Wednesday, March 17, 2010

Security Incentives

I love the internet and Google; otherwise I never would have run across this interesting article at JournalOfAccountancy.com: “Growing Opportunities: The Agricultural Chemical Security Credit”. Actually I wrote about this tax credit when it was included in the 2008 Farm Bill, but it is interesting to see it rise to the surface now. This tax credit effectively refunds 30% of covered measure security implementation costs up to a maximum of $2 million per year. That is a lot of security measures. Now, of course, this is limited to chemical security measures for agricultural products and has a number of limiting factors. But, it does go to show how strong the Farm Lobby is in Washington. This credit was added to the Farm Bill when it became obvious that DHS intended to include a number of agricultural chemicals in their list of chemicals of concern (COI). This would lead to many distributors and users of these chemicals falling under the Chemical Facility Anti-Terrorism Standards (CFATS). This was after they lost the fight for these to facilities to be excluded. While a number of people have complained about the power of the chemical industry lobbyists to prevent costly legislation from passing, this once again demonstrates that the chemical industry is made up of rank amateurs when it comes to the business of lobbying. Maybe it is time for the K Street Chemists to start thinking about giving up the fight against some of the proposed chemical security rules and start fighting for tax breaks instead.

Tuesday, March 16, 2010

HR 4842 Mark-Up

Today the Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology of the House Homeland Security Committee held a hearing to markup the recently introduced DHS Science and Technology Directorate Authorization bill, HR 4842. A number of minor amendments were adopted by voice vote and the Subcommittee favorably reported the amended bill to the full Committee. Chairwoman Clarke (D, NY) explained that the purpose of this legislation “is to ensure that the Science and Technology Directorate has the right tools available to be successful”. She further explained that success “means delivering products into the hands of our first responders, law enforcement officials, or critical infrastructure owners to help them achieve their mission and make America more secure”. Amendments were offered by Rep. Austria (R, OH), Rep. Kilroy (D, OH), Rep. Sanchez (D, CA), and Rep. Lujan (D, NM). All were passed on a voice vote with no demands for recorded votes. In today’s political climate this is a remarkable showing of bipartisan support for this legislation.

Two of the amendments might be of interest to the chemical security community. Ms Kilroy’s amendment added a new research program requirement to “develop and support cyber forensics and attack attribution” to §404(b). As part of the cyber security incentives research the S&T Directorate is required to under take with the National Research Council, Ms Sanchez’ amendment would include “analysis of the current marketplace and recommendations to promote cybersecurity insurance” in §405(b).

3 Reader Comments 03-15-10 SSP Experience

I got three different responses to my earlier post about Dick Sem’s thoughts on the SSP process. The first came from a long-time reader Edward Clark, the second from another security consultant that has apparently been reading the blog for a while, Jim Lupachinno. Finally Dick had a gracious response and new comment. All three comments are appended to the end of that blog post and are well worth reading. Both Ed and Jim had generally favorable comments about the SSP process, with both noting, however, that improvements can obviously be made to the program. Ed notes that CFATS “does allow the skilled security analyst [emphasis added] to assess the risk and implement appropriate mitigation strategies”. Dick acknowledges that, but notes that many facilities do not have such a person on staff and are attempting to complete the SSP using someone in-house without significant security training like the EH&S Manager. Jim emphasizes that the SSP process draws information from a number of different disciplines within the covered organization. He notes that:
“Sales, Human Resources, and Customer Service uniquely impact COI security at different phases of the inventory or production cycle. One effect of SSP interaction with support departments can be the bridging of ‘silos’ within some organizations.”
He also notes that communications with the emergency response community is necessary to answer some of the questions posed in the SSP. This communication “exchange contributes to a more thorough understanding of the challenges first responders face specific to the facility's COI”. This is another positive aspect of the SSP process. I urge all readers interested in the CFATS process to go back and read all three postings from these security professionals. I’m sure that these are not the only opinions out there on efficacy of the SSP process. I (and my reader presumably) want to hear about problems and challenges that facilities are having in their completion of the SSP. Those observations may lead to improvements in the methodology.

