Showing posts with label VSO. Show all posts
Showing posts with label VSO. Show all posts

Monday, November 30, 2015

Big Changes Coming Soon to Coast Guard's Homeport Website

On November 27, 2015, the Coast Guard made an announcement concerning its Homeport website via Maritime Commons (http://mariners.coastguard.dodlive.mil/2015/11/27/11272015-homeport-2-0-news-and-information/ ). The information is also posted on the Homeport website, http://homeport.uscg.mil .
We have been hearing for quite a while about upcoming changes to Homeport – these changes are happening and happening soon. Below is the text of the announcement from the Homeport/CG-FAC website:
The United States Coast Guard (USCG) Homeport Internet Portal (HIP) was established in 2005 to facilitate compliance with the requirements set forth in the Maritime Transportation Security Act (MTSA) of 2002, by providing secure information dissemination, advanced collaboration, electronic submission and approval for vessel and facility security plans, and complex electronic and telecommunication notification capabilities.
Since its inception, HIP has been expanded to provide additional support such as Transportation Worker Identification Card New Hire; Electronic Vessel Response Plan; Marine Event Permit Process; Port Status Indicator; Merchant Mariner Licensing and Documentation; Marine Training and Assessment Data (training documentation); Merchant Mariner Certificate; Sea Service Calculator; Merchant Mariner Verification of Certificates; and Merchant Mariner Credential Survey
The Coast Guard will launch Homeport 2.0 Jan. 29, 2016 in order to provide a better user experience and improve the security of user information. Upgrades will include fewer site navigation menus and more efficient and secure search functions.
Although most features will be available as soon as the new site launches, user access to a few conveniences may be interrupted. Review the Homeport 2.0 Deployment Schedule for details. Functions that are essential to maintaining port security or that are critical to continuing the flow of commerce will remain available during the transition period.
Alternative solutions are available for most features taken offline during the transition. Anyone who needs access to a service normally obtained through HIP should contact the appropriate subject matter expert listed in the Homeport 2.0 Deployment Schedule.
From the Deployment Schedule:
Uninterrupted services:
 · TWIC new hire procedures
· Port status query
 · Merchant Mariner Application Status
· VRP Express
· Vessels & facilities search
· Merchant Mariner Credential Verification
· Merchant Mariner Sea Service Calculator
· Most core CG accessible-only functions
Services unavailable Jan. 29 - March 31, 2016
· Mariner Training & Assessment Database
 · Security Plans Temporary
· Merchant Mariner Credential Survey
 Services unavailable Jan. 29 - April 30, 2016
 · Merchant Mariner Certificate
· Marine Event Application Temporary

The FAQ document (http://www.uscg.mil/hq/cg5/cg544/docs/Homeport_2%200_FAQs_AllUsers1%201.pdf) lists work-arounds for most unavailable services in a Deployment Schedule (http://www.uscg.mil/hq/cg5/cg544/docs/Homeport%20Application%20Deployment%20Schedule.pdf ). There is a separate FAQ document (http://www.uscg.mil/hq/cg5/cg544/docs/Homeport_2%200_FAQs_CommunityOwners1%201.pdf ) for community owners, who need to pay careful attention to deadlines. The deadline for migrating community content is January 29, 2016.  This is a hard deadline. “Legacy Homeport will be taken offline as of Jan. 29, 2016, and community owners should make all efforts to meet this deadline. Any content that is not transferred will be auto-archived and will not be easily accessible.”

Thursday, December 18, 2014

Coast Guard Publishes Request for Comments on How to Identify Vulnerabilities to Cyber-Dependent Systems

In today's Federal Register, the Coast Guard published a notice, requesting public input from the maritime industry and other interested parties on how to identify and mitigate potential vulnerabilities to cyber-dependent systems. Information on how to comment is included in the notice.  The text of the notice can be found at http://www.gpo.gov/fdsys/pkg/FR-2014-12-18/pdf/2014-29658.pdf. The text of the notice is reprinted below.Two things should be abundantly clear to all maritime security stakeholders. #1, the Coast Guard is very serious about listening to our voice on this issue. #2, the Coast Guard takes the issue of cyber security vulnerability very seriously and has moved it up the queue of security worries. If we don't participate in this process (help drive the train) we may find ourselves being the subject of a regulatory process that could have been managed another way (grit beneath the wheels).
________________________________________________________

Coast Guard

[Docket No. USCG–2014–1020]

Guidance on Maritime Cybersecurity Standards

AGENCY: Coast Guard, DHS.

ACTION: Notice with request for comments.

