|
|
|
15-1: The Impact of a Significant Disruption in International Logistics
|
|
|
|
|
|
|
|
|
The extent to which world trade can be seriously disrupted by a single instance of a catastrophe should not be underestimated. The closing of the U.S. ports located on the Gulf of Mexico after Hurricane Katrina delayed shipments of grain and other commodities for months. The fires around Los Angeles in 2003 and the three-day power outage of August 2003 in the Midwest and Northeast of the United States cost billions of dollars in manufacturing delays and shipment disruptions.
|
|
|
|
|
|
However, the greatest impact is that of a terrorist act. All North American international and domestic airline traffic was completely stopped after September 11, 2001, for 3 days; it took one complete day to reposition all of the aircraft and a couple of weeks to clear the logjam of air cargo shipments. Thirteen months later, in October 2002, the Booz-Allen-Hamilton firm conducted a “war game” simulation in which the players were told that a “dirty bomb”—a bomb containing radioactive materials that are spread by the force of the explosion—had been found in the Port of Los Angeles; they were then told that another bomb had been found in Minneapolis and that a third one had exploded in Chicago. The initial response of the 85 game participants (all from the U.S. government) was to shut down two ports for 3 days and, as the crisis worsened, to shut down all U.S. ports for 12 days. The Booz-Allen-Hamilton report estimated that this single decision would have engendered a backlog of containers in U.S. ports that would have taken three months to clear, and the delays would have cost the U.S. economy $58 billion in 2002. The corresponding costs in 2010 would likely be much higher, probably closer to $75 to 80 billion.
|
|
|
|
|
|
Similar disruptions could be anticipated in other parts of the world, whether they are the results of natural or man-made catastrophes. In order to prevent those occurrences, governments and international agencies have collaborated to establish security measures that address possible weaknesses in the international supply chain.
|
|
15-2: International Organizations
|
|
|
|
|
|
|
|
|
The first groups to implement large-scale security efforts were the international organizations that monitor agreements and treaties, such as the International Maritime Organization (IMO) and the Customs Cooperation Council.
|
|
|
|
|
15-2a: International Maritime Organization
|
|
|
|
|
|
|
|
|
One of the first international organizations to implement enhanced security measures was the IMO, when it voted to create the International Ship and Port Facility Security (ISPS) Code
in December 2002. In order to implement this code quickly, the IMO made it a part of the International Convention for the Safety of Life at Sea (SOLAS)
, in a section that addresses “Special Measures to Enhance Maritime Security.” Since the code had already been signed by 148 countries, these changes had to be implemented by all signatory countries, and they did so relatively quickly, with most ports and ships in compliance with the ISPS Code by June 2004.
|
|
|
|
|
|
To enhance port security, the code contains two sections: One specifies the required measures that a port has to put in place (Part A), and the other is a series of recommendations for the implementation of these measures (Part B). Because ports face different threats due to their location, the types of cargo they handle, and their physical layout, the implementation of the ISPS Code has been quite different from port to port, and the costs of implementation have varied widely. , This discrepancy is also caused by the fact that the mandatory requirements are somewhat ill-defined, worded mostly in terms of questions that need to be addressed rather than specific requirements. Nevertheless, the consensus of the research reports is that implementation of the ISPS Code has improved the situation everywhere and that it has many benefits in addition to the increase in the level of security. It has led to a decrease in the incidence of theft and pilferage, a substantial decline in the number of stowaways, and much smoother operations in loading and unloading ships—all of this at a cost of a few cents to a few dollars per container handled.
|
|
|
|
|
|
Ports have implemented the ISPS Code in three specific ways. First, they monitor tightly who has access to the port facilities. This is achieved by mandating that workers carry identification cards, by allowing access to only authorized persons, and by requiring visitors to provide identification. The ports also monitor the activities taking place in the port, by recording them on video cameras (see Figure 15-1) and by keeping these records for a period of a few weeks. Finally, the ports have secure systems of communications, designed to raise the alarm whenever a threat is detected.
