Showing posts with label MTSA. Show all posts
Showing posts with label MTSA. Show all posts

Monday, October 7, 2024

Review – S 5064 Introduced – Port Cybersecurity Plans

Last month, Sen Cornyn (R,TX) introduced S 5064, the Protecting Investments in Our Ports Act. The bill would amend 46 USC 54301 to require grantees under the Port Infrastructure Development Program that are using their grant to acquire digital infrastructure or software to have an approved security plan that “that addresses the cybersecurity risks of such digital infrastructure or software”. No funding would be authorized by this proposed legislation.

Moving Forward

Cornyn is not a member of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration, but his sole cosponsor {Sen Peters (D,MI)} is a member of the Committee. This means that there may be sufficient influence to see the bill considered in Committee. I do not see anything in the bill that would engender any organized opposition. I suspect that the bill would receive some level of bipartisan support.

Commentary

At first glance this is a motherhood and apple pie bill. If the government is going to be funding digital infrastructure, they sure ought to require that the grantees protect that investment with some minimum level of cybersecurity protection. And this would not require any new bureaucratic organization to oversee that requirement, the bill relies on the existing Maritime Transportation Security Act (MTSA) bureaucracy to oversee the requirement.

There is one problem though, there is no guarantee that an entity receiving a grant under §54301 is an MTSA covered facility that is required to have a security plan under §70103(c). In fact, §54301(a)(3)(A)(i)(II) allows for grants for projects “outside the boundary of a port, but is directly related to port operations or to an intermodal connection to a port”. An ‘outside the boundary of a port’ entity would not be covered under §70103(c).

 

For more details about the provisions of this bill, and a proposed fix for the problem identified in my commentary, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-5064-introduced - subscription required.

Wednesday, April 8, 2020

COVID-19 and Facility Security


Laurie Thomas has an excellent article over on LinkedIn about COVID-19 and the Maritime Transportation Security Act (MTSA). While there are many technical and administrative details about that program that are different from the Chemical Facility Anti-Terrorism Standards (CFATS) program, many of the points that Laurie makes apply to the CFATS program as well.

Communications


Communications is a key to maintaining regulatory compliance in this unusual situation. With both programs there are two different levels of important communications. The first is program level communications. For the MTSA covered facilities, Laurie notes that following the Maritime Commons blog is a good source for near real time information about program information. For the CFATS program the go-to source is the CFATS Knowledge Center. For unofficial program level news, Laurie has an excellent blog and this blog is a good source for CFATS news.

The second level is communications directed towards the regulators. For MTSA facilities this is communications directed at the Captain of the Port (COTP). For CFATS facilities this would be communication directed at the Infrastructure Security Compliance Division. In both cases, your local inspector is probably a good communications tool.

Compliance Issues


At the facility level, both programs require adherence to an approved security plan for the facility, and the COVID-19 pandemic may cause unexpected problems with those security plans. Neither the Coast Guard nor CISA is going to be surprised if your facility has some compliance issues arise during this pandemic. Personnel issues with security plans are going to be a very common concern. Neither agency has any official plans to waive compliance with the regulatory requirements of either program, but both programs will be willing to work with facilities on alternative methods of compliance.

The key here will be the early identification of problems with the current security plans and communicating those problems to the program authorities. Laurie makes an important point in her article when she says: “If something happens to bring you out of compliance, have an equivalent security measure ready at hand to replace the one that is the issue.” While the COPT or ISCD may not fully accept that ‘equivalent security measure’ it shows that you are interested in maintaining compliance and may make it easier for them to suggest a more appropriate response. Remember, they are hearing about these problems from a number of facilities and will have heard other options that may apply to your situation.

One of the most common problems that will arise during this pandemic will be a shortage of security personnel, especially at facilities that are shut down or working reduced shifts. COVID-19 quarantines are going to inevitably put some security officers off-line because of having COVID-19 symptoms or being exposed to someone with the disease. Some common mitigation measures will be:

• Increasing patrols by local law enforcement;
• Sharing patrol resources with other local facilities; or
• Using facility personnel to fill in for security officers.

Shutdown Alternative


For CFATS facilities, remember that status as a covered facility is dependent on the presence of chemicals of interest. Working down inventory levels to below the screening threshold quantity (STQ) may allow ISCD to remove the facility from the CFATS program. Even drastically reducing the on-hand levels without achieving sub-STQ levels may allow ISCD to reduce the Tier ranking for the facility or even remove the facility from the CFATS program. Talk with your chemical security inspector about this possibility. If you take this route, remember that a new Top Screen will have to be initiated when the facility goes back into operation.

