Showing posts with label 30-day ICR. Show all posts
Showing posts with label 30-day ICR. Show all posts

Monday, February 24, 2014

30 Day CFATS PSP ICR – Remote Access

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


Since control systems, security systems and business networks will likely be on the list of critical assets for most facilities (depending on which DHS chemicals of interest – COI – are present) personnel with access to these systems will almost certainly require vetting under the site personnel surety plan as it is difficult to imagine when such access would be not be considered unaccompanied.

Remote System Maintenance

Most complex cyber systems (which certainly includes control systems) now comes with the option for remote system maintenance support. CFATS covered facilities that utilize such options have an obligation to ensure that the vendor’s personnel who have such access are properly vetted under the facility’s PSP. This would appear to be another instance where the background check agency provisions (discussed in the last post in the series) of the ICR would come into play.

Since there is no way that the facility will actually know which individual is remotely accessing the facility’s computer systems there will have to be some shifting of responsibility to the vendor. This would have to be done through some formal document like a memorandum of understanding and this would have to be included in the facility’s site security plan so that ISCD could review the provisions as part of the SSP authorization and approval process. This would also mean that changes in vendors would have to be reported to ISCD as part of the ‘material change’ provisions of §27.210(d), §27.215(d) or §27.225(d)(2).

Remote Monitoring

Many facilities will opt for the use of off-site security monitoring programs. Since such monitoring programs will be a significant part of the security apparatus for the facility it will certainly fall under the critical area rule requiring vetting under RSPB #12. Again the vendor providing such services would most likely fall under the Background Check Agency provisions described earlier. Again, there would have to be some formal document in the site security plan outlining the vendor’s responsibility for conducting the vetting.


Friday, February 21, 2014

30 Day CFATS PSP ICR – Background Check Agency

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


In the previous post in the series I briefly discussed the roll of background check agencies in the PSP process as described (in passing) in the ICR. A reader asked me to expand on the idea so in this post I’ll take a more detailed look at how BGCAs will fit into the PSP processes.

Visitors

One of the major problems that many commenters have had with the PSP process outlined in the ICR is the issue of visitor’s being vetted 48 hours before they are given unescorted access to the facility. There are a wide number of folks that periodically visit chemical facilities to provide a wide variety of services. Some of these personnel are asked in on extremely short notice to provide high value services.

While the facility could get around the PSP vetting rules by providing vetted escorts for these visitors, this is frequently not a realistic option given the limited number of personnel working at many of these facilities. Relying on the escort provisions of the vetting rules would end up in many cases where there is escort in name only and facility managers are smart enough to realize this in advance of the situation arising.

Organizations that routinely provide these types of services could register with the folks at DHS as a sort of BGCA. The PII for their field support personnel would be entered into the PSP tool and would be linked with all of the covered chemical facilities that they had support contracts with. When the vendor linked an employee’s information to a covered facility, that facility would be notified by ISCD that the vetting information had been provided to DHS.

In the event that one of the employees at one of these vendors had to be assigned to a new facility on short notice, it would not be problem as long as their PII had already been submitted to ISCD. As long as there was enough time for ISCD to notify the facility that the person’s information had been submitted, the visitor would be properly vetted.

Facilities would have to have some way to identify these individuals when they arrived at the facility gate. This process could easily be established by the vendor emailing a copy of their employee’s corporate ID to the facility security manager in advance of visitor’s arrival. This information could be provided to the gate personnel as part of a daily expected visitors list. Checking the identification against that list would provide the means for closing the loop on the vetting process.

Truck Drivers

Most chemical facilities see a daily parade of local and long haul truck drivers picking up and delivering materials at the facility. In many cases it is not possible to keep those trucks away from critical areas of the facility and it is typically going to be difficult to provide an escort for a truck moving through the facility.

A large number of truck drivers already have already been vetted for their Hazardous Materials Endorsement (HME) or a Transportation Workers Identification Credential (TWIC). For reasons that I discussed in the ‘Three Options’ blog in this series ISCD is still requiring a PII submission on these folks to ensure that credential vetting is up-to-date. An alternative method is provided for the TWIC folks; no data submission is required if their TWIC is periodically validated by a TWIC Reader or checked against the Canceled Card List (CCL) and the Certificate Revocation List (CRL).

