Friday, December 12, 2008

More on the SOCMA SVA Problems

Last week I noted that SOCMA was reporting that some Tier 4 facilities were having problems getting DHS to accept the SOCMA SVA as an alternative SVA (see: “Alternative SVA Problems”). I have yet to hear back from SOCMA, but now PharmTech is reporting some additional information on the issue. The article quotes a SOCMA spokesman as saying:
“Upon recent discussions with DHS, we have learned that our tool may provide only limited amounts of data necessary for submission to DHS. In fact, it seems clear to us that no SVA other than DHS’s own will provide complete assurance to members that all data necessary for collection under this CFATS requirement will be sufficient. This is a last-minute reversal of what we have been led to believe.”
CFATS Requirements for Alternative SVA Section 27.235(a) sets for the requirements for an alternative SVA. It requires that
“The Assistant Secretary may approve an Alternate Security Program, in whole, in part, or subject to revisions or supplements, upon a determination that the Alternate Security Program meets the requirements of this Part and provides for an equivalent level of security to that established by this Part.”
In the preamble for the final interim rule (page 69) DHS provided some additional explanation for the Alternate Security Program (ASP):
“Tier 4 facilities may submit for review and approval the Sandia RAM for chemical facilities, the CCPS Methodology for fixed chemical facilities, or any methodology certified by CCPS as equivalent to CCPS and has equivalent steps, assumptions, and outputs and sufficiently addresses the risk-based performance standards and CSAT SVA potential terrorist attack scenarios” (emphasis added).
The CCPS Methodology outlined in Guidelines for Analyzing and Managing the Security Vulnerabilities of Fixed Chemical Sites (2003) provides guidelines for analyzing attack scenarios (pages 132-6) and provides a form for the analysis (pg 190), it does not identify particular scenarios. I would assume that the SOCMA tool deals with attack scenarios in essentially the same way. If users of either tool do not use the same attack scenarios that are included in the DHS SVA for the particular COI for that facility, DHS could request additional information for the missing scenario(s). Since SOCMA is not answering my direct questions, I do not know for sure what problems users of their SVA tool are experiencing with their ASP submissions. The attack scenario issue could be a problem using these ASPs. There could be additional information missing from these methodologies that are required for the CSAT SVA. I have not had a chance to do a line-by-line comparison of the CCSP SVA vs the CSAT SVA. DHS Adhering to the Letter of the Law It should not be surprising that DHS would be adhering to a strict interpretation of the provisions for ASPs. DHS has come under a great deal of criticism for providing special treatment to facilities because they are part of ‘voluntary industry security programs’ (see CAP report Chemical Security 101, page 26 for example). The new Congress will certainly be scrutinizing the implementation of the CFATS rules as they discuss permanent legislation to replace the temporary CFATS authorization. I’ll continue to try to get more information from SOCMA about the problems facilities are having with their ASP submissions. Additional information from the readership would also be appreciated.

Locals Look at Transportation Security Rule

There is an interesting article on SpotLightNews.net concerning how the recently published Rail Transportation Security Rule. It looks at how the new rules, which go into effect on December 26th, will affect local rail operations in Columbia County, Oregon. The most important piece of information found in this article is in the first few paragraphs. The second paragraph notes that:
“(Mike) Eyer is the sole hazardous materials compliance specialist for the Oregon Department of Transportation’s Rail Division, and the burden for making sure the state’s 200 or so handlers of hazardous cargo run safe operations over every inch of Oregon’s steel rails falls squarely on his shoulders.”
New Inspectors The article then goes on to report that Mr. Eyer is contracted to do the same inspections for the FRA, implying that he is the only hazmat compliance inspector operating in Oregon. It later notes that the inspection burden is being eased by the new regulation because the “rule provides an infusion of 200 new Federal Railroad Administration inspectors”. It would be unusual for a TSA regulation to provide for new FRA inspectors since these two organizations are in completely different cabinet departments. The only reference I can find in the rule to new inspectors is found in the discussion of comments about the chain of custody requirements. In response to a question from members of Congress about the small number of TSA inspectors available to enforce the rule, TSA reports that “TSA has deployed the 100 inspectors provided for by Congress in the Department of Homeland Security Appropriations Act for fiscal year 2005 (Pub. L. 108-90)” (page 72151). The preamble goes on to explain that these inspectors are deployed in 19 field offices and “cover the key rail and mass transit facilities in their regions”. It is clear that these inspectors will be charged with inspections and enforcement activities in support of this new rule in addition to their regular rail transport security duties. Lack of Enforcement Capability TSA identifies 241 rail hazardous materials facilities that will be affected by this regulation. This means that these facilities will fall under the inspection program for TSA for the first time. This is a significant increase in work load for those 100 TSA inspectors. This will be aggravated by the fact that the geographic distribution of these facilities almost certainly does not match the current distribution of inspectors in the 19 field offices. As the article notes, this is not an unusual situation. Congress has been remiss in authorizing an adequate head count for enforcement activities when they require that the executive branch write and enforce new regulations. The executive branch shares some culpability in that they do not request additional headcount when they submit their budget requests. In any case, come December 26th both Congress and DHS will point with a certain amount of pride at the additional layer of security that they have provided to the public with these new rules. But, without an adequate number of TSA inspectors to go out and look at hazmat rail facilities, to assist in the implementation and enforcement of these new rules, there is no assurance that these new rules will accomplish anything but add more paperwork to the system.

