Showing posts with label Coast Guard. Show all posts
Showing posts with label Coast Guard. Show all posts

Wednesday, April 23, 2025

Review – OMB Approves CG NRRI ICR Update – 4-22-25

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an information collection request (ICR) revision from the Coast Guard on “National Response Resource Inventory (NRRI)”. The revision reports a reduction in the number of responses expected by the Coast Guard with an increase in the burden hours.


 

For a more detailed discussion of the changes in the burden estimate provided by the Coast Guard, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-cg-nrri-icr-update-4 - subscription required.

Monday, October 18, 2021

Committee Hearings – Week of 10-17-21

This week, with both the House and Senate in Washington, there is a relatively light hearing schedule. There are two oversight hearings of potential interest here. There is one cybersecurity bill that may finally come up for a vote in the House.

Oversight Hearings

On Tuesday the Oceans, Fisheries, Climate Change, and Manufacturing Subcommittee of the Senate Commerce, Science and Transportation Committee will hold an oversight hearing on the Coast Guard. The witnesses include the Commandant and the senior enlisted person. According to the Committee’s web site, the hearing will look at “the Coast Guard’s role to safeguard our nation’s maritime interests to include budget oversight, oil spill response, marine safety, handling of sexual assault and harassment in the service, and diversity, equity, and inclusion.” I will be surprised if there are any cybersecurity questions raised.

On Thursday, the Senate Judiciary Committee will hold an oversight hearing on the Department of Homeland Security. The sole witness will be the Secretary. There is no information about the scope of the hearing. With this being the Judiciary Committee, I would not be surprised to see some questions on the Departments legal responsibilities with respect to cybersecurity.

On the Floor

According to the House Majority Leader’s ‘Weekly Leader’ site, we may finally see a vote on HR 4611, the DHS Software Supply Chain Risk Management Act of 2021. This bill was considered in the House on September 29th under the suspension of the rules process. At the end of the debate a recorded vote was demanded. The bill has been on the list of potential bills for a vote on a couple of instances since that debate. I expect that the bill will pass when the vote is held.

Wednesday, September 29, 2021

NMSAC to Look at Maritime Cybersecurity Efforts

Today, the Coast Guard published a meeting notice in the Federal Register (86 FR 53973-53974) for a teleconference of the National Maritime Security Advisory Committee (NMSAC) on October 28th, 2021. The meeting will include the presentation of two new cybersecurity tasks for consideration by NMSAC.

NOTE: There are currently some problems with the CG Homeport web site and the links to the NMSAC page are returning a ‘Cannot Be Found’ message as of this writing.

The two new cybersecurity taskings are:

• Provide feedback on cyber vulnerability assessments that are being conducted within the industry, and

• Provide input to support further development of the Maritime Cyber Risk Assessment Model.

To register to join the teleconference or provide public comments during the meeting, contact Mr. Ryan Owens (telephone 202-302-6565 or email ryan.f.owens@uscg.mil).

Friday, March 13, 2020

CG Sends Autonomous Vessel RFI to OMB


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received from the Coast Guard a request for information (RFI) for review. This pre-rulemaking document concerns “Identifying Barriers to Autonomous Vessels”.

According to the 2019 Fall Unified Agenda entry for this rulemaking:

“This notice solicits the public’s views on United States Coast Guard (USCG) regulations that may need to be updated, modified, or eliminated to facilitate the safe introduction of automated commercial vessels into our nation’s waterways. USCG requests comment on specific regulatory and operational requirements that are likely to be affected by increased integration of automated vessels into the maritime transportation system.”

Saturday, February 9, 2019

CG Withdraws Two Hazardous Substance Response Plan Rulemakings


Yesterday the Coast Guard published two notices in the Federal Register (84 FR 2799-2800 and 84 FR 2800-2801) announcing the withdrawal of two long-dormant rulemakings concerning hazardous-substance spill response plans for marine transportation related facilities and tank vessels. These rulemakings, dating back to 2000 and 1999 respectively, were intended to expand the existing oil spill response plan requirements to hazardous substances. In both instances the CG justified the withdrawal of the rulemakings by noting that: “the proposed rules are no longer appropriate to the current state of spill response in the chemical industry”.

Neither of these rulemakings had been on the Active Unified Agenda since I have been watching that for this blog until the Trump Administration added them back to the Active Agenda for the Fall 2017 Unified Agenda. It is now apparent that it was added simply because the Coast Guard was reviewing the rulemakings to be determined if they should be withdrawn.

Both announcements carefully note that:

The withdrawal of the NPRM qualifies as a deregulatory action under Executive Order 13771 (Reducing Regulation and Controlling Regulatory Costs), which directs agencies to reduce regulation and control regulatory costs and provides that “for every one new regulation issued, at least two prior regulations be identified for elimination, and that the cost of planned regulations be prudently managed and controlled through a budgeting process.”

