Transportation Worker Identification Credential (TWIC)-Reader Requirements
Federal RegisterMar 22, 2013
Ask Donna
What actually matters in this document.
Text
DEPARTMENT OF HOMELAND SECURITY
Coast Guard
33 CFR Parts 101, 104, 105 and 106
[Docket No. USCG-2007-28915]
RIN 1625-AB21
Transportation Worker Identification Credential (TWIC)—Reader Requirements
AGENCY:
Coast Guard, DHS.
ACTION:
Notice of proposed rulemaking.
SUMMARY:
In this Notice of Proposed Rulemaking (NPRM), the Coast Guard proposes to require owners and operators of certain vessels and facilities regulated by the Coast Guard to use electronic readers designed to work with the Transportation Worker Identification Credential (TWIC) as an access control measure. This NPRM also proposes additional requirements associated with electronic TWIC readers, including recordkeeping requirements for those owners and operators required to use an electronic TWIC reader, and security plan amendments to incorporate TWIC requirements. The TWIC program, including the proposed TWIC reader requirements in this rule, is an important component of the Coast Guard's multi-layered system of access control requirements and other measures designed to enhance maritime security.
This rulemaking action, once final, would build upon existing Coast Guard regulations designed to ensure that only individuals who hold a TWIC are granted unescorted access to secure areas at those locations. The Coast Guard has already promulgated regulations pursuant to the Maritime Transportation Security Act of 2002 (MTSA) that require mariners and other individuals to obtain a TWIC and present it for inspection by security personnel prior to gaining access to such secure areas. By requiring certain vessels and facilities to perform TWIC inspections using electronic TWIC readers, this rulemaking would further enhance security at those locations. This rulemaking would also implement the Security and Accountability For Every Port Act of 2006 electronic TWIC reader requirements.
DATES:
Comments and related material must either be submitted to our online docket via
http://www.regulations.gov
on or before May 21, 2013 or reach the Docket Management Facility by that date. Comments sent to the Office of Management and Budget (OMB) on collection of information must reach OMB on or before May 21, 2013.
ADDRESSES:
You may submit comments identified by Coast Guard docket number USCG-2007-28915 to the Docket Management Facility at the U.S. Department of Transportation. To avoid duplication, please use only one of the following methods:
(1)
Federal eRulemaking Portal:
http://www.regulations.gov.
(2)
Mail:
Docket Management Facility (M-30), U.S. Department of Transportation, West Building Ground Floor, Room W12-140, 1200 New Jersey Avenue SE., Washington, DC 20590.
(3)
Fax:
202-493-2251.
(4)
Delivery:
Room W12-140 on the Ground Floor of the West Building, 1200 New Jersey Avenue SE., Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays. The telephone number is 202-366-9329.
Collection of Information Comments:
If you have comments on the collection of information discussed in this NPRM, you must also send comments to OMB's Office of Information and Regulatory Affairs (OIRA). To ensure that your comments to OIRA are received on time, the preferred methods are by email at
oira_submission@omb.eop.gov
(include the docket number and “Attention: Desk Officer for Coast Guard, DHS” in the subject line of the email) or fax at 202-395-6566. An alternate, though slower, method is by U.S. mail to the Office of Information and Regulatory Affairs, Office of Management and Budget, 725 17th Street NW., Washington, DC 20503, ATTN: Desk Officer, U.S. Coast Guard.
FOR FURTHER INFORMATION CONTACT:
If you have questions on this proposed rule, call Lieutenant Commander Loan T. O'Brien, Coast Guard, telephone 202-372-1133. If you have questions on viewing or submitting material to the docket, call Barbara Hairston, Program Manager, Docket Operations, telephone 202-366-9826.
SUPPLEMENTARY INFORMATION:
Table of Acronyms
AHP Analytical Hierarchy Process
ANPRM Advanced Notice of Proposed Rulemaking
ASP Alternative Security Program
CAC Card Authentication Certificate
CCL Canceled Card List
CDC Certain Dangerous Cargoes
CFR Code of Federal Regulations
CGAA 2010 Coast Guard Authorization Act of 2010 (Pub. L. 111-281)
CHUID Card Holder Unique Identifier
CI/KR Critical Infrastructure/Key Resources
COTP Captain of the Port
DHS Department of Homeland Security
DPEA Draft Programmatic Environmental Assessment
FASC-N Federal Agency Smart Credential-Number
FONSI Finding of No Significant Impact
FSP Facility Security Plan
HSI Homeland Security Institute
ICE Test Initial Capability Evaluation Test
IPT Integrated Product Team
MARSEC Maritime Security
MERPAC Merchant Marine Personnel Advisory Committee
MISLE Marine Information for Safety and Law Enforcement
MODU Mobile Offshore Drilling Unit
MSRAM Maritime Security Risk Analysis Model
MTSA Maritime Transportation Security Act of 2002
NIST National Institute of Standards and Technology
NMSAC National Maritime Security Advisory Committee
NPRM Notice of Proposed Rulemaking
NTTAA National Technology Transfer and Advancement Act
NVIC Navigation and Vessel Inspection Circular
OCS Outer Continental Shelf
OIRA Office of Information and Regulatory Affairs
OMB Office of Management and Budget
OSV Offshore Supply Vessel
