Tuesday, February 10, 2009
CFATS Whistleblower Hot-Line
There have been some changes made to the DHS Chemical Security web page. The most important change is the new link (last link) of the “I want to:” block at the top of the page. The “Call the CFATS Tip Line” takes one to a new entry on the CSAT FAQ page (the first new entry in a couple of months) that provides information on how to report security concerns.
For a ‘possible security concern’ involving the CFATS regulation, the FAQ page (FAQ # 1620) provides a telephone number for the CFATS Chemical Facility Security Tip Line (877 394-4347). Apparently you do not get to talk to a real person, but you can leave an anonymous voice mail message or leave your contact information. This certainly sounds like a whistleblower hot-line.
The FAQ provides a separate number for reporting a ‘potential security incident’ that has already occurred (‘potential’ and ‘already occurred; I’m confused). This number is for the National Infrastructure Coordination Center (202-282-9201). Please note that this is not a toll free number, it is the standard Washington, DC area code. It also notes that this number should not be used for an in-progress security incident; one should call 911 or call the FBI in that instance.
Finally, the FAQ provides yet another number to call for questions about the CFATS regulations (866-323-2957).
I am severely disappointed that DHS is burying the whistleblower hot-line in the middle of the FAQ page. Even the link on the Chemical Security page is obscure and easily over looked. This number (with brief instructions) should probably be in a text box of its own near the top of the Chemical Security page and made a permanent part of the page.
Jack Frost and CFATS
A recent US EPA press release highlights the government’s problem with enforcing environmental and safety regulations. The press release explains the punitive actions that the EPA took against Jack Frost Fruit Company, of Yakima, Washington for failing to fulfill the Risk Management Plan obligations required by their storage of more than 10,000 lbs of anhydrous ammonia. The question becomes did the same company avoid the requirements of CFATS for the same chemical?
RMP Violations
The facility was fined for not having a Risk Management Plan (RMP) for a potential accidental off-site release of anhydrous ammonia. The RMP requires a company to assess their safety systems and material handling procedures to ensure that they are reducing the risks of releases of anhydrous ammonia. Additionally, the RMP requires that the facility communicate with the local community and emergency response personnel about the presence of the chemical and the emergency response requirements in the event of a release.
In addition to a fine of $20,554 the company is being required to undertake two projects to reduce the risks associated with an off-site release. The first project will be making improvements to their handling system and procedures to reduce the potential for an accidental release. The second project will help the local emergency response personnel to prepare for a potential release. The cost of the two projects will be at least $85,000.
In most cases where there is no RMP at a covered facility it is because the company was not aware of, or misunderstood, the requirements for an RMP. There will also be some number of companies that were aware of the requirements but decided not to spend the money to comply with those requirements. In either case the public is left at risk for exposure to an accidental release of toxic or highly flammable chemicals.
CFATS Cause for Concern
Regardless of the reason for not having an RMP, it is likely that the facility without an RMP is also not complying with the CFATS regulations. Facilities that are not aware of their obligations under RMP, a long standing EPA program, are likely be to equally unaware of their CFATS obligations. Facilities that willfully avoid their RMP obligations are probably not going comply with potentially expensive CFATS requirements.
CFATS Compliance Efforts
While DHS certainly has its hands full in getting the CFATS program fully functional (we are still waiting for the roll out of the Site Security Plan tool in CSAT), some effort needs to be expended to ensure that all chemical facilities with a STQ quantity of one of the DHS COI have completed a Top Screen.
One low cost effort would be to screen all completed EPA RMP enforcement actions against the list of facilities that have completed a Top Screen. Facilities showing up on the first, but not the second list should receive an enforcement letter from the Secretary directing the facility to complete a Top Screen.
As the Site Security Plan portion of CFATS gets to the field, DHS needs to begin looking seriously at how they are going to ensure that all potentially covered facilities are aware of their obligation to submit a Top Screen submission. Techniques are going to have to be developed to identify classes of facilities that probably have DHS COI on site. This could be done by data mining the Top Screen submission data base. Commercial data bases could then be used to identify other facilities in those classes for potential enforcement actions.
