Tuesday, November 15, 2011

HR 3383 Introduced – Rail Hazmat Notification

Last week the GPO published a copy of HR 3383, the Safe Transportation of Hazardous Materials Act of 2011, which had been introduced the week before by Rep. Gonzales (D,TX). The bill would require every rail carrier that transports hazardous materials to have a plan in place, and working, to notify emergency response personnel 48 hours in advance of when a hazmat shipment transits their jurisdiction. The plan would have to be updated annually.

Not all emergency response agencies would be required to be notified. An agency would have to specifically request notification from the railroad. The bill also provides that the notification could be made through county or State government agencies.

The bill does not differentiate between different categories of hazardous materials. Thus it ignores the possibility that the required information may be protected under other federal statutes. TIH routing information, for example is considered Special Security Information.

HR 2112 Becomes Continuing Resolution

This evening (Monday) the House-Senate Conference Committee filed their report on HR 2112, the Agriculture, Rural Development, Food and Drug Administration, and Related Agencies Appropriations Act, 2012. The report recommends adopting the Senate version of the bill with one minor change. It would add Division D to the bill which consists of a single sentence:

“SEC. 101. The Continuing Appropriations Act, 2012 (Public Law 112-36) is amended by striking the date specified in section 106(3) and inserting ‘December 16, 2011’.”

This would extend the current FY 2012 spending authority that expires on Thursday until December 16th. It would also extend the CFATS authorization to the same date.

The House Rules Committee web site notes that the HR 2112 Conference Report will ‘likely be considered pursuant to a rule’, though the hearing date for the formulation of that rule has yet to be announced. It will probably have to be held tomorrow.

Sunday, November 13, 2011

Congressional Hearings – Week of 11-14-11

Both the House and Senate will be in Washington this week, but the FY 2012 spending issue will be the big news this week, not Congressional hearings (remember the current ‘continuing resolution’ expires on the 18th). There will be two House hearings this week of potential interest to the chemical and cyber security communities, plus the House will finish work on HR 2838, the Coast Guard authorization bill.

Cyber Security


The Subcommittee on Crime, Terrorism, and Homeland Security of the House Judiciary Committee will be holding a hearing on Thursday about cyber security. Politically this is an impressive array of witnesses, including Michael Chertoff, but there is no one with specific control system expertise. Who knows, though, industrial control system security might be mentioned in passing; some Representative might even ask an ICS related question. Stranger things have happened.

Subcommittee Mark-up


The Subcommittee on Counterterrorism and Intelligence of the House Homeland Security Committee will also meet on Thursday to mark-up two bills; HR 2764, the WMD Intelligence and Information Sharing Act of 2011, and HR 3140, the Mass Transit Intelligence Prioritization Act. The second is an issue to the chemical security community only in that it reduces the number of DHS intelligence folks that might be looking at chemical intelligence issues. Without adding analysts this is a zero sum game that reduces the security of everyone else.

As I mentioned in my original posting on HR 2764 this is yet another bio-terrorism bill. Okay, I do have to admit it has some generic chemical, biological, radiological and nuclear language in it, but the main focus is on bio-weapons.

If anyone on the HS Committee Staff is reading, I’ll repeat my plug in that blog for an addition to this bill:

“What is lacking in the CFATS program (okay one of the things that is lacking) is an intelligence collection, analysis and dissemination capability to identify potential threats. This bill would be an excellent place to require OIA to establish a national chemical fusion center that would bring together government and private sector chemical intelligence collection and analysis capabilities. This could be coordinated with the Office of Infrastructure Protection to include communications to and from high-risk chemical facilities; the most likely sources of material for a truly large scale CBRN attack.”

Coast Guard Authorization


According to the Majority Leader’s web page the House will resume consideration of HR 2838 on Tuesday. Remember this is a restricted rule and only two pre-approved amendments are left to consider. The House version of this bill does have a ‘Homeland Security’ provision (okay, this is a real stretch); § does make GPS interference a felony if it affects maritime safety. As I asked in initial post on this bill; would that cover effecting ICS at an MTSA covered portside facility? It is just too vague to tell.

FY 2012 Spending


The Senate is due to start taking up HR 2354 on Monday afternoon. This bill would make appropriations for energy and water development and related agencies for FY 2012. While the amendment filing process has begun on this bill, I have yet to see the standard ‘amendment in the form of a substitute’ from the Senate Appropriations Committee. This may be because this bill may become the ‘vehicle’ for another short term extension of current spending authority. Various press sources have mentioned ‘Christmas’ (probably December 18th) as the expiration of that ‘continuing resolution’. Or, the House could end up drafting a new CR out of whole cloth.

Saturday, November 12, 2011

Reader Comment – USCG and Homeland Security

Yesterday a long time reader and security blogger in her own right, Laurie Thomas, (Maritime Security/MTSA News) responded to a comment I made in my posting about the introduction S 1665, the Senate version of the Coast Guard Authorization bill. I commented that:

“I suppose that the MTSA community should be happy that there are no new requirements added in this bill, but it does appear that the reason is not that the regulatory environment is completely covered but more because of a lack of attention.”

