Showing posts with label ANPRM. Show all posts
Showing posts with label ANPRM. Show all posts

Wednesday, February 28, 2024

OMB Approves BIS NPRM on IT-Communications Services Update ANPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs announced that it had approved an advanced notice of proposed rulemaking (ANPRM) from the DOC’s Bureau of Industry and Security on “Update for 15 CFR Part 7”. This rulemaking was not listed in the Fall 2023 Unified Agenda.

This Part of the Commerce and Foreign Trade regulations deals with “Securing the Information And Communications Technology and Services Supply Chain”. It will be interesting to see what changes to these regulations that BIS is considering. This might not be a topic that will be covered here in this blog.

The ANPRM should be published in the next week or so.

Thursday, August 31, 2023

Review - NTSB Publishes 2 ANPRM’s for Transportation Investigations

Today the National Transportation Safety Board (NTSB) published two advanced notices of proposed rulemaking (ANPRM) in the Federal Register (88 FR 60164-60165 and 88 FR 60166-60167) for “Authority of NTSB in Railroad, Pipeline, and Hazardous Materials Investigations”. The two rulemakings would provide definitions for key terms used in existing NTSB regulations at 49 CFR 831.40(a) that were not defined in US Code at (49 USC 1131):

• ‘Substantial property damage’, and

• ‘Significant injury to the environment’

Public Comments

The NTSB is soliciting comments on both rulemakings. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov) using the docket numbers listed below:

• Railroad rulemaking - NTSB-2023-0007, and

• Pipeline rulemaking - NTSB-2023-0008

Comments on both should be submitted by October 30th, 2023.

 

For more information on both rulemakings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/ntsb-publishes-2-anprms-for-transportation - subscription required.

Tuesday, July 4, 2023

Review - PHMSA Publishes HMR Modernization ANPRM

PHMSA is publishing an advanced notice of proposed rulemaking (ANPRM) in Wednesday’s (available online today) Federal Register (88 FR 43016-43047) for “Hazardous Materials: Modernizing Regulations To Improve Safety and Efficiency”. PHMSA is publishing this ANPRM to solicit stakeholder feedback on initiatives PHMSA is considering that may modernize the Hazardous Materials Regulations (HMR) and improve efficiencies while maintaining or improving a current high level of safety. PHMSA is considering addressing 46 different topics in this rulemaking.

PHMSA notes that the HMR focuses on three primary goals:

• Ensure that hazardous materials are packaged and handled safely and securely during transportation,

• Provide effective communication to transportation workers, emergency responders, and the general public of the hazards of the materials being transported, and

• Minimize the consequences of an accident or incident should one occur.

As new technologies become available, they may have effects on achieving those goals. Fully recognizing that concept PHMSA is soliciting comments on the safety, environmental, and economic impacts of regulatory modernization initiatives suggested by the regulated community and other stakeholders.

Public Comments

PHMSA is soliciting public comments on this ANPRM and has provided an example of a format for responses that will be easiest for them to digest.. Because of the breadth of the scope of this proposed rulemaking, PHMSA does not expect each commentor to reply to each set of questions (or even each question in a given series), but the more responses that PHMSA receives, the better they will be able to craft the subsequent notice of proposed rulemaking.

Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #PHMSA-2019-0031). Comments should be sent by October 3rd, 2023 (a 90-day response window!), but that is not a hard cutoff since this is an ANPRM.

 

For more details on the 46 areas of concern, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/phmsa-publishes-hmr-modernization - subscription required.

Wednesday, November 30, 2022

Review - TSA Publishes Surface Transportation Cybersecurity ANPRM

Today the TSA published an advanced notice of proposed rulemaking (ANRM) in the Federal Register (87 FR ) for “Enhancing Surface Cyber Risk Management”. In this rulemaking the TSA “is seeking input regarding ways to strengthen cybersecurity and resiliency in the pipeline and rail (including freight, passenger, and transit rail) sectors.”

ANPRM Questions

TSA has listed a series of specific questions that it is looking for input on from industry and the public in this ANPRM. These questions cover the following topics (number of questions in each topic):

Identifying current baseline of operational resilience and incident response (6),

Identifying how CRM is implemented (6),

Maximizing the ability for owner/operators to meet evolving threats and technologies (25),

Identifying opportunities for third-party experts to support compliance (3),

Cybersecurity maturity considerations (3), and

Incentivizing cybersecurity adoption and compliance (3).

Public Comments Solicited

TSA is soliciting public comments on this ANPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # TSA-2022-0001). Comments should be submitted by January 17th, 2023 (I expect that there will be several requests for an extension of this deadline due to the holidays).

 

For more details on the ANPRM, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/tsa-publishes-surface-transportation - subscription required.


