Monday, October 3, 2016

New EO 13650 Chemical Safety Documents

Last week the Occupational Safety and Health Administration (OSHA) updated their “Actions to Improve Chemical Facility Safety and Security” web site with a notice that EO 13650 Working Group had completed a number of new initiatives. Those initiatives included:

• The Working Group published Executive Order 13650 Regulatory Programs Overview
• The Working Group developed the Regulatory Frequent or Critical Violations resource
• OSHA and EPA published Fact Sheet: The Importance of Root Cause Analysis During Incident Investigation
• OSHA published Fact Sheet: The Use of Metrics in Process Safety Management (PSM) Facilities
• OSHA and EPA published the Process Safety Management and Risk Management Plan Comparison Tool

The links in that notice all go to the same place, the EO 13650 “Completed Actions: Modernizing Policies and Regulations” web page. That page further provides links to the following useful fact sheets and program information:



There is also a link to the EPA’s Substance Registry Services web page. This page allows for a single source search capability for a wide variety of Federal resources about chemical health, safety and security information for by chemical name or CAS number.

Saturday, October 1, 2016

TSA and CFATS TWICs

Earlier this week the DHS Transportations Security Administration (TSA) published a legal interpretation notice in the Federal Register (81 FR 66671-66672) addressing the term ‘field of transportation’ as used in 6 USC 469(a). That section in the US Code requires TSA to collect a fee for conducting vetting services for a number of transportation security programs, including the Transportation Workers Identification Credential (TWIC) and the Hazardous Material Indorsement (HMI) for commercial driver’s license.

The Interpretation


While the complete legal discussion of this interpretation can be found here it is summarized in the Federal Register notice as:

“This interpretation states that the ``field of transportation'' under 6 U.S.C. 469(a) [link added] includes an individual, activity, entity, facility, owner, or operator that is subject to regulation by TSA, DOT, or the U.S. Coast Guard, and individuals applying for trusted traveler programs.”

The actual interpretation document makes it clear that TSA intends to take the same broad interpretation as used by the DOT in using the terms ‘hazardous material employee’ and ‘hazardous material employer’. This would mean that any chemical facility that is affected in anyway by any of the hazardous material transportation regulations would be covered under this interpretation of ‘field of transportation’.

Field of Transportation and TWIC


As I mentioned in a post earlier this week concerning a potential amendment to §469(a) this interpretation of ‘field of transportation’ does not directly affect the listing in 49 USC 70105(b)(2) of who is allowed to apply for a TWIC. It would seem to indicate, however, that TSA is going to use that definition to allow personnel to apply for TWICs under provisions of §70105(b)(2)(G), the “other individuals as determined appropriate by the Secretary”.

Commentary


This seems to open up chemical facilities covered under the Chemical Facility Anti-Terrorism Standards (CFATS) program to be able require that employees at those facilities must possess a TWIC as a standard of employment. This would greatly ease the paperwork burden under the CFATS personnel surety program.


I do not see any chemical facility owner challenging the legality of this interpretation since it would not place any new burden on those organizations. I can see various labor organizations questioning this interpretation as allowing their members who do not work at MTSA regulated facilities (which are specifically not covered under the CFATS program) from being required to obtain a TWIC as a standard of employment, particularly where employees are not reimbursed for the cost of the TWIC application.

Friday, September 30, 2016

ISCD Publishes CFATS Update – 9-30-16

Today the DHS Infrastructure Security Compliance Division (ISCD) published their October 2016 CFATS Update, outlining the status of the implementation of the Chemical Facility Anti-Terrorism Standards (CFATS) site security plan (SSP) process. Even while ISCD is working on implementing CSAT 2.0 there continues to be increases in the number of CFATS facilities with authorized and approved SSPs.


August
2016
Sept
2016
Oct 2016
Covered Facilities
2,984
2,962
2,948
Authorized SSPs
3,410
3,415
3,448
Approved SSPs
2,645
2,653
2,671
Compliance Inspections
1,177
1,260
1,281

The update continues to ignore:

• Calls for a categorization of why over half of the facilities initially covered by the CFATS program have left the program;
• Calls for an explanation of why there are more authorized SSPs than there are facilities in the CFATS program;
• Calls for an explanation of how many SSPs remain to be completed;
• Calls for an accounting of how many of the facilities have failed their compliance inspections.


