Showing posts with label Pipeline Security. Show all posts
Showing posts with label Pipeline Security. Show all posts

Monday, March 9, 2026

Review – HR 7272 Introduced – DOE Pipeline Security

Back in January Rep Webber (R,TX) introduced HR 7272, the Pipeline Cybersecurity Preparedness Act. The bill would establish Department of Energy responsibilities for physical security and cybersecurity coordination to ensure the security, resiliency, and survivability of natural gas, hazardous liquid pipelines, and liquefied natural gas facilities. No new funding is provided.

Moving Forward

On February 4th, 2026, the House Energy and Commerce Committee held a business meeting that included consideration of HR 7272. The bill passed, without amendments by a voice vote (pages 41-2). Pending publication of the committee report on the bill, the bill is ready for consideration by the full House. I suspect that it will be considered under the suspension of the rules process and would be expected to pass with strong bipartisan support.

Commentary

The inclusion of ‘hazardous liquid pipelines’ in the provisions of this bill is a tad bit odd as they would be a PHMSA area of expertise. While it is clear that general security requirements for energy pipelines would apply to non-energy related chemical pipelines, there are specific safety requirements that would be applicable to toxic chemical pipelines (downwind chemical detection comes to mind) that are probably not necessary for energy pipelines. Having said that, all of the voluntary security measures that would be developed under this bill’s provisions would be beneficial for hazardous liquid pipelines.

 

For more information on the provisions of this bill, including additional commentary on codifying DOE security research requirements, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7272-introduced-doe-pipeline-security - subscription required.

Monday, January 5, 2026

Review - OMB Receives TSA Pipeline Security ICR Revision Request – 1-2-26

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a 30-day information collection request (ICR) revision notice from the TSA on “Pipeline Corporate Security Reviews and TSA Security Directive Pipeline– 2021–02 Series”. The ICR revision notice was published in the Federal Register (91 FR 149-150) on January 2nd, 2026. In addition to changing the name of the ICR, TSA is modifying their burden estimate.

The table below shows the proposed change in the burden estimate:

Public Comments

TSA is soliciting public comments on this ICR revision. Comments may be submitted to OIRA by clicking the comment box on the OIRA notice for this revision. Comments should be submitted by February 2nd, 2026.

 

For more information on the changes being sought in this ICR revision, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-receives-tsa-pipeline-security - subscription required.

Tuesday, August 5, 2025

Review – TSA Publishes Pipeline Safety 60-day ICR Revision

Yesterday, the TSA published a 60-day information collection request (ICR) revision notice in the Federal Register (90 FR 36446-36447) for their Critical Facility Information From the Top 100 Most Critical Pipeline Operators. The changes proposed include a minor revision of the title and removing one of the three current information collections.

The table below shows both the old (current) and new (proposed) burden estimates for this ICR.

Public Comments

The TSA is soliciting public comments on this ICR notice. Comments may be submitted via a button on the Federal Register page for this notice or by email to the TSA (TSAPRA@dhs.gov). Comments should be submitted by October 3rd, 2025.

Commentary

Readers of this blog will certainly be aware of my history of negative comments about the adequacy of ICR notices from TSA. None of those comments apply here. TSA has done a good job of laying out the information that someone would need to provide useable comments about the burden estimates in this notice. Covered pipeline organizations should review the data and take the opportunity to let TSA and OMB about the adequacy of those burden estimates.

 

For more information about the details of the burden estimate, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/tsa-publishes-pipeline-safety-60 - subscription required.

Friday, September 20, 2024

HR 9469 Introduced – TSA Pipeline Security

Earlier this month, Rep Garcia (D,CA) introduced HR 9469, the Pipeline Security Act. The bill would amend 49 USC 114 to specifically add pipeline security to the list of responsibilities of the Transportation Security Administration. No new funding is authorized by this legislation.