Saturday, June 9, 2018

Maritime Cybersecurity Webinar


This week the Coast Guard added a note to their Cyber News web page about a cybersecurity webinar “specifically tailored to maritime facility and vessel owners and operators”.

The Webinar


Following the link on the page leads to another Coast Guard page providing a summary of the webinar. It lists:

• Overview of the basics of maritime information technology and operational technology
• Summary of trends in the maritime industry
• Review of the current threat environment and recent cyber events
• Discussion of common real-world vulnerabilities
• Overview of the basics of cybersecurity
• Discussion of available resources to help you reduce your cybersecurity risk
Practical guidance on how to build and enhance your cybersecurity program.

Following an additional link you come to a recorded version of a May 21st, 2018 webinar presented by the ABS Group. Registration is required to view this webinar.

Other Links


The CG summary page provides links to two other information sources. The first is an ABS Group document entitled “Choosing Cybersecurity Standards & Best Practices for Vessel & Maritime Facility Owner/Operators”. That document includes some interesting decision-trees for selecting cybersecurity standards for operational control systems. They were designed for maritime systems, but have some application to industrial control systems in general.

The second link is to a MP4 version of the webinar described above, but that is dated May 16th, 2018. No registration is required to view this version.

Commentary


I was a little disappointed in the wording of the initial notice on the CG Cyber News page. It seemed to indicate that this webinar would be held sometime in the future. This is not a major issue, the information provided in the webinar is still useful, but it is always better to ‘attend’ one of these webinars ‘live’ since provisions are made for asking questions. Those provisions do not apply to the recorded version. Advanced notice of this webinar would have been helpful.

One other point about the CG notice. There is nothing in the news item or summary page indicating that this webinar was conducted by ABS Group. Until I got to the actual webinar (in both versions) I was under the impression that this was a Coast Guard webinar. Now that could still be true if ABS Group produced this under contract for the CG, but this issue really could have been clarified better.

Friday, April 20, 2018

CG Sends TWIC Reader Rule Delay to OMB


Earlier this week the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a proposed rule from the Coast Guard that would delay the implementation of the TWIC Reader Rule. This rulemaking was not included in the Fall 2017 Unified Agenda so there are little or no details publicly available. The final rule for the TWIC Reader was published in 2016. The effective date is August 23, 2018.

While the Trump Administration has established a firm reputation for delaying the implementation of Obama Administration regulations, particularly those finalized in the closing months of that Administration, this action would appear to be something a tad bit different. This rulemaking was years in development and specifically required by law, so it clearly is not an Obama policy legacy.

It will be interesting to see what justification that the Coast Guard is using to delay the implementation of this rule.

Sunday, November 26, 2017

NMSAC to Discuss CG Cybersecurity Guidance

On Friday the Coast Guard published a meeting notice in the Federal Register (82 FR 55847-55848) for a teleconference of the National Maritime Security Advisory Committee (NMSAC) on December 14th, 2017. The conference will discuss the Cybersecurity Working Group’s recent work on the draft of the Navigation and Vessel Inspection Circular (NVIC) 05-17 (Note: the new CG Homeport does now support standard links, yeah); Guidelines for Addressing Cyber Risks at Maritime Transportation Security Act Regulated Facilities, that was released earlier this year.


The teleconference is open to the public but registration is required. There will be a public comment period at the end of the NMSAC discussion.

Saturday, August 12, 2017

CG Publishes CSF Profile Document for Passenger Operations

Earlier this week the Coast Guard published on their Home Port web page (https://homeport.uscg.mil > Cybersecurity > Cyber News > Passenger Operations Cybersecurity Framework Profile Review; sorry the CG does not use links on its HomePort) a new cybersecurity guidance document and requested public comments on the document. The new document is the “Content Preview of the Passenger Operations Cybersecurity Framework Profile”. The Coast Guard’s blog did provide a real link to the document.

The Profile


This document is an attempt by the CG to help affected organizations (US passenger vessel operations) implement the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework (CSF). According to the CG’s blog:

“A profile implements the NIST Cybersecurity Framework, which was developed in 2014 to address and manage cybersecurity risk in a cost-effective way based on business needs and without placing additional regulatory requirements on businesses. The profile is how organizations align the Framework’s cybersecurity activities, outcomes, and informative references to organizational business requirements, risk tolerances, and resource allocations.”

The Profile is a .PDF document that first provides a list of 13 passenger vessel mission objectives with a brief description of each. These objectives include:

• Maintain human safety;
• Maintain marine safety and resilience;
• Maintain environmental safety;
• Maintain guest support and basic hotel services;
• Maintain regulatory compliance;
• Assure secure communications by function and mode;
• Optimize guest experience and value;
• Maintain supply chain and turnaround;
• Disembarking, embarking, and turnaround;
• Coordinate port operations;
• Assure (optimize) lifecycle asset management;
• Maintain passenger information and accounting systems; and
• Manage, monitor and maintain non-guest-facing office technology

The Profile then provides a CSF matrix showing each of the functions, categories and subcategories listed in the CSF with a listing for each of the 13 mission objectives listed above; categorizing them as either ‘High Priority’, ‘Moderate Priority’ or ‘Other Implemented Categories’. It is interesting that they do not use the pejorative term ‘Low Priority’ in the categorization.

