Showing posts with label Port Security. Show all posts
Showing posts with label Port Security. Show all posts

Monday, February 10, 2025

Review – Committee Hearings – Week of 2-9-25

This week with both the House and Senate in Washington, the hearing schedule picks up a bit over last week. There is one hearing in the House on port security issues. The Senate continues their work on presidential nominations, but they do expand the list of topics covered, including an FY 2025 budget resolution markup.

Port Security

On Tuesday the Subcommittee on Transportation and Maritime Security of the House Homeland Security Committee will hold a hearing on “Examining the PRC's Strategic Port Investments in the Western Hemisphere and the Implications for Homeland Security, Part I”.

Nomination Hearings

On Thursday, the Senate Judiciary Committee is scheduled to hold a business meeting to vote on the Patel nomination.

There are two other nomination hearings scheduled this week for committees to hear testimony from the nominees:

Health, Education, Labor, and Pensions - Lori M. Chavez-DeRemer to serve as Secretary of Labor, and

Health, Education, Labor, and Pensions - Linda McMahon to serve as Secretary of Education

Budget Hearings

On Wednesday and Thursday the Senate Budget Committee is scheduled to hold a business meeting to conduct a markup of their version of the FY 2025 Budget.

 

For more information about these hearings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/committee-hearings-week-of-2-9-25 - subscription required.

Thursday, June 7, 2018

Committee Marks-Up Homeland Security Bills


Yesterday the House Homeland Security Committee met to mark-up 10 pieces of legislation. Two of those bills deal with topics of specific interest to readers of this blog; industrial control system security (HR 5733) and Transportation Workers Identification Credentials (TWIC; HR 5729). Both bills were amended and then adopted by unanimous consent.

ICS Security


Rep. Langevin (D,RI) proposed the single amendment to HR 5733. It added a new subparagraph to the proposed amendment to 6 USC 148 that outlines the responsibilities of the National Cybersecurity and Communications Integration Center (NCCIC) to address industrial control system security issues. The new sub-paragraph reads:

“(4) collect, coordinate, and provide vulnerability information to the industrial control systems community by, as appropriate, working closely with security researchers, industry end-users, product manufacturers, and other industrial control systems stakeholders; and”

TWIC Reader Rule Delay


Rep. Jackson-Lee (D,TX) proposed the single amendment to HR 5729. The amendment added an ‘every 90-day’ reporting requirement on the status of the continued delays in the DHS implementation requirement to conduct an evaluation of the efficacy of the TWIC program. That delay is the underlying reason for delaying the implementation of the TWIC Reader Rule.

Moving Forward


The ‘unanimous consent’ provided for the adoption of both of these bills (as amended) is a strong measure of the bipartisan support they have in Committee. This means that they will probably be taken up by the whole House under the suspension of rules provision with no further amendments and they will certainly receive the super-majority required to pass bills under those provisions. The only question now is when they will make it to the floor of the House.

Commentary


The new language added to HR 5733 certainly affirms the current activities of the ICS-CERT to coordinate and publish industrial control system security alerts and advisories. The lack of a formal definition of ‘industrial control system’ beyond the vague “including supervisory control and data acquisition systems” {new §148(f)(1)} does nothing to affirm the ICS-CERT responsibility for activity for medical devices or transportation systems which are arguably not ‘industrial’.

As I noted in my post about the introduction of this bill, HR 5733 would have been an ideal place to deal with the IT-centric definition of ‘information systems’ and to provide a proactive definition of ‘industrial control system’ that could be used throughout DHS. Unfortunately, the lack of such action yesterday almost ensures that this bill will not be the vehicle for establishing that definition.

Saturday, June 17, 2017

HR 2831 Introduced – Port Security Corrections

Last week Rep. Rutherford (R,FL) introduced HR 2831, the Maritime Security Coordination Improvement Act. The bill makes a number of changes to laws pertaining to port security operations conducted by the Coast Guard. Changes of specific interest to readers of this blog would be increased emphasis on cybersecurity and changes to Maritime Transportation Security Act (MTSA) inspection requirements.

Cybersecurity


Section 4 of the bill address three separate issues related to port cybersecurity related to different levels of cybersecurity interest; DHS/CG, Captain of the Port (COTP), and MTSA covered facility owner.

Section 4(b) of the bill specifically adds cybersecurity to the areas of potential weakness that DHS/CG is required to look at when they are assessing the “detailed vulnerability assessment of the facilities and vessels that may be involved in a transportation security incident” 46 USC 70102(b)(1)(C).

