Showing posts with label Facility Security Officer. Show all posts
Showing posts with label Facility Security Officer. Show all posts

Wednesday, March 4, 2020

Suggestions for Facility Security Officers (FSOs) Concerning COVID-19 (Corona Virus) Response


Below are some suggestions for Facility Security Officers (FSOs) who are thinking about COVID-19 (corona virus) response. These suggestions are generated from conversations with other FSOs, with health care professionals, and from the cited references.

1. Let’s pay attention to what every single solitary health professional is telling us and wash our hands.   Make it both mandatory and easy for employees to wash their hands. Restaurants have signs stating, “Employees must wash their hands before leaving restroom.” Consider instituting this policy; it is one way to ensure periodic hand-washing. Make sure that the soap dispensers in the restroom and breakroom are full. Make this someone’s responsibility and put it in writing.

Make alcohol-based hand sanitizer (at least 60 – 95% alcohol) available when it is not possible to use soap and water. Portable hand sanitizer stands are available online but these stands are something that the facility can craft itself.

2. Make expectations for workplace behavior clear. Don’t assume that employees know that they should wash their hands, perform good cough and sneeze etiquette, stay home when sick, etc. Posters concerning these issues can be found on the Centers for Disease Control website at https://www.cdc.gov/nonpharmaceutical-interventions/tools-resources/educational-materials.html . It’s really important for employers to make their expectations about workplace behavior very clear and these posters are a good way to do it.

3. Perform routine environmental cleaning. From the CDC: “Routinely clean all frequently touched surfaces in the workplace, such as workstations, countertops, and doorknobs. Use the cleaning agents that are usually used in these areas and follow the directions on the label. No additional disinfection beyond routine cleaning is recommended at this time. Provide disposable wipes so that commonly used surfaces (for example, doorknobs, keyboards, remote controls, desks) can be wiped down by employees before each use.”

4. Distance is your friend. The health professionals are telling us to stay 6’ from other persons when possible. For example: if you are having a meeting, move the chairs further apart. If you are walking around the terminal, space yourselves out.

5. If you get into a situation where you must be around persons whose health status is not known to you (like aboard the vessel), you should take all reasonable precautions. If possible wear latex gloves.  Maintain a good space from the crew. Minimize touching handrails, etc. with your bare hands. A reasonable precaution may be to have one person along just to watch for and report on possible contamination. This person’s duties and responsibilities will only consist of this monitoring. Politely decline beverages and food. Although currently there is no evidence to support transmission of COVID-19 associated with food,  situations that might involve transmission of respiratory droplets should be avoided.  Use hand sanitizer as soon as possible and thoroughly wash hands (for 20 seconds) as soon as possible.

6. Be familiar with the latest policy on COVID-19. Coast Guard Maritime Commons blog (https://mariners.coastguard.blog/) informs the maritime community when these documents are issued.
  • The Coast Guard has issued Marine Safety Information Bulletin 01-20 Novel Coronavirus Precautions at https://www.dco.uscg.mil/Portals/9/DCO%20Documents/5p/MSIB/2020/MSIB-01-20-Novel-Coronavirus-Precautions-USCG.pdf?ver=2020-01-24-192641-323. The MSIB states that “Local industry stakeholders, in partnership with their Coast Guard Captain of the Port, should review and be familiar with section 5310 Procedures for Vessel Quarantine and Isolation, and Section 5320 - Procedures for Security Segregation of Vessels in their Area Maritime Security Plan (AMSP).” These plan sections detail the steps that the Captain of the Port will take to ensure that the vessel is quarantined or a security segregation is accomplished. (It has been my experience that many FSOs are not familiar with the details of their AMSP and do not have a copy. Many FSOs do not attend AMSC meetings.)
  • The Maritime Administration (MARAD) has issued Maritime Security Communications with Industry (MSCI) Advisory 2020-004-Global-Novel Coronavirus Outbreak., at https://www.maritime.dot.gov/content/2020-004-global-novel-coronavirus-outbreak. This communication states, “Illness of a person onboard a vessel that may adversely affect the safety of a vessel or port facility is a hazardous condition per 33 CFR 160.216 and must be reported to the U.S. Coast Guard COTP under 33 CFR 160.206. Suspected cases of 2019-nCoV must be reported to the COTP.”
  • The CDC’s main site for information on COVID-19 is https://www.cdc.gov/coronavirus/2019-ncov/index.html
  • A good guide for COVID-19 and employers, Interim Guidance for Businesses and Employers to Plan and Respond to Coronavirus Disease 2019 (COVID-19), February 2020, is found at https://www.cdc.gov/coronavirus/2019-ncov/specific-groups/guidance-business-response.html
  • The Centers for Disease Control (CDC) has a page concerning COVID-19 recommendations for ships, at https://www.cdc.gov/quarantine/maritime/recommendations-for-ships.html, Interim Guidance for Ships on Managing Suspected Coronavirus Disease 2019.
  • 42 CFR 71.21 requires ships’ masters to report to the CDC or to nearest the port at which the ship will arrive, the occurrence, on board, of any death or any ill person among passengers or crew (including those who have disembarked or have been removed) during the 15-day period preceding the date of expected arrival or during the period since departure from a U.S. port (whichever period of time is shorter).

