Showing posts with label Security Plans. Show all posts
Showing posts with label Security Plans. Show all posts

Monday, October 7, 2024

Review – S 5064 Introduced – Port Cybersecurity Plans

Last month, Sen Cornyn (R,TX) introduced S 5064, the Protecting Investments in Our Ports Act. The bill would amend 46 USC 54301 to require grantees under the Port Infrastructure Development Program that are using their grant to acquire digital infrastructure or software to have an approved security plan that “that addresses the cybersecurity risks of such digital infrastructure or software”. No funding would be authorized by this proposed legislation.

Moving Forward

Cornyn is not a member of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration, but his sole cosponsor {Sen Peters (D,MI)} is a member of the Committee. This means that there may be sufficient influence to see the bill considered in Committee. I do not see anything in the bill that would engender any organized opposition. I suspect that the bill would receive some level of bipartisan support.

Commentary

At first glance this is a motherhood and apple pie bill. If the government is going to be funding digital infrastructure, they sure ought to require that the grantees protect that investment with some minimum level of cybersecurity protection. And this would not require any new bureaucratic organization to oversee that requirement, the bill relies on the existing Maritime Transportation Security Act (MTSA) bureaucracy to oversee the requirement.

There is one problem though, there is no guarantee that an entity receiving a grant under §54301 is an MTSA covered facility that is required to have a security plan under §70103(c). In fact, §54301(a)(3)(A)(i)(II) allows for grants for projects “outside the boundary of a port, but is directly related to port operations or to an intermodal connection to a port”. An ‘outside the boundary of a port’ entity would not be covered under §70103(c).

 

For more details about the provisions of this bill, and a proposed fix for the problem identified in my commentary, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-5064-introduced - subscription required.

Wednesday, December 20, 2017

HR 4474 Introduced – Surface Transportation Security

Last month Rep. Watson-Coleman (D,NJ) introduced HR 4474, the Surface Transportation and Public Area Security Act of 2017. While the main focus of the bill is on public transportation security issues, it would have some impact on chemical transportation security issues.

Sections of the bill that may be of specific interest to readers of this blog include:

§106. Frontline employee security training.
§202. Risk scenarios.
§203. Assessments and security plans.
§301. Threat information sharing.
§302. Integrated and unified operations centers.
§304. Security technologies tied to foreign threat countries.

Security Training


Section 106 attempts to address the failure of the Transportation Security Administration (TSA) to implement surface transportation employee security training requirements established by Congress in 2007 (6 USC 1137, 1167, and 1184). TSA published a notice of proposed rulemaking in December 2016. The Fall 2017 Unified Agenda indicates that the Trump Administration currently intends to publish a final rule in September of next year, though that date slips each time the Unified Agenda is updated.

This section would require a report to Congress by the TSA on the status of the rulemaking and a subsequent review of that report by the DHS Inspector General.

Risk Scenarios


Section 202 would require TSA to annually use terrorist attack scenarios in establishing risk-based priorities supporting the modal transportation security plans currently required by 49 USC 114(s)(1)(B). Those scenarios are specifically required to include “cyber attack scenarios” {§202(b)}. A report to Congress is required on the priorities established, but details on the scenarios used is not required to be part of that report.

Security Plans


Similar to §106, §203 would require a report to Congress (with a subsequent review by the DHS IG) of the status of the rulemaking supporting the congressionally mandated (6 USC 1134, 1162, and 1181) development of security assessments and security plans by various surface transportation organizations. TSA published an advanced notice of proposed rulemaking on these requirements in December 2016 and the Trump Administration re-opened the comment period in March of this year. The current Unified Agenda lists this rulemaking under the ‘Long-Term Actions’ section with a ‘to be determined’ date for the issuance of an NPRM.

Information Sharing


Section 301 would specifically require TSA to provide personnel to support fusion centers “in jurisdictions with a high-risk surface transportation asset” {§302(a)} to improve the “timely sharing of classified information regarding terrorist and other threats”. It would also require DHS to provide assistance in obtaining security clearances for “appropriate owners and operators of surface transportation assets, and any other person that the Secretary determines appropriate to foster greater sharing of classified information relating to terrorist and other threats to surface transportation assets” {§302(c)}.

