Showing posts with label USCG. Show all posts
Showing posts with label USCG. Show all posts

Monday, April 8, 2019

Coast Guard Office of Port and Facility Compliance Issues 2018 Year in Review


On May 05, 2019, Coast Guard Maritime Commons, the Coast Guard’s blog for maritime professionals, published a notice that the Office of Port and Facility Compliance (CG-FAC) has issued its Annual Review, available on the CG-FAC website. The Maritime Commons post is at https://mariners.coastguard.dodlive.mil/2019/04/05/4-5-2019-port-and-facility-compliance-annual-report-published/    The Year in Review report is at the bottom of the CG-FAC homepage at https://www.dco.uscg.mil/Our-Organization/Assistant-Commandant-for-Prevention-Policy-CG-5P/Inspections-Compliance-CG-5PC-/cgfac/

As stated in the document, “The mission of the Office of Port and Facility Compliance (CG-FAC) is to provide safety, security, and environmental stewardship for the nation’s ports and facilities.”[1] Cargo and container security, facility security, TWIC, cyber security, the Area Maritime Security Committees, and most of the Maritime Transportation Security Act of 2002 (MTSA) activities vital to Facility Security Officers are managed from this office. This is a short, very readable document. The very important activities of this Office in 2018 are presented in brief summaries. There are often links included to source documents.
Topics addressed in the report include:
  • ·      Highlights of 2018:
  • o   Marine Transportation System Recovery
  • o   Biennial Facility Inspector & Port Security Specialist Workshop
  • o   Committee for the Marine Transportation System (CMTS) Workshop
  • o   Common Assessment and Reporting Tool (CART)
  • o   Explosive Handling Supervisor Program Manual
  • o   Regulated Bulk Liquid Transfer Monitor Manual
  • o   API 570 Policy Letters
  • o   International Engagement
  • o   Arctic Work on Prevention of Pollution of the Marine Environment
  • o   Liquefied Natural Gas (LNG) Facility Support
  • o   Reporting of Inadequate Port Reception Facilities
  • o   Marine Information for Safety & Law Enforcement (MISLE) Enhancements
  • o   Policy Advisory Council (PAC) Document Registry
  • o   National Maritime Security Advisory Committee (NMSAC)
  • ·         Cyber Risk Management
  • ·         Unmanned Aerial Systems (UAS)
  • ·         2018 Statistics
  • ·         Container Updates
  • ·         Rulemakings
  • ·         Training
  • ·         Area Maritime Security Committees
  • ·         On the Horizon for 2019[2] 

While all of these topics are important, here are several that really caught my attention.

First of all, 2018 enforcement statistics:

From 2018 Year in Review

It’s no surprise that access control generates the most citations of the top five. Next in line comes owner/operator requirements, followed by drill and exercise requirements, then comes a tie between restricted area and reporting (breach of security). Facility inspectors across multiple Coast Guard Sectors have been stating that reporting is becoming an area of concern. This is confirmed here. Four out of the top 5 citations appeared in LCDR Jennifer Osburn’s excellent 2017, report, MTSA Effectiveness[3], which listed these violations, 1) Access Control, 2) Restricted Areas, 3) Drills & Exercises, 4)Owner/Operator Requirements, and 5) Audits & VSP/ASP Amendments (stating that they were not in order and were “common” and “typical”).

Cyber risk management:
While the draft Cyber NVIC is going through review, units are encouraged to engage in conversations with facility owners, operators, and security officers about facilities’ cybersecurity/cyber risk management programs and how to begin incorporating cyber into FSAs and FSPs. The Cyber NVIC itself is an awareness tool to inform industry of the requirement to include cyber and provides examples of how cyber might relate to cites within 33 CFR 105 and 106. The NVIC itself is not a template for a Facility Security Plan (FSP) update, addendum, or otherwise example, and therefore addressing cyber risks should not pend on its publication.[4]