Laurie proposed two alternatives that she explains better in her comment (please read) but I’ll summarize as:

• Other members of the Coast Guard supported community feel that they have been slighted due to the previous attention on Homeland Security, and

• The realization that the pending MTSA 2 regulations need to be absorbed before new requirements are established.

Politically, the first reason certainly rings true. You can see this possibly reflected in the list of missions being supported that I described in the original blog post. One of those in particular, ice operations, has been receiving a lot of attention in both the Senate and the House in Coast Guard hearings this year. In a budget-limited year, adding funds for these other programs would certainly have to come at the expense of something and that could very well be reason for the lack of mention of new homeland security mission requirements.

The second reason seems a bit of a reach to me. That might explain the lack of new programs, but politicians are not known for thinking that far ahead. It certainly doesn’t explain the lack of the normal requirements for meaningless reports to Congress on TWIC Reader implementation or CFATS harmonization or any of the other hot-topic homeland security issues of the last couple of years. Nor can we assume that the Senate (and the House which also seems to have mostly ignored the HS mission in their version – HR 2838 – currently being considered on the floor) has decided to stop wasting regulator’s time with these endless reports.

No, I really think that we are starting to see a shift away from the post-9/11 sharp-focus on security and counter-terrorism. Part of the reason is certainly due to the lack of significant attacks on the homeland. The successful attacks have been extremely small scale and the larger scale attempts have been particularly inept. One would have to expect that the public and their politicians would sooner or later start to think that we seem to have the counter-terrorism thing under reasonable control.

The other problem is that the public (and the mass of reactive politicians) have a limited attention span and that is quite frankly focused on more important problems; it is yet again ‘the economy, stupid’. While this is most obviously noted in our communities by changes in funding priorities (which is what authorization bills are all about after all) it will also be seen in the lack of attention to ongoing security programs by both the public and the  politicians.

I don’t think that we are facing major cut backs in the chemical security related programs (MTSA and CFATS are both relatively low cost programs as far a Federal spending programs go). Industry has been generally supportive of what DHS and the Coast Guard have been doing and there are still some powerful politicians that strongly support these programs. I just don’t see any great new programs or requirements being set out for our community.

UNLESS…. (beware of knee-jerk political reactions)

Friday, November 11, 2011

TSA to Ignore Highway Hazmat Security

Yesterday the Office of Management and Budget (OMB) made an apparently routine announcement of their web site that the Transportation Security Administration (TSA) was withdrawing an information collection request renewal (ICR) that it had submitted in July. The ICR in question deals with the Corporate Security Review (CSR) program for trucking companies; an ICR I briefly covered back on July 7th.

Now there are any number of reasons that an agency might withdraw an ICR renewal, but usually they would deal with a change in policy that concerned the covered program. It appears that that is the case here. In the last line of the OMB announcement we find the following ‘short statement’:

TSA is no longer conducting CSRs on Hazmat entities [emphasis added]. TSA will only conduct reviews on non-Hazmat entities. Therefore the burden has decreased [to just 100 CSRs].”

There was nothing in the initial 60-day ICR notice or the follow-up 30-day notice that indicated that the TSA was reducing the scope of this program. On the contrary the initial notice indicated that TSA was intending on “conducting 500 visits per year” (76 FR 23238); an increase over the 400 visits projected when the information collection program was previously approved by OMB.

Now, I fully understand that the TSA surface security program is severely under staffed and unfunded and shame on Congress for that. But, why anyone would spend their limited resources looking at the security practices of non-hazmat related transportation companies while ignoring those companies that haul potential chemical terrorist weapons is completely unexplainable. Hopefully that is why this modified ICR was withdrawn.

DHS Publishes ANSP Meeting Update in FR

This is really just a formal repeat of previously reported news, but today the folks at the DHS Infrastructure Security Compliance Division (ISCD) published a notice in the Federal Register announcing the addition of the St. Petersburg, FL listening session to the series of public meetings about the Ammonium Nitrate Security Program. Since these ‘listening sessions’ are a part of the formal ‘publish and public comment’ process for this proposed regulation, DHS was required to publish this notice in the Federal Register.

As I noted in the earlier blog on this added meeting DHS did not provide all of the standard information about public participation in this new meeting in their web site notices. This posting in the FR certainly does include all of that information, but nothing has changed from the original formal notice.

Wednesday, November 9, 2011

HR 2096 Reported in the House – Cybersecurity

The House Science, Space and Technology Committee report on HR 2096, the Cybersecurity Enhancement Act of 2011, was published by the GPO late last week. The actual markup was conducted back in July, but the bill was not formally reported until October 31st. The bill is now available for action by the House.

This bill is essentially a funding authorization bill for a number of research related programs to enhance information security. In many cases it authorizes programs that expired in 2007; some at higher funding levels but some at much lower levels.

As I noted in my blog post about the introduction of this bill there is a brief mention in §102(1) of critical infrastructure, but there is not a single mention of control systems in the bill. Oh well, it is a cybersecurity bill, just not one that will be of much help to the control system security community.
 
/* Use this with templates/template-twocol.html */