PAC-D Policy Advisory Council Decision
PACS Physical Access Control System
PIN Personal Identification Number
QTL Qualified Technology List
RUA Recurring Unescorted Access
SAFE Port Act Security and Accountability For Every Port Act of 2006
SBA Small Business Administration
SSI Sensitive Security Information
TSA Transportation Security Administration
TSAC Towing Safety Advisory Committee
TSI Transportation Security Incident
TWIC Transportation Worker Identification Credential
TWIC 1 Final Rule Transportation Worker Identification Credential (TWIC) Implementation in the Maritime Sector; Hazardous Materials Endorsement for a Commercial Driver's License, 72 FR 3492 (Jan. 25, 2007)
TWIC 1 NPRM Transportation Worker Identification Credential (TWIC) Implementation in the Maritime Sector; Proposed Rules, 71 FR 29396 (May 22, 2006)
VSP Vessel Security Plan
Table of Contents
I. Public Participation and Request for Comments
A. Submitting Comments
B. Viewing Comments and Documents
C. Privacy Act
D. Public Meetings
II. Executive Summary
A. Purpose of the Regulatory Action
1. Need for the Regulatory Action
2. Legal Authority for the Regulatory Action
B. Summary of the Major Provisions of the Regulatory Action
C. Summary of Costs and Benefits
III. Background and Purpose
A. General Information About the Transportation Worker Identification Credential
B. Statutory and Regulatory History
C. Risk-Based Approach to Categorizing Vessels and Facilities
D. ANPRM Proposals
1. Classification of Vessels and Facilities into Risk Groups
2. TWIC Reader Requirements for Risk Group A
3. TWIC Reader Requirements for Risk Group B
4. TWIC Requirements for Risk Group C
5. Recurring Unescorted Access
6. TWIC Reader Approval, Calibration, and Compliance
7. Security Plan Amendment
8. Recordkeeping
9. Additional Persons Required To Obtain TWICs
E. Public Comments Received in Response to the ANPRM and Public Meeting
1. General Comments
2. Statutory Authority
3. Risk-Based Approach
a. General
b. MSRAM
c. Movement Between Risk Groups
d. MARSEC Levels
e. CCL and “Privilege Granting”
f. PIN Usage
4. Utility of TWIC Readers in Reducing TSI Vulnerability
5. TWIC Reader Requirements on Vessels
6. TWIC Reader Requirements for Risk Group A
a. Risk Group A Classification
b. Risk Group A TWIC Reader Requirements
7. TWIC Reader Requirements for Risk Group B
a. Risk Group B Classification
b. Risk Group B TWIC Reader Requirements
8. TWIC Requirements for Risk Group C
a. Risk Group C Classification
b. Risk Group C TWIC Requirements
9. Physical Placement of TWIC Readers
10. Recurring Unescorted Access
11. TWIC Reader Durability, Safety, Approval, Calibration, and Compliance
12. TWIC Pilot and HSI Report
13. Security Plan Amendment
14. Recordkeeping
15. Other Comments
F. TWIC Reader Pilot Program
1. Background
2. General Findings
3. Specific Challenges and Lessons Learned
G. HSI Report
H. Additional Data Sources
I. Advisory Committee Input
IV. Section-by-Section Description of Proposed Rule
A. Definitions
B. Federalism
C. Additional Persons Required to Obtain TWICs
D. TWIC Reader Requirements for Risk Group A
E. TWIC Reader Exemption for Vessels With 14 or Fewer TWIC-holding Crewmembers
F. TWIC Inspection Requirements for Risk Groups B and C
G. TWIC Inspection Requirements in Special Circumstances
H. Compliance Deadlines
I. Recordkeeping
J. Risk Group Classifications
K. Movement Between Risk Groups
L. Physical Placement of TWIC Readers
M. Technical Amendments
N. Privacy
O. Public Comment
V. Regulatory Analyses
A. Regulatory Planning and Review
B. Small Entities
C. Assistance for Small Entities
D. Collection of Information
E. Federalism
F. Unfunded Mandates Reform Act
G. Taking of Private Property
H. Civil Justice Reform
I. Protection of Children
J. Indian Tribal Governments
K. Energy Effects
L. Technical Standards
M. Environment
I. Public Participation and Request for Comments
We encourage you to participate in this rulemaking by submitting comments and related materials. All comments received will be posted, without change, to
http://www.regulations.gov
and will include any personal information you have provided.
A. Submitting Comments
If you submit a comment, please include the docket number for this rulemaking (USCG-2007-28915), indicate the specific section of this document to which each comment applies, and provide a reason for each suggestion or recommendation. You may submit your comments and material online, or by fax, mail, or hand delivery, but please use only one of these means. We recommend that you include your name and a mailing address, email address, or phone number in the body of your document so that we can contact you if we have any questions regarding your submission.
To submit your comment online, go to
http://www.regulations.gov
and use “USCG-2007-28915” as your search term. Locate this NPRM in the search results, click the corresponding “Comment Now” box, and follow the instructions. If you submit your comments by mail or hand delivery, submit them in an unbound format, no larger than 8½ by 11 inches, suitable for copying and electronic filing. If you submit comments by mail and would like to know that they reached the Facility, please enclose a stamped, self-addressed postcard or envelope.
We will consider all comments and material received during the comment period and may change this proposed rule based on your comments.