Thursday, December 11, 2008

More Thoughts on Security Forces

Earlier this week I looked at comments submitted on the Draft Risk Based Performance Standards Guidance document in two separate blogs. One comment that was found in a wide variety of submissions was the concern about the apparent requirement for facilities to have armed guards. Today I thought that I ought to take another look at what RBPS #4 says about security forces and Metric 4.5 in particular. Protective Forces Discussion in RBPS #4 RBPS #4 deals with the requirement to deter, detect, and delay a terrorist attack. The discussion of security measures in RBPS #4 actually has very little to say about security forces. There is just a single short paragraph (pages 52-3) that I’ll quote in its entirety here:
“Protective forces are often used to enhance perimeter security and provide a means of deterrence, detection, delay, and response. Such forces can be proprietary or contracted, and can be armed or unarmed. They may be qualified to interdict adversaries themselves, or simply to deter and detect suspicious activities and to then call local law enforcement to provide an interdiction.”
Appendix C adds very little to the discussion of security forces. In fact, the paragraph on page 144 describing the use of security forces is the same as that found in RBPS #4 with the addition of a single sentence. That sentence adds very little to the discussion as you can see here:
“Protective forces can be used in a variety of ways, including standing post at critical assets, monitoring critical assets using remote surveillance, or conducting roving patrols on a documented schedule that specifically includes identified targets, processes, or assets.”
The discussion in Appendix C does provide a brief discussion of the security considerations for security forces. Again, the entry is short enough to be quoted in its entirety here:
“No matter how they are deployed, protective forces alone generally do not provide sufficient perimeter security. Accordingly, if a facility employs protective forces, they likely will need to be used in combination with one or more of the other measures listed above to provide an appropriate level of security to meet the Restrict Area Perimeter performance standard.”
There is certainly nothing in any of this discussion that would lead anyone to believe that DHS is requiring anyone to use armed guards. So, where does the concern come from? To answer that we need to look at Metric 4.5. RBPS Metric 4.5 Metric 4.5, Interdiction by Security Forces or Other Means, provides separate standards for Tier 1, Tier 2 facilities and a combined standard for both Tier 3 and 4 facilities. The difference between the standards can be found in the first sentence. That difference between them is highlighted below:
Tier 1 – “The facility is extremely likely to be able to detect and initiate a response to armed intruders resulting in the intruders being interdicted before they reach a COI target asset or other potentially critical target.” Tier 2 – “The facility is likely to be able to detect and initiate a response to armed intruders resulting in the intruders being interdicted before they reach a COI target asset or other potentially critical target.” Tiers 3/4 – “The facility has some ability to detect and initiate a response to armed intruders resulting in the intruders being interdicted before they reach a COI target asset or other potentially critical target.”
The remainder of each metric is the same for all four tiers.
“This capability may be achieved by a facility security force, sufficient delay tactics to allow local law enforcement to respond before the adversary achieves mission success, standoff distances (for VBIEDs), process controls or systems that rapidly render the designated COI target asset(s) or other potentially critical target non-hazardous even if a breach of containment were to occur (e.g., a rapid chemical neutralization system), or other equivalent measures. If security forces are used, they may be contract or proprietary, mobile or posted, armed or unarmed, or a combination thereof.”
The phrase that is of concern to commenters is “interdicted before they reach a COI target asset” combined with the mention of potentially armed security forces in the last sentence. Purpose of Site Security Plan Before we proceed with this discussion we need to take a reality check and examine the whole purpose of completing the site security plans that the RBPS Guidance document is designed to support. The purpose is not to fulfill the requirements of the CFATS regulations. The purpose is to prevent a successful terrorist attack on high-risk chemical facilities. What constitutes a successful terrorist attack depends on the chemicals involved at that facility. For facilities with release toxic COI a successful attack would be a toxic cloud leaving the