Tuesday, September 14, 2021

OMB Approves DOC Cybersecurity ANPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an advanced notice of proposed rulemaking (ANPRM) for a Department of Commerce rulemaking on “Taking Additional Steps to Address the National Emergency with Respect to Significant Malicious Cyber-Enabled Activities”. This rulemaking was not reported in the Spring 2021 Unified Agenda.

As I noted when this rulemaking was submitted to ORIA last month, I suspect that this is an action required under EO 13984 of the same name. We could see this being published in the Federal Register within the coming week.

Tuesday, March 16, 2021

DOC Supply Chain Regulations to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs announced that it had received an advanced notice of proposed rulemaking (ANPRM) from the Department of Commerce on “Securing the Information and Communications Technology and Services Supply Chain: Licensing Procedures”. This rulemaking was not listed in the Fall 2020 Unified Agenda.

It is not unusual for rulemakings to appear without being mentioned in the most recent Unified Agenda, but at the start of a new administration it typically means (especially when it is an ANPRM) that this is a new initiative of the new administration. An ANPRM is an indication of early interest in establishing a regulatory framework of some sort, but the agency is looking to industry and the public for guidance in how it could go about it.

Saturday, January 30, 2021

Comments on CFATS Explosive Chemicals ANPRM – 1-30-21

On January 6th, CISA published an advanced notice of proposed rulemaking (ANPRM) for “Removal of Certain Explosive Chemicals From the Chemical Facility Anti-Terrorism Standards”. While I posted a comment to that rulemaking on January 7th, it was not until this week that the next two public comments were posted. So this is the first post about public comments about that ANPRM.

Comments were received this week from:

Douglas Maggard, and

Aerojet Rocketdyne

Comment Summary

The Maggard comment is generally supportive of the rulemaking.

The Aerojet Rocketdyne comment notes that BATFE (Bureau of Alcohol, Tobacco, Firearms and Explosives) does not regulate explosives utilized in support of government (DoD) contracts. The commentor notes that DOD may include protection requirements in contract language, but that language may have security gaps when compared to BATFE standards.

Commentary

There are two military related exemptions to 27 CFR 555 found in §555.141. The second exemption (bear with me for a second) is found in §555.141(a)(6); it applies to:

“Arsenals, navy yards, depots, or other establishments owned by, or operated by or on behalf of, the United States.”

These facilities are already exempt from coverage under the CFATS regulations under the DOD/DOE facility exemption.

The first BATFE exemption is found at §555.141(a)(5); it applies to:

“(5) The manufacture under the regulation of the military department of the United States of explosive materials for, or their distribution to or storage or possession by, the military or naval services or other agencies of the United States.”

Such facilities would not be exempt unless they were owned or operated by the Department of Defense or Department of Energy. Thus, it would seem that such facilities would, if the proposed changes to Appendix A were put into place, such facilities would not be regulated by either BATFE or CFATS regulations. This would need to be addressed by the CFATS rulemaking.

Wednesday, January 6, 2021

CISA Publishes CFATS Explosives Removal ANPRM

Today the DHS Cybersecurity and Infrastructure Security Agency (CISA) published an advanced notice of proposed rulemaking in the Federal Register (86 FR 495-498) concerning a proposal for “Removal of Certain Explosive Chemicals From the Chemical Facility Anti-Terrorism Standards”. According to the ANPRM summary CISA is considering “removing all 49 Division 1.1 explosive chemicals of interest from Appendix A of the Chemical Facility Anti-Terrorism Standards (CFATS) regulations.” This removal would effectively terminate the requirement for facilities to report the presence of these chemicals on their facility Top Screen and could result in the removal of some facilities from the CFATS program.

Background

Currently, Appendix A, the list of DHS chemicals of interest, contains 49 Division 1.1 explosive chemicals among the 300+ chemicals that trigger a Top Screen reporting requirement if certain minimum amounts of the listed chemicals are present at a facility. CISA’s Infrastructure Security Compliance Division (ISCD) uses those reports to determine if a facility is at high-risk of terrorist attack and would thus be required to prepare and maintain a site security plan for the protection of those chemicals.

Possession of those Division 1.1 explosive also triggers security and safety regulations of the DOJ’s Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). Industry has long maintained that adding the CFATS security requirements burden to facilities that are already fully compliant with ATF regulations is unnecessarily duplicative.

In Appendix A the Division 1.1 chemicals are listed as both Release-Explosive and Theft/diversion-EXP/IEDP security issue chemicals. CISA notes in the ANPRM that it does not currently regulate any chemical facilities due to the Release-Explosive security issue from the listed explosives because ATF storage regulations mitigate the off-site consequences of any potential direct attack on such facilities.

ISCD currently regulates 85 facilities for possession of Division 1.1 chemicals as Theft/diversion security issues. Most of those facilities also have other listed COI that would trigger the CFATS coverage, but there are currently 24 facilities that are only covered under the CFATS program due to the presence of Division 1.1 explosives.

