Showing posts with label AMSC. Show all posts
Showing posts with label AMSC. Show all posts

Tuesday, March 1, 2016

Summary of Coast Guard Office of Port and Facility Compliance (CG-FAC) 2015 Annual Report

On March 1, 2016, the Coast Guard Office of Port and Facility Compliance (CG-FAC) issued the 2015 Annual Report.  It can be found at http://www.uscg.mil/hq/cg5/cg544/docs/CG-FAC%20Year%20In%20Review%202015_Final.pdf. The MTSA community, especially Facility Security Officers, should read the entire report. Important points are summarized below, using portions of the report.

FSOs should pay particular attention to 2015 MTSA Facility Enforcement Actions and What’s Coming in 2016.

Strategy for the Waterside Security of Especially Hazardous Cargo
On 1 September 2015, the Commandant of the Coast Guard signed the "Strategy for the Waterside Security of Especially Hazardous Cargo."  It seeks to manage the risk of an attack on the Maritime Transportation System (MTS) involving EHC by mitigating the Threat, Vulnerability, and Consequence elements of risk through the Awareness, Prevention, Protection, Response, and Recovery components of the security spectrum. Security governance to facilitate and improve communication between industry and government on incident response/recovery, as well as maritime transportation infrastructure security, will be incorporated through an Implementation Plan.  CG-FAC is working an initial action plan with a 5 year execution.

Technology
USCG is deploying IPads to inspection corps who requested to be part of the program. This dramatically reduces large quantities of references and materials that inspectors need to carry around. Other devices which FAC recommends purchasing, at the unit’s expense, are a Bluetooth keyboard, portable Bluetooth printer, and Apps. The USCG would appreciate any feedback and recommendation for use of the iPads provided to the CG- Portal site. https://cg.portal.uscg.mil/units/cgfac2/iPads/SitePages/Home.aspx.

Port Security Specialist Program
The USCG has conducted a performance planning front end analysis (FEA) to determine Port Security Specialist and Security Specialist (Port / Recovery) performance requirements. Ten recommendations were identified during the FEA. Recommendations from this analysis will help optimize limited training resources and improve Port Security Specialist and Security Specialist (Port / Recovery) performance. A 2015 ALCOAST was issued providing an update to the PSS Program, defining roles and responsibilities of the PSS, and highlighting accomplishments.

Cybersecurity Assessment and Risk Management Approach (CARMA) Assessment in Philadelphia
During the week of June 8th, DHS Office of Sector Engagement Critical Infrastructure Resilience, in conjunction with the Coast Guard, led a cyber risk assessment in the Port of Philadelphia. Agencies involved were DHS, National Institute of Standards and Technology (NIST), Federal Energy Regulatory Commission (FERC), Customs and Border Protection (CBP), Transportation Security Administration (TSA), USCG Sector Del Bay, LANTAREA, CG-FAC, CG-CVC.

Coast Guard LNG Workgroup
Both Harvey-Gulf and TOTE have delivered vessels with LNG fueled engines, and the LNG workgroup worked closely with field units to interpret regulations and develop implementation strategies for these new facilities. CG-FAC chairs the LNG Workgroup, and during 2015 the work group facilitated the development and release of OES Policy letters 01-15 and 02-15 to, among other things, address gaps in 33 CFR 127 for LNG facilities that will bunker LNG. The report gives a link for USCG units to access the LNG Workgroup site in CG Portal (USCG restricted).

Alternative Security Program (ASP)
There are close to 200 facilities operating under ASPs and thousands of vessels, more than are using vessel-specific security plans. Since cyber-security is a topic of growing interest to the entire maritime industry the Coast Guard is exploring options for how to best incorporate cyber risks into security plans required by the Maritime Transportation Security Act. During the past year, two ASP Sponsoring Organization’s Workshops were held in Washington, DC. These workshops are a great forum for information sharing and discussions of best practices for both facilities and vessels. The workshop, held on November 18, 2015, provided an opportunity for in-depth discussions on cyber risks. Many industry groups are developing cyber security best practices and the Alternative Security Program potentially provides an ideal way of addressing cyber risks.