7. Find out what practical steps you should take if you discover that multiple persons on the vessel are sick and guess what! no one has reported it to anybody. CBP, the ships chandlers, the dock crew, have all been aboard. Talk to your local health department; they may have an outbreak plan. Do not assume that they know anything about your operations or the vessels that come into your dock.
Granted, vessel representatives are required to report sick or deceased crew/passengers within the last 15 days to the CDC under 42 CFR 71.21. However -  I am concerned that the flow of information CDC > U.S. Coast Guard > individual facility might somehow stovepipe. Here is what is supposed to happen, from the MARAD advisory “The Coast Guard will continue to review all “Notice of Arrivals” in accordance with current policies and will communicate any concerns stemming from sick or deceased crew or passengers to their Coast Guard chain of command and the CDC quarantine station who will coordinate with local health authorities.”

8.  Keep the Coast Guard informed at once of any situation that might involve the maritime nexus and COVID-19.

Just my opinion: I don't think we can make the distinction that COVID-19 is a safety, not a security issue. Security activities such as screening may bring employees into contact with other people in a manner that was acceptable six months ago but may not be acceptable today, so this virus is very much a security manager's concern.

Saturday, March 30, 2019

Coast Guard Issues Final Rule on Seafarers' Access to Maritime Facilities


On Monday April 1, 2019, the U.S Coast Guard will issue the Final Rule on Seafarers Access to Maritime Facilities at https://www.govinfo.gov/content/pkg/FR-2019-04-01/pdf/2019-06272.pdf. The Federal Register section consists of a very enlightening preamble followed by the actual sections of 33 CFR 105 that will be amended.
Here are some details on the Final Rule. All quotations are from the Rule.

What? All MTSA facilities must implement a system providing seafarers, pilots, and representatives of seamen’s welfare and labor organizations access

Where? Between vessels moored at the facility and the facility gate

How? In a timely manner and at no cost to the seafarer or other individuals.

What are the timelines? The Final Rule is effective May 01, 2019. The new Sec. 21 of the Facility Security Plan (FSP), System for Seafarers Access, needs to be submitted to the Coast Guard for review by 02/01/2020, for implementation by 06/01/2020. Most facilities are already in compliance with granting seafarer’s access, but may not be meeting all the specific requirements of the Rule. Note: please talk to your petty officer before submitting. Depending on when your FSP needs to be annually inspected or re-approved, the Coast Guard may want you to submit this section in alignment with the annual compliance review or reapproval process, for Coast Guard workload considerations.

The amendments to 33 CFR 105 are included at the end of this post.

Why did this regulatory action come about? The Seaman’s Church Institute tracked and documented a troubling pattern of restrictions on access for seafarers and seafarer welfare providers over a period of years.  Despite actions on the part of the Coast Guard to ensure resolution of access problems short of regulation, access continued to be restricted. Congress took notice and Sec. 811 was included in the Coast Guard Authorization Act of 2010 (Pub. L. 111-281) requiring “facility owners and operators to ensure shore access for seafarers and other individuals. Specifically, section 811 requires each MTSA-regulated facility to ‘‘provide a system for seamen assigned to a vessel at that facility, pilots, and representatives of seamen’s welfare and labor organizations to board and depart the vessel through the facility in a timely manner at no cost to the individual.’’ A Notice of Proposed Rule Making (NPRM) published in 2014 resulted. The Coast Guard held a public meeting on the issues in Washington, D.C. in early 2015.The comment period on the NPRM closed in February 2015 but the Coast Guard reopened and extended the comment period for an additional 60 days.

More details:

Who is the ‘seafarer” and who are  the people who need to be given access? Seafarers are seafarers assigned to a vessel at that facility. Only foreign seafarers who have proper visa credentialing are affected by this rule. The NPRM considered family members to be among the persons to be given access.  This class of people has been eliminated in the final rule. The persons to be given access are pilots and representatives of seamen’s welfare and labor organizations.