confines of the facility and causing serious injures or deaths in the surrounding community. For facilities with a release flammable or explosive COI, a successful attack would be a release and resulting explosion that would spread damage, injuries and death beyond the facility perimeter. For these facilities the purpose of the SSP is easy to see; prevent death and injury in the surrounding community. For facilities with theft/diversion COI it is less obvious what constitutes a successful attack. Does the facility have to prevent the COI from leaving the facility? Or, should the standard be related to the prevention of death and injuries in the larger community. I think that the prevention of death and injury in the greater community is the true purpose. With that in mind, a successful attack is prevented if the terrorists are intercepted by police forces after leaving the facility, but before they can combine these chemicals into an effective improvised explosive device. The Meaning of Interdiction With this clearer definition of the purpose of the Site Security Plan, we can take a more informed look at what ‘interdiction’ means. In the simplest of terms, ‘interdiction’ means stopping a terrorist attack before it becomes successful. Again, depending on the facility and the COI involved this could mean radically different things. This could include mitigation measures that prevent the effects of a release from spreading beyond the facility boundaries or providing protection to the potentially affected population. For most facilities with release COI ‘interdiction’ is going to mean stopping the terrorist attack from reaching the storage areas where the COI is found. Unfortunately, there is no known combination of barriers and sensors that is capable of stopping a determined group of terrorists. The best that can be hoped for is that the visible barriers and security procedures make the facility an unattractive target (Deter). Lacking that, those security measures need to be able to identify an impending attack as early as possible (Detect) and slow the progress of the attack so that some sort of effective response can be executed (Delay). Security Forces Will Be Required For the great majority of high-risk chemical facilities with release COI, the lack of adequate mitigation options is going to require that the attacking terrorists are physically intercepted and prevented from continuing their attack. A security response force is going to be the only tool that will be flexible and adaptable enough stop a ground attack on the facility. The higher the risk to the surrounding population associated with the COI stored at the facility, the more likely it will be that terrorists attacking the facility will be armed. Sending an unarmed security force to intercept and stop an armed intruder would only be considered by the criminally insane or some Hollywood film maker. This is becoming an overly long discussion for a single blog posting. I’ll continue this discussion in later posts, but for now lets summarize. For high-risk chemical facilities that have release COI that could affect significant off-site populations, the site security plan is going to have to identify a combination of actions that the facility is going to take to prevent a successful terrorist attack. If there are not viable means to mitigate the effects of a catastrophic release of the COI, the facility will have to rely on an armed security response to stop the attackers from initiating that catastrophic release.

Rail Transportation Security – Shipper Security Plan

This is another in a series of blogs that will look at the requirements of the recently released final rule on Rail Transportation Security. While the main focus of this regulation is directed at railroads, there are significant provisions (49 CFR part 1580, Subpart B) that will apply to a wide variety of chemical facilities that use railroad to ship or receive ‘specified quantities and types of hazardous materials’ {§1580.100(b)}.

This blog looks at what a security plan might look like for a covered hazmat shipper. Earlier blogs in this series were:
Rail Transportation Security – RSC Requirement
Rail Transportation Security – Reporting Security Concerns
Rail Transportation Security – Rail Car Chain of Custody
Rail Transportation Security – Inspection Authority
Rail Transportation Security – Reporting Railcar Locations

On the 26th of December the requirements for this rule will be in effect for covered freight railroads, covered hazmat shippers, and covered hazmat receivers located in HTUA’s. While the rule does not specify that a security plan is required, in practice some document is going to be required at each covered facility describing how the rule will be implemented at that facility. For discussion purposes we will call this plan the Hazmat Rail Shipper Security Plan (HRSSP).