Section 4(a) addresses cybersecurity at the COTP level by adding a new requirement for Area Maritime Security Advisory Committees (AMSAC) under 46 USC 70112(a)(2)(A). The AMSACs would be specifically required to “shall facilitate the sharing of information relating to cybersecurity risks and incidents (as such terms are defined in section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148)) to address port-specific cybersecurity risks and incidents, which may include the establishment of a working group of members of such committees to address such port-specific cybersecurity risks and incidents” {§70112(a)(2)(A)(i)}.

At the facility owner level the bill would require vessel and facility security plans under 46 USC 70103(c) to specifically address “prevention, management, and response to cybersecurity risks and incidents (as such terms are defined in section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148) [link added])” {new §70103(c)(3)(C)(v)}.

Facility Inspections

Section 5 of the bills makes a change to the requirements for the Coast Guard to inspect MTSA covered facilities under 46 USC 70103(c)(4)(D). Instead of inspecting at least twice a year (one conducted without advanced notice), the new requirement would reduce that to at least once a year without notice.

Moving Forward


Rutherford and all three of his cosponsors {including Chairman McCaul (R,TX)} are members of the House Homeland Security Committee, one of the two committees to which the bill was assigned for consideration. This bill will almost certainly be considered (and approved) in the Homeland Security Committee; consideration by the Transportation and Infrastructure Committee is much less assured.

There does not appear to be anything in the bill that would raise any significant opposition in the House. If McCaul can get the bill to the floor of the House, it is likely to eventually reach the President’s desk.

Discussion


There are no cybersecurity definitions in the bill beyond reference to the terms ‘cybersecurity risks’ and ‘incident’ from §148(a). Those definitions both rely on the definition of ‘information system’ which §148 takes from 44 USC 3502(8). That definition is very IT-centric; “the term ‘information system’ means a discrete set of information resources [emphasis added] organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information”. Thus, it could be argued that these cybersecurity requirements do not address control system, security system, or building maintenance system security issues.

In many industries (finance, commercial sales, and healthcare for example) protecting information is the paramount concern when we talk about cybersecurity. In port operations, however, the operational side of the house is probably more significant than is the need to protect just information. Thus, it would behoove Congress to ensure that the language in this bill reflects the importance of operational cybersecurity.

The only place that currently expands the IT-centric definitions of cybersecurity to include operations technology is 6 USC 1501(9). There the definition of ‘information system’ is still based on a reference to §3502, but it was specifically expanded by adding subparagraph (B) “includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers”.

The problem is, however, that §1501 does not also include the terms ‘cybersecurity risks’ or ‘incident’. One could use the current reference to §148 for those terms but specify that the term ‘information system’ is based upon §1501. Doing that in both instances where the first two terms are currently used would be very wordy and potentially confusing.

It would probably be better to add a new paragraph to §4 of the bill that provides definitions that would be used in the Port Security chapter of the US Code (46 USC 70101). If I were doing this, I would add the following definitions:

(1) The term ‘information system’ has the meaning given the term in section 3502 of title 44;

(2) The term ‘control system’ means a discrete set of information resources, sensors, communications interfaces and physical devices organized to monitor, control and/or report on physical processes, including manufacturing, transportation, access control, and facility environmental controls;

(3) The term ‘cybersecurity risk’ means:

(A) threats to and vulnerabilities of information, information systems, or control systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information, information systems, or control systems, including such related consequences caused by an act of terrorism; and

(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;

(4) The term ‘incident’ means an occurrence that actually, or imminently jeopardizes, without lawful authority:

(A) the integrity, confidentiality, or availability of information on an information system,

(B) the timely availability of accurate process information, the predictable control of the designed process or the confidentiality of process information, or

(C) an information system or a control system;


With these definitions in place the references to §148 are superfluous and should be removed. Then the intent would be clear that the bill would be addressing both the information and control system cybersecurity of port operations. And that is almost certainly the intent of the crafters of this bill.

Tuesday, January 24, 2017

S 133 Introduced – FY 2017 Intelligence Authorization

Earlier this month Sen. Burr (R,NC) introduced S 133, the Intelligence Authorization Act for Fiscal Year 2017. Last Friday the Senate Select Committee on Intelligence reported the bill favorably without amendment. There are two cybersecurity provisions that may be of interest to readers of this blog:

Sec. 312. Assistance for nationally significant critical infrastructure.
Sec. 614. Report on cybersecurity threats to seaports of the United States and maritime shipping.

CI Assistance


Section 312 would authorize elements of the intelligence community, through the Under Secretary for Intelligence and Analysis of the Department of Homeland Security, to provide assistance to covered critical infrastructure facilities “to reduce the risk of regional or national catastrophic harm caused by a cyber attack (sic) against covered critical infrastructure” {§312(c)}.