|
|
|
|
|
|
Figure 15-1. Monitoring of Port Facilities by Video Cameras
|
|
|
|
|
|
Source: Photo © Volodymyr Kyrylyuk. Used with permission.
|
|
|
|
|
|
As it applies to ships, the ISPS Code involves the creation of a company security officer for each carrier and a ship security officer for each ship, whose responsibilities are the development of a Ship Security Assessment, as well as several ship security plans to respond to possible threats against the ship, all of which are also dependent on the type of ship and the type of cargo it carries. Ships are also required to possess certain types of equipment and to restrict onboard access. Ship owners must adhere to additional standards, such as conducting background checks before the hiring of crew members, ensuring the security of paperwork on board, training employees in security procedures, and so on.
|
|
|
|
|
|
Unfortunately, since the research on ISPS has concentrated mainly on port facilities and since the ships' implementations of the ISPS Code are private corporate decisions, little is known about the ways these measures were enacted. Nevertheless, the IMO has issued countless International Ship Security Certificates, which indicates that most ships are in compliance with the ISPS Code requirements.
|
|
15-2b: World Customs Organization
|
|
|
|
|
|
|
|
|
Another international institution involved in security improvements in the international shipping of goods is the Customs Cooperation Council, better known as the World Customs Organization (WCO). Despite the fact that the primary role of the WCO has traditionally been the “simplification and harmonization of Customs' procedures,” it has been involved in a number of initiatives designed to enhance security.
|
|
|
|
|
|
Early on, the WCO saw its role as complementing the efforts of the IMO by helping importing countries and importers identify, before the goods leave the country of export, the cargoes that should be scrutinized before they should be allowed on their international trip to the importing country. The WCO achieved that objective by encouraging the standardization of documents, by identifying the data characteristics of high-risk shipments, and by establishing guidelines that allowed Customs authorities to have access to the documents of a particular shipment before it is loaded on board the carrier's vessel or aircraft. This particular emphasis is called the Advanced Cargo Information guidelines, which mirrors one of the initiatives of the U.S. Customs and Border Protection agency.
|
|
|
|
|
|
In June 2005, the WCO implemented its SAFE (Security and Facilitation in a Global Environment) initiative, a program it revised further in June 2007. The SAFE initiative further coordinates the efforts of Customs authorities worldwide in their efforts to combat terrorism. The SAFE requirements are fourfold:
|
|
|
|
|
|
· All Customs authorities have to adhere to a set of advance electronic information standards for all international shipments. What is required of shippers should be identical, regardless of country of export and country of import.
· Each country must have consistent risk management approaches to address security threats.
· Exporting countries' Customs authorities must comply with a reasonable request from the importing country's Customs authorities to inspect outgoing cargo, preferably by using non-intrusive technology (X-rays) if possible (see Figure 15-2).
· All Customs authorities must provide benefits to companies that demonstrate that they meet minimum standards of security. Such companies are called Authorized Economic Operators, and benefit from faster processing of Customs clearance and lower inspection rates.
|
|
|
|
|
Figure 15-2. A Mobile X-Ray Scanner for Cargo Containers
|
|
|
|
Source: Photo © Gerald Nino. U.S. Customs and Border Protection. Used with permission.
|
|
15-2c: International Chamber of Commerce
|
|
|
|
|
|
|
|
|
The International Chamber of Commerce (ICC) also weighed in on the issues related to security initiatives in the domain of international logistics, in a policy statement dated November 2002; in it, the ICC emphasized that security initiatives should be the domain of international agreements between countries, rather than initiatives imposed unilaterally by some governments. The ICC also emphasized that businesses involved in international trade have already invested considerable amounts in security initiatives and that, therefore, the rules and regulations imposed by international agreements should capitalize on these investments.
