Thursday, March 17, 2016

Bills Introduced – 03-16-16

Yesterday with both the House and Senate in session there were 40 bills introduced. Of those, two may be of specific interest to readers of this blog:

HR 4765 To provide first responders with planning, training, and equipment capabilities for crude oil-by-rail and ethanol-by-rail derailment and incident response, and for other purposes. Rep. Herrera Beutler, Jaime [R-WA-3] 

S 2694 A bill to ensure America's law enforcement officers have access to lifesaving equipment needed to defend themselves and civilians from attacks by terrorists and violent criminals. Sen. Toomey, Pat [R-PA]

It will be interesting to see how comprehensive (expensive) HR 4765 will be and if it includes a funding source.

Unless this bill includes some mention of chemical protective equipment, it will probably not receive future coverage in this blog.

Note: There is a bill of personal interest that I would like to mention here:

HR 4752 To require the National Aeronautics and Space Administration to investigate and promote the exploration and development of space leading to human settlements beyond Earth, and for other purposes. Rep. Rohrabacher, Dana [R-CA-48] 


It will not be covered in this blog, but if there are positive developments I would expect to write about them on LinkedIn.

Wednesday, March 16, 2016

RMP NPRM: 3rd Party Audits

This is part of a continuing series of blog posts about the EPA’s recently published notice of proposed rulemaking (NPRM) for revisions of their Risk Management Program. Earlier posts in this series include:


3rd Party Audit Overview


Sections 68.58 (Program 2) and 68.79 (Program 3) of the Chemical Accident Protection Regulations currently outline the requirements for compliance audits of the Risk Management Program at covered facilities. The NPRM is proposing a number of changes that would require some facilities to have those compliance audits conducted by 3rd party auditors. The NPRM would require 3rd party audits in two situations:

If there has been an accidental release from an RMP facility meeting the five-year accident history criteria as described in §68.42(a); or
If an implementing agency has made a determination that a third-party audit at an RMP facility is necessary.

The second case is an essentially an expansion of the EPA’s current practice of requiring 3rd party audits as part of consent orders.

A definition of ‘third-party audit’ would be added to §68.3. That definition would read:

“Third-party audit means a compliance audit conducted pursuant to the requirements of §§ 68.59 and/or 68.80, by an entity (individual or firm) meeting the competency, independence and impartiality criteria in those sections.”

3rd Party Audit Requirements


The NPRM would add a new paragraph (f) to both §68.58 (Program 2) and §68.79 (Program 3). It would establish the requirements for when the next required compliance audit would have to be conducted by an independent 3rd party auditor. As noted above the two causes would be a covered accidental release or a determination by an implementing agency that an RMP non-compliance had occurred. One specific non-compliance is mentioned; the use of an auditor that failed to meet the competency, independence, or impartiality criteria.

A new paragraph (g) would be added to both programs outlining the requirements for an implementing agency directive to conduct a 3rd party audit. Those requirements include:

• Implementing agency written notification;
• Provision for facility to provide information to, or request consultation with, the implementing agency; and
• The right to appeal a final 3rd party audit determination.

A new paragraph (h) would be added that would prescribe the schedule for the completion and submission of the 3rd party audit report. Unless otherwise specified by the implementing agency the deadline would within 12 months or within 3 years of the last completed audit; whichever is sooner.

Third-Party Audits


The NPRM would add new sections 68.59 and 68.80 to outline the requirements for the audits and the 3rd party auditors. Paragraph (a) of both would require owners to engage 3rd party auditors to effect the required audits.

Paragraph (b) of the new sections would require owners to investigate and document the competency, independence, and impartiality of their auditors. The paragraph also outlines the standards for competency, independence, and impartiality. One specific requirement of note in this paragraph is the requirement for a professional engineer (PE) to lead the audit team.

Paragraph (c) would outline the requirements for the 3rd party audit report. It affirms that the facility owner would be responsible for ensuring that the audit report was completed and submitted. It also deals with auditor file retention requirements and limits any attorney-client relationship between the auditor and the facility with regards to the audit report or its related documents.

Paragraph (d) specifies that the facility owner would have 90-days to determine an appropriate response to each of the findings in the audit report, and develop and provide to the implementing agency a findings response report. A time limit for implementation is not included in the NPRM. An implementation schedule and progress report would be required. The paragraph also outlines report retention requirements.