HR 4842 Introduction – DHS S&T Authorization Bill

On Monday, Rep. Yvette Clarke (D, NY), Chairwoman of the House Homeland Security Committee’s Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology, introduced HR 4842, the Homeland Security Science and Technology Authorization Act of 2010. Chairman Thompson (D, MS) and the ranking member on the subcommittee, Rep. Lungren (R, CA) are co-sponsors of HR 4842. This bill would authorize the DHS S&T Directorate for FY2011 and FY2012. There are a number of provisions of this bill that will be of interest to the chemical security community. Cybersecurity R&D Section 404 of this bill calls for the S&T Directorate to conduct and support a variety cybersecurity research and development efforts. The bill would authorize the appropriation of $75 million in both FY 2011 and FY 2012 for such R&D efforts to “prevent, detect, and respond to acts of terrorism and other large-scale disruptions to information infrastructure” {§404(d)}. One of the specified efforts would be to assist “the development and support of technologies to reduce vulnerabilities in process control systems” {§404(b)(5)}. Section 405 would require the S&T Directorate to work with the National Research Council to conduct a study of incentives to encourage to private sector to increase its efforts in the field of cybersecurity. One of the areas the bill directs to be included in the study is the evaluation of the use of regulations that would impose “under threat of civil penalty best practices on system operators of critical infrastructure” {§405(b)(3)}. Chemical Security R&D Section 409 would establish requirements for R&D to be conducted by the S&T directorate in the areas of chemical and biological threats research. Specifically for chemical security the Directorate would be tasked to “develop technology to reduce the Nation’s vulnerability to chemical warfare agents and commonly used toxic industrial chemicals” {§409(d)}. Included in this would be the establishment of the Chemical Security Analysis Center. The CSAC would be tasked with “conducting risk and vulnerability assessments based on chemical threat properties” {§409(d)(1)}. Additionally the Directorate would be required to work to “foster a coordinated approach to returning a chemically contaminated area to a normal condition, and to foster analysis of contaminated areas both before and after the restoration process” {§409(d)(3)} Mark-up Hearing

The Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology has a hearing scheduled for today at 2:00 pm EDT to markup this bill.

IST Questions – Active Mitigation

This is another of a series looking at how DHS might construct an Inherently Safer Technology Assessment Tool (ISTAT) for the Chemical Security Assessment Tool if Congress were to include a requirement for conducting an IST assessment as part of their legislation to make the CFATS program permanent. The other postings in the series were:

An IST Tool for CSAT
Reader Email – 03-04-10 IST Rules
IST Questions – Inventory Management
IST Questions – Chemical Substitution

 As I explained in the initial posting in this series active mitigation systems include automated, active safety systems that chemically or physically modify an RTCOI so that a catastrophic release of the material does not have a significant effect outside the facility boundaries. The main controversy with these systems is their reliability in the destructive environments associated with terrorist attacks. Because of this controversy, the initial questions will establish the efficacy of the system.

Chemical Neutralization 

The initial questions will establish the existence of chemical reactions that will convert the RTCOI to a chemical that does not present the same vapor phase toxicity. Follow-up questions will look at how quickly the reaction proceeds and examine the byproducts, chemical and physical, of that reaction. Finally the questions will examine if it is possible to design an automated system to effect the chemical neutralization that does not require operator action and will proceed in the event of loss of power or computer control.

Once the effectiveness of the neutralization system is established, the cost of the system will be established. As in earlier process changes that require new equipment these questions will address engineering estimates for the costs of these installations. As with any preliminary estimates they will include known costs (e.g.: list cost of storage tanks) plus a standard engineering markup to cover installation costs. DHS would have to establish a standard method for determining that markup.

Physical Neutralization 

Typically physical neutralization systems convert the vapor phase of an RTCOI into a form that would not leave the confines of the facility; the most common is one that uses a solvent spray to dissolve the released toxic vapor. The initial questions will look at the efficacy of the spray system, establishing the amount of solvent necessary to knock down a catastrophic release of the material from the single largest container on site. Subsequent questions will establish how the system will be designed to remain effective if power systems are shut down by the terrorist attack. Again, once the efficacy of the proposed system was established the costs of the system would have to be examined.

100% Efficacy? 

One political question that would have to be addressed with this type of IST program is whether or not the neutralization system would have to achieve 100% neutralization to be considered an adequate IST system. The argument can be made that reducing the amount of the RTCOI that leaves the facility to an amount less than as the Tier Reduction Quantity (TRQ) or the Facility Elimination Quantity (FEQ) established for that facility would be a sufficient risk reduction to meet the requirements for the current language in HR 2868. Thus 100% efficacy would not be required for these systems.