B. Viewing Comments and Documents
To view comments, as well as documents mentioned in this preamble as being available in the docket, go to
http://www.regulations.gov,
and use “USCG-2007-28915” as your search term. The menu options on the left side of the Web page enable you to filter the results for public submissions and other types of documents. If you do not have access to the Internet, you may view the docket online by visiting the Docket Management Facility in Room W12-140 on the ground floor of the Department of Transportation West Building, 1200 New Jersey Avenue SE., Washington, DC 20590, between 9 a.m. and 5 p.m., Monday through Friday, except Federal holidays. We have an agreement with the Department of Transportation to use the Docket Management Facility.
C. Privacy Act
Anyone can search the electronic form of all comments received into any of our dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). You may review a Privacy Act notice regarding our public dockets in the January 17, 2008 issue of the
Federal Register
(73 FR 3316).
D. Public Meetings
We intend to hold one or more public meetings regarding the proposals in this NPRM. A notice with the specific date and location of each meeting will be published in the
Federal Register
as soon as this information is known.
II. Executive Summary
This section provides a concise description of the major proposals and policy decisions in this NPRM. We also provide a summary of the costs and benefits of this NPRM in this section.
A. Purpose of the Regulatory Action
1. Need for the Regulatory Action
This regulatory action is necessary to improve the security of the nation's vessels and port facilities and to comply with statutory requirements. As authorized by the Maritime Transportation Security Act of 2002
1
(MTSA), the Transportation Security Administration (TSA) established the TWIC program to address identity management shortcomings and vulnerabilities identified in the nation's transportation system and to comply
with the MTSA statutory requirements. On January 25, 2007, the Department of Homeland Security (DHS), through the Coast Guard and TSA, promulgated regulations that require mariners and other individuals granted unescorted access to secure areas of MTSA-regulated vessels or facilities to undergo a security threat assessment by TSA and obtain a TWIC.
2
This rulemaking, which would require owners and operators of certain types of vessels and facilities to use electronic TWIC readers, is necessary to advance the goals of the TWIC program. This rulemaking applies only to MTSA-regulated vessels and facilities. As described more fully below in this Executive Summary, we conducted a risk-based analysis of MTSA-regulated vessels and facilities to categorize them into one of three risk groups. Risk Group A is comprised of vessels and facilities that present the highest risk of being involved in a transportation security incident (TSI).
3
Vessels and facilities in Risk Group A would have new TWIC reader requirements under this rule. Vessels and facilities in Risk Groups B and C present progressively lower risks, and would continue to follow existing regulatory requirements for visual TWIC inspection.
1
Public Law 107-295, 116 Stat. 2064 (Nov. 2, 2002).
2
Transportation Worker Identification Credential (TWIC) Implementation in the Maritime Sector; Hazardous Materials Endorsement for a Commercial Driver's License, 72 FR 3492 (Jan. 25, 2007).
3
A transportation security incident is a security incident resulting in a significant loss of life, environmental damage, transportation system disruption, or economic disruption in a particular area, as defined in 46 U.S.C. 70101 (49 CFR 1572.103).
The TWIC program, including the proposed TWIC reader requirements in this rule, is an important component of the Coast Guard's multi-layered system of access control requirements and other measures designed to enhance maritime security. Under this multi-layered system, owners and operators of MTSA-regulated vessels or facilities are required to submit for Coast Guard approval a comprehensive security plan detailing the access control and other security policies and procedures implemented on each vessel and facility. Security plans must identify and mitigate vulnerabilities. They accomplish this task by detailing the following items: (1) Security organization of the vessel or facility; (2) personnel training; (3) drills and exercises; (4) records and documentation; (5) response to changes in Maritime Security (MARSEC)
4
Level; (6) procedures for interfacing with other facilities and/or vessels; (7) Declarations of Security; (8) communications; (9) security systems and equipment maintenance; (10) security measures for access control; (11) security measures for restricted areas; (12) security measures for handling cargo; (13) security measures regarding vessel stores and bunkers; (14) security measures for monitoring; (15) security incident procedures; (16) audits and security plan amendments; (17) Security Assessment Reports and other security reports; and (18) TWIC procedures.
5
Coast Guard inspectors conduct routine and unannounced inspections and spot-checks to ensure proper implementation of approved security plans. The multi-layered security system also includes measures that consider broader security issues at U.S. ports and waterways, the coastal zone, the open ocean, and foreign ports.
4
“MARSEC Level” means the level set to reflect the prevailing threat environment to the marine elements of the national transportation system, including ports, vessels, facilities, and critical assets and infrastructure located on or adjacent to waters subject to the jurisdiction of the U.S. (33 CFR 101.105).
5
See
33 CFR 104.405 and 33 CFR 105.405.
The TWIC program's initial requirement on mariners and other individuals to obtain a TWIC provides security benefits in the maritime sector. Prior to this requirement, mariners and other individuals could access secure areas of MTSA-regulated vessels and facilities after presenting any number of identification cards, such as State-issued driver's licenses, mariner credentials, passports, and union identification cards. To detect invalid credentials, it was necessary for security personnel to become familiar with the appearance and security features of every type of acceptable credential. Moreover, since some government-issued credentials are used for purposes other than security, applicants for those credentials do not necessarily submit biographic and biometric information and undergo a security threat assessment or criminal background check. For example, a State-issued driver's license is a generally accepted form of government-issued identification in many places because it: (1) Is laminated or otherwise secure against tampering; (2) bears the individual's name and photograph; and (3) bears the name of the issuing authority. Nonetheless, while issuance of a driver's license is conditioned upon the applicant's successful completion of a course on driving instruction, road test, written test, eye examination, and other criteria specific to driving a motor vehicle, the applicant is not necessarily fingerprinted and screened against law enforcement databases for felony criminal activity or terrorist group affiliation. These are inherent shortcomings of an access control system that would permit access based on a patchwork of generic credentials issued to individuals who have undergone no security screening as a precondition to obtaining those credentials. In contrast, issuance of a TWIC is specifically conditioned on these security-related criteria.