Cyber Risk Management
On 15 January 2015, CG-FAC held a public meeting to solicit input on a policy development project to address cyber security risks in the marine transportation system. In June 2015, the Commandant announced the promulgation of the Coast Guard’s first Cyber Strategy. This Strategy presents a ten-year vision for Coast Guard operations in cyberspace, and lays out our Service’s highest strategic objectives in this rap- idly evolving operational domain.

With the signing of the Cyber Strategy, CG-FAC became the lead office for implementing the Protect Infrastructure portion of the Strategy. The newly formed Protect Infrastructure Cyber Strategy Implementation Team (CSIT) had representatives from nearly every office within CG-5P and also representatives from other offices including CG-2, CG-6, and CG- 5R. Other offices outside of HQ have also pitched in, including National Maritime Center (NMC), Areas and Districts. The CSIT recently submitted an implementation plan and continues to work to complete identified initiatives. CG-FAC members were active in supporting Coast Guard wide research and development related to cyber risks in the marine transportation system.

Cyber Lexicon
CG-FAC, working within the Transportation System Sec- tor Cyber Security Working Group, assisted in developing a Common Cyber Language for the Transportation Sector. The language can be used to assist sub-sectors such as airlines or rail within the Transportation Sector have a common language when discussing cyber issues. The trail to this file in Homeport is Missions>Cybersecurity>Cyber Information> Transportation Sector Common Cyber Language.

Cybersecurity Assessment and Risk Management Approach (CARMA)
CARMA is a DHS developed tool that attempts to identify cyber risks within the port. It is a stakeholder-vetted list of the Port’s cyber infrastructure, as defined by its critical functions, supporting value chains, and specific types of cyber systems. What is important is that it utilizes local stakeholders to derive a port-level understanding of shared vulnerabilities and with it a prioritized list of strategies for managing the identified risks. This allows individual owners and operators to prioritize budget and resource allocations according to common risks. It also uses the identified cybersecurity risks to help build valid scenarios that could be leveraged for sector or national-level cyber exercises. Information on CARMA is accessed via email at ncsd_cipcs@hq.dhs.gov.

Cyber Risk Awareness and Policy Development
In 2015, the Coast Guard worked with the National Maritime Security Advisory Council, the National Offshore Safety Advisory Council, and many individual industry associations to share cyber information.

In June, the U.S. Coast Guard submitted a paper and introduced cyber risk management as a topic at the International Maritime Organization. Transport Canada has been a particularly strong partner in cyber. CG-FAC sent out 12 cyber related notices in 2015. A new resource section was also added to Homeport that shares over 100 different links to cyber related sites from advisories to alerts, assessment tools, recovery resources, supporting documents, tools, and training and education.

2015 Facility Inspections Program Statistics
Total regulated facilities:
8,211
MTSA-regulated facilities:
3,476
Total facility inspections completed:
11,856
MTSA facility inspections completed:
5,937
Total container inspections completed:
18,053
Total transfer monitors conducted:
456
Total operational controls (COTP Orders)
34
Security COTP Orders
16
Safety/Environmental Protection COTP Orders
19



2015 MTSA Security Compliance by District
District
FSPs*
MTSA Inspections
Deficiencies
1st
298
949
164
5th
166
451
129
7th
310
928
241
8th
905
1902
570
9th
304
691
120
11th
135
326
120
13th
139
257
106
14th
77
214
142
17th
98
219
27
Total
2432
5937
1619

Container Update
CG-FAC continuously seeks to improve the National Container Inspection Program (NCIP) guidance and streamline the process for both industry and the field. CG-FAC recently met with Hapag-Lloyd and the National Cargo Bureau to discuss industry and Coast Guard concerns and issues with the shipment of containers in an effort to identify ways to mitigate risks. Hapag-Lloyd has developed a system called “Watchdog”, that analyzes shipping documents searching for key words to assist in selecting containers for inspection. Watchdog has enabled Hapag-Lloyd to inspect 20% of all containers shipped by the company.

