Tuesday, March 1, 2016

Summary of Coast Guard Office of Port and Facility Compliance (CG-FAC) 2015 Annual Report

On March 1, 2016, the Coast Guard Office of Port and Facility Compliance (CG-FAC) issued the 2015 Annual Report.  It can be found at http://www.uscg.mil/hq/cg5/cg544/docs/CG-FAC%20Year%20In%20Review%202015_Final.pdf. The MTSA community, especially Facility Security Officers, should read the entire report. Important points are summarized below, using portions of the report.

FSOs should pay particular attention to 2015 MTSA Facility Enforcement Actions and What’s Coming in 2016.

Strategy for the Waterside Security of Especially Hazardous Cargo
On 1 September 2015, the Commandant of the Coast Guard signed the "Strategy for the Waterside Security of Especially Hazardous Cargo."  It seeks to manage the risk of an attack on the Maritime Transportation System (MTS) involving EHC by mitigating the Threat, Vulnerability, and Consequence elements of risk through the Awareness, Prevention, Protection, Response, and Recovery components of the security spectrum. Security governance to facilitate and improve communication between industry and government on incident response/recovery, as well as maritime transportation infrastructure security, will be incorporated through an Implementation Plan.  CG-FAC is working an initial action plan with a 5 year execution.

Technology
USCG is deploying IPads to inspection corps who requested to be part of the program. This dramatically reduces large quantities of references and materials that inspectors need to carry around. Other devices which FAC recommends purchasing, at the unit’s expense, are a Bluetooth keyboard, portable Bluetooth printer, and Apps. The USCG would appreciate any feedback and recommendation for use of the iPads provided to the CG- Portal site. https://cg.portal.uscg.mil/units/cgfac2/iPads/SitePages/Home.aspx.

Port Security Specialist Program
The USCG has conducted a performance planning front end analysis (FEA) to determine Port Security Specialist and Security Specialist (Port / Recovery) performance requirements. Ten recommendations were identified during the FEA. Recommendations from this analysis will help optimize limited training resources and improve Port Security Specialist and Security Specialist (Port / Recovery) performance. A 2015 ALCOAST was issued providing an update to the PSS Program, defining roles and responsibilities of the PSS, and highlighting accomplishments.

Cybersecurity Assessment and Risk Management Approach (CARMA) Assessment in Philadelphia
During the week of June 8th, DHS Office of Sector Engagement Critical Infrastructure Resilience, in conjunction with the Coast Guard, led a cyber risk assessment in the Port of Philadelphia. Agencies involved were DHS, National Institute of Standards and Technology (NIST), Federal Energy Regulatory Commission (FERC), Customs and Border Protection (CBP), Transportation Security Administration (TSA), USCG Sector Del Bay, LANTAREA, CG-FAC, CG-CVC.

Coast Guard LNG Workgroup
Both Harvey-Gulf and TOTE have delivered vessels with LNG fueled engines, and the LNG workgroup worked closely with field units to interpret regulations and develop implementation strategies for these new facilities. CG-FAC chairs the LNG Workgroup, and during 2015 the work group facilitated the development and release of OES Policy letters 01-15 and 02-15 to, among other things, address gaps in 33 CFR 127 for LNG facilities that will bunker LNG. The report gives a link for USCG units to access the LNG Workgroup site in CG Portal (USCG restricted).

Alternative Security Program (ASP)
There are close to 200 facilities operating under ASPs and thousands of vessels, more than are using vessel-specific security plans. Since cyber-security is a topic of growing interest to the entire maritime industry the Coast Guard is exploring options for how to best incorporate cyber risks into security plans required by the Maritime Transportation Security Act. During the past year, two ASP Sponsoring Organization’s Workshops were held in Washington, DC. These workshops are a great forum for information sharing and discussions of best practices for both facilities and vessels. The workshop, held on November 18, 2015, provided an opportunity for in-depth discussions on cyber risks. Many industry groups are developing cyber security best practices and the Alternative Security Program potentially provides an ideal way of addressing cyber risks.

Cyber Risk Management
On 15 January 2015, CG-FAC held a public meeting to solicit input on a policy development project to address cyber security risks in the marine transportation system. In June 2015, the Commandant announced the promulgation of the Coast Guard’s first Cyber Strategy. This Strategy presents a ten-year vision for Coast Guard operations in cyberspace, and lays out our Service’s highest strategic objectives in this rap- idly evolving operational domain.

With the signing of the Cyber Strategy, CG-FAC became the lead office for implementing the Protect Infrastructure portion of the Strategy. The newly formed Protect Infrastructure Cyber Strategy Implementation Team (CSIT) had representatives from nearly every office within CG-5P and also representatives from other offices including CG-2, CG-6, and CG- 5R. Other offices outside of HQ have also pitched in, including National Maritime Center (NMC), Areas and Districts. The CSIT recently submitted an implementation plan and continues to work to complete identified initiatives. CG-FAC members were active in supporting Coast Guard wide research and development related to cyber risks in the marine transportation system.