The HRSSP will only address the requirements of 49 CFR part 1580. Since the shipper facility will have rail car quantities of a PIH chemical on hand, the facility will have been declared a high-risk chemical facility and there will be a site security plan under 6 CFR part 27 (CFATS). The HRSSP will probably become an annex to the CFATS SSP. The two will have a number of requirements that will be in common, but there will be a number of requirements that will pertain only to the HRSSP and the portion of the facility that is used to load and ship railcar quantities of the PIH chemical produced at the site.

Description of the HRSSP Area

The HRSSP will only address a limited portion of the facility. That area will extend from the railroad gate through the facility perimeter, along the railroad tracks into the facility and the rail secure area where rail cars are loaded and held until picked up by the railroad. The HRSSP will probably describe this area in words and diagrams or annotations on a facility map.

The description of the rail secure area will provide a general description of the security devices and procedures that prevent access to the area by unauthorized personnel. Specific requirements for security are not outlined in the rule. Some sort of barrier fencing with locking gates for personnel and train access will probably be necessary along with some sort of intruder detection system. Video surveillance should probably suffice.

Assigning Responsibilities 

The next section of the HRSSP will probably be the section that assigns responsibility for various functions under the HRSSP. Some of the assignments will be made by job description (shift supervisor, security guard, etc) while others will be required to be identified by name. It is almost always a good idea to assign primary responsibility and at least one back-up for required action.

The first position discussed will be the Rail Security Coordinator (§ 1580.101). If the facility is part of a company with multiple covered facilities, the RSC will be appointed on a Corporate Rail Security Plan. The HRSSP will only have to identify who the corporate RSC and alternates are and provide contact information. If the facility preparing the HRSSP is the only covered facility in the organization the RSC will probably come from the facility. In that case the RSC and at least one alternate will have to be identified. The requirements for the RSC were covered in an earlier blog.

The HRSSP will define who has responsibility for reporting security incidents to the TSA Freedom Center (§ 1580.105). This will probably be assigned to a management position. The requirements for reporting security incidents was covered in an earlier blog.

The next position discussed will be the Railcar Location Point of Contact (§ 1580.103). This may be appointed to a duty position or even contracted to an outside party. The requirements for this position were discussed in an earlier blog.

Additionally, the HRSSP will define who will provide information updates on railcars to the RLPOC. The HRSSP will also identify who is responsible for inspecting railcars before they are loaded (§ 1580.107). This will probably be identified by job description.

The final position to be discussed will be the individual responsible for turning over control of the shipping railcars to railroad personnel. This will probably be identified by a job position like shift supervisor or security guard. The requirements for this position were discussed in an earlier blog.

Describing Security Procedures 

The first security procedure to be discussed would most likely be the access procedures for the HRSSP. Entrance procedures for the railroad gate will be given by reference to the general site security plan. The access procedures for the rail security area will be more detailed. Personnel with routine unaccompanied access will be identified, probably by job descriptions. Entry procedures for personnel and rail cars will be described.

Empty rail cars will be inspected for tampering and potential IED’s before entering the rail secure area. The procedure will specify who will notify the RLPOC what railcars have entered the rail secure area and when and the spot in which they were placed in the rail secure area. The procedure will specify that the RLPOC will be notified when the railcar filling begins, the amount in the railcar at any point where the filling is temporarily stopped, and the final weight of material placed into the railcar. The procedure will require that the RLPOC is notified when the full railcar is turned over to the railroad. The procedure will also detail how the RLPOC will record and maintain the data so that a request for railcar location information can be supplied within 30 minutes of it being requested.

Incident Reporting Procedures 

The HRSSP will also describe procedures to be used to deal with unusual items found during railcar inspections, intruders in and/or around the HRSSP area of the facility and any other potential security breaches described in § 1580.105(c). The procedures will include security response as well as reporting requirements. Procedures will include how to deal with personnel who claim to be TSA/DHS inspectors. The requirement to demand identification and how to verify that identification with the TSA Freedom Center will be addressed.

