Showing posts with label Regulation. Show all posts
Showing posts with label Regulation. Show all posts

Saturday, October 4, 2025

BIS Sends UAS Supply Chain Security IFR to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOC’s Bureau of Industry and Security (BIS) on “Securing the Information and Communications Technology and Services Supply Chain: Unmanned Aircraft Systems”. The advanced notice of proposed rulemaking (ANPRM) was published on January 3rd, 2025.

According to the entry for this rulemaking in the Spring 2025 Unified Agenda:

“In this Interim Final Rule (IFR), the Department of Commerce’s Bureau of Industry and Security (BIS) will implement a rule regulating information and communications technology and services (ICTS) in the Unmanned Aircraft (UA) supply chain. This IFR will build upon BIS’s advance notice of proposed rulemaking (ANPRM) issued on January 3, 2025, that sought public comment on questions related to transactions involving ICTS integral to UAS that are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries identified at 15 CFR 791.4.”

Monday, November 25, 2024

BIS Sends Australia Group Final Rule to OMB

On Friday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the DOC’s Bureau of Industry and Security (BIS) on “Implementation of Certain Australia Group Decisions”. This rulemaking was not included in the Spring 2024 Unified Agenda.

The Australia Group is an ‘informal’ group of 42 countries that “coordinate their national export controls to limit the supply of chemicals and biological agents-as well as related equipment, technologies, and knowledge-to countries and nonstate entities suspected of pursuing chemical or biological weapons (CBW) capabilities.” 

Saturday, October 19, 2024

OMB Approves CISA’s Notice on Cybersecurity of Bulk Personal Information Transfers

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a ‘notice’ from CISA on “Security Requirements for Restricted Transactions Under Executive Order 14117”. The notice was sent to OIRA on July 8th, 2024.

This rulemaking was not published in the Spring 2024 Unified Agenda. This could be because this is a ‘notice’ not an actual proposed rulemaking.

As I noted in my earlier post:

“Executive Order 14117 outlines the Administration’s intent “to restrict access by countries of concern to Americans' bulk sensitive personal data and United States Government-related data when such access would pose an unacceptable risk to the national security of the United States.” Section 2(d) of that EO requires CISA to “propose, seek public comment on, and publish security requirements that address the unacceptable risk posed by restricted transactions”. Those ‘restricted transactions’ are outlined in §2(a) and are to be further defined by regulations issued by the Attorney General.”

I will probably not be covering these regulations in any depth in this blog, but I will certainly be announcing the relevant publications in the appropriate ‘Short Takes’ post.

Wednesday, August 21, 2024

BIS Sends ICTS Connected Vehicle NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOC’s Bureau of Industry and Security (BIS) on “Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles”. BIS published [removed from paywall] an advanced notice of proposed rulemaking (ANPRM) on this topic on March 1st, 2024.

According to the Spring 2024 Unified Agenda entry for this rulemaking:

“The Department of Commerce’s Bureau of Industry and Security (BIS) published an advance notice of proposed rulemaking (ANPRM) on March 1, 2024, to seek public comment on questions related to transactions involving information and communications technology and services integral to connected vehicles that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign countries or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (E.O.) 13873. BIS is reviewing comments and working to implement a proposed rule to assist BIS in better determining the technologies and market participants most appropriate for regulation pursuant to E.O. 13873 [link added] regarding connected vehicles.”

Saturday, July 13, 2024

OMB Approves 3 BIS Rulemakings – 7-12-24

Yesterday, the OMB’s Office of Information and Regulatory Affairs announced that it had approved three rulemaking actions by the DOC’s Bureau of Industry and Security:

Interim Final Rule - Standards-Related Activities and the Export Administration Regulations – Submitted May 17th, 2024,

NPRM - Proposed Amendments to the Export Administration Regulations: Crime Controls and Expansion/Update of U.S. Persons Controls. – Submitted May 9th, 2024,

NPRM - Proposed Amendments to End-Use and End-User Based Export Controls, Including U.S. Persons Activities Controls: Military and Intelligence End Uses and End Users. Submitted November 3rd, 2023,

None of these rulemakings look like they are going to be of specific interest here, but you never can tell with the BIS. At the very least, I will mention the publication of these rules in my ‘Short Takes’ blog post on the day of publication.

Thursday, June 13, 2024

OMB Approves Public Assistance NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NMRM) from DHS’ Federal Emergency Management Agency on “Update of FEMA's Public Assistance Regulations”. FEMA submitted this NPRM to OIRA on February 5th, 2024.