Commentary


I have always maintained that the primary weakness of both the RMP and the PSM process is the inability of either the EPA or OSHA to ensure compliance with their requirements. Neither agency is adequately staffed to do more than targeted inspections or respond with investigations of accidents or complaints. Both agencies have relied on program self-audits to serve in place of agency inspections.

Ignoring the relatively small number of facilities that are willfully out of compliance with the RMP regulations, it is hard to justify how a facility self-audit can really be effective when done with on-site personnel who are tasked with the day-to-day implementation of the process. Even when facilities have personnel with audit training, it is hard to get them to step back and take a look at their risk management plan with an eye that is not focused on their daily task of ensuring efficient and safe production.

Many larger companies see and solve this problem by having portions of the audit team come from other facilities. This does allow an outside eye to look at facility specific issues, but corporate wide issues are frequently overlooked for the same reason; the safety culture of the company helps to define, in large part, what is considered safe and adequate. I’m not saying that the company auditors deliberately overlook safety issues, just that their day-to-day activities color the way that they look at those issues.

Of course, 3rd party auditors are not without their own potential problems. Since these auditors are paid by the auditee there is a potential for good people to want to see their paymaster in a good light. This is the reason for requiring a PE to be the lead auditor; the PE’s professional reputation is on the line for every audit signed.

The bigger problem with a 3rd party auditor is the difficulty in finding someone with the requisite process knowledge to conduct a thorough review. Each chemical manufacturing process has its own subtle differences and safety issues and even the same process set up at two different facilities may have some significant differences in equipment or procedures that raise new safety issues. The problem is compounded further in facilities that have a unique, one-of-a-kind chemical process; it is highly unlikely that such a facility could find someone with no connection to the company to be a truly qualified auditor in that instance.


I suspect that this will be an area of great contention between the EPA and the chemical manufacturing industry. Hopefully there will be plenty of comments on this topic and the EPA seems to be asking the right questions in their NPRM. Hopefully, we will be able to find a reasonable way forward.

Bills Introduced – 03-15-16

With both the House and Senate in session yesterday there were 26 bills introduced. Three of those bills may be of specific interest to readers of this blog:

HR 4740 To direct the Attorney General to make grants to States and units of local government for the prevention, enforcement, and prosecution of cybercrimes against individuals, and for other purposes. Rep. Clark, Katherine M. [D-MA-5]

HR 4743 To authorize the Secretary of Homeland Security to establish a National Cybersecurity Preparedness Consortium, and for other purposes. Rep. Castro, Joaquin [D-TX-20]

S 2684 A bill to provide for the operation of unmanned aircraft systems by owners and operators of critical infrastructure. Sen. Inhofe, James M. [R-OK] 

The Clark and Castro bills probably have nothing to do with control system security. If so, they will not be mentioned again.


The Inhofe bill is an odd take on UAS and critical infrastructure in that it apparently does nothing to protect CI against drone intrusions. We will see.

Tuesday, March 15, 2016

S 2670 Introduced – Micro UAS

Last week Sen. Vitter (R,LA) introduced S 2670, the Micro Drone Safety and Innovation Act of 2016. The bill would establish the legal framework for the minimal regulation of micro unmanned aircraft system (micro UAS).

Micro UAS Exemptions


The bill adds a new §337 to the FAA Modernization and Reform Act of 2012 (49 USC 40101 note). It defines micro UAS as “an unmanned aircraft system the aircraft component of which weighs not more than 4.4 pounds, including payload” {new §337(f)}.

Under clearly specified operating conditions, it would exempt the operator of a micro UAS from any “provision of a statute, rule, or regulation relating to airman certification” {new §337(b)}. It specifically exempts micro UAS operators from requirements:

• To pass any aeronautical knowledge test;
• To meet any age or experience requirement; or
• To obtain an airman certificate or medical certificate.

Under the same operating conditions, the bill would exempt the micro UAS from airworthiness standards under 49 USC 447 and specific sections of 14 CFR part 91 regulations pertaining to operations of aircraft. The bill would specifically allow, again within the specified conditions, micro UAS to “be operated by any person without a certificate of authorization or waiver from the Federal Aviation Administration” {new §337(d)(2)}. The bill would also exempt micro UAS from subsequently adopted drone regulations.

