Tuesday, April 6, 2010

Article on CFATS Inspection Delays

A bit of a controversy has brewed up after Monica Hatcher of the Houston Chronicle reported this last weekend on the delays in the CFATS inspection process. Ms Hatcher reported that only 12 facilities have been inspected to date. While this should not be news to readers of this blog, it apparently caught Rep. Gene Green (D, TX), a member of the House Homeland Security Committee, completely by surprise; so much so that he is now reconsidering his previous support for the House passed HR 2868. Sue Armstrong, the acting deputy assistant secretary for infrastructure protection at DHS, explained the inspection situation to the Senate Homeland Security and Governmental Operations Committee at its CFATS status hearing back on March 3rd. A large part of the problem is due to the fact that DHS must negotiate changes in each facility’s Site Security Plan (SSP) submission to get it up to where the Infrastructure Security Compliance Division (ISCD) believes that it meets the requirements of the Risk-Based Performance Standards (RBPS). The negotiations are necessary since Congress prohibited DHS from requiring any specific security measures as a pre-requisite for SSP approval. According to a subsequent article by Ms Hatcher, Rep. Shirley Jackson-Lee (D, TX), is planning on holding hearings in the Sub-Committee she chairs, the Subcommittee on Transportation Security and Infrastructure Protection, on the reasons for the delay. As a co-sponsor of HR 2868, she is concerned that these delays will further justify delays in considering and ultimately passing HR 2868 in the Senate. Inspection Delay’s Were Inevitable Actually, these delays could easily have been foreseen by anyone that has done any sort of compliance inspections. The complexity of the RBPS, the wide variety of the facilities that are covered under CFATS, and the restrictions that have been placed upon DHS by the Congress (including late funding of inspection personnel in the early part of the program) have all worked to make this a much more complex process than most people apparently expected. At this point the only thing that is going to make this go any faster will be a drastic scaling up of the number of facility inspectors. With 6,000 facilities to inspect, 50 weeks per year available for inspections, that means that there will have to be 120 inspections per week to get to every facility within a year. If you have a three person team conducting each inspection (a small number for the largest facilities, but probably too many for the smallest facilities) you would need at least 360 trained inspectors. That is assuming that they were able to complete one inspection per week Given the need to preview the negotiated SSP in detail before the inspection, and to compile and prepare the post inspection report; a week is probably too little time. Add to this the need for re-inspections, compliance assistance visits, and the inevitable other requirements that crop up in a government organization; and you probably really need 500 trained inspectors along with a substantial support staff. Oh, by-the-way, Ms Armstrong has mentioned a number of times the difficulties that the Department has been having getting qualified personnel through the lengthy and bureaucratic Federal hiring process. Oh yes, did I mention that each inspector must go through a 14 week training program since there is no pool of chemical facility security inspectors to hire from? In short, everyone is just going to have to accept that the facility inspection process is going to take at least two years to complete. And DHS intends to re-inspect Tier 1 facilities every year and Tier 2 facilities every two years. Secretary Napolitano needs to go back to Congress for more head count. ISCD is going to need it. Or, you could have DHS opperate like OSHA and EPA, do an inspection only after there is a terrorist attack. Then you can fine the facility while you’re counting the dead bodies.

White House Homeland Security Page Updated

The White House made a change to their Homeland Security page, adding a link to the recently released “Surface Transportation Security Priority Assessment”. This report was prepared by the Transportation Sub-IPC, a sub-committee of the National Security Staff’s Transborder Security Interagency Policy Committee (IPC). According to the Executive Summary: “The study identified a set of 10 issue areas to examine, obtained input from surface transportation sector stakeholders, and analyzed the responses to reach a consensus set of priorities and recommendations.” As with most high-level policy guidance documents, this assessment is long on generalities and short on specifics. It looks at 10 issue areas and produced 20 recommendations. The level of generality is probably exemplified by the 8th Recommendation:
“Reemphasize National Infrastructure Protection Plan (NIPP) framework priorities with the Sector-Specific Agencies (SSA); surface transportation owners/operators; and State, local, tribal, and territorial (SLTT) partners in order to focus development and implementation of a relevant and representative model that enhances security of the Transportation Systems Sector partners.”
While much of the program outlined in this document can be implemented by the Obama Administration without additional Congressional input, there will have to be some legislative work done to provide the necessary authority and funding to execute the general proposals outlined in this document. Unfortunately, the methodology outlined in the document for producing these proposals did not seem to include any legislative input. It will be interesting to see if there is any concrete action taken by the Administration to make any progress on implementing these recommendations.