How is this access to be accomplished? By using one of these methods:

(1) Regularly scheduled escort between the vessel and the facility gate that conforms to the vessel’s watch schedule as agreed upon between the vessel and facility.
(2) An on-call escort between the vessel and the facility gate.
(3) Arrangements with taxi services or other transportation services, ensuring  that any costs for providing the access described in this section, above the service’s standard fees charged to any customer, are not charged to the individual to whom such access is provided. If a facility  provides arrangements with taxi services or other transportation services as the only method for providing the access described in this section, the facility is responsible to pay any fees for transit within the facility.
(4) Arrangements with seafarers’ welfare organizations to facilitate the access described in this section.
(5) Monitored pedestrian access routes between the vessel and facility gate.
(6) A method, other than those in paragraphs (d)(1) through (5) of this section, approved by the COTP.
(7) If an access method relies on a third party, a back-up access method that will be used if the third party is unable to or does not provide the required access in any instance. An owner or operator must ensure that the access required in paragraph (a) of this section is actually provided in all instances.

What is “in a timely manner”? The Captain of the Port (COTP) will decide if the manner is timely.
The facility owner or operator must provide the access described in this section without unreasonable delay, subject to review by the Captain of the Port (COTP). The facility owner or operator must consider the following when establishing timely access without unreasonable delay:
(1) Length of time the vessel is in port.
(2) Distance of egress/ingress between the vessel and facility gate.
(3) The vessel watch schedules.
(4) The facility’s safety and security procedures as required by law.
(5) Any other factors specific to the vessel or facility that could affect access to and from the vessel.
(d) Access methods.

What is “no cost”? There is an excellent discussion of this issue in the preamble to the Final Rule. “No cost” means two things: “no cost to the seafarer” and also “no cost that is somehow underhandedly passed onto the seafarer”, as in the facility bills the vessel for the costs of this access who takes the cost out of the seafarers’ wages. On p. 12104 of the Federal Register, there is a very stern notice about what the Coast Guard is going to do if it finds out that fees as a condition of shoreside access are being imposed on seafarers.

From the preamble, on costs:
The CGAA does not specify who should pay for no-cost access for seafarers. Ultimately, the Coast Guard determined that it is the facility’s responsibility to provide the no cost service, as Coast Guard regulations already require each facility to have an approved FSP, which must now include a system for providing no-cost access to the facility for certain individuals.
However, the Coast Guard declined to specifically prohibit charges to the vessel, and let parties decide the allocation of costs between facility and vessel. This rule provides flexibility to facilities on how to comply with the mandate and how to provide no-cost access for seafarers, as long as its solution does not result in a cost to seafarers.

What must my new FSP Section 22, System for seafarers’ access, include?
On or before February 3, 2020, the facility owner or operator must document the facility’s system for providing the access described in this section in the approved FSP in accordance with § 105.410 or § 105.415.
The description of the facility’s system must include—
(1) Location of transit area(s) used for providing the access described in this section;
(2) Duties and number of facility personnel assigned to each duty associated with providing the access described in this section;
(3) Methods of escorting and/or monitoring individuals transiting through the facility;
(4) Agreements or arrangements between the facility and private parties, nonprofit organizations, or other parties, to facilitate the access described in this section; and
(5) Maximum length of time an individual would wait for the access described in this section, based on the provided access method(s).

What about TWIC and seafarer access?
            From the preamble:
…. this rule does not change existing TWIC requirements, and whether escorts are or are not required under TWIC rules does not affect the obligation to provide no-cost access to the seafarer. The facility has flexibility to decide how to comply with its TWIC requirements and the no-cost access requirements of this rule… Congress requires MTSA-regulated facilities to grant access through the facility to seafarers at no cost to the seafarer. This rule does not change the requirement to escort or otherwise monitor the access of a person who is not authorized to have unescorted access to the facility.

What about safety concerns when granting this access?
From the preamble:
“This final rule provides facility owners and operators with flexibility to ensure the safe passage of seafarers to and from the facilities’ gates through a variety of methods. It remains the responsibility of the facility owner or operator to ensure safety in accordance with the approved FSP on file. If conditions are unsafe or overly burdensome at certain facilities, mariners are encouraged to contact the local COTP to report such unsafe or overly burdensome conditions.”

What about facilities operating under an Alternate Security Program (ASP)?
From the preamble:
“Each facility operating under a Coast Guard-approved ASP must include seafarer access as directed by the ASP itself. This may be in the form of an annex or appendix explaining how the facility will comply with this rule. This document must be submitted to and approved by the cognizant COTP in the location of the facility submitting the annex.”