The specified conditions which the bill requires for all of the above exemptions to FAA statutes and regulations are that the micro UAS will be operated {new §337(a)(1)}:

• At an altitude of less than 400 feet above ground level;
• At an airspeed not greater than 40 knots;
• Within the visual line of sight of the operator;
• During the hours between sunrise and sunset; and
• Not less than 5 statute miles from the geographic center of an airport

Moving Forward


Vitter is not a member of the Commerce, Science and Transportation Committee, the committee to which this bill was referred for consideration. Thus it is unlikely that he would have the pull to have this bill considered in Committee. The most probable way that this bill could move forward would be for it to be considered as an amendment to another bill that would require Vitter’s cooperation for passage.

Commentary


This bill would throw the recent FAA interim final rule (IFR) on small UAS registration into all sorts of confusion. First, it ignores any differences between commercial operation and model aircraft operation; which plays a major part in differentiating how small UAS will be registered. Secondly, the small UAS definition in this bill falls within the boundaries of the definition of the IFR as far as aircraft size. The IFR sets the weight limit as being between 0.55-lbs and 55-lbs. Thirdly, the bill does not exempt the small UAS from marking requirements, but the only way of fulfilling those requirements is to obtain a registration number.

While the bill does restrict operation around airports (and does include provisions for obtaining permission to operate within the 5-mile airport limit) it does not provide any restrictions on the operation of the small UAS near critical infrastructure, over crowds, near aerial fire-fighting operations, or any other ‘reasonable’ flight area restrictions.


In general, this bill would create more confusion than would be outweigh any benefit that would accrue to the owners of the small UAS defined in this bill.

ICS-CERT Publishes Siemens Advisory

This morning the DHS ICS-CERT published an advisory for a protection mechanism failure vulnerability in the Siemens SIMATIC S7-1200 CPU. The vulnerability was reported by Maik Brüggemann and Ralf Spenneberg from Open Source Training. The newest version (December 2014) of the firmware does not include this vulnerability.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to circumvent user program block protection. The Siemens Security Advisory notes that the attacker must have network access to an affected device, and the PLC’s access protection must be disabled for this vulnerability to be exploited.

RMP NPRM: Accident Investigations Overview

This is part of a continuing series of blog posts about the EPA’s recently published notice of proposed rulemaking (NPRM) for revisions of their Risk Management Program. Earlier posts in this series include:


Accident Investigation Overview


The preamble to the NPRM describes current requirements for accident investigations in the RMP program. This includes both investigations specifically required for ‘catastrophic release’ incidents and to support process hazard analysis (PHA) program requirements for addressing previous incidents.

The NPRM is proposing the following changes that would affect the requirements for accident investigations:

Modifying the definition of catastrophic release in §68.3 to be identical to the description of accidental releases required to be reported under the accident history reporting requirements in §68.42;
Adding a definition for ‘root cause’ to §68.3;
Requiring a root cause analysis during incident investigation requirements under §68.60 (Program 2) and §68.81 (Program 3) to ensure that facilities determine the underlying causes of an incident to reduce or eliminate the potential for additional accidents resulting from deficiencies of the same process safety management system;
Requiring the owner or operator to address findings from all incident investigations required under §§ 68.60 and 68.81, in their hazard review {§68.50(a)(2)} or PHA {§68.67(c)(2)} respectively;
Clarifying that incident investigations are required even if the process involving the regulated substance is destroyed or decommissioned following or as the result of an incident;
Requiring that facility owners or operators complete an incident investigation report within 12 months of an incident that resulted in, or could reasonably have resulted in, a catastrophic release;
Requiring the inclusion in the RMP accident history under §68.42 of information on root causes analyzed as part of an incident investigation;
Modifying the on-line reporting system for RMPs (RMP*eSubmit) to incorporate an appropriate list of root cause categories for RMP facility incident investigations of RMP reportable accidents; and
Requiring in §68.195(a)(2) that the root cause categories be submitted in the RMP within 12 months of the release;

EPA Feedback


At the end of each of the discussions about the proposed changes described above, the EPA has also listed a number of questions upon which it would like specific feedback. Sometimes these questions refer to potential future rulemakings, but mostly they deal with alternative solutions to the problems discussed that the EPA has been considering. Comments about those alternative solutions are important in deciding how the EPA will move forward with the final rule.