Wednesday, February 5, 2020

OMB Approves CG Cybersecurity Guidelines


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a Coast Guard guidance document addressing cyber risks at Maritime Transportation Security Act (MTSA) Regulated Facilities. This document was submitted to OIRA for review last October. I suspect that the Coast Guard will publish this document in the next week or two.

Monday, July 22, 2019

HR 3409 Introduced – FY 2020 CG Authorization


Last month, Rep. DeFazio (D,OR) introduced HR 3409, the Coast Guard Authorization Act of 2019. The bill contains one cybersecurity provision and one emergency response provision. The bill is currently scheduled to be considered in the House this week.

Cybersecurity


Section 414 of the bill would require the CG to expand its current Insider Threat Program to include monitoring of “all Coast Guard devices, including mobile devices”. No definition of terms ‘devices’ or ‘monitoring’ is provided.

Emergency Response


Section 309 of the bill would modify two separate sections of 46 USC:

§70107, security plan implementation grants; and
§70132, Credentialing standards, training, and certification for State and local support for the enforcement of security zones for the transportation of especially hazardous cargo

In both sections the term ‘emergency response providers’ would be substituted for the existing term ‘law enforcement personnel’ or ‘law enforcement agency personnel’ where they are used in those sections. The definition of ‘emergency response providers’ is taken from 6 USC 101(6) and still includes ‘law enforcement’ personnel.

Moving Forward


DeFazio is the Chair of the House Transportation and Infrastructure Committee to which this bill was assigned for consideration. That Committee has already amended and adopted the bill in a hearing last month, though the record of which amendments were adopted and the final committee action on the bill is missing from the Committees hearing page.

One of the amendments that was to have been considered (and apparently was, see below) was offered by Rep. Garamendi (D,CA) concerned the application process for the Transportation Workers Identification Credential (TWIC). It would require the CG to establish a pilot program where personnel applying for a merchant mariner credential could jointly apply for a TWIC.

The Committee Report has not yet been published, nor has the amended version of the bill. I suspect that we will see both later today as this bill is supposed to be considered tomorrow under the suspension of the rules process. That would limit debate and require a supermajority for passage. The fact that the leadership is scheduling the bill under this process generally means that they expect the bill to receive substantial bipartisan support.

It is a tad bit unusual for the bill to be considered without the official publication of the reported version of the bill, but the House is trying to get a lot of ‘routine’ measures taken care of before the adjourn for their summer recess at the end of the week. The Majority Leader has provided a link to a revised version of the bill on the current Weekly Leader page; presumably this is the version being reported by the Committee, though it looks like there are additional changes. That may be misleading because of the incompleteness of the Committee’s markup hearing page.

Revised Bill


The two original provisions discussed above remain in the revised bill as does the Garamendi amendment (now §429). Two of the newly added provision need to be addressed here, one is an additional cybersecurity provision and a change to the Maritime Transportation Security Act (MTSA) program.

The cybersecurity provision in §422 would establish a “a rotational research, development, and training program” {new §846(1)} within DHS that would allow Coast Guard Academy graduates and faculty to be detailed to the Cybersecurity and Infrastructure Security Agency (CISA) and allow cybersecurity personnel from DHS to be detailed to the CG Academy.

The MTSA provision is found in a relatively short §317. It would amend 46 USC 70103(b)(3), Maritime Transportation Security Plans. It would require the Secretary to review and approve updates to Area Maritime Transportation Security Plans where the current section only requires review and approval of the original plan. A similar requirement is also put into place for extending the current review and approval of Vessel and Facility Security Plans requirements under §70103(c)(4) to include the updates for those plans.

Friday, April 20, 2018

CG Sends TWIC Reader Rule Delay to OMB


Earlier this week the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a proposed rule from the Coast Guard that would delay the implementation of the TWIC Reader Rule. This rulemaking was not included in the Fall 2017 Unified Agenda so there are little or no details publicly available. The final rule for the TWIC Reader was published in 2016. The effective date is August 23, 2018.

While the Trump Administration has established a firm reputation for delaying the implementation of Obama Administration regulations, particularly those finalized in the closing months of that Administration, this action would appear to be something a tad bit different. This rulemaking was years in development and specifically required by law, so it clearly is not an Obama policy legacy.

It will be interesting to see what justification that the Coast Guard is using to delay the implementation of this rule.

Tuesday, April 3, 2018

DHS Publishes 2018 Penalty Adjustment Final Rule


Yesterday the Department of Homeland Security published a final rule in the Federal Register (83 FR 13826-13839) making the annual inflation adjustments to the statutory maxim penalty amounts for a large number of programs under its supervision. This was a direct final rule with an effective date of April 2nd, 2018.

For readers of this blog, four of the changes may be of specific interest. They are shown in the table below. The link in the program column is to the paragraph describing the program changes in the rulemaking. The TSA penalties apply to all surface transportation regulations.