Plants fully realize that they will not be able to do the required PII submissions when a truck driver shows up at their gate. The facilities will get around this by requiring all delivery companies to ensure that their drivers have been vetted against the CFATS PSP before they will be allowed to deliver or pick-up loads at the facility. Maritime Transportation Security Act (MTSA) covered facilities are already using that tactic with requiring drivers to have TWICs for similar reasons.

Trucking companies that routinely service MTSA covered facilities are going to have little problem certifying that their drivers’ TWICs are periodically validated by TWIC Readers. For companies located further from port facilities that certification will be harder to do.

Again, the trucking company could set itself up in the CFATS PSP tool as a BGCA and register their drivers. HME and TWIC holders would be entered in one portion of the tool and the remainder of the drivers in the other portion. Those registered drivers would be linked to the facilities to which they would be expected to deliver. For driver changes, all that would be necessary would be for there to be enough time for ISCD to notify the facility that the driver’s PII had been submitted.

And again, there would have to be some way to close the loop by adequately identifying the driver to the facility. This would be accomplished in the same way that I described in the Visitor’s Section above.

Contractors

Contractor is kind of an undefined term used in the ICR and the CFATS regulations. Generally speaking there are two groups of people that fit into this category. One is a large company that provides a variety of direct services to the facility under a blanket contract. These folks will almost certainly want to avail themselves of the BGCA provisions to get their people vetted. Many of these people will be moved from facility to facility as needs change so it would provide a lot more versatility to the organization if they would not have to go through a new vetting process every time they were moved.

The second kind of contractor is usually a professional that is hired individually on a contract basis for providing a specific service for a specific amount of time. The longer the expected period of the service the more likely it will be that the individual facility will handle the vetting process. For those individuals that move between facilities more frequently, it may be worthwhile to find a BGCA that provides CFATS PSP vetting services and pay them to submit his PII. In other cases it may be more appropriate for the individual contractor to handle those BGCA activities on their own.

Site Security Plan

ISCD has made clear in the ICR discussions that they intend to provide a certain amount of creative leeway for facilities to tailor the PSP program to their situation. This means that if a facility intends to allow the use of a BGCA to vet the various non-employees that periodically show up at the facility gates to work then there will have to be a decent description of how that second-party vetting process would be conducted.

ISCD also reminds folks fairly frequently in the ICR discussion that the DHS vetting against the TSDB is only one portion of the background check requirements outlined in the personnel surety Risk-Based Performance Standard. The CFATS regulations (6 CFR §27.230(12)) outline three additional types of background checks that need to be done as part of the facility PSP. Those are:

• Measures designed to verify and validate identity;
• Measures designed to check criminal history;
• Measures designed to verify and validate legal authorization to work;

The first and last of those requirements are fairly straight forward and are outlined in more general labor regulations. The second provides the facility management with a lot more leeway in what is determined to be acceptable findings in the individuals criminal history. What criminal offenses and/or times since completion of the jail time for those offenses is deemed to be disqualifying is up to the facility management.


When a facility uses a BGCA to vet some or all of their employees there needs to be clear rules spelled out for that BGCA to make those criminal history assessments. This is particularly true when non-employee vetting is being done by someone different than does the employee vetting. It would seem to be prudent to have a standard Memorandum of Understanding with each vendor, contractor or trucking company that will be serving as its own BGCA that outlines the acceptable criminal background that the facility will allow as part of its Site Security Plan.

Thursday, February 20, 2014

30 Day CFATS PSP ICR – Moving Forward

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


With less than 2 weeks left in the comment period, and no comments posted to the www.Regulations.gov web site it may be time to look at what this PSP would look like in actual practice. First, we need to remember that ISCD is only going to apply the PSP requirements to Tier 1 and Tier 2 facilities. This was done to reduce the initial work load on the new PSP system and give ISCD a chance to work the bugs out before they apply it to the bulk of the facilities. This means that another round of ICRs will be required to make that change since the current burden estimate is only based upon the participation of the Tier 1 and Tier 2 facilities.

I also understand that ICS is going to go back to their earlier rollout method of initially only requiring a limited number of Tier 1 facilities to implement the PSP. This will allow those facilities to have their Chemical Facility Inspectors (CSI) on hand during the start up to help work through any of the problems in the system. This was successfully used in the initial rollout of the Top Screen and Security Vulnerability Assessment tools.

System Design

There is going to be some time lag between the time that OMB approves the ICR and the actual implementation of the PSP tools in CSAT. This is because DHS has spent only a limited amount of time and money on developing the tools and manuals. Given the history of this program, I think that we can forgive the ISCD team for thinking that they might be required to make some changes in their current plan by the time OMB gets done with their approval process.

