Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) published an approval for another TSA emergency information collection request supporting increased security oversight of gas and liquid pipelines. This emergency ICR update addresses changes to the Pipeline Corporate Security Review (1652-0056) which was most recently updated on April 15th, 2021. According to the supporting document [.PDF download link] provided to OIRA, this emergency ICR approval is needed to support a new TSA Security Directive for pipeline cybersecurity security operations.
New Security Directive
That new Security Directive will add new information collection requirements to this ICR. They will include:
Cybersecurity Contingency/Response Plan,
Third-Party Evaluation, and
Certification of completion of SD requirements
The support document does not include any new burden estimates for the added information collection requirements.
Only the third collection will require the submission of documents to the TSA. TSA will not be specifying the format for the certification requirement; it will be submitted via email. The documentation for the other two requirements will have to be available for TSA inspectors upon request.
OIRA Approval
As with most emergency ICR requests, OIRA gave rapid approval of the ICR request. Its approval was, however, only for 6-months. OIRA did required that TSA publish a 60-day ICR notice for this change within 90-days.
Commentary
There is an interesting discussion about the TSA/Pipeline cybersecurity situation over at Mondaq.com. One point that I do not think has yet drawn much attention is the efficacy of using Security Directives as the way forward for controlling cybersecurity of any critical infrastructure operation. At some point a pipeline operator is going to cry foul and take the TSA to court for overstepping their authority.
If TSA is going to mandate security controls, they are going to have to go through the regulatory process of publishing a notice of proposed rulemaking, accepting and responding to public comments, and publishing a final rule. They should have started this process almost as soon as their last Security Directive was published, formally establishing the requirements of that rule. Instead, they are using their questionable authority to issue another, more expansive and expensive, security directive.
Unfortunately, we cannot expect Congress to address this issue because of the intra-committee conflicts about who will have oversight and funding responsibilities for pipeline security measures.