Since April 15, 2009, TWIC has been the single credential used throughout the maritime sector. Accordingly, security personnel only need to become familiar with the appearance and security features of one credential. Moreover, unlike other government-issued credentials, TWIC is specifically designed for maritime transportation security. TWIC's purpose is to promote a vetted maritime workforce by establishing security-related eligibility criteria, and by requiring each TWIC-holder to undergo TSA's security threat assessment as part of the process of applying for and obtaining a TWIC.
While the existing security benefits of the TWIC program are substantial, electronic TWIC readers would provide greater security benefits because the TWIC card is designed to contain several enhanced security features that can only be utilized through the use of an electronic TWIC reader. One of these features is the set of two fingerprint templates from two different fingers embedded in each TWIC card. The Coast Guard is proposing to require the use of electronic TWIC readers, which would match the TWIC-holder's fingerprint to one of the embedded fingerprint templates. An electronic TWIC reader would provide a more reliable form of identity verification than the current visual comparison of the TWIC-holder's face to the photograph on the TWIC. Because a TWIC reader, when properly functioning, engages the security features of the card and cross-references with TSA's Canceled Card List (CCL), which the owner or operator would be required to update at least weekly, it is also more reliable than visual inspection for ensuring that a TWIC is not counterfeit or expired, or has not been reported lost, stolen, damaged, or revoked. When TWIC readers or TWICs are damaged or malfunctioning, the proposed rule would permit owners and operators to revert to visual inspection of the TWICs for 7 days if certain conditions are met.
Despite the enhanced reliability that TWIC readers would offer, not all vessels and facilities face security risks that justify the costs and other burdens that would result from a universal TWIC
reader requirement for all vessels and facilities. Therefore, in this rulemaking, we are considering a phased approach to implementing TWIC reader requirements by proposing such requirements first for vessels and facilities where the risk of harm is expected to be the greatest. We will continue to analyze risk data on MTSA-regulated vessels and facilities and consider whether additional or modified TWIC reader requirements are warranted in future rulemakings.
This Notice of Proposed Rulemaking (NPRM) proposes TWIC reader requirements for MTSA-regulated vessels and facilities that we have determined to present a heightened risk of being involved in a TSI, as described more fully below in Section III.C., “Risk-Based Approach to Categorizing Vessels and Facilities.” The Coast Guard assembled a panel of maritime security subject matter experts from the Coast Guard and TSA to conduct a risk-based analysis of MTSA-regulated vessels and facilities. The panel assessed the distinct types of vessels and facilities using three factors: (1) Maximum consequences to that vessel or facility resulting from a terrorist attack; (2) criticality to the nation's health, economy, and national security; and (3) utility of the TWIC in reducing risk.
For the first factor (maximum consequence resulting from a terrorist attack), we used the Coast Guard's Maritime Security Risk Analysis Model (MSRAM). MSRAM is a terrorism risk-analysis tool the Coast Guard uses to perform risk analysis on Critical Infrastructure and Key Resources (CI/KR) in the maritime domain, given a range of terrorist attack scenarios. The purpose of MSRAM is to capture and rank the security risks facing different types of potential terrorist targets spanning all CI/KR sectors in the nation's ports and on its waterways.
An initial step in the MSRAM process is to calculate the maximum potential consequence resulting from the total loss of a target, factoring in injury and loss of life, economic and environmental impact, symbolic effect, and national security impact. MSRAM then assesses risk for a range of scenarios (each involving a combination of potential terrorist target and method of attack) in terms of threat, vulnerability, and consequence. MSRAM considers the response capability of the owner or operator, local first responders, and Federal agencies to mitigate the consequences of an attack. MSRAM also considers input from Area Maritime Security Committees (AMSCs).
6
6
AMSCs are committees established pursuant to 46 U.S.C. 70112(a)(2)(A). AMSCs are composed of at least seven members having an interest in the maritime security of a specific geographic area. AMSC members may be selected from government, public safety, law enforcement, maritime industry, and other port stakeholders. AMSCs assist in the development, review, and update of formal plans that detail maritime security measures and procedures for ports in a specific geographic area.
See
33 CFR part 103.
For the second factor (criticality to the nation's health, economy, and national security), we considered the impact of the total loss of a vessel or facility beyond the immediate local consequences, taking into account the regional or national impacts on human health, the economy, and national security.
For the third factor (TWIC utility), we considered the utility of the TWIC program in reducing a vessel's or facility's vulnerability to a terrorist attack.
