Showing posts with label TSA ICR. Show all posts
Showing posts with label TSA ICR. Show all posts

Friday, August 16, 2013

TSA ICR Renewal 60-Day Notice – Pipeline Operator Security Information

Today the Transportation Security Administration published a 60-day information collection request (ICR) renewal notice in the Federal Register (78 FR 50077-50078) supporting the information reporting guidelines outlined in the Pipeline Security Guidelines. The information collections supported here are all voluntary in nature.

There are two specific types of information requests covered in this ICR renewal; security manager contact information and incident reporting information. TSA is requesting the contact information so that they might be able to contact the security manager in a timely manner if they develop security information that might be of interest to the pipeline owner/operator. The ICR notice does not explain why TSA wants to be notified of pipeline security incidents, but it is presumably so that they  may share incident information with other owner/operators as necessary to prevent attacks on other pipelines.

Incident Reporting

The types of incident information that TSA suggest should be reported to the Transportation Security Operation Center (TSOC; 866-615-5150 or TSOC.ST@dhs.govincludes:

• Explosions or fires of a suspicious nature affecting pipeline systems, facilities, or assets;
• Actual or suspected attacks on pipeline systems, facilities, or assets;
• Bomb threats or weapons of mass destruction (WMD) threats to pipeline systems, facilities, or assets;
• Theft of pipeline company vehicles, uniforms, or employee credentials;
• Suspicious persons or vehicles around pipeline systems, facilities, assets, or right-of-way;
• Suspicious photography or possible surveillance of pipeline systems, facilities, or assets;
• Suspicious phone calls from people asking about the vulnerabilities or security practices of a pipeline system, facility, or asset operation;
• Suspicious individuals applying for security-sensitive positions in the pipeline company;
• Theft or loss of Sensitive Security Information (SSI) (detailed pipeline maps, security plans, etc.); andShow citation box
• Actual or suspected cyber-attacks that could impact pipeline Supervisory Control and Data Acquisition (SCADA) or enterprise associated IT systems.

Burden Estimate

The table below shows the burden estimate for this renewal notice and the previously approved ICR.


This Notice
Previous
Reports
3,340
3,440
Burden Hours
845
895
Burden Cost
0
0

The changes in burden reporting reflects a change in the number of estimated incidents, 140 incidents were estimated in the earlier ICR Notice  but only 40 incidents in this notice. I would assume that the change is based on the actual number of incidents reported to date to TSA, but that is not specifically stated in this notice.

Public Comments


The TSA is soliciting public comments on this ICR renewal. They request that such comments be sent to the TSA PRA Officer (TSAPRA@dhs.gov). There is no explanation given as to why TSA is not using the Federal eRulemaking Portal for taking these comment submissions. It will certainly make it more difficult to determine if the TSA has responded to any such comments when they submit the 30-day notice sometime in the indeterminate future.

Monday, April 2, 2012

TSA Publishes 30-Day ICR Notice for Rail Security Program

The Transportation Security Administration published a 30-Day information collection request (ICR) notice in today’s Federal Register (77 FR 19680-19681) in support of its rail security program. This is a follow-up to the 60-day ICR notice published in January.

In my blog about that earlier notice I noted that TSA failed to explain why there was the large change in the number of respondents between this proposed submission and the currently approved ICR from 2008. That earlier ICR called for an expected 88,145 responses and a total burden of 288,945 hours at a cost of $9.4 million. The current ICR notice shows only 54,023 hours and does not list a cost nor does it list a total number of expected responses. Again there is no explanation for the change in this public document.

Friday, January 7, 2011

TSA Publishes 60-day ICR for New Exercise Program

Yesterday the Transportation Security Administration published a 60-day notice of their intent to file with the Office of Management and Budget (OMB) an information collection request (ICR) to support a new exercise program. Not an ab-reduction exercise program, the Exercise Information System (EXIS) described in this ICR is a component of TSA’s new Intermodal Security Training Exercise Program (I-STEP).

TSA estimates that up to 380,000 users may take about 8 hours each to submit information into EXIS over the next three years to support their voluntary participation in I-STEP. TSA is seeking public comments on this ICR notice. Comments need to be submitted by March 7, 2011 and may be emailed to TSAPRA@dhs.gov.

EXIS

TSA describes EXIS as “an Internet-accessible knowledge-management system developed by TSA serving stakeholders-industry, port authorities, Federal agencies, and State and local governments--and integrating other security-related training and exercise components at the sensitive security information level [emphasis added]” (76 FR 792). EXIS will provide data management throughout the exercise development, execution and review process. The new system can allow users to:

• Customize exercise design;
• Conduct robust analyses;
• Create analytical reports; and
• Collaborate and share information
Information Collection

As part of the voluntary exercise development, execution and review process EXIS will collect five types of information:

• User registration data
• Desired nature and scope of the exercise
• Post-exercise security evaluations
• EXIS evaluation
• After-Action reports
Based upon the participation projected and one exercise per year per participant, TSA expects a total annual hour burden for this ICR to be 3 million hours. Since there is no charge for participation in I-STEP, TSA projects no cost annual cost burden for participants. This of course totally ignores the time cost of participation.

Information Uses

Within the EXIS process the information submitted will be used to aid in the development of the user’s training exercise. Additionally, TSA notes that the information will be used to “automatically populate the [exercise] database with lessons learned from past exercises conducted in similar environments” (76 FR 793) both by the immediate user and other EXIS participants.

TSA also expects to analyze and use this information to internally to inform their efforts “to assess and improve the capabilities of all surface transportation modes to prevent, prepare for, mitigate against, respond to, and recover from transportation security incidents”.

Personal Observations

Anyone that has worked on emergency planning, and make no mistake security planning is at heart emergency planning, knows that, as we used to say in the Army, no plan survives contact with the enemy. No matter how hard one works on developing a plan, something will go unnoticed. Short of having to implement the plan in an emergency situation, conducting exercises are the best way to identify and correct shortcomings in such plans.

TSA is to be commended on providing a modern, internet based, exercise development program. Allowing exercise developers to learn lessons not only from their own exercises but from the exercises of others is perhaps one of the best ideas to come out of TSA. Now all we need to do is to see how well this is executed.
 
/* Use this with templates/template-twocol.html */