“The degree to which funds are sufficient to meet agency needs likely depends on several factors external and internal to DHS. External factors include the number of regulated facilities and the sufficiency of security plan implementation. Internal factors include the ratio between headquarters staff and field inspectors; the risk tiers of the regulated facilities; and the timetable for implementation.”In looking at the reauthorization options Shea provides more information on the option of failing to specifically reauthorize CFATS while continuing specific funding authority to enforce the program. I have reported hearing about this option, but Shea provides a cite {“Office of the General Counsel, General Accounting Office, Principles of Federal Appropriations Law, Third Edition, GAO-04-261SP, January, 2004, pp. 2-70–2-71” (footnote #27, pg 10 of the CRS Report)}for the GAO legal opinion that supports that option. Shea also notes what a number of us have written; using this option leaves DHS open to certain litigation if they were to attempt to enforce CFATS regulations in that situation. Minor Shortcomings I haven’t found any outright errors in the report, but I do disagree with a couple of minor points of interpretation. For example, Shea notes (pg 12) that “DHS has already implemented select regulatory extensions for certain agricultural operations and colleges and universities”. DHS certainly extended an ‘indefinite’ extension to agricultural ‘end users’. I don’t think, however, that the wording in the Appendix A final rule referenced in the footnote for ‘colleges and universities’ constituted a selective regulatory extension; it merely pointed out the procedures available to any facility to request a deadline extension. Another example can be found where Shea addresses the issue of reporting of security concerns in the discussion of Congressional options for addressing information security. The report states (pg 17) that: “Congress may also address concerns raised regarding the ability of concerned individuals to report misdeeds by creating a ‘whistleblower’ reporting mechanism.” Unfortunately, there was not an earlier discussion of existing protections that could have noted that DHS has a ‘CFATS Tip-Line’ that serves this whistleblower function. These are very minor shortcomings. In the final analysis the value of the research and the concise reporting far outweighs these issues. This is an important contribution to the ongoing political discussion about what is going to be done with CFATS. I highly recommend this report to all interested parties.
Friday, July 17, 2009
CRS CFATS Report
As I noted yesterday the Congressional Research Service published a report on the reauthorization options open to Congress for the soon to expire (10-04-09) authority for CFATS regulations. The report authored by Dana Shea examines the legislative history of the current authority, how the CFATS regulations have been implemented to date, security issues that have been mentioned in congressional debates but are as of yet unresolved, and potential solutions that have been proposed for addressing those issues. Finally, the report briefly examines the four pieces of legislation currently before Congress that address the authority for CFATS; HR 261, HR 2477, HR 2868, and HR 2892.
Shea has done a very good job of summarizing the current situation, available options, and pending legislation. Anyone with an interest in the continuing regulation of high-risk chemical facilities should add this report to their library. A number of writers (myself included) have attempted to summarize the issues associated with the reauthorization of CFATS, but, due to space limitations, none of us have been allowed to approach the issue in the detail presented in this report.
New Issues and Information
Shea has identified an issue that I have yet to see addressed anywhere else, the problem of determining adequate funding levels for CFATS. The report notes that as early as December 2007 Congress was asking if the requested and appropriated funds were “sufficient to hire and retain the staff necessary to perform the required compliance inspections” (pg 6). Then Shea explains why that simple question has been so hard to answer:
Thursday, July 16, 2009
HR 2868 Hearings Next Week
Yesterday afternoon wallmond (William Almond, Washington, DC) posted the following Tweet on Twitter yesterday afternoon:
“House Energy & Commerce Cmte likely to hold CFATS hearing next week. Enviro'lists & labor unions (not security experts or industry) to star” Note: please forgive the abbreviations but Twitter does have a 140 character message limitation.I have looked at the Energy and Commerce Committee web site for next week’s schedule and HR 2868 does not show up yet. They do have three days (Mon, Tue, and Wed) scheduled for a full committee mark up of HR 3200 (America’s Affordable Health Choices Act of 2009). That is a full hearing schedule that is likely to get delayed by floor votes, etc. I’ll be slightly surprised if HR 2868 get a hearing next week and I suspect that if it does occur it will be before the Energy and the Environment subcommittee. That would be appropriate since they handle water issues. Remember, this is the committee that essentially killed HR 5577 last year because they did not want to give up authority over water treatment facilities. Dingell was the chairman then, not Waxman, but the Committee is still going to try to retain some oversight responsibility for CFATS at water treatment facilities. This Committee has not had a full court press by the pro-IST people yet, so it is probably fitting that they start off with those folks. Besides the pro-IST people have not had a chance to testify this year. And they really want to shut down the chlorine gas use at water treatment facilities. The AWWA will also be present in some form to ‘balance’ the presentation. We shouldn’t expect to see non-water related industry at these hearings. They were covered at Homeland Security.