Unmanned Aerial Systems (UAS)
There is an excellent discussion here of a best practice from Sector New Orleans, focusing on focus on tracking authorized UAS flights rather than trying to determine unauthorized flights.
In an effort to support this established novel practice, CG-FAC is working with the Coast Guard
Operations Systems Center (OSC) to develop a voluntary “Notice of UAS Operations” submissions tool on Homeport. The objective is to develop a communications network similar to New Orleans’. CG-FAC is also working on a policy letter to provide guidance on the procedure for reporting unauthorized UAS flights to include the FAA reporting guidelines.[5]

Rulemakings
This section contains an explanation of where we are (or are not) with the TWIC reader final rule. Congress forbad the USCG from implementing the rule or any similar rulemaking until an assessment of the TWIC program is reported to Congress. The RAND Corporation is performing this assessment.
Once completed (estimated June 2019 by HSOAC/RAND), the Coast Guard will review the
results of the assessment and move forward with the TWIC Reader Rule implementation
process, taking into consideration any changes resulting from the assessment, coordination with the Transportation Security Administration (TSA) and the Screening Coordination Office
(SCO), and any possible Congressional feedback concerning the assessment.[6]

Policy Advisory Council (PAC) Document Registry
PACs are “decision documents…that provide interpretation of regulations covered under the Maritime Transportation Security Act (MTSA) of 2002. PACs are a valuable tool for explaining maritime security regulations and aiding Coast Guard field units and the maritime industry.”[7] PACs were issued from 2003 to 2011. Since then, these documents may have been superseded or policy may have changed.  The Coast Guard reviewed all the PACS in 2017.
All active PACs were compiled into a single Adobe document that is indexed and keyword searchable. PACs deemed “no longer required” were rescinded and those incorporated into other policy documents were noted in the registry. The new registry was published on Feb 6, 2018, replacing the individual PAC files previously posted on Coast Guard’s Homeport website. The registry will be reviewed by CG-FAC-2 on an annual basis, where updates and changes will be tracked, noted in the registry, and communicated to port stakeholders through Homeport.[8]

On the Horizon for 2019
CG-FAC is working to address Coast Guard specific tasking within the recent FAA
Reauthorization Act, which directs the Coast Guard, in coordination with other stakeholders, to establish a cyber risk assessment model for the marine transportation system. This cyber risk assessment tool will follow the National Institute of Standards and Technology’s Cybersecurity Framework, similar to CG-FAC’s work on Cybersecurity Framework Profiles (CFP).[9]

What this section doesn’t mention: issuance of two NVIC updates, 03-03 CH-3 and 03-07 CH-1. NVIC 03-07 CH-1 may be waiting on the reader rule which means it is on the shelf depending on what Congress says about the Rand report. NVIC 03-03 CH-3 has been worked on for several years and should be ready to go?

Conclusion:
There is something for every MTSA stakeholder in this Office of Port and Facility Compliance 2018 Year in Review. FSOs are urged to read the entire report.





[1] U.S. Department of Homeland Security. United States Coast Guard. Office of Port & Facility Compliance. https://www.dco.uscg.mil/Our-Organization/Assistant-Commandant-for-Prevention-Policy-CG-5P/Inspections-Compliance-CG-5PC-/cgfac/
[2] U.S. Department of Homeland Security. United States Coast Guard. Office of Port and Facility Compliance.
2018 Annual Report. 2019.  https://www.dco.uscg.mil/Portals/9/CG-FAC/Documents/Year%20in%20Review/YearInReview2018.pdf?ver=2019-04-03-153641-730
[3]Osburn, Jennifer. Maritime Transportation Security Act of 2002 (MTSA) Effectiveness. 2017. https://www.dco.uscg.mil/Portals/9/CG-FAC/Documents/MTSA%20Effectiveness.pdf?ver=2017-07-19-070242-347
[4] U.S. Department of Homeland Security. United States Coast Guard. Office of Port and Facility Compliance.
2018 Annual Report. 2019.  https://www.dco.uscg.mil/Portals/9/CG-FAC/Documents/Year%20in%20Review/YearInReview2018.pdf?ver=2019-04-03-153641-730
[5] Ibid.
[6] Ibid.
[7] Ibid.
[8] Ibid.
[9] Ibid.

