Safety and Accident Prevention
Homeland security and citizen response to emergency situations: a perspective on the need for a policy approach to information access
Charles Herrick
Published online: 8 March 2009 � Springer Science+Business Media, LLC. 2009
Abstract Open access to public information is a hallmark of American political culture; however, the terrorist attacks on and before September 11, 2001 have prompted a
reevaluation of how ‘‘freedom of information’’ should be balanced against the need for
enhanced homeland security. This essay begins with a summary of legislative and exec-
utive actions that have led to restriction of environmental and health-related information
formerly available to the public. Drawing on studies of disaster behavior, it is argued that
citizen responders may be significantly hampered by restriction of environmental and
public health-related information formerly available by means of public access web sites.
The Lasswellian policy decision process is examined to explore the basis for a balancing test for agencies contemplating restriction of information related to environmental and
public health-related threats. It is suggested that the Office of Management and Budget
(OMB) implement guidance for federal agencies in weighing decisions concerning the
public status of information.
Keywords Security � Public access � Policy � Decision process
Public access to environmental and public health-related information: background and context
Open access to public information is a hallmark of American political thought and culture.
As articulated by James Madison, ‘‘A popular government, without popular information, or
the means of acquiring it, is but a prologue to a farce or a tragedy or perhaps both.
Knowledge will forever govern ignorance, and a people who mean to be their own
governors, must arm themselves with the power knowledge gives’’ (Padover 1953, p. 346).
Over the past quarter century, the principle of informed consent or public right-to-know
has been codified through numerous articles of law and regulation, especially in arenas
such as public health, consumer protection, worker safety, and the environment.
C. Herrick (&) Stratus Consulting Inc., 1920 L Street, NW, Suite 420, Washington, DC 20016, USA e-mail: [email protected]
123
Policy Sci (2009) 42:195–210 DOI 10.1007/s11077-009-9081-7
Provision of public access to information about environmental and health-related risks
is a key component of the U.S. federal environmental protection policy regime. Industrial
manufacturing facilities, water and electric utilities, and other operations that use and store
hazardous chemicals such as chlorine, ammonia, and cyanide pose a serious threat to local
communities. The Environmental Protection Agency (EPA) has estimated that at least 123
plants store toxic chemicals that, if released through explosion, accident, or terrorist attack,
could result in a vapor plume that would put as many as 1 million people at risk. Drawing
on EPA data, the Department of Homeland Security estimates that there are approximately
3,400 facilities in which a ‘‘worst-case’’ release could potentially affect over 1,000 people
(National Journal Group 2001). In addition, thousands of smaller facilities utilize sub-
stances known to harm humans and the environment. For example, EPA regulates about
15,000 facilities under the 1990 amendments to the Clean Air Act because they produce,
use, or store specified chemicals that would pose substantial risk to human health if
released into the air. Understandably, people who live or work near such facilities are
concerned about chronic exposure, as well as risks posed by acute exposure associated with
a major discharge event. 1
Many U.S. environmental laws include provisions intended to enhance or enable public
access to information about environmental and health-related conditions and threats. This
information is useful to citizens in understanding chemical hazards in their communities
and in stimulating communication between industry, stakeholders, and the public to
improve emergency response strategies and tactics at the local level. Environmental and
public health-related statutes that incorporate information access and dissemination pro-
visions include the Comprehensive Environmental Response, Compensation, and Liability
Act (CERCLA), Pollution Prevention Act, Emergency Planning and Community Right-to-
Know Act (EPCRA), Safe Drinking Water Act, Clean Air Act, and the National Envi-
ronmental Policy Act. Hazardous chemical reporting under EPCRA is intended to provide
information to local governments and citizens who live in areas surrounding subject
facilities. The EPCRA requires that an emergency plan, Material Safety Data Sheets, 2
and
a hazardous chemical list be made available to the general public. Similarly, Section 112(r)
of the Clean Air Act requires companies of all sizes that use certain flammable and toxic
substances to develop a Risk Management Program, which includes a hazard assessment
that details the potential effects of an accidental release, an accident history of the past
5 years, an evaluation of worst-case and alternative accidental releases, and an emergency
response program that spells out procedures for informing the public should an accident
occur.
In the arenas of environment and public health, the principle of public right-to-know is
founded upon two compelling imperatives: (1) a need to inform local-level and citizen
1 In late 1985, more than 150 people required medical attention when a toxic chemical—aldicarb—was
released from a Union Carbide facility in Institute, West Virginia. Union Carbide’s officials failed to notify local authorities about the release event because they reportedly believed the gas would settle and remain within the plant’s perimeter. Local authorities were confused about what was happening, what substance was involved, and how to protect and treat citizens. More recently, an explosion at a hazardous waste management and disposal facility in Apex, North Carolina resulted in a massive fire and subsequent evacuation of over 17,000 residents. First responders were hampered because they did not know what types of chemicals were stored at the facility and were confused regarding how best to fight the fire and manage site access until the company provided an inventory of stored materials nearly 24 h after the onset of the fire. 2
Originally established under OSHA to help assure employee safety, Material Safety Data Sheets (MSDS) are printed forms that characterize a hazardous chemical or substance, including physical properties, hazards to personnel, fire and explosion potential, safe handling recommendations, health effects, fire fighting techniques, reactivity, and proper disposal (U.S. EPA 2006).
196 Policy Sci (2009) 42:195–210
123
deliberations concerning the appropriateness of near-by industrial activities; and (2) a need
to help local communities recognize, assess, and effectively respond to toxic release
events.
Post 9/11 information restriction
Data and information that can help citizens recognize and respond to environmental and
health-related risks can also be used by terrorists and other malefactors to plan and execute
attacks on communities and units of critical infrastructure. Because of this, terrorist attacks
on U.S. soil have prompted reevaluation of how ‘‘freedom of information’’ should be
balanced against the need for enhanced security. In recent years, this balance has swung in
favor of information control.