SUMMARY: The Coast Guard is developing policy to help vessel and facility operators identify and address cyber-related vulnerabilities that could contribute to a Transportation Security Incident. Coast Guard regulations require certain vessel and facility operators to conduct security assessments, and to develop security plans that address vulnerabilities identified by the security assessment. The Coast Guard is seeking public input from the maritime industry and other interested parties on how to identify and mitigate potential vulnerabilities to cyber-dependent systems. The Coast Guard will consider these public comments in developing relevant guidance, which may include standards, guidelines, and best practices to protect maritime critical infrastructure.
DATES: Comments must be submitted to the online docket via http://www.regulations.gov, or reach the Docket Management Facility, on or before February 17, 2015.
ADDRESSES: Submit comments using one of the listed methods, and see SUPPLEMENTARY  INFORMATION for more information on public comments.
• Online—http://www.regulations.gov following Web site instructions.
• Fax—202–493–2251.
• Mail or hand deliver—Docket Management Facility (M–30), U.S. Department of Transportation, West Building Ground Floor, Room W12–140, 1200 New Jersey Avenue SE., Washington, DC 20590–0001. Hours for hand delivery are 9 a.m. to 5 p.m., Monday through Friday, except Federal holidays (telephone 202–366–9329).
FOR FURTHER INFORMATION CONTACT: For information about this document call or email LT Josephine Long, Coast Guard; telephone 202–372–1109, email Josephine.A.Long@uscg.mil or LCDR Joshua Rose, Coast Guard; 202–372–1106, email Joshua.D.Rose@uscg.mil.
For information about viewing or submitting material to the docket, call Cheryl Collins, Program Manager, Docket Operations, telephone 202–366–9826, toll free 1–800–647–5527.
SUPPLEMENTARY INFORMATION:
Public Participation and Comments
We encourage you to submit comments (or related material) on the questions listed below. We will consider all submissions and may adjust our final policy actions based on your comments.
Comments should be marked with docket number USCG–2014–1020, and should provide a reason for each suggestion or recommendation. You should provide personal contact information so that we can contact you if we have questions regarding your comments; but please note that all comments will be posted to the online docket without change and that any personal information you include can be searchable online (see the Federal Register Privacy Act notice regarding our public dockets, 73 FR 3316, Jan. 17, 2008).
Mailed or hand-delivered comments should be in an unbound 81⁄2 x 11 inch format suitable for reproduction. The Docket Management Facility will acknowledge receipt of mailed comments if you enclose a stamped, self-addressed postcard or envelope with your submission.
Documents mentioned in this notice, and all public comments, are in our online docket at http://
www.regulations.gov and can be viewed by following the Web site’s instructions.
You can also view the docket at the Docket Management Facility (see the mailing address under ADDRESSES) between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays.
Discussion
The Coast Guard is developing policy to help vessel and facility operators identify and address cyber-related vulnerabilities that could contribute to a Transportation Security Incident (TSI).1 Coast Guard regulations require certain vessel and facility operators to conduct security assessments, and to develop security plans that address vulnerabilities identified by the security assessment.2 Vessel and facility security plans must also address specific security functions, including the following:
• Communications
• Security Training Requirements
• Procedures for vessel/facility interfacing
• Declaration of Security
• Security Systems and Equipment Maintenance
• Security Measures for Access Control
• Security Measures for Handling Cargo
• Security Measures for Monitoring
• Security Incident Procedures
The Coast Guard is seeking public input on the following questions:
(1) What cyber-dependent systems, commonly used in the maritime industry, could lead or contribute to a TSI if they failed, or were exploited by an adversary?
(2) What procedures or standards do vessel and facility operators now employ to identify potential cybersecurity vulnerabilities to their operations?
(3) Are there existing cybersecurity assurance programs in use by industry that the Coast Guard could recognize? If so, to what extent do these programs address vessel or facility systems that could lead to a TSI?
(4) To what extent do current security training programs for vessel and facility personnel address cybersecurity risks and best practices?
(5) What factors should determine when manual backups or other nontechnical approaches are sufficient toaddress cybersecurity vulnerabilities?
(6) How can the Coast Guard leverage Alternative Security Programs 3 to help vessel and facility operators address cybersecurity risks?
(7) How can vessel and facility operators reliably demonstrate to the Coast Guard that critical cyber-systems meet appropriate technical or procedural standards?
(8) Do classification societies, protection and indemnity clubs, or insurers recognize cybersecurity best practices that could help the maritime industry and the Coast Guard address cybersecurity risks? (See also http://www.dhs.gov/publication/cybersecurityinsurance.)
Authority
This notice is issued under the authority of 5 U.S.C. 552(a).
Dated: December 12, 2014.
Captain Andrew Tucci,
Chief, Office of Port & Facility Compliance, U.S. Coast Guard.
[FR Doc. 2014–29658 Filed 12–17–14; 8:45 am]
1 A Transportation Security Incident is defined in 33 CFR 101.105 to mean ‘‘a security incident resulting in a significant loss of life, environmental damage, transportation system disruption, or economic disruption in a particular area.’’
2 33 CFR parts 104 and 105, subparts C and D.
3 An Alternative Security Program is defined in 33 CFR 101.105 to mean ‘‘a third-party or industry organization developed standard that the Commandant [of the Coast Guard] has determined provides an equivalent level of security to that established by [33 CFR Chapter I, Subchapter H].’’


