Showing posts with label Coast Guard ANPRM. Show all posts
Showing posts with label Coast Guard ANPRM. Show all posts

Wednesday, April 15, 2009

TWIC Reader ANPRM – Record Keeping Requirements

This is the final blog posting in a series of blogs about the advanced notice of proposed rule making (ANPRM) that the Coast Guard recently published about the potential regulation of transportation worker’s identification credential (TWIC) reading devices. These devices would be used to verify the identity of people working in ships and facilities covered under the Maritime Transportation Security Act (MTSA). The other blogs in this series include: TWIC Reader ANPRM – Identification Techniques TWIC Reader ANPRM – Risk Groups TWIC Reader ANPRM – Reader Use by Risk Groups TWIC Reader ANPRM – Recurring Unescorted Access TWIC Reader ANPRM – Security Plan Requirements The ANPRM expresses the Coast Guard’s current thinking about what types of requirements will be included in the regulations that will be formally proposed later this year. This post looks at potential requirements for record keeping. As with any government program, record keeping will be used to confirm compliance with the new rules. Unescorted Access Records The TWIC Readers will be able to record the date and time of every reading, along with appropriate personal identification information. This type of information may be of use in law enforcement investigations. The Coast Guard is considering requiring facility and vessel owners to keep records of the entry data for two years. Since Risk Group C facilities and vessels are not required to use a TWIC Reader to control access, they will not be required to maintain these records. Interestingly, the Coast Guard is specifically not expecting to require that exit data records be maintained. They explain that they believe that “that type of requirement would be burdensome compared to the security benefit that it would provide” (74 FR 13368). With no requirement to record exit data, there will be no requirement to read TWIC upon exiting the facility/vessel. Recurring Unaccompanied Access Records For facilities or vessels that use the recurring unaccompanied access procedure the Coast Guard is expecting to require that the owner/operator maintain records of people that have been granted unaccompanied access under the procedure. The Coast Guard expects that they would be able to look at such records during an inspection and determine the identity of the (fourteen or fewer) personnel currently being authorized unaccompanied access under the recurring unaccompanied access procedure. The other part of the recurring unaccompanied access procedure that will be inspectable is the requirement to periodically check the validity of the TWIC. To be inspectable the Coast Guard would have to require that records of the validity checks would have to be maintained.

Tuesday, April 14, 2009

TWIC Reader ANPRM – Security Plan Requirements

This is another in a series of blogs about the advanced notice of proposed rule making (ANPRM) that the Coast Guard recently published about the potential regulation of transportation worker’s identification credential (TWIC) reading devices. These devices would be used to verify the identity of people working in ships and facilities covered under the Maritime Transportation Security Act (MTSA). The other blogs in this series include: TWIC Reader ANPRM – Identification Techniques TWIC Reader ANPRM – Risk Groups TWIC Reader ANPRM – Reader Use by Risk Groups TWIC Reader ANPRM – Recurring Unescorted Access The ANPRM expresses the Coast Guard’s current thinking about what types of requirements will be included in the regulations that will be formally proposed later this year. This post looks at potential requirements for changes to security plans. Security Plan Amendments Current vessel and facility security plans were prepared, submitted and approved before these requirements were developed for the use of the TWIC Reader to identify, validate and verify the people authorized unescorted access to secure areas within the vessel or facility. Amendments to those security plans will have to be completed to take into account these new requirements. The Coast Guard is considering a six month (from the time of the publication of the final rule) time limit to submit the amended security plan, or perhaps setting up a staggered schedule to avoid having all security plans come due for renewal at the same time. Public comment on these time schedules and deadlines is requested. Security Plan Amendments could be required to address a wide variety of implementation requirements to include:
TWIC verification requirements; Unreadable fingerprint identification requirements; Separate physical access system requirements, including identity protection; Recurring unescorted access (RUA) requirements; Escort requirements at RUA facilities or on RUA vessels; Periodic card validity check requirements at RUA facilities or on RUA vessels;
Alternative Security Plan Amendments The Coast Guard does not currently believe that these TWIC Reader rules will require re-writing § 101.120. That is because there is already existing authority {§ 101.120(d)(i)(ii)} to allow the Coast Guard to order the amendments to existing ASPs. The Coast Guard expects to use the same time limits in such orders, but requests public comments on the suitability of those time limits. An organization ASP could cover more than one vessel and/or facility and could cover more than one risk group. With this in mind the Coast Guard notes that they would expect the amended ASP to address each relevant risk group.