Cyber Lexicon
CG-FAC, working within the Transportation System Sec- tor Cyber Security Working Group, assisted in developing a Common Cyber Language for the Transportation Sector. The language can be used to assist sub-sectors such as airlines or rail within the Transportation Sector have a common language when discussing cyber issues. The trail to this file in Homeport is Missions>Cybersecurity>Cyber Information> Transportation Sector Common Cyber Language.

Cybersecurity Assessment and Risk Management Approach (CARMA)
CARMA is a DHS developed tool that attempts to identify cyber risks within the port. It is a stakeholder-vetted list of the Port’s cyber infrastructure, as defined by its critical functions, supporting value chains, and specific types of cyber systems. What is important is that it utilizes local stakeholders to derive a port-level understanding of shared vulnerabilities and with it a prioritized list of strategies for managing the identified risks. This allows individual owners and operators to prioritize budget and resource allocations according to common risks. It also uses the identified cybersecurity risks to help build valid scenarios that could be leveraged for sector or national-level cyber exercises. Information on CARMA is accessed via email at ncsd_cipcs@hq.dhs.gov.

Cyber Risk Awareness and Policy Development
In 2015, the Coast Guard worked with the National Maritime Security Advisory Council, the National Offshore Safety Advisory Council, and many individual industry associations to share cyber information.

In June, the U.S. Coast Guard submitted a paper and introduced cyber risk management as a topic at the International Maritime Organization. Transport Canada has been a particularly strong partner in cyber. CG-FAC sent out 12 cyber related notices in 2015. A new resource section was also added to Homeport that shares over 100 different links to cyber related sites from advisories to alerts, assessment tools, recovery resources, supporting documents, tools, and training and education.

2015 Facility Inspections Program Statistics
Total regulated facilities:
8,211
MTSA-regulated facilities:
3,476
Total facility inspections completed:
11,856
MTSA facility inspections completed:
5,937
Total container inspections completed:
18,053
Total transfer monitors conducted:
456
Total operational controls (COTP Orders)
34
Security COTP Orders
16
Safety/Environmental Protection COTP Orders
19



2015 MTSA Security Compliance by District
District
FSPs*
MTSA Inspections
Deficiencies
1st
298
949
164
5th
166
451
129
7th
310
928
241
8th
905
1902
570
9th
304
691
120
11th
135
326
120
13th
139
257
106
14th
77
214
142
17th
98
219
27
Total
2432
5937
1619

Container Update
CG-FAC continuously seeks to improve the National Container Inspection Program (NCIP) guidance and streamline the process for both industry and the field. CG-FAC recently met with Hapag-Lloyd and the National Cargo Bureau to discuss industry and Coast Guard concerns and issues with the shipment of containers in an effort to identify ways to mitigate risks. Hapag-Lloyd has developed a system called “Watchdog”, that analyzes shipping documents searching for key words to assist in selecting containers for inspection. Watchdog has enabled Hapag-Lloyd to inspect 20% of all containers shipped by the company.

Mis-declared cargo and leakage are the most prominent issues ailing the shipment of containers and account for 86% of deficiencies according to the Cargo Incident Notification System website. According to the same website, over 70% of those deficiencies involve general cargo shipments, which point to the success of inspection programs focused on declared Hazardous Materials (HAZMAT).

Higher national compliance rates in declared HAZMAT shipments led to a shift for inspections rates of declared HAZMAT and general cargo container shipments. Previous guidance prioritized HAZMAT over general cargo shipments at a 90% to 10% inspection goal respectively. On average, of the total containers inspected nationally the Coast Guard has achieved roughly 60% to 40% HAZMAT to general cargo annually.

Transportation Worker Identification Credential (TWIC) Verifications
As part of the MTSA security program, Facility Inspectors conducted a combined 48,289 visual and electronic inspections of TWIC cards in 2015, and identified 970 instances of non-compliance with TWIC requirements.  CG-FAC is currently conducting market research for replacement readers; current hand-helds are reaching the end of their service life. There are currently a few USCG units conducting field testing for iPad based reader applications. 

USCG TWIC Implementation branch members worked directly with counterparts at TSA to discuss and address TWIC program improvements and issues. TSA has recently begun implementation of a civil enforcement program for individual TWIC holders violating regulatory requirements. Many Transportation Security Inspectors – Surface (TSI-S) personnel have reached out to Districts and Sectors to coordinate implementation of this inspection program.

2015 MTSA Facility Enforcement Actions
In 2015, the Coast Guard completed 4,717 security-related MTSA annual and spot check ex- aminations and recorded 131 enforcement activities against MTSA-regulated facility owners or operators for noncompliance with MTSA regulations.  The 131 enforcement activities executed in 2015 took place at 115 MTSA-regulated facilities and included official letters of warning or administrative civil penalties.