Under current operational guidelines, rules governing exemptions to the 1974 Freedom
of Information Act (FOIA) have been relaxed, enabling federal agencies to withhold
information that would previously have been released. An October 2001 memorandum
from Attorney General John Ashcroft directed agency heads to rescind the ‘‘presumption of
disclosure’’ that had been operative under previous administrations. Agencies are no longer
compelled to articulate a plausible scenario of harm, merely to assure that information
withholding decisions have a ‘‘sound basis’’ in legal reasoning (U.S. DOJ 2001). Under the
2002 Homeland Security Act, Congress added a broad exemption concerning information
on ‘‘critical infrastructure’’ to the range of data and information that federal agencies need
not disclose under the Freedom of Information Act (Tombs 2005; Sidel 2004). Similarly,
the Public Health Security and Bioterrorism Preparedness Act of 2002 stipulates that
certain types of public infrastructure information are exempt from disclosure requirements
under the federal FOIA (U.S. Congress 2002). In addition, the DOJ Information Security
Oversight Office (ISOO) instructed agencies to take appropriate steps to assure the security
of ‘‘sensitive but unclassified information’’ related to America’s homeland security (Pozen
2005). Federal efforts to restrict information releases are being mirrored at the state level.
In a 2006 study, the National Conference of State Legislators (NCSL) determined that 50
U.S. states and territories have enacted statutory provisions exempting various types of
critical infrastructure information from disclosure under FOIA.
In response to the 9/11 attacks and executive directives, federal agencies removed
thousands of documents from their web sites and classified many more. For example, an
article in the Bulletin of the Atomic Scientist cited a host of information sources ‘‘tempo- rarily removed’’ from agency web sites and/or public information reading rooms (Costner
2002). Examples of federal government information resources removed or restricted from
public access are described in Exhibit 1. As illustrated in Exhibit 1, many of the information
resources removed from public access were developed for use by citizens and community-
level stakeholders to better understand and deal with health-related environmental risks,
including catastrophic releases of hazardous substances due to natural disasters, techno-
logical failures, human error, and terrorist attacks. While agency actions appear to have
been informed by assessments of the potential sensitivity of publicly available information
resources, there is no documentation of efforts to weigh the restriction of information
against the foregone values and benefits associated with its release.
At the U.S. Department of Energy, information removals were formalized through
distribution of a department-wide directive to ‘‘review the operational information
accessible to members of the public and remove or restrict access, as appropriate, to
information that may be used to target the Department of Energy.’’ The directive went on
Policy Sci (2009) 42:195–210 197
123
to identify a number of potentially sensitive items, including emergency planning hazard
assessments, safety analysis reports, environmental impact statements, detailed site and
facility maps, photographs of facilities, and personal data on employees’’ (Costner 2002,
p. 1). However, the directive did not provide guidance and/or criteria for how managers
should frame this decision process or assess potential security risks against the social value
of the information disseminated.
Agency documentation and Congressional testimony suggest that the situation was
similar at the U.S. EPA. Shortly after 9/11, the chief of information systems in the U.S.
Environmental Protection Agency’s Region II office—which includes New York—wrote
in an email ‘‘If there are any sites that look like they would offer site specific information
about facilities, especially hazardous chemicals, water supplies, etc., we should break the
links.’’ To bolster this effort, EPA headquarters delivered an Agency-wide request in late
September asking those in the agency responsible for disseminating information to identify
potentially ‘‘sensitive’’ information, and particularly ‘‘resources which provide information
on chemicals, and/or location, and/or amounts, and/or impacts on the environment or
human health’’ (OMB Watch 2002, p. 1). The criteria outlined in EPA’s agency-wide
assessment are reproduced in Exhibit 2. As was the case for DOE, EPA did not perform a
formalized assessment of public values or mission objectives affected through the decision
to restrict information.
As mentioned earlier, many of the removed or restricted information items were orig-
inally complied and intended for use by citizens dealing with toxic or hazardous release
events. To illustrate better how citizens use environmental and health-related information,
we next review recent sociological research on how individuals and groups react under
emergency and disaster conditions.
The realities of disaster response behavior
Much discussion of how the general public might respond after an emergency or disaster
event highlights the possibility of mass panic and social disorder. However, research on
population responses to a wide range of natural and technological disasters suggests a
Exhibit 1 Information resources removed from public access
The Environmental Protection Agency removed Clean Air Act, Risk Management Program information from its public access web site, including response plans to protect human health and the environment in the event of a release.
The Department of Transportation took down most of the national pipeline mapping system that enables communities to identify hazardous pipeline routes.
The Environmental Protection Agency removed a database known as ARCHIE, the Automated Resource for Chemical Hazard Incident Evaluation, which enabled users to evaluate how different chemicals behave under alternative release circumstances.
The U.S. Geological Survey instructed government libraries to destroy copies of a CD-ROM describing public water supplies, used by communities to protect source water.
The Department of Energy removed environmental impact statements that alerted local communities to potential dangers from nearby nuclear energy plants, as well as information on the transportation of hazardous materials.
The Department of Homeland Security released rules for implementing the National Environmental Policy Act (NEPA) that include categorical exemptions for the release of information dealing with disaster cleanup efforts.
198 Policy Sci (2009) 42:195–210
123
tendency toward reasoned adaptability and cooperation (Glass and Schoch-Spana 2002,
p. 218). A recent review by Lee Clarke confirms that people don’t tend to panic during
disaster situations (Clarke 2003). People may well be terrified, but ‘‘social bonds remain
intact and the sense of responsibility to others remains…strong’’ (Tierney 2003). Further, ‘‘an emergent norm process occurs [wherein] survivors share their tools, food, equipment,
and, especially, their time. Groups of survivors tend to emerge to respond to each others’
needs’’ (Fischer 2006).
The literature on disaster behavior also shows that disaster ‘‘victims’’ invariably con-
stitute the real first responders in most emergency situations. Studies indicate that
individuals and groups close to disaster sites tend to converge, seek information, engage in
collective decision making, perform rescues, and help transport injured victims to emer-
gency care providers. It is an under-appreciated fact that the vast majority of live rescues
are carried out by community residents—so-called ‘‘occupant responders’’—rather than by
official response agencies or search and rescue teams (Tierney 2003, p. 36).
