Showing posts with label S 3416. Show all posts
Showing posts with label S 3416. Show all posts

Tuesday, April 7, 2020

S 3506 Introduced – CFATS Extension


Last month Sen Lankford (R,OK) introduced S 3506, the Chemical Facility Anti-Terrorism Standards Program Extension Act of 2020. This bill was intended to provide a short-term extension of the CFATS program through July 18th, 2020.

Moving Forward


While Lankford is a sub-committee chair in the Senate Homeland Security and Governmental Affairs Committee, the committee to which this bill was assigned for consideration, future consideration of this bill has been made problematic since another short-term extension was provided for the program in HR 748 (PL 116-136). That bill extended the program authorization through July 23rd, 2020.

Commentary


This bill was introduced three days after the House passed HR 6160, a longer-term extension of the CFATS program. That bill would extend the authorization for the program through April 18th, 2020. The shorter extension in S 3506 would have given the Republican leadership another chance to get S 3416 through Committee and onto the floor of the Senate. Unfortunately, I think the COVID-19 problems are going to effectively block any controversial bills from consideration in the Senate for the remainder of the session.

The only CFATS bill that appears to have any chance of making it to the President is HR 6160. This kicks the can to the 117th Congress. That Congress (which could be dominated by the Democrats in both the House and Senate) will be focused on re-building the economy after the pandemic has run its course. I expect that the CFATS program is going to run on short term extensions for a while.

There is still a possible monkey wrench that could disable the program. While CFATS generally has wide spread support in Congress, the President’s 2021 budget request proposed shutting down the program and moving the chemical security inspectors into protective security advisor slots. If Trump is serious about closing the CFATS program, then a veto of HR 6160 would certainly be an easy way to do that. I suspect that partisanship in the Senate would overcome CFATS support in preventing an override of that veto.

Rep Thompson (D,MS), Chair of the House Homeland Security Committee, is well aware of the President’s stated opposition to the CFATS program (any regulatory program for that matter) so we may see another short-term reauthorization in the inevitable next COVID-19 relief bill. That extension would probably carry through October 1st so that repeated CFATS extensions could go back into the DHS spending bill or continuing resolutions where they resided for so many years.

Wednesday, March 25, 2020

S 3416 – Emergency Response Information Sharing


This is part of a series of blog posts on the recently introduced S 3416, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020, which would modify and reauthorize the Chemical Facility Anti-Terrorism Standards (CFATS) program for five years. Other posts in this series include:


Information Sharing Strategy


The strategy that I discussed in yesterday’s post is also intended to address “the sharing of information with the local emergency manager, the local emergency response provider, and any on site emergency response provider for a covered chemical facility” {§6(a)}. That strategy would include “guidance on further improving outreach to the local emergency manager, the local emergency response provider, and any on site emergency response provider for a covered chemical facility” {§6(b)(3)}. That guidance would include requirements for:

• A statement of the name or title, organizational affiliation, and phone number of a local emergency manager or local emergency response provider, and any on site emergency response provider, for the covered chemical facility;
• The documented policy of the covered chemical facility to coordinate access to the facility with the local emergency manager, local emergency response provider, and any on site emergency response provider described in sub-paragraph (A), for purposes of training and pre-incident planning; and
• Written documentation by the covered chemical facility that the owner or operator has provided the local emergency manager or local emergency response provider with need to know (within the meaning of 6 CFR 27.400(e), or any successor thereto) and appropriate chemical-terrorism vulnerability information credentials the name and amount of each chemical of interest held, stored, or manufactured at the covered chemical facility.