I think that we will see a delay of at least 60 to 90 days between the time that OMB approves the ICR and the time that ISCD announces the initial deployment of the CSAT tools and the limited initial roll out.

Registration Tool

One thing that is going to have to change is the current CSAT Registration Tool. Currently the facility registers specific people to allow them to have access to the various portions of CSAT that affects that facility. Currently the tool allows for the registration of an Authorizer (Executive responsible for CFATS implementation at the facility), Submitter (Person who actually submits completed information to ISCD via CSAT), Lead Preparer/Preparers (the folks that actually enter data into the various tools) and Reviewers (people that are authorized to look at but not touch CSAT information).

For facilities that are doing all of their own data submission in-house, there will probably be a need to add one or two folks from HR to the list of Preparers for the facility. This will not require any CSAT changes.

For facilities that are going to rely on an outside agency to handle the submission of data for their PSP, things get a bit more complicated. The easy way out (and as usual the worst way to do things) would be to authorize one person at the background check agency (BGCA) to do all of the submissions for the facility; this could be done under the current registration rules. The reason that this is the worst way to handle the registration is that we all know that there will not be just one person handling all of the data submission from the BGCA. With just one person ‘registered’ there will inevitably be login credential sharing which tends to compromise the security of the system, a system that will be handling Personally Identifiable Information (PII).

What I suspect that ISCD will do will be to allow a facility to register the use of a BGCA. The BGCA will be enrolled in the ISCD PSP and will register individual employees as Preparers for the BGCA. This will make things simpler for everybody involved. This will also allow vendors and contractors to provide information to a BGCA so that their employees that require access to CFATS facilities on a routine basis can be easily vetted for multiple facilities.

PSP Tool

With the use of BGCA I suspect that we will see effectively a dual PSP tool; one for facilities and one for BGCAs. I think that it may be listed as a single tool, but depending on how one signs in you will see two different sets tools. The basic data being submitted will be exactly the same set of PII, but there will have to be some way for the BGCA to indicate for which facility that PII will be submitted.

I would like to make a suggestion here. I think that it would be much simpler (and eliminate a number of potential errors). The BGCA should be allowed to enter an individual’s PII into the ISCD PSP tool without a chemical facility initially being listed. As they were notified by their clients (vendors, contractors and potentially even individuals) that a person was going to need to have access to a facility, they would add a facility identification number to that individual’s PSP information. Since that person would already be vetted through the PSP, the 48 hour notice would not be necessary and ISCD could send a message to the facility that the person had been vetted through the PSP.

How Long?

On March 5th, barring some unforeseen eventuality, the folks at NPPD will submit this PSP ICR request to the OMB’s Office of Information and Regulatory Affairs (OIRA). The big question is how long the approval process will take at OIRA. I have seen ICRs approved on the day of their submission, but those were either entirely non-controversial simple exercises or they were politically driven by the Administration. Neither of those applies to the CFATS PSP ICR.

A large part of the inevitable delay in OIRA is trying to work out the political bugs in the program. The more people (or the more powerful the people) that complain about an ICR the longer it will take.

I expect that we will see some negative comments from the same people that complained about the 60-day ICR. Some will go through the eRulemaking Portal, but most will go directly to OIRA outside of public scrutiny. Many of those will be politely ignored and OIRA will try to iron out compromise solutions with the complainer and NPPD/ISCD. How long that will take is anybody’s guess.


I will be very surprised if it takes less than 60 days and I would not be very surprised if it takes six month. The longer it takes past six months, however, the more likely it will be that NPPD will again have to withdraw the ICR and start all over again. I give that about a 40% chance of occurring.

Sunday, February 9, 2014

30 Day CFATS PSP ICR – Positive Match

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


One of the controversial issues in the PSP has been the DHS response to positive matches against the Terrorist Screening Database (TSDB). Industry has long expected that DHS would immediately notify them if any of the names that were submitted to the CFATS PSP returned a positive match against the TSDB. That is not, however, the Department’s stance. They have consistently stated that:

Regardless of the option, in the event that there is a potential match, the Department has procedures in place that it will follow to resolve the match and coordinate with appropriate law enforcement entities as necessary.

Information Release Controlled by Law Enforcement

In the earlier iteration of the proposal for the CFATS PSP ISCD made it clear that whenever possible, they would notify the facility as quickly as the investigative process allowed. There have been some people that have interpreted this to mean that ISCD would be handling the investigation of personnel with a positive match to the TSDB. That was specifically addressed in this notice when DHS replied:

The Department does not lead the investigation of any affected individual with terrorist ties; rather the Department supports law enforcement investigation activity.