We combined the above three factors and developed an overall risk ranking of vessels and facilities by type. The panel then assigned numerical valued weights to the three factors. In determining the final weights, the panel chose the approach that best reflected its understanding of the maritime environment and TWIC program implementation, the importance of consequences in representing target attractiveness to terrorists, and the panel's expert perspective of risk. The actual numerical valued weights finalized by the panel are Sensitive Security Information (SSI). Finally, the panel calculated the priority scores for each vessel and facility type. At the end of this process, types of vessels and facilities with similar scores were combined into one of three risk groups.
Vessels and facilities that present a heightened risk for being involved in a TSI, Risk Group A, would have new TWIC reader requirements under this rule. For now, vessels and facilities that do not present this heightened risk would either continue to visually inspect TWICs or voluntarily deploy TWIC readers. We believe this approach would implement the TWIC reader program in a targeted manner that enhances the security of MTSA-regulated vessels and facilities without imposing undue burdens.
2. Legal Authority for the Regulatory Action
Under MTSA, the Secretary of Homeland Security (Secretary) is required to issue regulations designed to prevent individuals from entering secure areas of MTSA-regulated vessels or facilities without holding a TWIC or being accompanied by another individual holding a TWIC.
7
As a first step toward implementing that mandate, DHS, through the Coast Guard and TSA, promulgated a rule on January 27, 2007 that requires all maritime workers and other individuals to obtain a TWIC before they are granted unescorted access to secure areas in the maritime sector. We also required owners and operators of MTSA-regulated vessels or facilities to visually inspect the TWICs of individuals seeking access to secure areas at those locations. Additionally, we included alternatives to accommodate instances when an individual cannot present a TWIC because it has been lost, damaged, or stolen. In the January 27, 2007 rule, we did not implement TWIC reader requirements. Instead, we decided that TWIC reader requirements would follow in a separate rule after pilot testing TWIC readers in the maritime sector.
7
46 U.S.C. 70105(a)-(f).
The Security and Accountability For Every (SAFE) Port Act of 2006
8
required the Secretary to conduct a pilot program to test the business processes, technology, and operational impacts of TWIC readers in the maritime environment, and to issue regulations that require the deployment of TWIC readers that are consistent with the findings of the pilot program.
9
8
Public Law 109-347, 120 Stat. 1884 (Oct. 13, 2006).
9
46 U.S.C. 70105(k)(3).
B. Summary of the Major Provisions of the TWIC Reader Advanced Notice of Proposed Rulemaking and This NPRM
On March 27, 2009, the Coast Guard published an advanced notice of proposed rulemaking on TWIC reader requirements (ANPRM).
10
The ANPRM proposed a risk-based approach to TWIC reader requirements. First, the ANPRM proposed to classify MTSA-regulated vessels and facilities into one of three risk groups, based on specific factors related to TSI consequence. Second, the ANPRM proposed TWIC reader requirements for vessels and facilities in the two highest risk groups (Risk Groups A and B). For the lowest risk group (Risk Group C), the ANPRM proposed visual TWIC inspection requirements instead of TWIC reader requirements because we determined that routine electronic biometric matching using TWIC readers would not be practical at lower risk vessels and facilities. This is consistent with the understanding that TWIC readers constitute one component
of a multi-layered maritime security system, but are not necessary or appropriate for every vessel or facility.
10
Transportation Worker Identification Credential (TWIC)—Reader Requirements, 74 FR 13360 (March 27, 2009).
Based on the public comments received in response to the ANPRM, the findings of the DHS pilot program, and further analysis of the relevant issues, this NPRM reiterates many of the ANPRM's proposals, including retaining the ANPRM's risk-based framework for classifying vessels and facilities into the same three risk groups. As in the ANPRM, vessels and facilities are generally placed in higher risk groups based on the hazardous nature of the cargo handled or carried, or an increase in the number of passengers present. Our analysis demonstrates that it is necessary to maximize the use of the TWIC's security features where the risk is highest, as described more fully below in Section III.C., “Risk-Based Approach to Categorizing Vessels and Facilities.” We also believe it is necessary to carefully weigh the costs and benefits of TWIC reader requirements on the regulated population.
The main change in approach from the ANPRM to this NPRM is regarding the TWIC reader requirements for the different risk groups. Specifically, this NPRM proposes TWIC reader requirements for Risk Group A only. For Risk Groups B and C, this NPRM proposes to maintain the existing visual TWIC inspection requirements instead of TWIC reader requirements. This approach is designed to target the use of TWIC readers at the highest risk entities while minimizing the overall burden of the rule. Proposing TWIC reader requirements for Risk Group A only in this NPRM is indicative of our desire to minimize highest risks first, but should not be read to foreclose revised TWIC reader requirements in the future. We will continue to gather and analyze data to determine how the use of TWIC readers might be appropriate for each risk group. Any future changes will be made through rulemaking and the public will have an opportunity to comment.
This NPRM also proposes a requirement for owners and operators using TWIC readers to maintain records on each individual granted unescorted access to a secure area. Owners and operators would be required to maintain such records for a period of 2 years. Additionally, this NPRM proposes requirements to amend security plans to incorporate TWIC reader requirements for vessels and facilities in the highest risk group. These provisions are designed to ensure that owners and operators of vessels or facilities in Risk Group A comply with TWIC reader requirements.
Table ES-1—Summary of Requirements/Provisions Proposed in This NPRM
Proposed requirement or provision
Vessels
(33 CFR part 104)
Facilities
(33 CFR part 105)
OCS Facilities
(33 CFR part 106)
Risk Group A classification
Vessels that carry CDC in bulk
Facilities that handle CDC in bulk
Not applicable.