CRS Report on CFATS Reauthorization
There is a brief note on HomeStation.typepad.com today about a recently published Congressional Research Service report about options that Congress has for reauthorization of CFATS. It quotes the introduction of the report as saying:
“This report provides a brief overview of the existing statutory authority and the regulation implementing this authority. It describes several policy issues raised in previous debates regarding chemical facility security. The report identifies policy options that might resolve components of these issues. Finally, legislation introduced in the 111th Congress is discussed.”Unfortunately this blog from the Texas A&M Integrative Center for Homeland Security did not provide a link to the report. So I went to the Federation of American Scientists web page and they did have a link to the CRS report. A brief scan of the document looks interesting. Here is an excerpt from the table of contents:
Policy Options Maintain the Existing Regulatory Framework Extend the Sunset Date Codify Existing Regulations Alter the Existing Statutory Authority Accelerate or Decelerate Compliance Activities Incorporate Additional Facility Types Consider Inherently Safer Technologies Modify Information Security Provisions Preempt State RegulationsIt is a lengthy document which I’ll try to read tonight and report on it tomorrow.
Incident Evacuations
There is an interesting pair of articles over on Homeland1.com by Jim Sideras about planning for and executing evacuations. The first article is very technical and will be hard to follow if the reader is not familiar with the FEMA incident management system. The second article is more general and should be read by anyone with responsibility for emergency response planning for any high-risk chemical facility, especially if there is a potential for significant off-site affect from a terrorist attack or chemical accident.
Facility authority for emergency response stops at the fence-line, but there is a moral and legal responsibility for facilities to provide adequate information to local emergency planners and response personnel to allow them to plan and execute an appropriate response to a chemical release that could affect the surrounding community.
Understanding the considerations that go into planning and executing an area evacuation will allow the facility to be more proactive in providing the necessary information to the incident commander. This is just another argument for someone in the facility emergency response planning team to have completed Federal incident response training. It will make it easier for the facility to communicate with the community emergency response teams.
Facility Evacuations
Companies will also have to consider the requirements for an evacuation of their own facility. The drivers for a facility evacuation may be an on-site incident or an incident at a neighboring establishment. A facility evacuation plan should also include:
Why/when an evacuation may be required; Who will make the decision to evacuate; How that decision will be communicated to facility personnel; What provisions will be made for facility safety and security in the event of an evacuation; Where the off-site assembly area will be; How the decision will be made to re-enter the facility;High-risk chemical facilities are going to have to be able to continue to provide for the continuity of their security plans in the event of an evacuation. Unless the facility is able to evacuate COI (very unlikely for release COI) or chemically neutralize the COI, the risk of terror attack is not eliminated when there is an incident at a neighboring facility. In fact, such incidents may actually be a prelude to a planned terrorist attack as a method of subverting security measures. At a minimum, provisions need to be made for monitoring security systems from off-site, either at another facility of the same company, an mobile emergency center, or security company facility. This, of course, means that secure communications techniques must be used for this monitoring. Facilities that rely more upon human-based security measures (security guards, patrols, etc) are going to have to consider providing for additional protections for those security personnel if they are to remain on-site during evacuations. As we are approaching the higher-risk portion of the hurricane season along the East Coast and Gulf Coast regions of the United States, it is also important to consider how the facility will deal with mandatory evacuations due to hurricanes. Again, the continuity of security and safety plans must be included in the planning for such evacuations. Special attention must be applied to the period immediately after evacuations are lifted and there is movement of people back into the area. Reduced emergency response services will be available during this period.
