Showing posts with label Whistleblower Protection. Show all posts
Showing posts with label Whistleblower Protection. Show all posts

Thursday, June 20, 2019

HR 3256 Amended and Adopted in Homeland Security Committee

Yesterday the House Homeland Security Committee amended and subsequently adopted HR 3256, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2019. The alternate language was adopted by a voice vote (pretty much along party lines by the sound of it) and the final action was taken by a recorded vote of 14 to 12; strictly along party lines.

The Republican opposition to the bill was voiced by Ranking Member Rogers (R,AL) and addressed predictable issues. One notable portion of that opposition narrative was voiced at 17:25 into the video when Rogers stated: “The bill enlarges the whistleblower protection program in an agency that does not have the capacity or skills to administer such a program.” Comment: This is perhaps why the Democrats felt that changes in the current whistleblower provisions were needed.

All three statements on the bill {Chairman Thompson (D,MS), Rogers, and Subcommittee Chair (and author of the bill) Richmond (D,LA)} all emphasized how important reauthorization of the CFATS program was and how hard everyone was working together to get this done. They all agreed that additional work needs to be done to bill to get it to the point where there can be strong bipartisan support for the bill when it gets to the floor of the House.

The next venue for consideration of the bill will be the House Energy and Commerce Committee. Further amendments of the bill are sure to be seen there.

Watching this hearing it was clear that it was a closely scripted proceeding with every remark read from the script to ensure that nothing was said that was out of line. Even so, there was some minor drama when it came to the final vote on the adoption of the bill due to the number of Democrats that were not able to make it to the hearing. This made the vote much closer than it would have been.

Tuesday, March 12, 2019

CFATS Subcommittee Hearing – 03-12-19


Today the Cybersecurity, Infrastructure Protection, and Innovation Subcommittee of the House Homeland Security Committee held a hearing on “Securing Our Nation's Chemical Facilities: Stakeholders Perspectives on Improving the CFATS Program” (video here). The Subcommittee heard from a panel of labor and safety advocates as well as a representative of the American Chemistry Council (ACC).

Witnesses


Today’s witnesses included (link to prepared testimony):

Mr. John Morawetz, International Chemical Workers Union Council;
Dr. Mike Wilson, Ph.D, MPH, BlueGreen Alliance;
Pamela Nixon, People Concerned About Chemical Safety; and
Kirsten Meskill, BASF

As I mentioned in an earlier blog post, there was a fifth witness originally scheduled to be on the panel. There was no indication today why Randy E. Manner, Manner Analytics, was not present at the hearing.

Expected Coverage


As expected, based upon previous hearings and the change in leadership in the House, much of the questioning today addressed four topics:

• Voluntary ‘best practices’;
• Information sharing;
• Employee involvement; and
• Whistleblower protections

The ‘new’ term ‘best practices’ has apparently replaced the more controversial ‘inherently safer technology (IST)’ that was used extensively in the chemical safety and security discussions in the earlier Democratic lead House. All of the questioners and panel members (even to an extent Meskill) generally agreed that the sharing of ‘best practices’ related to actions that facility could take to reduce their chemical risk was a good idea. There were no concrete ideas (or even suggestions) how those ‘best practices’ could be implemented at other facilities. There was a general agreement that DHS Infrastructure Security Compliance Division (never named in the hearing) should share what information that it did have.

The ‘information sharing’ bit was mainly about how and what CFATS facilities should share with local first responders, emergency planners and local communities to help respond to the release of chemicals or chemical incidents resulting from terrorist attacks, weather emergencies or accidents. Again, there was a general agreement that that information sharing was important and should be expanded. Ranking Member Katko (R,NY) made the point that other regulatory programs had more expansive information sharing requirements where concerns should more probably be addressed. Katko made a vague point about the CVI requirements for first responders.

Employee involvement in safety and security planning has long been a priority for Democrats. The point was made many times by Committee members and panelists that line employees would have valuable insights that should be included in identifying security vulnerabilities and planning for site security plans. Meskill made the point that they included employees at all stages of the security (and safety) planning and implementation process but agreed that she could not speak for all CFATS facilities.