A key term used in §312 is ‘covered cybersecurity asset’ which is defined as “an information system or industrial control system [emphasis added] that is essential to the operation of covered critical infrastructure” {§312(a)(2)}.

The bill describes the type of assistance to be provided by the intelligence community. It includes {§312(e)(2)}:

• Activities to develop a national strategy to effectively leverage intelligence community resources made available to support the program;
• Activities to consult with the Director of National Intelligence and other appropriate intelligence and law enforcement agencies to identify within the existing framework governing intelligence prioritization, intelligence gaps and foreign intelligence collection requirements relevant to the security of covered cyber assets and covered critical infrastructure;
• Activities to improve the detection, prevention, and mitigation of espionage conducted by foreign actors against or concerning covered critical infrastructure;
• Activities to identify or provide assistance related to the research, design, and development of protective and mitigation measures for covered cyber assets and the components of covered cyber assets; and
• Activities to provide technical assistance and input for testing and exercises related to covered cyber assets.

Cybersecurity Threats to Seaports


Section 614 would require the Under Secretary of Homeland Security for Intelligence and Analysis to submit a report to Congress on cybersecurity threats to seaports and maritime shipping. The report would address “the cybersecurity threats to, and the cyber vulnerabilities within, the software, communications networks, computer networks, or other systems” {§614(a)}. While it does not specifically address control systems, the ‘other systems’ mention probably provides for coverage of that topic.

In addition to a report on any recent cyberattacks or cybersecurity threats, the bill would require an assessment of{§614(b)}:

• Any planned cyberattacks directed against such software, networks, and systems;
• Any significant vulnerabilities to such software, networks, and systems; and
• How such entities and concerns are mitigating such vulnerabilities.

While not specifically stated, the report will almost certainly be classified because of the requirement to be “consistent with the protection of sources and methods” {§614(a)}.

Moving Forward



This bill was supposed to have been a ‘must pass’ bill in the last session. The House passed three slightly different versions of an intel authorization bill and the Senate Select Committee on Intelligence marked up their own version of such a bill, but nothing made its way to the Senate floor. With most of the players remaining the same in the Senate, it will be interesting to see if the change in administration has any potential effect on the consideration of this bill.

Saturday, March 5, 2016

CG Publishes NPPD Report on Effects of Malicious Cyber Activity

This week the Coast Guard published a report by DHS-NPPD Office of Cyber and Infrastructure Analysis about the consequences of malicious cyber activity directed against seaport operations. The report, Consequences to Seaport Operations from Malicious Cyber Activity {sorry the CG Homeport does not use real links so: CG Homeport –> Cybersecurity –> Cyber Information (More)} takes a fairly high-level look at cyber threats.

Key Findings


The report makes the following four key findings:

• Unless cyber vulnerabilities are addressed, they will pose a significant risk to port facilities and aboard vessels within the Maritime Subsector;
• A cyber-attack on networks at a port or aboard a ship could result in lost cargo, port
disruptions, and physical and environmental damage depending on the systems affected;
• The impacts to critical infrastructure sectors depend on how a cyber-attack affects a port,
the level and length of disruption that occurs at the port, and the capability to divert
shipments to other ports;
• Several mitigation measures can increase the security and resiliency of ports: setting up maritime cybersecurity standards, sharing information across the sector, conducting routine vulnerability assessments, using best practices, mitigating insider threats, and developing contingency plans for cyber-attacks.

Cybersecurity Vulnerabilities


After providing a statistical overview of seaport operations in the United States and the various types of cyber systems (both land-side and ocean-going) that support those operations, the report provides a broad look at the various types of cybersecurity vulnerabilities that face operators of those systems. These include (with a brief discussion of each):

• Limited cybersecurity training and preparedness;
• Inadequately protected commercial off-the-shelf technologies and legacy systems;
• Errors in software;
• Network connectivity and interdependencies;
• Software similarities;
• Foreign dependencies;
• GPS jamming and spoofing; and
• Insider threats

This is followed by a brief discussion about how these vulnerabilities could be used to effect cyber-attacks on port operations and ship operations. Real-life illustrative examples are provided where available. For port operations the report looks at:

• Disruption of cargo operations;
• Accessing ICS;
• GPS disruption; and
• Other malicious activities

For ship operations the report looks at:

• GPS jamming and spoofing; and
• ICS access

Critical Infrastructure Effects


The report then looks at the consequences attacks on port systems could have on the general economy by addressing specific effects on various areas of critical infrastructure. A substantial number of real world examples are used to illustrate the potential effects. The effects on the following specific critical infrastructure sectors are looked at:

• Critical manufacturing;
• Commercial facilities;
• Food and agriculture;
• Energy;
• Chemical; and
• Transportation systems

Mitigation Measures


The concluding portion of this report very briefly discusses mitigation measures that could be employed. The measures discussed (at just a paragraph each) include:

• Establishing cybersecurity standards;
• Implementing information sharing systems;
• Conducting vulnerability assessments and exercises;
• Ensure the use of best practices;
• Resiliency efforts; and
• Ultimately, use unaffected alternative ports in the event of a real cyber-attack.