Program
Reg Reference
Current
New
$33,333
$34,013
CG, MTSA
$33,333
$34,013
CG, MTSA
$59,893
$61,115
$11,182
$11,410

This annual direct rulemaking is required by §701 of the Bipartisan Budget Act of 2015 (PL 114-74). This year the final rule is a tad bit late, since it was supposed to be published by January 15th.

Interestingly, these new penalties can be assessed for any violations (not previously adjudicated, of course) that occurred since November 2nd, 2015 when the Bipartisan Budget Act was signed.

Thursday, September 22, 2016

Bills Introduced – 9-21-17

Yesterday with both the House and Senate in session there were 44 bills introduced. Of those, one may be of specific interest to readers of this blog:

S 3379 A bill to improve surface transportation and maritime security. Sen. Thune, John [R-SD]

It is interesting that this bill was only referred to Thune’s Commerce, Science and Transportation Committee and not the Homeland Security and Government Affairs Committee. According to a Committee press release:

“The legislation addresses deficiencies in the Transportation Security Administration’s (TSA) efforts to protect rail, transit, highway, and maritime passenger and freight transportation identified through congressional oversight and a recent report by the Department of Homeland Security inspector general.”


The details of this bill will be interesting, but it will be unlikely for the bill to get through both the Senate and House before the end of the session in December.

Tuesday, August 23, 2016

Coast Guard Publishes TWIC Reader Final Rule

Today the Coast Guard published a final rule in the Federal Register (81 FR 57651-57713) outlining the requirements for the use of Transportation Workers Identification Credential (TWIC) card readers at facilities and on vessels covered by the Maritime Transportation Security Act (MTSA) program. The notice of proposed rulemaking (NPRM) for this rulemaking was published in March of 2013 and I completed a series of blog posts on the public comments received on that NPRM. This final rule was approved by OMB back on July 11th, 2016.

This rule will require that before an individual is allowed unescorted access to designated secure area of a Risk Group A vessel or facility, an individual will have:

• His or her TWIC authenticated;
• The status of that credential validated against an up-to-date list maintained by the TSA; and
• The individual's identity confirmed by comparing his or her biometric (i.e. fingerprint) with a biometric template stored on the credential.

The final rule authorizes a facility or vessel owner to use either a TWIC Card Reader on the approved TSA list or choose to fully integrate electronic TWIC inspection and biometric matching into a new or existing Physical Access Control System (PACS). Due to the exemption for vessels with 20 or fewer covered personnel there is only one vessel currently covered by this rulemaking. A total of 525 facilities are affected.

The effective date of this rule is August 23, 2018.


Future blog posts will take a more detailed look at the provisions of this final rule.

Tuesday, July 12, 2016

OMB Approves CG TWIC Reader Final Rule

On Saturday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced their approval of the final rule for the Coast Guard’s Transportation Workers Identification Credential (TWIC) Card Reader Requirements. The final rule had been submitted to OIRA back in April. The notice of proposed rulemaking (NPRM) for this rule was published in June of 2013 and I did a series of blog posts on the public comments the CG received about the NPRM.

As I have mentioned earlier this final rule will have no effect on facilities covered by the Chemical Facility Anti-Terrorism Standards (CFATS) program as it only applies to Maritime Transportation Security Act (MTSA) covered facilities which are exempt from CFATS coverage. There is, however, an outside chance that some provisions from this rule could be included in the CFATS revisions that we are expecting to see in the not too distant (hopefully) future.


I expect that the final rule will be published in the Federal Register later this week.

Monday, April 4, 2016

CG Sends TWIC Reader Final Rule to OMB

On Saturday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that the Coast Guard had submitted their final rule on Transportation Worker Identification Credential (TWIC); Card Reader Requirements (RIN: 1625-AB21) for review. The notice of proposed rulemaking for this action was published in March 2013.

The abstract for this rulemaking listed in the Fall 2015 Unified Agenda describes the rule this way:

“The Coast Guard is establishing electronic card reader requirements for maritime facilities and vessels to be used in combination with TSA's Transportation Worker Identification Credential (TWIC). Congress enacted several statutory requirements within the Security and Accountability for Every (SAFE) Port Act of 2006 to guide regulations pertaining to TWIC readers, including the need to evaluate TSA's final pilot program report as part of the TWIC reader rulemaking. During the rulemaking process, we will take into account the final pilot data and the various conditions in which TWIC readers may be employed. For example, we will consider the types of vessels and facilities that will use TWIC readers, locations of secure and restricted areas, operational constraints, and need for accessibility. Recordkeeping requirements, amendments to security plans, and the requirement for data exchanges (i.e., Canceled Card List) between TSA and vessel or facility owners/operators will also be addressed in this rulemaking.”