Citation


Citation Title
Enforcement Activities Executed
33 CFR 101.305
Reporting, Breach of Security
3
33 CFR 105.125
Noncompliance
3
33 CFR 105.140
Alternative Security Program
1
33 CFR 105.200
Owner or operator requirements
27
33 CFR 105.205
Facility Security Officer requirements
7
33 CFR 105.210
Facility personnel with security duties
13
33 CFR 105.220
Drill and exercise requirements
15
33 CFR 105.225
Facility recordkeeping requirements
4
33 CFR 105.255
Security measures for access control
29
33 CFR 105.260
Security measures for restricted areas
8
33 CFR 105.275
Security measures for monitoring
3
33 CFR 105.290
Additional cruise ship terminal requirements
2
33 CFR 105.305
Requirements for facility security assessments
1
33 CFR 105.400
Facility Security Plans
5
33 CFR 105.410
Facility Security Plans – Submission and approval
7
33 CFR 105.415
Facility Security Plans – Amendment and audit
3
Total
131

As noted on the previous page, as in 2014, almost 50% of Coast Guard enforcement actions at regulated facilities were for 33CFR105.200 and 105.255 violations.

Rulemakings
Seafarer’s Access to Maritime Facilities - On July 27, 2015, the public comment period for the Seafarer’s Access to Maritime Facilities Notice of Proposed Rulemaking (NPRM) officially closed. The 162 comments have been adjudicated and the Final Rule is being developed. This proposed rule would implement section 811 of the Coast Guard Authorization Act of 2010, and requires each owner or operator of a facility regulated by the Coast Guard to implement a system that provides seafarers and other individuals with access between vessels moored at the facility and the facility gate, in a timely manner and at no cost to the seafarer or other individual.

Consolidated Cruise Ship Security - On June 1, 2015, the public comment period for the Consolidated Cruise Ship Security Notice of Proposed Rulemaking (NPRM) officially closed. The 115 comments have been adjudicated and the Final Rule is being developed. The Coast Guard proposes to amend its regulations on cruise ship terminal security and the proposed regulations would provide detailed, flexible requirements for the screening of all baggage, personal items, and persons—including passengers, crew, and visitors—intended for carriage on a cruise ship. The proposed regulations would standardize security of cruise ship terminals and eliminate redundancies in the regulations that govern the security of cruise ship terminals.

Training
This year, CG-FAC traveled to each District to meet with a number of Facility Inspectors and Port Security Specialists during the FAC road show. Program staff covered certain topics specific to the Unit, District, or Area’s request.  Hot topics were LNG as Fuel, TWIC, MTSAII, and Cyber.

Area Maritime Security Committees
In April 2015, the Delaware Bay Area Maritime Security Committee was recognized as the 2014 Area Maritime Security Committee of the Year. This AMSC has developed a Regional Business Continuity Planning Template which was developed by taking an all hazards approach to include commercial risks. The template document serves as a readily implementable tool for use by Port Stakeholders in developing their own Business Continuity Plans. Widespread use of this template will lead to facilities better suited  to maintain critical business functions throughout our port and the nation, leading to a more  secure, resilient port and the ability to continue to contribute to the regional economy through unforeseen circumstances.

Trending Issues in Port Safety, Security, and Resilience
MTSRU - In order to build system continuity and maintain effective levels of program readiness, CG-FAC Senior Leadership developed and incorporated a strategy with the office business plan to host a National MTSRU Workshop every two years, to review and update program policies, guidance and analyze lessons learned from real events to improve response effectiveness and enhance program visibility.

Cooperation with Transport Canada - increased cooperation in 2016.

What to Expect in 2016
Facility Security - A policy letter encouraging facilities to submit their FSP/VSP/ASP renewals to the Coast Guard 60 days prior to the expiration date will be signed and disseminated to the field in CY16. Also, the Breach of Security Instruction has been updated to include suspicious activity response. The instruction will be published mid- 2016 and will address network security in addition to physical security incidents. Finally, be on the lookout for NVIC 03-03, Change 3 as well as an Alternative Security Plan NVIC in CY16.

EHC Strategy - CG-FAC will be working with other offices to create an Implementation Working Group for the EHC Strategy. This working group will look to implement the four goals of the EHC Strategy including awareness, prevention, response, and recovery.

Cyber - CG-FAC is working on several policy updates concerning cyber risk management. In cooperation with NIST, CG-FAC is drafting a Cyber Framework Implementation Guide for bulk liquid facilities. This will help facility operators identify the components of the NIST Cybersecurity Framework most applicable to their operations. CG-FAC is also developing a NVIC that will provide cyber risk management guidance to facility and vessel operators. CG-FAC will continue to support the Areas on conducting Cyber Awareness Training for CG Units.

