OMB Approves Emergency TSA Pipeline Reporting Changes
Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) approved two emergency revisions to information collection requests (ICR) from the Transportation Security Administration (TSA) for pipeline security reporting requirements. The ICR revisions are for the “Critical Facility Information of the Top 100 Most Critical Pipelines” (1652-0050) and “Pipeline Operator Security Information” (1652-0055). Both ICR-revision requests used similar language concerning the recent Colonial Pipeline ransomware attack as part of the justification for the emergency approval request.
Critical Facility Information ICR
According to the ICR supporting statement [.DOCX download link] for 1652-0050 that TSA provided to OIRA on Tuesday:
“TSA is seeking emergency approval to amend this collection, 1652-0050, to require all owner/Operators to review Section 7 of TSA’s Pipeline Security Guidelines and assess current activities, using the TSA Pipeline Cybersecurity Self-Assessment form, to address cyber risk, and identify remediation measures that will be taken to fill those gaps and a time frame for achieving those measures.”
This effort will be part of a pending TSA Security Directive that will require “requires owner/operators to identify areas where their practices do not align with the recommendations [in Section 7] in the Guidelines [Pipeline Security Guidelines] and develop a remediation plan” (para 3 of supporting document).
TSA is expecting companies to submit the PCSA either via email (document encrypted) or via a secure web site.
Apparently, the TSA has not provided a copy of the Pipeline Cybersecurity Self-Assessment form to OIRA as it is not included in documents listed on the ICR page. Neither has TSA updated the burden estimate on this ICR to provided an indication of how much time will be necessary to conduct the review, complete the document and submit it to TSA.
TSA already has an update to this ICR in process. A 60-day ICR notice was published last month. I addressed the shortcomings of the information provided in that notice. Interestingly, the Critical Facility Security Review (CFSR) Form that is included in this emergency change approval is the same 2017 version that was included in the current version of the ICR and does not reflect the proposed cybersecurity changes that TSA was proposing in April.
The OIRA approval of this emergency revision to the ICR includes the following notice on the terms of clearance:
“Prior to the next submission of this ICR for review, TSA will fully evaluate whether increased coordination between USCG, CISA, and TSA could clarify and simplify the submission procedure for respondents.”
Pipeline Operator Security Information ICR
According to the ICR supporting statement [.DOCX download link] for 1652-0050 that TSA provided to OIRA on Tuesday:
“In order to address the ongoing cybersecurity threat to pipeline systems and associated infrastructure, TSA is seeking emergency approval to amend this collection to require all Owner/Operators subject to the SD’s requirements to report cybersecurity incidents or potential cybersecurity incidents on their IT and OT systems to the CISA within 12 hours of discovery using the CISA Reporting System In addition, the SD requires critical pipeline owner operators to appoint cybersecurity coordinators and to provide contact information for the coordinators to TSA.”
The ICR file does not include any forms, nor does it provide for a change in the burden estimate for this ICR. Interestingly, the previous revision to this ICR, approved in 2019, included a decrease in the burden estimate. That change was never explained in either the published ICR notices or in the supporting statement [.docx download link].
Pipeline Security Guidelines
The TSA Pipeline Security Guidelines referenced in these two ICRs refers to the guidance that TSA initially published in 2010 and then updated in 2018. With very little fanfare, TSA published an updated version of the document, reportedly last month. According to the Record of Changes replaced Section 5, Criticality.
The change to Section 5 is comprehensive. The wording completely changes from the previous version and there is a completely new approach for explaining how facilities can determine whether a facility is a critical pipeline facility.
No changes have been made to the cybersecurity portions of the Guidelines.