PART 105—MARITIME SECURITY: FACILITIES
■ 1. The authority citation for part 105 is revised to read as follows:
Authority: 33 U.S.C. 1226, 1231; 46 U.S.C. 70103; 50 U.S.C. 191; Sec. 811, Pub. L. 111–
281, 124 Stat. 2905; 33 CFR 1.05–1, 6.04–11, 6.14, 6.16, and 6.19; Department of
Homeland Security Delegation No. 0170.1.
§ 105.200 [Amended]
■ 2. Amend § 105.200 as follows:
■ a. In paragraph (b)(1), remove the words ‘‘security organizational structure’’ and add in their place the words ‘‘organizational structure of the security personnel’’ and remove the words ‘‘within that structure’’;
■ b. In paragraph (b)(4), remove the text ‘‘an FSP’’ and add in its place the text ‘‘a Facility Security Plan (FSP)’’;
■ c. In paragraph (b)(6) introductory text, remove the acronym ‘‘TWIC’’ and add in its place the words ‘‘Transportation Worker Identification Credential (TWIC)’’;
■ d. In paragraph (b)(6)(i), after the words ‘‘FSP are permitted to’’ add the words ‘‘serve as an’’;
■ e. In paragraph (b)(6)(ii), remove the word ‘‘should’’ and add in its place the words ‘‘in the event that’’;
■ f. In paragraph (b)(6)(iii), remove the word ‘‘what’’, and add in its place the word ‘‘which’’ and after the words ‘‘are secure areas and’’ add the words ‘‘which are’’;
■ g. In paragraph (b)(9), remove the text ‘‘coordination of’’ and add in its place the text ‘‘implementation of a system, in accordance with § 105.237, coordinating’’ and remove the text
‘‘(including representatives of seafarers’ welfare and labor organizations)’’ and add in its place the text ‘‘, as described in § 105.237(b)(3)’’; and
■ h. In paragraph (b)(14), remove the text ‘‘TSA’’ and add in its place the text ‘‘Transportation Security Administration (TSA)’’.
■ 3. Add § 105.237 to read as follows:
§ 105.237 System for seafarers’ access.
(a) Access required. Each facility owner or operator must implement a system by June 1, 2020 for providing access through the facility that enables individuals to transit to and from a
vessel moored at the facility and the facility gate in accordance with the requirements in this section. The system must provide timely access as described in paragraph (c) of this section and incorporate the access methods described in paragraph (d) of this section at no cost to the individuals covered. The system must comply with the Transportation Worker Identification Credential (TWIC) provisions in this part.
(b) Individuals covered. The individuals to whom the facility owner or operator must provide the access described in this section include—
(1) Seafarers assigned to a vessel at that facility;
(2) Pilots; and
(3) Representatives of seafarers’ welfare and labor organizations.
(c) Timely access. The facility owner or operator must provide the access described in this section without unreasonable delay, subject to review by the Captain of the Port (COTP). The facility owner or operator must consider the following when establishing timely access without unreasonable delay:
(1) Length of time the vessel is in port.
(2) Distance of egress/ingress between the vessel and facility gate.
(3) The vessel watch schedules.
(4) The facility’s safety and security procedures as required by law.
(5) Any other factors specific to the vessel or facility that could affect access to and from the vessel.
(d) Access methods. The facility owner or operator must ensure that the access described in this section is provided through one or more of the following methods:
(1) Regularly scheduled escort between the vessel and the facility gate that conforms to the vessel’s watch schedule as agreed upon between the vessel and facility.
(2) An on-call escort between the vessel and the facility gate.
(3) Arrangements with taxi services or other transportation services, ensuring that any costs for providing the access described in this section, above the service’s standard fees charged to any customer, are not charged to the individual to whom such access is provided. If a facility provides arrangements with taxi services or other transportation services as the only method for providing the access described in this section, the facility is responsible to pay any fees for transit within the facility.
(4) Arrangements with seafarers’ welfare organizations to facilitate the access described in this section.
(5) Monitored pedestrian access routes between the vessel and facility gate.
(6) A method, other than those in paragraphs (d)(1) through (5) of this section, approved by the COTP.
(7) If an access method relies on a third party, a back-up access method that will be used if the third party is unable to or does not provide the required access in any instance. An owner or operator must ensure that the access required in paragraph (a) of this section is actually provided in all instances.
(e) No cost to individuals. The facility owner or operator must provide the access described in this section at no cost to the individual to whom such access is provided.
(f) Described in the Facility Security Plan (FSP). On or before February 3, 2020, the facility owner or operator must document the facility’s system for providing the access described in this section in the approved FSP in accordance with § 105.410 or § 105.415.
The description of the facility’s system must include—
(1) Location of transit area(s) used for providing the access described in this section;
(2) Duties and number of facility personnel assigned to each duty associated with providing the access described in this section;
(3) Methods of escorting and/or monitoring individuals transiting through the facility;
(4) Agreements or arrangements between the facility and private parties, nonprofit organizations, or other parties, to facilitate the access described in this
section; and
(5) Maximum length of time an individual would wait for the access described in this section, based on the provided access method(s).
■ 4. Amend § 105.405 as follows:
■ a. In paragraph (a)(18), remove the text ‘‘part 105; and,’’ and add in its place ‘‘this part;’’;
■ b. In paragraph (a)(21), remove the period at the end of the paragraph and add in its place ‘‘; and’’; and
■ c. Add paragraph (a)(22).
The addition reads as follows:
§ 105.405 Format and content of the Facility Security Plan (FSP).
(a) * * *
(22) System for seafarers’ access.
* * * * *
Dated: March 27, 2019.
Jennifer F. Williams,
Captain, U. S. Coast Guard, Director of
Inspections and Compliance.