Natural disasters tend to be somewhat repetitive and to concentrate in particular areas.
For instance, seismic belts, hurricane prone regions, tornado ‘‘alleys,’’ flood plains, and
areas susceptible to wildfire are well documented (Alexander 2002, p. 5; Putnam 2002,
p. 1). The statistical frequency of many natural hazard events is well established. Similarly,
some types of catastrophic technological failures are also subject to statistical regularity
(Perrow 1984). This general predictability allows for some degree of event-specific
planning and mitigation. For example, development of event-specific mutual assistance
agreements and training exercises, and pre-positioned inventories of equipment and sup-
plies known to be useful in responding to specific types of disasters. However, even when
major disaster events are accurately forecast, they frequently contain elements of surprise
and almost always become occasions for extensive response improvisation (Tierney 2003,
p. 41; Comfort 2002, p. 106; Bruins 2000, p. 70). Disaster response tends to be accom-
plished through ‘‘loosely-coupled collections of individuals, groups, and organizations that
continually change and that have permeable boundaries’’ (Tierney 2003, p. 42). Louise
Comfort has described disaster response networks as ‘‘complex adaptive systems’’
(Comfort 1999, pp. 100–102).
The need for response improvisation is likely to be especially marked in the event of a
terrorist attack. Terrorist attacks, especially those carried out on specific U.S. domestic
resources, do not occur with any type of statistical regularity. This makes them exceedingly
difficult to predict, except possibly in the abstract (Herrick et al. 2006; Alexander 2002;
Comfort 2002). As Richard Little argues, ‘‘we find ourselves in a time where former
contexts of threat, vulnerability, and target have all changed and continue to do so. Threats
Exhibit 2 Criteria utilized by the U.S. EPA to guide restriction or removal of publicly available infor- mation resources
‘‘EPA has developed four criteria for assessing the sensitivity of our information resources: ‘type,’ ‘specificity,’ ‘connectivity,’ and the ‘availability’ of information. Information on a facility’s or a pollutant’s location, chemical identification, volume, acute effects, and plant processes and management falls within the ‘type’ criterion. The ‘specificity’ criterion builds on the type of information and assesses the level of detail available for each type. The ‘connectivity’ criterion looks at the degree to which individual pieces of information can be connected to create realistic scenarios. Finally, the ‘availability’ criterion assesses the level of control that EPA has over releasing the information. This criterion ascertains whether or not EPA is the sole provider of a particular piece of information. If information is widely available through other sources outside of EPA’s control—such as information available from State or local government agencies, public interest groups, in textbooks or from universities—then EPA’s removal may not substantially alter its availability’’ (OMB Watch 2002, p. 1).
Policy Sci (2009) 42:195–210 199
123
are unpredictable and the full range of threats probably unknowable’’ (Little 2004, p. 57).
This virtual inability to predict specific terrorist attacks, coupled with the almost inevitable
reality of response improvisation for all types of disasters, suggests that we will continue to
be faced with situations in which citizens and occupant responders need to react quickly
and intelligently to unfolding disaster events. Thomas Glass and Monica Schoch-Spana
articulate five guidelines for improving disaster response by citizens and the public. One of
the five guidelines focuses specifically on the importance of information provision; and all
five guidelines include a significant public information dissemination component. In the
face of uncertainty, the public needs accurate descriptions of risk and exposure conditions,
instruction in protective measures, and related information. Provision of such information
is valuable not only because it decreases the chances of misinformed response activities
and logistical confusion but also equally important, the flow of information is itself a
source of comfort and reassurance. When disaster strikes there tends to be an urgent need
for reliable information.
Homeland security and environmental and public health-related information: factors that complicate risk characterization
Determination of whether a given information object might or might not be germane to a
terrorist plot is an inherently complicated and speculative matter, depending not only on
the form and content of the information, but also upon intelligence findings concerning
terrorist plans, tendencies, and technical capabilities (Rand 2004). Moreover, even if we
could be reasonably sure that a particular type of information reveals an actionable vul-
nerability, it is not clear whether publicizing vulnerabilities makes them more or less likely
to be exploited. David Pozen suggests that disclosure of security-related information might
actually reduce risk by alerting the public to potential threats. Public attention and vigi-
lance may in turn spur industries and agencies to opt for inherently safer inputs, operations,
and products (Pozen 2005; Echeverria and Kaplan 2002). While lacking an unambiguous
base in empirical documentation, this general line of reasoning has long been the staple of
the U.S. right-to-know advocacy community (Wolf 1996).
It is also logical to presume that suppression of risk in one context or location has the
potential to move it to another. ‘‘Shifting risks may be more dangerous than tolerating
them, both because those who face new risks may be unaccustomed to them and because
those who no longer face old ones may become more vulnerable when conditions change’’
(Douglas and Wildavsky 1983). Removal of information resources such as those outlined
in Exhibit 1 could actually increase public risk by effectively weakening laws designed
specifically to protect human health, environmental quality, and other social values. As an
example, it is well substantiated that public release of data from EPA’s Toxics Release
Inventory has compelled industries to change processes and inputs, and in so doing, reduce
emissions (Cohen 2001; Wolf 1996). Current policies of information restriction could
prove to be examples of the type of risk shifting behavior described by Douglas and
Wildavsky.
Industrial facilities and other components of infrastructure utilize literally thousands of
chemicals and compounds, some of which are synthesized exclusively for specific pro-
cesses at particular plants. Very few specialists, much less the lay public, can be said to
understand the human and environmental risks associated with fugitive or catastrophic
release of these substances, relevant exposure scenarios and pathways, fate and transport
dynamics, and appropriate treatment regimes. Owing to this complexity, the rationale
200 Policy Sci (2009) 42:195–210
123
behind the public’s right-to-know cannot be satisfied by the mere provision of raw data. To
the contrary, meaningful application of the public’s right-to-know requires active facili-
tation on the part of the government. In the U.S., the Environmental Protection Agency and
several state agencies have taken steps to enable and facilitate the public’s awareness and
understanding of environmental and health-related risks, partially through development of
interpretive information products, interactive maps and models, and web-based data
applications. Many of the information resources being withheld or restricted were origi-
nally developed to help citizen and occupant responders make sense of disaster situations,
assess threats, and implement rational and effective response actions (Herrick 2004; Weick
and Sutcliffe 2001).