Potential Congressional Actions
As Congress begins to look at extending the CFATS authorization or, hopefully, making the program permanent, some thought needs to be applied to providing DHS with additional tools to aid in ensuring regulatory compliance. One way to do that would be to require that EPA provide DHS with a list of all facilities that have submitted a current RMP. This would help DHS to identify some of the facilities that should have completed a Top Screen submission. Other government agencies with comparable programs that DHS used to formulate their COI list should also be required to provide similar facility lists to DHS.
Congress could also consider requiring manufacturers and distributors of COI to provide to DHS lists of customers that received more than a STQ of a COI. These rules would not need to be as extensive as those being developed for ammonium nitrate manufacturers and suppliers. Such lists would provide DHS with information on facilities that should have submitted a Top Screen.
Moving Forward with CFATS
DHS is finishing the process of getting their CFATS program fully established. Once that is done they need to begin working on the enforcement side of the program. That enforcement will be focused on ensuring compliance with security plans at self-identified high-risk facilities. It also needs to have an enforcement component that actively looks for potential high-risk facilities that have not yet begun the CFATS process.
Monday, February 9, 2009
Wisconsin Ignores Chemical Threat
There is an interesting blog posting over on HSDL.org (HSDL - Homeland Security Digital Library). Ijkaijan briefly reports on a draft copy of the Wisconsin Homeland Security Strategy that was published last week. It outlines Wisconsin’s “direction for our prevention, protection, response, and recovery efforts for the next three years (2009-2011)” (pg 4). It is an ‘all hazards’ document looking at the potential effects of storms, terrorism, even mass evacuations of neighboring Chicago or Minneapolis/St Paul.
No Chemical Facility Response
What is of great concern to me is that it makes no mention of responses to accidents or attacks at chemical facilities within the State. Now, Wisconsin does not have a facility that made the Top 101 list on last year’s Center for American Progress’ Chemical Security 101 report, but it did have two facilities (the Murphy Oil refinery in Superior, and the Hydrite Chemical plant in Oshkosh) that made the Appendix B list (‘List of 202 additional facilities’) in that report. A major release at either of those two facilities could affect more than 100,000 individuals.
There will certainly be other high-risk chemical facilities located in the State. The large agricultural industry located in the State means that there will be a significant number of facilities storing anhydrous ammonia. Water treatment plants mean that there will be chlorine storage and transportation sites.
Emergency Response
While high-risk chemical facilities are largely responsible for their own security, the State and local governments will be stuck with the large part of the emergency response efforts for major accidents or terrorist attacks on these facilities. I would have thought that it would be appropriate for an ‘all hazards’ strategy to provide at least as much attention to the planning effort for this as it does for emergency snow removal (admittedly more of a problem in Wisconsin than here in Alabama).
New SOCMA Approach to IST
The Synthetic Organic Chemical Manufacturers Association (SOCMA) has long opposed mandatory application of inherently safer technology (IST) as a method of reducing the risk of terrorist attack on high-risk chemical facilities. I have noted that I thought that their attacks on IST were politically short-sighted and unpersuasive. Last Friday they took a slightly different tact in a posting on Blog.TheHill.com; they started explaining some of the problems associated with an imposed IST requirement.
IST as Chemical Engineering
Anyone that has experience in working in the chemical process industry is familiar with the concept of IST. Every time that a new chemical process is introduced into a facility or modified at that facility a series of safety reviews are conducted. Reviews are conducted on new hazardous chemicals, on the storage and handling of those chemicals, and finally on the process where the chemicals will be used. Any reputable chemical company will automatically consider a wide variety of inherently safer technologies to help reduce safety risks associated with hazardous chemicals. Chemical engineers, chemists, industrial hygienists, regulatory affairs personnel, and hourly employees will all be involved in that process.
Unfortunately, the term ‘reputable chemical company’ does not necessarily cover all facilities that handle hazardous chemicals. There are a large number of facilities that use hazardous chemicals that are not considered to be chemical facilities and lack the staff, training, and regulatory requirement to conduct these extensive safety evaluations. There are other facilities that lack the funds and expertise. Finally there are facilities that just cannot be bothered to expend the time or money. An aggressive enforcement effort of existing chemical safety laws by EPA and OSHA would bring many of these facilities into line.