Commentary


One important vulnerability left out of this discussion is the area of information protection. Recent reports that sea going pirates are hacking shipping information about cargoes and shipping routes to target specific ships points out how much valuable information is being used in port information systems. Attacks on those information systems could also be used to misdirect the land-side shipment of high-value containers, expanding the reach of cargo hijackers.

While this report approaches the issue from a very high-level perspective of the port related cybersecurity problems facing the country, there is hardly a resounding call to action included in the report. The very brief and wholly inadequate discussion of mitigation measures leaves the impression that there is not much that can be done to prevent cyber-attacks or mitigate the effects of a cyber-attack. The final mitigation measure of just using an unaffected alternate port emphasizes the effective hands-off approach that the OCIA appears to be offering to the potential problem.


While I understand that the OCIA has no direct responsibility for port operations, the fact that this report was released by the Coast Guard means that it should have included, either as an addendum to the report or as a separate cover document, a proposed course forward for the Coast Guard, shippers, port operators and port facility owners. The failure to set the course will ensure that this document will settle into the Saragossa Sea of maritime bureaucratic effluvia, soon to be forgotten.

Monday, November 2, 2015

Committee Hearings – Week of 11-1-15

With both the House and Senate in Washington this week there will only be three committee hearings that may be of specific interest to readers of this blog. The House Rules Committee will hold two hearings to look at consideration of a surface transportation authorization bill and the House Homeland Security Committee will mark-up a number of bills.

STA Rules Committee Hearing

The House Rules Committee will be holding two hearings this week trying to reconcile two different versions of the Surface Transportation Authorization Act; HR 22 (Senate version) and HR 3763. The first hearing will be this evening and will establish the rule for the general consideration of the bill (will probably us HR 22 as the vehicle). The second hearing will be on Tuesday and will determine how the proposed amendments (86 currently listed on the Committee web site) will be addressed on the floor of the House.


Homeland Security Markup

On Wednesday the House Homeland Security Committee will hold a markup hearing for seven separate bills. Of those bills only three may be of specific interest to readers of this blog and none of them have yet been introduced (Committee Drafts are available):

• State and Local Cyber Protection Act of 2015;
• Department of Homeland Security CBRNE Defense Act of 2015; and
• Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2015;

I’ll have more information on these bills in a later post.

On the Floor

The House will be taking up a number of homeland security related bills under the suspension of rules this week. Of those only one may be of specific interest to readers of this blog; HR 3503, the Department of Homeland Security Support to Fusion Centers Act of 2015. Unfortunately, there will be limited debate and no chance to correct the deficiencies I noted.


The House will also probably consider the STA authorization bill that I mentioned above. It is also scheduled to address the President’s veto of HR 1735, the National Defense Authorization Act of 2016.

BTW: This week really marks the start of the House’s operation under Speaker Ryan. That may get interesting, but probably not this week.

Monday, June 2, 2014

Committee Hearings – Week of 6-1-14

The House is working back in their districts this week but the Senate is in session. Transportation will be the focus of three hearings; one authorization and two spending hearings. The other hearing of potential interest to readers of this blog will be an oversight hearing on port security.

THUD Spending

There will be two hearings this week on the Senate’s version of the FY 2015 transportation spending bill. The Homeland Security subcommittee of the Senate Appropriations Committee will meet Tuesday to mark-up the draft version of the bill which is not yet publically available. The Full Committee will meet Thursday for the final mark-up. I fully expect the bill to contain language addressing the safety of crude oil unit trains in general and the regulation of DOT 111 rail cars specifically.

Surface Transportation Authorization

The Surface Transportation and Merchant Marine Infrastructure, Safety, and Security Subcommittee of the Senate Commerce, Science and Transportation Committee will meet on Tuesday to discuss “Surface Transportation Reauthorization: Examining the Safety and Effectiveness of our Transportation Systems”. Again, I expect that the topic of the safety of the safety of crude oil unit trains and DOT 111 car regulations will come up.