A common response to concerns about terrorist utilization of publicly-available infor-
mation resources has been to remove the information from the web, but to keep it available
in hardcopy format in public reading rooms (OMB Watch 2002; Costner 2002). This
strategy is problematic because the ready availability of these resources by means of
internet and/or wireless technology is essential to enable its utilization in a context that
actually matters, which is to say, in situ and in real-time by first and/or occupant responders
(Tombs 2005). There are at least four reasons why resources such as these cannot be
replaced by the mere availability of hard-copy documents and records in government
reading rooms: (1) document rooms are not open 24/7/365, and therefore may be
unavailable when disaster strikes; (2) documents and records do not provide interpretive
tools for use by responders in emergency situations; 3
(3) reading rooms are only operated
in limited locations; and (4) the reading room itself may be inaccessible due to the disaster
event. In other words, these information applications were developed to address a prima
facie need-to-know on the part of citizens and the emergency response community.
Removal of these information resources almost certainly reduces emergency response
effectiveness and subjects localities to the real and well-documented threats associated
with acute exposure to hazardous substances.
It is also argued that access to potentially sensitive information resources should be
granted only to authorities such as fire and police departments. Yet as has been docu-
mented in the case of Hurricane Katrina and other disasters, a common aspect of major
disasters is the break-down in authority systems (Wise 2006). For a given disaster situation,
it is frequently difficult to anticipate who or what organization will need to assume authority (Weick and Sutcliffe 2001). While aspects of this deficiency are being addressed
through improved Incident Command Systems (ICS) and expanded training programs, and
there are other aspects of the problem likely to remain the province of self-organizing,
emergent groups (Comfort 1999, pp. 100–102).
While it would be reckless to suggest that all information should be provided to the
public through open access media, it is not clear that domestic vulnerabilities have been
reduced through restriction of the type of infrastructure and health-related information
being considered in this essay. Indeed, it seems plausible to argue that some domestic risk
profiles may have actually increased due to the restriction of environmental and public
health-related data and information. Based on these considerations, the advisability and
3 Many of the information resources removed shortly after 9/11 include simple, interactive maps, models,
and decision aids to enable users to customize information to address local characteristics and other unique circumstances. For example, EPA’s Automated Resource for Chemical Hazard Incident Evaluation (ARCHIE), which enabled users to evaluate how different chemicals behave under alternative release circumstances.
Policy Sci (2009) 42:195–210 201
123
appropriateness of information restriction and/or withholding decisions needs to be judged
in terms of associated trade-offs in social value (Dahl 2004; Gozdor et al. 2003; Pozen
2005; Tombs 2005; Smock 2003). It would thus seem reasonable that federal agencies
formulate, publish, and adopt balancing criteria to guide the management of potentially
sensitive public information. How might such a balancing exercise be approached?
Public access and the need to approach information security by means of a policy decision process
In the western political tradition, the related concepts of public right-to-know and informed
consent are rooted in the moral primacy of the autonomous individual. As Faden et al.
(1986, p. 8) explained, the term autonomy is associated with political values such as
freedom to choose, self-mastery, and responsibility for individual choices. The concept of
autonomy entails both passive and active components, and can be understood in terms of
‘‘external non-constraint and the presence of critical…capacities integral to self-gover- nance’’. Open access to information that can affect an individual’s well-being or life
prospects is therefore critical to the meaningful exercise of individual freedom and choice,
both for political life and personal conduct and development.
But what does it mean to say that an individual has a right to access specific types of information? Rights are powerful assertions of claims that demand respect and socio-
political status (Shue 1980). If an individual appeals to rights, a response is warranted. As
Ronald Dworkin puts it, rights are ‘‘trumps’’ (Dworkin 1977, p. 92). However, it is not the
case that rights are nonderogable. ‘‘The assertion that rights are powerful normative
considerations does not imply that their weight is absolute or that exceptions cannot be
built into their scope’’ (Nickel 1987, p. 17). Rights can conflict with one another, some
rights are more important than others, and there are cases where the exercise of one right
may necessitate the temporary suspension of another right. In other words, there are
occasions in which it is appropriate to recognize and act upon trade-offs among different
rights.
As we have tried to illustrate, the specter of domestic terrorism has spawned a clash of
competing values: on the one hand, there are legitimate reasons to bolster U.S. homeland
security, but on the other hand, citizen deliberation is fundamental to the liberal political
process and the public has a right-to-know about environmental and health-related risks
(Gozdor et al. 2003). The current tendency toward information withholding and restriction
is based on the presupposition that certain types of data, records, and information can be
accessed and used by terrorists to identify and exploit vulnerabilities in U.S. domestic
infrastructure. This is not an unreasonable position; there is evidence that terrorist groups
have and continue to guide their activities through research and utilization of publicly
available information, with perhaps the most notorious example being the commercial
airline timetables utilized by the 9/11 perpetrators. 4
We cannot argue that the right-to-
know clearly trumps security-related concerns, nor can we support a claim that security-
related concerns—by their very recognition—trump the public’s right- and/or need-to-
know about environmental and health-related emissions and exposure risks. This is not an
4 As documented in the 9/11 Commission Report, Khalid Sheikh Mohammed prepared for the hijacking
operation by collecting ‘‘Western aviation magazines; telephone directories for American cities;…brochures for schools; and airline timetables, and he conducted internet searches on U.S. flight schools’’ (National Commission on Terrorist Attacks Upon the United States 2004, p. 157).