Exercise requirements: CG-FAC is working on policy to clarify the definition for annual, and other time periods, as it is used in the 33 CFR 154 for exercise requirements.

Pipeline testing: CG-FAC is updating current policy and incorporating that into a pipeline testing policy NVIC that will guidance on alternate testing methods.

HOMEPORT— CG FAC is working with other Coast Guard Headquarters Offices to complete a long overdue technical refresh of Homeport.  This update will improve reliability and cyber security for the system and provide a better user interface.

Regulatory Projects:
Consolidated Cruise Ship Security - The public comment period for this NPRM ended on June 1, 2015. The anticipated final rule publication date is in 2016.

Seafarer’s Access to Maritime Facilities - The public comment period for this NPRM ended July 27, 2015. The anticipated final rule publication date is in 2016.

Transportation Worker Identification Credential (TWIC) Reader Requirements - The Final Rule is in final agency clearance.



Friday, January 29, 2016

Maritime Commons Reports on Texas AMSC Cyber Training: USCG Remarks

In the January 28, 2016 Coast Guard Maritime Commons, the Coast Guard reported on the South Texas Area Maritime Security Committee Maritime Awareness Security Terrorism Training Seminar focusing on Cybersecurity. Maritime Commons gave a digest of Sector Corpus Christi’s Commander and Chair of the Area Maritime Security Committee, Capt. Tony Hahn’s remarks. He referred to the importance of the Coast Guard’s Cyber Strategy and encouraged attendees to do the following:

  •         Incorporate cybersecurity into Area Maritime Security Committee risk assessments;
  •         Leverage grant funding to evaluate cyber risks;
  •         Create discreet venues to share cybersecurity information with maritime industry;
  •         Develop guidance for commercial vessels and facilities on how to identify and evaluate cyber-related vulnerabilities;
  •         Work with the International Maritime Organization to develop global maritime cyber prevention and response protocols;
  •         Incorporate cybersecurity into required training for vessel and security officers;
  •         Incorporate cybersecurity into requirements for Coast Guard issued mariner credentials


Thursday, December 17, 2015

MTSA Secure and Restricted Areas

More Thoughts on the Secure Area Concept

<>  From October 2015 Waves on the Waterfront.

 This was a good short general discussion of the definitions of restricted and secure areas. However, one of the sources of confusion about secure areas is repeated in this discussion. It appears because it exists in the regulation, i.e., secure area as that area over which the owner has implemented security measures for access control.[1] Because many facilities have areas over which the owner has implemented security measures for access control where a TWIC is not required, this definition is puzzling. For example, the facility has a main office immediately inside the single fence that encircles the entire facility. TWIC cards are not required to access the office, according to the approved FSP, yet the office is within that area over which the owner has implemented security measures for access control. This seems to be in contradiction to the definition of secure area.

Even at this late date, years after TWIC implementation, there is still widespread misunderstanding about these two terms, secure and restricted areas. The idea of “secure area” has several concepts embedded within it. 
  • ·         Designating areas as restricted, secure, or both adds additional layers of security. 
  • ·         The secure area must have a maritime nexus, because the secure area is the area where persons need a TWIC for unescorted access and the purpose of the card itself is to ensure that only persons who have undergone the TWIC background checks have unescorted access to these high-risk, TSI-prone areas in facilities and vessels.
  • ·         Secure areas are a security measure described out in the FSP so to a certain extent they can be fluid across the system, and are subject to the judgement of the individual Coast Guard unit that approves the FSP.  The only secure area that will be guaranteed to be designated as such across the system, from the largest facility in the country to Laurie’s Sand & Gravel Dock, is the area immediately adjacent the vessel (that triggers the FSP) when the vessel is at the dock.[2]


For purposes of clarification, it might be useful if 33 CFR 101.105 be amended to read “Secure area means the area on board a vessel or at a facility or outer continental shelf facility over which the owner/operator has implemented security measures for access control where a TWIC card is required for unescorted access, in accordance with a Coast Guard approved security plan.” In all secure areas, TWIC cards are required for unescorted access. It seems odd therefore to exclude this important concept from the definition.

To keep the two concepts clear in the mind, it is less helpful to contrast them than to simply remember the following:
  • ·         Restricted areas require limited access and a higher degree of security protection[3]; a  list of areas that must be designated as restricted, as appropriate for the facility, is  given in 33 CFR 105.260(b).
  • ·         Secure areas are those areas where persons need a TWIC for unescorted access. There can be no secure area that is not connected with TWIC card use.




[1] 33 CFR 101.105, definition of secure area.
[2]  Navigation and Inspection Circular 03-07, enc. 3.
[3] 33 CFR 101.105, definition of restricted area.

