This article is the second of a series of 4-articles that will focus on NFPA 3000® Standard for an Active Shooter/Hostile Event Response (ASHER) Program 2021. The first article gave an introduction to the standard and the further three articles will focus on the key elements of the program – Plan, Respond and Recover. This article concentrates on the importance of developing a robust plan.
Planning for any type of incident should form part of a community risk assessment and community risk reduction plan (NFPA 1300). Lessons learnt from previous active shooter/hostile events has highlighted the following key points:
- The public had no or little information on where to go or what to do;
- The public/residents were unable to locate or find out the status of loved ones;
- No communication interoperability;
- No responder integration;
- Lack of training (public and first responders);
- Years to recovery from an incident.
The action points that were highlighted and needed to be addressed included:
- The need to provide clear command points for responder control;
- Have crowd control points with meeting points for families and friends etc.;
- Establish phone help lines;
- Have on-going planning, training and joint exercises;
- Establish common communication protocols.
NFPA 3000 consists of 17 chapters which are predominately split into the three key areas – plan, respond & recover. The chapters that cover the planning phase are:
- Chapter 4 – ASHER Program Development Process.
- Chapter 5 – Risk Assessment.
- Chapter 6 – Planning/Coordination.
- Chapter 7 – Resource Management.
- Chapter 9 – Facility Preparedness.
- Chapter 10 – Financial Management.
Note: Chapter 8 – Incident Management falls under the Respond sections of the standard.
Considering the planning phase in more detail, chapter 4 provides an outline of the necessary components of an ASHER program for organizations, stakeholders and an Authority Having Jurisdiction (AHJ) with a framework for developing the program and the documented policy and program organizational statement.
Chapter 5 applies to persons/organizations with the responsibility for organizing, managing, and sustaining an ASHE preparedness, mitigation, response and recovery program. The risk assessment sits at the heart of the program development and influences all phases of an ASHER program: preparedness, mitigation, response and recovery. It is not one typical type of facility or venue in which these types of incidents occur. This is why a comprehensive risk assessment, where an entire community campus or facility can be assessed and evaluated with a specific risk rating. The process provides the requirements for assessing community and facility risks associated with an ASHE incident. The risk assessment should cover a community and facilities risk assessment and include hazard identification, vulnerability assessment, consequence identification and risk analysis. As part of the risk assessment the assessor should gain an understanding of the demographics of the people that live/work there, the building construction, its surroundings and access for emergency services, and security measures. Whist evaluating potential targets, an assessor may decide on a set of criteria and assumptions for how to judge different elements. It is important to be consistent and use the same assumptions and criteria when assessing all potential targets. The use of qualified data can be used to determine the probability of an ASHE for an area/facility. Local police crime records and statistics, community data on crime, building management data on incidents and national statistics can all be used to determine threat levels.
Identifying ‘at-risk locations’ is an important part of the risk assessment process and should include places where ASHE incidents are capable of causing death, physical injury, psychological harm, property damage, environmental impact, or system disruptions. Any location or event could be considered to be at risk particularly where there are public gatherings, places and events of national or local significance.
As highlighted earlier a community risk assessment (CRA) will need to be carried out to determine the probability of an incident and the consequences of an attack. The consequences should be grouped into four categories, namely;
- Human impacts (civilian and responder injuries, deaths, or psychological trauma);
- Economic impacts (property loss, both direct and indirect effects);
- Community impacts (public confidence);
- Functional impact (continuity of operations).
Each facility/venue identified as a risk location should be considered in the risk assessment and made available to the AHJ for further consideration within the wider CRA. Once risk assessments are complete, target hazards should be ranked based on probability and consequence. Developing an effective plan is a cornerstone to the ASHER program. The plan needs to be developed and organized in a logical framework based on resource capabilities and the risk assessment. Multi-agency and multidisciplinary relationships need to be established to develop plans, risk assessments, mutual aid agreements and protocols along with memorandums of understanding (MOU) where required. The plan development needs to use a formal process to ensure that the plans are developed, maintained, updated, tested and activated ensuring the planning team performs a gap assessment of resources necessary to meet the plan’s mission.