Public Comments


The Coast Guard is asking for public comments on the Profile. They have provided a comment submission form (download .XLS) very similar to the format used by NIST to request comments during the development of the CSF. Comments can be emailed to  HQS-SMB-CG-FAC-CYBER@uscg.mil. Comments should be submitted by September 7th, 2017.

Commentary


I really do like the general format of this Profile document. The mission statement provides a general overview of what the affected organizations are supposed to be attempting to accomplish in the operations. Tying that back into the CSF matrix with a prioritization scheme provides a workable management tool for implementation of the CSF.

There are two specific areas where ‘process control systems’ (a very interesting substitute for the term ‘industrial control systems’ that I would typically use) are prominently discussed in the Mission Objective portion of the Profile. First in the description of ‘Maintaining Human Safety’ it starts: “Recognizing cybersecurity-effects on process control systems that impact personnel safety.” Similarly, in ‘Maintain environmental safety’ it addresses cybersecurity effects “on process control systems that impact environmental safety”. Additionally, there are at least two other mission objectives that include mention of “manage support systems security”, a clear reference to various process control systems.

I am more than a little surprised at the prioritization of these ‘process control systems’ in many areas of the CSF implementation matrix, but that may be more of reflection on my lack of familiarity with passenger vessel operations than anything else. I was pleased, however, to see both the human safety and environmental safety objectives receive ‘high profile’ rankings under two of the Risk Assessment subcategories:

ID.RA -3: Threats, both internal and external, are identified and documented; and
ID.RA - 5: Threats, vulnerabilities, likelihoods, and impacts are used to determine risk

Unfortunately, that pleasure was more than offset by the ‘other’ ranking across the board for the “ID.RA -2: Threat and vulnerability information is received from information sharing forums and sources” in the same Risk Assessment Category. That hardly supports the ‘high profile’ rankings noted above.


I really do recommend that everyone with an interest in maritime safety (not just passenger vessels) take a good look at this 16-page document. It provides an interesting perspective on CSF implementation in an often-overlooked area of operations. Likewise, the control system security community (particularly those with maritime experience) should also give the document a good review. The Coast Guard deserves a wide variety in the thoughtful comments it receives on this Profile.

Thursday, June 8, 2017

Two Transportation Reg Rollback Initiative Published Today

Today DHS and DOT published separate notices in the Federal Register (82 FR 26632-26634, and 82 FR 26734-26735) requesting public feedback on potential rules and regulations that should be reviewed for potential elimination under President Trumps regulatory rollback initiative (EO 13777). The DHS initiative addresses Coast Guard regulations, guidance documents, and interpretative documents that could be repealed, replaced, or modified. The DOT effort is a Department-wide look at existing policy statements, guidance documents, and regulations to identify unnecessary obstacles to transportation infrastructure projects.

Coast Guard


DHS is looking for input on Coast Guard regulations that:

• Eliminate jobs, or inhibit job creation;
• Are outdated, unnecessary, or ineffective;
• Impose costs that exceed benefits;
• Create a serious inconsistency or otherwise interfere with regulatory reform initiatives and policies;
• Are inconsistent with the requirements of section 515 of the Treasury and General Government Appropriations Act, 2001 (44 U.S.C. 3516 note), or the guidance issued pursuant to that provision, in particular those regulations that rely in whole or in part on data, information, or methods that are not publicly available or that are insufficiently transparent to meet the standard of reproducibility; or
• Derive from or implement Executive Orders or other Presidential directives that have been subsequently rescinded or substantially modified.

Specifically, DHS is looking to review regulations found in:


They are also planning on looking at guidance documents and information collection requests.

DHS is soliciting public comments. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2017-0480). Comments should be submitted by July 10th, 2017.

DOT


The DOT initiative published today takes a slightly different tact. They are specifically trying to identify regulations, guidance documents and policies that unjustifiably delay or prevent completion of surface, maritime, and aviation transportation infrastructure projects. They want information that identifies:


DOT is soliciting public comments. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # OST-2017-0057). Comments should be submitted by July 24th, 2017.

Commentary


Regardless of how you might feel about the current administration, it is almost certainly a good idea to periodically review the current regulatory environment to ensure that outdated, outmoded or even ineffective regulations are modified or removed. There are statutory processes in place for internal departmental reviews, but no government employee is going to be able to identify or even understand all of those regulations that cause unnecessary pain and economic hardships in the regulated community.


Having said that, it should be remembered that no executive branch department can change regulatory requirements specifically mandated by Congress. Those will require legislative changes, something that can only be suggested by the Administration. This is briefly addressed in the DOT project.

