Showing posts with label Emergency ICR. Show all posts
Showing posts with label Emergency ICR. Show all posts

Thursday, June 25, 2015

OMB Approves Emergency ICR for FFIEC Cybersecurity Assessment Tool

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an emergency information collection request for the use of a cybersecurity assessment tool “that will assist financial institutions of all sizes in assessing their inherent cybersecurity risk and their risk management capabilities”.

This cybersecurity assessment tool was developed as a cooperative project of the Office of the Comptroller of the Currency (OCC), the Federal Deposit Insurance Corporation (FDIC), the Board of Governors of the Federal Reserve (Board), and the National Credit Union Administration (NCUA), under the auspices of the Federal Financial Institutions Examination Council (FFIEC). The table below lists the burden estimates, both for the individual agencies and the total burden and is based upon the supporting data [.DOC download] submitted to OIRA. The hours-burden is based upon an estimated 80 hours per assessment.

Agency
Respondents
Hour-Burden
OCC
1,511
120,880
Board
5,282
422,560
FDIC
4,084
326,720
NCUA
6,206
496,480
All Agencies
176
14,080
Total
17,259
1,380,720

NOTE: The ‘all agencies’ figures are not well described; being listed solely as “technology service providers”.

The supporting data document also notes that (pg 3):

“The Assessment incorporates the publicly available cybersecurity framework developed by the National Institute of Standards and Technology.  The Assessment tailors this framework to the financial industry.”

Finally, even though the Treasury reports that failure to use the tool could lead to “disruption, degradation, or unauthorized alteration of information and systems could affect a financial institution’s operations and core processes and undermine confidence in the nation's financial services sector” (pg 2) the collection is voluntary.

Commentary

I certainly do not intend to start covering cybersecurity issues in the banking sector as a normal topic in this blog. But I thought that this ICR approval is an illustration of the way that this Administration is addressing the cybersecurity situation that we are currently facing in this country (and let’s face it, the world).

First off, this is little more than an adaptation of the NIST Cybersecurity Framework (CSF) that was issued in February of 2014, well over a year ago. The implementation of the CSF, a risk-management tool not a cybersecurity tool, was to be a main focus for the various critical infrastructure regulatory agencies. And now, 15 months later, the financial services sector is getting ‘emergency’ approval to use this tool. This is hardly an expeditious response for protecting a sector that is arguably one of the most targeted for cyber attack.

Finally, the Administration continues to insist on making the use of the CSF related tools completely voluntary, even in one of the most highly regulated environments. This makes absolutely no sense what so ever.


This hands-off attitude in addressing serious cybersecurity problems is a hallmark of this Administration and may be a key reason that its own cybersecurity problem keep re-occurring with such regularity.

Friday, May 1, 2015

OMB Approves Emergency FRA ICRs

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) reported that it had approved three emergency information collection requests (ICR) from the DOT’s Federal Railroad Administration. These ICRs support recent actions taken by the FRA to increase the safety of highly-hazardous flammable trains. These ICR’s specifically address information collection requirements for:

∙ FRA Safety Advisory 2015-01 (OMB # 2130-0607);
∙ FRA Safety Advisory 2015-02 (OMB # 2130-0608); and
∙ FRA Emergency Order No. 30 (OMB # 2130-0609).

In each case OIRA approved the emergency ICRs with an end date of October 31st, 2015. The FRA request did note that they intended to renew the ICRs for the two safety advisories in regular order, but that the ICR for the emergency order would be superseded by the ICR for HM-251, the HHFT rulemaking expected to be published later this month.

Burden Estimates

Here are the burden estimates for these three ICRs:


2130-0607
2130-0608
2130-0609
Annual Responses
351,000
50
25
Burden Hours
6,333
100
1,000


The burden estimate for 2130-0607 is based upon (WORD® download) an estimate of the number of automated reports from Wheel Impact Load Detectors (WILD) along routes traveled by affected trains. The subsequent information collection will be the submission of work orders to deal with the maintenance requirements specified in the safety advisory. There is no indication of the basis for this number of estimated WILD reports or if it takes into account the recommended (but unspecified number of) new WILD installations.

The burden estimate for 2130-0608 is based upon (WORD® download) the FRA estimate of the number of accidents involving HHFT trains each year; they are estimating 50 such accidents. This under-estimates the number of responses because the FRA may request information from both a railroad and multiple stakeholders for any given accident. The actual number of requests per accident would be difficult to estimate.


The burden estimate for 2130-0609 is based upon (WORD® download) the FRA estimate of the number of petitions the FRA expects to receive for the use of alternatives to the safety requirements outlined in the Emergency Order.

Friday, August 30, 2013

FRA Requests Emergency Safety ICR

Today the Federal Railroad Administration published an emergency information collection request (ICR) in the Federal Register (78 FR 53818-53819) supporting their recent Emergency Order 28. The FRA is asking for OMB approval of the ICR by September 1st for 180 days’ worth of information collections.

The ICR would cover the requirements from the Emergency Order to:

Develop a plan to identify specific locations and circumstances when HAZMAT trains or vehicles may be left unattended;
Communicate, record, and verify securement information about HAZMAT trains that are left unattended;
Review and revise procedures for determining the number of hand brakes that must be set on HAZMAT trains that are left unattended;
Implement procedures for discussing process for security HAZMAT trains that are to be left unattended; and
Establish procedures to ensure job briefings of all employees that will conduct train securement of HAZMAT trains to be left unattended.

These requirements were already set in place by Emergency Order #28, this ICR would provide administrative approval for FRA to require the developing and maintaining of the documentation demonstrating compliance with the requirements.


The FRA estimates that the 655 railroad covered by this order in the United States will have a total of over 23 million individual responses to these requirements over the next year for a total of over 1.9 million hours of regulatory burden. No estimate is made of how much this regulatory burden will cost the railroad industry. Neither does this emergency ICR address the additional burden associated with the joint safety advisory published on the same day and topic by the FRA and PHMSA.
 
/* Use this with templates/template-twocol.html */