Public Comment

CISA is seeking public comment on their proposal to consider removing these chemicals from Appendix A. They are specifically asking for feedback on four specific questions:

• Should CISA remove Division 1.1 explosives for consideration as a release-explosive security concern? Why or why not?

• Should CISA remove Division 1.1 explosives for consideration as a theft/diversion-EXP/IEDP security concern? Why or why not?

• How would the removal of Division 1.1 explosives impact the security posture of chemical facilities?

• Would the removal of Division 1.1 explosives impact the regulatory burden of CFATS on chemical facilities? If so, in what ways and to what extent?

Comments may be submitted via the Federal eRulemaking Portal (www.regulations.gov; Docket #CISA-2020-0014). Comments should be submitted by March 8th, 2021

NOTE TO SELF: Reference blog post on January 4th, 2021, not all rulemakings are required to be submitted to OMB’s Office of Information and Regulatory Affairs before being published in the Federal Register.

Thursday, December 3, 2020

NHTSA Publishes Automated Driving ANPRM

Today the DOT’s National Highway Traffic Safety Administration (NHTSA) published an advanced notice of proposed rulemaking in the Federal Register (85 FR 78058-78075) for the “Framework for Automated Driving System Safety”. NHTSA is seeking public input on a framework that “would objectively define, assess, and manage the safety of ADS [automated driving system] performance while ensuring the needed flexibility to enable further innovation.”

The Framework

In this ANPRM NHTSA is not proposing the establishment of a new Federal Motor Vehicle Safety Standard (FMVSS) for ADS as it is too early in the development process to identify the critical safety characteristics that would be necessary to develop a new FMVSS. Instead, NHTSA intends to develop “a framework approach to safety for ADS developers would use performance-oriented approaches and metrics that would accommodate the design flexibility needed to ensure that manufacturers can pursue safety innovations and novel designs in these new technologies.”

In the development of this framework NHTSA plans to focus on four core functions of the ADS. Those functions are:

• How the ADS receives information about its environment through sensors (“sensing”),

• How the ADS detects and categorizes other road users (vehicles, motorcyclists, pedestrians, etc.), infrastructure (traffic signs, signals, etc.), and conditions (weather events, road construction, etc.) (“perception”),

• How the ADS analyzes the situation, plans the route it will take on the way to its intended destination, and makes decisions on how to respond appropriately to the road users, infrastructure, and conditions detected and categorized (“planning”), and

• How the ADS executes the driving functions necessary to carry out that plan (“control”) through interaction with other parts of the vehicle.

NHTSA is soliciting comments on these core functions, including:

• Whether commenters agree that these are the core functions,

• Views on NHTSA's description of these functions, and

• Whether and how NHTSA should prioritize its research as it develops a safety framework.

Additionally, NHTSA acknowledges that they have identified eight other aspects of an ADS that could be of specific interest in the development of their framework. Those include:

(1) Identifying reduced system performance and/or ODD in the presence of failure,

(2) operating in a degraded mode within reduced system constraints,

(3) performing the essential task of transporting occupants or goods from starting point to the chosen destination,

(4) recognizing and reacting appropriately to communications from first responders, including fire, EMS, and law enforcement,

(5) receiving, loading, and following over-the-air software updates,

(6) performing system maintenance and calibration,

(7) addressing safety-related cybersecurity risks, and

(8) system redundancies.

NHTSA is soliciting comments on these other aspects of an ADS described above including:

• Which of these aspects the Agency should prioritize as it continues the research necessary to develop a safety framework,

• Whether it has an appropriate role to play with any or all of these elements outside of research,

• Should NHTSA's role be regulatory or sub-regulatory for each element?

Interestingly, the Agency does note that they are not specifically authorized under the Safety Act “to regulate areas such as general privacy and cybersecurity unrelated to safety”.

Regulatory Mechanisms

Looking forward, NHTSA recognizes that at some point they will be responsible for regulating ADS safety. In this ANPRM, NHTSA looks at potential regulation mechanisms and sees comments on those topics as well. These proposed mechanisms include:

Mandatory reporting and/or disclosure,

• NHTSA'S FMVSS setting authority,

• Applying the established FMVSS framework to ADS safety principles, and

Reforming how NHTSA drafts new FMVSS to keep pace with rapidly evolving technology.

NHTSA provides the following examples of possible regulatory action:

FMVSS requiring obstacle course-based validation in variable scenarios and conditions,

FMVSS requiring vehicles to be programmed to drive defensively in a risk-minimizing manner in any scenario within their ODD [operational design domain],

FMVSS drafted in a highly performance-oriented manner,

Timing and phasing of FMVSS development and implementation,

NHTSA Soliciting Comments

As mentioned above, the Agency is soliciting public comments on this proposed rulemaking. In addition to the comments mentioned above, NHTSA includes 24 specific questions to which it is seeking public input. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2020-0106). Comments should be submitted by February 1st, 2021.