While the Chemical Facility Anti-Terrorism Standards (CFATS) program is not directly affected by this rulemaking, I suspect that facilities that are using Option 3 in the CFATS personnel surety program (PSP) might want to take a look at this rulemaking when it comes out. At some point in time, the DHS Infrastructure Security Compliance Division may consider adding some or all of the requirements from this final rule to their implementation of the TWIC Readers under Option 3. That change, if it comes, would not likely take place until the second phase of the PSP is put into place to include Tier III and Tier IV facilities.


I expect that it will take a couple of months, at least, for OIRA to review and approve this rulemaking.

Sunday, April 12, 2015

Congressional Hearings – Week of 04-10-15

Both the House and Senate will be back in Washington after a long two week spring break. The committee calendars are on the light side, particularly in the Senate. That may be due to slow posting of committee meetings, however. There are four hearings this week that may be of specific interest to readers of this blog: one hazmat transportation, two cybersecurity and one that will deal with MTSA activities.

DOT Regulations Update

The Subcommittee on Railroads, Pipelines, and Hazardous Materials of the House Transportation and Infrastructure Committee will be holding an oversight hearing on Tuesday on ongoing DOT rail, pipeline and hazmat rulemakings. Two acting administrators (FRA and PHMSA) and the NTSB Chair will be witnesses.

The Committee Staff has put together a nice overview document for the hearing. Topics of interest will include:

∙ Automatic and Remote-Controlled Shut-Off Valves for New Transmission Pipelines;
∙ Maximum Allowable Operating Pressure;
∙ Integrity Management;
∙ Leak Detection;
∙ DOT “High-Hazard Flammable Train” Rule;
∙ Special Permits and Approvals;
∙ Hazardous Materials Safety Permits; and
∙ Tank truck wet lines

This will probably be a pretty contentious hearing. Interesting side note; the Staff report notes that the HHFT rule is due to be published May 12th. We will have to wait and see how that works out.

Cybersecurity Markups

This week there will be markup of two draft cybersecurity bills; both on Tuesday. The first will be another information sharing bill (National Cybersecurity Protection Advancement Act of 2015). This will be a full committee markup by the House Homeland Security Committee. The second is a breach notification bill (Data Security and Breach Notification Act of 2015). This will also be a full committee markup, this time by the House Energy and Commerce Committee and it will include two other bills so a two day hearing is scheduled.

There are some interesting differences between this bill and the other introduced earlier. It does not specifically include industrial control systems in the definition of ‘information system’, but it does specifically make the DHS ICS-CERT the agency responsible for sharing control system security information. I’ll have more information on all of these bills in a later post.

At present there is nothing in the breach notification bill that applies to control systems since it only deals with breaches where personally identifiable information is involved. I’ll watch the approved amendments to see if anything expands that to include control system information.

Coast Guard Mission

On Wednesday the Subcommittee on Coast Guard and Maritime Transportation of the House Transportation and Infrastructure Committee will be holding an oversight hearing on the mission of the Coast Guard. The only witness scheduled is Deputy Commandant for Operations. The Committee Staff has again produced an overview document.

An interesting point made in this document is that the ‘Ports, Waterways and Coastal Security’ mission of the Coast Guard is the most costly in terms of spending and ‘resource hours’. Given this fact it is interesting to note that of all Homeland Security Missions PWCS has had the history of meeting its operational metrics. In fact of the six sub-missions listed for PWCS only one had not successfully met its operations performance measures in 2013; Security Compliance Rate for High Risk Maritime Facilities (the MTSA program). It will be interesting to hear more about the problems in this program.


Friday, February 1, 2013

Coast Guard Publishes Request for Comments Notice


Today the Coast Guard published a notice in the Federal Register (78 FR 7334-7336) requesting comments on how to best proceed with the implementation of §822 of the Coast Guard Authorization Act of 2010 (Pub. L. 111-281). While the words ‘advanced notice of proposed rulemaking’ are nowhere to be found in this notice, this is certainly what it appears to be.
In passing the Coast Guard Authorization Act of 2010 Congress added two new mandates in §822:
• Make a current copy of the vulnerability assessment conducted under subsection (b) available to the port authority with jurisdiction of the facility and appropriate State or local law enforcement agencies; and
• Integrate, to the maximum extent practical, any security system for the facility with compatible systems operated or maintained by the appropriate State, law enforcement agencies, and the Coast Guard.