Mis-declared cargo and leakage are the most prominent issues ailing the shipment of containers and account for 86% of deficiencies according to the Cargo Incident Notification System website. According to the same website, over 70% of those deficiencies involve general cargo shipments, which point to the success of inspection programs focused on declared Hazardous Materials (HAZMAT).

Higher national compliance rates in declared HAZMAT shipments led to a shift for inspections rates of declared HAZMAT and general cargo container shipments. Previous guidance prioritized HAZMAT over general cargo shipments at a 90% to 10% inspection goal respectively. On average, of the total containers inspected nationally the Coast Guard has achieved roughly 60% to 40% HAZMAT to general cargo annually.

Transportation Worker Identification Credential (TWIC) Verifications
As part of the MTSA security program, Facility Inspectors conducted a combined 48,289 visual and electronic inspections of TWIC cards in 2015, and identified 970 instances of non-compliance with TWIC requirements.  CG-FAC is currently conducting market research for replacement readers; current hand-helds are reaching the end of their service life. There are currently a few USCG units conducting field testing for iPad based reader applications. 

USCG TWIC Implementation branch members worked directly with counterparts at TSA to discuss and address TWIC program improvements and issues. TSA has recently begun implementation of a civil enforcement program for individual TWIC holders violating regulatory requirements. Many Transportation Security Inspectors – Surface (TSI-S) personnel have reached out to Districts and Sectors to coordinate implementation of this inspection program.

2015 MTSA Facility Enforcement Actions
In 2015, the Coast Guard completed 4,717 security-related MTSA annual and spot check ex- aminations and recorded 131 enforcement activities against MTSA-regulated facility owners or operators for noncompliance with MTSA regulations.  The 131 enforcement activities executed in 2015 took place at 115 MTSA-regulated facilities and included official letters of warning or administrative civil penalties.


Citation


Citation Title
Enforcement Activities Executed
33 CFR 101.305
Reporting, Breach of Security
3
33 CFR 105.125
Noncompliance
3
33 CFR 105.140
Alternative Security Program
1
33 CFR 105.200
Owner or operator requirements
27
33 CFR 105.205
Facility Security Officer requirements
7
33 CFR 105.210
Facility personnel with security duties
13
33 CFR 105.220
Drill and exercise requirements
15
33 CFR 105.225
Facility recordkeeping requirements
4
33 CFR 105.255
Security measures for access control
29
33 CFR 105.260
Security measures for restricted areas
8
33 CFR 105.275
Security measures for monitoring
3
33 CFR 105.290
Additional cruise ship terminal requirements
2
33 CFR 105.305
Requirements for facility security assessments
1
33 CFR 105.400
Facility Security Plans
5
33 CFR 105.410
Facility Security Plans – Submission and approval
7
33 CFR 105.415
Facility Security Plans – Amendment and audit
3
Total
131

As noted on the previous page, as in 2014, almost 50% of Coast Guard enforcement actions at regulated facilities were for 33CFR105.200 and 105.255 violations.

Rulemakings
Seafarer’s Access to Maritime Facilities - On July 27, 2015, the public comment period for the Seafarer’s Access to Maritime Facilities Notice of Proposed Rulemaking (NPRM) officially closed. The 162 comments have been adjudicated and the Final Rule is being developed. This proposed rule would implement section 811 of the Coast Guard Authorization Act of 2010, and requires each owner or operator of a facility regulated by the Coast Guard to implement a system that provides seafarers and other individuals with access between vessels moored at the facility and the facility gate, in a timely manner and at no cost to the seafarer or other individual.