Thursday, April 9, 2009

TWIC Reader ANPRM – Recurring Unescorted Access

This is another in a series of blogs about the advanced notice of proposed rule making (ANPRM) that the Coast Guard recently published about the potential regulation of transportation worker’s identification credential (TWIC) reading devices. These devices would be used to verify the identity of people working in ships and facilities covered under the Maritime Transportation Security Act (MTSA). The other blogs in this series include: TWIC Reader ANPRM – Identification Techniques TWIC Reader ANPRM – Risk Groups TWIC Reader ANPRM – Reader Use by Risk Groups The ANPRM expresses the Coast Guard’s current thinking about what types of requirements will be included in the regulations that will be formally proposed later this year. This post looks at potential policies related to recurring unescorted access to security areas on MTSA covered vessels and facilities. Small Vessel or Facility For small, tight knit groups personal recognition is the best form of identification. As long as the initial identification is secure and accurate, small work teams that work together on a daily basis are nearly impossible to infiltrate. It is this concept that the Coast Guard is utilizing in suggesting that small vessels and facilities may not have to require the use of a TWIC reader for Recurring Unescorted Access to secure areas within that vessel or facility. The Coast Guard is suggesting that an appropriate number of personnel that would meet this requirement is fourteen or fewer personnel. This is based on the concept of a small vessel where “the crew would typically include up to one Master, one Chief Engineer, and three four-person crews who rotate through watch shifts” (74 FR 13368). An MTSA covered vessel or facility with no more than 14 people who require unaccompanied access to the secure areas within that vessel or facility could include rules for Recurring Unescorted Access in their security plan. Personal Identification When an individual is hired to work on the small vessel or facility the individual’s identity is verified biometrically with the TWIC and a Reader. The TWIC is authenticated and validated at the same time. While working on the vessel or facility with an approved Recurring Unescorted Access plan, the TWIC will serve as a photo ID that will have to be checked periodically (on a schedule specified in the plan) but not every time that the individual enters a secure area on that vessel or facility. The individual’s TWIC will have to be periodically verified, but a TWIC reader will not be required for this validation. If a TWIC reader would not be available for the check the operator would be required to maintain a list of FASC-Ns and names of the employees in the Recurring Unescorted Access program. This list could then be verified against a current TSA Hot List of invalidated TWIC. It would actually be a negative verification; no match would be a good thing. Schedule for Validation The frequency of validation would vary by the vessel/facility Risk Group and the current MARSEC Level. For Risk Groups A and B the validation would be required weekly at MARSEC Level 1 and daily for MARSEC Levels 2 and 3. For Risk Group C the validation would have to be done monthly at MARSEC Level 1 and weekly for MARSEC Levels 2 and 3.

Monday, April 6, 2009

TWIC Reader ANPRM – Reader Use by Risk Groups

This is the second in a series of blogs about the advanced notice of proposed rule making (ANPRM) that the Coast Guard recently published about the potential regulation of transportation worker’s identification credential (TWIC) reading devices. These devices would be used to verify the identity of people working in ships and facilities covered under the Maritime Transportation Security Act (MTSA). The other blogs in this series include: TWIC Reader ANPRM – Identification Techniques TWIC Reader ANPRM – Risk Groups The ANPRM expresses the Coast Guard’s current thinking about what types of requirements will be included in the regulations that will be formally proposed later this year. This post looks at the risk based deployment requirements that might govern the actual use of the TWIC Readers. Validating Identity Generally speaking, each time an individual enters a security area on an MTSA covered facility or vessel, the individual’s identity and authorization to enter such area unescorted will be verified using the TWIC. Whether this will be done by visually checking the card or using a TWIC Reader will depend on facility/vessel risk group rating and the Maritime Security (MARSEC) level at the time of the entry. A summary of the validation requirements that the Coast Guard is currently considering is described below. Risk Group A (highest risk) at all MARSEC levels. The individual’s identity will be verified by biometric match of fingerprint to the template stored in the TWIC. The TWIC will be authenticated by a successful challenge/response with the TWIC Reader. The TWIC FASC-N will be validated against the TSA supplied Hotlist. Under MARSEC Level 1 the Hotlist will be updated weekly; it will be updated daily at MARSEC Levels 2 and 3. Risk Group B (middle risk) at MARSEC Level 1. The individual’s identity will be verified by biometric match of fingerprint to the template stored in the TWIC on one randomly selected day each month. On all other days the picture printed on the TWIC will be compared to the holder’s appearance. At MARSEC Levels 2 and 3 the individual’s identity will be verified by biometric match of fingerprint to the template stored in the TWIC every day. At all MARSEC Levels the TWIC will be authenticated by a successful challenge/response with the TWIC Reader. The TWIC FASC-N will be validated against the TSA supplied Hotlist. Under MARSEC Level 1 the Hotlist will be updated weekly; it will be updated daily at MARSEC Levels 2 and 3. Risk Group C (lowest risk) at all MARSEC Levels. The individual’s identity will be verified by comparing the picture printed on the TWIC with the holder’s appearance. The TWIC will be authenticated by visually checking security features upon entry with electronic verification by a successful challenge and response during annual inspections and random spot checks by the Coast Guard. The TWIC validation will be done by checking the expiration date at each entry. The Coast Guard will perform electronic spot checks.