NOTE: All of those ‘Calls for…’ have come from this blog.

ICS-CERT Publishes Building Control System Advisory

Yesterday the DHS ICS-CERT published a control system security advisory for twin vulnerabilities in the American Auto-Matrix Building Automation Front-End Solutions application. The vulnerabilities were reported by Maxim Rupp. American Auto-Matrix has produced an update to mitigate the vulnerabilities. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The vulnerabilities include:

• Local file inclusion - CVE-2016-2307; and
• Plain text storage of a password - CVE-2016-2308


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to provide an attacker authenticated credentials to all aspects of the system.

CSAT 2.0 Update – 9-30-16

CSAT 2.0 is going live and there have been some changes on the Chemical Facility Anti-Terrorism Standards (CFATS) web site to support the change in the Chemical Security Assessment Tool (CSAT). Today the folks at the DHS Infrastructure Security Compliance Division (ISCD) published links to three new CSAT manual on the CFATS Knowledge Center web page. Earlier this week they published a list of dates for CSAT 2.0 webinars and in-person demonstrations.

New Manuals


In addition to the previously published Top Screen user manual, DHS has now also published:


NOTE: I am having problems downloading the CSAT Portal User Manual. I’m sure that this is a temporary problem. It does not appear that it is a problem with the link, the document is just taking a long time to successfully load.

The Survey Application User Manual is a new manual. It describes how various parts of the CSAT application work.

The CSAT web site has not yet been updated to show these new manuals. They are currently only available on the CFATS Knowledge Center.

Webinars and Demonstrations


ISCD will be reprising their two-part webinar demonstrating the CSAT 2.0 application. Webinar 1 (CSAT Portal and Top Screen) will be held on October 12th (registration). Webinar 2 (SVA and SSP) will be held on October 13th (registration).

ISCD will be holding a number of live demonstrations of CSAT 2.0 at cities around the country. The current schedule includes:

• Boston, MA – 10-25-16 (registration);
• Tampa, FL – 10-27-16 (registration);
• Chicago, IL – 11-15-16 (registration);
• New Jersey – TBA;
• Los Angeles, CA – TBA;
• Houston, TX – TBA;
• San Francisco, CA – TBA; and

• Portland, OR – TBA

Coast Guard Announces NMSAC Meeting – 10-18-16

Yesterday the Coast Guard published a meeting notice in the Federal Register (81 FR 66977-66978) for a two-day public meeting of the National Maritime Security Advisory Committee on October 10th, 2016 in Leesburg, VA. There will be a webcast of the meeting as well as a teleconference link.

Topics of specific interest to readers of this blog will be addressed on the first day of the meeting. They include:

• Extremely Hazardous Cargo Strategy;
• Transportation Worker Identification Credential;
• Facility Security Officer Regulation and Training; and
• Regulatory Update.

There is no indication in the notice that advance registration is required to attend, view the web cast (https://share.dhs.gov/​nmsac/​) or listen to the teleconference connection (1-855-475-2447; pass code 764 990 20#).


Written comments on the above topics may be submitted to NMSAC for consideration. Comments can  be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2016-0499).

Thursday, September 29, 2016

Bills Introduced – 09-28-16

Yesterday with the Senate and House running back to their home districts for campaign purposes a total of 199 bills were introduced. Of those one bill may be of specific interest to readers of this blog:

HR 6227 To provide for a comprehensive interdisciplinary research and development initiative to strengthen the capacity of the electricity sector to neutralize cyber attacks. Rep. Bera, Ami [D-CA-7]


Without even seeing the wording of this bill I suspect that it has very little chance of passing in this session of Congress. It will be interesting to see, however, exactly how it is worded to see if it should (IMHO) be reintroduced next session.
 
/* Use this with templates/template-twocol.html */