Sunday, April 4, 2010

FRA’s National Rail Plan Ignores Security

The Federal Railroad Administration published a request for comments on their National Rail Plan (NRP) on Monday, in the April 5th, 2010 (actually published on the Internet on the previous Saturday - yesterday) Federal Register. The development of the NRP is a new responsibility for the FRA, the requirement having just been established in the Passenger Rail Investment and Improvement Act of 2008 (PRIIA). Last fall the FRA had submitted a Preliminary NRP to Congress as required by PRIIA. A copy of that document is available on the FRA web site. According to this request for comments that preliminary plan “set forth FRA's proposed approach to developing the long-range NRP, including goals and objectives for the greater inclusion of rail in the national transportation system” (75 FR 17203). FRA Plan Ignores Freight and Passenger Security I cannot find a single mention of any security issue in either the request for comments or the preliminary plan. I understand that the Transportation Security Agency is the lead agency for all transportation security issues, but both documents address environmental issues that fall under the purview of the Environmental Protection Agency. To make matters worse, the FRA lists 46 agencies and groups that will be included in their outreach effort (Appendix A, Preliminary National Rail Plan). That list includes Federal Agencies like the Department of Housing and Urban Development, State and local government groups, and private industry and labor organizations. The one agency that is pointedly missing in their out reach effort is the Department of Homeland Security. Any plan that purports to chart the future course of development of the nation’s rail infrastructure, yet fails to take into account the efforts necessary to protect those systems from terrorist attack is short sighted and self-defeating. Railroads and their customers will be spending time and energy in protecting their passengers and freight from terrorist attacks. Failing to take into account those efforts and resources will certainly result in other components of the plan from coming into fruition through lack of available resources. Suggestions for Additional Questions The request for comments provides a list of questions that the FRA would like to see addressed in the public comments on the NRP. The questions are broken into ten categories. There are additional security related questions that should have been asked for most of these categories. The questions posed below are examples of the types of questions that could have been asked and are certainly not exhaustive. The proposed questions are tied into existing categories.
1. Strategies for funding. What sources of funding will be available for the implementation of security practices necessary to prevent terrorist attacks? Would protection of passengers from terrorist attack be better funded by private or governmental organizations? When there is a conflict between funding necessary counterterrorism activities and expanding other rail services, which should have higher priority? 2. Passenger service on freight rail lines. Who will be responsible for protecting passenger trains from chemical releases from attacks on freight railcars on adjacent tracks? How often will TIH railcars be forced to be stopped on unsecure rail sidings waiting for passing passenger trains? 5. Transportation safety issues. How much money should be spent on strengthening TIH railcars? How long should current railcars be allowed to be used instead of being upgraded to safer TIH railcars? 7. Land use issues. How will small community safety be weighed in determining the proper routing of TIH railcars? How much money should be set aside for moving rail yards out of urban areas to reduce the threat of terrorist attack on TIH railcars in those rail yards?
Reissue NRP Request for Comments The FRA’s inability to consider the security issues involved in their development of a National Rail Plan greatly compromises the utility of that planning effort. FRA should seriously consider withdrawing their request for comments. Once withdrawn they could actively work with TSA to address security issues that will affect the effective development of a National Rail Plan. Only then can the FRA develop a NRP that actually will have some reasonable chance to guiding the future development of the rail transportation infrastructure in the United States.

Saturday, April 3, 2010

Chem Sector Security Summit Web Page Update 03-26-10

Late Friday afternoon, DHS updated their web page for the 2010 Chemical Sector Security Summit. While I noted last November that DHS had gotten an early start on advertising their annual chemical security summit, they are about a week later this year than last in announcing the preliminary agenda and providing registration information. Announced in this updated page is a similar registration restriction to that implemented last year. There will only be three reservations allowed for each organization. This is being done again this year to ensure that every organization that wishes to have someone attend will have the chance to do so. There is a link to both the registration web site and to the Hotel web page for the Summit. There is now a link to a preliminary agenda for the meeting. Many of the presentations will be about similar topics to last year's, but will reflect changes that have occurred since last June’s meeting. For example both ammonium nitrate regulations and the background checks were discussed last year. Hopefully this year there will be discussion of an upcoming final rule for the ammonium nitrate program and a description of the actual background check tool. There are some new topics that will be discussed at this year’s meeting. Cyber security and control system security will be addressed in two separate presentations. IST will be covered in a presentation and a panel discussion, reflecting the new DHS interest in this subject. And, of course, there will be a discussion of how the inspection process is progressing. Once again, this looks like a meeting that will be well worth attending.