202 Policy Sci (2009) 42:195–210
123
issue that can be settled in the abstract or by appeals to political values, but requires
formalized consideration of all substantial interests and values that bear upon outcomes
and careful consideration of alternative policy approaches. The canonical approaches of the
policy sciences have been assembled to address issues such as this.
The basic conceptual framework of the policy sciences was laid out by Harold Lasswell
and later elaborated by Brewer (1974), Brunner (1982), and others. Fundamentally, policy
‘‘is a social process of authoritative decision making by which the members of a com-
munity clarify and secure their common interests’’ (Lasswell and McDougal 1992). The
policy sciences offer methods and intellectual orientations that offer ways to improve the
formulation and implementation of policy. (Clark 1992) According to Tribe, the policy
sciences provide ‘‘devices for organizing thought in rational ways—methods for sorting
out issues and objectively clarifying the empirical relationships among alternative actions
and their likely consequences (1973).
The conceptual framework of the policy sciences involves a series of activities and
considerations that are essential to responsible and effective community-level decision
making. (Lasswell 1971) Although constituting distinct functions, these activities can be
carried out simultaneously, and are often combined. (Clark 1992) As Clark writes, the
decision process is a means of reconciling (or at least managing) conflict through politics in
order to find a working specification of a community’s common interests (Clark 2002). The
outcomes of a decision process are the rules or norms it generates. The basic activities of
the classical policy decision process are outlined below:
Intelligence: Decision making depends upon the collection, compilation, and analysis of data and information on past trends, current status, relevant processes, and alternative
future projections for factors and conditions that bear upon the issue under consider-
ation. Depending on the issue, this process may need to be specialized, intensive, and
protracted. Decisions based upon inadequate characterization of a problematical
situation have potential to result in irrelevant, inefficient, or counterproductive
outcomes.
Promotion: Promotion involves recommendation and the marshalling of support for policy alternatives. Ideally, the promotion process should entail active debate about
different courses of action. The promotion process helps citizens and political
stakeholders to refine and focus their values and expectations, while dismissing
alternative courses of action.
Prescription: Prescription is the process through which a community formulates and enacts policies and guidelines for action. The prescription process implies that specific
community members posses recognized and legitimate authority to execute and enforce
rules. To be politically appropriate and effective, a prescription should include three
elements: (1) topically appropriate and technically adequate content, (2) a designation
and justification of authority, and (3) a clear stipulation of what will be controlled by the
policy and how that control will be exercised.
Invocation: Invocation involves actions taken and resources utilized to invoke a rule or prescription. As Clark writes, ‘‘it is the initial or provisional characterization of the kinds
of behavior that will be permitted in terms of a prescription’’ (Clark 2002). In many
cases, governmental bodies employ individuals specialized in this function, such as law
enforcement officials, who typically exercise provisional judgments about compliance
with prescriptions. It is essential that invocation activities be clear, transparent, and
widely communicated; and that individuals acting in an official capacity are
appropriately credentialed, skilled, and trained. Lacking these conditions, invocation
Policy Sci (2009) 42:195–210 203
123
of a prescription runs the risk of appearing arbitrary in its application of governmental
authority.
Application: Application is the final, authoritative demonstration and characterization that specific behaviors or actions either do or do not comply with a prescription. Such
determinations may be founded upon legal, administrative, or technical factors, and are
thus likely to involve specially designated authorities or officers. The application
function often involves formalized interpretation of rules with respect to particular cases
or instances. While application and invocation clearly overlap, application pertains to
the later stages of an event lifecycle.
Appraisal: Appraisal involves the critical evaluation of a decision process and its particular outcomes. Through a formal and systematic process of appraisal, a community
can characterize and assess the degree to which its policy goals have been achieved.
Data and criteria relevant to the appraisal of a policy should be consistent with the
results of assessments conducted under the intelligence element of the decision process.
Termination: Termination involves the cessation, repeal, or fundamental alteration of a prescription. Often overlooked during policy formulation, termination is an action
invoked by determination or recognition that a policy has accomplished its objective(s)
and is no longer necessary, or alternatively, has failed to accomplish its goal and must be
substantially changed or abandoned in order to attempt a different solution.
As outlined in this essay, the U.S. information restriction regime is comprised of a
mixed bag of loosely coordinated statutes, executive memoranda, and legal interpretations.
It includes a variety of departmental or agency-level actions, of differing degrees of
formality, authorized at various levels of authority. As illustrated in Table 1, there appear
to be many ways in which decisions to remove or restrict environmental and public health-
related information fail to address basic aspects of the policy sciences decision process.
Most importantly, the decision process appears to have been one-sided in that more
consideration was given to security risks associated with contemplated terrorist actions
than was focused on environmental and public health-related risks due to pollutant and
toxic exposures.
Faithful and systematic application of the Lasswellian decision process does not
guarantee perfect policy. However, formal consideration and application of explicit criteria
does help to expose ‘‘mistakes, inconsistencies, contradictions, and deceptions in the
decision process.’’ It can also make clear how [a] decision factor might be improved,
according to specific standards, in practice’’ (Clark 2002).
A mechanism for balancing information access with information security
The general question of how to balance information release with national security is by no
means new. Since the end of WWII, policy makers, policy practitioners, and security
experts have engaged in a number of efforts to critique and improve the management of
sensitive information. In 1997, a commission comprised of Daniel Patrick Moynihan,
Samuel Huntington, John Deutch and others looked for ways to improve U.S. govern-
mental processes for declassification of sensitive information. According to the
Commission, persistent problems associated with sensitive information management
include huge volumes of material subject to review, limited resources within agencies, staff
resistance to mandated declassification efforts, a legacy of poor records management, and a
lack of leadership insistence that recordkeeping and declassification should be priority
204 Policy Sci (2009) 42:195–210
123
agency missions (RCPRGS 1997). Despite the institutional difficulties that plague
declassification efforts, the basic process rests upon the simple and non-controversial
rudiments of risk management. As noted by the Commission, declassification involves
identification and use of ‘‘sensible, cost-effective, and routine ways to separate the
Table 1 Narrative summary of decision process steps as they relate to removals and restrictions of envi- ronmental and public health-related information (Costner 2002; OMB Watch 2002; Dahl 2004; Gozdor et al. 2003; Pincus 2006)
Decision process element
Summary
Intelligence Removals appear to have been guided by simple templates or ‘‘rubrics’’ to help identify data or information that might tend to be sensitive if available for use by individuals or groups contemplating malevolent action. The degree to which alternatives to removal were considered is unclear. Nor is it clear whether officials attempted to balance risks associated with removal against those associated with open access and potential utilization by terrorists. Finally, there is no evidence that the process was conducted in response to specific, ‘‘actionable’’ threats to U.S. infrastructure.