Wednesday, July 15, 2009
RBPS Guidance – RBPS #7 Sabotage
This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the:
Risk-Based Performance Standards Guidance Document
RBPS Guidance – Getting Started
RBPS Guidance – RBPS #1 Restrict Area Perimeter
RBPS Guidance – RBPS #2 Secure Site Assets
RBPS Guidance – RBPS #3 Screen and Control Access
RBPS Guidance – RBPS #4 Deter, Detect and Delay
RBPS Guidance – RBPS #5 Shipping Receipt and Storage
RBPS Guidance – RBPS #6 Theft or Diversion
This posting deals with security measures put into place to deal with sabotage. DHS defines sabotage as “deliberate action aimed at weakening an employer through subversion” and notes that it is of particular concern for “facilities that are high risk based on their production of mission-critical or economically critical chemicals” (pg 68).
Security Measures
Most of the security measures discussed for this RBPS are covered in much more detail in other RBPS. The main preventive security measure is the thorough vetting of personnel that are allowed unescorted access to critical areas of the facility (RBPS 12 and Appendix C). While the discussion does note that the depth of the background investigation should be tied to the “severity of the consequences that could occur because of sabotage” (pg 69), there is no discussion of using a two-man rule that was briefly discussed in RBPS 6.
Visitor control is another security measure that receives some treatment in this RBPS and includes a listing of the various types of visitors that might be expected at high-risk chemical facilities. The discussion briefly lists five types of control measures that might be used to mitigate the sabotage risks posed by visitors. Those control measures are:
“Positive identification of visitors; “Validation of the visit by contacting appropriate facility personnel; “The use of visitor registration forms to provide a record of the visitor and the time, location, and duration of the visit; “The use of visitor cards/badges; and “Visitor escort requirements.”Two other types of security measures are briefly addressed with the discussion pointing to other RBPS for more information. Physical security measures are mentioned with references to RBPS 1, 3 and 4. Cyber security is mentioned, noting that the previously mentioned security measures are “of limited value against cyber sabotage attempts”. The discussion then points the reader at RBPS 8. Metrics The summary metric for this RBPS has only two levels. Tier 4 facilities are expected to have procedures and security measures in place that are aimed at “deterring, detecting, delaying, and responding to sabotage” (pg 70) while the other three tiers will have procedures and security measures that are ‘effective’ in achieving the same ends. It is interesting to see the ‘responding’ requirement mentioned here since it is not addressed or even mentioned anywhere else in the RBPS. Of the three sub-metrics listed in this RBPS only one is mentioned in the discussion portion of this section, visitor control (Metric 7.3). Metric 7.1 provides a list of procedures that a facility might use to “deter, detect, delay, and respond to sabotage”, but again, none of the listed procedures includes security response or emergency response. Metric 7.2 provides a detailed listing of ‘requirements’ for Tamper Resistant Devices. In fact this is a more detailed listing than the one in RBPS 6 (Metric 6.9) where there is a discussion of tamper resistant techniques.
Water Treatment Facilities and CFATS
As readers of this blog are well aware, the current authorization for CFATS exempts water treatment and wastewater treatment facilities from CFATS coverage. HR 2868 (like HR 5577 last year) will, if passed, remove that exemption. While passage of HR 2868 is certainly not a sure thing this year, it is likely that when a reauthorization bill is passed it will remove the water treatment exemption.
The American Water Works Association (AWWA) is already trying to get its membership prepared for that eventuality. On Wednesday, July 29th the AWWA is going to host a webinar; Outlook for Chemical Security — Are You Prepared? It will be held from 1:00 to 2:30 pm EDT and will be open to Association members and non-members alike. The cost will be $75 for members and $125 for nonmembers.
Agenda
The AWWA notes that the webinar will “provide the Department of Homeland Security's (DHS) observations of lessons learned from the implementation of its current program, and drinking water experts will speak to the concurrent challenge of maintaining Safe Drinking Water Act (SDWA) compliance”.
