About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



1 [1] (February 14, 2020)

handle is hein.crs/govcacc0001 and id is 1 raw text is: 




&~ ~                        riE SE .$rCh &~ ~ ~


   gogn, q              goo
   g
                  , q
   aS
   ' X
   11LULANJILiN,

Updated February 14, 2020


Chemical Facility Anti-Terrorism Standards


State and federal governments have long regulated safety
practices at facilities that store large amounts of hazardous
chemicals to reduce the risk of harm from an accidental
release. In 2006, the Department of Homeland Security
Appropriations Act, 2007 (P.L. 109-295) authorized the
Department of Homeland Security (DHS) to regulate
security practices at chemical facilities to reduce the risk of
terrorists triggering an intentional release or stealing
chemicals for use in attacks elsewhere. Congress extended
and modified this authority through the Protecting and
Securing Chemical Facilities from Terrorist Attacks Act of
2014 (P.L. 113-254). This authority is currently set to
expire in April 2020. The Administration's proposed
FY2021 budget would eliminate funding for this DHS
program.


St       .    . d a,,, ---d\
In 2007, DHS promulgated the Chemical Facilities Anti-
Terrorism Standards (CFATS, 6 C.F.R. Part 27). These
regulations require certain high-risk chemical facilities to
meet risk-based performance standards in 18 areas (Table
1). The statute does not permit DHS to require any
particular security measure. Facilities may implement any
security program or process that adequately meets the
requisite performance level for its risk level.

Each covered facility must meet standards based on its
specific risk, i.e., higher risk facilities must meet more
stringent standards than lower risk facilities.

Table I. CFATS Risk-Based Performance Standards


*     Restrict Area
      Perimeter
 *    Secure Site Assets
 *    Screen and Control
     Access
 *    Deter, Detect, and
      Delay
 *    Shipping, Receipt, and
      Storage
 *    Theft and Diversion
 *    Sabotage
 *    Cyber
 *    Response
Source: 6 C.F.R. §27.230


Most chemical facilities do not have to meet these
standards. The statute specifically excludes all facilities
defined as a water system or waste water treatment works,
owned or operated by the Department of Defense or


Department of Energy, regulated by the Nuclear Regulatory
Commission, or regulated under the Maritime
Transportation Security Act of 2002 (P.L. 107-295). Any
non-excluded facility that possesses more than a defined
threshold of any of the 322 chemicals of interest (6
C.F.R. Part 27, Appendix A) must submit information to
DHS through an online survey known as Top-Screen. DHS
uses Top-Screen data to determine each facility's risk level.
Only facilities DHS deems high risk must meet the risk-
based performance standards. As of December 2019,
approximately 42,000 unique facilities had submitted Top-
Screen data. DHS has determined that 3,310 (<8%) of these
are high-risk facilities.

DHS assigns each high-risk facility to one of four graduated
risk tiers (Figure 1). About 5% of the high risk facilities are
in the highest tier, Tier 1.

Figure I. CFATS Facility Risk Tier Distribution
                             Tier I
  I[                            1.


Source: CRS analysis of DHS data, January 2020.
Each covered facility must prepare and submit a Security
Vulnerability Assessment that describes its vulnerability to
DHS-defined attack scenarios and a Site Security Plan that
details how the facility will meet each of the 18 risk-based
performance standards appropriate for its risk tier.
Following evaluation of the Site Security Plan and an on-
site authorization inspection, DHS may issue a letter of
approval. The approved facilities must implement the Site
Security Plan and conduct annual implementation audits.
DHS inspects each covered site every two years.


The 116th Congress is considering whether the CFATS
authority should be reauthorized, modified, or allowed to
expire. The Administration's FY2021 budget proposes
eliminating funding for the CFATS program.


Tier 4
51%


*   Monitoring
*   Training
*   Personnel Surety
*   Elevated Threats
*   Specific Threats,
    Vulnerabilities, or Risks
*   Reporting of Significant
    Security Incidents
*   Significant Security
    Incidents and Suspicious
    Activities
*   Officials and Organization
*   Records