According to the ‘Statement of Need’ for this rulemaking in the Fall 2023 Unified Agenda:

“FEMA proposes to amend its Public Assistance and Community Disaster Loan program regulations to incorporate statutory changes that have amended sections of the Stafford Act relating to Public Assistance and Community Disaster Loans and to improve program administration. These include the Post-Katrina Emergency Management Reform Act of 2006 (PKEMRA), Pub. L. 109-295, 120 Stat. 1394, the Security and Accountability for Every Port Act of 2006 (SAFE Port Act), Pub. L. 109-347, 120 Stat. 1884, the Pets Evacuation and Transportation Standards Act of 2006 (PETS Act), Pub. L. 109-308, 120 Stat. 1725, the Sandy Recovery Improvement Act of 2013 (SRIA), Pub. L. 113-2, 127 Stat. 39, the Emergency Information Improvement Act of 2015, Pub. L. 114-111, 129 Stat. 2240, the Bipartisan Budget Act of 2018, Pub. L. 115-123, 132 Stat. 64, and the FAA Reauthorization Act of 2018, Division D, Disaster Recovery Reform Act of 2018 (DRRA), Pub. L. 115-254, 132 Stat. 3438.  FEMA also proposes to implement program improvements and make clarifications and corrections to existing regulations.”

I do not expect that I will be covering this rulemaking in any depth, but I will be watching it for any language or definitions that would specifically include responses to chemical incidents.

Thursday, April 4, 2024

NMSAC Meeting to Address CG Cybersecurity Rulemaking

Today, the Coast Guard published a meeting notice in the Federal Register (89 FR 23601-23602) for a scheduled meeting of the National Maritime Security Advisory Committee (NMSAC). The meeting will be held on May 10th. The main item on the agenda for this meeting will be the presentation of a new task for NMSAC on “Notice of Proposed Rulemaking on Cybersecurity in the Marine Transportation System”.

There is no specific solicitation of public comments in this notice, but typically written comments may be submitted to the Federal eRulemaking Portal site for the meeting (www.Regulations.gov; Docket # USCG-2024-0232).

Tuesday, February 27, 2024

Review - CG Marine Cybersecurity NPRM – Cybersecurity Plan

Last week, the CG published a notice of proposed rulemaking for “Cybersecurity in the Marine Transportation System”. The proposed regulations would update the maritime security regulations by adding regulations specifically focused on establishing minimum cybersecurity requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and U.S. facilities subject to the Maritime Transportation Security Act of 2002 regulations. This is part of a continuing series of posts on that rulemaking. The earlier posts included:

NPRM Introduction (short version),

Cybersecurity Officer (short version)

This post looks at the requirements for each vessel/facility to have a Cybersecurity Plan

Before the Cybersecurity Plan is started, each covered vessel or facility is required to conduct a Cybersecurity Assessment. The Cybersecurity Plan is then required to incorporate the results of that Cybersecurity Assessment as well as the cybersecurity measures outlined in the new Subpart F. The Cybersecurity Plan would be marked (and protected) as Sensitive Security Information. The proposed rule would require each Cybersecurity Plan to include 14 specific sections. Once the plan is completed it would be required to be submitted to the Coast Guard official responsible for approving the facility or vessel security plan under the Maritime Transportation Security Act. That official would then approve the plan, request additional information, or disapprove the plan.

Commentary

I am more than a little disappointed in the lack of detail about the requirements for the Cybersecurity Assessment. I understand that the Coast Guard was trying to write it general enough that it would apply to everyone, but would not unnecessarily burden anyone with unnecessary requirements. Unfortunately, there are some requirements that should have been included.

First and foremost is the absence of any requirement to define the cybersecurity systems that are to covered by the Cybersecurity Plan. Before any assessment can be made the system must be defined by listing all of the electronic components and defining how they are connected to each other and external communications systems, including the internet, perhaps to include a software bill of materials (SBOM) where available. Additionally, there needs to be a definition of how external communications to and from the system will be controlled or restricted, especially personally owned devices. To be sure, the controls of those communications would probably be included in the Cybersecurity Pan, but the communications nodes would have to be identified in the assessment.


For more details about the proposed regulatory requirements for Cybersecurity Plans, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cg-marine-cybersecurity-nprm-9c8 - subscription required.

Saturday, February 10, 2024

OSHA Sends Walk-Around Rep Final Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from DOL’s Occupational Safety and Health Administration (OSHA) on “Worker Walkaround Representative Designation Process”. The NPRM was published on August 30th, 2023.

According to the Fall 2023 Unified Agenda entry for the rulemaking:

“This rulemaking will clarify the right of workers and certified bargaining units to specify a worker or union representative to accompany an OSHA inspector during the inspection process/facility walkaround, regardless of whether the representative is an employee of the employer, if in the judgment of the Compliance Safety and Health Officer such person is reasonably necessary to an effective and thorough physical inspection.”

 
/* Use this with templates/template-twocol.html */