Consolidated Cruise Ship Security - On June 1, 2015, the public comment period for the Consolidated Cruise Ship Security Notice of Proposed Rulemaking (NPRM) officially closed. The 115 comments have been adjudicated and the Final Rule is being developed. The Coast Guard proposes to amend its regulations on cruise ship terminal security and the proposed regulations would provide detailed, flexible requirements for the screening of all baggage, personal items, and persons—including passengers, crew, and visitors—intended for carriage on a cruise ship. The proposed regulations would standardize security of cruise ship terminals and eliminate redundancies in the regulations that govern the security of cruise ship terminals.

Training
This year, CG-FAC traveled to each District to meet with a number of Facility Inspectors and Port Security Specialists during the FAC road show. Program staff covered certain topics specific to the Unit, District, or Area’s request.  Hot topics were LNG as Fuel, TWIC, MTSAII, and Cyber.

Area Maritime Security Committees
In April 2015, the Delaware Bay Area Maritime Security Committee was recognized as the 2014 Area Maritime Security Committee of the Year. This AMSC has developed a Regional Business Continuity Planning Template which was developed by taking an all hazards approach to include commercial risks. The template document serves as a readily implementable tool for use by Port Stakeholders in developing their own Business Continuity Plans. Widespread use of this template will lead to facilities better suited  to maintain critical business functions throughout our port and the nation, leading to a more  secure, resilient port and the ability to continue to contribute to the regional economy through unforeseen circumstances.

Trending Issues in Port Safety, Security, and Resilience
MTSRU - In order to build system continuity and maintain effective levels of program readiness, CG-FAC Senior Leadership developed and incorporated a strategy with the office business plan to host a National MTSRU Workshop every two years, to review and update program policies, guidance and analyze lessons learned from real events to improve response effectiveness and enhance program visibility.

Cooperation with Transport Canada - increased cooperation in 2016.

What to Expect in 2016
Facility Security - A policy letter encouraging facilities to submit their FSP/VSP/ASP renewals to the Coast Guard 60 days prior to the expiration date will be signed and disseminated to the field in CY16. Also, the Breach of Security Instruction has been updated to include suspicious activity response. The instruction will be published mid- 2016 and will address network security in addition to physical security incidents. Finally, be on the lookout for NVIC 03-03, Change 3 as well as an Alternative Security Plan NVIC in CY16.

EHC Strategy - CG-FAC will be working with other offices to create an Implementation Working Group for the EHC Strategy. This working group will look to implement the four goals of the EHC Strategy including awareness, prevention, response, and recovery.

Cyber - CG-FAC is working on several policy updates concerning cyber risk management. In cooperation with NIST, CG-FAC is drafting a Cyber Framework Implementation Guide for bulk liquid facilities. This will help facility operators identify the components of the NIST Cybersecurity Framework most applicable to their operations. CG-FAC is also developing a NVIC that will provide cyber risk management guidance to facility and vessel operators. CG-FAC will continue to support the Areas on conducting Cyber Awareness Training for CG Units.

Exercise requirements: CG-FAC is working on policy to clarify the definition for annual, and other time periods, as it is used in the 33 CFR 154 for exercise requirements.

Pipeline testing: CG-FAC is updating current policy and incorporating that into a pipeline testing policy NVIC that will guidance on alternate testing methods.

HOMEPORT— CG FAC is working with other Coast Guard Headquarters Offices to complete a long overdue technical refresh of Homeport.  This update will improve reliability and cyber security for the system and provide a better user interface.

Regulatory Projects:
Consolidated Cruise Ship Security - The public comment period for this NPRM ended on June 1, 2015. The anticipated final rule publication date is in 2016.

Seafarer’s Access to Maritime Facilities - The public comment period for this NPRM ended July 27, 2015. The anticipated final rule publication date is in 2016.

Transportation Worker Identification Credential (TWIC) Reader Requirements - The Final Rule is in final agency clearance.