IST as Chemical Security
What is new is the security aspect of IST. As more companies are coming to face the reality of increased security costs associated with the COI listed in Appendix A to 6 CFR 27, many are re-evaluating the cost-benefit analysis of many alternative processing methods and techniques. In many cases changing chemicals or processes in ways that were too expensive are now becoming economically viable when security costs are included in the calculations.
What concerns organizations like SOCMA and the American Chemistry Council (ACC) is that many people that are pushing the IST requirement see it as the be all and end all of chemical safety and security. Many IST supporters see these requirements in new regulations forcing most users of many hazardous chemicals, poison inhalation hazard (PIH) chemicals in particular, to get rid of these chemicals without due consideration of the economic viability of doing so.
Realistic Compromise
As in many political arguments today (and this is, at its most essential, a political argument) neither side seems to be willing to listen to and address the legitimate concerns of the other side. What is required is a workable, realistic compromise and a reduction in the volume of the rhetoric. Such a compromise would have to be based on the following principals:
Every high-risk chemical facility owes it to its owners, its workers, and its neighbors to periodically re-evaluate its use of DHS COI to see if there are safer chemicals or process changes that can reduce the potential safety and security risks associated with the use of those high-risk chemicals. Many of the technical and business calculations that will go into the evaluation will be facility specific. Personnel without the appropriate technical background will be ill equipped to second guess those decisions. An independent technical body should be formed to provide for an appropriate technical review of decisions not to implement IST alternatives. In areas where there exists an extraordinary hazard to a large civilian population, the government should consider the use of financial incentives to implement IST provisions that are not otherwise economically viable or to move the facility to another location.Industry owes it to their owners and employees to remain viable economic concerns. It does not appear that blind opposition to IST will prevail in the current political climate. Therefore industry needs to work with IST proponents to work out a program that will be economically viable.
Saturday, February 7, 2009
ISA Security Guidelines
On February 5th, 2009 the International Society of Automation announced the release on an ANSI/ISA Standard (ANSI/ISA-99.02.01-2009) for “Establishing an Industrial Automation and Control Systems Security Program”. The standard is available for purchase (in hard cover) on the ISA web site. ISA members can download a copy of the standard for free.
I’ll have further information in a future blog.
Homeland Security Reorganization II
The House Homeland Security Committee held their first meeting of the 111th Congress on last Wednesday. The Committee completed their reorganization, adopted an oversight plan, and looked at what they wanted to accomplish this session.
Chemical Facility Security
There were only brief mentions about pending chemical facility security legislation in the various sources reporting about the meeting (the meeting was open to the public, but not webcast so I did not get a chance to follow the meeting). The tone of the comments suggests that Chairman Thompson is not planning on re-introducing HR 5577 from last session. Rather it seems that the new Committee will write new legislation. That could prove interesting.
Other Homeland Security Legislation
Three pieces of homeland security legislation from Committee members has already been re-introduced and passed in the House this last week. All three were passed in the House last session but were not taken up by the Senate, nor was Chairman Thompson able to get them added to the DHS spending bill.
None of them have a direct impact on the chemical community with the possible exception of Rep Harmon’s (D, CA) bill (HR 553) to prevent over-classification of Homeland Security produced information. This legislation would require that DHS produce unclassified versions of intelligence reports. This would allow for more sharing of such reports with security planners at high-risk chemical facilities.
It looks like the House Committee is going to join with the Senate Homeland Security Committee in trying to pass the first DHS Authorization Bill. Authorization Bills provide guidance to Congress and , to a lesser extent, the affected Department on what the priorities will be for that Department. Spending guidelines are set, but not actually appropriated in these bills. Senators Lieberman and Collins introduced their version during the ending days of the 110th session. It will be interesting to see the differences between these two versions of that authorization
Thursday, February 5, 2009
Pending Rule – Vulnerability Assessments
Last week I wrote about three pending TSA rules that were listed on the Office of Management and Budget web site under the Fall 2008 Regulatory Agenda. Today I will take a closer look at what the rule on railroad vulnerability assessments and security plans could look like. This will be based on the material provided on the OMB web site and the referenced sections of the Implementing Recommendations of the 9/11 Commission Act of 2007 (PL 110-53). How the Obama Administration will actually implement the 9/11 Commission requirements remains to be seen.