Moving Forward

Garcia is a member of the House Homeland Security Committee to which this bill was assigned for consideration. This means that there could be sufficient influence to see the bill considered in Committee. There will be some Republican opposition to the call for security directives or regulations for pipeline security, but I suspect that there will be at least some level of bipartisan support for the bill. Unfortunately, this late in the session, the bill is not likely to be considered.

Commentary

The reality is that this bill is going to codify responsibility for actions that TSA is already taking. Even the security directive and regulation section would not require TSA to take any actions beyond that which it has already taken. Bills such as this, however, are important in that they provide a legal backstop for charges that the agency has exceeded its authority. The current authority under §114 is broadly written and could be argued to support the agencies security directives and current rulemaking process. This would make that argument unnecessary.


For more information on the provisions of the legislation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9469-introduced - subscription required.


Saturday, April 1, 2023

CRS Reports – Week of 3-25-23 – PHMSA and Pipeline Safety

This week the Congressional Research Service published a report on “DOT’s Federal Pipeline Safety Program: Background and Issues for Congress”. According to the summary of this 36-page report:

“The U.S. energy pipeline network includes approximately 3.3 million miles of onshore pipeline transporting natural gas, crude oil, and other hazardous liquids. Over the past decade, major safety incidents in California, Massachusetts, Mississippi, and other states have drawn criticism from stakeholders and have raised concerns in Congress about pipeline safety regulation. The 2021 ransomware attack on the Colonial Pipeline has also drawn attention to federal pipeline security activities, including agency roles and the linkage between pipeline safety and security.”

The report discusses ten separate policy issues related to pipeline safety that may be of concern in Congress as reauthorization of the pipeline safety program is slated to be considered this year. Of particular interest here: PHMSA and Pipeline Security. In concluding its one-page discussion of the topic, the report notes:

“In the 117th Congress, the Pipeline and LNG Facility Cybersecurity Preparedness Act (H.R. 3078) would have required the Secretary of Energy to enhance coordination among “appropriate Federal agencies,” state government agencies, and the energy sector in pipeline security; coordinate incident response and recovery; support the development of pipeline cybersecurity applications, technologies, demonstration projects, and training curricula; and provide technical tools for pipeline security. What role PHMSA might play in any future pipeline security initiatives, and what resources it might require to perform that role, may be a consideration for Congress.”

NOTE: CRS also published a geeky legal look at executive agency communications with Congress during the rule making process.

Friday, March 31, 2023

OMB Approves TSA Top 100 Pipeline ICR Revision

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the revision to the TSA’s information collection request (ICR) for “Critical Facility Information of the Top 100 Most Critical Pipelines”. The revision request had been submitted by the TSA on October 14th, 2021. The revision was a follow-up to the emergency change made to the ICR in May 2021 for the first TSA pipeline security directive and included adding the pipeline cybersecurity self-assessment document.

The reason for the delay was that OIRA required TSA to resubmit their supporting document after making clarification changes.

Wednesday, December 28, 2022

Review - TSA Publishes 30-day Pipeline CSR ICR Notice

Today the TSA published a 30-day information collection request (ICR) revision notice in the Federal Register (87 FR 79899-79900). The 60-day ICR notice was labeled as an ‘extension’ not a revision. This notice reports that there will be a revision of the voluntary “Pipeline Corporate Security Review (PCSR)” workbook that will reduce the burden associated with this ICR. Additionally, the name is being changed to “Pipeline Corporate Security Reviews (PCSR) and Security Directives” to reflect the changes that had been previously approved by the OMB’s Office of Information and Regulatory Affairs (OIRA).

Soliciting Comments

The TSA is soliciting comments on this ICR revision/extension. Comments may be submitted by email to www.reginfo.gov/​public/​do/​PRAMain. Comments should be submitted by January 27th, 2023.

For more details on the ICR notice, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/tsa-publishes-30-day-pipeline-csr - subscription required.