Facility Vulnerability Assessment

The Coast Guard is considering four possible options for the requirement to share vulnerability assessments:
• Require each MTSA-regulated facility owner or operator to make a copy of the current FVA available to the cognizant Coast Guard Captain of the Port, port authority, and State and local law enforcement agencies, upon request.
• Require each MTSA-regulated facility owner or operator to proactively provide a copy of the current FVA to the port authority and State and local law enforcement agencies at a prescribed time interval (as opposed to making copies of FVAs available to the port authorities and law enforcement upon request).
• Require each MTSA-regulated facility owner or operator to share the current FVA with the port authority and State and local law enforcement agencies annually at the annual exercise required under 33 CFR 105.220 or at a newly required annual FVA sharing meeting.
• Require each MTSA-regulated facility owner or operator to share the current FVA with the port authority and State and local law enforcement agencies during the regularly scheduled 5-year re-submission process of the Facility Security Plan (FSP).

Security System Integration

The Coast Guard is considering four options for fulfilling the security system integration requirements of the mandate:
• Require each MTSA-regulated facility owner or operator to have and demonstrate via annual exercises the ability to provide manual alerts regarding a transportation security incident (TSI) to appropriate State and local law enforcement agencies and the Coast Guard.
• Require each MTSA-regulated facility owner or operator to have and demonstrate via annual exercises the ability to provide automated alerts regarding a TSI to appropriate State and local law enforcement agencies and the Coast Guard.
• Require each MTSA-regulated facility owner or operator to make security data feeds regarding a TSI (e.g., alerts, video feeds, alarms, etc.) available to appropriate State and local law enforcement agencies and the Coast Guard.
• Require each MTSA-regulated facility owner or operator to incorporate a technological solution that integrates their electronic surveillance and communications systems with compatible systems operated or maintained by the appropriate State and local law enforcement agencies and the Coast Guard.

Request for Comments

The Coast Guard is actively looking for input on these potential methods of meeting the Congressional mandate. The notice provides a series of specific questions that they are specifically looking to have answered. Additionally they are looking for comments on the feasibility, costs, and benefits of each of the preliminary alternatives described above.
Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2012-0907). Comments should be submitted by May 2, 2013.

Saturday, November 17, 2012

OMB Receives CG TWIC Reader Rule


On Friday the Office of Management and Budget announced that it had received the Coast Guards notice of proposed rulemaking (NPRM) for the long awaited TWIC Reader Rule. This rule has been held up for a number of reasons including delays in starting and finishing the TSA TWIC Reader pilot program.

As I noted in an earlier blog I would suspect that it will be sometime after the first of the year when OMB approves this NPRM. Because of the slow pace of the rule making process it is likely that the final rule on this will not go into effect until sometime in 2014.

Wednesday, October 17, 2012

CG Meeting Update Posted


The Coast Guard today published in today’s Federal Register (77 FR 63849) the correction to their FSO Training meeting registration link that I described in my post last Friday. For more details about the meeting see my original post.

Thursday, October 11, 2012

CG Facility Security Officer Training Meeting


Today the Coast Guard published a notice in the Federal Register (77 FR 61771-61772) announcing a public meeting to obtain input on a draft model FSO training course and other elements of the FSO training program. This training program development was mandated by §821 the Coast Guard Authorization Act of 2010 (46 USC §70125).

The meeting will be held on November 9th, 2012 in Washington, D.C. Seating is limited so advanced registration is required; register on-line. As we have come to expect from the Coast Guard (again special kudos) the meeting will be streamed live on-line.

Copies of the draft model FSO training course will be available on the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2012-0908) and on the CG Homeport web site two weeks before the scheduled meeting. The meeting will address the following topics about the training program (77 FR 61772):

• Draft model FSO training course;

• Computer-based training and distance learning;

• Provisional FSO certification;

• FSO continuing education;

• FSO refresher course;

• Interim policy to provide curriculum guidelines for potential FSO training course providers.

Public comments will be solicited at the meeting and written comments may be submitted to the docket on the Federal eRulemaking Portal through November 23rd, 2012.

Thursday, September 27, 2012

TWIC Reader Rule Update


Laurie Thomas has an interesting post on her Maritime Security/MTSA News blog about a recent meeting of the TWIC Stakeholder Communications Committee. Laurie notes that:

“The NPRM concerning the use of TWIC readers has been developed and is currently going through high-level approval and review.”

The TWIC Reader rule is still going through the DHS approval process and has yet to be sent to the Office of Management and Budget for its review. The OMB approval process can be quite lengthy (most rules, about 75%, take at least 90 days to receive OMB approval).

Midnight Rule Making


There is another factor that could slow the approval process even further; the midnight rule controversy. At the end of a presidential administration there is a tendency to try to complete work on rulemaking processes so that the outgoing administration can put their final stamp on the regulatory process. When there is any controversy surrounding the potential rules the opposition cries foul, maintaining that the new administration should be the one to have approval of the regulatory action as they will be the ones tasked with enforcing the rules.