|
|
|
|
|
|
The recommendations made by the ICC reflect the organization's goals of facilitating international trade; its concerns were that country-specific requirements would place undue burdens on businesses and therefore would hamper trade. It also was concerned about the widespread dissemination of information among a number of law enforcement authorities and counseled that great care should be taken in the handling of the business information collected by security initiatives, so that no “sensitive confidential company information” would be released.
|
|
|
|
|
15-3: National Governments
|
|
|
|
|
|
|
|
|
Despite the efforts undertaken by the international organizations to make international trade more secure, and the admonitions of the ICC that unilateral requirements would hinder trade, as well as the efforts of the WCO toward a common set of requirements, many governments unilaterally implemented a number of different measures in the wake of the terrorist attacks of the past two decades. While the attacks on the World Trade Center and the Pentagon in 2001 tend to be at the forefront of most Americans' consciousness, the list of tragedies is unfortunately much longer, as shown in Table 15-1. The frequency of those attacks, as well as the increasing diversity of groups intent on disrupting democratic societies, led many governments to create and enforce a number of security measures, many of which have had a substantial impact on international trade. Each government implemented those security measures because they felt that their country was specifically targeted. Unfortunately, this is not the case, as is shown in the table; terrorists have been somewhat indiscriminate in their activities, attacking multiple targets in many different countries. It has truly become a worldwide concern.
|
|
|
|
|
|
|
Table 15-1. Major Terrorist Acts between 1990 and 2009
|
|
|
Terrorism Act
|
Date
|
Location
|
|
World Trade Center bombing
|
February 26, 1993
|
New York, United States
|
|
Sarin gas subway attack
|
March 20, 1995
|
Tokyo, Japan
|
|
Oklahoma City bombing
|
April 19, 1995
|
Oklahoma City, United States
|
|
Métro bombings
|
Summer-Fall 1995
|
Paris, France
|
|
Omagh bombings
|
August 15, 1998
|
Omagh, Northern Ireland
|
|
World Trade Center attacks
|
September 11, 2001
|
New York, United States
|
|
Anthrax mailings
|
September-October 2001
|
United States
|
|
Bali bombings
|
October 12, 2002
|
Bali, Indonesia
|
|
Istanbul bombings
|
November 15 and 20, 2003
|
Istanbul, Turkey
|
|
Moscow Metro bombing
|
February 6, 2004
|
Moscow, Russia
|
|
Madrid train bombings
|
March 11, 2004
|
Madrid, Spain
|
|
London subway bombings
|
July 7, 2005
|
London, United Kingdom
|
|
Mumbai train bombings
|
July 11, 2006
|
Mumbai, India
|
|
Mumbai hotel attacks
|
November 26, 2008
|
Mumbai, India
|
|
|
|
15-3a: The United States
|
|
|
|
|
|
|
|
|
The U.S. government implemented a large number of measures to limit the country's vulnerability to terrorist attacks, focusing initially on interdiction, a strategy that the country had already been pursuing in its war against contraband street drugs and illegal immigration.
|
|
|
|
|
|
Interdiction
is a strategy that attempts to eliminate all imports of a particular type of good and all entries of a specific group of persons into a country. The reasoning is relatively simple: If no terrorist can enter the country, and if no materials that can be used to cause widespread harm can be imported, then no terrorist acts are possible. The United States started to follow this approach almost immediately after the terrorist attacks of September 11, 2001, with a very strict monitoring of the flying public and of the luggage transported on airliners. The Transportation Safety Administration (TSA) was created in November 2001 by consolidating a large number of small private security firms, a move that was quite controversial at the time, as many employees of these firms did not meet federal hiring standards. The interdiction policy implemented by the TSA involves a systematic inspection of all passengers and of their checked luggage, a policy which is plagued with a number of failings, as described in the following three boxes. Because of these issues, the TSA policies have increasingly been characterized as “theater,” ineffective at achieving their stated goals, but presenting a reassuring presence in airports that demonstrates that “something is being done” to combat terrorism. ,
|
|
|
|
|
|
The Fallacy of One-Hundred-Percent Inspections
|
|
|
|
|
|
The United States formalized further the creation of its interdiction strategy on November 25, 2002, by creating the Department of Homeland Security (DHS), consolidating 22 services that had so far operated somewhat independently. The goal was that these departments would be more effective if they were able to cooperate around a shared mission. The DHS reinforced the visibility of its mission of interdiction by renaming or regrouping many of these agencies to reflect their role in terrorism prevention: The U.S. Customs Service became Customs and Border Protection, and the investigative bureaus of the former Immigration and Naturalization Service and Customs became Immigration and Customs Enforcement. This newest department of the U.S. government counts more than 200,000 employees, third in size to the Department of Defense and the Department of Veterans Affairs, and three times larger than the Social Security Administration.