Plans Will Vary

Each facility will address the details of this plan in a number of different ways. The plan outlined above provides a listing of the areas that must be addressed according to the Rail Transportation Security Rule. Covered facilities will need to start work on this plan as soon as possible. The rule does go into effect on December 26th, but there is, as of yet, no indication when TSA will begin enforcing the rule.

Wednesday, December 10, 2008

More Comments on Draft RBPS Guidance – 12-05-08

This blog looks at the remaining 8 comments that were filed as of last Friday on the Regulations.gov web site for the Draft Risk Based Performance Standards (RBPS) Guidance document that would be used by high-risk chemical facilities to guide them in developing their site security plan under the Chemical Facility Anti-Terrorism Standards (CFATS). The other 11 comments were discussed in yesterday’s blog. The comments that will be discussed today come from: National Paint and Coatings Association Compressed Gas Association Labor, Public Health, Environmental and Public Interest Groups IBM Industrial Safety Training Council National Petrochemical & Refiners Association Industrial Defender Inc American Gas Association National Paint and Coatings Association Comments The NPCA believes that DHS has developed a reasonable approach to a wide variety of high-risk chemical facilities, especially facilities so designated because they posses theft/diversion COI. The NPCA suggests that the metrics associated with RBPS #1 should explicitly note the acceptability of security restricted areas as opposed to the entire facility. The NPCA believes that many of the metrics need to include more references to measures that would be appropriate theft/diversion risk facilities. The NPCA questions how the requirements for 3rd party background verification can be implemented for less than truck load (LTL) truck drivers that typically deliver theft/diversion COI. Compressed Gas Association Comments The CGA notes that many facilities in their industry are small facilities with minimal staffing that will have extreme difficulties implementing many of the suggested security procedures. The CGA would like to see clarification to a number of specific metrics to address facilities that have only theft/diversion COI on site. The CGA suggests that the TWIC program be expanded for high-risk chemical facilities outside of port facilities. The CGA notes that many companies in its organization will have a corporate security officer who will effectively be the SSO for a number of small facilities. Labor, Public Health, Environmental and Public Interest Groups This coalition of a variety of labor, public health, environmental and public interest groups has been active in lobbying for expanding the current CFATS regulations. They suggest that the RBPS fails to address the use of inherently safer technology as a means to decrease the risk to high-risk chemical facilities. They also suggest that the personnel surety programs outlined in the RBPS inadequate protect worker rights. IBM Comments IBM briefly requests that the RBPS Guidance address how facilities can share Chemical Vulnerability Information (CVI) with local agencies in ‘the course of joint training exercises’ and still maintain the security of that information. Industrial Safety Training Council Comments The ISTC believes that the TWIC credentials are an inadequate screening tool for access to restricted areas of high-risk chemical facilities in that the background check provisions are less than adequate. The ISTC would like to see explicit language that requires that high-risk chemical facilities that are also covered under MTSA are required to comply with the personnel surety RBPS. The ISTC would also like to see the personnel surety RBPS recognize procedures by which a private-sector third-party may provide personnel surety programs for high-risk chemical facilities. National Petrochemical & Refiners Association Comments The NPRA notes the tight timeline DHS is working under to get this document to the affected facilities. The NPRA does note that there is much repetitive and overlapping information in the various RBPS. The NPRA is concerned that DHS inspectors could use the metrics in this guidance document as the de facto standard for measuring site security plan compliance. The NPRA notes that it appears that the guidance was written specifically for large, integrated chemical facilities and thus does not apply well to smaller facilities with limited resources. The NPRA questions the appropriateness of the number of instances where metrics are the same for multiple Tier levels. The NPRA requests that a number of terms used in the metrics be clarified or defined. The NPRA suggests that the Guidance has expanded the requirements for background checks beyond what is required in the regulations. They note that background checks and adjudication processes are normally handled at the corporate level not the facility level. Industrial Defender Inc Comments Industrial Defender provides alternative wording for a variety of areas under the Cyber Security RBPS. This wording provides more detailed guidance for areas such as access control, cyber security controls, network monitoring, incident response, and audits. American Gas Association Comments The AGA would like to see the RBPS explicitly state that security measures required by other Federal agencies would satisfy CFATS requirements. The AGA objects to the implied requirement in Metric 4.5 for a full-time armed security force. My Comments on Comments A number of commenters noted that, in general, the RBPS seem to be written with large chemical facilities in mind, not smaller facilities. I do agree that the wording of the metrics, in particular, does seem to be slanted in that direction. I am not sure how DHS can reword those metrics to address this issue without making the document unwieldy. Perhaps they can provide a section discussing how the metrics should be viewed by a variety of smaller facilities that still fall under the high-risk definition of CFATS. The comments made by the special interest (I do not mean this in a derogatory fashion, I just can’t find a simple method of identifying this group) coalition with respect to the lack of reference to IST are important. DHS does owe it to the public to at least address the possibility of risk reduction as a potential security measure in this document. Unfortunately, I think that the political discussion contained in the submission will over shadow the legitimate case for including IST language in the Guidance. It is interesting that the special interest coalition and the NPRA can provide comments about the same issue, worker protection in the personnel surety process, and come to such widely different views about the effectiveness of the RBPS requirements. The special interest coalition has long expressed concerns that employers could use the personnel process to get rid of troublesome workers and they do not believe that the Guidance provides enough protection in this regard. The NPRA feels, on the other hand, that the Guidance goes overboard in providing for protections. A good rule in politics is that if two sides disagree with a requirement for opposite reasons, then a decent compromise has been reached. The NPRA does bring up one legitimate point in their discussion of this issue. In many instances, personnel decisions (which personnel surety certainly is) are made at the corporate level, not the facility level. This is done for a variety of reasons, but generally does provide for a higher level of worker protection because of the likely removal of personalities from process. The RBPS needs to address the centralization of this process. A number of commenters make the point that their facilities are not manned on a continuous basis and use this as a justification for exemption from some of the security requirements listed in the Guidance. There needs to be a serious discussion of this issue. On one hand it is hard to imagine a high-risk chemical facility that can maintain adequate security without an on-site security presence 24-7. On the other hand it would be difficult for many of these smaller facilities to afford even the services of an unarmed guard when the facility is closed. This goes to the basic question of who bears the cost of security. Does the company that makes a profit from the use or sale of highly hazardous chemicals have an obligation to protect the community? Does society that requires the use of such chemicals to maintain its standard of living bear the burden of self-protection? I believe that the general cost of security is a cost of doing business, the same as personnel costs, and the same as safety or pollution control. There are certain security costs for these facilities, however, that might legitimately fall under the heading of providing for the common defense, something upon which we rely on the government. Emergency response, police, fire and emergency medical, certainly falls under this heading. Perhaps we need to add security forces to the “provide for the common defense” heading.