Friday, January 29, 2016

Maritime Commons Reports on Texas AMSC Cyber Training: USCG Remarks

In the January 28, 2016 Coast Guard Maritime Commons, the Coast Guard reported on the South Texas Area Maritime Security Committee Maritime Awareness Security Terrorism Training Seminar focusing on Cybersecurity. Maritime Commons gave a digest of Sector Corpus Christi’s Commander and Chair of the Area Maritime Security Committee, Capt. Tony Hahn’s remarks. He referred to the importance of the Coast Guard’s Cyber Strategy and encouraged attendees to do the following:

  •         Incorporate cybersecurity into Area Maritime Security Committee risk assessments;
  •         Leverage grant funding to evaluate cyber risks;
  •         Create discreet venues to share cybersecurity information with maritime industry;
  •         Develop guidance for commercial vessels and facilities on how to identify and evaluate cyber-related vulnerabilities;
  •         Work with the International Maritime Organization to develop global maritime cyber prevention and response protocols;
  •         Incorporate cybersecurity into required training for vessel and security officers;
  •         Incorporate cybersecurity into requirements for Coast Guard issued mariner credentials


Monday, October 20, 2014

U. S, Coast Guard has Issued Marine Safety Information Bulletin 17- 14 dated October 17, 2014 Ebola Virus Precautions

The U. S, Coast Guard has issued Marine Safety Information Bulletin 17- 14 dated October 17, 2014 Ebola Virus Precautions – Update at  https://www.uscg.mil/msib/

“The purpose of this Bulletin is to provide an update to the maritime industry with respect to assessing Ebola risks and the responsibility of vessel/facility agents, owners, masters, operators, Area Maritime Security Committee members, and persons to immediately report potential communicable disease hazards to the United States Coast Guard (USCG) and the Centers for Disease Control and Prevention (CDC).”

The MSIB includes key points to remember concerning Ebola.

Tuesday, November 19, 2013

GAO Issues Report: Maritime Security: DHS Could Benefit from Tracking Progress in Implementing the Small Vessel Security Strategy


On November 19, 2013, the Government Accountability Office issued GAO Report 14-32, Maritime Security: DHS Could Benefit from Tracking Progress in Implementing the Small Vessel Security Strategy.  This report is of particular interest to us here at the University of Findlay because our course Small Vessel Security for Rural Communities was recently certified by DHS as AWR 311. The report can be found at http://www.gao.gov/products/GAO-14-32. Below are highlights from the report.

From the highlights:

Why GAO did this study: The Coast Guard estimates that there were more than 22 million small vessels operating in the United States in 2012. Terrorists, smugglers, and other criminals can use small vessels as platforms for their activities because small vessels are generally unregulated and largely anonymous. Law enforcement agencies face the challenge of distinguishing between legitimate small vessel operators and the relatively few individuals estimated to be engaged in illicit activities. DHS issued its SVSS in April 2008 and its follow-on SVSS Implementation Plan in January 2011 to help guide actions to mitigate the security risks arising from small vessels. Given the importance of small vessel security, GAO was asked to review DHS’s efforts in developing and implementing the SVSS Implementation Plan.

  
This report examines what actions, if any, DHS and its components have taken to address small vessel security concerns, and the extent to which they have implemented action items in the SVSS Implementation Plan. GAO analyzed DHS documents; interviewed DHS officials; and visited two ports selected on the basis of the volume of small vessel traffic and security initiatives in place, among other things. While the results of the port visits cannot be generalized across all ports, they provided insights on small vessel security issues and operations.

What GAO found: The Department of Homeland Security (DHS) and its components—such as the U.S. Coast Guard and Customs and Border Protection (CBP)—have started or completed initiatives to address small vessel security risks, but DHS is not tracking the progress being made to address action items in the Small Vessel Security Strategy (SVSS) Implementation Plan. “Small vessels” are characterized as any watercraft—regardless of method of propulsion—less than 300 gross tons, and used for recreational or commercial purposes. DHS component officials GAO met with identified examples of key initiatives that they have completed or have under way to enhance small vessel security, including an initiative to help CBP better track small vessels arriving from foreign locations and another to assist the Coast Guard in assessing and monitoring small vessel launch sites. Although the SVSS Implementation Plan states that DHS is to assess and update the plan, DHS has not determined the progress its components and other relevant stakeholders—such as the Department of Defense—are making in completing the action items and has no current plans to do so. DHS officials stated that this is due, in part, to budget constraints that make this a low priority. DHS officials stated that updating the SVSS Implementation Plan would be valuable, and doing so is particularly important since more than one component could be responsible for action items in the plan. Accordingly, by systematically gathering information from its components and other relevant stakeholders to regularly update the progress they are making in addressing the action items in the plan, DHS could help prioritize initiatives given constrained budgets and better identify successes and lessons learned, among other things.

