; script kiddies. These are frequently adolescent (not necessarily age defined) individuals seeing what they can accomplish to make a name for themselves. As more ICS attack tools become generally available on the Internet, the number and exploits of these denizens of the dark side of the Internet will become more of a problem for control system owners.

The most common form of cyber-attack for most facilities is not an outsider. Most ‘attacks’ will come from within the firewall and may be deliberate attacks by employees or contractors with personal grudges or, probably more common, accidental ‘attacks’ where employees or contractors inadvertently do something that has some sort of disruptive effect on the system. The last category is probably the most common form of control system incident and needs to be better documented.

Control System Vulnerabilities


All of the control system vulnerabilities that are reported by folks like ICS-CERT, vendors (like the Siemens-CERT) and independent security researchers (white hats) make any of the above described attacks easier. As these vulnerabilities are discovered and mitigated (or mitigations are developed) it is the responsibility of the ICS owner to ensure that the mitigations and protective tools are applied to their systems.

Unfortunately, I would suspect that the vast number of control systems do not have systems engineers available to track vulnerabilities and implement protective mitigations. Large company systems probably have some level of protective services available, but most small company owners that employ the lower cost systems have no idea that the vulnerabilities exist, much less how to protect them.

The Solutions Are Not Easy


The ‘easy answer’ would be to require vendors to push vulnerability report and mitigation measures to the owners. There are a couple of problems with this. First, many systems are not sold directly by the vendor so they have no way to contact all of the owners. Systems where a direct push of new versions and updates to the ICS (and we have seen more reports of this type action lately on ICS-CERT advisories) is possible, the vendor runs the risk of disrupting the actual operation of the control system.

Finally, the long time over which an ICS is used ensures that there will be a turnover of knowledgeable employees on site and maybe even of the management team while the system still runs. There are some unknown number of systems where the current owners are just letting the system run, hoping that nothing breaks down that their routine maintenance can’t address.

The long term solution is to engineer industrial control systems with security part of the integral design. Even that won’t be a perfect solution. It just takes too long for control systems to die. That and the fact that even with security part of the design process, there will still be hole to find and exploit. Just look at how long Microsoft has been working at their security processes; they have their security updates down to just a couple of times per month…

Moving Forward


No, everyone in the ICS sector needs to be more aware of the security problems and there has to be better communications between everyone in the community. Vendors need to reach out to owners. Owners need to network to gain access to the necessary information. White Hats need to keep plugging away at problem identification. And people like me need to keep bugging the world about the problem.

Saturday, August 11, 2012

HR 6221 Introduced – Cybersecurity


Last month Rep. Clarke (D,NY) and Rep. Lungren (R,CA) introduced HR 6221, the Identifying Cybersecurity Risks to Critical Infrastructure Act of 2012. It’s interesting that Ms. Clarke, Ranking Member of the House Homeland Security Committee’s Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies and the Subcommittee Chair are the sponsors of this bill since he voted against similarly worded amendments that she has offered on each of the cybersecurity bills that were reported by the Subcommittee. The bill would add a new section to the Homeland Security Act of 2002 (6 USC 141): § 226 Identification of Sector Specific Cybersecurity Risks.

Identification of Cybersecurity Risks


The bill would require the Secretary of DHS to “research, identify, and evaluate cybersecurity risks to critical infrastructure” {§226(a)} on a continuous and sector-by-sector basis. The Secretary would coordinate with sector specific agencies, owners and operators and any “private sector entity engaged in ensuring the security or resilience of critical infrastructure” {§226(a)(3)}.

The Secretary would take into account the following factors when identifying cybersecurity risks {§226(b)}:

• The actual or assessed threat, including a consideration of adversary capabilities and intent, preparedness, target attractiveness, and deterrence capabilities.

• The extent and likelihood of death, injury, or serious adverse effects to human health and safety caused by a disruption, destruction, or unauthorized use of critical infrastructure.