The Democrats again have long had concerns about the whistleblowing protections provided to employees. Member concerns about protecting employees from retaliation due to their reporting security (and safety) problems at facilities. Interesting, none of the panel members could provide any information on the problem when questioned. Katko pointed out (in the only second round of questioning in the hearing) that the CFATS Tip Line provided a way that employees could anonymously report problems at covered facilities (including the lack of initial notification to ISCD).

Cybersecurity


The one new (and unexpected to me) topic that came up a number of different times was cybersecurity. Langevin (D,RI), Rice (D,NY) and Jackson-Lee (D,TX) all had questions about cybersecurity issues. Langevin questioned cybersecurity training (particularly in control rooms); Rice asked about cybersecurity standards in CFATS and Jackson-Lee announced that she would be introducing the Frank Lautenberg Chemical Facility Cybersecurity. No detailed responses were available from any of the panel members.

Commentary


In an earlier set of blog posts I identified those items that I though should be addressed in any legislation reauthorizing the CFATS program. Two of those posts are appropriate (in my opinion) responses to some of the questions raised today. Those include:

Best practices (IST); and

There are a couple of things that still need to be addressed here. First is Katko’s comments about the applicability of Chemical-Terrorism Vulnerability Information (CVI) requirements to first responders. ISCD has long maintained that first responders entering a facility in response to an actual emergency situation are not required to be CVI qualified; actual emergency response does not rely on access to CVI controlled information. Emergency planning is something else entirely. There are requirements (§7.02) outlined in the CVI Guidance manual for providing access to CVI information to State and local officials, including emergency response planners. That guidance ends by explaining:

“State, local, and tribal officials, including first responders, must have access to any information that is necessary to plan for and respond to an emergency event at a chemical facility [emphasis added]. It is equally important that this information is available in a form that is readily accessible and easily disseminated. Accordingly, to the extent possible, facilities should provide information to State, local and tribal entities in non-CVI form. In many cases, a facility can provide a product that contains all of the necessary operational and facility-specific information and excludes CVI.”

Katko also made a point that should be remembered by everyone involved in the CFATS reauthorization process; the CFATS regulations are not the only federal rules that require chemical companies to coordinate emergency response planning information with local authorities. Facilities could easily find the necessary information for emergency response planners in their already required information provided to local fire departments and Local Emergency Planning Committees (LEPCs).

There are some exceptions to the EPA reporting requirements that apply to CFATS facilities. Most chemicals on the DHS list of chemicals of interest (COI) that triggers CFATS reporting requirements that are not on the EPA’s Risk Management Program list of covered chemicals are covered by CFATS because they can be used for preparing improvised explosives or improvised chemical weapons. While these chemicals are not generally as much of an off-site hazard as the RMP covered chemicals, the emergency response planning is more of a law enforcement issue than fire department response planning. This would make for some interesting information sharing requirements that are not specifically outlined in any existing regulations.

The other interesting thing that came out of this hearing was the new Committee interest in cybersecurity issues. Richmond’s Subcommittee should probably hold another hearing (maybe two) specifically about cybersecurity issues. This is going to be a complex set of issues and a wide variety of experts and stakeholders are going to have to be involved in the efforts to address it.

One thing that the Committee crafters are going to have to deal with in writing cybersecurity requirements is that the CFATS program is a risk-based program that prohibits DHS from requiring specific security measures. This is due to the recognition that each of the very wide variety of covered facilities (from a number of different chemical and non-chemical manufacturing facilities) require differing security measures to protect against terrorist attacks. This remains true for the varying information and control system technologies that will be found in these facilities.

Tuesday, December 16, 2014

HR 4007 – Implementation Deadlines

This is part of a continuing discussion of the recently passed HR 4007, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014. In this post I will be looking at the various implementation deadlines set by Congress. The previous postings in this series was:


Congress has been fairly vocal about the delays in getting site security plans approved, so it is not unexpected that there were a number of very specific implementation deadlines put into this legislation. Some of them are very tight deadlines that don’t take into consideration review requirements outside of DHS.