|
|
|
|
|
|
The United States complemented its interdiction approach with the creation of the Customs-Trade Partnership Against Terrorism (C-TPAT)
in 2001; however, only a handful of companies were involved in this program in 2001 and 2002. By 2003, 137 companies joined, and in 2008, there were over 10,000 importers and logistics services providers enrolled in the program.
|
|
|
|
|
|
Understanding Type I and Type II Errors
|
|
|
|
|
|
The program is a shift away from interdiction and one-hundred-percent inspection; it is designed to recognize that the immense majority of the shipments that travel internationally are innocuous and, therefore, that they should not be the targets of law enforcement. The only concerns with these shipments should be the possibility that they are intercepted by criminals and the merchandise that they contain is substituted for dangerous goods. The goal of the program is therefore to encourage corporations involved in international trade to enact security measures that would prevent tampering with the shipments at any point in the supply chain; corporations are asked to evaluate their levels of security in the supply chain, determine their vulnerability, and remedy any issues.
|
|
|
|
|
|
The Paradox of Type I and Type II Errors As They Apply to Security Issues
|
|
|
|
|
|
Corporations apply for participation in the C-TPAT program, and after their applications have been accepted, they become “Tier I” members. Tier I members are also called “certified” corporations. After their supply-chain security has been analyzed by Customs and Border Protection and the firms' security measures have been found to be “reliable, accurate, and effective,” the firms' applications are “validated,” and the firms become “Tier II” members. Corporations that go beyond the minimum requirements of Customs can reach the level of “Tier III” members. As of December 2008, there were about 8,000 corporations that had Tier II status, and fewer than 300 had reached Tier III.
|
|
|
|
|
|
In order to encourage corporations to participate in the C-TPAT program, Customs and Border Protection offers companies several advantages, including a lower probability of Customs inspections at the port of entry, priority scheduling of inspections when they are deemed necessary, and assistance from Customs' supply-chain security specialists to solve security challenges. Although the program was originally instituted as a voluntary program for companies involved in international trade, it has evolved into a mandatory program for all importers, carriers, and third-party logistics providers; participation is not encouraged, it is essentially expected.
|
|
|
|
|
|
The C-TPAT program operates very much within the guidelines established by the SAFE initiative enacted by the WCO. In addition, by concentrating on the analysis of shipments that can be presumed to present some level of risk (determined by their characteristics, often the fact that they are “unusual”), the C-TPAT program also meets the requirements of the ICC to be least disruptive to international commerce.
|
|
|
|
|
|
In addition to the C-TPAT program, the United States has also created a number of other initiatives, all designed to improve security:
|
|
|
|
|
|
· The Maritime Transportation Security Act (MTSA) was enacted in 2002, and is the U.S. version of the IMO's International Ship and Port Facility Security Code.
· Its follower, the Security and Accountability For Every Port (SAFE Port) Act, added additional requirements and specific enforcement responsibilities by the Coast Guard. Although it shares the same name as the WCO's initiative, it is not related.
· The Transportation Workers' Identification Credential (TWIC) program is a system of identification cards for all persons who have access to U.S. ports. It is based on biometric information. The TWIC program has been implemented from port to port, starting in 2008 (at New England ports); most ports were in compliance by April 2009.