Typically, since they own the TSDB and are responsible for counter-terrorist investigations within the United States, the FBI will be the lead investigative agency for most positive matches against the TSDB. Depending on how someone was placed on the TSDB, another federal law enforcement agency may take the lead. In any case, the lead investigative agency will be responsible for deciding when the facility management may or may not be told about a positive match by one of their employees.

The Department has made clear they understand the point of view of the facility management:

The Department recognizes the significant and vested interest the high-risk chemical facility or designee may have in ensuring an affected individual with terrorist ties does not successfully carry out a terrorist attack against or involving a high-risk chemical facility.

The Department almost certainly understands that it will look extremely bad if a terrorist attack is successfully carried out while the Department knows that the individual has been listed on the TSDB as being a suspected terrorist. It is in the best interest of the Department to provide information to the facility management as quickly as possible so that a potential threat can be removed from the facility. Still, the Department’s hands may be tied by an on-going investigation being conducted by a law enforcement agency

Other Programs

All other programs vetted through the TSA (and the TSA will be doing the actual vetting of individual information against the TSDB) have a adjudication program requirement where the individual must be informed if the TSA determines that the individual is a security threat based upon any of the background checks conducted by the TSA (the CFATS PSP is the only program that does not have TSA doing criminal background checks in addition to the TSDB vetting).

In those cases there is no imminent danger that the individual will be given unaccompanied access to a protected facility while the background check process is proceeding. This almost certainly means that a criminal investigation, if deemed necessary, would have already been initiated and probably completed by the time that the individual is informed of fact that issuance of the credential has been denied.


Perhaps ISCD should also take the same tack with respect to the CFATS PSP; set up the program in a way that facilities could not allow employees, contractors or visitors unaccompanied access to critical areas of the facility until they have been notified by DHS that the vetting process has been completed and that there is no indication of potential terrorist ties associated with the individual. Industry has maintained, however, that that is not an acceptable method of doing business and have routinely complained about the 48 hour notice requirement in the proposed program.

Sunday, February 2, 2014

30 Day CFATS PSP ICR – Three Options

This is part of an ongoing series of blog posts about the recently published 30-day information collection request (ICR) published in the Federal Register by DHS. This ICR would support the long overdue personnel surety program requirements for the Chemical Facility Anti-Terrorism Standards (CFATS) program. Earlier posts in the series include:


Scope of the PSP

Risk-Based Performance Standard 12 {6 CFR §27.230(12)} outlines the general requirements for a personnel surety program for personnel. It requires that CFATS covered facilities:

“Perform appropriate background checks on and ensure appropriate credentials for facility personnel, and as appropriate, for unescorted visitors with access to restricted areas or critical assets,”

Most of the background checks listed in the subsequent subparagraphs are conducted by the facility through a variety of governmental and non-governmental agencies. Facilities have a great deal of leeway about the scope of such checks and what negative information will be disqualifying information for determining which individuals will be employed at the facility or which visitors will be provided unescorted access to critical or sensitive areas of the facility.

The background check requirements of §27.230(12)(iv); “Measures designed to identify people with terrorist ties” require access to the Terrorist Screening Database (TSDB) maintained by the FBI. Vetting against that database is described in this ICR as an “inherently governmental function” which requires action by DHS. This ICR describes how individual facilities will initiate such action.

The Options

This ICR provides a description of the three options that DHS has currently designed for fulfilling the facility portion of the requirements for the TSDB vetting. Two of those options require submission of information by the facility; the third utilizes TWIC readers to verify that information on an individual has already been submitted and vetted against the TSDB. The notice continues to maintain that ISCD will consider, on a case by case basis, alternative methods for vetting against the TSDB that facilities might propose in their Site Security Plan (SSP) or Alternative Security Plan (ASP).

The two data submission options would require facilities to submit specific personally identifiable information (PII) to the DHS Infrastructure Security Compliance Division (ISCD) via a new on-line PSP tool within the current Chemical Security Assessment Tool (CSAT). Data submission could be done through either manual entry of individual’s information, submission of an Excel file containing information on multiple individuals, or the Department may allow the submission of the information through a Web-service (a software system designed to support interoperable machine-to-machine interaction over a network).