Monday, March 15, 2010

Greenpeace Chemical Security Campaign

Greenpeace continues to roll out new variations on their messages calling for grassroot support for new, comprehensive chemical security legislation. The current campaign builds on their “Don’t Let the ‘Crazies’ Fool You” campaign that uses the latest zombies movie to stand as a symbolic exemplar of the hazards associated with dangerous chemicals. Each new variation brings a new round of social network site (Twitter and probably FaceBook) responses that spread the word virally around the internet. It is hard to tell from the outside how well this translates into clicks on the form emails to Representatives and Senators, or maybe more importantly, how well it gets contributions to the Greenpeace political coffers. Their campaigns do not call for contributions to Greenpeace, but I would be very surprised is such contributions did not track their efforts. Political Exaggerations I have chided the chemical industry opposition to HR 2868 for some of their exaggerations, so it is only fair that I point out that Greenpeace is guilty of the same type of political shenanigans. For example, in their latest piece touted on Twitter (though the actual web page may be older) they quote their standard statistic of “One in three Americans is currently at unnecessary risk from dangerous chemical plants.” While not false, this is an exaggeration of the first order based upon their failure to explain how the figure was arrived at. This ‘one-in-three’ number can be traced back to the figure of 110 million Americans ‘put at risk’ of a potential toxic inhalation hazard release due to a terrorist attack. This figure was developed by the Center for American Progress. They looked at 300 chemical facilities that reported storing large quantities of chemicals like chlorine gas and anhydrous ammonia. Using the maximum distance that a toxic cloud would spread before it became effectively non-hazardous, they then drew a circle around the facility with that distance as a radius. Counting all of the people that lived/worked within that circle provided the number of people at risk for that facility. While everyone within that circle is potentially at risk for injury from a catastrophic release, only a small fraction could actually be possibly exposed in an actual incident. The wind disperses a chemical cloud in a fan shaped pattern. The extent of the area covered by the cloud in that fan shaped area is dictated by the wind and temperature at the time of release. In any case that fan covers only a small portion of the circle used to calculate the ‘at-risk’ population cited by CAP and Greenpeace. Furthermore, toxic exposures within that fan area will vary widely; from deadly to no effect. Depending on the physical characteristics of the toxic gas, people above the ground floor in multi-story buildings might not be affected, even within hundreds of yards of the release. Finally, the medical effects on the great majority of the personnel actually exposed would be short term effects requiring little medical care. To be sure, a catastrophic release of a large chlorine tank car in an urban area would kill a large number of people, but not anywhere near the numbers being reported by the environmental activists. Assume that it is fair to calculate that anyone within the exposure circle as being at risk, because on any given day the wind could be blowing in any direction. Even if they might not be harmed in a given successful terrorist attack, they are at risk for being harmed if the wind is blowing the correct direction. Even then the 110 million people figure is misleading. Many of these facilities are concentrated in small areas around the country. Thus their circle-of-effects overlap to a great extent. If a single person is exposed to potential injury from multiple plants, they cannot be counted multiple times in the national ‘at-risk’ pool. Finally, we need to compare these potential risks to everyday risks that people accept as a natural part of their lives. For example since they count everyone in the potential effects area as being at risk, isn’t everyone that drives on or walks along roadsides at risk for severe injuries in an automobile accident. Thus the number at risk for that (certainly over 300,000,000) readily outweighs the risk of being exposed to hazardous chemicals from a successful terrorist attack. There is a Risk Now, don’t get me wrong. There is a large level of risk for significant portions of the population from a successful attack on a large toxic inhalation hazard chemical storage sites. One way of reducing that level of risk is to change over to less hazardous chemicals where possible and appropriate. There are also other ways that are nearly as effective given the actual probability of such an attack happening (based upon past history, no chance; based upon reasonable projections that such an attack could happen, some small chance). A reasonable discussion needs to take place on how to make that assessment in a way that best serves society as a whole. Trying to force that discussion based upon fear makes it very hard for the people with different ideas to take you seriously. Greenpeace, you need to come up with a better method for expressing your legitimate concerns about the real hazards associated with these materials. Until you do, your opposition will not take you seriously, and you will have little chance of affecting the political outcome.