Monday, December 15, 2014

Jan. 15 2015 USCG Public Meeting In Washington DC to Receive Comments on the Development of Cybersecurity Assessment Methods for Vessels and Facilities Regulated by the Coast Guard

On Friday, December 12, 2014, the United Stated Coast Guard posted a notice of a January 15 2015 public meeting in Washington DC to receive comments on the development of cybersecurity assessment methods for vessels and facilities regulated by the Coast Guard. The docket number for submitting comments prior to this meeting is USCG-2014-1020.  Comments may be submitted both before and after the meeting.  There are several deadlines for persons interested in participating.  For attendance in person, the Coast Guard advises that seating is limited and should be reserved by the method specified in the notice NLT January 05, 2014. There will be a live video feed of the meeting.  To access the video feed, the request must be made by the means specified in the notice NLT January 13, 2015. Persons who wish to attend the meeting in person are advised of transportation and identification requirements.

My memory may be failing me but it seems to me like the last time I tried to access this building (Department of Transportation Headquarters building) two government-issued photo IDs were required, not one, as the notice specifies.  Below is the text of the notice from regulations.gov.  The supplemental documents referenced in the notice have not been posted as of noon 12/15/14.

Action

Notice of public meeting and request for comments.

Summary

The U.S. Coast Guard announces a public meeting to be held in Washington, DC, to receive comments on the development of cybersecurity assessment methods for vessels and facilities regulated by the Coast Guard. This meeting will provide an opportunity for the public to comment on development of security assessment methods that assist vessel and facility owners and operators identify and address cybersecurity vulnerabilities that could cause or contribute to a Transportation Security Incident. The Coast Guard will consider these public comments in developing relevant guidance, which may include standards, guidelines, and best practices to protect maritime critical infrastructure.

Dates

The meeting will be held on Thursday, January 15, 2015 from 9:00 a.m. to 12:00 p.m. The deadline to reserve a seat is Monday, January 5, 2015. All written comments and related material must either be submitted to the online docket via http://www.regulations.gov on or before January 29, 2015 or reach the Docket Management Facility by that date.

Addresses

The public meeting will be held at the Department of Transportation Headquarters, Oklahoma Room, 1200 New Jersey Avenue SE., Washington, DC 20590; the building telephone number is 202-366-1035. The building is accessible by taxi, public transit, and privately-owned conveyance. However, public parking in the vicinity of the building is extremely limited. Meeting participants are encouraged to use mass transit.
Seating is limited, so please reserve a seat as soon as possible, but no later than January 5, 2015. To reserve a seat, please email Josephine.A.Long@uscg.mil with the participant's first and last name for all U.S. Citizens, and additionally, official title, date of birth, country of citizenship, and passport number with expiration date for non-U.S. Citizens. To gain entrance to the Department of Transportation Headquarters building, all meeting participants must present government-issued photo identification (e.g., state-issued driver's license). If a visitor does not have a photo ID, that person will not be permitted to enter the facility. All visitors and any items brought into the facility will be required to go through security screening each time they enter the building.

The Coast Guard will provide a live video feed of the meeting. To access the video feed, email a request to LT Josephine Long at Josephine.A.Long@uscg.mil no later than January 13, 2015.

The docket for this notice is available for inspection or copying at the Docket Management Facility (M-30, U.S. Department of Transportation, West Building Ground Floor, Room W12-140, 1200 New Jersey Avenue SE., Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays. You may also find this docket on the Internet by going to http://www.regulations.gov, entering USCG-2014-1020 in the search box and following the instructions.