Port Security

The Senate Homeland Security and Governmental Affairs Committee will be meeting on Wednesday to look at “Evaluating Port Security: Progress Made and Challenges Ahead”. The witness list currently includes:

• Ellen McClain, Office of Policy, DHS;
• Rear Admiral  Paul F. Thomas, USCG;
• Kevin K. McAleenan, Customs and Border Protrection, DHS;
• Brian E. Kamoie, FEMA, DHS;
• Stephen Sadler, TSA, DHS; and

• Stephen L. Caldwell, GAO.

Friday, August 2, 2013

Bills Introduced – 8-1-13

On the next to last day of the session before the summer recess it was a busy day for the introduction of legislation; 70 bills in the Senate and 86 bills in the House. The following may be of specific interest to the chemical security/safety and cybersecurity communities:

S 1429 Latest Title: An original bill making appropriations for the Department of Defense for the fiscal year ending September 30, 2014, and for other purposes. Sponsor: Sen Durbin, Richard (D,IL)

S 1435 Latest Title: A bill to amend title 49, United States Code, to provide certain port authorities, and for other purposes. Sponsor: Sen Gillibrand, Kirsten E. (D,NY)

S 1462 Latest Title: A bill to extend the positive train control system implementation deadline, and for other purposes. Sponsor: Sen Thune, John [SD]

S 1464 Latest Title: A bill to facilitate and enhance the declassification of information that merits declassification, and for other purposes. Sponsor: Sen Shaheen, Jeanne [NH]

HR 2952 Latest Title: To amend the Homeland Security Act of 2002 to make certain improvements in the laws relating to the advancement of security technologies for critical infrastructure protection, and for other purposes.Sponsor: Rep Meehan, Patrick (R,PA)


HR 2958 Latest Title: To amend title 49, United States Code, to provide certain port authorities, and for other purposes.Sponsor: Rep Nadler, Jerrold (D,NY)

Thursday, August 1, 2013

Bills Introduced – 07-31-13

Yesterday there was one bill introduced that might be of interest to the port security community:

HR 2875 Latest Title: To authorize programs and activities for the improvement and protection of ports and harbors, and for other purposes. Sponsor: Rep Velazquez, Nydia M. (D,NY)


Just how extensive the port security portions of the bill are is not yet clear.

Thursday, July 4, 2013

Unified Agenda – Spring 2013 – Published

Yesterday the Office of Management and Budget posted the Spring 2013 Unified Agenda on their Reginfo.gov web site. This includes the individual agency lists of rule makings that are planned and/or in various stages of completion. It includes links to the ‘Current Long Term Actions’ list of rulemakings that are under consideration.

DHS Rulemakings

Table 1 below shows the current list of DHS rulemakings on the Unified Agenda that will be of specific interest to the chemical safety and security communities. Chemical safety is not normally considered an DHS concern, but it is one of the missions of the Coast Guard so some chemical safety rulemakings are included on the DHS list.

OS
Final Rule
Ammonium Nitrate Security Program
OS
Final Rule
Classified National Security Information
USCG
NPRM
Updates to Maritime Security
USCG
Final Rule
Transportation Worker Identification Credential (TWIC); Card Reader Requirements
USCG
Final Rule
Bulk Packaging To Allow for Transfer of Hazardous Liquid Cargoes
USCG
Final Rule
Revision to Transportation Worker Identification Credential (TWIC) Requirements for Mariners
USCG
Final Rule
2012 Liquid Chemical Categorization Updates
TSA
NPRM
General Aviation Security and Other Aircraft Operator Security
TSA
NPRM
Security Training for Surface Mode Employees
TSA
NPRM
Freight Railroads and Passenger Railroads--Vulnerability Assessment and Security Plan
TSA
NPRM
Standardized Vetting, Adjudication, and Redress Services
Table 1: Current DHS Chemical Safety/Security Rulemakings

Comparing this latest Unified Agenda with the previous version published last December there are no major deletions or additions on the list of regulatory actions that the chemical safety/security communities will be specifically interested in on the DHS list (I’ll take a quick look at DOT and EPA lists in a separate post). The TWIC Card Reader rule did move into the ‘Final Rule’ category since the NPRM for that rulemaking has been published.

It hasn’t really struck me until today, but there are no cybersecurity specific rule makings on the DHS list.

There was some movement from the long term actions list to the current Unified Agenda, those items have been marked in BOLD in the table above.

The only changes within the rulemaking plans for these items are changes to the expected dates of the next action. The dates included in the Unified Agenda are, at best, hopeful guesses and the further they are in the future the less accurate they become.