Information Sharing Requirements


Section 15(a) amends 6 USC 622(e) by adding a paragraph (6), Sharing Information with Emergency Response Providers. This new paragraph would require DHS to “make available to State, local, and regional fusion centers and State and local government officials, including officials of State or local law enforcement agencies and emergency response providers” {new §622(e)(6)(B)} information that DHS determines is necessary “to ensure that emergency response providers are capable to effectively prepare for, respond to, and mitigate chemical security incidents at covered chemical facilities”. That information will include:

• The name of the covered chemical facility;
• The address of the covered chemical facility;
• The phone number of the covered chemical facility;.
• The name and Chemical Abstract Service number of each chemical of interest used, stored, or manufactured as specified in the Top-Screen submitted by the covered chemical facility;
• The quantity and concentration of each chemical of interest specified in the Top-Screen submitted by the covered chemical facility; and
• The name or title, organizational affiliation, and phone number of a local emergency manager or local emergency response provider for the covered chemical facility specified in the site security plan of the covered chemical facility.

The bill would require to DHS to use an existing “single information technology infrastructure, information technology platform, online platform, or website” {new §622(e)(C)(i)} for this required information sharing. Presumably this means the Infrastructure Protection Gateway that ISCD established in 2015.

DHS would be required to update this information every 90-days.

Emergency Responder Outreach


The new §622(e)(6) above would also require the Infrastructure Security Compliance Division (ISC) to conduct an outreach to local officials during compliance inspections or audits. Inspectors would be required to {new §622(e)(6)(E)}:

• Contact and notify the local emergency manager or local emergency response provider, and any on-site emergency response provider, identified by the covered chemical facility that there is a covered chemical facility in their response area; and
• Inform the response officials identified by the covered chemical facility of the available secure communications and information technology infrastructure platforms or other mechanisms to obtain additional information.

Commentary


I have two major concerns about the emergency response language in this bill; the lack of definition of key terms and the ‘need to know’ language used.

There are three new terms used in this bill about emergency responders that are unique to the bill and require definitions:

• Local emergency manager;
• Local emergency response provider; and
• On-site emergency response provider.

First-off, I think that the third term ‘on-site emergency response provider’ should be eliminated. If the facility management has not provided an on-site responder with necessary information about all of the chemicals on the site (not just those covered by the CFATS program), the facility has problems that need to be addressed by OSHA, not DHS.

Next, instead of the term ‘local emergency manager’ I would suggest that the terminology that should be used is “the head of the Local Emergency Planning Committee established under 42 USC 11001. Then, instead of ‘local emergency response provider’ the bill should use ‘the head of the fire department that provides coverage for the facility’. Actually, the second term is operationally redundant for most facilities as local fire departments are supposed to be represented on the local LEPC. But that is only true for ‘most’ facilities since there are a number of areas that have no LEPC or the LEPC is not really active.

The bill uses the phrase “with a need to know (within the meaning of section 27.400(e) of title 6, Code of Federal Regulations” to modify the term ‘emergency responders’ wherever there is a requirement to share information with those responders. Now, I understand the need to protect Chemical-terrorism Vulnerability Information (CVI) which is what §27.400 refers to, and ‘need-to-know’ is a key part of that protection.

The CVI information that DHS is required to share under the proposed §622(e)(6) is limited to:

• The name and Chemical Abstract Service number of each chemical of interest used, stored, or manufactured as specified in the Top-Screen submitted by the covered chemical facility; and
• The quantity and concentration of each chemical of interest specified in the Top-Screen submitted by the covered chemical facility

Both of these items of information should be available to the listed agencies via the Environmental Protection Agency. With that in mind, I would like to propose striking the phrase “with a need to know (within the meaning of section 27.400(e) of title 6, Code of Federal Regulations” wherever is used in §622(e)(6) and adding the following at the end of the paragraph:

(f) The information provided in (b) is presumed to be Chemical-Terrorism Vulnerability Information in accordance with 6 CFR 27.400. The individuals listed in (b) with whom that information is to be shared are deemed to have ‘need-to-know’ under §27.400(e)(i).

One final niggly bit; the inclusion of the requirements for the outreach to local emergency responders in §6 of the bill is more than a little confusing since the other part of that section deals with cybersecurity. The emergency response information share provision of § should have been included as part of §15 that proposes the addition of §622(e)(6) probably as part of §15(b).