Monday, August 6, 2018

Latest Developments that will Affect Implementation of the TWIC Reader Final Rule


On August 02, 2018, HR 5729 was signed into law, becoming Public Law No: 115-230,The  Transportation Worker Identification Credential Accountability Act of 2018.  The law is so brief that it is quoted in its entirety at the end of this post.  It prohibits the Coast Guard from implementing the TWIC Reader Final Rule and proposing or issuing a notice of proposed rulemaking for any revision to that rule except to extend its effective date, or for any other rule requiring the use of biometric readers for biometric transportation security cards. The Coast Guard may not do any of this before the end of the 60-day period after submission to Congress of the results of an assessment of the effectiveness of the TWIC program, required under a 2016 law mandating a comprehensive security assessment of the program. TSA was supposed to have commenced and completed this assessment of the TWIC program in 2017, but I can find no evidence on the relevant congressional committee websites of testimony on the assessment.

On August 03 the Coast Guard published a post on Maritime Commons, Latest Developments Regarding the TWIC Reader Final Rule, at http://mariners.coastguard.dodlive.mil/2018/08/03/8-3-2018-latest-developments-regarding-twic-reader-final-rule/, advising about HR 5729.
The Maritime Commons post gives some information from International Liquid Terminals Association et. al. v. DHS, the industry groups lawsuit against the TWIC reader rule, that also impacts implementation of the rule: “Additionally, the United States District Court for the Eastern District of Virginia issued a court order July 24, 2018, delaying the TWIC Reader Final Rule implementation at Certain Dangerous Cargo transfer and non-transfer facilities until further order of the Court, in response to a lawsuit brought by industry groups.”

What this will probably mean for us is that the clock has been stopped on the TWIC reader final rule – not just for certain classes of facilities, but for all facilities subject to the rule. Maritime Commons states in the August 03 post that “The Office of Port and Facility Compliance will provide additional information regarding the impacts of this law, the current lawsuit, and the Notice of Proposed Rulemaking in the near future.”
______________________________________________________

Public Law No: 115-230
An Act, To restrict the department in which the Coast Guard is operating from implementing any rule requiring the use of biometric readers for biometric transportation security cards until after submission to Congress of the results of an assessment of the effectiveness of the transportation security card program.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the “Transportation Worker Identification Credential Accountability Act of 2018”.
SEC. 2. RESTRICTION ON IMPLEMENTATION OF TRANSPORTATION WORKER IDENTIFICATION CREDENTIAL BIOMETRIC READER RULE.
The department in which the Coast Guard is operating may not implement the rule entitled “Transportation Worker Identification Credential (TWIC)–Reader Requirements” (81 Fed. Reg. 57651), and may not propose or issue a notice of proposed rulemaking for any revision to such rule except to extend its effective date, or for any other rule requiring the use of biometric readers for biometric transportation security cards under section 70105(k)(3) of title 46, United States Code, before the end of the 60-day period beginning on the date of the submission under paragraph (5) of section 1(b) of Public Law 114–278 (130 Stat. 1411 to 1412) of the results of the assessment required by that section.
SEC. 3. PROGRESS UPDATES.
Not later than 30 days after the date of the enactment of this Act, and every 90 days thereafter until the submission under paragraph (5) of section 1(b) of Public Law 114–278 (130 Stat. 1411 et seq.) of the results of the assessment required by that section, the Secretary of Homeland Security shall report to the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate regarding the implementation of that section.