• The threat to national security caused by the disruption, destruction, or unauthorized use of critical infrastructure.

• The harm to the economy that would result from the disruption, destruction, or unauthorized use of critical infrastructure.

• Other risk-based security factors that the Secretary determines appropriate to protect public health and safety, critical infrastructure, or national and economic security

Communication of Cybersecurity Risks


The Secretary would be required {§226(c)} to share information about the identified risks with owners and operators. If the risk information is classified the Secretary would be restricted to sharing it with owner operators that “possess the appropriate security clearances”.

As is expected in this type of bill the Secretary would also have to provide Congress with periodic reports on the identified “cybersecurity risks to critical infrastructure researched, identified, and evaluated” {§226(d)}.

Application of Requirements


The definition of ‘critical infrastructure’ that is central to this bill is taken from 42 USC 5195c(e):

“In this section, the term ‘‘critical infrastructure’’ means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”

This is a very expansive definition of critical infrastructure. The term ‘debilitating impact’ is the key part of that definition and it is not clear what it means. This gives the Secretary wide latitude in deciding what types of facilities to cover with the cybersecurity risk evaluations.

No Funding


The bill does not provide for the establishment a new office in DHS (presumably within NPPD) that would be responsible for the conduct of the necessary research, identification and evaluation of cybersecurity risks. More importantly it doesn’t provide for any new money for the Department to use in the execution of these requirements. In other words, everything necessary to accomplish the requirements of the bill will have to come out of existing Department operations.

Moving Forward


This is a fairly innocuous bill with no new requirements laid upon the private sector. Being introduced by the Ranking Member and the Chair of the Subcommittee with jurisdiction for cybersecurity matters it would normally be expected to have a the bipartisan support necessary for early consideration and passage. This late in the session in an election year, however, it is unlikely that this bill will wend its way through the approval process, especially since the Subcommittee did not hold any hearings on the bill before the summer recess.

Sunday, March 20, 2011

New PHMSA Bulk Transfer Rule – Security Issues

In a blog posting earlier this week I discussed some of the considerations that would need to be included in the hazard assessment to be required by the newly proposed PHMSA rules for bulk loading and unloading of hazardous materials to and from tank trucks. Readers of this blog might have been surprised that I didn’t discuss the review of a potential terrorist threat as one of the hazards that would need to be included in the proposed hazard assessment. The reason is simple; PHMSA specifically excludes security issues from consideration in their NPRM.

In the preamble to this proposed rule PHMSA states that: “Security and incidental storage of bulk transport tanks are beyond the scope of this rulemaking action.” (76 FR 13317) While I personally object to this exclusion as being short sighted, I understand the reason that PHMSA has taken this position. After all, Congress has given TSA responsibility for transportation related security issues (while not providing the resources necessary to enforce those requirements, but that’s another issue). Furthermore, since the described hazmat transfers, by definition, take place at facilities, the highest risk facilities are already supposed to consider security risks under the CFATS program.

Having said that; PHMSA does briefly address at least one security issue in their discussion of the types of things that the risk assessment should address. In the preamble where they discuss the conditions that might affect the safety of the transfer operation PHMSA lists the following items that should be addressed in the risk assessment: “access control [emphasis added], lighting, ignition sources, physical obstructions, and weather condition” (76 FR 13320). ‘Access control’ is certainly a security issue.

Access Control and Transfer Operations

While not specifically outlined in the NPRM, there are two different types of access control that will need to be addressed in the risk assessment and the subsequent operating procedures. The first deals with the access of the tank truck to the facility and the second deals with the access of the driver. While the two would seem to be intimately intertwined, they need to be considered separately.

The truck entering the facility for transfer operations needs to be confirmed to be the truck and trailer that were supposed to be sent to the facility for that particular transfer. First, since the carrier was supposed to ensure that a risk assessment was done on the trailer before it arrived at the facility to ensure that it is safe for the load that it is to carry, it is important to check that the arriving tank wagon is the one upon which that risk assessment was done.

