Showing posts with label ICR Revision. Show all posts
Showing posts with label ICR Revision. Show all posts

Friday, April 1, 2022

OMB Approves TRIA ICR Revision Adding Cyber Carrier Information

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an information collection request (ICR) revision by the Treasury Department for their ICR on “Collection of Data from Property and Casualty Insurers for Reports Concerning the Terrorism Risk Insurance Program” (1505-0257). The revision was required because of a need for more information on captive insurers and cyber insurance required by TRIA changes mandated in the latest reauthorization of the program in Title V, Division I of PL 116-94.

According to the supporting document (NOTE: this is a DOCX download link) provided to OIRA:

“The proposed changes regarding cyber insurance seek more detailed information concerning cyber insurance written by insurers subject to the Program, in lines of insurance both covered and not covered by the Program, so that Treasury may better evaluate the Program’s response to cyber-related incidents that could have implications for the Program and its effectiveness, and Treasury’s administration of it.  In addition, the proposed changes seek information on the type of policyholders, by size, obtaining cyber insurance, and also request detailed information on coverage for ransomware-related losses, including existing claims information.”

The data collection form (2022 Data Call Non-Small Insurers (Proposed Revisions).xlsx NOTE: this is an XLSX download link) now includes a page {Cyber (US)} that includes 29 lines for the collection of data about cyber insurance policies (including ransomware losses).

Thursday, April 8, 2021

TSA Publishes 60-Day ICR Revision Notice for Pipeline Info

Today the Transportation Security Administration published a 60-day information collection request revision notice in the Federal Register (86 FR 18291-18292) for their “Critical Facility Information of the Top 100 Most Critical Pipelines” program. The revision is necessitated by changes being made to the Critical Facility Security Review (CFSR) Form and the resulting changes to the burden estimate for this ICR.

The Revision

According to the Notice:

“TSA is revising the information collection to align the CFSR question set with the revised Pipeline Security Guidelines, and to capture additional criticality criteria. As a result, the question set has been edited by removing, adding and rewriting several questions, to meet the Pipeline Security Guidelines [link added] and criticality needs. Further, TSA is moving the collection instrument from a PDF format to an Excel Workbook format.”

The table below shows the current burden estimate and the revised estimate provided in this Notice.

 

Current

Proposed

Responses

180

160

Time Burden

810

800

Cost

0

0

NOTE: There is an apparent typo in the Notices burden estimate calculations; 80 x 2 x 3 = 480 not 4800.

Public Feedback

The TSA is soliciting public comments on this ICR revision. The TSA is not using the Federal eRulemaking Portal to receive comments on this ICR. Instead, respondents are asked to email their comments to TSAPRA@dhs.gov.

Commentary

Failure by the TSA to use the public commenting option ensures that the TSA has control of what public responses will be shown to the OMB when this revision is submitted.

Long time readers of this blog will undoubtedly be aware that I have had many concerns about TSA ICR notices over the years. This notice is another example of TSA’s unwillingness or incapability to provide adequate information in the notice to allow for commentors to provide effective feedback on the required questions about the efficacy of this ICR. The public cannot assess the accuracy of the TSA’s burden estimate because we have no way of knowing what changes have been made to the Critical Facility Security Review.

The paperwork that the TSA submitted to OMB’s Office of Information and Regulatory Affairs when this ICR was last updated (in 2017) included a copy of the CFSR [.DOCX download link], but access to that form was never provided to the public in either the 60-day nor 30-day ICR notice. Furthermore, TSA provides a cost estimate for the burden when they submit the ICR to OIRA but does not publish that estimate in their notices to allow for public comment.

Okay, enough ranting; substantive comments now. The current CFSR does not include any questions about cybersecurity for these critical pipeline facilities. I would presume that this is because the earlier version of the Pipeline Security Guidelines that were being used when that CFSR was submitted to ORIA did not mention cybersecurity. The current version of the Guidelines, however, does include an extensive listing (see pages 16 thru 21) of baseline and enhanced cybersecurity measures that are recommended by TSA. If the new CFSR reflects these cybersecurity guidelines with additional questions, then there should be a substantial increase in the number of questions on the CFSR and a concomitant increase in the time necessary to complete the CFSR. That is not reflected in the burden estimate.

Further, TSA does not explain the change in the number of expected responses from 180 to 160.

TSA needs to address these issues when they publish their 30-day ICR notice later this year.

I will be submitting a copy of this blog post to the TSA as a comment on this ICR notice. 

Tuesday, March 23, 2021

CISA Publishes 60-Day CFATS ICR Revision Notice

Today the Cybersecurity and Infrastructure Security Agency published a 60-day information collection request revision notice in the Federal Register (86 FR 15490-15493) for the Chemical Facility Anti-Terrorism Standards (CFATS) program. This is one of four ICRs that support the operations of the CFATS program.