Vessels certificated to carry more than 1,000 passengers
Facilities that receive vessels certificated to carry more than 1,000 passengers.
Vessels towing one of the above
Barge fleeting facilities that receive barges carrying CDC in bulk.
Risk Group B classification
Vessels that carry hazardous materials other than CDC in bulk
Facilities that receive Risk Group B vessels
All OCS facilities.
Vessels that carry flammable or combustible liquid cargoes.
Vessels certificated to carry 500-1,000 passengers.
Vessels towing one of the above.
Risk Group C classification
Vessels that carry non-hazardous cargoes
Facilities that receive Risk Group C vessels
Not applicable.
Vessels certificated to carry less than 500 passengers.
Vessels towing one of the above.
MODUs and OSVs.
Movement between risk groups
Vessels are permitted to move between risk groups based on the materials carried at a given time. Described in VSP
Facilities are permitted to move between risk groups based on the materials handled at a given time. Described in FSP
Not applicable.
Visual TWIC inspection requirement
Risk Groups B and C perform identity verification, card authentication, and card validation by visual TWIC inspection for each individual prior to being granted unescorted access to secure areas
Risk Groups B and C perform identity verification, card authentication, and card validation by visual TWIC inspection for each individual prior to being granted unescorted access to secure areas
Risk Groups B performs identity verification, card authentication, and card validation by visual TWIC inspection for each individual prior to being granted unescorted access to secure areas.
TWIC reader requirement
Risk Group A must use TWIC reader with biometric check for identity verification, card authentication, and card validation on each individual prior to being granted unescorted access to secure areas
Risk Group A must use TWIC reader with biometric check for identity verification, card authentication, and card validation on each individual prior to being granted unescorted access to secure areas
No requirement.
TWIC reader exemption based on minimum crew size
Vessels with 14 or fewer TWIC-holding crew are exempt
No exemption
Not applicable.
Physical placement of TWIC readers
Vessel access points only
Access points to each secure area
Not applicable.
Unreadable fingerprints
Exception handling process may include PIN or alternate biometric
Exception handling process may include PIN or alternate biometric
Not applicable.
TWIC reader malfunction
Owner or operator performs visual TWIC inspection. Individuals that have been granted unescorted access with a valid TWIC in the past may still be granted such access for up to 7 days (with the possibility of an additional extension at the COTP's discretion)
Owner or operator performs visual TWIC inspection. Individuals that have been granted unescorted access with a valid TWIC in the past may still be granted such access for up to 7 days (with the possibility of an additional extension at the COTP's discretion)
Not applicable.
Recordkeeping
Records on each individual whose TWIC was scanned using a TWIC reader must be kept for 2 years
Records on each individual whose TWIC was scanned using a TWIC reader must be kept for 2 years
Not applicable.
Lost/stolen TWIC
Individuals following prescribed procedures may be granted unescorted access for no longer than 7 consecutive days. (Additional 30-day extension may be granted per Coast Guard guidance.)
Individuals following prescribed procedures may be granted unescorted access for no longer than 7 consecutive days. (Additional 30-day extension may be granted per Coast Guard guidance.)
Individuals following prescribed procedures may be granted unescorted access for no longer than 7 consecutive days. (Additional 30-day extension may be granted per Coast Guard guidance.)
Compliance deadline
2 years after final rule publication
2 years after final rule publication
Not applicable. Existing regulations apply.
C. Summary of Costs and Benefits
Under MTSA, the Coast Guard regulates approximately 13,825 vessels, 3,270 facilities, and 56 Outer Continental Shelf (OCS) facilities. Of those MTSA-regulated facilities that could have potentially been regulated, 38 vessels and 532 facilities are affected by this proposed rule. We estimate the annualized cost of this proposed rule on the affected population of 38 vessels and 532 facilities to be about $26.5 million, while the 10-year cost is $186.1 million, discounted at 7 percent. The main cost drivers of this proposal are the acquisition, installation, and integration of TWIC readers into access control systems. Annual costs would be driven by costs associated with Canceled Card List updates, recordkeeping, training, system maintenance, and opportunity costs associated with failed TWIC reader transactions. We account for delays of up to two minutes for failed TWIC reader transactions. We estimate that 5% of TWIC-holders who access Risk Group A facilities and vessels will need to replace their TWICs annually, also contributing to the annual costs of this rule.
The benefits of this proposed rule include the enhancement of the security of vessels, ports, and other facilities by ensuring that only individuals who hold TWICs are granted unescorted access to secure areas at those locations. TWIC readers will not help identify valid cards that were obtained via fraudulent means, e.g., through unreported theft or the use of fraudulent IDs. Further, if the Coast Guard becomes aware of an imminent threat to a facility or vessel, the Coast Guard will notify the relevant Captain of the Port and other Federal, state, and local law enforcement officials and implement additional security measures as appropriate as a part of DHS's layered approach to security. This proposed rule would also implement the MTSA transportation security card requirement, as well as the SAFE Port Act of 2006 electronic TWIC reader requirements. The main benefit of this regulation, decreased terrorism risk, cannot be quantified given current data limitations.
Table ES-2—Estimated Costs and Functional Benefits of TWIC Reader Requirements
11
Category
NPRM
Applicability
High risk MTSA-regulated facilities and high risk MTSA-regulated vessels with greater than 14 crew.