Section 1512 of the 9/11 Commission Act requires the Secretary of DHS to issue regulations that require railroads that are designated as high-risk to conduct vulnerability assessments (VA) and develop a security plan (SP) based on that assessment. The Secretary will develop standards and guidelines for the VA’s and SP’s in accordance with the National Strategy for Railroad Transportation Security (NSRTS) outlined in § 1511 (NOTE: it is not clear to me that the NSRTS has yet been developed, but that is a separate issue for another day). The deadline established in § 1512(a) for the publication of this regulation passed in August of last year.
Tier Assignments
Section 1512(h) requires that the Secretary assign “each railroad carrier to a risk-based tier established by the Secretary”. The tiers, and the methodology used to assign rail carriers to those tiers, will be established using the criteria established in the NSRTS. At least on of those tiers will be a ‘high-risk’ tier. The regulations prepared under the §1512 requirements may require rail carriers to provide the “information necessary for the Secretary to assign a railroad carrier to the appropriate tier” {§ 1512(h)(1)}
Vulnerability Assessment
Section 1512(d) details the requirements for the vulnerability assessments that will be required by these regulations. The VA must identify critical assets and infrastructure, vulnerabilities to those assets and infrastructure, and strengths and weaknesses related to those vulnerabilities. Those critical assets and infrastructure will include platforms, stations, intermodal terminals, tunnels, bridges, switching and storage areas, and information systems as appropriate.
The strength and weaknesses required to be identified in the vulnerability assessment must address eight specific areas listed in § 1512(d)(1)(c). Those areas are:
Physical security; Passenger and cargo security; Programmable electronic devices, computers, or other automated systems; Alarms, cameras, and other protection systems; Communications systems and utilities needed for railroad security purposes; Emergency response planning; Employee training; and Such other matters as the Secretary determines appropriate.Additionally, the VA must identify those backup systems and system redundancies that are necessary to allow the railroad carrier to continue operations in the event of a terrorist attack or other incident. Systems specifically identified in § 1512(d)(1)(D) include “disruption of commercial electric power or communications network”. Security Plan Section 1512(e) requires that the Secretary provide ‘technical assistance and guidance’ on the development and implementation of the security plans required to be included in this regulation. The section goes on to detail nine specific areas that those plans should address. Only two of those nine areas actually deal with classical security measures and those only address security for ‘security-sensitive materials’ and the additional security measures to be applied “when the Secretary declares a period of heightened security risk” {§ 1512(e)(1)(F)} One of the required components of the security plan is the appointment of a ‘security coordinator’. This is very similar to the Rail Security Coordinator established in last fall’s freight rail security rule. There are some differences. In this legislation the security coordinator must have the authority to “to implement security actions under the plan” {§ 1512(e)(1)(A)}; there is no such requirement for an RSC. Section 1512(e)(2) also requires that the security coordinator is a US citizen, though the Secretary can waive this requirement after conducting a “background check of the individual and a review of the consolidated terrorist watchlist”. Consultation It appears that one of the most common components of the requirements included in the 9/11 Commission Act was the requirement for coordinating actions. Section 1512(m) establishes that requirement in this case. It requires the Secretary to consult with “railroad carriers, nonprofit employee labor organizations representation railroad employees, and public safety and law enforcement officials” in preparing this regulation. Interestingly there is no requirement to coordinate with shippers or other customers of the railroads. The Way Forward TSA has tried to work with the railroad industry to get them to voluntarily comply with requirements to conduct vulnerability assessments and establish security plans. The lack of specificity in the requirements for that voluntary effort and the inability of TSA to enforce compliance ensures that most of the security efforts will fall short of the requirements of § 1512. This rule will be much more complex than the CFATS regulations. TSA would do well, though, to look at the implementation scheme used for CFATS. A computer based system for providing pre-tiering information, as well as vulnerability assessment and security plan filing will go a long way to making the implementation of these requirements easier for both the regulated community and the regulators.
Subscribe to:
Posts (Atom)