Reader Comments 03-30-10 Water Security

It’s been a busy week and I missed mentioning two comments posted to my earlier blog about water facility security. Bob Radvanovsky, who brings us WaterSec List, posted both comments and they are well worth reading. Security and Bond Ratings Bob’s first comment looks at the ‘compliance vs security’ issue, noting that in many cases following the rules does not mean that the facility is secure. In that posting he makes an interesting observation that I haven’t seen before, writing: “In most cases, these organizations would loose their bond ratings if they were to admit that they had a security flaw or vulnerability, so instead, do nothing.” I’m pretty sure that Bob is right, any adverse information about the facility could have an effect on their bond rating and that rating is very important to any organization that must rely on the sale of bonds to finance capital improvements. I’m not sure how bond rating organizations would find out about adverse security reports since they are ‘classified’ SSI and should be protected against disclosure. Having said that, I would be interested in hearing if any of the public water treatment facilities that were mentioned in the CAP Chemical 101 report have had their bond ratings affected by that listing. An interesting side light to that question relates to funding for security measures. If a water treatment facility had to execute a major capitol project to effect a mandated increase in security (like substitute sodium hypochlorite for chlorine gas), would that have an effect on the bond rating for the facility? One could argue that the improvement would reduce the risk associated with the facility and that should improve (or at least be neutral to) the facility bond rating. On the other hand, it does point out a severe security issue that would remain while the project proceeded (which could take a couple of years in some cases), so that might temporarily decrease the facility bond rating. Another possibility would be that the new security related capital project could adversely affect the bond rating by increasing the amount of borrowing for the facility to a level that would have an effect on the bond rating. In the normal course of events this project would not be pursued until other projects were paid off, but if the project were mandated by the Federal (or State under the current version of HR 2868) government, that might not be possible. This should be part of the economic evaluation of the projected IST implementation. Insider Attacks In his second post Bob writes that: “This, to me, represents a form of sabotage, and perhaps someone internally who knew the base operations of the organization and what impact this would have on the sudden removal of said equipment.” He also notes that, with the recent increase in radical militias, there might be an expected increase in the potential for insider attacks on facilities. One explanation is a non-terroristic action; employees might have realized that the manual operation of the facility would result in more overtime work to affect the manual operation of the facility. This would mean increased paychecks for those employees. Another explanation, much more threatening, would be that if there were an insider working for or with a terrorist organization, the lack of electronic supervisory control would make it easier to undertake a serreptious attack that would allow for contamination of the drinking water leaving the facility. I’m not sure how successful this would really be with the on going investigation of the ‘theft’, but it would be an interesting attack profile.

Friday, April 2, 2010

Reader Comment 04-01-10 LEPC Response

Jim Lupacchino, from Day & Zimmermann Security Services, responded to a blog posting from last week that had been continuing the discussion of hazard communication. Jim wrote: “I respect the spirit of your commentary. Recognizing that wind speed, humidity and dispersion rates impact the spread of a "threat cloud", I would suggest that there are companies that work with chlorine and anhydrous ammonia that are in close communication with LEPCs'.“Perhaps the LEPCs' could stand up and recognize the companies that share the risks of onsite poison inhalation hazards and demonstrate corporate citizenship in their respective communities.” I agree that there are almost certainly companies out there that do a good job of keeping their neighbors informed about their on-site chemical hazards. Unfortunately those companies seldom make the news for their communications skills. This is the reason that I wrote the posting that started the original discussion; they do deserve recognition, both from their communities and others in the industry. When I see news reports about this type of pro-active community outreach, I will certainly recognize it. It does seem to me that most companies seem to be trying to take the tack of remaining invisible. They do everything that they can to stay below the level of public perception. A lot of this has to do with the bad press that the chemical industry gets when individual facilities do a bad job of handling information sharing during incidents. Bayer CropScience got a lot more bad press for their handing of their Aug 2008 incident than Barton Solvents got good press for the proactive way they handled the results of their catastrophic fire in Kansas City in July 2007. Having said that, every company that holds significant quantities of release toxic COI has a legal and moral obligation to keep their potentially affected neighbors fully aware of the potential hazards from those chemicals and how to respond to potential releases. Trying to educate the public during a catastrophic release is a waste of time and could get hundreds of people killed. Hunkering down and ignoring the press when outsiders point out the hazards in ways that are designed to get people upset only ensures that the public gets a one-sided presentation of the hazard. And it certainly won’t do anything to help prevent a panic in the event of a significant yet non-catastrophic event. I agree with Jim that local LEPC’s should let the public know when facilities are cooperative and proactive in providing emergency response planners with the necessary information needed to get their jobs done properly. They also need to blow the whistle when that cooperation is not forth coming, the point made by Fred Millar in his earlier comment. What we really need is a spirit of cooperation and communication between high-risk facilities and their neighbors. After all, they are inexorably tied together; that is what makes the facility at high-risk of being a terrorist target and what puts the community at risk for the consequences of a terrorist attack.

Thursday, April 1, 2010

Methyl Bromide Continues

Back in late November of 2009 I posted a blog entry about the EPA’s proposed rule for providing another one-year exemption on the planned phase out of methyl bromide. There were a large number of responses to that proposed rule posted to the Regulations.gov web site (Docket #EPA-HQ-OAR-2009-0351), and I have not had the inclination to review them. I’m not so much concerned about the environmental impact of the continued use of methyl bromide (though that is of concern, just not really appropriate to this blog), as I am about the fact that DHS pulled methyl bromide from their list of release toxic COI based on the fact that it wouldn’t be around long enough to require facilities producing/storing the material to protect it against terrorist attack. Well, the proposed rule has made its way to the OMB. Yesterday, according to the RegInfo.gov web site, the EPA submitted the proposed rule for their consideration. This is significantly later than EPA had planned to get the Final Rule published (in December according to the Fall Regulatory Agenda), but these things do take time. It will be interesting to see how long the OMB sits on this rule and how that will affect methyl bromide use in this spring’s planting season (that probably already started in California). In any case, this continued saga again calls into question DHS’ decision back in 2007 to remove this toxic inhalation hazard chemical from their list of chemical of interest.
 
/* Use this with templates/template-twocol.html */