Tuesday, April 4, 2017

Coast Guard Announces NMSAC Meeting

Today the Coast Guard published a meeting notice in the Federal Register (82 FR 16407-16408) concerning an upcoming meeting of the National Maritime Security Advisory Committee (NMSAC). The two-day meeting will be held on Aprils 25th, 2017 in Norfolk, VA.

The agenda items of potential interest to readers of this blog includes:



Monday, April 3, 2017

Committee Hearings – Week of 04-2-17

This week will be busy week of hearings in both the House and Senate. Of the hearings being held this week there are four that may be of specific interest to readers of this blog; two sector cybersecurity hearings, a markup hearing and a Coast Guard hearing.

Cybersecurity


On Tuesday, the Senate Energy and Natural Resources will hold a hearing to “Examine efforts to protect U.S. energy delivery systems from cybersecurity threats”. The witness list includes:

• Patricia Hoffman, US Department of Energy;
• Andrew Bochman, Idaho National Laboratory;
• Gerry Cauley, North American Electric Reliability Corporation;
• Duane D. Highley, Arkansas Electric Cooperative Corporation;
• Dave McCurdy, American Gas Association; and
• Colonel Gent Welsh, Washington National Guard

On Tuesday, the Oversight and Investigations Subcommittee of the House Energy and Commerce Committee will hold a hearing on “Cybersecurity in the Health Care Sector: Strengthening Public-Private Partnerships”. The witness list includes:

• Denise Anderson, National Health Information Sharing and Analysis Center;
• Michael McNeil, Royal Philips; and
• Terry Rice, Merck & Company, Inc.

Interestingly, the hearing background document speaks glowingly of the FDA’s efforts on medical device cybersecurity as a model for the remainder of the healthcare sector.

Markup Hearing


On Wednesday, the Senate Commerce, Science, and Technology Committee will hold a markup hearing to look at a number of bills. Of the bills being considered there are three that may be of specific interest to readers of this blog:

S 763, Surface and Maritime Transportation Security Act;
S 770, Making Available Information Now to Strengthen Trust and Resilience and Enhance Enterprise Technology (MAIN STREET) Cybersecurity Act

Neither of these bills have been published by the GPO. The links above are to committee drafts of the bills. I am holding off my reviews of the bills until the GPO version is printed.

Coast Guard


On Tuesday, the Coast Guard and Maritime Transportation Subcommittee of the House Transportation and Infrastructure Committee will hold a hearing on “Authorization of Coast Guard and Maritime Transportation Programs”. The witness list includes:

• Admiral Paul F. Zukunft, United States Coast Guard;
• Master Chief Steven W. Cantrell, United States Coast Guard
• Michael A. Khouri, Federal Maritime Commission

• Joel Szabat, Maritime Administration

Monday, March 20, 2017

Committee Hearings – Week of 3-19-17

Both the House and Senate will be in session this week. While health care and election cybersecurity will be the main press focus this week there are a large number of other hearings taking place. Three of those hearings may be of specific interest to readers of this blog. They will deal variously with cybersecurity and the Coast Guard.

Cybersecurity


On Wednesday the House Homeland Security Committee will be holding a hearing to look at “A Borderless Battle: Defending Against Cyber Threats”. The witness list includes:

• Keith B. Alexander, IronNet Cybersecurity;
• Michael Daniel, Cyber Threat Alliance;
• Frank J. Cilluffo, George Washington University; and
• Bruce W. McConnell, EastWest Institute

I do not suspect that there will be a lot of detailed information about specific control system security issues, but there will be some discussion of cyber-physical threats and policy responses.

On Wednesday the Senate Commerce Science and Transportation Committee will hold a hearing to look at “The Promises and Perils of Emerging Technologies for Cybersecurity”. The witness list includes:

• Caleb Barlow, IBM Security;
• Venky Ganesan, Menlo Ventures;
• Steve Grobman, Intel Security; and
• Malcolm Harkins, Cylance Corporation

While focusing on ‘technologies’ don’t expect this hearing to get too technical. It will almost certainly contain some discussion of cyber-physical system protection but I do not expect too much focus on specific control system technology.

Coast Guard



On Wednesday the Oceans, Atmosphere, Fisheries and Coast Guard Subcommittee of the Senate Commerce Science and Transportation Committee will hold a hearing on “State of the Coast Guard: Ensuring Military, National Security, and Enforcement Capability and Readiness”. The Commandant will be the only witness. There may be some brief discussion about the Maritime Transportation Security Act (MTSA) program enforcement, but don’t expect much detail.

Saturday, June 18, 2016

CG Announces NMSAC Meeting – 7-5-16

The Coast Guard is publishing a meeting notice in Monday’s Federal Register (81 FR 39939-39940; available on-line today) for a meeting of the National Maritime Security Advisory Committee. The public meeting will be conducted via teleconference.