Thursday, August 18, 2022

Review - OMB Approves TSA Pipeline Cybersecurity ICR Update

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an information collection request extension from TSA on “Pipeline Operator Security Information” (OMB Control Number 1652-0055). The 60-day ICR Notice was published on June 30th, 2022 and the 30-day ICR Notice was published on October 14th, 2022.

This extension was required by OIRA’s approval of an emergency revision to this ICR back in May, 2021 supporting the changes in pipeline reporting requirements is Security Directive 1 (SD1). No changes were made in pipeline security reporting requirements in this extension; this is just a formal reporting of those program changes made in the emergency revision. There is, however, a change in the burden estimate for the changes previously made, since TSA did not provide an estimate of the burden change in their emergency revision request.


For more details on the approved ICR, including my commentary on the estimate of time necessary to collect and report the required information on cybersecurity incidents – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-tsa-pipeline-cybersecurity - subscription required.

Thursday, July 28, 2022

OMB Approves TSA Pipeline Security ICR Update – 7-26-22

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an information collection request (ICR) “Extension without change of a currently approved collection” for the TSA’s “Pipeline Corporate Security Review” (1652-0056). I do not typically review ‘extension without change’ notices except that this one was TSA and it was approved with a change from OIRA.

Looking at the approval notice I quickly spotted a significant change in the approved burden (see table below); typically, a change in burden does not make an ICR update an ‘extension without change’.

 

Inventory as of this Action

Requested

Previously Approved

Expiration Date

7/31/2023

36 Months From Approved

7/31/2022

Responses

331

0

20

Time Burden (Hours)

12,830

0

180

The Supporting Document for the ICR extension notes that the TSA had come back to OIRA last summer for an emergency change to this ICR to support the second security directive for pipelines. Yep, I remember that clearly. Unfortunately, the OMB Control Number History for this ICR does not list that emergency ICR revision approval. That confused me for a bit, but it’s all clear now.

It is a good thing that I did see and start investigating the situation. The ORIA file on this ICR now contains an updated copy of the Pipeline CSR Workbook that TSA surface inspectors use to conduct their corporate security reviews (CSR). The revised cybersecurity questions are found under the ‘Checklist IT’ tab in the spreadsheet. Somewhat generic questions, but that has to be expected in a questionnaire like this.

Monday, December 20, 2021

Review - HR 6084 Introduced – Energy Product Reliability

Last month, Rep Rush (D,IL) introduced HR 6084, the Energy Product Reliability Act. The bill would require the Federal Energy Regulatory Commission (FERC) to establish an Energy Product Reliability Organization that would to for energy pipelines what NERC has done for the national electric grid. No funding is authorized by this bill.

Rust is a member of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see this bill considered in Committee. I suspect that there would be substantial opposition to this bill from Republicans that generally resist comprehensive regulatory requirements such as those foreseen by this legislation. The bill could pass out of Committee because of Democratic control

I doubt that this bill would make it to the floor of the House because of opposition from two different Committee Chairs, the Homeland Security Committee and the Transportation and Infrastructure Committee. The new authority for EPRO’s would cut into their separate influence over cybersecurity and pipeline security respectively.

Commentary

The requirement for the EPRO to consult with TSA And DOE on cybersecurity standards is more than a little odd. The DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), certainly retains the preeminent government authority (the knowledge based definition of that term) on energy cybersecurity, TSA retains the regulatory authority to oversee security (including, by default, cybersecurity). Thus the ‘consult with’ requirement of §2(e)(4) should probably be changed to a ‘coordinate with’ mandate, unless the legislation were to remove TSA responsibility for security oversight of energy pipelines. Of course, that is not likely to happen (see paragraph immediately above).

TSA has been working with the pipeline industry on voluntary physical security standards for quite some time and CESER also has a background in physical pipeline security processes. Thus, it would certainly be appropriate, at a minimum, to change that paragraph to read:

(4) CONSULTATION.—The Energy Product Reliability Organization shall consult with the Administrator of the Transportation Security Administration and the Secretary of Energy in developing energy product reliability standards relating to cybersecurity for energy pipelines.