The Clinton and Bush administrations were both accused of using the midnight rule making process to further their agenda, but both actually put internal rules in place to minimize the amount of rulemaking that was completed in the last months of their administrations. Now the Obama administration may or may not be around for an additional four years (the election is still way to close to call) so it wouldn’t be fair for us to expect a formal announcement of avoiding midnight rule making, but it appears that an unofficial policy may be in place.

OMB Rule Submissions


The table below shows the rules that the Administration has officially submitted to OMB during 2012; all data current as of yesterday according to the Office of Information and Regulatory Affairs (OIRA) web site. The ‘Completed’ columns show the number of rules submitted during that month upon which OMB has completed their action. The ‘Incomplete’ column shows the number of rules submitted during that month that still have actions pending.

Completed
Incomplete
Submitted
Jan
45
14
59
Feb
38
8
46
Mar
44
12
56
Apr
28
9
37
May
25
19
44
Jun
15
11
26
Jul
17
10
27
Aug
10
17
27
Sep
3
9
12

 
Looking at this data it appears that the Obama Administration has taken unofficial steps to reduce the potential appearance of midnight regulating in the event that the President is not re-elected in November. If he is re-elected I would bet that there is a surge of rules submitted to OMB and a similar increase in the rate of approval of regulations by that agency (for example there are 28 EPA rules currently under review at OMB).

TWIC Reader Rule


Given the above information, I would not be surprised to see the TWIC Reader Rule still pending approval come year end. If Obama is not re-elected in November I would suspect that the rule would not go to the OMB before January 21st, 2013. If he is re-elected the rule would be expected to go to OMB in November and not be approved until after the first of the year.

Monday, September 10, 2012

Update on MTSA Hearing


The House Transport Committee has provided some additional information on their web site concerning tomorrow’s hearing on the status of the Maritime Transportation Security Act (MTSA). They have added a witness list and a briefing memo to their hearing page since I did my Congressional Hearing blog post on Saturday.

The currently scheduled witnesses are:

• Rear Admiral Joseph Servidio, Assistant Commandant for Preparedness, United States Coast Guard
• Mr. Stephen Caldwell, Director, Homeland Security and Justice Issues, Government Accountability Office
• Ms. Beth Rooney, Manager of Port Security, Port Authority of New York & New Jersey, testifying on behalf of American Association of Port Authorities
• Mr. Chris Koch, President & CEO, World Shipping Council

The web site also contains a link to the Staff Briefing Memo for this hearing. That memo summarizes the current state of the Coast Guards implementation of the MTSA legislation and supporting regulations. In addition it provides a brief summary of areas of that implementation that are currently incomplete or unsatisfactory based upon previous GAO reports. These areas include:

• TWIC;

• Foreign seafarer identification; and

• Foreign port assessments.

A new GAO report will almost certainly form the basis for the testimony of Stephen Caldwell.

Saturday, September 8, 2012

Congressional Hearings – Week of 9-10-12


Both the Senate and House return to work on Monday and much of what they do or do not do will be influenced by the upcoming election. The House is striving hard to shed the image of a do-nothing body, there are lots of hearings scheduled and a large number of bills coming to the floor. Currently there are only two hearings of probable interest to readers of this blog, one on CFATS and one on MTSA. Finally there is possible action on spending and cybersecurity.

CFATS Hearing


The Environment and Energy Subcommittee of the House Energy and Commerce Committee will be holding a hearing on September 11th on the “The Chemical Facilities Anti-Terrorism Standards Program – A Progress Report”. Under Secretary Beers and Cathleen Berrick of the GAO are the two currently listed witnesses with other witnesses yet to be announced according to the Staff Background Memo. ISCD Director Wulf will probably sit next to Beers at the witness table and I suspect that there will be some industry witnesses on a second panel.

This is not being billed as an oversight hearing and the Background Memo sounds like it will concentrate on how ISCD is completing the action items they set up after the release of the Anderson-Wulf memo. The memo provides the following list of hearing objectives:

• Allow DHS to provide a progress report on the CFATS program with respect to both implementation of the action items and overall achievement of benchmark objectives identified in the Anderson/Wulf memorandum;

• Give DHS an opportunity to discuss the viability of using ASPs and whether expanding ASP usage is warranted. In 2007, DHS announced it would only accept an ASP for Tier 4 facilities; and,

• Update Members on the status of GAO’s recommendations for the CFATS program.

The Memo also references an earlier report by GAO on the CFATS issue. It has the same title as the one published as Steve Caldwell’s testimony for the House Appropriations Hearing in July. Some discrepancy here though; the memo says it was published in August instead of July and claims that the earlier report was marked For Official Use Only. The earlier document was not marked that way, but, as I mentioned in an earlier blog, there might have been an FOUO addendum to that GAO report.

There is no indication that anyone is prepared to ask any questions about the real problem at ISCD, the inability to effectively evaluate Site Security Plan submissions.