Monday, March 23, 2020

S 3416 Introduced – CFATS Reauthorization and Cybersecurity


Earlier this month Sen. Johnson (R,WI) introduced S 3416, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020. The bill would modify and reauthorized the Chemical Facility Anti-Terrorism Standards (CFATS) program for five-years. While there are some similarities to S 3405 that Johnson introduced in the 115th Congress, it would not be fair to state that this is a re-write of that bill.

This is a complex bill that covers a wide variety of different topic related to the CFATS program. Those topics include:

• Employee input regarding security measures.
• Strategy to improve cybersecurity and outreach to local emergency responders.
• Site security plan assessments.
• Expedited approval program.
• CFATS recognition program.
• Standards for auditors and inspectors.
• Personnel surety program.
• Security risk assessment approach and corresponding tiering methodology.
• Amendments relating to Appendix A of part 27 of title 6, USC
• Bidirectional information sharing platform.
• CFATS security harmonization waiver program.

Cybersecurity


Rather than eliminate CFATS coverage of cybersecurity issues as was initially proposed in S 3405, §6 of the bill would require DHS to periodically (initially 1 year and then every 2 years) to publish “a strategy that includes the strategic and operational goals and priorities of the Department of Homeland Security for covered chemical facilities to improve the cybersecurity of covered chemical facilities” {§6(a)}. That strategy would include an assessment of cybersecurity threats to {§6(b)(1)}:

The information technology or operational technology affecting the security risk of a chemical of interest of the covered chemical facility;
Processes and operations relating to a chemical of interest (COI); and
Security measures of the covered chemical facility relating to a COI;

The strategy would also include “processes for periodic mitigation of (the) security vulnerabilities” {§6(b)(2)} affecting those areas listed above.

Additionally, §3 of the bill would amend the stated purpose of the CFATS program in 6 USC 622 to specifically include cybersecurity. Paragraph (a)(2)(C) would be amended to read:

(C) establish risk-based performance standards designed to eliminate or mitigate physical, cybersecurity, and hybrid physical-cybersecurity vulnerabilities in order to address high levels of
security risk at covered chemical facilities; and

Cybersecurity Definitions


Section 2 of the bill would add two new cybersecurity related definitions to 6 USC 621; ‘hybrid physical-cybersecurity vulnerability’ and ‘security vulnerability assessment’.

The term ‘hybrid physical-cybersecurity vulnerability’ is defined as “a vulnerability in the security of a covered chemical facility that relates to the combination of the physical operations and cybersecurity operations of the covered chemical facility” {new §621(10)(A)}. It would also include a vulnerability of a covered chemical facility to {new §621(10)(B)}:

A physical threat to a cybersecurity operation affecting the chemical of interest of the covered chemical facility; or
A cybersecurity threat to a physical operation of the covered chemical facility.

The second term, ‘security vulnerability assessment’, is defined as an assessment of the vulnerabilities of a covered chemical facility to physical threats and cybersecurity threats to the information technology or operational technology of the covered chemical facility as those technologies relate to {new §621(12)(ii)}:

A chemical of interest;
An operation involving a chemical of interest; or
A security measure of the covered chemical facility;

Moving Forward


Johnson is the Chair of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. Typically, this would ensure that this bill would receive coverage by that Committee. The bill was initially listed as being included in the Business Meeting that occurred right after the bill was introduced, but it was removed from the agenda shortly thereafter. I discussed this in some detail in my earlier post about that hearing.

I will be very surprised if this bill does get considered in Committee. While it looks like Johnson has made several attempts to address the concerns of Democrats in this bill (more on those is subsequent posts), there are still changes that the opposition party would like to see made in this bill. If the bill is brought up, I would expect to see substitute language offered by Johnson to address at least some of those concerns.

As I mentioned earlier, the only way that this bill is going to make it to the floor of the Senate, is for it to be considered under the Senate’s unanimous consent process. A single Senator can stop that process by objecting and those objections need not have anything to do with the provisions of the bill. This has been a contentious session of Congress and the COVID-19 epidemic is not making it any less so.