Promotion The removal of environmental and public health-related information from federal agency web sites has been reviewed ex post in the context of Congressional hearings, GAO audits, and commentary on the part of the media and non- governmental watch-dog organizations. However, public commentary was not sought before-the-fact, and stakeholders were caught off-guard by removal of valued data and information applications formerly available through public access web sites.
Prescription Actions to redact or remove information from public circulation have been authorized in terms of legal precedents and statutory provisions, and initiated under the signatory authority of senior political and career officials. However, stakeholders express confusion regarding the substantive rationale behind removal decisions, and do not understand why some information items have been removed, while others remain available. In others words, the prescription function seems inconsistent and lacking in logical basis.
Invocation It is not clear that all individuals charged with review and removal of sensitive materials have been trained in security assessment. Information assessment activities and subsequent restrictions were not conducted in the public venue; nor did agencies publish their intention to conduct security screening exercises and remove information from public venues. In many ways, this series of agency actions lacked formal, meaningful invocation.
Application The removal of environmental and public health-related information seems to lack precedent, transparency, and the stipulation of reasonably foreseeable outcomes. It is not clear whether and how specific removals are subject to appeal or other forms of adjudication.
Appraisal The implications of information removal and access restrictions have not been evaluated by the agencies mentioned in this essay, at least not in a manner that has been subject to public review and critique. Nor have they provided broadly available mechanisms through which to elicit public and stakeholder feedback on the impacts associated with removal of specific information items. Further, it is not clear whether agencies have taken steps to obtain data and assess whether risks have migrated due to information restrictions, whether removals have resulted in unintended consequences, or, most fundamentally, whether and how removals have impeded non-security-related agency mission objectives.
Termination The information removal and restriction activities outlined in this essay (see Exhibit 1) have no clear sunset or termination date. Some materials removed shortly after the 9/11 attacks have been replaced, others made available through restricted conditions, and others remain unavailable.
Policy Sci (2009) 42:195–210 205
123
categories of materials no longer warranting protection from those needing to stay secret
(RCPRGS 1997; Quist 1993). Such efforts attempt to balance plausible harms associated
with information release against benefits expected to ensue from enhanced access, in
essence asking the same questions as would be asked in the context of decisions regarding
environmental and health-related information withholding or disclosure.
How should the government undertake the challenge of balancing information access
against the legitimate need for information restriction? The U.S. government’s policy for
management of federal information systems and resources is framed by a relatively
obscure document published by the Office of Management and Budget (OMB), known as
OMB Circular A-130. Using prose that sound almost Jeffersonian, Circular A-130
acknowledges that ‘‘[g]overnment information is a valuable national resource…’’ and that ‘‘[t]he free flow of information between the government and the public is essential to a
democratic society.’’ The document further states that ‘‘management of federal information
resources should protect the public’s access to government information’’ (US OMB 2000,
p. 4).
Information provision is clearly part of the organic mission of U.S. government agen-
cies. Moreover, as already noted, many U.S. laws and statutes require the collection and
public dissemination of specific types of data and information. Indeed, in some cases,
Congress has required that the government take steps to assure that stakeholders and
citizens are able to utilize disseminated data and information in an appropriate and
effective manner. 5
This means that federal agency information management activities are
subject to the Administrative Procedures Act (APA). The APA is intended to make agency
activity as open as possible to participation from outside the agency and to reduce the
scope for ‘‘arbitrary and capricious’’ decisions by requiring that agency actions be justified
and susceptible to administrative and/or court challenge. As Steven Kelman writes, even
[t]he simplest, most bare-boned procedures require that agencies publish all proposed
actions in the Federal Register and allow at least 30 days after publication for submission of written comments’’ (Kelman 1987, p. 93). Under Section 552, agencies are required to
make public ‘‘statements of the general course and method by which [their] functions are
channeled and determined, including the nature and requirements of all formal and
informal procedures.’’
Based upon the stipulations of A-130 and widely-established standards of APA practice,
it would seem reasonable to expect that U.S. federal agencies should (a) publish notifi-
cation of the planned or anticipated removal of publicly-available data and information;
and (b) articulate a decision process and associated assessment criteria through which to
determine whether specified records or information resources ought to be restricted or
removed from public access.
Congress and the Executive Branch commonly use devices such as guidelines, technical
manuals, bulletins, circulars, and interpretive memoranda to stipulate or refine policy
(Kerwin 1994, p. 258). Consistent with its policy coordination and oversight role, the
Office of Management and Budget could devise and provide guidance for departments and
executive agencies to utilize in formulating approaches to weigh competing values with
respect to decisions regarding the disposition and management of sensitive information. In
recent years, OMB guidance has been issued and used to address a wide range of sub-
stantive issues, including risk assessment protocols, state and local grants management,
5 For example, CERCLA includes provisions that not only require information sharing with the public, but
also require citizen participation and information exchange with technical experts (Gozdor et al. 2003, p. 10980).
206 Policy Sci (2009) 42:195–210
123
privacy, information technology procurement, data and information quality, economic cost
and benefit characterization methodologies, and statistical definitions.