This can only be done by having the carrier independently communicate to the facility the identity of the tank wagon destined for a particular load. The person who clears the vehicle to enter the facility needs to have a listing of vehicles that will be coming into the facility with appropriate identifying information. That information needs to be in the hands of the facility before the vehicle arrives.

Before the transfer operations begin the vehicle needs to be checked to ensure that there is no new damage to the vehicle that would negate the previously done risk assessment. High-risk chemical facilities will also check to ensure that there are no improvised explosive devices placed on the vehicle. While this is essentially a requirement for high-risk facilities, all facilities should do at least a cursory inspection for this type of risk.

Access control for the driver of the vehicle is as important as checking the identity of the vehicle. Particularly where a driver is part of the transfer operations, the facility needs to insure that the driver is one who is appropriately trained in those operations as required by this NPRM. This is most easily done by requiring that the carrier provide certification on their vehicle notification that the identified driver is trained in accordance with the provisions of §172.704(a)(2)(iii) outlined in this NPRM.

High-risk chemical facilities will have additional requirements under the personnel surety requirement of RBPS #12. For drivers transferring the hazmat loads described in this NPRM will be required to have a Hazmat endorsement on their CDL, which requires a background check conducted by the TSA. Verifying the driver’s identity against that document and against the listed driver on the vehicle notification document should satisfy the RBPS #12 requirements.

Carrier Transfer Operations

Where the carrier has sole responsibility for transfer operations at a facility, there is still a facility responsibility for controlling access to their property. In fact, since the facility is surrendering control of the safety of the transfer operation to the carrier, it is probably more important to put strong access controls in place to ensure that at least the right person and the right vehicle are involved in the process.

Wednesday, March 16, 2011

New PHMSA Bulk Transfer Rule - Risk Assessment

As I mentioned last Friday, PHMSA has finally (this was first addressed in January 2008 – 73 FR 916) published the NPRM for their bulk hazardous material loading and unloading regulations for cargo tank motor vehicles. One of the basic requirements for this new rule is that a risk assessment must be completed for all hazmat tank truck loading and unloading operations.

Who is Responsible

A new section, §177.831, is added to the Hazardous Materials Regulations (HMR) laying new requirements on each “person who loads, unloads, or provides transfer equipment to load or unload a hazardous material to or from a cargo tank motor vehicle”. This statement is clear, but its application in the real world might be a tad more difficult. HAZMAT loading operations are normally conducted by facility employees but the person who actually unloads a tank truck at the receiving location may be a facility employee, an employee of the supplier providing the material, or a truck driver working for a third party.

Generally speaking the hazmat employer responsible for the loading or unloading operations is responsible for conducting the risk assessment. There are confounding factors that may spread some of that responsibility around. Where the hazmat employee conducting the transfer operations is not a facility employee and the facility requires “unique operational procedures” there is a dual responsibility for the assessment. If a facility provides transfer equipment, a hose for example, for a transfer operation conducted by a separate hazmat employer, there is again a dual responsibility for the conduct of the risk assessment.

In fact, even where facility personnel are responsible for transfer operations, “the motor carrier must conduct a risk assessment and develop operating procedures that are specific to the cargo tank involved in the transfer operation” (76 FR 13319).

It seems that the only case where there is not some sort of dual responsibility for conducting the risk assessment is “where the motor carrier is primarily responsible for the safety of the transfer operation, such as at a business or residence”. The preamble explains that this is typically found at gasoline delivery to commercial gas stations or propane deliveries to homes.