The introduction of S 3506 (the language for which is still not available) by Sen. Lankford (R,OK), a Subcommittee Chair on the HGSA is, it seems to me, a clear recognition that S 3416 will not move forward.

Commentary


While I do not think that this bill will move forward, I will still be making additional posts about the provisions of this bill as it is an interesting look at the changes in Johnson’s outlook on the CFATS program.

The cybersecurity provisions are an important case in point. First off, Johnson has made a complete turnaround on his support for cybersecurity coverage in the Program from last session. Where he was prepared to eliminate cybersecurity coverage, he is now making it a key point in the purpose and scope of the program. Nothing in this bill will directly require a change in the current cybersecurity processes in the CFATS program or individual site security plans, but it does specifically require DHS to take a hard look at those processes and security measures and periodically re-address them in the future.

Second, Johnson’s emphasis on cybersecurity in this CFATS reauthorization bill (and in fact, the actual publication of the bill at all) is a direct slap at the President’s attempt to deauthorize the CFATS program and use its inspectors as additional Protective Security Advisors. If there were any thought that Congress was going to go along with this eradication of the CFATS program, this bill is certainly a clear sign that it is not going to happen without a fight.

The one odd thing about the ‘new’ cybersecurity review requirements under §6 is the conspicuous absence of the Cybersecurity and Infrastructure Security Agency (CISA). While the program is currently included under the ‘infrastructure security’ wing of the Agency, the bill keeps referring to the ‘Secretary’ as being the responsible party for effecting changes in the program. I thought that the whole purpose of elevating the old NPPD to Agency status was to raise the status and level of responsibility for the newly crowned Director.

I am particularly happy to see Johnson acknowledge that there are three components to cybersecurity at chemical facilities, IT security, OT security and Security security, the cybersecurity of facility security controls. While there are certainly those in the control system security field that will object to the use of ‘operations technology’ to describe the full gamut of the control system security realm, it is important to note that Johnson (not a techy) is apparently using the undefined term in the broadest sense. And I like the way that he spells out the dual importance of physical security of cybersecurity controls and the cybersecurity of physical security controls.

There is a lot of interesting stuff in this bill, and it is a shame that the effort currently appears to have been wasted.

Friday, March 13, 2020

HSGA Markup Hearing – No CFATS Bill – 3-11-20


Earlier this week the Senate Homeland Security and Governmental Affairs Committee held a business meeting to markup 14 pieces of legislation. S 3416, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020, was not considered. Two other bills of interest here (S 3045, Cybersecurity Vulnerability Identification and Notification Act of 2019; and S 3207, Cybersecurity State Coordinator Act of 2020) were amended and adopted by the Committee. I will discuss those revisions in separate posts.

Where was S 3416?


S 3416 was removed from the agenda early this week, shortly after the introduction of HR 6160, the House CFATS extension bill. That bill, if passed (and it will almost certainly be passed next month), would take pressure of the Committee to address the CFATS program in a more complicated fashion. That is one of the contributing factors to S 3416 not being considered on Wednesday.

The other consideration is almost certainly the inability of the Committee to come up with some sort of consensus language for S 3416. Chairman Johnson (R,WI) knows that for a bill to make it to the floor of the Senate under the unanimous consent process (the only way a stand-alone CFATS bill is going to be considered in the Senate) is with the active support of Ranking Member Peters (D,MI) and, probably more importantly, the support of Sen. Carper (D,DE) who effectively killed Johnson’s last attempt at CFATS legislation, S 3405, in the 115th Congress.

Commentary


Johnson has never been a strong supporter of the Chemical Facility Anti-Terrorism Standards (CFATS) program, basically because he does not like regulatory programs. He has voted for CFATS bills in the past because the program allows for regulatory standards to be negotiated at the facility level, so it is not a one-rule-fits-all style regulation. The fact that industry is generally supportive of the program also provides Johnson with some political cover.