Wednesday, October 15, 2014

Truncated Last Name on TWIC Card: Names Limited to 19 Characters

Recently, TSA posted the following information of concern to persons with lengthy last names, at http://www.tsa.gov/stakeholders/transportation-worker-identification-credential-twic. (TSA does not date the bulletins on its website so I am unable to state the exact date of this posting.)

Truncated Last Name on TWIC Card: Since TSA began issuing the new version 2.03 TWIC® cards in May 2014, only the first 14 characters (including spaces, hyphens, and apostrophes) of the applicant’s last name are printed on the card.  The last name is always followed by a comma.  If a person’s last name exceeds 14 characters, all after the 14th character are not printed, and a comma follows immediately after the 14th character.  This has caused some Transportation Workers to have their credentials questioned at facilities because the name on the card does not match the person’s full name.


On October 17, 2014, a system change will be made to extend the last name as printed on the TWIC® to a maximum of nineteen (19) characters, followed immediately by a comma.  Last names containing fewer than 19 characters will continue to be followed immediately by a comma.  TSA is looking into ways to include full last names, regardless of the number of characters, given the limited space available on the card for printing.  Until a satisfactory solution is developed and implemented, the last name printed on TWICs® beginning October 17, 2014 will be limited to the first 19 characters of the last name.

Friday, May 24, 2013

TSA issues notices about affects of contractor change-over: mobile enrollment and EYO, center hours



The Transportation Security Administration has issued two notices about the change-over from contractor Lockheed Martin to contractor MorphoTrust. This changeover will affect  mobile enrollment and Enroll Your Own (EYO) arrangements and enrollment center availability and hours.  Both notices are reproduced below.

 UPDATED 05/23/2013: Transportation Worker Identification Credential (TWIC) – Mobile Enrollment and Activation Services TSA has been contacted by a number of stakeholders interested in establishing mobile enrollment and activation services at their facilities. TSA understands the flexibility that mobile enrollment and activation services provide, not only for TWIC renewals but for Extended Expiration Date (EED) TWICs.

 TSA has been contacted by a number of stakeholders interested in establishing mobile enrollment and activation services at their facilities. TSA understands the flexibility that mobile enrollment and activation services provide, not only for TWIC renewals but for Extended Expiration Date (EED) TWICs.

In April 2013, TWIC enrollment services began transitioning to a new contractor, MorphoTrust, under a Universal Enrollment Services (UES) contract. The UES contract includes enhanced mobile enrollment services, Enroll Your Own (EYO), and bulk payment arrangements.
Mobile enrollment services include the following options below:
 Mobile Enrollment Only – Mobile enrollment service without a mobile activation service
 Mobile Enrollment Plus Activation - Mobile enrollment and corresponding activation service
 Extended Expiration Date (EED) Bulk Order/Activation - Mobile service available via bulk orders, which includes the mobile activation service

MorphoTrust is now accepting orders for these services and will begin service in mid-summer 2013. Please submit mobile enrollment requests to Win Noble, MorphoTrust UES Communications Manager, at wnoble@morphotrust.com
Further details about mobile enrollment services and EYO capabilities will be available on the UES website – https://universalenroll.dhs.gov/ 

Please note that Lockheed Martin’s capacity to provide mobile enrollment and activation capability has been filled through the end of their contract. Please consider alternate plans such as utilizing fixed enrollment centers or requesting mobile services after completion of the UES transition (scheduled for end of June 2013). 

(Available at http://www.tsa.gov/sites/default/files/publications/pdf/twic/mobile_enrollment_and_activation_05_23_2013.pdf)

_____________________________________________________________

TWIC Stakeholders:  
The following TWIC enrollment centers will be closed on the date noted in an effort to assist their transition to a new enrollment provider as part of the Transportation Security Administration (TSA) Universal Enrollment Services (UES) initiative.  

As enrollment centers transition, their individual web pages will be updated to reflect any new logistics (e.g., location updates, new hours of operation, payment details, etc.).  Current information on enrollment centers can be found at:   
Below is a schedule of enrollment centers for the week of May 27-31, 2013, in which a Center will need to be closed on a given date to assist its transition.  Please note that during the week a site is transitioning, appointments will be blocked and the site will likely be busier than usual.  For appointments following a site’s transition, applicants can call the UES Call Center at 1-855 DHS-UES1 (1-855-347-8371), Monday through Friday: 8:00 AM - 10:00 PM EST.