Commentary

NHTSA continues to run a catchup game on the regulation of automated driving systems. Part of that is the normal regulatory inertia that affects any government operation, but the other is the lack of Congressional direction and authorization to operate in a quickly changing technological environment. Having said that, today’s ANPRM is a significant next step in NHTSA’s effort to keep up with ADS development.

While NHTSA continues to mention cybersecurity in its ADS literature and this ANPRM, I do not think that they are taking the issue seriously enough. Not a single one of the 24 specific questions that NHTSA proposed for response addressed cybersecurity topics.

Furthermore, NHTSA missed the boat by not including a fifth ‘core function’ for ADS; “Protection”. In keeping with the language of the ANPRM, “protection” would refer to the ability of the ADS system to continue to protect the safety of the vehicle’s occupants in the event of an electronic failure due to component failure, communication (internal or external) disruption or cyberattack. In process safety terms, this means that the system has mechanisms and protocols in place to ensure that it fails in an inherently safe manner.

I think that it is important for NHTSA to encourage developers to consider system failure modalities early in the development cycle and include development of ‘fail safe’ mechanisms as a design criterion. As NHTSA moves into the FMVSSA development process it needs to consider identifying common failure modes and specifying minimum standards for engineering responses to those modalities.

This is more than just ‘cybersecurity’, though it certainly embodies a key component of operations technology cybersecurity, failure mitigation. Cyberattacks are one failure mode that must be considered in the design and development process, but other failure modes must also be addressed.  Other failure modes that should be addressed include:

• Loss of signal from external devices,

• Internal communication disruption,

• Physical, mechanical, or electronic interruption of sensors,

• Interrupted or incomplete software updates, and

• Loss of power to either powertrain or electronic systems.

Developers need to demonstrate that they have taken failure mitigation into account in their design process, documenting the failure modes identified and explaining the mitigation measures adopted. Further, they need to have an identified process in place for:

• Detecting new failure modes in development testing and real-world operations,

• Developing appropriate mitigation measures, and

• Communicating those measures to vehicles in the field.

Finally, NHTSA has to have a reporting mechanism in place for reporting newly identified failure modes and the mitigation measures adopted. And NHTSA has to be prepared to (and allowed to) proactively share those failure modes with other ADS and OEM vendors using the same or significantly similar equipment.

A copy of this blog post will be filed as a comment on this ANPRM.

Tuesday, November 3, 2020

NHTSA Sent Automated Driving Systems ANPRM to OIRA for Review

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an advanced notice of proposed rulemaking (ANPRM) from the DOT’s National Highway Transportation Safety Administration (NHTSA) concerning “Safety Principles for Automated Driving Systems”.

According to the Spring 2020 Unified Agenda abstract for this rulemaking:

“This notice solicits comments on regulatory approaches to motor vehicles equipped with Automatic Driving System (ADS). The agency seeks public comments on the creation of a safety framework for objectively and transparently assessing and validating the success of each ADS vehicle or developer in designing safety into its vehicles. More specifically, it asks commenters about developing and establishing a regulatory approach such as amending Federal Motor Vehicle Safety Standards (FMVSS) or developing alternative safety regulations relating to ADS vehicle performance.”

 Commentary

We are starting to get to that point in time where we have to consider whether the current Administration’s OMB will complete action on this rulemaking. In the normal course of events, it would not be beyond ‘reasonable’ for OIRA action on this rulemaking to be delayed beyond January 21st, 2021. If Biden is elected, I do not expect that this would be one of the rulemakings that the Trump Administration would try to press through to early, lame duck approval.

On the other hand, if this ANPRM were to be published before January 21st, I do not expect that there would be any serious opposition to the continuation of the rulemaking in the Biden Administration. In short, this is an issue that the Federal government is going to have to address in the regulatory near term. The face of the final rule would almost certainly be different under Trump or Biden administrations, but this early stage of the rulemaking is more about collecting information than actually regulating.

Tuesday, May 28, 2019

NHTSA Publishes Automated Driving Systems ANPRM


Today the DOT’s National Highway and Traffic Safety Administration (NHTSA) published an advance notice of proposed rulemaking (ANPRM) in the Federal Register (84 FR 24433-24449) concerning possible changes to the Federal Motor Vehicle Safety Standards (FMVSS) that would be necessary to support the introduction of automated driving systems (ADS-DV). This rulemaking would specifically address changes to the 100-series (crash avoidance) FMVSS.