What GAO recommends: GAO recommends that DHS regularly update the progress its components and other relevant stakeholders are making in addressing action items in the SVSS Implementation Plan. DHS concurred with the recommendation.

From the main body of the report:

DHS officials we spoke with stated that there is no plan to update the SVSS Implementation Plan because it is not a priority, given budget constraints, and it is too early to measure the effectiveness of action items in the plan. According to a senior DHS Policy official, although the SVSS Implementation Plan states that DHS should assess and update the plan annually, given these constraints, an annual review is too frequent. The senior DHS official added that per the Secretary of Homeland Security’s direction, DHS components are focusing on maintaining their ongoing operations under constrained budgets, and so efforts to update the SVSS Implementation Plan are not currently a priority…Coast Guard officials added that America’s Waterway Watch—a program highlighted in the SVSS Implementation Plan that provides outreach to the public, including the small vessel community, on awareness of threats and how to report suspicious activity—may not receive funding in DHS’s fiscal year 2014 appropriation…

DHS officials also stated that because the SVSS Implementation Plan was issued in early 2011, it is too early to expect a majority of the action items to be completed or, especially for the long-term action items, to have been implemented. These officials stated that accomplishing the SVSS’s goals and objectives through implementation of the many action items in the SVSS Implementation Plan will require a significant investment of time and resources, along with buy-in from state and local maritime security stakeholders. Accordingly, it could take years to fully implement some of the action items and determine whether they are effective…

Although it may be too early to measure the effectiveness of some action items in the SVSS Implementation Plan, updating the progress made in addressing the action items could help DHS and its components prioritize their efforts given constrained budgets; better identify successes and lessons learned; and enhance collaboration with federal, state, and local stakeholders regarding small vessel security issues. The SVSS Implementation Plan states that, because of risk, the unpredictability of budgets, policy changes, and administrative priorities, the plan must be reviewed regularly to ensure that it remains current and accurate. By engaging in this review process, the plan states that it is intended to be a living document that provides a strategic overview of participating agencies’ implementation of the SVSS. Standards for Internal Control in the Federal Government calls for federal agencies to design and implement control activities to enforce management’s directives.

Conclusions: Recognizing the risks posed by terrorists using small vessels to attack targets or as a conveyance for terrorists and their contraband to enter the United States, DHS issued its SVSS Implementation Plan in January 2011 to help guide efforts to mitigate the security risks arising from small vessels. DHS component agencies have completed some initiatives and have other initiatives under way to address the risk of a small vessel attack, but DHS is not gathering information on the progress its components or relevant stakeholders are making to address action items in the SVSS Implementation Plan and has no plans to do so. The SVSS Implementation Plan, by design, is to be revised to accommodate new information about threats, technologies, requirements, and lessons learned as action items are implemented, but DHS has not updated the plan since it was issued in 2011. Given that internal controls call for federal agencies to design and implement control activities to enforce management’s directives, DHS could better prioritize initiatives and identify successes if it was to regularly update the progress its components and other relevant stakeholders are making to address the action items in the SVSS Implementation Plan. This information could be particularly useful to DHS components that may be operating under more constrained budgets than when the plan was first issued.


Recommendation for Executive Action: To improve DHS’s ability to monitor progress, prioritize action items, and identify successes, we recommend that the Secretary of Homeland Security systematically gather information from the department’s components and other relevant stakeholders to regularly update the progress they are making in addressing action items in the SVSS Implementation Plan.