Based on OMB guidance, agencies would develop and publish assessment criteria and a
weighing approach to formalize and guide decision making regarding whether to dis-
seminate and how best to manage potentially sensitive environmental and public health-
related information. Based on the fundamental values at play in this debate, it would seem
reasonable that OMB and agency criteria would need to recognize and address at least five
factors (Rand 2004; Herrick et al. 2008):
1. Will the document or information directly reveal a potential vulnerability or weakness in security? Agencies should consider whether the information would be useful for
selecting one or more specific potential targets, or executing an attack on a potential
target.
2. If the data or information requested were combined with other information, could it
reveal a vulnerability or weakness in security? If so, is the other information readily
available in the public domain?
3. To what degree the public or particular stakeholders benefit through the ready availability and/or release of environmental or health-related data and information?
The ability to articulate a need for the requested information should weigh heavily
toward a decision to maintain and/or enhance public access.
4. If the Agency does not release the information, will it forego a defined benefit? Agencies operate legislated programs and execute policies in order to achieve specific
mission objectives. If information redaction or restriction impedes or retards mission
functions, it should be avoided or otherwise mitigated. The ability to articulate a
benefit through information sharing should weigh heavily toward appropriately
managed dissemination and/or disclosure.
5. Is the document or information already widely available or easily retrievable to the public? Agency records and documents may have been released already and
disseminated to external organizations or be available through web sites or other
media within open sources or the public domain. If the requested information is
already readily available, withholding may not be a viable option.
Consistent with the intent and authority of the APA, a balancing framework should also
define and include administrative mechanisms to allow affected parties to seek appeal or
functional redress for the denial of information resources. It should also require a reporting
function under which agencies communicate annually to OMB, the President, and Con-
gress regarding types and instances of information withheld or restricted from public
access, information previously withheld but restored to public access, and a detailed
narrative rationale behind any such decisions. Such a framework, combined with the
appeal and reporting process, provides an appropriately thorough and transparent mech-
anism through which to consider the trade-offs entailed in agency decisions to withhold or
release certain types of data and information. Importantly, the reporting stipulation would
provide a source of data to support program evaluation and future empirical analyses of the
efficacy of alternative withholding and release policies.
Conclusion
There is little argument that the U.S. government has expanded, intensified, and further
institutionalized its use of force and coercion in the aftermath of 9/11. However, the
Policy Sci (2009) 42:195–210 207
123
constitutional legitimacy and cultural appropriateness of these security-related enhance-
ments remains open to question. As we have discussed, this tension is especially acute in
the related arenas of informed consent and public right-to-know. While the public’s right-
to-know is not absolute, it is instrumental to the exercise of fundamental rights and tra-
ditional political values. Focusing on the environment and public health, this essay has
explored sociological and rights-based reflections that point toward the need for a policy
decision process addressing dissemination or restriction of potentially sensitive
information.
In the early 1940s, Harold Lasswell introduced the construct of the garrison state
(Lasswell 1941). Animated by totalitarian claims to world order, the garrison hypothesis
asserts that civil freedoms will diminish as preparation for war and maintenance of security
become political society’s dominant thrust. The ‘‘main components of the garrison state
include compulsion, full labour, abolition of political parties, abolition of legislatures, and
abolition of elections’’ (Morgan 2004). While these extreme outcomes did not come to
pass, other aspects of the garrison concept may have begun to materialize. Commentators
such as Goldsmith and Mayer argue that factors such as warrantless wiretapping, indefinite
detention without due process, extraordinary renditions, coercive interrogation, and a
pervasive disregard of Congressional prerogative constitute a material erosion of the
American constitutional system (Goldsmith 2007; Mayer 2008) Indeed, there is a striking
similarity between Lasswell’s basic fear and the practical problems associated with
maintenance of civil liberties while simultaneously addressing a perpetual threat from
terrorists.
Acknowledgments Some of the research underlying this essay was sponsored by the American Water Works Association Research Foundation. The project was managed by Mr. Frank Blaha, who also provided helpful comments on an early draft of this paper.
References
Alexander, D. (2002). Principles of emergency planning and management. Oxford: Oxford University Press. Brewer, G. (1974). The policy sciences emerge: To nurture and structure a discipline. Policy Sciences, 5,
239–244. doi:10.1007/BF00144283. Bruins, H. (2000). Proactive contingency planning vis-à-vis declining water security in the 21st century.
Journal of Contingencies and Crisis Management, 8(2), 63–72. doi:10.1111/1468-5973.00125. Brunner, R. (1982). The policy sciences as science. Policy Sciences, 15, 115–135. doi:10.1007/BF00143074. Clark, T. (1992). Practicing natural resource management with a policy orientation. Environmental Man-
agement, 16(4), 423–433. doi:10.1007/BF02394119. Clark, T. (2002). The policy process: A practical guide for natural resource managers. New Haven: Yale
University Press. Clarke, L. (2003). Conceptualizing responses to extreme events: The problem of panic and failing grace-
fully. In L. Clarke (Ed.), Terrorism and disaster: New threats, new ideas. Oxford: Elsevier. Cohen, M. (2001). Information as a policy instrument in protecting the environment: What have we learned?
Environmental Law Reporter, 31, 10425–10431. Comfort, L. (1999). Shared risk: Complex systems in seismic response. Oxford: Pergamon, Elsevier Science
Ltd. Comfort, L. (2002). Rethinking security: Organizational fragility in extreme events. Public Administration
Review, 62(Special Issue), 98–107. doi:10.1111/1540-6210.62.s1.18. Costner, B. (2002). Access denied. The Bulletin of the Atomic Scientists, 58(2), 58–62. http://www.
thebulletin.org/print.php?art_ofn=ma02costner. Dahl, R. (2004). Does secrecy equal security? Limiting access to environmental information. Environmental
Health Perspectives, 112(2), 104–107. Douglas, M., & Wildavsky, A. (1983). Risk and culture. Berkeley: University of California Press. Dworkin, R. (1977). Taking rights seriously. Cambridge: Harvard University Press.
208 Policy Sci (2009) 42:195–210
123
Echeverria, J., & Kaplan, J. (2002). Poisonous procedural ‘‘Reform’’: In defense of environmental right to know. Washington, D.C.: Georgetown Environmental Law and Policy Institute, Georgetown University.