In fact, the only date provided for the rulemaking activities listed above that is worth discussing is the July 2013 date for the Bulk Packaging To Allow for Transfer of Hazardous Liquid Cargoes rulemaking by the Coast Guard. The NPRM was published last year and the ‘expected date’ for the Final Rule is this month. If it is published by the end of July I will be surprised and I will be disappointed if it isn’t published by the end of September.

Long Term Actions

The Long Term Actions list is shown in table 2 below. There are no new additions to this list.

USCG
Top Screen Information Collection From MTSA-Regulated Facilities Handling Chemicals
TSA
Protection of Sensitive Security Information (SSI)
TSA
Drivers Licensed by Canada or Mexico Transporting Hazardous Materials To and Within the United States
Table 2: Long Term Actions

The last two items in the table already have interim final rules in place and just require TSA to respond to comments filed on that action and update the rule. The interim final rules date back to 2004 and 2006 and there is no incentive for TSA to take any action to ‘complete’ these rulemakings.

The Coast Guard Top-Screen for MTSA facilities rule is a slightly different story. This was initiated as part of a congressionally mandated harmonization of the chemical security rules under CFATS and MTSA and keeps moving back and forth between the Unified Agenda and the Long Term Actions list. I doubt that any action will ever be taken on this unless there is an attack on a chemical facility covered by MTSA.


BTW: The Pending DHS Security Rules page on this blog has not been updated in a while; it is hard to get motivated to update it since DHS is SOOOOO slow in moving their rules along. The Obama Administration’s resumption of periodically publishing the Unified Agenda will provide the needed impetus for getting that page updated.

Sunday, June 23, 2013

Comments for TWIC Reader NPRM – 6-22-13

This is part of a continuing series of blog posts on the public comments filed in the previous week for the Coast Guard’s TWIC Reader NPRM. The previous posts in the series are listed below.


There were 10 comments posted this week, a record for this docket but hardly a major closing comment period for a rule that has been as long awaited or as recently debated in Congress as this one.  Maybe the port security community knows more about the TWIC Reader than does Congress or the GAO.

Address GAO Report Concerns

A chemical bulk terminal operator recommends that the final rule be delayed until the Coast Guard and TSA have a chance to address the concerns expressed in the recent GAO report on the TWIC Reader Pilot. This argument was also raised by a member of Congress, a barge operator.

Expand TWIC Reader Requirements

A port security consultant recommends that the TWIC Reader requirements be extended to any Group B or C facility that shares a fence line with a Risk Group A facility. They argue that the common fence line would be easier to access from a lower risk facility if that facility does not require biometric verification of identity and TWIC status. They also argue that each Risk Group B and C facility be required to have one portable TWIC Reader available to respond to sudden changes is security situation that might require the deployment of a TWIC Reader.

An identification card vendor association make the point that Congress did not specify differing security standards based upon some arbitrary risk group ranking. They note that the use of the TWIC as a visual flash pass ID makes it no more useful than any other printed ID card.

Multiple Entries

The chemical bulk terminal operator recommends that the multiple entry rule be changed to require that only during the initial entry to a facility in a 24-hour period should an individual have to utilize a TWIC Reader to gain access. During subsequent entries the TWIC could be used as a flash pass in accordance with USCG Policy Advisory Council (PAC) 08-09 [No link available, I’m sorry, but the CG Homeport page does not provide for permanent links to documents].

A local water taxi company makes a point made in multiple earlier comments that requiring the showing of a TWIC upon every entry to secured spaces on smaller vessels with limited crews makes no sense.

Exempt Smaller Facilities

A marine service organization thinks that automatically making barge fleeting facilities that handle Certain Dangerous Cargo (CDC) Risk Group A facilities ignores the security realities of these facilities, particularly the limited access that is available. An Alaskan cruise line operator expresses the same concern for small cruise facilities.

Crewmember Definition


The barge operator would like to see the final rule include a definition of ‘crewmember’ based upon the definition in Navigation Vessel Inspection Circular 03-07. This is particularly important when considering the 14-crewmember exemption for requiring a TWIC Reader on Risk Group A vessels.

Wednesday, June 19, 2013

TWIC Reader Hearing Redux

Earlier this week the Subcommittee on Border and Maritime Security of the House Homeland Security Committee held a hearing to look at “Threat, Risk and Vulnerability: The Future of the TWIC Program”. Since this was more than a month since we sat through a similar hearing held by the Government Operations Subcommittee of the House Oversight and Government Affairs Committee, I had hoped to hear some new information about the TWIC Reader program, particularly from the GAO. Fortunately, I am used to being disappointed by Congressional hearings.