With the President’s budget proposal to eliminate the CFATS program in FY 2021, Johnson was put in a tough position of trying to decide who to support, the President or industry. HR 6160 looks like his easy out, kicking the can down the road for 18 months. One thing Johnson should consider, however, is that 18 months puts the problem before the 117th Congress.

With the potential for COVID-19 tanking the economy between now and November, Johnson should not assume that he will chair the HSGA Committee next session. There is now a definite possibility that the Democrats will control the Hill and the White House next year, possibly (depending on how bad things get) with strong, veto-proof majorities. This could be Johnson’s last chance to have a major say in how the CFATS program proceeds.

Monday, March 9, 2020

Committee Hearings – Week of 3-8-20


This week with both the House and Senate in Washington before a week back in their districts the big news in congressional hearings continues to be COVID-19 as well as more budget hearings. There is also a markup hearing in the Senate that will look at a CFATS reauthorization bill and the CISA subpoena bill.

Budget Hearings


Agency
House
DOD
3-10-20 Budget
Coast Guard
3-10-20 A-DHS
CG/TSA
3-11-20 HS-S
CISA/S&T
3-11-20 HS-S
ARPA-E
3-11-20 A-EWR

Budget – Budget Committee
A-DHS – Appropriations – DHS Subcommittee
HS-S – Homeland Security Subcommittee
A-EWR – Appropriations – EWR Subcommittee

The Senate will also be holding budget hearings, but the ones that are scheduled are not agencies that I closely follow in this blog.

Senate Markups


On Wednesday the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting that will include marking up 15 bills. Those will include:

S 3045, Cybersecurity Vulnerability Identification and Notification Act of 2019;
• S 3416, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020; and
S 3207, Cybersecurity State Coordinator Act of 2020;

The CFATS bill is still not available for review. Hopefully, I will see it before Wednesday.

On the Floor


As I noted yesterday the Senate will resume consideration of S 2657, the comprehensive energy bill. There is a vote on SA 1407, the substitute language, at 5:00 pm EDT. Further amendments will likely be considered tomorrow and Wednesday. We should see a final vote this week.

Friday, March 6, 2020

Bills Introduced – 3-5-20


Yesterday with the House and Senate preparing to head home for the weekend there were 67 bills introduced. Three of those bills may receive additional coverage in this blog:

HR 6096 To improve oversight by the Federal Communications Commission of the wireless and broadcast emergency alert systems. Rep. McNerney, Jerry [D-CA-9]

HR 6113 To establish an Advanced Research Projects Agency-Water, and for other purposes. Rep. Katko, John [R-NY-24]

S 3416 A bill to reauthorize the Chemical Facility Anti-Terrorism Standards Program of the Department of Homeland Security. Sen. Johnson, Ron [R-WI]

I will be watching both House bills for cybersecurity language and definitions; not holding my breath.

Looking forward to seeing what Johnson has come up with this session for the CFATS program. Nothing on his web site about this bill, but that is not too unusual. Earlier this week, Johnson did make a comment about CFATS program in a hearing on the DHS 2021 Budget proposal:

“Additionally, CISA provides security assessments and advisory services to the sixteen critical infrastructure sectors of our economy. For all but one sector in which CISA has oversight, CISA employs a common approach by using voluntary Protective Security Advisors. In 2006, Congress authorized a specific regulatory program for the Chemical sector — the Chemical Facility Anti-Terrorism Standards program (CFATS). CFATS is set to expire in the coming weeks, and the administration proposes to transfer CFATS Chemical Security Inspectors into the same voluntary system used for the other critical infrastructure sectors. I support this common sense approach, but am willing to work with industry, the administration, and congressional colleagues on a path forward we can hopefully all agree on.”

This bill is currently scheduled to be considered in the Senate Homeland Security and Governmental Affairs Committee next week.

 
/* Use this with templates/template-twocol.html */