Barriers in FMVSS


The current rulemaking will seek to address barriers in the current crash avoidance FMVSS that would impede the introduction of ADS-DV designed without traditional manual controls. NHTSA has identified three categories of such impedances:

The standard requires a manual control.
The standard specifies how the agency will use manual controls in the regulatory description of how it will test.
The definition or use of terms (e.g., “driver”) in the FMVSS that assume human control of vehicles.

The first two categories are addressed in this rulemaking. The last will be common to other sections of the FMVSS (which will be covered in separate rulemakings), so NHTSA is considering a completely separate rulemaking for the definitions problem.

Manual Control


After a brief discussion of one of the potential barriers in the FMVSS to ADS-DV introduction, NHTSA proposes four possible solutions to the manual control issue:

First, if the required control is necessary for motor vehicle safety on all vehicles, NHTSA would retain the requirement for all vehicles, even if that requires potentially redundant technologies for certain ADS-DVs without traditional manual controls.
Second, if the required control is no longer necessary for motor vehicle safety for any vehicle, NHTSA could remove or otherwise modify the requirement, if permitted to by law.
Third, if the required control is still necessary for motor vehicle safety for traditional vehicles, but not necessary for the safety of ADS-DVs without traditional manual controls, NHTSA could retain the requirement only for traditional vehicles and, if permitted by law, exclude ADS-DVs without manual controls.
Fourth, if the required control is necessary for motor vehicle safety, but a different control (i.e., a non-human-actuated control) would be necessary for an ADS-DV to perform the same function, NHTSA may retain the existing requirement for traditional vehicles, but have a separate, different control or equipment requirement for ADS-DVs without traditional manual controls.

Testing


Currently, the FMVSS “outline performance requirements that must be met under certain test procedures and NHTSA will conduct compliance verification tests in accordance with these procedures”. Where the existing language requires the use of manual controls that may not exist in ADS-DV these requirements would impede the introduction of ADS-DV. Removing these impedances will almost certainly require the development of new testing methods.

NHTSA has identified the following potential approaches to this testing dilemma:

Normal ADS-DV operation;
Test Mode with Pre-Programmed Execution (TMPE);
Test Mode with External Control (TMEC);
Simulation;
Technical Documentation for System Design and/or Performance Approach; and
Use of Surrogate Vehicle with Human Controls

Questions


The ANPRM provides a table that lists the current crash prevention FMVSS provisions that may impeded the introduction of ADS-DV. NHTSA is requesting comments on the general approaches to the manual control and testing problems identified above. It also proposes a series of questions (here, here, here, here, here, here, and here)   that it would like commenters to address.

The list of questions includes only two that address (even broadly) cybersecurity issues. They are:

22. How could vehicle-based electronically accessible libraries for conducting FMVSS testing be developed in a way that would allow NHTSA to access the system for compliance testing but not allow unauthorized access that could present a security or safety risk to an ADS-DV?

27. Could a means of manual control be developed that would allow NHTSA to access the system for compliance testing but not allow unauthorized access that could present a security or safety risk to an ADS-DV?

Comments on this rulemaking are due by July 29th, 2019. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2019-0036).

Commentary


There is a lot of interesting problems identified in this rulemaking that are going to have a profound impact on the introduction of automated driving systems. To add to the complexity, the fact that NHTSA is considering at least two (probably 3) more rulemakings addressing FMVSS compliance issues and it becomes clear that engineering for these ADS-DV systems is much further along that the regulatory scheme. Inevitably, these regulatory changes are going to cause additional problems for the engineers.

I continue to be concerned with how NHTSA is apparently glossing over the cybersecurity issue in their regulatory schema. Acknowledging that there are effectively no current cybersecurity requirements in the FMVSS, NHTSA needs to start the public comment process on how such requirements should be addressed in any modified  FMVSS requirements supporting ADS-DV introduction. Since automated controls are not going to have driver backup in vehicles designed without manual controls, security systems and requirements for those automated controls is going to be even more important than in existing cyber-augmented vehicles.

I applaud NHTSA for learning the lesson from the Volkswagen diesel mileage testing fiasco and recognizing that any automated testing program needs to be protected from on-board gaming of the test. I just wish that it could be as forward thinking in identifying potential requirements in the FMVSS for general cybersecurity protections for the vehicle.

Thursday, April 18, 2019

OMB Approves two Automated Driving Rules


Earlier this week the OMB’s Office of Information and Regulatory Affairs (OIRA) approved two advanced notices of proposed rulemaking (ANPRMs) from DOT agencies starting the regulatory process on two separate automated vehicle regulatory actions. The first was a rulemaking from the National Highway Transportation Safety Administration (NHTSA) on “Removing Regulatory Barriers for Automated Driving Systems”. The second was from the Federal Motor Carrier Safety Administration (FMCSA) on “Safe Integration of Automated Driving Systems-Equipped Commercial Motor Vehicles”.