· Other programs, such as the Container Security Initiative (CSI) and the Free and Secure Trade (FAST) program, were described in Chapters 11 and 13.
|
|
|
|
|
15-3b: The European Union
|
|
|
|
|
|
|
|
|
The European Union has approached security in a significantly different way: While it recognizes that there are new security issues with the increase in terrorism and the availability of weapons of mass destruction in the hands of criminals, its primary focus has been prevention. In a paper outlining its security strategy, the European Union emphasized that the reduction of poverty, the enforcement of international agreements against arms proliferation, the restoration of democratic governments in areas of regional conflicts, and an increase in international cooperation for criminal investigations would be most effective in dealing with security threats.
|
|
|
|
|
|
Therefore, it is not surprising that most of the initiatives implemented in the European Union were in response to international organizations' guidelines, first the International Ship and Port Facilities Security Code of the IMO, and then the SAFE framework of the WCO. Although there were some unilateral interpretations of these guidelines, the European Union, by and large, has responded to security threats in a relatively uniform fashion.
|
|
|
|
|
|
It is also clear that the European Union has responded to recent terrorist threats much less vigorously than the United States. This was, at least in part, because Europe had faced numerous other terrorist attacks prior to 2001—from internal as well as external elements, from criminal as well as “political” groups—and therefore had already implemented substantial countermeasures. In every decade since the 1950s, European countries have experienced significant violent attacks, from local terrorist groups such as the Organisation de l'Armée Secrète in France, the Provisional Irish Republican Army in the United Kingdom, the Baader-Meinhof Gang and the Rote Armee Fraktion in Germany, the Brigate Rosse in Italy, and the Euskadi Ta Askatasuna (Basque Separatist Party) in Spain and France, in addition to foreign groups from North Africa and the Middle East.
|
|
15-3c: Other Countries
|
|
|
|
|
|
|
|
|
Countries outside of Europe and North America reacted with policies that mirrored those of the European Union, by implementing the ISPS Code and SAFE framework, mostly in the spirit of international cooperation rather than as a response to a perceived threat of terrorism. The prevalent viewpoint was that terrorists were targeting mostly the United States and possibly the European Union and that this was a U.S. problem, from which they could “remove” themselves.
|
|
|
|
|
|
This attitude was further reinforced by actions of the United States that often imposed additional measures on its trade partners, who were asked to implement them under the scrutiny of U.S. enforcement agencies, whether Customs and Border Protection, Immigration and Customs Enforcement, or the Coast Guard.
|
|
|
|
|
|
Many countries engaged in these changes reluctantly, as they had much more significant domestic problems and did not want to spend their resources on a “foreign” problem. The subsequent bombings in Bali, Moscow, Madrid, London, and Mumbai changed this perspective relatively quickly, and most countries today agree that terrorism is a worldwide problem, although they often see it as less significant than widespread poverty and its associated risks of significant crime and potential social unrest.
|
|
|
|
|
15-4: Corporate Efforts
|
|
|
|
|
|
|
|
|
Although governments frame the issue of supply chain security in terms of the risk of terrorism, most companies see security in a much narrower way, focusing principally on the risk of theft and other criminal activities, such as tampering, vandalism, and counterfeit products. Companies comply with requests to reduce terrorism by participating in governmental programs and other efforts to secure the international logistics' environment, but they see the benefits of such increased security mostly in terms of reduced cargo losses.
|
|
|
|
|
|
Nevertheless, the surge in government programs designed to eliminate terrorism was the impetus for many companies to engage in Total Security Management (TSM), a management philosophy based on the Total Quality Management concepts developed by W. Edwards Deming in the 1970s, which encourages every employee, at every level, to recognize the importance of security within the corporation and suggest improvements in processes and procedures. By having a commitment to security that permeates all levels of responsibility within the company, security is increased greatly and becomes an essential part of the culture of the firm. Even though there are costs to making these improvements, the idea behind TSM is that these costs will be offset by the corresponding reductions in theft, damaged goods, and lost productivity, in the same way as Crosby determined that “quality is free.”