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6084-introduced - subscription required.

Friday, August 20, 2021

OMB Approves Another Emergency TSA Pipeline Security ICR – 8-19-21

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an emergency change to an information collection request (ICR) from the TSA for their “Pipeline Corporate Security Review” (1652-0056). This approval was based upon the OIRA determination that there was: “No material or nonsubstantive change to a currently approved collection.”

This is essentially the same emergency approval that the OMB approved last month. The expiration date did not change, nor did the requirement to submit a 60-day ICR notice.

Looking at the justification document [.DOCX download link] for this latest revision, there is only one significant change from the last justification submitted to OIRA. In the old version, the last sentence in Section 3 of the document reads: “Such statements can be made by e-mail or other means without required use of a specific form.” In the current ICR justification that has been changed to read:

“For convenience, TSA will also provide an optional form (TSA Security Directive Pipeline 2021-02 Statement of Completion) for each submission deadline that Owner/Operators can complete and submit via email.   This form is Sensitive Security Information and will only be shared with the Owner/Operators and others with the need to know.”

OIRA’s “Paperwork Reduction Act Change Worksheet” [.PDF download link] confirms that this is the only change approved in the collection.

Friday, July 16, 2021

Review - OMB Approves Another Emergency TSA Pipeline Security ICR

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) published an approval for another TSA emergency information collection request supporting increased security oversight of gas and liquid pipelines. This emergency ICR update addresses changes to the Pipeline Corporate Security Review (1652-0056) which was most recently updated on April 15th, 2021. According to the supporting document [.PDF download link] provided to OIRA, this emergency ICR approval is needed to support a new TSA Security Directive for pipeline cybersecurity security operations.

As with most emergency ICR requests, OIRA gave rapid approval of the ICR request. Its approval was, however, only for 6-months. OIRA did required that TSA publish a 60-day ICR notice for this change within 90-days.

For more details about the ICR coverage and the upcoming Security Directive, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-another-emergency-tsa - subscription required.

Thursday, July 1, 2021

Review - TSA Publishes Two Pipeline Security ICR Revisions – 6-30-21

 Yesterday the TSA published two information collection request revision notices in the Federal Register (86 FR 34775-34777 and 86 FR 34777-34778) for two pipeline security related ICRs. These are the same two ICRs for which OMB’s Office of Information and Regulatory Affairs approved emergency ICRs for increased cybersecurity reporting requirements in the TSA’s Pipeline Cybersecurity Directive back in late May. The submission of yesterday’s ICR change notices was mandated by OIRA as part of that earlier approval.

Critical Facility Information ICR

In this notice TSA provides an updated burden estimate that includes the new Pipeline Cybersecurity Self-Assessment form. The only change from the emergency approval ICR is the additional data for the PCSA. TSA expects that each of the 100 critical pipeline facilities covered in the ICR will take six hours to complete the PCSA for a 600 hour increase in the burden estimate.

Pipeline Operator Security Information ICR

In this notice TSA provides an updated burden estimate that includes both the new mandatory cybersecurity incident reporting and the new security point-of-contact information reporting requirement. Neither of the new reporting requirements were included in the emergency approval of revised ICR in May. There was no change to the ‘Other Incident’ reporting burden estimate.

TSA expects that each of the 100 critical pipeline facilities covered in the ICR will take 30 minutes to complete the point-of-contact reporting requirement. Additionally, TSA expects that each facility will be expected to report 20 cybersecurity incidents under the new reporting requirements, with two hours required for each report. The total addition burden described in this ICR notice is 4,050 hours.