NOTE: The House Appropriations Committee has not announced a date yet for the completion of that earlier hearing that was interrupted by a large number of floor votes. But they have other things on their agenda, as I’ll explain later, so I would not be surprised to see that hearing skipped.

BTW: The public comments tool that I discussed in an earlier blog post still does not appear to be working; it still only provides a ‘Site Maintenance Underway’ notice when you press the ‘Submit’ button. Their ‘Site Maintenance’ is as slow as Congress.

MTSA Hearing


The Coast Guard and Maritime Transportation Subcommittee of the House Transportation Committee will hold a hearing on September 11th on “Tenth Anniversary of the Maritime Transportation Security Act: Are We Safer?”. No other details are currently available.

Continuing Resolution


Since none of the House-passed spending bills have yet made their way to the floor of the Senate (nor has the Senate taken any action on a Budget Bill, but that isn’t new for Reid’s Senate) we will start to see some sort of work being done on a Continuing Resolution to carry the government spending from October 1st through some time after the election. There have been news reports that an agreement has been reached on a six-month extension; with both parties apparently being convinced that they will control the 113th Congress and the White House.

Cybersecurity


There is still a possibility of S 3414 coming back to the floor of the Senate, as I mentioned about a month ago. The Administration is unofficially upping the ante on cybersecurity by floating a draft version of an Executive Order that is drawn from portions of this bill. A negotiated agreement on what amendments to vote on will give opponents some measure of control over how the Feds will control cybersecurity. An Executive Order will leave them relying on a Romney win for that control in an election that could easily go either way.

Wednesday, June 13, 2012

TSA TWIC and HME Fees NPRM


Today the Transportation Security Administration published a notice of proposed rulemaking (NPRM) in the Federal Register (77 FR 35343-35349) concerning the establishment of fees for the security threat assessments (STAs) that serve as the basis for the fees for such identification credentials as the Transportations Workers Identification Credential (TWIC) and the Hazardous Materials Endorsement (HME).

Currently the TSA is required to collect fees for the issuance of TWICs and HMEs that cover the cost of the STAs. These fees are currently written into the appropriate regulations; 49 CFR §1572.403, §1572.405, and §1572.501. TSA is proposing to remove the fee amount listing from the CFR and establish a requirement to publish changes to the fee schedule in the Federal Register.

TSA explains the reason for making this change in this way:

“Absent the ability to amend fees through notice rather than rulemaking, TSA is less likely to make timely changes to fees when associated costs change, such as contracts or vendor pricing, and when such changes are made, there is an increased likelihood that they would be more dramatic. Amending fees through notice would allow for more incremental changes and reduce the risk of TSA suspending issuance of credentials to meet HME or TWIC program requirements or decreasing services until a rule change is completed to reflect the new fee amount.” (77 FR 35347)

No Significant Economic Impact


TSA further explains that because this is an ‘administrative’ change making no changes in the procedures that private entities will be following that they certify “that this rulemaking would not have a significant economic impact on a substantial number of small entities. However, TSA invites comments from members of the public who believe there would be a significant impact” (77 FR 35348).

Of course this does not address the potential for more frequent fee changes. Since most of these changes will be increases (Has a government agency ever reduced fees?) in fees and many employers actually pay the TWIC and HME fees, this could result in a ‘significant’ increase in costs.

Public Comment


TSA is soliciting public comment on this NPRM. Comments must be filed by July 30th. Comments can be filed via the Federal eRulemaking Portal (www.Regulations.gov; Docket Number TSA-2004-19605).

Thursday, May 17, 2012

House Appropriations Committee Report Addresses CFATS


A House Appropriations Committee draft report on the FY 2013 DHS appropriations bill that was marked up yesterday contains an extensive and scathing analysis of the problems associated with the CFATS program. While the recommendations and mandates included in the report do not carry the force of law, they can be enforced by the Committee’s funding of programs in subsequent years.

The ISCD Problem


While the Committee has not held any hearings on the problems self-identified by the Infrastructure Security Compliance Division, the Committee has reached a definitive conclusion about the effects of these problems (pg 99):

“It is the Committee’s understanding that even with the changes that are currently being implemented, it will still be more than a year before the CFATS regulatory process authorizes, approves, and inspects even a single facility of the over 4,500 facilities that are part of the program. Furthermore, based on information received by the Committee, it may be almost seven years before all facilities will be fully authorized, approved, and inspected. This type of timeline and lack of progress is unacceptable.”