Both of these rulemaking submissions were approved pretty quickly. The NHTSA ANPRM was submitted on March 14th, 2019 and the FMCSA ANPRM on March 21st, 2019. ANPRM’s are the first step in the rulemaking process and typically propose a list of questions that the agency would like answered by the regulated and affected communities before they actually propose regulatory action.

There is no telling when these ANPRMs will actually be published in the Federal Register. There is no procedural reason that it should be more than a couple of days, Both rulemakings were approved by OIRA ‘consistent with change’ so I suspect that it will probably be at least a month before these ANPRMs are published given the rulemaking history of the Trump Administration.

Saturday, March 23, 2019

FMCSA Sends Automated Vehicle ANPRM to OMB


On Thursday the DOT’s Federal Motor Carrier Safety Administration (FMCSA) sent an advance notice of proposed rulemaking (ANPRM) to the OMB’s Office of Information and Regulatory Affairs (OIRA) for review. The ANPRM would address the “Safe Integration of Automated Driving Systems-Equipped Commercial Motor Vehicles”.

According to the abstract in the Fall 2018 Unified Agenda:

“FMCSA requests public comment about Federal Motor Carrier Safety Regulations (FMCSRs) that may need to be updated, modified, or eliminated to facilitate the safe introduction of automated driving systems (ADS) equipped commercial motor vehicles (CMVs) onto our Nation's roadways. FMCSA requests comment on specific regulatory requirements that are likely to be affected by an increased integration of ADS-equipped CMVs. However, the Agency is not seeking comments on its financial responsibility requirements because they are not directly related to CMV technologies and because future insurance requirements will depend in part on the evolution of State tort law with respect to liability for the operation of ADS-equipped vehicles.”

Thursday, October 25, 2018

Lock-Out/Tag-Out ANPRM to OMB


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an advanced notice of proposed rulemaking (ANPRM) from DOL’s Occupational Health and Safety Administration (OSHA) for changes to their Lock-Out/Tag-Out regulations.

The abstract for this rulemaking in the Fall 2018 Unified Agenda notes:

“Recent technological advancements that employ computer-based controls of hazardous energy (e.g., mechanical, electrical, pneumatic, chemical, and radiation) conflict with OSHA's existing lock-out/tag-out standard. The use of these computer-based controls has become more prevalent as equipment manufactures modernize their designs. Additionally, there are national consensus standards and international standards harmonization that govern the design and use of computer-based controls: this approach of controlling hazardous energy is more accepted in other nations, which raises issues of needing to harmonize U.S. standards with those of other countries. The Agency has recently seen an increase in requests for variances for these devices. This RFI will be useful in understanding the strengths and limitations of this new technology, as well as potential hazards to workers.”

One of the contract jobs I did during my first break from the chemical industry was as an industrial safety instructor for a major greenfield manufacturing facility. One of the classes that I spent a great deal of time developing and then presenting to new employees was the mandatory LOTO training, both for affected and authorized employees. I have a special place in my heart for this safety program. But the reason that I am including this rulemaking notice in my blog has more to do with the cybersecurity implications of the possible rulemaking.

Anytime that we start to consider adding “computer-based controls of hazardous energy” to a safety program we need to ensure that the security of those controls are very carefully taken into account. Failure to do so will place workers in needless danger.

Wednesday, July 18, 2018

OMB Approves PHMSA Classification ANPRM


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced  that it had approved the advanced notice of proposed rulemaking (ANPRM) from the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) in regards to actions to be taken by pipeline owners when class location changes result from population increases.

While the intent of this potential rulemaking is the same as when I posted my blog entry on the submission of this rulemaking to OIRA, there has been a substantial change to the Unified Agenda entry on the topic in the Spring 2018 version of the agenda that was released since that earlier post. The Fall 2017 version contained a great deal more supporting information and explanation of what this rulemaking could entail. It is not clear if this is a change in how PHMSA views this potential rulemaking or if it is just an attempt to reduce the verbiage in the Unified Agenda.

Monday, June 25, 2018

NHTSA Sends Automated Driving ANPRM to OMB


On Saturday the DOT’s National Highway Traffic Safety Administration (NHTSA) sent an advance notice of proposed rulemaking (ANPRM) to the OMB’s Office of Information and Regulatory Affairs (OIRA) for review. According to the Spring 2018 Unified Agenda entry for this rulemaking NHTSA is looking for “public comments on NHTSA's progress in developing proposals for the establishment of a pilot research program for the safe on-road testing and development of the emerging advanced vehicle safety technologies, especially automated driving systems”.

With the number of publicly reported incidents involving accidents with automated driving vehicles on public streets, it would seem that NHTSA is more than a little late with this proposed rulemaking.