TSA is soliciting public comments on both of these ICR revision notices. As is usual for the TSA, they do not us the Federal eRulemaking Portal (www.Regulations.gov) site for comment submission. They require that comments be emailed (or delivered) to TSAPRA@dhs.gov. Comments should be submitted by August 30th, 2021.

For a more detailed discussion of these two ICR notices, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/tsa-publishes-two-pipeline-security - subscription required.

Thursday, June 10, 2021

Review - HR 3078 Introduced - Pipeline and LNG Facility Cybersecurity

Last month Rep Upton (R,MI) introduced HR 3078, the HR 3078 Introduced - Pipeline and LNG Facility Cybersecurity Preparedness Act. The bill would give the Department of Energy primary responsibility for physical and cybersecurity of pipelines and liquified natural gas facilities.

NOTE: This analysis of HR 3078 is based upon a Committee Print of the bill being used during today’s markup hearing by the House Energy and Commerce Committee. The Government Printing Office has not yet published the official version of the bill.

Moving Forward

Upton is a senior member of the Energy and Commerce Committee and the bill is cosponsored by eighteen Republicans and Democrats, including the Chair {Rep Pallone (D,NJ)} and the Ranking Member {Rep McMorris (R,WA)}. This explains why the bill is moving forward with a markup hearing so quickly.

The bill has wide bipartisan support within the Committee and will have no problem passing in today’s hearing. The problem is going to be moving this bill forward to the floor of the House. Since this bill gives new authority to DOE over pipelines it also provides the Energy and Commerce Committee with new oversight responsibility as well. As I noted in my commentary on the introduction of HR 3243, this is going to put the Committee in direct conflict with the House Homeland Security Committee and the House Transportation and Infrastructure Committee as who will be top dog in keeping pipeline security under control.

Until that conflict is resolved, neither of these bills will be able to move to the floor of the House for consideration.

For a more detailed analysis of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3078-introduced Subscription Required.

Wednesday, June 9, 2021

House Energy and Commerce Cybersecurity Markup Hearing Scheduled

The House Energy and Commerce Committee will be holding a markup hearing tomorrow. The agenda includes three cybersecurity bills:

HR 3078, the Pipeline and LNG Facility Cybersecurity Preparedness Act,

HR 2931, the Enhancing Grid Security through Public-Private Partnerships Act, and

HR 2928, the Cyber Sense Act of 2021

NOTE: Each of the links above are to committee prints of the bills. GPO has not yet gotten to these bills. I have not yet reviewed them.

Friday, May 28, 2021

Review - TSA Publishes Pipeline Cybersecurity Directive

Yesterday the Transportation Security Administration published “Security Directive Pipeline-2021-01” designed to enhance the cybersecurity of critical pipelines. This action was taken in response to the Colonial Pipeline ransomware attack earlier this month that shut down a major fuel supply pipeline for much of the East Coast.

The new Security Directive requires owners and operators of identified critical pipelines to:

• Report cybersecurity incidents to the DHS Cybersecurity and Infrastructure Security Agency (CISA).

• Designate a Cybersecurity Coordinator who is required to be available to TSA and CISA 24/7 to coordinate cybersecurity practices and address any incidents that arise.

• Review their current activities against TSA's recommendations for pipeline cybersecurity to assess cyber risks, identify any gaps, develop remediation measures, and report the results to TSA and CISA.

All information submitted to the TSA and CISA in compliance with this Directive will be treated as sensitive security information (SSI) in accordance with 49 CFR 1520. Essentially this means that it is exempt from public disclosure requirements and it will be protected in government and contractor systems as sensitive but unclassified information.

For a more detailed review, see my Substack blog, CFSN Indepth Analysis, https://patrickcoyle.substack.com/p/tsa-publishes-pipeline-cybersecurity (subscription required)

Thursday, May 27, 2021

Review OMB Approves Emergency TSA Pipeline Reporting Changes

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) approved two emergency revisions to information collection requests (ICR) from the Transportation Security Administration (TSA) for pipeline security reporting requirements. The ICR revisions are for the “Critical Facility Information of the Top 100 Most Critical Pipelines” (1652-0050) and “Pipeline Operator Security Information” (1652-0055). Both ICR-revision requests used similar language concerning the recent Colonial Pipeline ransomware attack as part of the justification for the emergency approval request.