Covered Instruments

This revision notice addresses changes in the following collection documents:

Request for Redetermination,

Request for Extension,

Top-Screen Update,

Compliance Assistance, and

Declaration of Reporting Status

The links above are .docx download links. They are for the currently approved form or instructions. We will not be able to see the revised documents until CISA submits the ICR to the OMB’s Office of Information and Regulatory Affairs shortly after the 30-day ICR notice is published.

Changes

In this revision notice CISA is making changes in the documentation to reflect the organizational change from NPPD to CISA. They are also updating the burden estimates to reflect recent collected data history and extrapolations of future activity. The burden estimates are reflected in the table below.

Revised Estimate

Current Estimate

Number

Time

Cost

Number

Time

Cost

Request for Redetermination

250

62.5

$5,364

625

156.0

$10,581

Request for Extension

400

41.7

$3,576

730

58.0

$3,955

Top-Screen Update

2,500

312.5

$26,818

1,875

150.0

$10,158

Compliance Assistance

1,600

133.3

$11,443

683

55.0

$3,698

Declaration of Reporting Status

100

25.0

$2,145

480

120.0

$8,126

The links in the table lead to the detailed discussion of the revision methodology in this revision notice.

Public Comments

CISA is soliciting public comments on this ICR revision. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # CISA-2021-0003). Comments should be submitted by May 24th, 2021.

Saturday, March 6, 2021

OMB Approves Emergency ICR Revision for DHS Vulnerability Discovery Program

On Thursday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an emergency request for a revision of the DHS information collection request (ICR) for their Vulnerability Discovery Program. Like the emergency request that I discussed earlier this week, this approval would allow other Federal Agencies and Departments to establish their own cybersecurity vulnerability reporting programs under the approved ICR for the DHS program.

Justification for Expanding Scope of ICR

It turns out that the earlier request was not actually approved, but rather reported as “Improperly submitted and continue”; essentially OIRA was telling DHS to resubmit the request while continuing to allow DHS to collect information under the existing ICR. The new request for emergency approval (.DOCX download link) includes a three-part justification for the broader application of the ICR. First it establishes the DHS authority to establish the Vulnerability Discovery Program:

“Pursuant to section 101 of the Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act, (commonly known as the SECURE Technologies Act) [PL 115-390] individuals, organizations, and/or companies may submit any discovered security vulnerabilities found associated with the information system of any Federal agency [emphasis added]. This collection would be used by these individuals, organizations, and/or companies who choose to submit a discovered vulnerability found associated with the information system of any Federal agency.”

This claim is a tad bit stretched. The language of §101 actually specifically applies to “appropriate information systems of Department of Homeland Security” {§101(a)}. The stretch may be justified by the definition of ‘appropriate information system’ in §101(f)(3); that is defined as “an information system that the Secretary of Homeland Security selects for inclusion under the vulnerability disclosure policy required by subsection (a)”. That is still a long stretch as the term is still specifically applied to systems of “Department of Homeland Security” in (a).

The second portion of the claim relates to the need for the expansion of the 1601-0028 ICR because of the SolarWinds attack:

“DHS and Federal cybersecurity agencies are working to address the recently discovered SolarWinds hack on Federal agencies and organizations around the world. While DHS had previously obtained approval to collect this information on its own behalf, recent cyber attacks exploiting vulnerabilities have exemplified the need to have this capability government-wide. In 2020, a major cyberattack, nicknamed the SolarWinds cyberattack, by a group backed by a foreign government penetrated thousands of organizations globally including multiple parts of the United States federal government, leading to a series of data breaches. The cyberattack and data breach were reported to be among the worst cyber-espionage incidents ever suffered by the U.S., due to the sensitivity and high profile of the targets and the long duration (eight to nine months) in which the hackers had access.”

While an investigation of the extent of the SolarWinds attack would not require an expanded Vulnerability Discovery Program, it could certainly be argued that such an expansion could help prevent future attacks of this scope. It should be noted that if this justification letter had been written just a couple of days later, it could have also referenced the exploits of the zero-day Microsoft email server vulnerabilities.

Finally, the justification references the recent changes made to 44 USC 3553(b) made by§1705 of PL 116-283 that expanded the scope of the DHS responsibilities for the security of information systems throughout the federal government. While the DHS letter specifically references the ‘information sharing’ provisions of §1705’s new paragraph (l) added to §3553, a better argument can be made that the new subparagraph (b)(8)(B) added by §1705(1):

“(B) deploying, operating, and maintaining secure technology platforms and tools, including networks and common business applications, for use by the agency to perform agency functions, including collecting, maintaining, storing, processing, disseminating, and analyzing information; and”

Moving Forward

With this week’s approval of the emergency expansion of 1601-0028, DHS will be required 60-day and 30-day information collection request revision notices in the Federal Register, seeking public comment on the revised collection. It will be interesting to see what basis DHS will use for estimating the burden for the vastly expanded collection.