The first option is direct vetting of individuals. DHS would take PII provided by the facility through the PSP tool and submit it to the FBI’s Terrorist Screening Center for comparison to the TSDB. Periodically, ISCD would re-submit the same information to determine if an previously vetted individual has been added to the TSDB. This re-vetting would require no action by the facility. There is nothing in the ICR which identifies the frequency of the re-vetting process.

The second option allows DHS to use a slightly different set of PII provided by the facility to verify that other DHS agencies have already vetted the individual against the TSDB. The accepted programs already periodically re-vet against the TSDB (this is a DHS ‘best practice’) so ISCD would be able to periodically (again no definition of the period in ‘periodically’ is provided) re-validate the TSDB status of the individuals by re-checking with the issuing agency. There is no real need to define periodically here since it is purely an internal matter and does not require any action by facility owners or operators.

Presumably ISCD will continue to use TSA to conduct the actual check of the TSDB. Since TSA is charged with recovering the costs of their ‘security assessments’, they will ‘charge’ ISCD for each check of the TSDB that they conduct (I seem to remember hearing that ISCD was already ‘paying’ for this service, but I haven’t been able to track down a source for that information). Checking DHS records for the current status of other security vetting’s will not cost ISCD anything (or possibly just much less).

For facilities, there is no practical difference between option 1 and option 2. They are still required to have information (with minimal differences it the information) submitted to ISCD. They will either do it themselves, or will pay to have a third party do it for them.

There is one DHS vetting program that gets special treatment in the CFATS PSP; the TWIC card. The Department is requiring records checks of the other programs because there is no way to visually verify if the covered identity document is current and/or real. The TWIC, via a TWIC reader can be so confirmed. In the third option, the facility would not have to submit information to the CFATS PSP tool for individuals “if the high-risk chemical facility (or others acting on their behalf) electronically verify and validate the affected individuals' TWICs through the use of TWIC readers (or other technology that is periodically updated using the with revoked card information).” Presumably the last comment refers to either the Canceled Card List (CCL) or the Certificate Revocation List (CRL).

Responses to Comments about Options

There were two comments that suggested alternative methods for vetting personnel that were not employees or contractor employees. NPPD responded that the two suggested methods were outside the scope of the current ICR and implied that they would require a rulemaking to implement.

There was a comment that the proposed options in the 60-day notice did not follow recommendation #16 of the Surface Transportation Security Priority Assessment concerning the reciprocal use of various security threat assessment information. NPPD responded that “the Department has defined, and continues to define, the “enroll once, use many” concept as the ability to reuse previously submitted program enrollment information and/or vetting results upon collection of sufficient information to confirm an individual's prior enrollment in a Department program or prior vetting results”.

There were several comments to the effect that the data submission requirements for the second option actually constituted a second background check. As I noted above, ISCD would not use the provided information to conduct an actual check of the TSDB, but rather to verify a current and valid vetting under the other DHS program.

There was a similar response to comments that Option 2 violated the ‘no additional background check’ requirement of violates 49 U.S.C. 5103a(g)(1)(B)(i) [Note the link in the ICR notice went to §5103 instead of §5103a]. NPPD reiterated that no additional background checks were being done; ISCD was using the information to verify that a claimed vetting document was current. This is being done not only to prevent the use of revoked documents, but also counterfeit documents.

The Details

Once the 30-day ICR is approved by OMB’s Office of Information and Regulatory Affairs (OIRA), we can expect to see ISCD introduce the PSP tool in CFATS. They will publish at least one User’s Manual for the PSP and we can expect to see a new revision of the CSAT Registration manual to reflect the use of outside agencies for the submission of PSP data.

I expect that the actual PSP tool will be a relatively simple tool with a typical CSAT fill in the blanks type format. The ICR notice makes it clear that there will be provisions for uploading MS Excel files or XML files for bulk submissions to the system. The site will either specify the column format or will provide a template for the file (I would bet on the later).

The registration manual revision will be a completely different story. With DHS pushing hard for the use of contract organizations to submit employee data and thousands of vendors who will need to get their employees vetted (frequently for more than one facility) the registration problems look to be really complicated. I would bet that DHS will set up a separate registration program for organizations other than chemical facilities and then provide some method for covered chemical facilities to link their PSP tool to those organizations.


While the ICR notice makes it clear that employee vetting information is not Chemical-Terrorism Vulnerability Information (CVI), under current rules the fact that a facility is considered to be a CFATS covered facility is CVI. I expect that ISCD will relax that particular provision.

