Showing posts with label Recurring Unescorted Access. Show all posts
Showing posts with label Recurring Unescorted Access. Show all posts

Friday, May 8, 2009

Reader Comment – 05-06-08 – RUA Procedures

On Wednesday Anonymous posted a comment to my blog on TWIC Reader ANPRM comments, addressing the issue of confusion about the RUA (Recurring Unescorted Access). Anonymous writes:
“RUA could be made less mystifying if the Coast Guard would give some real-life examples, maybe by utilizing the FAQ page on the Homeport TWIC site. As was done with side-by-side accompaniment, via the PAC documents and the NVIC. Here's how RUA would be utilized on a vessel, on a small facility with limited personnel, on a large facility with an access control system aligned with TWIC. I think your explanation [in an earlier blog] of RUA is probably the best explanation I've read so far.”
Writing Regulations

This is a typical problem that regulation writers have. They are writing rules and regulations that will have to apply to a variety of situations. Every sentence that they write is reviewed by a number people; a variety of subject matter experts, lawyers and managers. Text that explains the concepts involved is avoided because of the fear that the explanation will limit enforcement activities when matters reach the litigation phase.

This problem is further aggravated in writing an ‘Advanced Notice of Proposed Rule Making’. Here the agency objective is to try to find out some of the unintended consequences of their proposed rule. They want to try to describe their intended rule in some level of detail, but want to leave enough room in the description to identify potential problems in the application of the rule.

There is actually a good side to the responders’ confusion about the RUA provisions. The regulation writers will see the same level of confusion that I have identified here in my blog. This should lead them to providing a little more detail in their explanation of the RUA concept in the actual draft regulation that will be published as a ‘Notice of Proposed Rule Making’(NPRM).

It is doubtful that that explanation would be found in the actual wording of the regulation, but it would certainly be discussed in more detail in the Preamble to the rule. This is where the regulators explain what they are trying to accomplish and address the comments submitted in the earlier rule making efforts.

Need for Public Participation This is why public comments on all phases of regulation development are so important to making good regulations. The writers of regulations have some level of technical expertise in area being regulated; usually on the enforcement side of the issue. What they usually lack is day-to-day experience in the industrial side of things.

Even when the writer has spent some time in the industry, it is impossible for them to have experience in all of the many varieties of organizations that will be affected by their regulations. This is why I take so much of my time in reviewing and writing about the submitted comments on draft regulations that will affect the chemical security community. I am hoping to goad people into submitting their own comments.

While I appreciate comments like this one from Anonymous being posted to my blog, they would be more effective if the same comments were posted to the Regulations.gov website.

Tuesday, April 14, 2009

TWIC Reader ANPRM – Security Plan Requirements

This is another in a series of blogs about the advanced notice of proposed rule making (ANPRM) that the Coast Guard recently published about the potential regulation of transportation worker’s identification credential (TWIC) reading devices. These devices would be used to verify the identity of people working in ships and facilities covered under the Maritime Transportation Security Act (MTSA). The other blogs in this series include: TWIC Reader ANPRM – Identification Techniques TWIC Reader ANPRM – Risk Groups TWIC Reader ANPRM – Reader Use by Risk Groups TWIC Reader ANPRM – Recurring Unescorted Access The ANPRM expresses the Coast Guard’s current thinking about what types of requirements will be included in the regulations that will be formally proposed later this year. This post looks at potential requirements for changes to security plans. Security Plan Amendments Current vessel and facility security plans were prepared, submitted and approved before these requirements were developed for the use of the TWIC Reader to identify, validate and verify the people authorized unescorted access to secure areas within the vessel or facility. Amendments to those security plans will have to be completed to take into account these new requirements. The Coast Guard is considering a six month (from the time of the publication of the final rule) time limit to submit the amended security plan, or perhaps setting up a staggered schedule to avoid having all security plans come due for renewal at the same time. Public comment on these time schedules and deadlines is requested. Security Plan Amendments could be required to address a wide variety of implementation requirements to include:
TWIC verification requirements; Unreadable fingerprint identification requirements; Separate physical access system requirements, including identity protection; Recurring unescorted access (RUA) requirements; Escort requirements at RUA facilities or on RUA vessels; Periodic card validity check requirements at RUA facilities or on RUA vessels;
Alternative Security Plan Amendments The Coast Guard does not currently believe that these TWIC Reader rules will require re-writing § 101.120. That is because there is already existing authority {§ 101.120(d)(i)(ii)} to allow the Coast Guard to order the amendments to existing ASPs. The Coast Guard expects to use the same time limits in such orders, but requests public comments on the suitability of those time limits. An organization ASP could cover more than one vessel and/or facility and could cover more than one risk group. With this in mind the Coast Guard notes that they would expect the amended ASP to address each relevant risk group.

Thursday, April 9, 2009

TWIC Reader ANPRM – Recurring Unescorted Access

This is another in a series of blogs about the advanced notice of proposed rule making (ANPRM) that the Coast Guard recently published about the potential regulation of transportation worker’s identification credential (TWIC) reading devices. These devices would be used to verify the identity of people working in ships and facilities covered under the Maritime Transportation Security Act (MTSA). The other blogs in this series include: TWIC Reader ANPRM – Identification Techniques TWIC Reader ANPRM – Risk Groups TWIC Reader ANPRM – Reader Use by Risk Groups The ANPRM expresses the Coast Guard’s current thinking about what types of requirements will be included in the regulations that will be formally proposed later this year. This post looks at potential policies related to recurring unescorted access to security areas on MTSA covered vessels and facilities. Small Vessel or Facility For small, tight knit groups personal recognition is the best form of identification. As long as the initial identification is secure and accurate, small work teams that work together on a daily basis are nearly impossible to infiltrate. It is this concept that the Coast Guard is utilizing in suggesting that small vessels and facilities may not have to require the use of a TWIC reader for Recurring Unescorted Access to secure areas within that vessel or facility. The Coast Guard is suggesting that an appropriate number of personnel that would meet this requirement is fourteen or fewer personnel. This is based on the concept of a small vessel where “the crew would typically include up to one Master, one Chief Engineer, and three four-person crews who rotate through watch shifts” (74 FR 13368). An MTSA covered vessel or facility with no more than 14 people who require unaccompanied access to the secure areas within that vessel or facility could include rules for Recurring Unescorted Access in their security plan. Personal Identification When an individual is hired to work on the small vessel or facility the individual’s identity is verified biometrically with the TWIC and a Reader. The TWIC is authenticated and validated at the same time. While working on the vessel or facility with an approved Recurring Unescorted Access plan, the TWIC will serve as a photo ID that will have to be checked periodically (on a schedule specified in the plan) but not every time that the individual enters a secure area on that vessel or facility. The individual’s TWIC will have to be periodically verified, but a TWIC reader will not be required for this validation. If a TWIC reader would not be available for the check the operator would be required to maintain a list of FASC-Ns and names of the employees in the Recurring Unescorted Access program. This list could then be verified against a current TSA Hot List of invalidated TWIC. It would actually be a negative verification; no match would be a good thing. Schedule for Validation The frequency of validation would vary by the vessel/facility Risk Group and the current MARSEC Level. For Risk Groups A and B the validation would be required weekly at MARSEC Level 1 and daily for MARSEC Levels 2 and 3. For Risk Group C the validation would have to be done monthly at MARSEC Level 1 and weekly for MARSEC Levels 2 and 3.
 
/* Use this with templates/template-twocol.html */