Topics to be discussed during the meeting include:

• Coast Guard Cyber Security Tasking;

Cybersecurity Tasking


The NMSAC has been tasked (See CG Homeport NMSAC Full Committee Meeting Minutes September, 29-20 2015 for a list of the latest tasking statements; sorry the CG does not use links) to take a look at the feasibility of forming a Maritime Information Sharing and Analysis Center (ISAC) to share cybersecurity related information with the maritime industry. NMSAC has been asked to answer three questions:

• Is a Cybersecurity ISAC in the best interest of the Maritime Industry?
• Is a Cybersecurity ISAC feasible?
• What elements/mechanisms should exist to actively engage and recruit participation in Cybersecurity ISAC?

Next Generation TWIC


A year ago the NMSAC was tasked with looking at potential card options and features for future development of a standard which is sensible, achievable, and timely for the NexGen TWIC. That tasking included the following questions to be addressed by NMSAC:

• Should TWIC consider additional markers, if it can be accommodated, such as a QR barcode detailing card care information?
• Should TWIC consider changes to the topographical features on the front or back of the TWIC card?
• Should TWIC permit reading of the facial image in the same manner as fingerprints? [The facial image would be readable without PIN and over contact OR contactless interface]?
• Although not readily available in the immediate future, should the TWIC be available as a virtual credential?
• What other additional information should be imbedded in the TWIC, if any?

Extremely Hazardous Cargo Security


The NMSAC will receive a tasking at this meeting to work with the Chemical Transportation Advisory Committee to develop an implementation strategy for the Extremely Hazardous Cargo Security Strategy. The term ‘Extremely Hazardous Cargo’ describes a specific subset of Certain Dangerous Cargo (CDC) shipped in bulk by ship or barge. It includes bulk shipments of Chlorine, Ammonium Nitrate, Anhydrous Ammonia, LPG, and LNG. The requirement to establish this strategy was set by Congress in §812 of the Coast Guard Authorization Act for Fiscal Years 2010 and 2011 (PL 111-281).

Public Comments



There is a 15-minute period set aside for public comments during the teleconference. Written comments on the above topics may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2016-0499). Written comment should be submitted by 6-27-16.

Monday, June 13, 2016

Committee Hearings – Week of 6-12-16

The House and Senate are both in Washington this week, trying hard to get the important bills passed before they take their election year lengthened summer recess in mid-July. There are six hearings currently scheduled for this week that may be of interest to readers of this blog; three spending bill hearings, one cybersecurity, and one Coast Guard and one pipeline safety hearing.

Spending Bills


The House Rules Committee is holding a hearing as I write this blog to determine the rule for the consideration of HR 5293, the FY 2017 DOD spending bill. The Republicans are going to be backing off of open rules for these spending bills to ensure that Democrats don’t add poison pill amendments that will prevent the bills from passing (help pass a moderately liberal amendment that draws the ire of the hardcore conservatives and then vote against the final bill). We will only see some amendments in today’s rule.

Tomorrow the Rules Committee will hold their second hearing on HR 5293 to set out the remainder of the amendments that will be considered on the floor of the House.

The House Appropriations Committee will be meeting Tuesday to markup the FY 2017 DHS spending bill.

Coast Guard Hearing


The Coast Guard and Maritime Transportation Subcommittee of the House Transportation and Infrastructure Committee will be meeting Tuesday to look at “Coast Guard Mission Needs and Resources Allocation”. The hearing will probably not address chemical transportation safety or security issues. The witness list is short:

• Admiral Michel, United States Coast Guard; and
• Jennifer Grover, US GAO

Cybersecurity


The House Homeland Security Committee will be holding a hearing on Wednesday to look at “The Cybersecurity Act of 2015: Industry Perspectives”. The witness list includes:

• Matthew J. Eggers, U.S. Chamber of Commerce
• Robert H. Mayer, United States Telecom Association
• Mark Clancy, Soltra
• Mordecai Rosen, CA Technologies
• Ola Sage, e-management

Pipeline Safety


The Senate Energy and Natural Resource Committee will be holding a hearing on Tuesday to “Examine oil and gas pipeline infrastructure and the economic, safety, environmental, permitting, construction, and maintenance considerations associated with that infrastructure.” The witness list includes:

• Andrew Black, Association of Oil Pipe Lines;
• Sean McGarvey, North America's Building Trades Unions;
• Paul W. Parfomak, Congressional Research Service;
• N. Jonathan Peress, Environmental Defense Fund

On the Floor

Earlier this afternoon the House considered HR 5312, the Networking and Information Technology Research and Development Modernization Act of 2016. A vote will take place later this evening or tomorrow. Later this week the House will consider HR 5293 described above.


The Senate will be finishing up consideration of S 2943, the FY 2017 National Defense Authorization Act. As of this morning none of the amendments that have been mentioned in this blog have been considered and there is no telling if any will make it to the floor. After action is completed on S 2943, the Senate will take up S 2837, the FY 2017 Commerce, Justice and Science spending bill.