Wednesday, December 16, 2015

On December 15 2015, the Department of Homeland Security issued its Semiannual Regulatory Agenda. As Dennis Bryant so aptly puts it, “this agenda is aspirational in nature.” This means DHS hopes that the given timetables will be met. Below is MTSA-related information from the Agenda, with my comments. The full agenda can be found at https://www.gpo.gov/fdsys/pkg/FR-2015-12-15/pdf/2015-30621.pdf


Updates to Maritime Security
Abstract: The Coast Guard proposes certain additions, changes, and amendments to 33 CFR, subchapter H. Subchapter H is comprised of parts 101 through 106. Subchapter H implements the major provisions of the Maritime Transportation Security Act of 2002 (MTSA). This rulemaking is the first major revision to subchapter H. The proposed changes would further the goals of domestic compliance and international cooperation by incorporating requirements from legislation implemented since the
original publication of these regulations, such as the Security and Accountability for Every (SAFE) Port Act of 2006, and including international standards such as Standards of Training, Certification & Watchkeeping security training. This rulemaking has international interest because of the close relationship between subchapter H and the International Ship and Port Security Code (ISPS).

NPRM .................. 07/00/16

Comments: At this point, I can’t speculate when this update will be issued, or how outdated it will be  when it finally comes out. It’s obvious to MTSA practitioners that an update needs to be made. Absent this update, industry and regulators end up operating from NVICs and PACs and policy letters and other documents, not an ideal situation from either an industry or a regulator’s point of view. PACs and letters under CF-FAC signature aren’t regulations. They lack the industry comment that is an integral part of the regulatory process. The regulatory process seems to have evolved into a process too cumbersome for today’s fast moving workplace.


Seafarers’ Access to Maritime Facilities
Abstract: This regulatory action will implement section 811 of the Coast Guard Authorization Act of 2010 (Pub. L. 111–281), which requires the owner/operator of a facility regulated by the Coast Guard under the Maritime Transportation Security Act of 2002 (Pub. L. 107–295) (MTSA) to provide a system that enables seafarers and certain other individuals to transit between vessels moored at the facility and the
facility gate in a timely manner at no cost to the seafarer or other individual. Ensuring that such access through a facility is consistent with the security requirements in MTSA is part of the Coast Guard’s Ports, Waterways, and Coastal Security (PWCS) mission.
 The timetable on this rule is:
 NPRM .................. 12/29/14
NPRM Comment Period Reopened…05/27/15
NPRM Comment Period End…07/01/15
Final Rule ............ 02/00/16
Comments:  I would not be surprised to see this final rule issued in first quarter 2016. This regulation will (almost certainly) require action on the part of all MTSA facilities, including a new FSP section. Interesting example of a narrowly-focused regulation that sped through the process, despite an extended comment period. We need to keep in mind, however, the many Coast Guard actions that preceded this reg.

Transportation Worker Identification Credential (TWIC); Card Reader Requirement

Concerning the TWIC Reader rule (Transportation Worker Identification Credential (TWIC); Card Reader Requirement) the Agenda states: Regulatory Plan: This entry is Seq. No. 62 in part II of this issue of the Federal Register.


Comment: There is no Part II to this issue of the FR, so I am assuming that this is just one more puzzling  aspect of the TWIC program.

Monday, November 30, 2015

Big Changes Coming Soon to Coast Guard's Homeport Website

On November 27, 2015, the Coast Guard made an announcement concerning its Homeport website via Maritime Commons (http://mariners.coastguard.dodlive.mil/2015/11/27/11272015-homeport-2-0-news-and-information/ ). The information is also posted on the Homeport website, http://homeport.uscg.mil .
We have been hearing for quite a while about upcoming changes to Homeport – these changes are happening and happening soon. Below is the text of the announcement from the Homeport/CG-FAC website:
The United States Coast Guard (USCG) Homeport Internet Portal (HIP) was established in 2005 to facilitate compliance with the requirements set forth in the Maritime Transportation Security Act (MTSA) of 2002, by providing secure information dissemination, advanced collaboration, electronic submission and approval for vessel and facility security plans, and complex electronic and telecommunication notification capabilities.
Since its inception, HIP has been expanded to provide additional support such as Transportation Worker Identification Card New Hire; Electronic Vessel Response Plan; Marine Event Permit Process; Port Status Indicator; Merchant Mariner Licensing and Documentation; Marine Training and Assessment Data (training documentation); Merchant Mariner Certificate; Sea Service Calculator; Merchant Mariner Verification of Certificates; and Merchant Mariner Credential Survey
The Coast Guard will launch Homeport 2.0 Jan. 29, 2016 in order to provide a better user experience and improve the security of user information. Upgrades will include fewer site navigation menus and more efficient and secure search functions.
Although most features will be available as soon as the new site launches, user access to a few conveniences may be interrupted. Review the Homeport 2.0 Deployment Schedule for details. Functions that are essential to maintaining port security or that are critical to continuing the flow of commerce will remain available during the transition period.
Alternative solutions are available for most features taken offline during the transition. Anyone who needs access to a service normally obtained through HIP should contact the appropriate subject matter expert listed in the Homeport 2.0 Deployment Schedule.
From the Deployment Schedule:
Uninterrupted services:
 · TWIC new hire procedures
· Port status query
 · Merchant Mariner Application Status
· VRP Express
· Vessels & facilities search
· Merchant Mariner Credential Verification
· Merchant Mariner Sea Service Calculator
· Most core CG accessible-only functions
Services unavailable Jan. 29 - March 31, 2016
· Mariner Training & Assessment Database
 · Security Plans Temporary
· Merchant Mariner Credential Survey
 Services unavailable Jan. 29 - April 30, 2016
 · Merchant Mariner Certificate
· Marine Event Application Temporary