Wednesday, May 9, 2018

FAA Sends Two UAS Rules to OMB


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received two rulemakings from DOT’s Federal Aviation Administration (FAA) for review. Both rulemakings addressed operations of unmanned aircraft systems (UAS). The two rulemakings were (links are to the announcements):

Operations of Small Unmanned Aircraft Over People – Notice of proposed rulemaking (NPRM); and
Safe and Secure Operations of Small Unmanned Aircraft Systems – Advanced notice of proposed rulemaking (ANPRM)

Over People


According to the Fall 2017 Unified Agenda entry for this rulemaking:

“This rulemaking would address the performance-based standards and means-of-compliance for operation of small unmanned aircraft systems (UAS) over people not directly participating in the operation or not under a covered structure or inside a stationary vehicle that can provide reasonable protection from a falling small unmanned aircraft. This rule would provide relief from certain operational restrictions implemented in the Operation and Certification of Small Unmanned Aircraft Systems final rule (RIN 2120-AJ60) [link added].”

Safe and Secure Operations


According to the Fall 2017 Unified Agenda entry for this rulemaking:

“This action would solicit public comments for several operational limitations, airspace restrictions, hardware requirements, and associated identification or tracking technologies for Unmanned Aircraft Systems (UAS). The ANPRM will ask a series of questions regarding the balance of needs between UAS operators and the law enforcement and national defense communities. This action is necessary to address safety and security concerns from the homeland security, Federal law enforcement, and national defense communities.”

Thursday, May 3, 2018

PHMSA Sends Class Location Rule to OMB


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an advanced notice of proposed rulemaking from DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) concerning possible changes where class locations have changed due to population increases.

The Unified Agenda listing for this rulemaking notes that:

“This rulemaking regards existing class location requirements, specifically as they pertain to actions operators are required to take following class location changes. Operators have suggested that performing integrity management measures on pipelines where class locations have changed due to population increases would be an equally safe but less costly alternative to the current requirements of either reducing pressure, pressure testing, or replacing pipe. This request for public comment would be used to inform future regulatory or deregulatory efforts related to this topic.”


Wednesday, January 18, 2017

PHMSA Publishes Crude Oil Volatility ANPRM

Today the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) published an advance notice of proposed rulemaking (ANPRM) in the Federal Register (82 FR 5499-5508) concerning a possible rulemaking addressing volatility of unrefined petroleum products
and Class 3 materials.

As mentioned in an earlier post, this ANPRM is based upon a rulemaking petition filed by the Attorney General for the State of New York. According to the summary of the ANPRM that petition asks PHMSA to revise the hazardous materials regulations (HMR) to “implement a Reid Vapor Pressure (RVP) limit less than 9.0 pounds per square inch (psi) for crude oil transported by rail”. In that same summary PHMSA notes that it will use public comments on this ANPRM to “help assess and respond to the petition and to evaluate any other potential regulatory actions related to sampling and testing of crude oil and other Class 3 hazardous materials. PHMSA will also evaluate the potential safety benefits and costs of utilizing vapor pressure thresholds within the hazardous materials classification process for unrefined petroleum-based products and Class 3 hazardous materials”.

Review of Existing Data


The body of the ANPRM provides a discussion of how PHMSA currently regulates how the transportation hazards of crude oil and other flammable (Class 3) liquids are categorized. It then goes on to provide a brief discussion of how PHMSA dealt with the possible issue of adding vapor pressure to the regulatory scheme in the recent highly-hazardous flammable train rulemaking. PHMSA requested input on the potential use vapor pressure, but did not end up including it in that rulemaking.

In 2014 DOE and DOT commissioned the Sandia National Laboratory to conduct a review “of available crude oil chemical and physical property data literature to characterize and define tight crude oils based on their chemical and physical properties, and identify properties that could contribute to increased potential for accidental combustion”. The initial stages of that study concluded that “the wide-ranging variability in crude oil sample type, sampling method, and analytical method, as well as the acknowledgement that this variability limits the adequacy of the available crude oil property data set as the basis for establishing effective and affordable safe transport guidelines.”

The next phase of that Sandia study is specifically designed to determine what methods of sampling and analysis are suitable for characterizing the physical and chemical properties of different crude oils.

Questions to be Answered


While the Sandia study is on-going, PHMSA is looking for input on a wide variety of issues that would have to be considered in any proposed rulemaking on crude oil and flammable liquid vapor pressure regulation in the transportation realm. In asking for that input PHMSA is asking for answers to a specific set of questions that it breaks down into four broad categories; 24 general questions, six safety questions, eight vapor pressure questions; and a single packaging question.