Hazmat Routing Rule Controversy

There is an interesting article in the latest issue of Traffic World that looks at the continuing controversy surrounding the recent final rule on routing analysis and selection for rail cars carrying the most dangerous hazardous materials. The final rule was published in late November (see: “PHMSA Publishes Rail Routing Final Rule The final rule made some minor changes to the interim final rule that has been in effect since June 1st. Midnight Rule Since the final rule went into effect after the election, there are many (including reader Fred Millar who is quoted in the article) who believe this is a so called ‘Midnight Rule’; a last minute rule making effort by a lame duck administration extending its span of control into the new administration. In this particular case, that seems to be an unfair claim. Section 1551(e) of the Implementing Recommendations of the 9/11 Commission Act of 2007 (PL 110-53) required that the final rule be published by May 3, 2008. DHS instead published an interim final rule, allowing for an additional comment period. So this should not be considered a ‘last minute’ rule. Few Routing Decision Changes Having said that, I find myself in significant agreement with one point made by the opponents of this rule; it will probably have little effect on railroad routing decisions. The 27 factors that must be taken into account will make any route selection way too subjective. The analysis for any route over a couple of miles long will be too complex to review and find deficient in a legally defendable manner. This may change when TSA/PHMSA brings their computer based route analysis tool on-line (see: “Several Changes to Rail Hazmat Routing IFR”). Opponents of the Rule The Traffic World article points out that many of the opponents of this rule hope that it will be quickly overturned after the new Obama Administration takes office in January. Since the final rule was published within 60 days of the inauguration there are provisions (rarely used) for Congress to declare the rule null and void. This does not seem likely to occur given the comments made by Rep. Edward J. Markey (D-MA), one of the leading proponents of the routing selection provisions in the authorizing legislation. The article quotes him as saying: “I will be carefully watching the implementation of this law in the coming year and look forward to revisiting the re-routing issue”. Since the first route selection decisions will not be made before September 1st, 2009, it will be some time before Congress actually gets a chance to re-look at the issue. The article points out that the Obama administration could start working on a re-write of the rule when they take office in late January. Effectively, this is a pretty slim hope. The President-Elect is doing a credible job of putting his team together before the inauguration, but he is unlikely to have appointments made down to that level in PHMSA that soon. It is unlikely that any action will be taken until after the initial route analyses are completed in September. ANPRM to Use Computer Model More Likely What is more likely to happen is that if, the new computer model comes on-line as expected, there will be a move from within the staff at PHMSA to initiate an advance notice of proposed rule making to require railroads to use that tool to do their route analysis. This would be more likely to have a realistic affect on route selection than trying to force an ‘out-of-the-cities’ mandate over the objections of the railroads and shippers. In any case, this will be one of the issues that a number of people, me included, will be watching over the coming months.

