Showing posts with label TSA Regulations. Show all posts
Showing posts with label TSA Regulations. Show all posts

Thursday, February 5, 2009

Pending Rule – Vulnerability Assessments

Last week I wrote about three pending TSA rules that were listed on the Office of Management and Budget web site under the Fall 2008 Regulatory Agenda. Today I will take a closer look at what the rule on railroad vulnerability assessments and security plans could look like. This will be based on the material provided on the OMB web site and the referenced sections of the Implementing Recommendations of the 9/11 Commission Act of 2007 (PL 110-53). How the Obama Administration will actually implement the 9/11 Commission requirements remains to be seen. Section 1512 of the 9/11 Commission Act requires the Secretary of DHS to issue regulations that require railroads that are designated as high-risk to conduct vulnerability assessments (VA) and develop a security plan (SP) based on that assessment. The Secretary will develop standards and guidelines for the VA’s and SP’s in accordance with the National Strategy for Railroad Transportation Security (NSRTS) outlined in § 1511 (NOTE: it is not clear to me that the NSRTS has yet been developed, but that is a separate issue for another day). The deadline established in § 1512(a) for the publication of this regulation passed in August of last year. Tier Assignments Section 1512(h) requires that the Secretary assign “each railroad carrier to a risk-based tier established by the Secretary”. The tiers, and the methodology used to assign rail carriers to those tiers, will be established using the criteria established in the NSRTS. At least on of those tiers will be a ‘high-risk’ tier. The regulations prepared under the §1512 requirements may require rail carriers to provide the “information necessary for the Secretary to assign a railroad carrier to the appropriate tier” {§ 1512(h)(1)} Vulnerability Assessment Section 1512(d) details the requirements for the vulnerability assessments that will be required by these regulations. The VA must identify critical assets and infrastructure, vulnerabilities to those assets and infrastructure, and strengths and weaknesses related to those vulnerabilities. Those critical assets and infrastructure will include platforms, stations, intermodal terminals, tunnels, bridges, switching and storage areas, and information systems as appropriate. The strength and weaknesses required to be identified in the vulnerability assessment must address eight specific areas listed in § 1512(d)(1)(c). Those areas are:
Physical security; Passenger and cargo security; Programmable electronic devices, computers, or other automated systems; Alarms, cameras, and other protection systems; Communications systems and utilities needed for railroad security purposes; Emergency response planning; Employee training; and Such other matters as the Secretary determines appropriate.
Additionally, the VA must identify those backup systems and system redundancies that are necessary to allow the railroad carrier to continue operations in the event of a terrorist attack or other incident. Systems specifically identified in § 1512(d)(1)(D) include “disruption of commercial electric power or communications network”. Security Plan Section 1512(e) requires that the Secretary provide ‘technical assistance and guidance’ on the development and implementation of the security plans required to be included in this regulation. The section goes on to detail nine specific areas that those plans should address. Only two of those nine areas actually deal with classical security measures and those only address security for ‘security-sensitive materials’ and the additional security measures to be applied “when the Secretary declares a period of heightened security risk” {§ 1512(e)(1)(F)} One of the required components of the security plan is the appointment of a ‘security coordinator’. This is very similar to the Rail Security Coordinator established in last fall’s freight rail security rule. There are some differences. In this legislation the security coordinator must have the authority to “to implement security actions under the plan” {§ 1512(e)(1)(A)}; there is no such requirement for an RSC. Section 1512(e)(2) also requires that the security coordinator is a US citizen, though the Secretary can waive this requirement after conducting a “background check of the individual and a review of the consolidated terrorist watchlist”. Consultation It appears that one of the most common components of the requirements included in the 9/11 Commission Act was the requirement for coordinating actions. Section 1512(m) establishes that requirement in this case. It requires the Secretary to consult with “railroad carriers, nonprofit employee labor organizations representation railroad employees, and public safety and law enforcement officials” in preparing this regulation. Interestingly there is no requirement to coordinate with shippers or other customers of the railroads. The Way Forward TSA has tried to work with the railroad industry to get them to voluntarily comply with requirements to conduct vulnerability assessments and establish security plans. The lack of specificity in the requirements for that voluntary effort and the inability of TSA to enforce compliance ensures that most of the security efforts will fall short of the requirements of § 1512. This rule will be much more complex than the CFATS regulations. TSA would do well, though, to look at the implementation scheme used for CFATS. A computer based system for providing pre-tiering information, as well as vulnerability assessment and security plan filing will go a long way to making the implementation of these requirements easier for both the regulated community and the regulators.