The FAQ document (http://www.uscg.mil/hq/cg5/cg544/docs/Homeport_2%200_FAQs_AllUsers1%201.pdf) lists work-arounds for most unavailable services in a Deployment Schedule (http://www.uscg.mil/hq/cg5/cg544/docs/Homeport%20Application%20Deployment%20Schedule.pdf ). There is a separate FAQ document (http://www.uscg.mil/hq/cg5/cg544/docs/Homeport_2%200_FAQs_CommunityOwners1%201.pdf ) for community owners, who need to pay careful attention to deadlines. The deadline for migrating community content is January 29, 2016.  This is a hard deadline. “Legacy Homeport will be taken offline as of Jan. 29, 2016, and community owners should make all efforts to meet this deadline. Any content that is not transferred will be auto-archived and will not be easily accessible.”

Thursday, June 18, 2015

Coast Guard Releases Cyber Strategy

On June 16, 2015, the U.S. Coast Guard issued its Cyber Strategy.  The document may be found at http://www.uscg.mil/seniorleadership/DOCS/cyber.pdf.  

The document opens with a sobering statement of the problem: “Cybersecurity* is one of the most serious economic and national security challenges we face as a Nation. Government systems—including Coast Guard systems—face a mounting array of emerging cyber threats that could severely compromise and limit our Service’s ability to perform our essential missions.” “In the digital age…there is no strategic objective the Coast Guard can adequately meet—or operational mission the Coast Guard can fully perform—without a robust and comprehensive cyber program.*”

The asterisks link to definitions, and this document gives us a good range of definitions of cyber-related terms.  Definitions, so important to the MTSA community, are found in Appendix I, and definitions sources are from a variety of documents and explain many cyber-related terms, including:
Cybersecurity breach – Unauthorized access to data, applications, services, networks and/or devices, by-passing their underlying security mechanisms. A cybersecurity breach that may rise to the level of a reportable Maritime Transportation Security Act (MTSA) security breach occurs when an individual, an entity, or an application illegitimately enters a private or confidential Information Technology perimeter of a MTSA-regulated facility or vessel, Maritime Critical Infrastructure/Key Resources, or industrial control system such as Supervisory Control and Data Acquisition systems, including but not limited to terminal operating systems, global positioning systems, and cargo management systems.

Reproduced in its entirety below is the Executive Summary. Port security stakeholders are encouraged to read the entire document.

The Coast Guard is committed to ensuring the safety, security, and stewardship of our Nation’s waters. This commitment requires a comprehensive cyber strategy that provides a clear framework for our overall mission success.

Cyber technology has fueled great progress and efficiency in our modern world. Coast Guard operations are more effective because of the rapid evolution in cyber technology, and advanced technologies have also led to an unprecedented era of efficiency of the Maritime Transportation System (MTS). However, with these benefits come serious risks. Information and its supporting systems are continually attacked and exploited by hostile actors. Foreign governments, criminal organizations, and other illicit actors attempt to infiltrate critical government and private sector information systems, representing one of the most serious threats we face as a nation.

As the Coast Guard relies on modern digital information and communications systems to execute its missions, the Service must defend against those who threaten them. The Coast Guard must also build and sustain an operational advantage in cyberspace to ensure optimal integration of information and intelligence with our operations. Moreover, the Coast Guard must lead the effort to protect maritime critical infrastructure from a broadening array of cyber threats.

To fully ensure the Coast Guard is able to perform its essential missions in the 21st Century, it must fully embrace cyberspace as an operational domain. To this end, the Coast Guard will focus on three specific strategic priorities in the cyber domain over the next ten years:
•             Defending Cyberspace
•             Enabling Operations
•             Protecting Infrastructure

Defending Cyberspace: Secure and resilient Coast Guard IT systems and networks are essential for overall mission success. To ensure the full scope of Coast Guard capabilities are as effective and efficient as possible, the Coast Guard must serve as a model agency in protecting information infrastructure and building a more resilient Coast Guard network.