Sunday, March 14, 2010

Reader Comment 03-13-10 SSP Experience

Dick Sem of Sem Security Management was one of the first people that I contacted when I started working on chemical facility security issues back in early 2007. I found his contact information thru an internet search. We have stayed loosely in touch since then. When he posted on LinkedIn.com that he had been working on some SSP submissions, I sent him a message, asking him to share some of his general impressions with readers of this blog. Late Saturday he left those comments appended to my recent post on the premature reports of the death of CFATS. His comments are worth reading in their entirety. He is an experienced security professional and his opinions on the process should be considered by DHS as they continue to review and update their process. 

One Size Fits All 

Dick’s ending comment is especially important. We always hear about how important it is for security measures to be risk based and how we must avoid a ‘one size fits all’ set of security requirements. In a slightly different look at this Dick writes:
“While I'm getting things off my chest, this process looks like its developers never actually saw especially small facilities with relatively limited resources. The SSP tries too much to be all things to all facilities with little concern for their size, function, location, etc. Perhaps it would have been better if there had been separate SSP's based, in addition to Tier level, upon the size of facility or type (i.e. chemical, educational, manufacturing, paper, water treatment, etc.)”
Now, I know that DHS developed all of their tools with the intention that any covered facility, regardless of size or type, could provide information about their security efforts. This means that there are many questions that will be answered “No” or “N/A” by many facilities; especially smaller facilities. I’m not sure, however, that DHS has communicated adequately that they are not expecting that facilities should be using these questions as security guidelines that must/should be followed by every facility. 

Part of the problem is, of course, caused by the Congressional restriction that DHS could not require specific security measures as a pre-requisite for SSP approval. I understand, and agree with, the underlying reason, but it does make it more difficult for DHS to communicate what is expected of facilities. 

Another problem was the short amount of time that DHS had to get this stuff all put together. There simply wasn’t time to develop separate SSP’s for each industrial sector that might have covered chemicals on-site.Though, to be fair, DHS has addressed a number of individual chemical communities with the suggestion that they develop an Alternative Security Plan process for their specific situations. Most have declined, allowing the burden to remain at the doorstep of DHS. Some individuals at ISCD have been particularly upset with the academic community in this respect. 

SSP Misnomer 

Dick Sem also points out a problem with terminology, writing about the Site Security Plan process that “And once you're done, you have a completed checklist with planned and proposed measures but no actual plan.” A number of writers (myself included) have pointed out this particular problem, but none of us have yet come up with a good solution. 

It certainly wouldn’t be practical for each facility to submit a compilation of all of the security procedures that are in use at a facility. For a larger facility this could easily run to a couple hundred pages of densely written pages explicating who does what to whom. Evaluating such documents at DHS would certainly be unmanageable with twice their current staff. 

Now, those procedures are actually more important than the SSP submission checklist when it comes to actually protecting the facility. But there is another problem with the submission of full procedures; DHS has taken the stance that the approved SSP is, in fact, an enforceable contract between DHS and the facility. Once the SSP is submitted and approved, DHS can require the facility to properly employ, train and maintain they system outlined in their SSP. Failure to do so, could result in $25,000/day fines. 

Now everyone knows that effective procedures must be living documents; constantly being updated and revised to reflect their operation in the real world. As long as such changes do not change the answers to the SSP questionnaire, facilities would have more leeway to make these modifications. If the actual procedures were submitted and approved, DHS would have to buy off on even the smallest procedural changes. 

Process Discussion One thing that we have seen is that DHS realizes that their process must also grow and evolve as lessons are learned. Comments like Dick Sem’s are an important part of the process of making the CFATS program more effective. I know that I have a significant readership at ISCD; so DHS is seeing this discussion. 

I would like to solicit comments from anyone that has been involved in the implementation process. Comments from security professionals are important, but so are comments from security managers of facilities that are going it alone, without advice from security professionals. System integrators and vendors will also have valuable inputs to this discussion. We do have to worry about CVI issues in this discussion. While I have decried the overuse of ‘Anonymous’ in posted comments, I would much rather have that than names that can be linked back to a single facility. And please, let’s keep the discussion generic so that no facility’s security is compromised.
 
/* Use this with templates/template-twocol.html */