Tuesday, February 3, 2009

Pending Rule – Security Training of Employees

Last week I wrote about three pending TSA rules that were listed on the Office of Management and Budget web site under the Fall 2008 Regulatory Agenda. Today I will take a closer look at what the rule on security training of employees could look like. This will be based on the material provided on the OMB web site and the referenced sections of the Implementing Recommendations of the 9/11 Commission Act of 2007 (PL 110-53). How the Obama Administration will actually implement the 9/11 Commission requirements remains to be seen. Section 1517 of the 9/11 Commission Act directs the Secretary of DHS to “develop and issue regulations for a training program to prepare railroad frontline employees for potential security threats and conditions” {§ 1517(a)}. The Secretary is also required to “issue guidance and best practices for a railroad shipper employee security program” {§ 1517(g)}. The requirements of this section are detailed and comprehensive. And we are now a year past the date specified (February 3, 2008) for the implementation of this rule. Consultation Requirements Section 1517(b) requires that the Secretary consults with a wide variety of people and organizations in the development of the proposed regulations. While a specific consultive framework is not specified, it does not seem likely that Congress intended for the standard regulatory comment procedure to adequately fulfill this requirement. Along with the typical subject matter experts, this section requires that the consultation includes railroad carriers and shippers, as well as the labor organizations representing railroad workers. Mandatory Training Elements Section 1517(c) specifies eleven different elements that must be addressed in the training program in addition to the catch all other “security training activities that the Secretary considers appropriate”. These range from the use of personal protective equipment to live “situational training exercises regarding various threat conditions, including tunnel evacuation procedures”. Program Requirements Section 1517(d) provides direction for additional program requirements. It includes the requirement that railroads submit their training plans to TSA for approval. It also requires all ‘frontline employees’ to be trained within one year and new hires to be trained within sixty days of being hired. Additionally the rules require the Secretary to periodically update the training requirements and re-issue the regulations. The Way Forward Bits and pieces of the training requirements found in this section have been included in other regulations recently published by TSA. Unfortunately, the combined total of those requirements still fall way short of the program required in this law. Writing the regulations should not be difficult or time consuming. What could take a significant amount of time is bringing the disparate consultees together and developing a coherent program that will satisfy the requirements of this legislation.

Monday, February 2, 2009

Pending Rule – Reporting Security Issues

Last week I wrote about three pending TSA rules that were listed on the Office of Management and Budget web site under the Fall 2008 Regulatory Agenda. Today I will take a closer look at what the rule on reporting security issues could look like. This will be based on the material provided on the OMB web site and the referenced sections of the Implementing Recommendations of the 9/11 Commission Act of 2007 (PL 110-53). How the Obama Administration will actually implement the 9/11 Commission requirements remains to be seen. The OMB site provides a general abstract for the proposed rule. It describes provisions for “procedures by which TSA could issue civil money penalties for violations of any statutory requirement administered by TSA” and “procedures by which members of the public could report to TSA a problem, deficiency, or vulnerability regarding transportation security”. It also references sections of the 9/11 Commission Act that provide whistleblower protections to a variety of transportation workers. Enforcement Authority The OMB web site cites § 1302 of the 9/11 Commission Act as the authority for procedures for issuing civil penalties for laws administered by the TSA. This section provides for a $10,000 per day penalty for violations of applicable rules or orders issued by the Secretary of DHS. It establishes a maximum fine of $50,000 for individuals or $400,000 for “a person other than an individual or small business concern”. It does not pre-empt fines set by other legislation. Section 1304 provides for special provisions for assessing civil penalties for “public transportation agencies”. Section 1415 repeats these requirements and also prohibits the Secretary from imposing civil penalties for violating “administrative and procedural requirements” pertaining to grant applications. Section 1302 describes how the penalties would be administered and provides for the exclusive jurisdiction for district courts of the United States for civil actions to collect such fines. It limits the scope of such civil actions to collect fines by providing that “a court may not re-examine issues of liability or the amount of the penalty” in such cases. This section also provides for a public annual report by the Secretary of “all enforcement actions taken by the Secretary under this subsection”. That report must include “the docket number of each enforcement action, the type of alleged violation, the penalty or penalties proposed, and the final assessment amount of each penalty”. Procedures for Public Reporting Three different sections {§§ 1413(i), 1521(i), and 1536(i)} of the 9/11 Commission Act require TSA to establish rules for public reporting of “a problem, deficiency, or vulnerability regarding” security. Each of the individual sections governs a different section of the transportation sector; public transportation, motor carrier, and railroad. Each of these sections of the 9/11 Commission Act require the same thing. The Secretary is required to “establish through regulations after an opportunity for notice and comment, and provide information to the public regarding, a process by which any person may submit a report to the Secretary”. This establishes the legal requirement to prepare the regulation covered in this blog. All three sections add additional requirements beyond establishing the public reporting system. There is a requirement for the Secretary to respond to the submitter, if identified in the report, and acknowledge receipt of the report. Additionally the Secretary is required to review every report and to “take appropriate steps to address any problems or deficiencies identified”. Whistleblower Protections The interesting thing about the sections requiring the establishment of the public reporting process is that they form only a very small part of the section in which they are contained. The establishment of whistleblower protections makes up the largest part of those sections. In fact, a careful reading of the three sections leads one to conclude that the reporting systems are being established to provide a communication tool for transportation employees to contact TSA with information about “a problem, deficiency, or vulnerability regarding” their employer. These protections are already part of the US Code, so technically they do not have to be included in TSA regulations to provide legal cover for whistleblowers. Unfortunately, they do little good if employees are not aware of their protection. Few employees would be willing to risk their jobs by providing inside information about security issues to TSA without knowing that TSA could provide legal protections for their jobs. This means that any public announcement of these communications channels would have to provide information about the whistleblower protections included in the law. For the public communication channel to be effective in encouraging whistleblowers to come forward employers are going to have to be required to inform their workers of the protections available under these sections. Practically speaking, the only thing that could make that happen would be for that requirement to be included in the regulation being developed to establish the communication channel. The Way Forward Providing whistleblower protections to employees has long been a high priority for organized labor and the Democratic Party. It would not be unexpected for the Obama Administration to move forward quickly to publish the NPRM for this regulation. The wording for that NPRM will certainly include more about the whistleblower protections than we would have seen from the Bush Administration.
 
/* Use this with templates/template-twocol.html */