Risk Assessment

Section 177.831(a) describes the newly required risk assessment as a “a systematic analysis to identify and evaluate the hazards associated with the specific loading or unloading operation”. It subsequently explains that the “analysis must be appropriate to the complexity of the process and the materials involved in the operation” {§177.831(a)(2)} and then lists three specific areas that should be addressed:

“(i) The characteristics and hazards of the material to be loaded or unloaded;

“(ii) Measures necessary to ensure safe handling of the material, such as temperature or pressure controls; and

“(iii) Conditions that could affect the safety of the loading or unloading operation, including access control, lighting, ignition sources, and physical obstructions.”
For those unloading operations that are entirely the responsibility of the carrier, PHMSA does not intend for this rule to require a location specific risk assessment to be required where large numbers of such locations would make that requirement impractical. They specifically state in the preamble to the NPRM that such carriers would not need to “conduct a separate risk assessment of each residence or retail outlet (i.e., gas station) to which it delivers propane or gasoline, but may instead assess the overall risk of such operations and develop operating procedures that apply generally to such operations” (76 FR 13320).

Equipment to be Assessed

The wording of the description of the equipment that is intended to be included in the safety assessment is very important. The new regulatory language states “including [emphasis added] any device in the loading and unloading system that is designed specifically to transfer product between the internal valve on the cargo tank and the first permanent valve on the supply or receiving equipment (e.g., pumps, piping, hoses, connections, etc.)” {§177.831(a). [NOTE: there is a missing closing parenthesis at the end of this description in the NPRM.]

It is important to remember that the word ‘including’ in this context means that the description that follows is not the only definition of the term; just a common example being used for illustrative purposes. This is an important distinction. Other equipment could also be part required assessment. For example, vent lines allowing for pressure equalization between the cargo tank and the storage tank, gas lines used to pressurize the cargo tank during unloading operations, and loading scales used to gauge the amount of material added to the cargo tank.

Even so, I think the example provided in the current language is overly restrictive. At one facility where I worked we had permanent unloading lines for all of the raw materials that we received into bulk storage tanks. One end of the stainless steel flex lines were attached to facility piping by a flanged connection. At the other end of the flex line was a manual valve. A strict interpretation of the exemplar provided in the would thus limit the area of concern for the assessment to the short section of on-truck piping between the internal valve and the manual valve on the end of the flex line.

Characteristics and Hazards

The term “characteristics and hazards of the material” is going to be very important to the implementation of this regulation. If PHMSA narrowly interprets this terminology to mean those ‘characteristics and hazards’ that are addressed in the HMR then the hazard assessment will be narrowly focused. The resulting assessments will be limited to looking at things like flammability, corrosivity and toxicity; all important characteristics and hazards to be sure.

PHMSA needs to expand the definition of this term to include reactivity and expand it beyond the narrow ‘no water’ definition of reactivity found in the HMR. Numerous unloading incidents occur every year when the wrong material is off-loaded into a storage tank. These reactions can range from the violently exothermic reactions of a strong acid and base; the reactions that explosively release gasses like bleach and aqua ammonia; to the slower but just as catastrophic polymerization reactions that produce enough heat over time to produce uncontrollable decomposition reactions.

These types of reactions are not covered in the HMR because they are a miniscule risk in transit. When these reactions happen in loading operations they are limited in scope because the incompatible material being loaded on-top-of is typically very small in volume relative to the material being loaded. If the catastrophic reaction does take place it seldom moves outside the front gate.

At fixed facilities where material is being added to a storage tank the possibility of sufficient quantity of the ‘other chemical’ being present is greatly increased. The problem is frequently compounded by the fact that the level in the ‘wrong tank’ has not been properly checked and the tank is overfilled. With hazardous chemicals where the storage tank is vented back to the tank wagon to avoid toxic releases that overfilling can force the reacting products back into the tank wagon, expanding the hazard area significantly.

Use of Assessment

The importance of this hazard assessment cannot be over stated. The results of this assessment will become the basis for the development of the operating procedures that will be used to ensure that these transfer operations are conducted in a safe manner. I’ll look at the requirements for those procedures in a future blog post.
 
/* Use this with templates/template-twocol.html */