CFATS Repeal

The bill is very clear that, in general, the current CFATS regulations will continue in force with some changes. Section 2107(b)(1) states that “each existing CFATS regulation shall remain in
effect unless the Secretary amends, consolidates, or repeals the regulation”. And it is important to note that the term ‘existing CFATS regulation’ is specifically defined {§2101(5)} to include any guidance documents published in the Federal Register. This would include the Risk Based Performance Standards guidance document and the Clarification to Chemical Facility Anti-Terrorism Standards; Propane and presumably the current Agricultural Facilities Time Extension Notification.

Having given with the one hand, however, Congress required the Secretary of DHS to take away with another. In §2107(b) the bill would require that:

“Not later than 30 days after the date of enactment of the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014, the Secretary shall repeal any existing CFATS regulation that the Secretary determines is duplicative of, or conflicts with, this title.”

Now I have not had the time to go through the current regulations and see what if any of the current provisions of 6 CFR Part 27 may be “duplicative of, or conflicts with, this title”. Even though the bill has not yet been signed into law, I’m sure that the Secretary has at least a couple of lawyers looking at this requirement.

Unfortunately, even with the best of intentions and unlimited lawyer power, I am afraid that the Secretary is going to have a hard time meeting this deadline. Forgetting for the moment the amount of time lost to holidays and the resultant short staffing in any agency at this time of year, even if the Secretary meets the 30 day deadline to produce such a regulation change, it will probably take another 30 to 60 days for it to be processed through OMB.

Also, I’m not sure that this requirement is specific enough to allow the Secretary to avoid the publish and public comment process required by 5 USC 553.


Facility Outreach Program

Section 2109 give DHS just 90 days to establish an outreach program to help identify potential chemical facilities of interest (think back to the West Fertilizer incident) and to make “make available compliance assistance materials and information on education and training” {§2109(2)}. Since the Department has done a great deal of work on this topic since the publication of Executive Order 13650 (see requirement here) this requirement should be fairly simple to complete.

Expedited Approval Facilities

As I mentioned in my last post the Secretary is required to come up with a program to help Tier 3 and Tier 4 facilities expedite the site security plan approval process. This is essentially a program where the facility can self-certify that their plan meets the minimum risk based performance standards associated with a facility at their level of risk.

There are actually two prongs to this program, both of which DHS is required to have up and running within 180 days of the bill being signed. Both are set forth in §2102(c)(4). First it requires that the “Secretary shall issue guidance for expedited approval facilities that identifies specific security measures that are sufficient to meet the risk-based performance standards”{§2102(c)(4)(B)(i)}.

Then it allows the Secretary to “develop prescriptive site security plan templates with specific security measures to meet the risk-based performance standards under subsection (a)(2)(C) for adoption and certification” {§2102(c)(4)(H)(i)}.

To aid in DHS being able to meet this deadline Congress has allowed that the Department should not be subject to the administrative rulemaking provisions of 5 USC 553 (publish and comment requirements) or 44 USC Chapter 35, Subchapter I (clearance through OMB’s Office of Information and Regulatory Affairs). These exceptions to the regulatory process will certainly make things easier for ISCD to publish a final guidance document as they essentially have carte blanch to do things their way.

Congress could justify moving this outside of the normal rulemaking process because any Tier 3 or Tier 4 facility has the full option to use this expedited approval method in full or in part or not at all. This means that the guidance cannot ‘really’ be a burden on anyone.

Whistleblower Protections

One of the provisions that was added to this bill to make it easier to obtain bipartisan support was the whistleblower protections set forth in §2105. This requires the Secretary, within 180 days, to “establish, and provide information to the public regarding, a procedure under which any employee or contractor of a chemical facility of interest may submit a report to the Secretary regarding a violation of a requirement under this title” {§2105(a)(1)}.

Setting up the reporting and investigation mechanisms may be possible within the 180 day time frame, but this will also require the publication of a regulation (actually just an addition to 6 CFR 27) and Congress did not try to exempt DHS from the normal regulatory process for this requirement. Since this will place a potential ‘burden’ on every ‘chemical facility of interest’ (NOT just CFATS facilities) the normal process will have to be followed.

Various Reports


All of the remaining time deadlines for implementation processes deal with reports to Congress. And no one (besides some beleaguered staffers at ISCD and various congressional committees) cares about those. 