Wednesday, July 12, 2017

Draft Navigation and Vessel Inspection Circular No. 05-17, Guidelines for Addressing Cyber Risks at Maritime Transportation Security Act (MTSA) Facilities

In the July 12, 2017 Federal Register, the Coast Guard posted the notice of the publication of Draft Navigation and Vessel Inspection Circular (NVIC) No. 05-17, Guidelines for Addressing Cyber Risks at Maritime Transportation Security Act (MTSA) Facilities.  The NVIC is available at  https://www.regulations.gov/document?D=USCG-2016-1084-0002. Comments must be submitted to the online docket via http://www.regulations.gov, or reach the Docket Management Facility, on or before September 11, 2017.

Facility Security Officers (FSOs) are advised that this is a draft NVIC, posted for review, to allow industry an opportunity to give feedback and commentary which the Coast Guard will evaluate and incorporate in the final version of the NVIC. This is a richly detailed performance standard on implementation of security measures to ward off the worst threat looming over us.

It is possible that Facility Security Plan sections 2, 3, 4, 5, 6, 8, 9, 10, 11, 12, 13, and 16 as well as the Facility Security Assessment may be affected by this NVIC. This is not a lengthy document (37 pages) so FSOs are encouraged to read it in its entirety. The amount of detail was difficult to summarize, especially Enclosure 2, and only the organization and main points are described below.
__________________________________________________________

SUMMARY OF THE NVIC (largely taken from the text. My words are in italics) The NVIC has two enclosures.
(1) Cyber Security and MTSA
(2) Cyber Governance and Cyber Risk Management Program Implementation Guidance

Purpose:  MTSA-regulated facilities are instructed to analyze vulnerabilities with computer systems and networks in their Facility Security Assessments. This NVIC will assist FSOs in completing this requirement. Additionally, this NVIC provides guidance and recommended practices for MTSA regulated facilities to address cyber related vulnerabilities. Until specific cyber risk management regulations are promulgated, facility operators may use this document as guidance to develop and implement measures and activities for effective self governance of cyber vulnerabilities.

Background: The Coast Guard currently has the regulatory authority to instruct facilities and Outer Continental Shelf (OCS) facilities regulated under MTSA to analyze computer systems and networks for potential vulnerabilities within their required FSA and, if necessary, FSP.

DISCLAIMER. This guidance is not a substitute for applicable legal requirements, nor is it itself a rule. It is not intended to nor does it impose legally binding requirements on any party. It represents the Coast Guard’s current thinking on this topic and may assist industry, mariners, the general public, and the Coast Guard, as well as other federal and state regulators, in applying statutory and regulatory requirements.

Enc. 1 Cyber Security and MTSA:  33 CFR Parts 105 and 106.

The Coast Guard interprets (threats) to specifically include threats to computer systems and attacks in the electronic (cyber) domain.

In this draft document, the Coast Guard is laying out its interpretation of regulatory provisions in parts 105 and 106 as applicable to electronic and cybersecurity systems. This enclosure discusses the specific regulatory provisions that instruct owners/operators of a Maritime Transportation Security Act (MTSA) regulated facility to address cyber/computer system security in the Facility Security Assessment (FSA) and, if applicable, provide guidance within their FSPs to address any vulnerabilities identified in the Facility Security Assessment (FSA). This document intends to assist the owner/operator in identifying cyber systems that are related to MTSA regulatory functions, or whose failure or exploitation could cause or contribute to a Transportation Security Incident. If there are electronic or cybersecurity-related vulnerabilities identified in an FSA, an owner/operator may choose to provide this information in a variety of formats, such as a stand-alone cyber annex to their FSP, or by incorporating cybersecurity procedures alongside the physical security measures of their FSP.

For facilities with strong cyber programs - In many cases, companies have established cybersecurity and risk management programs that provide for strong cyber defense. For those situations, the owner/operator may demonstrate that those policies meet or exceed the requirements of 33 CFR parts 105 and 106. Owners/operators that already employ a comprehensive cybersecurity plan for their organization, or who wish to apply a standard security program that incorporates cybersecurity to multiple facilities, may wish to submit a security plan under the Alternative Security Program, 33 CFR 101.120.

How detailed does the FSA or FSP need to be? Owners/operators do not need to indicate specific or technical controls, but should provide general documentation on how they are addressing their cyber risks.

Cyber components for 33 CFR:
Recommended Cyber Analysis as part of the FSA:  The NVIC gives information on how to provide the cyber component for 105.305 (d)(2)(v).

UnderRecommendation to Address Identified Cyber Vulnerabilities (as applicable)” the NVIC gives  general, recommended guidance on how to mitigate cyber vulnerabilities determined during the FSA by regulation/FSP section. I can see most facilities describing cyber measures for most of the sections, which will require FSP amendments. There is guidance here on what the Coast Guard wants to see in the FSP sections as relating to cyber. 