The TSA Pipeline Security Guidelines referenced in these two ICRs has recently been updated. The revisions do not specifically address cybersecurity issues. Rather they revised the methodology for identifying critical pipeline facilities.

For detailed analysis of the ICR’s see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-emergency-tsa-pipeline

Wednesday, May 12, 2021

Bills Introduced – 5-11-21

Yesterday, with both the House and Senate in session, there were 92 bills introduced. One of those bills will receive additional coverage in this blog:

HR 3078 To require the Secretary of Energy to carry out a program relating to physical security and cybersecurity for pipelines and liquefied natural gas facilities. Rep. Upton, Fred [R-MI-6]

Looks like Upton has been thinking about this for a while, either that or his staff is really good at throwing legislation together quickly. One bad thing about relying on DOE for pipeline security oversight is that they would only have a mandate on crude and fuel pipelines, leaving the hazardous chemical pipelines in the same lax oversight (from a security perspective) regime that got Colonial Pipeline into trouble.

I would like to mention in passing a resolution that was also introduced yesterday. I know that there will be some interested readers, so I will probably mention process highlights for this legislation, but I will not be reviewing it in any depth.

H Res 383 Recognizing the 50th anniversary of the National Association of Chemical Distributors. Rep. Moolenaar, John R. [R-MI-4]

Sunday, May 9, 2021

Pipeline Cybersecurity – The Colonial Ransomware Attack

While it is still early in the investigation, the ransomware attack on the Colonial Pipeline IT systems has had a definite impact on the operation of their East Coast pipeline. Apparently, the control systems involved in the control of the pipeline were not directly affected, but the company shutdown those systems to prevent the attackers from pivoting into the industrial control system networks. An excellent article (to be expected, certainly) from Kim Zetter points out the reasons that the two networks (IT and OT) are connected.

IT-OT Connection Risk Assessment

Pipeline managers have to make the risk assessment about how much interconnection there should be between their IT and OT networks. This attack may (probably not) make some managers change their risk assessments and disconnect the two networks.

Pivoting from the corporate IT networks to the operational networks needs to be difficult. Colonial apparently had controls in place to help prevent that move. They also realized that the longer the attacker was present in their IT networks, the more likely it would be that a route bypassing the security measures in place would be found. Shutting down the control systems until the IT attack could be remediated was a prudent act.

But, as this ransomware epidemic (yes, I used ‘that’ word) is showing the world, corporate IT networks are increasingly vulnerable to this attack methodology. And we are increasingly seeing that the IT/OT nexus has allowed control system networks to become targetable for ransomware attack.

Old Fashioned Air-Gap Security

If the system had been designed to allow for physical network segregation while continuing operation, the effect of the ransomware attack would not be as drastic as the East Coast may be facing in the coming days. Completely air gapping a pipeline control system is probably not possible. Sensors, valves, pumps and other equipment along the length of the pipeline all needs central oversight and control. This means that communications between all of the components of the pipeline control system must exist. And those communications nodes must be adequately protected.

Companies need to be able to physically isolate their control systems from the IT network. This would allow them to continue manufacturing and/or transportation activities while it was working to remediate the ransomware problems on the IT networks. Thus companies could continue money making operations while they worked on their other problems.

Cybersecurity Regulations

I have said before (see here for example) that the federal government has to be careful about what operations they try to regulate for the purpose of protecting control systems from outsider attack. There is simply not enough money or qualified workers available to regulate every control system in the United States. The government does have an interest, however, in overseeing the safety and security of critical infrastructure like fuel pipelines and that should probably include regulating cybersecurity of those facilities so that the populous can rely on the timely delivery of that fuel.