Security Technologies


Section 304 would require DHS to provide a report to Congress on the threats posed to surface transportation assets “posed by the use of security technologies, including soft4
ware and networked technologies, developed or manufactured by firms that are owned or closely linked to the governments of countries that are known to pose a cyber or homeland security threat”.

Moving Forward


Watson-Coleman is a member of the House Homeland Security Committee (as are a number of her co-sponsors), one of the two committees to which this bill was assigned for consideration. Other co-sponsors {including Rep. Lipinski, (D,IL)} are members of the House Transportation and Infrastructure Committee, the other committee to which the bill was assigned. This means that it is possible that this bill could be considered in either or both committees. There are no Republican co-sponsors, however, which would suggest that there is insufficient bipartisan support to move the bill forward in Committee.


The security training and security plan provisions of this bill are sure to draw objections from owners of the potentially affected transportation companies and their lobbying organizations. This makes it unlikely that the bill would be supported by a sufficient number of Republicans to move the bill forward in the House.

Tuesday, March 14, 2017

TSA Reopening Comment Period on Security Plan ANPRM

Today the DHS Transportation Security Administration (TSA) published a notice in the Federal Register (82 FR 13575) providing notice that it was reopening the comment period for their Advance Notice of Proposed Rulemaking (ANPRM) on ‘Surface Transportation Vulnerability Assessments and Security Plans”. The comment period for that rulemaking originally closed on February 14th, 2017.

A total of nine comments have been received on that ANPRM. Only one of those was from someone related to the freight railroad sector; a co-comment from the Association of American Railroads (AAR) and the American Short Line and Regional Railroad Association (ASLRRA). Their comments can be summed up by saying: “We already have this stuff covered, leave us alone.”

The re-opening of the comment period makes it clear that, now that the Trump Administration’s rulemaking review has been completed, this rulemaking will proceed since TSA is required to complete the rulemaking by law (6 USC 1162 and 6 USC 1172). The very small number of comments received for such a potentially costly rulemaking was obviously engendered by the assumption that the Trump TSA would not go forward with the rulemaking process.

I suspect that when we finally see the regulations proposed in the NPRM it will be very minimalist with regards to programs affecting the freight rail industry, essentially adopting the status quo. The only problem with that is that the law specifically establishes the mandate that the regulations require the railroads to “prepare, submit to the Secretary for approval [emphasis added], and implement a security plan in accordance with this section that addresses security performance requirements” {§1162(a)(1)(B)}.


The AAR/ASLRRA comments do not address how TSA should go about dealing with that requirement. I think we are going to see some additional comments.

Wednesday, February 12, 2014

PHMSA Publishes 60-Day ICR Notice for 8 ICRs

Today the DOT Pipeline and Hazardous Material Safety Administration published a 60-day information collection request (ICR) notice in the Federal Register (79 FR 8535-8538) covering eight separate ICRs that PHMSA will be requesting that OMB renew. Those ICRs are:

• Requirements for Cargo Tanks, 2137-0014;
• Hazardous Materials Incident Reports, 2137-0039;
• Flammable Cryogenic Liquids, 2137-0542;
• Container Certification Statement, 2137-0582;
• Response Plans for Shipments of Oil, 2137-0591;
• Hazardous Materials Security Plans, 2137-0612;
• Inspection and Testing of Meter Provers, 2137-0620; and
• Requirements for United Nations (UN) Cylinders, 2137-0621.

Publication of multiple ICRs like this typically means that no changes are being made and that is the case here. The total number of responses and the total burden hours for all of these ICRs remains the same as currently approved.


PHMSA is soliciting public comment on these ICR renewals. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # PHMSA-2013-0002) and should be submitted by April 14th, 2014.
 
/* Use this with templates/template-twocol.html */