Wednesday, June 1, 2016

S 3001 Introduced – FY 2017 DHS Spending

Last week Sen. Hoeven (R,SD) introduced S 3001, the Department of Homeland Security Appropriations Act, 2017. As is the case with this spending bill there is no specific language addressing cybersecurity and only one brief mention of chemical safety/security provisions in the bill. The Senate Appropriations Committee Report on the bill, however, contains numerous mentions of these topics

Chemical Defense


The one mention of chemical issues (okay just partially chemical issues) is found in §518. That section notes that funds appropriated for the establishment of the DHS Chemical, Biological, Radiological, Nuclear, and Explosives Office cannot be spent until Congress authorizes the establishment of the office (see HR 3875 that has been passed in the House). Apparently the Appropriations Committee feels that the bill will pass in the Senate. Section 518 also required DHS to prepare a report to Congress on how it intends to stand up the bill before any money is spent.

Chemical Security


The Chemical Facility Anti-Terrorism Standards (CFATS) program is not mentioned by name in the Committee Report, but there is one mention of the Chemical Security Inspectors that make that program work and the funding level for the Infrastructure Security Compliance (the umbrella under which CFATS operates) is addressed.

The Committee Report notes (pg 29) that DHS is looking at how they support the dispersed inspection workforce for both CSI and the Protective Security Advisors program. Since these personnel are dispersed around the country DHS is looking at managing them on a regional basis instead of centrally out of Washington. The Report calls for the OIG to undertake a study of how DHS implements this change.

The funding level for ISCD has been set (pg 98) at $72.3 Million, about $6.3 Million less than requested and $6.0 Million less than last year. The cuts are justified based upon the slow hiring rate. Like last year, the Committee notes that there is no funding set for the Ammonium Nitrate Security Program, reflecting the lack of progress on that rulemaking. Recognizing the problems ISCD is having crafting a cost effective security program the Committee again “encourages NPPD to continue working with stakeholders that manufacture, sell, and transport explosive precursor chemicals to achieve the objectives of the ammonium nitrate rulemaking process taking into consideration the costs and benefits of any recommendations”.

Cybersecurity


The Committee Report starts off (pgs. 6-7) by noting that cybersecurity is #2 of the top three priorities that the Committee has set forth in crafting this bill. The Committee is recommending $1.8 Billion across DHS for cybersecurity spending; more than a 10% increase over the FY 2016 spending level. The bulk (2/3rds) of this money is going to the National Protection and Program Directorate that funds “programs specifically aimed at protecting civilian, Federal, and State networks”. This includes (pg 7):

• A 19% increase in US CERT funding to $117 Million;
• $281 Million for Federal Network Security; and
• $480 Million for Network Security Deployment (including Einstein)
• $13.9 Million for National Computer Forensics Institute (pgs. 90-1);
• Only $2.5 Million of the requested increase for ICS-CERT (pg 98);

Surface Transportation Security


Surface transportation security issues continue to get systematically overlooked by Congress. The Committee is increasing the funding for surface transportation security (pg 71) at TSA to $122 million. That includes all non-aviation modes of transportation and is a 10% increase in funding over FY 2016.

The report briefly mentions rail security (pg 110), but that is a misnomer. What is actually being discussed is the importance of grant funding for first responder training for rail accidents that include hazardous chemical (most specifically crude oil) spills. No specific funding is mentioned, but FEMA is required to prepare a report to Congress on the “unique needs of first responders related to hazardous materials transportation (including crude oil) and response to incidents”.

Coast Guard Security Issues


The Coast Guard is a big and expensive agency within DHS and gets plenty of mention. Chemical safety and security issues only get passing mention, however. The Committee report takes the CG to task for failing to publish their Notice of Proposed Rulemaking (NPRM) on Facility Security Officer Training; a rulemaking that is not even listed on the Spring 2016 Unified Agenda or Long Term Agenda for the Coast Guard. The Committee directs the CG to publish the NPRM next year.

Moving Forward



This bill should make it to the floor of the Senate for consideration during the month of July. There is a very outside chance that the House could take up their version of the bill (it should be introduced next week) before the summer recess. It is unlikely, however, that the inevitable differences could be worked out in the two bills during the abbreviated fall schedule before the end of the physical year. I really expect that we will see a continuing resolution that will tide the spending over until after the election. What happens after the election is anyone’s guess at this point.

Saturday, March 5, 2016

CG Publishes NPPD Report on Effects of Malicious Cyber Activity

This week the Coast Guard published a report by DHS-NPPD Office of Cyber and Infrastructure Analysis about the consequences of malicious cyber activity directed against seaport operations. The report, Consequences to Seaport Operations from Malicious Cyber Activity {sorry the CG Homeport does not use real links so: CG Homeport –> Cybersecurity –> Cyber Information (More)} takes a fairly high-level look at cyber threats.