Monday, February 2, 2009

Pending Rule – Reporting Security Issues

Last week I wrote about three pending TSA rules that were listed on the Office of Management and Budget web site under the Fall 2008 Regulatory Agenda. Today I will take a closer look at what the rule on reporting security issues could look like. This will be based on the material provided on the OMB web site and the referenced sections of the Implementing Recommendations of the 9/11 Commission Act of 2007 (PL 110-53). How the Obama Administration will actually implement the 9/11 Commission requirements remains to be seen. The OMB site provides a general abstract for the proposed rule. It describes provisions for “procedures by which TSA could issue civil money penalties for violations of any statutory requirement administered by TSA” and “procedures by which members of the public could report to TSA a problem, deficiency, or vulnerability regarding transportation security”. It also references sections of the 9/11 Commission Act that provide whistleblower protections to a variety of transportation workers. Enforcement Authority The OMB web site cites § 1302 of the 9/11 Commission Act as the authority for procedures for issuing civil penalties for laws administered by the TSA. This section provides for a $10,000 per day penalty for violations of applicable rules or orders issued by the Secretary of DHS. It establishes a maximum fine of $50,000 for individuals or $400,000 for “a person other than an individual or small business concern”. It does not pre-empt fines set by other legislation. Section 1304 provides for special provisions for assessing civil penalties for “public transportation agencies”. Section 1415 repeats these requirements and also prohibits the Secretary from imposing civil penalties for violating “administrative and procedural requirements” pertaining to grant applications. Section 1302 describes how the penalties would be administered and provides for the exclusive jurisdiction for district courts of the United States for civil actions to collect such fines. It limits the scope of such civil actions to collect fines by providing that “a court may not re-examine issues of liability or the amount of the penalty” in such cases. This section also provides for a public annual report by the Secretary of “all enforcement actions taken by the Secretary under this subsection”. That report must include “the docket number of each enforcement action, the type of alleged violation, the penalty or penalties proposed, and the final assessment amount of each penalty”. Procedures for Public Reporting Three different sections {§§ 1413(i), 1521(i), and 1536(i)} of the 9/11 Commission Act require TSA to establish rules for public reporting of “a problem, deficiency, or vulnerability regarding” security. Each of the individual sections governs a different section of the transportation sector; public transportation, motor carrier, and railroad. Each of these sections of the 9/11 Commission Act require the same thing. The Secretary is required to “establish through regulations after an opportunity for notice and comment, and provide information to the public regarding, a process by which any person may submit a report to the Secretary”. This establishes the legal requirement to prepare the regulation covered in this blog. All three sections add additional requirements beyond establishing the public reporting system. There is a requirement for the Secretary to respond to the submitter, if identified in the report, and acknowledge receipt of the report. Additionally the Secretary is required to review every report and to “take appropriate steps to address any problems or deficiencies identified”. Whistleblower Protections The interesting thing about the sections requiring the establishment of the public reporting process is that they form only a very small part of the section in which they are contained. The establishment of whistleblower protections makes up the largest part of those sections. In fact, a careful reading of the three sections leads one to conclude that the reporting systems are being established to provide a communication tool for transportation employees to contact TSA with information about “a problem, deficiency, or vulnerability regarding” their employer. These protections are already part of the US Code, so technically they do not have to be included in TSA regulations to provide legal cover for whistleblowers. Unfortunately, they do little good if employees are not aware of their protection. Few employees would be willing to risk their jobs by providing inside information about security issues to TSA without knowing that TSA could provide legal protections for their jobs. This means that any public announcement of these communications channels would have to provide information about the whistleblower protections included in the law. For the public communication channel to be effective in encouraging whistleblowers to come forward employers are going to have to be required to inform their workers of the protections available under these sections. Practically speaking, the only thing that could make that happen would be for that requirement to be included in the regulation being developed to establish the communication channel. The Way Forward Providing whistleblower protections to employees has long been a high priority for organized labor and the Democratic Party. It would not be unexpected for the Obama Administration to move forward quickly to publish the NPRM for this regulation. The wording for that NPRM will certainly include more about the whistleblower protections than we would have seen from the Bush Administration.
 
/* Use this with templates/template-twocol.html */