Tuesday, December 9, 2008

Comments on Draft RBPS Guidance – 12-05-08

The holiday weekend must have held up a number the comments from getting through to Regulations.Gov. A full week after the end of the comment period and new comments were still being posted to the site. As of last Friday there were twenty new comments submitted. This is too many comments to review in a single blog. The list below shows the commenters that will be reviewed in this blog. The remainder will be reviewed later this week. Marathon Oil Corporation Air Liquide BP Edison Electric Institute and USWAG GB Biosciences Corporation The Aluminum Association Payne Fence Products DCP Midstream LLC The Fertilizer Institute Tectonic Engineering Lubrizol Corporation Marathon Oil Corporation Comments Marathon complains that the Guidance implies that facilities should include provisions for chemicals in the SSP other than those listed in the initial notification letter received after Top Screen submission. Marathon believes that the Guidance should explain how inspectors will use the Guidance to evaluate SSPs. Marathon believes that the wording in Metric 4.5 implies that armed security forces will be required and believes that arming security forces would be unsafe at many chemical facilities. Marathon believes that the redress procedures described for RBPS #12 cannot be applied to DHS disqualifications based on the Terrorist Screening Database managed by DHS. Air Liquide Comments Air Liquide believes that DHS should be more specific in explaining that security measures may be limited to areas in which high-risk materials are stored or handled. Air Liquide believes that DHS should remove specific numeric bench marks found in Metrics 3.4 and 13.2. Air Liquide believes that DHS should include specific time frame bench marks in the discussions for RBPS #4. Air Liquide believes that DHS does not consider other security implications of the strict vehicle parking restrictions found in Metric 3.3. BP Comments BP believes that DHS should clarify the Guidance with respect to the choice between Asset-Specific and Facility-Wide security measures. BP believes that DHS should describe the records that should be maintained as part of RBPS #18. BP believes that the suggestion in the Guidance to co-locate safety and security control systems in a command center is not always feasible. Edison Electric Institute and USWAG The Edison Electric Institute and the Utility Solid Waste Activities Group commend DHS on the development of a useful tool to help guide the development of appropriate security measures at a diverse set of facilities. GB Biosciences Corporation Comments GB Biosciences believes that the Guidance should include a discussion of the coordination with TSA for facilities that might also be hazmat shippers or receivers covered under the new Rail Transportation Security Regulations. GB Biosciences believes that it is not necessary to provide continuous escorts to personnel as implied in Metric 3.2. GB Biosciences believes that the discussion in Metric 4.5 requires the use of armed security personnel, which may be unsafe at many chemical facilities. GB Biosciences believes that the Guidance should discuss how current personnel surety procedures would interface with the requirements of RBPS #12. GB Biosciences would like DHS to clarify the role of Site Security Officer and explain if a safety professional can hold that position. The Aluminum Association Comments The Aluminum Association that the 4 Tier level associated with CFATS provides for too little differentiation between security levels required for facilities. The Aluminum Association recommends that the Guidance be submitted to an outside review by security experts. Payne Fence Products Comments Payne Fence Products believes that the discussion of perimeter barriers should be more robust and include discussion of fencing products other than chain link fences which are relatively easy to penetrate. Payne Fence Products believes that the discussion should include bullet-resistant barriers and anti-tunneling measures. Payne Fence Products believes that reliance on State Department K ratings for vehicle barriers is dated and should be replaced by references to ASTM F2656-07. Payne Fence Products objects to the inclusion of commercial sources of information and recommends that DHS use the American Fence Association web site instead. DCP Midstream LLC Comments DCP Midstream believes that DHS should explain how the department might utilize RBPS #19. DCP Midstream believes that Metric 4.5 requires the use of armed security personnel and DCP Midstream questions the safety of allowing firearms on facility property. The Fertilizer Institute Comments The Fertilizer Institute supports the provision of a Guidance document that does not establish legally enforceable requirements. Tectonic Engineering Comments Tectonic recommends that DHS include a discussion in the Guidance documents on how facilities can resolve disagreements about Site Security Plan provisions with DHS since DHS cannot prescribe solutions. Tectonic also recommends that the Guidance provides a list of acceptable Alternative Security Plans. Lubrizol Corporation Comments Lubrizol appreciates the efforts DHS made in crafting a Guidance document that assists facilities in crafting an acceptable Site Security Plan without specifying legally enforceable requirements. My Comments on Comments It amazes me the number of commenters that noted that some of the requirements were either too prescriptive or not prescriptive enough. With the number qualifiers, explanations and disclaimers that DHS has included in this document, there should be no doubt that DHS has no intention or even legal basis for requiring anyone to comply with anything in this document. That Air Liquide could argue both sides of the prescription argument in the same document is especially intriquing. The most consistent comment in these eleven submissions is the concern expressed about the apparent requirement for armed guards embodied in Metric 4.5. Ignoring for the moment my previous comment about the lack of legal specificity, these comments provide an important point for discussion; do some facilities need to reconsider their stand on armed guards. I have dealt with the issue of arming security guards in some detail in a series of blogs that I wrote back in June of this year. In particular I addressed weapons limitations and the potential for overcoming those limitations by using unconventional weapons. I urge anyone interested in this issue to read those blogs. Here I’ll just discuss the need for armed guards. First off, armed guards are not required in this RBPS Guidance document; nothing can be required by law. Even Metric 4.5, which concerns so many of the commenters, specifically mentions that either armed or unarmed guards may be used to fulfill the ‘requirements’ of this metric. So facilities can rest assured that DHS does not require armed guards. Now, having fulfilled the section 550 requirement, lets discuss reality. First off, not all facilities even need to consider armed guards. Facilities that only have theft/diversion COI only need to delay attackers long enough for local police to apprehend them before they get too far from the facility gate with their stolen chemicals. Armed guards are not required; just good communications and a police response plan. The highest risk facilities, those Tier 1, and possibly Tier 2, facilities, are going to have to take a good hard look at using armed security personnel. There is no other way that they are going to have any significant chance of stopping any half-way organized terrorist attack on their facility. There is no barrier system that cannot be overcome in minutes with a small explosive device. There is no other way to stop a team determined to enter the facility. The only other realistic alternative is to get rid of the Toxic (and possibly flammable) COI that makes the facility Tier 1. Remember, if you get a terrorist attack delayed and rely on the local police for your response force, they are going to arrived armed and trigger happy. They are not going to know the areas of the facility where the simple act of discharging a service revolver may ignite a firestorm. They are not going to pay attention to what is down range of their weapons on the other side of their terrorist target and will certainly puncture the worst possible storage tank with their stray bullets. At least with a trained security force under facility control there is a chance of avoiding the collateral damage; not a good chance, but a chance none the less. Finally, ask yourself if your facility were located in the Niger Delta, would you have armed guards patrolling the facility? If you doubt that your answer would be yes, then ask the security managers from Exxon or Shell facilities that have been attacked in those areas. They certainly have armed security forces protecting their facilities.
 
/* Use this with templates/template-twocol.html */