Affected Population
38 vessels.
532 facilities.
Costs ($ millions, 7% discount rate)
$26.5 (annualized).
$186.1 (10-year).
Costs (Qualitative)
Time to retrieve or replace lost PINs for use with TWIC cards.
Benefits (Qualitative)
Standardization of access control and credential verification throughout industry.
Enhanced access control and security at U.S. maritime facilities and onboard U.S. flagged vessels.
Reduction of human error when checking identification and manning access points.
We used a
risk-based approach to apply these regulatory requirements on less than 5 percent of the MTSA-regulated population, which represents approximately 80 percent of the potential consequences of a TSI. A discussion of our risk-based approach is provided below in Section III.C., “Risk-Based Approach to Categorizing Vessels and Facilities.” For a more detailed discussion of the methodology underpinning our risk-based approach, please refer to the Coast Guard report, “Analysis of Transportation Worker Identification Credential (TWIC) Electronic Reader Requirements in the Maritime Sector,” which is available for viewing in the public docket for this rulemaking. The proposals in this NPRM target the highest risk entities while minimizing the overall burden of the rule. Furthermore, we propose several types of relief in an effort to minimize the possible burden on the regulated population.
11
For a more detailed discussion of costs and benefits, see the full Preliminary Regulatory Analysis and Initial Regulatory Flexibility Analysis available on the docket for this rulemaking. Appendix G of that document outlines the costs by provision and also discusses the complementary nature of the provisions and the subsequent difficulty in distinguishing independent benefits from individual provisions.
III. Background and Purpose
This section provides a detailed discussion of the considerations and rationale for the policy decisions that informed this NPRM. The section that follows (Section IV.) sets forth the NPRM's proposals.
Section III.A. provides a general description of the TWIC and its security features, and also explains how the TWIC is used in the maritime sector as an access control measure.
Section III.B. discusses the statutory basis for this rulemaking, and summarizes the regulatory history of the TWIC program. The Coast Guard's most recent TWIC-related regulatory action is the ANPRM on TWIC reader requirements.
Section III.C. describes the ANPRM's risk-based approach for evaluating and categorizing types of vessels and facilities into risk groups. In doing so, this section summarizes the factors considered in developing the ANPRM's categorization system.
Section III.D. summarizes the ANPRM's proposals for TWIC reader requirements and other TWIC-related requirements for each risk group.
Section III.E. provides a detailed discussion of the public comments received during the ANPRM's comment period and public meeting. Section III.E. also provides our responses to those comments.
Sections III.F., III.G., III.H., and III.I. discuss DHS's TWIC Reader Pilot Program on TWIC reader functionality, the Homeland Security Institute's report on the ANPRM's risk group classification system, additional data sources, and Advisory Committee input in the rulemaking process, respectively.
A. General Information About the Transportation Worker Identification Credential
This section provides a general description of the types of vessels and facilities currently covered under MTSA, the TWIC and its security features, and also explains how the TWIC is currently used in the maritime sector for access control.
Under MTSA, the Coast Guard is authorized to regulate vessels and facilities. For purposes of MTSA, the term “facility” means “any structure or facility of any kind located in, on, under, or adjacent to any waters subject to the jurisdiction of the United States.”
12
For purposes of MTSA, the term “vessel” includes “every description of watercraft or other artificial contrivance used, or capable of being used, as a means of transportation on water.”
13
12
46 U.S.C. 70101(a)(2).
13
46 U.S.C. 115; 1 U.S.C. 3.
Coast Guard regulations implementing MTSA with respect to vessels
14
apply to: Mobile Offshore Drilling Units (MODUs), cargo vessels, or passenger vessels subject to International Convention for Safety of Life at Sea, 1974 (SOLAS), chapter XI-1 or Chapter XI-2; foreign cargo vessels greater than 100 gross register tons; generally, self-propelled U.S. cargo vessels greater than 100 gross tons; offshore supply vessels; vessels subject to the Coast Guard's regulations regarding passenger vessels; passenger vessels certificated to carry more than 150 passengers; passenger vessels carrying more than 12 passengers engaged on an international voyage; barges carrying, in bulk, cargoes regulated under the Coast Guard's regulations regarding tank vessels or Certain Dangerous Cargoes (CDCs);
15
barges carrying CDCs or cargo and miscellaneous vessels engaged on an international voyage; tankships; and generally, towing vessels greater than eight meters in register length engaged in towing barges.
14
See
33 CFR 104.105.
15
The term “Certain Dangerous Cargoes” is defined in 33 CFR 101.105 by reference to 33 CFR 160.204, which lists all of the covered substances.
Coast Guard regulations implementing MTSA with respect to facilities
16
apply to: Waterfront facilities handling dangerous cargoes (as generally defined in 49 CFR parts 170 through 179); waterfront facilities handling liquefied natural gas and liquefied hazardous gas; facilities transferring oil or hazardous materials in bulk; facilities that receive vessels certificated to carry more than 150 passengers; facilities that receive vessels subject to SOLAS, Chapter XI; facilities that receive foreign cargo vessels greater than 100 gross register tons; generally, facilities that receive U.S. cargo and miscellaneous vessels greater than 100 gross register tons; barge fleeting facilities that receive barges carrying, in bulk, cargoes regulated under the Coast Guard's regulations regarding tank vessels or CDCs; and fixed or floating facilities operating on the OCS for the purposes of engaging in the exploration, development, or production of oil, natural gas, or mineral resources (OCS facilities).