Looking at the written testimony presented by Mr. Lord (GAO) it looks like we entered a short time warp and were transported back to May 8th. The differences between the GAO report presented at that hearing and the one presented this week can’t be more than a couple of hundred words and most of those are the salutations to the committee chair and members.

The prepared testimony presented by Mr Sadler (TSA), on the other hand, was almost completely re-written, but it did not shed any new light on the issues at hand. Sadler (and presumably his bosses) still maintains that the TWIC Reader Pilot demonstrated that the “TWIC reader systems function properly when they are designed, installed, and operated in a manner consistent with the characteristics and business needs of the facility or vessel operation. People who watched the last hearing can probably still hear that refrain echoing through their minds.

We did have two new additions to this revival show; Rear Admiral Servidio (Coast Guard) and Mr. Woodring (Port of Houston Authority). The only information that the Admiral added was that the Coasties had extended the comment period by 30-days to give folks a chance to respond to the GAO charges that the TWIC Reader Pilot was inadequately designed and executed. As I have noted in other blog posts, that extension of the comment period has not brought much discussion of the TWIC Reader Pilot.

Mr. Woodring, a retired 27 year veteran of the Coast Guard and now working on the civilian side of the same street, brings an interesting perspective to the testimony. Having said that, he also ignores the TWIC Reader Pilot issue while pointing out the strong and weak points of the TWIC system (well worth reading for those not familiar with the program).

Oh well, I have come to expect the rehash or earlier information when multiple committees look at the same topic. It would have been more helpful if the two Subcommittees could have done this all at one time.


BTW: I don’t think I’m going to waste my time watching the replay video; I have never been a fan of re-runs or re-makes.

Monday, June 17, 2013

Comments for TWIC Reader NPRM – 6-15-13

This is part of a continuing series of blog posts on the public comments filed in the previous week for the Coast Guard’s TWIC Reader NPRM. The previous posts in the series are listed below.


Only six comments were received in the last week and there is less than a week left in the extended comment process. The commenters include two industry organizations, a petrochemical manufacturer, a barge operator, a local government ferry operator, and a local port authority.

Barge Fleet Exemption

A barge and tugboat association urges the Coast Guard to exempt barge fleeting operations from the requirement of using TWIC Readers. They argue that the current requirement based upon periodic handling of Certain Dangerous Cargo (CDC) ignores the unique situation of these facilities and the limited access already allowed.

Electronic Flash Pass

A major petrochemical manufacturer recommends that the Coast Guard specifically authorize the use of the TWIC in conjunction with an electronic access control system (not a full TWIC Reader) as an electronic flash pass instead of requiring visual inspection when a TWIC Reader is not deployed.

Portable TWIC Readers

The petrochemical manufacturer requests that the final rule specifically address the use of portable TWIC Readers at infrequently used entrances to facilities.

Risk Group A Designations

The petrochemical manufacturer objects to “the arbitrary re-designation of petroleum refineries, non-CDC bulk hazardous materials facilities, and petroleum storage facilities into Risk Group A”. They don’t believe that the designation is justified upon a risk-based analysis.

A local government ferry operator objects to the designation of ferries in Risk Group A solely based upon the number of passengers carried. They would rather see a vessel-specific risk assessment used to determine the risk group assignment of vessels. A local government port operator makes the same argument for assessing the risk group assignments for port facilities.


TWIC Reader Expansion to Risk Group B Facilities

A biometric industry association recommends the expansion of the use of TWIC Readers to Risk Group B facilities. The petrochemical manufacturer disagrees and calls the suggestion self-serving.


A local government ferry operator objects to the designation of ferries in Risk Group A solely based upon the number of passengers carried. They would rather see a vessel-specific risk assessment used to determine the risk group assignment of vessels.

Comment Period Ending


The extended TWIC Reader extended comment period will end this Thursday. Based upon previous TWIC related rulemakings, there will almost certainly be a surge in the number of comments submitted during the coming week.

Saturday, June 8, 2013

Comments for TWIC Reader NPRM – 6-8-13

This is part of a continuing series of blog posts on the public comments filed in the previous week for the Coast Guard’s TWIC Reader NPRM. The previous posts in the series are listed below.


Just about half-way through the one-month extension for comments on the TWIC Reader NPRM there are just four new comments posted. The comments come from a barge fleet operator, two terminal operators and a bus-transportation industry organization.

Cover Over-the-Road Bus Drivers

The bus industry organization is asking that the TWIC program be expanded to include over-the-road bus drivers. It reports that the industry is currently being governed by a patchwork of background screening requirements and this is making it difficult for the small business owner to operate in multiple markets, or even serving a variety of security conscious customers in a limited geographical area.