Key Findings


The report makes the following four key findings:

• Unless cyber vulnerabilities are addressed, they will pose a significant risk to port facilities and aboard vessels within the Maritime Subsector;
• A cyber-attack on networks at a port or aboard a ship could result in lost cargo, port
disruptions, and physical and environmental damage depending on the systems affected;
• The impacts to critical infrastructure sectors depend on how a cyber-attack affects a port,
the level and length of disruption that occurs at the port, and the capability to divert
shipments to other ports;
• Several mitigation measures can increase the security and resiliency of ports: setting up maritime cybersecurity standards, sharing information across the sector, conducting routine vulnerability assessments, using best practices, mitigating insider threats, and developing contingency plans for cyber-attacks.

Cybersecurity Vulnerabilities


After providing a statistical overview of seaport operations in the United States and the various types of cyber systems (both land-side and ocean-going) that support those operations, the report provides a broad look at the various types of cybersecurity vulnerabilities that face operators of those systems. These include (with a brief discussion of each):

• Limited cybersecurity training and preparedness;
• Inadequately protected commercial off-the-shelf technologies and legacy systems;
• Errors in software;
• Network connectivity and interdependencies;
• Software similarities;
• Foreign dependencies;
• GPS jamming and spoofing; and
• Insider threats

This is followed by a brief discussion about how these vulnerabilities could be used to effect cyber-attacks on port operations and ship operations. Real-life illustrative examples are provided where available. For port operations the report looks at:

• Disruption of cargo operations;
• Accessing ICS;
• GPS disruption; and
• Other malicious activities

For ship operations the report looks at:

• GPS jamming and spoofing; and
• ICS access

Critical Infrastructure Effects


The report then looks at the consequences attacks on port systems could have on the general economy by addressing specific effects on various areas of critical infrastructure. A substantial number of real world examples are used to illustrate the potential effects. The effects on the following specific critical infrastructure sectors are looked at:

• Critical manufacturing;
• Commercial facilities;
• Food and agriculture;
• Energy;
• Chemical; and
• Transportation systems

Mitigation Measures


The concluding portion of this report very briefly discusses mitigation measures that could be employed. The measures discussed (at just a paragraph each) include:

• Establishing cybersecurity standards;
• Implementing information sharing systems;
• Conducting vulnerability assessments and exercises;
• Ensure the use of best practices;
• Resiliency efforts; and
• Ultimately, use unaffected alternative ports in the event of a real cyber-attack.

Commentary


One important vulnerability left out of this discussion is the area of information protection. Recent reports that sea going pirates are hacking shipping information about cargoes and shipping routes to target specific ships points out how much valuable information is being used in port information systems. Attacks on those information systems could also be used to misdirect the land-side shipment of high-value containers, expanding the reach of cargo hijackers.

While this report approaches the issue from a very high-level perspective of the port related cybersecurity problems facing the country, there is hardly a resounding call to action included in the report. The very brief and wholly inadequate discussion of mitigation measures leaves the impression that there is not much that can be done to prevent cyber-attacks or mitigate the effects of a cyber-attack. The final mitigation measure of just using an unaffected alternate port emphasizes the effective hands-off approach that the OCIA appears to be offering to the potential problem.


While I understand that the OCIA has no direct responsibility for port operations, the fact that this report was released by the Coast Guard means that it should have included, either as an addendum to the report or as a separate cover document, a proposed course forward for the Coast Guard, shippers, port operators and port facility owners. The failure to set the course will ensure that this document will settle into the Saragossa Sea of maritime bureaucratic effluvia, soon to be forgotten.

Tuesday, February 23, 2016

CG Notice Withdraws Frack Water Barge Shipment Policy Letter

Today the Coast Guard published a notice in the Federal Register (81 FR 8976-8978) withdrawing its proposed policy letter concerning the carriage of shale gas extraction waste water (SGEWW) in bulk via barge that was published in October of 2013. The Coast Guard will continue to approve such shipments on a case by case basis.

The Coast Guard regulations for transporting hazardous bulk liquid cargoes by barges are covered under 46 CFR Parts 151 and 153. SGEWW is not one of the listed products in §151.05 so any shipments of that material are required (§151.05-15) to obtain specific permission from the Commandant before it can be shipped by barge. The proposed policy letter would have set forth a standard procedure for requesting that approval.

The only reason given for the withdrawal of the proposed policy letter is that the low number of requests for approval to-date indicate a relative lack of interest on the part of the industry. The notice indicates that the Coast Guard will continue to collect information from the requests it has/will receive and re-evaluate the need for guidance documents or additional regulation at some future date.

Commentary

There is a discussion in the notice about the comments that the CG did receive during the comment period for the original notice. Over 70,000 comments were received with more than 68,000 coming in an organized campaign of form letters. The Coast Guard noted that those form letters expressed opposition to the policy letter but failed to offer “input regarding the substance of transporting SGEWW in bulk as described in the policy. In short the campaign was targeted at opposing fracking (which is outside of the control or regulation of the Coast Guard) rather being concerned with the safe transportation of the SGEWW.