Enc. 2 Cyber Governance and Cyber Risk Management Program Implementation Guidance. The Coast Guard details how the NIST Cybersecurity Framework (CSF) can be implemented in the maritime environment. Sections 1 – 4 of this enclosure utilize the NIST CSF as the recommended foundation for development of a cyber risk management program. Facility owner/operators should consider these guidelines in conjunction with their own risk management policies to help ensure they account for cyber risks. The four sections of this enclosure are:
1.       Establishing Cyber Risk Management: Forming a Cyber Risk Management
       Team (CRMT), Defining Cyber Risk Management Policy, and Establishing a
       Cyber Risk Management Program
2.       Enterprise-Wide Inventory and Analysis
3.       Consequence Analysis, Vulnerability Analysis, and Prioritization
4.       Protect, Detect, Respond, and Recover.

These are the nuts and bolts of the cyber security measures, so to speak: how the USCG suggests that the NIST Framework can be translated over into the MTS. Each section is detailed and written in plain understandable English, unlike many cyber publications. Throughout these sections, where appropriate, the NVIC gives examples of suggested procedures to follow. There’s a lot of what-to-do and why-we-do-it. The 4.1 Protect Section is particularly rich with bulleted lists.


Appendix A contains tables and metrics - methods for measuring and scoring cyber vulnerability. Table 1 is a Consequence Evaluation Guide for vulnerability assessments, linking how bad it is to a number. Table 2 is a Consequence Score Action (document/consider/mitigate as relates to cyber, using the score from Table 1) matrix, for scoring scenarios for Facility Security Assessments. Table 3 is a Connective Vector Assessment and will assist operators in determining which systems perform or are related to these critical security and safety functions by examining the purposes and connections of each system. “Yes” responses from Table 3 are then evaluated using Table 4, the Cyber Infrastructure Vulnerability Assessment. Each system that receives a “no” in Table 4 should be evaluated through Table 5, the Vulnerability Severity Assessment, where it will receive a vulnerability score. Systems with the highest TOTAL score (at the bottom of Table 5) should be considered the most vulnerable.

Friday, June 2, 2017

New Information from MARAD About Maritime Security Communications with Industry

From the April meeting of the National Maritime Security Advisory Committee, new information from MARAD about maritime security communications with industry. Information about the new program can be found at  https://www.marad.dot.gov/environment-and-safety/office-of-security/msci/

From this website: The U.S. Maritime Administration has established a new interagency approach to communicating with U.S. maritime industry stakeholders regarding identified maritime security threats. The new system, U.S. Maritime Advisory System, replaces Special Warnings to Mariners (previously generated by the U.S. Department of State’s Office of Transportation Policy), MARAD Advisories (previously generated by the Department of Transportation’s Maritime Administration), and global maritime security focused Marine Safety Information Bulletins (previously generated by the Department of Homeland Security’s U.S. Coast Guard), to more effectively and efficiently communicate with U.S. maritime industry stakeholders and U.S. mariners regarding identified threats in the maritime domain.

Two new instruments will be issued through the System, U.S. Maritime Alerts and U.S. Maritime Advisories. The U.S. Maritime Alert is a new tool that has been developed to expeditiously provide basic information (location, incident type, and date/time) on reported maritime security threats to U.S. maritime industry interests.  In some situations, a U.S. Maritime Alert may be issued to refute unsubstantiated claims. U.S. Maritime Alerts do not contain policy or recommendations for specific courses of action (this type of information is reserved for U.S. Maritime Advisories). A U.S. Maritime Advisory may follow the issuance of a U.S. Maritime Alert and is intended to provide more detailed information, when appropriate, through a “whole-of-government” response to an identified maritime threat.

 Both instruments will normally be transmitted by the National Geospatial-Intelligence Agency, will be emailed to U.S. maritime industry stakeholders, and will be posted to this web portal to inform mariners of identified maritime security threats. Vessel Masters, Company Security Officers, ship operators, U.S. mariners, maritime industry associations, U.S. maritime unions and professional associations, and U.S. mariner related non-governmental organizations are the intended recipients of these messages. Maritime industry stakeholders wishing to be added to the email distribution list for U.S. Maritime Alerts and U.S. Maritime Advisories should email their request to MaradSecurity@dot.gov.

______________________________________________________________________


Please note: This blog always quotes heavily from the sources identified in the opening paragraph. I acknowledge that I should probably be using quotation marks and block indentation. Readers should assume that text is from the source and not original with the blog author unless otherwise stated.