Enabling Operations: To operate effectively within the cyber domain, the Coast Guard must
develop and leverage a diverse set of cyber capabilities and authorities. Cyberspace operations, inside and outside Coast Guard information and communications networks and systems, can help detect, deter, disable, and defeat adversaries. Robust intelligence, law enforcement, and maritime and military cyber programs are essential to enhancing the effectiveness of Coast Guard operations, and deterring, preventing, and responding to malicious activity targeting critical maritime infrastructure. Coast Guard leaders must recognize that cyber capabilities are a critical enabler of success across all missions, and ensure that these capabilities are leveraged by commanders and decision-makers at all levels.

Protecting Infrastructure: Maritime critical infrastructure and the MTS are vital to our
economy, national security, and national defense. The MTS includes ocean carriers, coastwise shipping along our shores, the Western Rivers and Great Lakes, and the Nation’s ports and terminals. Cyber systems enable the MTS to operate with unprecedented speed and efficiency. Those same cyber systems also create potential vulnerabilities. As the maritime transportation Sector Specific Agency (as defined by the National Infrastructure Protection Plan), the Coast Guard must lead the unity of effort required to protect maritime critical infrastructure from attacks, accidents, and disasters.

Ensuring Long-term Success: In support of the three strategic priorities, this Strategy
identifies a number of cross-cutting support factors that will ensure the Coast Guard’s long-term success in meeting the Service's strategic goals in the cyber domain. These include:
(1) recognition of cyberspace as an operational domain,
(2) developing cyber guidance and defining mission space,
(3) leveraging partnerships to build knowledge, resource capacity,
and an understanding of MTS cyber vulnerabilities,
(4) sharing of real-time information,
(5) organizing for success,
(6) building a well-trained cyber workforce, and

(7) making thoughtful future cyber investments.

Friday, June 12, 2015

TSA Posts Notice Regarding Resolution of Delays in Processing TWIC Cards, with Caveat

On June 12, 2015, the Transportation Security Administration posted the following notice at http://www.tsa.gov/stakeholders/transportation-worker-identification-credential-twic:

1) UPDATED! TWIC Processing Delays: The previously announced delay in processing some TWIC applications has been resolved.  Most applicants will receive a TWIC within a month of enrolling, and often in about two weeks.  However, despite progress in reducing processing delays for the small number of applicants whose criminal or immigration records indicate that they may not be eligible for a TWIC, those applicants may still experience a two-and-a-half month wait before receiving a TWIC or notification from TSA.
To ensure all eligible applicants receive a new or renewal TWIC before it is needed for work we continue to strongly encourage all applicants to apply for their TWIC at least 10 to 12 weeks prior to when the card will be required to avoid inconvenience or interruption in access to maritime facilities.

_______________________________________________________

Takeaways from this notice: applicants with anything in their background that might result in a application refusal on criminal history or immigration grounds may still experience a lengthy delay.  It remains to be seen if persons with clean backgrounds continue to experience lengthy delays.  Employers would be well-served to take TSA’s advice and assume that the application process will take 10 – 12 weeks.


The only way to find out if anything new has been posted on the TSA TWIC website is to check it daily.  At the bottom of the site is a revision date.  If this date has changed, new material has been added.  Do not rely on the NEW!  verbiage on notices because TSA does not remove this on a timely basis.

Friday, May 29, 2015

MTSA Training Course Update from Maritime Commons

Maritime transportation security act training course update -

On May 28, 2015, the following was posted on the Coast Guard’s Maritime Commons blog, at http://mariners.coastguard.dodlive.mil/2015/05/28/5282015-maritime-transportation-security-act-training-course-update/:

“The Coast Guard is pleased to see the large number of maritime industry employees who choose to take part in the voluntary Maritime Transportation Security Act Training Course Program, choosing to attend courses reviewed and approved via a Coast Guard accepted Quality Standard System, or QSS.

The Coast Guard was informed that one of the accepted QSSs, Det Norske Veritas – Germanischer Lloyd, has withdrawn from certifying FSO, CSO, MSLEP and FPSSD courses. The American Bureau of Shipping is a QSS organization accepted by the Coast Guard and continues to participate in the certification process of these courses.
Additional information can be found on the Coast Guard’s facilities webpage.

Effective security training for maritime industry professionals is critical to the success of the nation’s security efforts. As the Coast Guard continues to develop regulations to establish comprehensive FSO training requirements, maritime industry employees with security duties are strongly encouraged to take approved courses.”

Here are some take-aways from this post:
1.  At this point, ABS is the sole course certifier for FSO, CSO, MSLEP and FPSSD.
2.  The Coast Guard continues to “strongly encourage” maritime industry employees with security duties to take approved courses. Because the new regulation mandating training is not yet in effect, strongly encourage is all they can do, but a word to the wise ought to be sufficient.

Persons who are hoping  that the Coast Guard may grandfather any FSO currently serving or who has received any sort of FSO training (4 hours? 2 hours?), and only require new FSOs to become certified under the new regulations, should probably take a look at the communications that have come out from CG-FAC supporting approved courses.