This is certainly outside of the scope of the Coast Guard’s rulemaking effort. The issue should be more appropriately address through Congress.

Expand TWIC Reader Requirement

The terminal operator is suggesting that the use of the TWIC Readers should be required for more than just the Risk Category A facilities. They note that they have carefully integrated a TWIC reader into their access control system at all of their facilities, in many cases utilizing Federal security grants. They are concerned that limiting the TWIC Reader requirements to just the Risk Category A facilities will mean that much of that money will have been wasted and that security at many those facilities will decline if they effectively have to switch to a ‘flash pass’ system because TWIC Readers are not required.

Similarly, a fuel-terminal operator, questions if the intent of the proposed rule would prevent Risk Category B&C facility operators from requiring the use of TWIC Readers at their facilities instead of using guards to inspect the use of the ‘flash pass’ TWIC.

Small Facility Exemption

The fuel-terminal operator expressed the opinion that small facilities regulated under 49 CFR 105 should be provided a TWIC Reader exemption for facilities with less than 14 people. They note that the same reasoning allowing that exemption for vessels would apply equally well to facilities.

Change Barge Rules


The barge fleet operator objects to ammonium nitrate bulk barges being categorized as Risk Group A vessels. They also note that where there is no ‘bank access’ to areas where CDC (certain dangerous cargo) are stored that those vessel should be reclassified as Risk Group B or C.

HR 2217 Amendments

As I noted earlier this week the House passed HR 2217, the DHS FY 2014 appropriations bill. There were a number of amendments to this bill offered from the floor, but only four would be of specific interest to readers of this blog; one dealing with Port Security Grants, two dealing with the TSA surface transportation security operations and one with TSA security vetting.

Port Security Grants

The House adopted by voice vote an amendment offered by Rep. Brownley (D, CA) that specifically sets the Port Security Grant program funding at $97,500,000; the same funding level as was set in FY 2013. The bill as offered in the House did not specify how much money was to go into each of the FEMA grant programs. This amendment changed this for this specific program.

In an interesting parliamentary move, Ms. Brownley did not mention the Port Security Grant program in the actual amendment, it simply removed and then re-added back the amount allocated to the general FEMA grant funding amount. Her description {CRec 6-5-13 pg H3157} of the purpose of the amendment on the floor is what served to allocate this for the specific program.

Surface Transportation Programs

There were two amendments offered dealing with the TSA surface transportation security programs. The first, offered by Rep. Lynch (D,MA) {CRec 6-5-13 pg H3138}, was adopted by the House in a voice vote, increased spending for surface transportation security programs by $15,676,000, restoring funding to the FY 2013 levels.

The second amendment, offered by Rep. Garrett (R,NJ) failed on a mixed vote (68 Republicans voted No, 19 Democrats voted Yes). The amendment would have added a section to the end of the bill prohibiting any spending on TSA Visible Intermodal Protection and Response (VIPR) teams outside of airports. The debate {CRec 6-5-13, pg H3178} clearly showed Mr. Garrett’s displeasure with the use of VIPR teams in the surface transportation arena.

TSA Security Vetting

An amendment offered by Rep. Mica (R,FL) and subsequently withdrawn {CRec 6-5-13, pg 3154} would have increased the funding for the Office of Transportation Threat Assessment and Credentialing by $23,334,000. The money would have come from the administration of the TSA airport screening program. The debate {CRec 6-5-13, pg 3150} indicated that Mr. Mica was more concerned about cutting the ‘bloated’ TSA airport program than with increasing the ‘connecting the dots’ operations at the OTTAC.

Moving On


It is likely that many of these amendments made by the House to HR 2217 will not make it into the final bill signed by the President. The Senate will almost certainly take up their version of a DHS spending bill (not yet published) and substitute that language for the language adopted by the House this week. A conference committee will then iron out the differences between the two versions of the bill.

Saturday, June 1, 2013

Comments for TWIC Reader NPRM – 6-1-13

This is part of a continuing series of blog posts on the public comments filed in the previous week for the Coast Guard’s TWIC Reader NPRM. The previous posts in the series are listed below.


The second week into a one-month comment extension and there were only two comments posted this week; an individual and a marine service operator.

Waterside Access

The individual commentor questions the need for TWIC Readers when “the biggest threat to any facility in any port is waterside access because facilities do not have authority to enforce laws or access on the water”.

Barge Fleeting Facilities


The marine service operator questions the need for TWIC Readers at barge fleeting facilities when the serviced vessels will not be required to have TWIC Readers because of the 14 person crew limit rule. He notes that most of these facilities employee even fewer people than the towing vessels they service.
 
/* Use this with templates/template-twocol.html */