Written comments may also be submitted in response to this notice. All written comments and related material submitted before or after the meeting must either be submitted to the online docket via http://www.regulations.gov on or before January 29, 2015 or reach the Docket Management Facility by that date. You may submit written comments identified by docket number USCG-2014-1020 before or after the meeting using any one of the following methods:
(1) Federal eRulemaking Portal: http://www.regulations.gov.
(2) Fax: 202-372-1990.
(3) Mail: Docket Management Facility (M-30), U.S. Department of Transportation, West Building Ground Floor, Room W12-140, 1200 New Jersey Avenue SE., Washington, DC 20590-0001.
(4) Hand delivery: Same as mail address above, between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays. The telephone number is 202-366-9329.
To avoid duplication, please use only one of these four methods.

The Coast Guard will post a video recording and written summary of the meeting to the docket.

For Further Information Contact

If there are questions concerning this meeting, please call or email LT Josephine Long, Coast Guard at 202-372-1109 or via email at Josephine.A.Long@uscg.mil or LCDR Joshua Rose, Coast Guard; at 202-372-1106 or via email at Joshua.D.Rose@uscg.mil. If there are questions on viewing or submitting material to the docket, call Ms. Cheryl Collins, Program Manager, Docket Operations, telephone 202-366-9826.

Supplementary Information

Background and Purpose

On February 12, 2013, the President signed Executive Order (E.O.) 13636 “Improving Critical Infrastructure Cybersecurity.” The E.O. provided the national approach to protecting critical infrastructure cybersecurity and directed federal agencies to assess cyber risk to critical infrastructure. Pursuant to E.O. 13636, the National Institute of Standards and Technology (NIST) developed a voluntary Preliminary Cybersecurity Framework, (1) followed by the February 12, 2014 publication of a Framework for Improving Critical Infrastructure Cybersecurity (2) (Cybersecurity Framework). The Cybersecurity Framework serves to help industry stakeholders reduce their cyber risk and vulnerabilities. The Coast Guard encourages vessel and facility owners and operators to adopt the Cybersecurity Framework voluntarily to achieve a minimum standard of cybersecurity protection.
Section 7(d) of E.O. 13636 states that in developing the Cybersecurity Framework, the Director of NIST “shall engage in an open public review and comment process” and consult with stakeholders including owners and operators of critical infrastructure. Similarly, the Coast Guard will host this public meeting to engage the public and obtain comments to assist in the drafting of procedures to enable operators of vessels and facilities regulated pursuant to the Maritime Transportation Security Act of 2002 (MTSA) to identify and address cybersecurity risks that could result in a Transportation Security Incident (TSI). (3) This may include standards, guidelines, and best practices to protect maritime critical infrastructure. 

The meeting will include the following topics:

(1) Identify: What cyber dependent systems perform vital functions that are addressed in MTSA requirements, such as access control, cargo control, and communications?
(2) Protect: What standards are suitable to ensure the integrity of these systems?
(3) Detect: What procedures are available to owners and operators to detect cyber intrusions that could compromise the integrity of vital systems or contribute to a TSI?
(4) Respond: What response and notification procedures can minimize the consequences of cyber events?
(5) Recover: What procedures can owners and operators take to promote rapid maritime transportation system recovery after a cyber incident?

In addition to the topics outlined above, the Coast Guard is posting several supplemental documents to the online docket for this notice. The supplemental documents provide additional background information that may be useful for the public to consider in formulating comments. We encourage individuals interested in participating in the public meeting and/or submitting comments to the docket to review the supplemental documents. To view the supplemental documents and other documents mentioned in this notice as available in the docket, please follow the instructions described above in the ADDRESSES section. If you do not have access to the Internet, you may view the docket online by visiting the Docket Management Facility in Room W12-140 on the ground floor of the Department of Transportation West Building, 1200 New Jersey Avenue SE., Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays. The Coast Guard has an agreement with the Department of Transportation to use the Docket Management Facility.

The Coast Guard encourages the public to participate by submitting comments either in person at the meeting or in writing. The public may submit written comments to Coast Guard personnel at the meeting. The Coast Guard will post these comments to the online public docket. All comments received will be posted without change to http://www.regulations.gov and will include any personal information you have provided.

Privacy Act

Anyone can search the electronic form of comments received into any of the dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). There is a Privacy Act notice regarding the public dockets for review in the January 17, 2008, issue of the Federal Register(73 FR 3316).

Information on Services for Individuals With Disabilities

For information on facilities or services for individuals with disabilities or to request special assistance at the public meeting, contact LT Josephine Long at the telephone number or email address indicated under the FOR FURTHER INFORMATION CONTACT section of this notice.

Authority
This notice is issued under the authority of 5 U.S.C. 552(a).
Dated: December 3, 2014.
Andrew Tucci,
Chief, Office of Port & Facility Compliance, U.S. Coast Guard.
[FR Doc. 2014-29205 Filed 12-11-14; 8:45 am]

BILLING CODE 9110-04-P