Wednesday, April 1, 2009

TWIC Reader ANPRM – Risk Groups

This is the second in a series of blogs about the advanced notice of proposed rule making (ANPRM) that the Coast Guard recently published about the potential regulation of transportation worker’s identification credential (TWIC) reading devices. These devices would be used to verify the identity of people working in ships and facilities covered under the Maritime Transportation Security Act (MTSA). The other blogs in this series include: TWIC Reader ANPRM – Identification Techniques The ANPRM expresses the Coast Guard’s current thinking about what types of requirements will be included in the regulations that will be formally proposed later this year. This post looks at the risk based deployment requirements that might govern the actual use of the TWIC Readers. General Risk Considerations There are two different types of security consideration that the Coast Guard is considering to use to define the requirements for the use of these devices to validate the identity of workers authorized unescorted access to secure areas within MTSA covered facilities. The first is the security risk specifically associated with the facility where the TWIC Reader will be used. To provide a useable measure of this risk all MTSA covered vessels and facilities would be classed into one of three risk groups (A – highest risk, B, and C). The second type security risk is more general in nature and is expressed as the Maritime Security (MARSEC) level (1 – highest risk, 2, and 3). MARSEC is published by the Coast Guard for all MTSA covered facilities in a specified area and is based on current intelligence assessments. Risk Group Determination The Coast Guard has used the Maritime Security Risk Analysis Model (MSRAM) to develop a risk-based ranking for all covered vessels and facilities by type. Three factors were used in the MSRAM to produce the risk-based ranking; the “maximum consequence resulting from a terrorist attack, the criticality to the nation's health, economy and national security, and the utility of TWIC in reducing risk” (74 FR 13363). Once the MSRAM had produced a risk rank list for each type of vessel or facility covered under the MTSA regulations, those lists were analyzed using the Analytic Hierarchy Process (AHP) to divide each list into three groups. Because of the importance of these groupings to this potential regulation the Coast Guard has asked the “Homeland Security Institute (HSI) to provide an independent peer review of our analysis” using the AHP. The HIS review will, when completed this fall, be placed in the docket for this ANPRM and subsequent NPRM. Proposed Risk Groups The ANPRM (74 FR 13367) provides the descriptions of covered vessels and facilities as they fit into the three Risk Groups. Risk Group A would include:
(1) Vessels that carry Certain Dangerous Cargoes (CDC) in bulk; (2) Vessels certificated to carry more than 1,000 passengers; (3) Towing vessels engaged in towing a barge or barges subject to (1) or (2) above; (4) Facilities that handle CDC in bulk; (5) Facilities that receive vessels certificated to carry more than 1,000 passengers; and (3) Barge fleeting facilities that receive barges carrying CDC in bulk.
Risk Group B would include:
(1) Vessels that carry hazardous materials other than CDC in bulk; (2) Vessels subject to 46 CFR Chapter I, Subchapter D, that carry any flammable or combustible liquid cargoes or residues; (3) Vessels certificated to carry 500 to 1,000 passengers; (4) Towing vessels engaged in towing a barge or barges subject to (1), (2), or (3) above; (5) Facilities that receive vessels that carry hazardous materials other than CDC in bulk; (6) Facilities that receive vessels subject to 46 CFR Chapter I, Subchapter D, that carry any flammable or combustible liquid cargoes or residues; (7) Facilities that receive vessels certificated to carry 500 to 1,000 passengers; and (8) Facilities that receive towing vessels engaged in towing a barge or barges carrying hazardous materials other than CDC in bulk, crude oil, or certificated to carry 500 to 1,000 passengers. (9) All OCS [Outer Continental Shelf] facilities subject to 33 CFR part 106 would fall into risk group B.
Risk Group C would include:
(1) Vessels carrying non-hazardous cargoes that are required to have a vessel security plan; (2) Vessels certificated to carry less than 500 passengers; (3) Towing vessels engaged in towing a barge subject to (1) or (2) above; (4) Mobile Offshore Drilling Units (MODU); (5) Offshore Supply Vessels (OSVs) subject to 46 CFR chapter I, subchapters L or I; (6) MTSA-regulated facilities that receive vessels carrying non-hazardous cargoes that are required to have a vessel security plan; (7) Facilities that receive towing vessels engaged in towing a barge carrying non-hazardous cargoes; (8) Facilities that receive vessels certificated to carry less than 500 passengers.