Thursday, April 20, 2017

DHS Publishes 60-Day ICR Revision Notice for CVI Program

Yesterday the DHS National Protection and Programs Directorate (NPPD) published a 60-day information collection request (ICR) notice in the Federal Register (82 FR 18466-18468) for revisions being made to support the Chemical-Terrorism Vulnerability Information (CVI) program within the Chemical Facility Anti-Terrorism Standards (CFATS). The proposed changes reduce the number of information collections and the DHS burden estimate for that program.

Changes


Based upon the experience of the last three years, the Infrastructure Security Compliance Division (ISCD) of the NPPD is removing five information collection instruments from this ICR. They are:

• “Determination of CVI”;
• “Determination of a “Need to Know” by a Public Official”;
• “Disclosure of CVI Information;
• “Notification of Emergency or Exigent Circumstances”; and
• “Tracking Log for CVI Received”

This leaves just one ICR instrument covered by this collection, the information collected by the CVI Training web site and the subsequent CVI user application. ISCD reports that they expect a reduction in the number of respondents for this remaining instrument to decrease from 30,000 to 20,000.

Commentary


Once again it is nice to see a detailed accounting of the changes being proposed by a federal agency in the ICR process. Such details provide the data necessary to make informed comments for ultimate consideration by the OMB’s Office of Information and Regulatory Affairs.

I also commend DHS for this review of the collection instruments covered by the ICR and their intent to remove little used or unnecessary instruments. Having said that, I have concerns about the removal three of the identified instruments;

• “Disclosure of CVI Information;
• “Notification of Emergency or Exigent Circumstances”; and
• “Tracking Log for CVI Received”

All three of these instruments are still required by the DHS CVI Procedural Manual; the first with mandatory language (“must promptly report”) and the other two with permissive language (“should be kept and submitted” and “DHS encourages"). In fact, the first is required by the CFATS regulations {6 CFR 27.400(d)(7)}.

The notice would appear to attempt to address these three instruments by stating that:

“The Department expects that in many instances when the Department may need or want to collect information regarding emergency and/or unauthorized disclosure of CVI, the collection would not be covered by the Paperwork Reduction Act because the information would be collected during the conduct of an investigation involving specific individuals or entities. See 44 U.S.C. 3518(c)”

That would certainly be true of the subsequent investigation of the reports in the first two instances, but not the initial reports themselves.

I would like to suggest that DHS continues to retain these three instruments in this ICR with an appropriate low number of respondents and the current estimate of burden hours and cost rates.

Public Comments


DHS is soliciting public comments about this ICR. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; DHS-2017-0015). Comments should be submitted by June 19th, 2017.

A copy of this blog post is being submitted as a comment to this ICR notice.

Thursday, June 25, 2015

OMB Approves ICR Revision for PMSA Fireworks Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced the approval of a revision of a PHMSA information collection request supporting the Approvals program for hazardous materials. The revision was needed because of changes in reporting requirements for those seeking fireworks approvals included in the HM-257 final rule published in July, 2013.

According to the supporting data [.DOC download] submitted by PHMSA the new reporting requirements are expected to only affect 211 of the 11,074 Approvals applicants. The new requirements would result in an additional five minutes on each of the 24.5 (average) requests for approvals for each these applicants. This would increase the total hour burden estimate by 430 hours to 28,270 hours.

Commentary

This is a totally unremarkable revision of a long-standing ICR and as such I would typically ignore this, especially considering that OIRA approved the ICR revision without change for the standard three years. What caught my attention, however, was the fact that the ICR revision was requested on May 29th, 2014. This completely unremarkable ICR revision took over a year to approve, even after OIRA had signed off on the data during the rulemaking process just 5 months before this request was submitted.

Short of a congressional investigation or a GAO audit (often a precursor to such an investigation) we will never know why this ICR approval took so long. It is, however, part of a long history of slow movement in OIRA on conducting approvals of what are supposed to simple administrative reviews of whether or not an Agency has dotted all the “i’s” and crossed all the “t’s” in justifying collecting information from the public.

Many times we can clearly see that the delays are politically driven (see the still unapproved ICR for the CFATS personnel surety program), but that does not seem to be the situation here. While there were some objections in the fireworks community to some of the provisions of the HM-257 rulemaking, those controversies were effectively settled by the publication of the rule.