The general questions covers many of the issues that any new regulatory scheme has to address to justify the cost of the regulation. It includes questions about

• How a 9.0 psi Reid Vapor Pressure limit on crude oil would affect the outcome of accidents involving crude oil transportation;
• How to measure the health and environmental effects of the proposed regulations;
• What methods could be used to reduce the vapor pressure of crude oils above the proposed limit;
• Whether the vapor pressure standard should be applied to all modes of transportation;
• Whether other risk factors that should also be addressed;
• The fixed and variable costs of establishing the vapor pressure limit; and
• The transportation of the flammable gasses removed from the crude oil;

The safety questions address the potential implications that the adoption of the vapor pressure limit have on other portions of the HMR. It includes questions about:

• The possible adoption of a new crude oil listing in the hazardous materials table (HMT) for high vapor pressure crudes; and
• The effect of flammable liquids with high concentrations of dissolved flammable gasses on the response community.

Public Responses


PHMSA is soliciting public comments on this ANPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2016-0077. Comments should be submitted by March 20th, 2017.


There will almost certainly be a large letter writing campaign (or even possibly multiple campaigns) orchestrated by environmental activist organizations. Federal agencies do not take any special cognizance of the number of comments submitted for or against a rulemaking. They are required, however, to address specific issues raised in comments. When cut-and-paste comments are received, the agency only has to deal with a single response to each of the issues raised in the response. All of the activist organizations clearly understand this, thus it would seem that these campaigns are designed more for internal reasons (most likely fund raising) than to affect the outcome of the regulatory process.

Sunday, December 18, 2016

TSA Publishes Surface Transportation Security Plan ANPRM

On Friday the DHS Transportation Security Administration (TSA) published an advance notice of proposed rulemaking (ANPRM) in the Federal Register (81 FR 91401-91416) concerning surface transportation vulnerability assessments and security plans (VASP). This is another longstanding requirement from Congress dating back to 2007. Those requirements are outlined in 6 USC 1162 (railroads, both freight and passenger) and 6 USC 1172 (over-the-road bus – OTRB – companies).

Congressional Mandate


The congressional mandate prescribed that TSA tier rank railroads and OTRBs based upon risk of terrorist attack. Additionally, Congress required that TSA establish regulations to prescribe that identified high-risk railroads and OTRBs:

• Conduct a vulnerability assessment;
• Identify a security coordinator; and
• Prepare and submit security plans to TSA for approval.

These requirements were supposed to have been in place in 2008.

Cybersecurity Requirements


Interestingly the congressional mandate specifically identified two separate cybersecurity requirements in the vulnerability assessment obligations. First was the specific inclusion of ‘information systems’ in the list of potential critical assets and infrastructure to be evaluated {§1162(d)(1)(A) and §1172(d)(1)(A)}. Second, in the list of areas in which companies were to be required to identify weaknesses, Congress specifically included “the security of programmable electronic devices (emphasis added), computers, or other automated systems” {§1162(d)(1)(C)(iii) and §1172(d)(1)(C)(iii)}.

TSA Questions


TSA starts this ANPRM with the assumption that “many higher-risk railroads (freight and passenger), public transportation agencies, and over-the-road buses (OTRBs) have implemented security programs with security measures similar to those identified by the 9/11 Act's regulatory requirements.” With that in mind TSA is looking for information on three topics:

• Existing practices, standards, tools, or other resources used or available for conducting vulnerability assessments and developing security plans;
• Existing security measures, including whether implemented voluntarily or in response to other regulatory requirements, and the potential impact of additional requirements on operations; and
• The scope/cost of current security systems and other measures used to provide security and mitigate vulnerabilities.

Additionally, TSA has included in the ANPRM a list of thirteen specific questions that it would like to see answered by surface owner/operators that have conducted vulnerability assessments of security systems/operations. Additionally, TSA provides lists of questions about:


Public Feedback


TSA is soliciting public feedback on this ANPRM. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov, Docket # TSA-2016-0002). Comments should be submitted by February 14th, 2017.

Commentary


This is very early in the rulemaking process and this ANPRM (as is usual) does not provide a lot of indication about how TSA currently envisions the regulatory process. The only real insight provided is the list of entities that TSA expects might be affected by this rulemaking. It should not be a surprise that Class 1 railroads and any railroad transporting rail security-sensitive materials (RSSM) in a high-threat urban area (HTUA) are specifically included.

Throughout the ANPRM TSA makes the point that many of the potentially regulated entities already have vulnerability assessments and security plans in place. This is based upon a number of voluntary ‘inspections’ TSA surface inspectors have done over the years. In order to show a cost-effective regulation, TSA is going to have to make every effort to allow existing effective processes to be used to meet any regulatory requirements.


Interestingly though, TSA is careful to mention ‘many existing’ not ‘most existing’ to describe current effective programs in this ANPRM. This does not provide a great deal of confidence in the current security situation almost ten years after these requirements were established by Congress.
 
/* Use this with templates/template-twocol.html */