Friday, June 12, 2015

TSA Posts Notice Regarding Resolution of Delays in Processing TWIC Cards, with Caveat

On June 12, 2015, the Transportation Security Administration posted the following notice at http://www.tsa.gov/stakeholders/transportation-worker-identification-credential-twic:

1) UPDATED! TWIC Processing Delays: The previously announced delay in processing some TWIC applications has been resolved.  Most applicants will receive a TWIC within a month of enrolling, and often in about two weeks.  However, despite progress in reducing processing delays for the small number of applicants whose criminal or immigration records indicate that they may not be eligible for a TWIC, those applicants may still experience a two-and-a-half month wait before receiving a TWIC or notification from TSA.
To ensure all eligible applicants receive a new or renewal TWIC before it is needed for work we continue to strongly encourage all applicants to apply for their TWIC at least 10 to 12 weeks prior to when the card will be required to avoid inconvenience or interruption in access to maritime facilities.

_______________________________________________________

Takeaways from this notice: applicants with anything in their background that might result in a application refusal on criminal history or immigration grounds may still experience a lengthy delay.  It remains to be seen if persons with clean backgrounds continue to experience lengthy delays.  Employers would be well-served to take TSA’s advice and assume that the application process will take 10 – 12 weeks.


The only way to find out if anything new has been posted on the TSA TWIC website is to check it daily.  At the bottom of the site is a revision date.  If this date has changed, new material has been added.  Do not rely on the NEW!  verbiage on notices because TSA does not remove this on a timely basis.

Tuesday, January 27, 2015

TSA Notice Concerning TWIC Card Delay

Today, January 27, 2015, the Transportation Security Adminstration posted the following notice on its website at http://www.tsa.gov/stakeholders/transportation-worker-identification-credential-twic

NEW!  TWIC Processing Delays: Currently, some TWIC applicants are experiencing delays of more than 75 days to receive their TWIC.  We regret any inconvenience or difficulty this may be causing, and are working diligently to reduce the time it takes to process all TWIC applications.  The delay mentioned above applies to applications that involve criminal history records or immigration status that must be verified, although others may also experience a delay.  We strongly encourage all applicants to apply for their TWIC at least 10 to 12 weeks prior to when the card will be required to avoid inconvenience or interruption in access to maritime facilities.

Monday, January 5, 2015

New TWIC Enrollment Requirements for U.S.-Born TWIC Applicants

Sometime over the holidays, TSA posted the following on the TSA TWIC website:

NEW!  NEW ENROLLMENT REQUIREMENTS FOR U.S.-BORN TWIC APPLICANTS:

Starting on July 1, 2015 Transportation Worker Identification Credential (TWIC®) applicants who were born in the United States, and who claim U.S. citizenship, must provide documents to prove their citizenship.  Applicants need to bring one document from List A, or two documents from List B as shown below.

Until July 1, 2015 TWIC applicants who were born in the U.S. may continue to certify that they are U.S. citizens by checking the box on the electronically signed TWIC application and bring documents as listed on the UES website here.

TSA is making this change to align TWIC proof-of-citizenship requirements with those of other TSA programs such as the Hazardous Material Endorsement and TSA Pre✓ programs.  Requiring proof of citizenship at the time of enrollment will ensure that all TWIC applicants meet eligibility requirements for the credential.

Acceptable Documentation Providing Proof of U.S. Citizenship

List A:  Bring one of the following:
• Unexpired U.S. Passport (book or card) – demonstrates U.S. Citizenship
• Unexpired U.S. Enhanced Driver’s License (EDL) – demonstrates U.S. Citizenship if indicated on card
• Unexpired Enhanced Tribal Card (ETC) – demonstrates U.S. Citizenship
• Unexpired Free and Secure Trade (FAST) Card – demonstrates U.S. Citizenship if indicated on the card
• Unexpired NEXUS Card – demonstrates U.S. Citizenship if indicated on the card
• Unexpired Secure Electronic Network for Travelers Rapid Inspection (SENTRI) Card -- demonstrates U.S. Citizenship if indicated on the card
• Unexpired Global Entry Card -- demonstrates U.S. Citizenship if indicated on the card

List B:  Or, bring one of the following plus a government-issued photo ID:
• Original or certified copy of birth certificate issued by a State, county, municipal authority, or outlying possession of the U.S. bearing an official seal
• U.S. Certificate of Citizenship (N-560 or 561)
• U.S. Certificate of Naturalization (N-550 or 570)
• U.S. Citizen Identification Card (I-179 or I-197)
• Consular Report of Birth Abroad (FS-240)
• Certification of Report of Birth (DS-1350)
• Certification of Birth Abroad (FS-545)
• Expired U.S. passport within 12 months of expiration*

*An expired U.S. passport may not be presented by itself. It must be presented with at least one other document (and a name change document if needed).