Community Risk Reduction (CRR) is a process to identify and prioritize local risks, followed by the integrated and strategic investment of resources (emergency response and prevention) to reduce their occurrence and impact. CRR programs typically follow a six-step approach towards development. CRR is not a new concept for the fire service with many organizations having been actively involved in fire prevention for many years through public education, building inspections and other activities. Although there is no specific blueprint for developing CRR plans, there are some common and essential steps. Ultimately, the CRR plan will be unique to each fire department, based on the types of risks for that particular community, however for an effective ASHER program multi-agency involvement will be required in the planning, response and recovery stages.
In the wider context of ASHER planning and CRR, a security threat assessment can identify the relevant spectrum of threats and realistic scenarios likely to affect a community and wider population. Analysing current data may highlight the existence of any stated or implied threat, any known precedence of similar incidents at similar sites or communities. Typical threats likely to be covered in an analysis may include terrorism, crime, civil unrest and nuisance behaviour in addition to active shooters/hostile events.
Critical infrastructure assets should be considered as they have a history of being attacked by a range of threat actors including violent extremists, disenfranchised individuals and saboteurs, and in some region’s nation states and their proxies within the context of both open and covert regional hostile actions. The primary motivation for attacking infrastructure assets is not to inflict mass casualties, but to damage or destroy physical assets that provide critical operational functions for society. Additionally, threat actors target critical infrastructure to affect not just local communities but economies and undermine confidence in governmental authority and capability, or in attempts to pressure and influence the conduct of organizations and their activities.
A vulnerability is any weakness or condition that can be exploited by an adversary or threat actor to realize an attack. Reviewing vulnerability informs the assessment of risk by considering the attractiveness of assets relative to that of other similar assets in light of control measures in place. This process allows threats and assets to be combined in a rational way into risks that are specific to a community. Vulnerabilities can include, but are not limited to, natural landscape, physical assets characteristics, human behaviour, locations of people, equipment and buildings, or operational and procedural security arrangements.
Risk analysis should provide decision makers with sufficient information to make an informed decision on the need for increasing or decreasing the investment in security and protection across the spectrum of assets under consideration. The risk analysis involves the consideration of the risk description, developed in the previous identification step, along with the combined outputs of those analyses (threat, criticality, and vulnerability analyses) that contributed to its formulation. The risk analysis should examine how these factors interact to determine an overall level of risk through a consideration of the consequences of the event occurring combined with the likelihood of the event with that consequence. Risk analysis requires a careful consideration of both likelihood and consequence. The consequence of safety and security risks can usually be expressed as a measure of financial loss, stakeholder/community impact, reputational damage, loss of operational capability, or health and safety implications. Impacts derived as part of the criticality assessment are used to inform the determination of overall risk consequence.
Factoring the outputs from these assessments the resource analysis can be determined and the following should be included as a minimum:
- A review of the minimum standards for emergency responder competencies for both law enforcement, fire and EMS;
- A review of agreements, including MOU’s, already in place between agencies;
- Identification of gaps between applicable existing standards and current capabilities;
- Development of capabilities to bridge gaps.
As part of the ASHER plan development, it must be confirmed that the plans address coordination among agencies, resource management across all disciplines, staffing requirements, integrated training with other disciplines. The plan should also consider the health and medical issues (including responder behavioral health), financial responsibilities and management along with plans for recovery and restoration.
It can be seen that the development of an effective plan to fulfil the requirements of an ASHER program can be a challenging and wide-reaching exercise. The plans should provide a starting point for multi-agency and multi-disciplinary operations and they should be flexible so they can be adjusted as circumstances and environments change. In the third installment of this series of articles we shall look at the respond phase covering incident management, communications, competencies of personnel, training and public education and information.
References:
- NFPA 1300 Standard on Community Risk Assessment and Community Risk Reduction Plan Development 2020 Edition. National Fire Protection Association
- NFPA 3000TM Standard for an Active Shooter/Hostile Event Response (ASHER) Program 2021. National Fire Protection Association.
About the Author
Branch President, GCC Branch – The Institution of Fire Engineers.