Monday, March 30, 2009

TWIC Reader ANPRM – Identification Techniques

As I noted last Friday the Coast Guard published an advance notice of proposed rule making (ANPRM) about the use of electronic TWIC Readers. This blog will be the first in a series of blogs that will look at some of the details of the program that they are thinking about implementing. Along the way we will look at potential applications at high-risk chemical facilities not associated with MTSA covered facilities. In this first blog we will look at the various identification techniques that can be associated with the Transportation Workers Identification Credential and the TWI Reader. Identity Verification There are three different techniques that facilities can use the TWIC to verify a worker’s identity. The first, most basic and least secure is to use the picture on the card and to compare it to person’s face. Of course, any picture ID card could be used in the same way. The next most secure way to use the TWIC would be to place the card into a smart card reader and enter the worker’s 6-digit PIN into the reader. This provides about the same level of security as a standard bank card. What the TWIC was designed for was biometric identification verification. The worker’s identification is verified during the application process and an electronic copy of a fingerprint is encoded on the chip embedded in the TWIC. At the point of identification the TWIC would be placed into the TWIC Reader and the worker’s fingerprint read. The two would then be compared to verify the worker’s identity. For high-risk chemical facilities that are not covered by the MTSA rules, the security manager must determine what level of identification is necessary at that facility. Initial identification of the individual is certainly going to require verification of identity based on finger prints. For most facilities, once the initial identification verification is completed, photo ID is going to be adequate since the employee will be familiar to his co-workers. For larger facilities with multiple levels of access to areas without security guard coverage some sort of automated identification verification will be necessary. Card Authentication Since the TWIC Reader identification verification system relies on information provided by the TWIC there needs to be some form identification verification for the card itself. There are two levels of TWIC authentication available on every legitimate TWIC. First there are visible security features embedded into the front and back surfaces of the card. The absence of one or more of these visible features indicates that the card is a poor forgery. The second, more secure level of TWIC authentication requires the use of a TWIC Reader. First the Reader finds the Card Authentication Certificate programmed into the TWIC chip. The TWIC Reader then initiates a challenge and response protocol based on data included in the certificate. An improper response indicates a forged card. Any facility that designs their security identification procedures around a card system that relies on personnel identification information contained only in the card must come up with a similar type procedure. If the biometric identification information is contained in the on-site system rather than the card, methods of authenticating the identification card are not as critical. Card Validation A TWIC will spend most of its life in un-secure areas. They will be subject to theft and other forms of diversion. Workers will loose their clearance for unescorted access to MTSA security areas, but will physically retain their TWIC. There are a variety of reasons that an authentic TWIC should not be able to authorize unaccompanied access to a secure area. This means that the current status of that TWIC must be validated. When a TWIC Reader authenticates a TWIC it immediately reads the identification for that card, the Federal Agency Smart Card—Number (FASC-N). The TWIC reader then compares that FASC-N to a list of ‘bad’ numbers provided by TSA. If the FASC-N is not found on that list then the TWIC is validated. At this point the identity and security status of the holder is verified. Again, this level of sophistication would not be required for a privately developed security identification card system if the data used to verify the identity of the user was maintained on an isolated system within the security perimeter. Any identification system that allows the verification data to reside outside that perimeter must use a similar level of sophistication.
 
/* Use this with templates/template-twocol.html */