TSA is the agency that is responsible for overseeing the security (including cybersecurity) of pipelines. It is easy to fault TSA for lax oversight, but in truth Congress has been very slow to provide TSA with any specific regulatory authority over cybersecurity of these pipelines. That means that any specific cybersecurity requirements are going to have to go through the legislative process before TSA can start crafting any real regulations.

I would like to suggest that Congress consider (probably as part of their annual pipeline oversight authorization bill) requiring that TSA prepare a regulation for pipeline control systems requiring that they are able to be physically isolated from corporate IT networks when there are indications of a cyber attack (probably should specifically include ransomware attacks) on the IT networks.

Thursday, April 8, 2021

TSA Publishes 60-Day ICR Revision Notice for Pipeline Info

Today the Transportation Security Administration published a 60-day information collection request revision notice in the Federal Register (86 FR 18291-18292) for their “Critical Facility Information of the Top 100 Most Critical Pipelines” program. The revision is necessitated by changes being made to the Critical Facility Security Review (CFSR) Form and the resulting changes to the burden estimate for this ICR.

The Revision

According to the Notice:

“TSA is revising the information collection to align the CFSR question set with the revised Pipeline Security Guidelines, and to capture additional criticality criteria. As a result, the question set has been edited by removing, adding and rewriting several questions, to meet the Pipeline Security Guidelines [link added] and criticality needs. Further, TSA is moving the collection instrument from a PDF format to an Excel Workbook format.”

The table below shows the current burden estimate and the revised estimate provided in this Notice.

 

Current

Proposed

Responses

180

160

Time Burden

810

800

Cost

0

0

NOTE: There is an apparent typo in the Notices burden estimate calculations; 80 x 2 x 3 = 480 not 4800.

Public Feedback

The TSA is soliciting public comments on this ICR revision. The TSA is not using the Federal eRulemaking Portal to receive comments on this ICR. Instead, respondents are asked to email their comments to TSAPRA@dhs.gov.

Commentary

Failure by the TSA to use the public commenting option ensures that the TSA has control of what public responses will be shown to the OMB when this revision is submitted.

Long time readers of this blog will undoubtedly be aware that I have had many concerns about TSA ICR notices over the years. This notice is another example of TSA’s unwillingness or incapability to provide adequate information in the notice to allow for commentors to provide effective feedback on the required questions about the efficacy of this ICR. The public cannot assess the accuracy of the TSA’s burden estimate because we have no way of knowing what changes have been made to the Critical Facility Security Review.

The paperwork that the TSA submitted to OMB’s Office of Information and Regulatory Affairs when this ICR was last updated (in 2017) included a copy of the CFSR [.DOCX download link], but access to that form was never provided to the public in either the 60-day nor 30-day ICR notice. Furthermore, TSA provides a cost estimate for the burden when they submit the ICR to OIRA but does not publish that estimate in their notices to allow for public comment.

Okay, enough ranting; substantive comments now. The current CFSR does not include any questions about cybersecurity for these critical pipeline facilities. I would presume that this is because the earlier version of the Pipeline Security Guidelines that were being used when that CFSR was submitted to ORIA did not mention cybersecurity. The current version of the Guidelines, however, does include an extensive listing (see pages 16 thru 21) of baseline and enhanced cybersecurity measures that are recommended by TSA. If the new CFSR reflects these cybersecurity guidelines with additional questions, then there should be a substantial increase in the number of questions on the CFSR and a concomitant increase in the time necessary to complete the CFSR. That is not reflected in the burden estimate.

Further, TSA does not explain the change in the number of expected responses from 180 to 160.

TSA needs to address these issues when they publish their 30-day ICR notice later this year.

I will be submitting a copy of this blog post to the TSA as a comment on this ICR notice. 

 
/* Use this with templates/template-twocol.html */