Faden, R., Beauchamp, T., & King, N. (1986). A history and theory of informed consent. Oxford: Oxford University Press.
Fischer, H. (2006). Disaster myths and their implications for disaster planning and response. Natural Hazards Observer, 31(1), 6–7.
Glass, T., & Schoch-Spana, M. (2002). Bioterrorism and the people: How to vaccinate a city against panic. Clinical Infectious Diseases, 34(15), 217–223. doi:10.1086/338711.
Goldsmith, J. (2007). The terror presidency: Law and judgment inside the Bush administration. New York: W.W. Norton.
Gozdor, C., Campbell Jones, S., Klick, K., & Steinhilber, M. (2003). Where the streets have no name: The collision of environmental law and information policy in the age of terrorism. Environmental Law Reporter, 33(12), 10979–10995.
Herrick, C. (2004). Objectivity versus narrative coherence: Science, environmental policy and the U.S. data quality act. Science & Public Policy, 7, 419–433.
Herrick, C., Pratt, J., Raucher, R., Kalas-Adams, N., Cotruvo, J., Darr-Bornstein, K., et al. (2006). Emer- gency response and recovery planning for water systems: A kit of tools. Denver: American Water Works Association Research Foundation.
Herrick, C., Scherer, E., & Walter, G. (2008). Critical information policies for water utilities. Denver: American Water Works Association Research Foundation.
Kelman, S. (1987). Making public policy. New York: Basic Books. Kerwin, C. (1994). Rulemaking: How government agencies write law and make policy. Washington, DC:
Congressional Quarterly Press. Lasswell, H. (1941). The garrison state. American Journal of Sociology, 46, 455–468. doi:10.1086/218693. Lasswell, H. (1971). A pre-view of policy sciences. New York: American Elsevier. Lasswell, H., & McDougal, M. (1992). Jurisprudence for a free society: Studies in law, science, and policy
(Vol. 2). New Haven: New Haven Press. Little, R. (2004). Holistic strategy for urban security. Journal of Infrastructure Systems (June), 52–59. doi:
10.1061/(ASCE)1076-0342(2004)10:2(52). Mayer, J. (2008). The dark side: The inside story of how the war on terror turned into a war on American
ideals. New York: Doubleday Books. Morgan, M. (2004). The garrison state revisited: Civil-military implications of terrorism and security.
Contemporary Politics, 10(1), 5–19. doi:10.1080/13569770410001701224. National Commission on Terrorist Attacks Upon the United States. (2004). The 9/11 Commission Report.
New York: W.W. Norton and Company. National Journal Group. (2001). Threat assessment: Chemical plants could be targets. Global Security
Newswire. http://www.nti.org/d_newswire/issues/2001/12/17/11s.html. Nickel, J. (1987). Making sense of human rights. Berkeley: University of California Press. OMB Watch. (2002). EPA turns over documents on information removal, yet questions remain. OMB
Watch. http://www.ombwatch.org/article/articleprint/738/-1/39. Padover, S. (1953). The complete Madison. New York: Harper and Brothers. Perrow, C. (1984). Normal accidents: Living with high-risk technologies. New York: Basic Books. Pincus, W. (2006). GAO finds Pentagon erratic in wielding secrecy stamp. The Washington Post. July, 14,
A19. Pozen, D. (2005). The mosaic theory, national security, and the freedom of information act. The Yale Law
Journal, 115, 628–679. Putnam, L. (2002). By choice or by chance: How the internet is used to prepare for, manage, and share
information about emergencies. First Monday, 7(11), 1–11. Quist, A. (1993). Security classification on information. Oak Ridge, TN: Oak Ridge National Laboratory. Rand. (2004). Mapping the risks: Assessing the homeland security implications of publicly available geo-
spatial information. Santa Monica: Rand Corporation. RCPRGS. (1997). Report of the commission on protecting and reducing government secrecy. (Senate
Document 105–2) Washington, DC: United States Government Printing Office. Shue, H. (1980). Basic rights. Princeton, NJ: Princeton University Press. Sidel, M. (2004). More secure less free?. Ann Arbor: University of Michigan Press. Smock, R. (2003). Prologue to a farce or a tragedy? Accessing government records in the wake of 9/11/
2001. The Public Historian, 25(2), 123–127. doi:10.1525/tph.2003.25.2.123. Tierney, K. (2003). Disaster beliefs and institutional interests: Recycling disaster myths in the aftermath of
9–11. In L. Clarke (Ed.), Terrorism and disaster: New threats, new ideas. Oxford: Elsevier.
Policy Sci (2009) 42:195–210 209
123
Tombs, R. B. (2005). Policy review: Blocking public geospatial data access is not only a homeland security risk. URISA Journal, 16(2), 49–51.
Tribe, L. (1973). Policy sciences: Analysis or ideology? Philosophy & Public Affairs, 2, 66–110. U.S. Congress. (2002). Public health security and bioterrorism preparedness act of 2002. Public Law, 107–188. U.S. Department of Justice. (2001). FOIA Post. Washington, DC: United States Department of Justice Office
of Information and Privacy. http://www.usdoj.gov/oip/foiapost/2001foiapost19.htm. U.S. Environmental Protection Agency. (2006). Terminology reference system. http://www.epa.gov/trs/. U.S. Office of Management and Budget. (2000). Circular A-130: Management of federal information
resources. Washington, DC: United States Office of Management and Budget. Weick, K., & Sutcliffe, K. (2001). Managing the unexpected. San Francisco: Jossey-Bass. Wise, C. (2006). Organizing for Homeland security after Katrina: Is adaptive management what’s missing?
Public Administration Review (May/June), 302–318. doi:10.1111/j.1540-6210.2006.00587.x. Wolf, S. (1996). Fear and loathing about the public right to know: The surprising success of the emergency
planning and community right-to-know act. Journal of Land Use and Environmental Law, 11(2), 217–320.
210 Policy Sci (2009) 42:195–210
123