|
|
|
|
|
|
In order to be comprehensive in their security efforts, companies have to secure four areas in their supply chains: (1) their fixed assets (plants, warehouses, distribution centers), (2) their inbound and outbound shipments while they are in transit, (3) the information on which they rely to manage their operations, and (4) their workforce, to ensure that it is reliable and trustworthy.
|
|
|
|
|
|
In order to protect their fixed assets, companies install physical barriers designed to prevent entry by unauthorized persons. Fences are built along the perimeter of the facilities, the doors to the buildings are locked (emergency exit doors are locked from the inside so that they cannot be opened from the outside), all other points of access (e.g., roof hatches) to the buildings are secured, the number of outside lights is increased, a backup electric generator is added to prevent interruptions to lights and communication systems, and a public-address and an alarm system are installed. Companies also build gates at the entrance to the facilities, with a security guard ensuring that no unauthorized person is allowed to enter. Companies install security cameras to monitor all activities on the premises, and the videos are monitored by trained security personnel. Finally, emergency security procedures are established and training is provided for all employees, so that they know what their responsibilities are in the event of a security breach. These measures mirror the requirements of the ISPS Code for port facilities.
|
|
|
|
|
|
In order to protect their shipments while they are in transit, companies implement a different set of measures. They make sure that all cargo containers are sealed before they leave any facility, with a seal that is a good deterrent to a potential thief (see Figure 15-5), and that the seal numbers are carefully monitored. They make sure that the information on the identity of the cargo is released to as few people as possible. Companies also instruct their truck drivers to continuously monitor their surroundings and make sure that they do not stop at a rest area soon after leaving a plant, as most cargo thefts occur within a few miles of the cargo's point of origin. Many U.S. companies have put in place a “geo-fencing” system, which alerts security officials when the cargo departs from a pre-determined itinerary. Such a system is based on the Global Positioning System (GPS) and allows only slight variations in itinerary (such as a detour for construction or an accident) but sends a warning if the cargo strays more than 25 miles (40 kilometers) from the highway that the truck is supposed to take. The truck driver is then immediately contacted for further information, and the local police authorities are dispatched if there is a problem. Finally, an emergency plan should be developed and all employees should be trained in its application.
|
|
|
|
|
|
Figure 15-5. Two Different Container Seals; Only One is Tamper Resistant (Top)
|
|
|
|
|
|
Source: Photo © Pierre David.
|
|
|
|
|
|
It is also very important for companies to guard their corporate information. While the techniques used to safeguard electronic data are quite complex, and are the subjects of a number of books, a good system of procedures must ensure that information reaches only those people who need to know what is transported or what is currently in inventory. Procedures should be in place to monitor the dissemination of information (electronic and paper) within the firm.
|
|
|
|
|
|
Finally, good security measures are fundamentally predicated on good human resources practices. For instance, if employees are intent on violating the security measures put in place by a corporation, they likely will achieve their goals, as it is impossible to defend against all possibilities without affecting the normal conduct of business. It is therefore very important to verify employees' backgrounds, monitor their activities, train them to recognize security violations, and provide an anonymous system to report their concerns.
|
|
Chapter 15: International Logistics Security
Review and Discussion Questions
|
|
|
|
|
|
|
|
|
|
|
|
1. What are the different main international logistics security programs, implemented either by international agencies or national governments?
2. What are the main differences between the alternative approaches taken by the United States and the European Union in terms of security?
3. What are the problems of a security policy that is based on one-hundred-percent inspection?
4. What are the four areas in which a corporation must enact security measures to protect itself against theft and terrorism?
5. Suppose a particular disease has an incidence of 1 percent in the population. The test used to detect this disease has a 5 percent Type I error rate; there is no Type II error rate. A physician sees test results from a patient that indicates that the patient has that disease; the probability that the patient actually has that disease is 0.01/0.0595, or about 17 percent. Explain this result.
|
|