Perhaps it is time for somebody in Congress to start asking questions about the ICR approval process and the lengthy delays being experienced in the OIRA’s reviews.

Thursday, May 14, 2015

PHMSA Publishes HHFT ICR Revision 60-day Notice

Today the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) published a 60-day information collection request (ICR) revision notice in the Federal Register (80 FR 27844-27845) for the ICR recently approved supporting the high-hazardous flammable train final rule that was published last week.

Apparently in their ICR request for the HHFT final rule PHMSA failed to take into account the fact that in addition to an initial reporting requirement in the preamble for failure to meet the “January 1, 2017 deadline for retrofitting non-jacketed DOT-111 tank cars in PG I service” the preamble also provided authority for the Secretary to require additional follow-up reporting requirements.

PHMSA is estimating that the initial and follow-up reporting requirement may result in up to 50 additional responses at 30 minutes per response with an annual burden increase of 25 hours and $1,000.


PHMSA is soliciting public input on this ICR revision. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2012-0082). Comments should be submitted by July 13th, 2015.

Saturday, March 29, 2014

PHMSA Publishes 60-Day ICR for OPID and Operator Registry Forms

The DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) published a 60-day ICR revision notice in Monday’s Federal Register (79 FR 18118-18119, available on-line today) concerning proposals to revise two forms used by gas transmission and gas distribution pipeline operators to provide information to the National Registry of Pipeline and LNG Operators under authority of 49 CFR §191.22 and  §195.64.

Those two forms are:

• PHMSA F 1000.1, OPID Assignment Request; and
• PHMSA F 1000.2, Operator Registry Notification

OPID Assignment Request Changes

PHMSA is proposing to make the following changes to the OPID Assignment Request form:

Align the gas distribution and gas transmission commodity choices with those found on the annual and incident reports;
Modify the list for types of gas distribution operators to reflect the ownership structure of the operator;
Collect the miles of pipe and facility descriptions for each state;
Eliminate liquefied natural gas (LNG) plans and procedures as a separate safety program type; and
Collect business cell phone numbers for contacts in addition to office phone numbers.

Operator Registry Notification Changes

PHMSA is proposing to make the following changes to the Operator Registry Notification form:

Remove and revise instructions regarding pipeline safety program information submissions at several locations in the form and instructions;
Reduce the number of notification types and the text describing each type to enhance clarity;
Require Type B notifications to indicate whether the operator is assuming or ceasing operatorship of pipeline facilities;
Require separate notifications for an acquisition and a divestiture;
Allow an operator submitting a divestiture to request the deactivation of their OPID
Align the gas distribution and gas transmission commodity choices with those found on the annual and incident reports;
Collect data about miles of pipeline separate from facilities, such as breakout tanks, storage fields, and compressor stations, in Step 3;
Require operators to provide data about pipeline facilities (Step 3) when they submit a change in entity operating (Type B) notification;
Collect the miles of pipe and facility descriptions for each state; and
Add a “Guidance for Selecting the Appropriate Notification Type” section to the instructions.

Burden Estimate

This ICR Notice provides a revised estimate of the burden that these collections will impose on the 2,328 Natural gas, 82 LNG facility and 335 Hazardous Liquid operators on an annual basis. Table 1 below shows a comparison of proposed revised ICR with the currently approved ICR for these forms. The current data comes from information submitted  to the OMB’s Office of Information and Regulatory Affairs (OIRA).


Current
OPID
Current
Notification
Proposed

Responses
2753
11012
630
Time Burden
2753
2753
630
Cost Burden
NR
NR
NR
Table 1: Burden Estimates

The currently approved OPID numbers are high because this was for the initial implementation of the program and all 2753 operators had to register. Only new operators and certain changes would be reported with this form now so the current annual collection requirement would be much less than 2753 submissions. PHMSA estimated that it would take one hour to complete the OPID Assignment Request form.

PHMSA originally estimated that there would be four notifications per year from each operator using the Operator Registry Notification form. They estimated that it would take 15 minutes for each of those notifications.

PHMSA does not routinely report the cost burden in its ICRs. They do, however, provide a cost estimate to OIRA. They most recently estimated that hourly cost for this ICR was $64.75 providing a total annual burden cost for both forms at $356,513.50.

The ICR notice does not make it clear what form the 630 responses would involve. It would seem that the one hour per submission would mean that it was the OPID Assignment Request. Either that or the proposed changes to the Operator Registry Notification form would take four times as long to complete. In either case, PHSMA should explain the basis for the change in the burden estimate.

Public Comments

PHMSA is soliciting public comments on these proposed form changes and the associated change in the ICR burden. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2014-0018). Comments need to be submitted by May 30th, 2014.
 
/* Use this with templates/template-twocol.html */