There will be three speakers from the water treatment industry as well as a speaker from DHS. There is some confusion as to who will be representing DHS. The AWWA press release on WaterOnLine.com says that Sue Armstrong (Director, Infrastructure Security Compliance Division) will be the speaker, while the AWWA web page says that it will be her Deputy, Dennis Deziel. They are both very familiar with the CFATS program and should be able to provide some valuable insights.
The three industry representatives will be:
Kurt Vause, Manager, Engineering Division, Anchorage Water and Wastewater Utility Paul Swaim, Regional Technology Manager, CH2M Hill Steve Creel, Engineering Practice Leader, American WaterThe topics that will be covered will be:
“Chemical Security – Status Report on Legislation & Potential Impacts on Drinking Water Utilities “Key Elements of Chemical Facility Security “Maintaining Public Health Protection While Making Treatment Changes “Making Choices When Selecting Disinfectants in a Security Conscious Environment”Inherently Safer Technology Water treatment facilities using chlorine gas and/or anhydrous ammonia make up a large portion of the ‘dangerous’ chemical facilities identified by the Center for American Progress report Chemical Security 101. The water treatment industry is well aware that they are a major target of IST proponents, but firmly believe that CAP has over simplified their chlorine gas substitution arguments. This is why two of topics discussed during this webinar will address IST related issues. If I were working the political side of this issue for the AWWA I would encourage member utilities to invite their local Congressman and staff to a free viewing of the webinar. It would be very beneficial for these politicians who will be making IST policy decisions to fully understand what actually goes into making the IST decision at a water treatment facility. Chlorine gas is very dangerous if it is released (either deliberately or accidentally) and there are a variety of alternative technologies that are currently available. Unfortunately, they will not work in all situations. Actually, anyone that has an interest in the IST debate should probably view this webinar. The chemical industry needs to see how argue against the IST proponents using arguments other than ‘bureaucrats just don’t understand chemistry’. IST proponents need to understand that the substitution question is just not as simple as ‘bleach does the same thing as chlorine’. Finally, the committee staff for both the Homeland Security Committees and the Energy and Commerce Committees will probably learn more from this presentation than from all of the testimony any of these committees will hear. One other organization that really needs to pay attention to this IST presentation is DHS. DHS will be the ones that will be enforcing any mandatory IST program. It would do well for the management of the Infrastructure Security Compliance Division to watch this presentation. I know that Armstrong/Deziel will be there, but the entire management team should pay attention. I am pretty sure that the AWWA would be willing to share a copy with the Chemical Security Academy to use as part of the inspector training program. This would be good preparation.
Tuesday, July 14, 2009
HR 2892 Status Update 07-13-09
The Government Printing Office web site now has the Senate passed version of HR 2892 available on its web site. A quick review of that version produces no surprises. There are some new section numbers for items of interest to the chemical security community.
First, the section that extends the CFATS program authorization until October 4th 2010 is now §551.
Second, the provisons that I reported on yesterday related to clarifying the SSI classification rules is now found in §564.
Rescission of NPPD Funds
There is a section that I haven’t mentioned before on the funding side of this bill that might be of interest. It is one of many of the sections in the General Provisions (Title V) portion of the bill that rescinds unspent monies from previous budgets. These are mainly housekeeping measures necessary for keeping the financial books straight. Section 556 rescinds $8 million from the “unobligated balances of prior year appropriations made available for National Protection and Programs Directorate ‘Infrastructure Protection and Information Security’”.
The NPPD is the parent agency for the CFATS program. It is not clear from this short paragraph in the budget, but some portion of that money comes from the money appropriated in earlier budgets for CFATS inspectors that have not yet been hired. Most of the problems that NPPD has been having with their hiring processes have been related to the way the funding for the Department has been done at the last minute (and in some cases after the last minute) for the last couple of years of the Bush Administration. This was due to the conflicts between the Republican Administration and the Democratic Congress. Early passage of the FY 2010 budget will help to alleviate that problem.
Subscribe to:
Posts (Atom)