Monday, March 23, 2015

TSA Notice Concerning Reporting Non-Receipt of Mailed TWICs

Today the Transportation Security Administration posted a notice concerning persons who have enrolled for a TWIC card, received notification that the card has been mailed, and then fail to receive the card through the mail. The notice is at http://www.tsa.gov/stakeholders/transportation-worker-identification-credential-twic. This is the "down side" of the TSA one-visit program. It remains to be seen how many of the cards will fail to reach the end receiver.  Persons who have received the card through the mail tell me that the envelope is clearly marked "Transportation Security Administration".

The notice is printed in its entirety below.

NEW! Reporting Non-Receipt of Mailed TWICs: TWIC applicants who request to receive their TWIC card by mail will receive a phone or email notification that the card has been mailed.  After notification that the card has been mailed, applicants have 60 days to report non-receipt of the card by contacting the Universal Enrollment Services (UES) Call Center at: (855) 347-8371. Failure to report non-receipt of the card within 60 days will result in a $60 fee to replace the lost card.

Monday, February 9, 2015

From Coast Guard Maritime Commons blog today, a reminder that USCG has not yet made final decision on transportation of fracking water (Shale Gas Extraction Waste Water, or SGEWW, in bulk) by barge

From Coast Guard Maritime Commons today, a reminder that USCG has not yet made final decision on transportation of fracking water (Shale Gas Extraction Waste Water, or SGEWW, in bulk) by barge, at http://mariners.coastguard.dodlive.mil/2015/02/06/262015-coast-guard-has-not-taken-final-action-on-proposed-policy-letter-for-carriage-of-cargo/

This blog, Coast Guard Maritime Commons, is a wonderful source of information on many maritime topics, including security.  It should be required reading for FSOs. FSOs can sign up at the blog site to be notified of new postings. The posting on fracking water is reproduced below:

The Coast Guard reiterated Thursday that it has not taken final agency action or approved requests for the carriage of Shale Gas Extraction Waste Water, or SGEWW, in bulk.

“The Coast Guard has not taken final agency action on the June 2012 request to carry Shale Gas Extraction Waste Water,” stated CAPT John Mauger, Chief of the Office of Design Engineering Standards at Coast Guard Headquarters. “Our action on this request is still pending our analysis of the comments received during the public review of our proposed policy.”

In June 2012, the Coast Guard received a request to classify and carry SGEWW for bulk transportation via barge. The regulations in 46 CFR 153, require the Coast Guard’s Office of Design and Engineering Standards to assess the hazards and classify a cargo before it can be carried in bulk.

In October 2013, the Coast Guard published a draft policy that proposed conditions for carriage of this cargo. No decision regarding the carriage of this cargo has been made.

As described in the draft policy, the proposed standards would not supersede existing allowances for oil field wastes to be shipped as hazardous wastes under long-standing Coast Guard policy in Navigation and Vessel Inspection Circular 7-8 7, Guidance on Waterborne Transport of Oil Field Wastes. This policy describes the oil field wastes and provides several examples. Under this policy, vessels carrying hazardous waste are subject to inspection. Further, waterfront facilities involved in the handling, storage or transfer of hazardous waste are regulated by the Coast Guard under 33 CFR, Part 126.


- See more at: http://mariners.coastguard.dodlive.mil/2015/02/06/262015-coast-guard-has-not-taken-final-action-on-proposed-policy-letter-for-carriage-of-cargo/#sthash.WWyTbfcS.dpuf

Update to TSA TWIC NEWS Posting on Truncated Last Name on TWIC Card

TSA has posted an update to the issue concerning persons with last names of more than 14 characters who have enrolled for a TWIC.  The take-away for FSOs is, "TSA is exploring ways to print the full last name on the card regardless of the number of characters.  Security personnel should be aware that some TWIC holders will have authentic cards although their full last name, as printed on the card, may be truncated." 
(Off topic: I made a request to John Schwartz that updated and new items on this website be posted with a date so we can figure out what was posted when.  He advised that that was already being considered.  I see that they are still considering it.) 
Truncated Last Name on TWIC Card: TWIC cards issued since May 2014 truncated the number of characters printed on cards for individuals with long last names.  Version 2.3 TWIC® cards printed prior to 12/12/2014 printed only the first 14 characters of a person’s last name.  The number of characters includes spaces, hyphens, and apostrophes in the person’s last name.  The printed last name is always followed by a comma. If a person’s last name exceeds 14 characters, all characters after the 14th are not printed.  A comma follows immediately after the 14th character.
Version 2.3 TWIC cards printed on or later than 12/12/2014 are printed with a maximum of last name 19 characters, followed by a comma.
Despite the limited space available on the card, TSA is exploring ways to print the full last name on the card regardless of the number of characters.  Security personnel should be aware that some TWIC holders will have authentic cards although their full last name, as printed on the card, may be truncated.