The report goes on to note that another large-scale industrial security program operated by elements of DHS has been effectively implemented in a timely manner. The report describes the Coast Guards Maritime Transportation Security Act (MTSA) implementation this way (pg 99):

“In less than two years after enactment of that Act, vessels and port facilities had conducted vulnerability assessments and developed security plans to include: passenger, vehicle, and baggage screening procedures; security patrols; restricted areas; personnel identification procedures; access control measures; and/or installation of surveillance equipment. The Coast Guard had reviewed and approved these plans and, to this day, continues to regularly inspect the facilities and vessels for compliance to ensure there is a consistent, risk based security program for all the Nation’s ports to better identify and deter threats.”

Based upon this apparent disparity between the successes of the two programs the Committee “directs the Under Secretary for NPPD in conjunction with the Commandant of the Coast Guard” to conduct a critical review of the CFATS implementation. There are eight specific areas that the report identifies to be included in the review (pgs 99-100):

1. Is the ISCD organized to efficiently, effectively, and faithfully carry out the requirements detailed in Section 550 of Public Law 109–295?

2. Is the Site Security Plan program sufficient and justified to accomplish the goals of the CFATS program?

3. Should the facility inspection process be streamlined and if so, what is the most efficient mechanism to do so, particularly for low-threat facilities?

4. Are the requirements for ISCD personnel for the inspection process—to include manning, training, site visits, and enforcement— being met?

5. Have clear training and guidance materials been provided to the inspectors so that they can review security plans and conduct inspections consistently, regardless of the type of facility visited?

6. Has ICSD developed adequate plans for follow up inspections for entities whose Site Security Plans have been approved?

7. Does the CFATS program include the appropriate level of stakeholder outreach to address valid industry concerns?

8. Are the requirements outlined in the Information Collection Request Reference Number 201105–1670–002 [Personnel Security Program] duplicative of other programs?

It is absolutely clear that the Committee intends for this review to be more than they typical congressionally mandated paper study. Instead of the typical 90- or 180- day reporting period the Report mandates that the report be submitted to Congress by April 1st, 2013; almost a full year for the completion of the study.

Alternative Security Programs


The Report also addresses a perennial congressional favorite security topic, the utilization of ‘alternative security programs’. It notes that “the use of alternative security programs established by private sector entities in the implementation of the CFATS program” (pg 100) is specifically allowed by the §550 authorization for the program. The Committee directs the Under Secretary to report on the ISCD use of alternative security programs to “address the massive backlog of unapproved site security plans”. This report will also be due on April 1st, 2013.

Interestingly the Committee demonstrates its lack of understanding of the fundamental definitions of the CFATS program when the report comments that:

“While alternative site security programs may not be advisable for high-risk facilities, the Committee believes that in many cases the use of alternative programs may be an efficient and effective method to reduce the backlog currently in existence.”

All facilities covered by the CFATS program are, by definition, ‘high-risk facilities’. There are rankings or tiers of ‘high-risk’, but all covered facilities are at high risk for terrorist attack as determined by the Secretary. Additionally, no one in Congress has explicated how these alternative security programs will reduce the approval and inspection work load of ISCD. Unless Committee is suggesting that non-governmental organizations can be delegated the inherently governmental responsibility of conducting site approval and inspection activities, ISCD will still have to do the hard work of the program.

Personnel Assurance Program


The Appropriations Committee becomes the third Committee in Congress (Homeland Security and Energy and Commerce Committees being the other two) that has expressed concerns about the personnel surety program that has yet to be finally defined by DHS. Every Congressman that has commented on the program has expressed concerns that the program does not recognize TWIC or HME identifications as meeting the requirements of the program. Since we haven’t seen the final document on the program (another oft delayed program) it isn’t clear that this is actually the case, but the complaints are continuously voiced.

The other concern included in this report about the personnel surety program is the provision that if a submitted name is found to be on the Terrorist Screening Database (TSDB), ISCD specifically has stated that they did not intend to notify the facility of that determination. The Report notes the Committee’s concern (pg 101):

“While the Committee understands the need to protect ongoing investigations, the liability concerns of allowing a person in the TSDB into a chemical facility is distressing to the Committee and to industry stakeholders.”

Another report to be submitted by April 1st, 2013 will be required to address these surety concerns. An interesting requirement in this report is inclusion of an analysis of the number of chemical workers (presumably at CFATS facilities) are already covered by the TWIC. Since no one will be able to make a realistic assessment of the TWIC status until facilities submit the list of covered personnel that will be covered by the surety program, I don’t see how ISCD will legitimately make this information available.

While it might be reasonable to provide a one-year reporting period one would like to think that other Committees in the House and Senate might actually step up and address the problems that I have been identified in the ISCD implementation of the CFATS program. Or maybe not. After all the Senate Homeland Security and Government Affairs Committee has yet to hold a hearing on the problems; they’re more interested in looking as the Secret Service agents consorting with prostitutes.
 
/* Use this with templates/template-twocol.html */