Saturday, February 1, 2014

30 Day CFATS PSP ICR Published

The DHS National Protection and Programs Directorate (NPPD) published a 30-day information collection request (ICR) notice in Monday’s Federal Register (79 FR 6417-6452) for the long overdue personnel surety program (PSP) for the Chemical Facility Anti-Terrorism Standards (CFATS) program. The ICR lays out at great length (35 Federal Register pages) how facilities would be expected to vet their employees, contractors, and visitors for unaccompanied access to security critical areas at high-risk chemical facilities regulated under CFATS.

NPPD’s Infrastructure Security Compliance Division (ISCD) expects that facilities will use one or more of three basic options for vetting personnel against the Department’s Terrorist Screening Database (TSDB):

Option 1 – Direct vetting

These options are essentially the same ones that were included in the earlier 60-day ICR notice, but the devil is in the details. Included in the ICR discussion are responses to the 28 comments that had been received on the earlier notice. Those ISCD responses include why they have adopted or rejected the changes suggested by the commentor.

As I did with the earlier ICR notice, I will be taking a detailed look at the provisions of the revised program in a series of blog posts.

Public Comments Solicited

As with all 30-day ICR notices public comments are being solicited. While they may be sent directly to the OMB’s Office of Information and Regulatory Affairs (OIRA), NPPD has made provisions for submission through the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0061). Comments should be submitted by March 5, 2014.

Moving Forward

The publication of a 30-day ICR notice on a new information collection program usually means that the program is nearing implementation; typically going on line in three to four months. For controversial programs the delays can be quite lengthy and the most controversial plans frequently die here, still born. While the CFATS program clearly needs a viable PSP, it is unlikely that this ICR will move forward quickly.

CFATS Legislation Effects

Throwing a further potentially complicating factor into this process is the impending introduction of new CFATS legislation by Rep. McCaul, Chair of the House Homeland Security Committee. One of the components of this bill that I have been hearing rumors about is language addressing the personnel surety issue. Chairman McCaul has frequently chided ISCD Director Wulf for not making more use of the TWIC program for the CFATS PSP.

Of course, that bill would have to pass in both the House and Senate for it to have any legal effect on the CFATS PSP. But, the presence of a viable bill in the legislative process with a significantly different look at PSP might serve to delay consideration of this ICR at OIRA.


On the other hand, the reasons for the frequent delays in the introduction of McCaul’s bill may have been because he was waiting for this notice to be published because the bill explicitly provides legislative support for this program. In that case, if the bill were to move expeditiously through the legislative process (and it would have to come to a Senate vote before the summer recess to have much chance of passing in an election year), then OIRA’s review of this notice might be accelerated.

Saturday, June 8, 2013

PHMSA Publishes 30-day Pipeline ICR

The Pipeline and Hazardous Material Safety Administration published a 30-day information collection request (ICR) in Monday’s Federal Register (78 FR 34703-34704; available on-line today) for their revision of the Gas Distribution Annual Report. This is a follow-up to the 60-day ICR published in February.

New Form Revisions

PHMSA received extensive comments from two industry organizations in response to the 60-day ICR. Those comments were received from


In response to those comments PHMSA made a number of revisions to the form or the instructions for filling out the form. Those revisions include:

• Part A, Section 6 – Change options for the operator type be consistent with those on Energy Information Agency Form EIA-176;
• Part B, Sections 1, 2 and 3 – Change to using the term “reconditioned cast iron” be used consistently in all three sections since that term is defined in the instructions;
• Part C – Change the leak cause definitions to improve clarity and make the definitions more consistent with how incident cause is reported on the gas distribution incident reporting form;
• Part D – Clarify that PHMSA is clarifying that it is seeking information on the “apparent root cause” of excavation damage;
• Part D – Change the instructions for Part D by incorporating the definitions developed by the Common Ground Alliance's DIRT program; and
• Part E – Clarify the data that PHMSA  is seeking on “Estimated Number of EFVs in System at End of Year.”

None of the above changes had any significant impact on the data collection and reporting burden place upon pipeline owners and operators.

Public Participation


As the changes above demonstrate PHMSA does pay attention to comments received from the regulated industry and other portions of the private sector. Comments do need to be submitted to have an impact. Additional public comments my be submitted directly to the Office of Management and Budget  (OIRA_Submission@omb.eop.go) on this request. Comments should be received at OMB by July 10th.
 
/* Use this with templates/template-twocol.html */