Root Cause Analysis


The term ‘root cause’ would be defined in §68.3 as: “a fundamental, underlying, system-related reason why an incident occurred that identifies a correctable failure(s) in management systems”.

The changes being made to §68.60 (Program 2) and §68.81 (Program 3) in regards to root cause analysis are identical. In paragraph (d)(7) in each section the requirements for an incident report, including a root cause analysis are specified as:

“The factors that contributed to the incident including the initiating event, direct and indirect contributing factors, and root causes. Root causes shall be determined by conducting an analysis for each incident using a recognized method;”

The EPA is not requiring a specific root cause analysis method, but the only method specifically mentioned in the preamble is the “Guidelines for Investigating Chemical Process Incidents” from the Center for Chemical Process Safety (CCPS). The preamble does note that OSHA is working on developing a fact sheet on existing resources that explain how to conduct root cause analyses.

Commentary


Over the last twenty plus years in the chemical process industry I have taken part in a number of accident and near miss investigations. In the early years of my career those investigations concentrated on the proximate cause of the incident and how to fix that specific problem. As the industry has matured there has been more of an emphasis in most major chemical companies at looking deeper into the causes of accidents to identify the root cause.

Proximate causes of accidents are the easiest to identify and correct, but they only serve to protect against that specific version of the problem. Identifying root causes and correcting those takes much more time and resources to complete the identification process. Fixing those root causes is also a much more difficult task to complete, but success helps to prevent whole classes of future incidents not just the re-occurrence of the incident under investigation.


The only drawback that I can see of requiring root cause analysis for all required accident investigations is that a properly conducted analysis almost requires someone who has been specifically trained in root cause analysis. Too often I have seen inexperienced investigation leaders guide an investigation team to a pre-determined cause that did not get to the ultimate systemic problem that was the true root cause of the issue. Still, even those poorly conducted root cause analysis investigations did a better job of preventing future accidents than did the old-style proximate cause investigations that may still be too prevalent in many small to medium sized chemical manufacturing facilities.

Monday, March 14, 2016

Pipeline Safety Markup Hearing – 03-14-16

This evening the Energy and Power Subcommittee of the House Energy and Commerce Committee announced that it would be holding a markup hearing on a committee draft of a pipeline safety bill. This is the same draft that served as the basis for a hearing by the same subcommittee earlier this month. The Senate recently passed their version of this program authorization, S 2276.

There are currently 17 sections in the draft bill versus the 27 sections in the Senate bill. The following sections in the Draft bill do not have a direct counterpart in the Senate bill:

Sec. 4. Integrity management review.
Sec. 8. Direct hire authority for Pipeline and Hazardous Materials Safety Administration.
Sec. 11. Underground gas storage facilities.
Sec. 12. Requirements for certain hazardous liquid pipeline facilities.
Sec. 15. Emergency orders.
Sec. 16. Pipeline safety information grants to communities.

The following are very brief reviews of those sections listed above:

Section 4 simply requires reports to Congress on integrity management programs for natural gas pipeline facilities and hazardous liquid pipeline facilities.

Section 8 allows PHMSA to hire personnel without regards to the preference systems outlined in 5 USC 3309 thru 3319.

Section 11 is similar to provisions in S 2276 except that they would apply to all underground gas storage facilities instead of just natural gas underground storage facilities.

Section 12 would amend 49 USC 60109 by adding a paragraph dealing with Hazardous Liquid Pipelines.

Section 15 would amend 49 USC 60118 by providing the Secretary of Transportation with the authority to issue emergency orders to correct situations “involving an imminent hazard that presents a substantial likelihood of death, severe personal injury, or significant harm to property or the environment” {new §60118(f)(1)(A)(i)}.

Section 16 would amend 49 USC 60130 by making substantial changes to the requirements and restrictions associated with the administration of Pipeline Safety Grants.


As is fairly typical in Energy and Commerce Committee markups, the hearing is scheduled for two days. Obviously the Committee leadership expects there to be a large number of amendments that will be considered. No details about any possible amendments are currently available on the Hearing web site.
 
/* Use this with templates/template-twocol.html */