Enrollment Center
Date Closed for UES Transition (Wk. of May 27-May 31)
American Samoa
05/28/13
Cedar Rapids, IA
05/29/13
Eureka, CA
05/29/13
La Plata, MD
05/29/13
Longview, WA
05/29/13
Pasco, WA
05/29/13
Port Fourchon, LA
05/28/13
Portland, ME
05/28/13
Providence, RI
05/28/13
Traverse City, MI
05/29/13

*Note: Following a site’s effective transition closure date above, check or money order payments for enrollments should be made payable to 'MorphoTrust USA', check or money order payments for card replacements and Extended Expiration Date (EED) services should be made payable to 'Lockheed Martin'.  For additional information and updates on the TWIC program, please visit http://www.twicinformation.com/twicinfo/.  

(From TWIC Stakeholder communications email)





Friday, March 22, 2013

More from TWIC Reader Notice of Proposed Rulemaking



Will there be a different requirement for TWIC reader use at elevated MARSEC Levels for Risk Group A?

The Coast Guard recognizes that the system of MARSEC Levels creates a useful mechanism for the Coast Guard to elevate security requirements at times of heightened risk. Nonetheless, the Coast Guard uses this mechanism in a targeted manner, and at this time, the Coast Guard does not believe that elevated TWIC reader requirements at higher MARSEC Levels are generally practical or appropriate. In considering the comments above, the Coast Guard notes the change that it has made from the ANPRM to this NPRM with respect to TWIC reader requirements. In the NPRM, the Coast Guard proposed TWIC reader requirements for Risk Groups A and B, with stricter TWIC reader requirements for both risk groups at higher MARSEC Levels. The ANPRM’s stricter TWIC reader requirements would have primarily affected Risk Group B because the ANPRM proposed routine biometric scanning with a TWIC reader for Risk Group A at all MARSEC Levels. For example, the ANPRM would have required Risk Group B to use TWIC readers at MARSEC Level 1 for card authentication (i.e., no routine biometric scan) and once-monthly biometric identity verification. The ANPRM, however, would have only required Risk Group B to regularly use TWIC readers for biometric identity verification at higher MARSEC Levels. In this NPRM, the Coast Guard has eliminated the proposed TWIC reader requirements for Risk Group B. The requirements for routine biometric scanning with a TWIC reader for Risk Group A remain the same as in the ANPRM. Note that the Coast Guard proposes increased requirements at higher MARSEC Levels to the extent that the NPRM would require Risk Group A to perform daily updates of CCL information at higher MARSEC Levels, instead of the weekly updates required at MARSEC Level 1.

What types of readers may be utilized?

The Department of Commerce’s National Institute of Standards and Technology (NIST) and TSA are developing TWIC reader specifications. TSA will establish a process to qualify TWIC readers, and will maintain a Qualified Technology List (QTL) of acceptable TWIC readers. The Coast Guard anticipates that there may be changes from the ICE Test list to the QTL list, based on final TWIC reader specifications resulting from the QTL process.

A list of TWIC readers that have passed the Initial Capability Evaluation (ICE) Test is available at http://www.tsa.gov/assets/pdf/twic_ice_list.pdf. As stated in PAC–D 01–11, however, TWIC readers allowed pursuant to PAC–D 01–11 may no longer be valid after promulgation of a TWIC reader final rule, and DHS will not fund replacement TWIC readers.

TSA is developing the QTL so that approved readers meet durability standards. Additionally, in this NPRM, we’re proposing requirements that provide owners and operators the flexibility to choose the TWIC reader that best suits their operational needs.

Section 101.105, Definitions.TWIC reader means an electronic device listed on TSA’s Qualified Technology List (QTL) and used to verify and validate: the authenticity of a TWIC; the identity of the TWIC-holder as the legitimate bearer of the credential; that the TWIC is not expired; and that the TWIC is not on the CCL. TSA’s QTL of acceptable TWIC readers may be accessed online at http://(TBD).