The people behind these types of response campaigns to regulatory issues know full well that failure to address the specific issues involved in the proposed regulations/guidance means that the responses will largely be ignored by the regulatory agency. This is especially true when the issues raised in the form letters are not under the control of the agency soliciting public input. All this means is that the organizing entity is not really trying to influence government policy but is simply trying to raise money to keep their organization funded by appearing to address the concerns of its constituents.


Now there is nothing inherently wrong with organizing a letter writing campaign. In fact, a smaller campaign with only 140 signatories did raise specific issues with the policy letter and suggested that a rulemaking process might be better suited to this situation. The CG disagreed with that final point, but did agree with other points raised in the letter and noted that they would take them into consideration during the on-going case-by-case approval process.

Saturday, February 13, 2016

CG - Application of Cybersecurity Principles

Yesterday the Coast Guard published a copy of “The Application of Cybersecurity Principles to Marine and Offshore Operations” on their Homeport web site (sorry the CG does not use real links on Homeport – You can find this under the Cybersecurity tab). The publication is apparently the first volume in a series of publications on maritime cybersecurity being published by the American Bureau of Shipping.

A quick look at the table of contents looks like the 35-page publication covers the basics of cybersecurity (both IT and OT). It will be interesting to see what specific changes are being recommended for the maritime environment.

There is a nice brief discussion about cybersecurity in general in the first section of the publication. It makes a significant comment that applies to a variety of environments beyond just the maritime (pg 2):

“Most organizations arguably understand the need for protecting and monitoring cyber-linked business support and control systems. Even so, the breadth and complexity of protecting such systems may present a daunting challenge to many organizations that do not have a comprehensive picture of cybersecurity.”

There is also an important discussion of how cybersecurity and safety intersect, particularly in cyber-physical systems (CPS). The authors make an important point (pg 3):

“A cybersecurity incident on a ship, on a platform, or within a facility, might result from system fault or failure, operator error or inaction, inadvertent conflicts in incompatible software, or deliberate malfeasance or malice. Any such incident may result in intrusion or malfunction in a general purpose network, resulting in a cascading failure that can spread into ship or platform CPS to cause unexpected consequences for any number of systems.”


This looks like a document that will be well worth reading by anyone in control system management as well as cybersecurity professionals. Certainly the maritime community should, as the Coast Guard intended, take a specific interest in this publication and the remainder of the series as it becomes available.

Thursday, February 4, 2016

CG Chemical Transportation Advisory Committee Meeting Announced

Today the Coast Guard published a meeting notice in the Federal Register (81 FR 6028-6030) for a three-day meeting of the Chemical Transportation Advisory Committee starting March 1st, 2016 in Houston, TX. The first two-days of the meeting will be at the sub-committee level with the final day being a public full-committee meeting.

The separate subcommittee meetings will address the following topics:

• Task Statement 13-06: Harmonization of Response and Carriage Requirement for Oil-Like Substances, including Biofuels and Biofuel Blends.
• Task Statement 13-03: Safety Standards for the Design of Vessels Carrying Natural Gas or Using Natural Gas as Fuel.
• Task Statement 13-07: Recommendations for Safety Standards for Ship to Ship Transfer of Hazardous Material Outside of the Baseline.
• Task Statement 13-01: Recommendations for Guidance on the Implementation of Revisions to MARPOL Annex II and the International Code for the Construction and Equipment of Ships Carrying Dangerous Chemicals in Bulk (commonly known as IBC code) and 46 CFR 153 Regulatory
• Task Statement 13-04: Improve Implementation and education of discharge requirements related to solid bulk cargo residues.
• Task Statement 15-01: Marine Vapor Control System (VCS) Certifying Entities (CE) Guidelines update and VCS supplementary guidance for the implementation of the final rule.

Additional information on the task statements can be found under the CTAC tab on the left side of the CG Homeport page. Sorry the CG does not use live links on the Homeport site so you have to click through the menu options. Someday the Coasties will really join the internet age.

The full committee meeting will address the topics described above and will attempt to formulate recommendations to the Commandant on each of the topics. Additionally, the Committee will receive CG updates on:

• International Maritime Organization activities as they relate to the marine transportation of hazardous materials.
• U.S. regulations and policy initiatives as they relate to the marine transportation of hazardous materials.


These meetings are open to the public and there will be public comment periods scheduled in each subcommittee meeting as well as at the full committee meeting. People wishing to attend the meetings should pre-register via email (Cristina.E.Nelson@uscg.mil). Those wishing to pre-register to make an oral public comments can do so by email (Evan.D.Hudspeth@uscg.mil). Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2016-0031). Those comments should be submitted by February 12th, 2016 so that they can be distributed to Committee members before the meeting.
 
/* Use this with templates/template-twocol.html */