16
See
33 CFR 105.105 and 106.105.
This rulemaking applies to the above-described vessels and facilities regulated by the Coast Guard pursuant to the authority granted in MTSA. The TWIC program is one component of the Coast Guard's multi-layered system of access control requirements and other measures designed to enhance maritime security. Under this multi-layered system, owners and operators of MTSA-regulated vessels or facilities are required to submit for Coast Guard approval a comprehensive security plan detailing the access control and other security policies and procedures implemented on each vessel and facility. Security plans must identify and mitigate vulnerabilities. They accomplish this task by detailing the following items: (1) Security organization of the vessel or facility; (2) personnel training; (3) drills and exercises; (4) records and documentation; (5) response to changes in Maritime Security (MARSEC) Level; (6) procedures for interfacing with other facilities and/or vessels; (7) Declarations of Security; (8) communications; (9) security systems and equipment maintenance; (10) security measures for access control; (11) security measures for restricted areas; (12) security measures for handling cargo; (13) security measures regarding vessel stores and bunkers; (14) security measures for monitoring; (15) security incident procedures; (16) audits and security plan amendments; (17) Security Assessment Reports and other security
reports; and (18) TWIC procedures.
17
Coast Guard inspectors conduct routine and unannounced inspections and spot-checks to ensure proper implementation of approved security plans. The multi-layered security system also includes measures that consider broader security issues at U.S. ports and waterways, the coastal zone, the open ocean, and foreign ports.
17
See
33 CFR 104.405 and 33 CFR 105.405.
The TWIC is a tamper-resistant biometric credential TSA issues to eligible maritime workers who require unescorted access to secure areas of MTSA-regulated vessels and facilities. To obtain a TWIC, applicants must provide biographic and biometric information and complete a TSA security threat assessment. Applicants are disqualified from obtaining a TWIC if their assessment reveals that they: have been convicted, or found not guilty by reason of insanity, of certain felonies;
18
are under want, warrant, or indictment for certain felonies;
19
have been released from incarceration within the preceding 5-year period for committing certain felonies;
20
may be denied admission to, or removed from, the United States under the Immigration and Nationality Act;
21
or otherwise pose a terrorism security risk to the United States.
22
18
46 U.S.C. 70105(c)(1)(A)-(B).
19
46 U.S.C. 70105(c)(1)(C).
20
46 U.S.C. 70105(c)(1)(D)(i).
21
46 U.S.C. 70105(c)(1)(D)(iii); 8 U.S.C. 1101
et seq.
22
46 U.S.C. 70105(c)(1)(D)(iv).
The face of the TWIC shows the holder's photograph, name, and TWIC expiration date, and the back shows a unique credential number (TWIC Serial Number). Because TWIC is the single credential used throughout the maritime sector, it provides considerable security benefits, including ensuring that individuals permitted to enter secure areas within the maritime transportation system have successfully undergone TSA's security threat assessment, involving a criminal history records check and an intelligence-related check. Before TWIC was in use, mariners and other individuals could access secure areas of MTSA-regulated vessels and facilities after presenting a State-issued driver's license or any number of other government-issued identification cards. To detect invalid credentials, it was necessary for security personnel to become familiar with the appearance and security features of every type of acceptable credential. Moreover, since some government-issued credentials are used for purposes other than security, applicants for those credentials do not necessarily submit biographic and biometric information and undergo a security threat assessment or criminal background check. For example, a State-issued driver's license is a generally accepted form of government-issued identification in many places because it: (1) Is laminated or otherwise secure against tampering; (2) bears the individual's name and photograph; and (3) bears the name of the issuing authority. Nonetheless, while issuance of a driver's license is conditioned upon the applicant's successful completion of a course on driving instruction, road test, written test, eye examination, and other criteria specific to driving a motor vehicle, the applicant is not necessarily fingerprinted and screened against law enforcement databases for felony criminal activity or terrorist group affiliation. These are inherent shortcomings of an access control system that would permit access based on a patchwork of generic credentials issued to individuals who have undergone no security screening as a precondition to obtaining those credentials. In contrast, issuance of a TWIC is specifically conditioned on these security-related criteria.
Since April 15, 2009, TWIC has been the single credential used throughout the maritime sector. Accordingly, security personnel only need to become familiar with the appearance and security features of one credential. Moreover, unlike other government-issued credentials, TWIC is specifically designed for transportation security. Its purpose is to ensure a vetted maritime workforce by establishing security-related eligibility criteria, and by requiring each TWIC-holder to undergo TSA's security threat assessment as part of the process of applying for and obtaining a TWIC.
In addition to its visible security features, the TWIC stores two electronically readable reference biometric templates (i.e., fingerprint templates), a personal identification number (PIN) selected by the TWIC-holder, a digital facial image, authentication certificates, and a Federal Agency Smart Credential-Number (FASC-N). These features enable the TWIC to be used in different ways for: (1) Identity verification; (2) card authentication; and (3) card validation.
Identity verification ensures that the individual presenting the TWIC is the same person to whom the TWIC was issued. Identity can be verified by visually comparing the photo on the TWIC to the TWIC-holder. Using a TWIC reader, identity can be verified by matching one of the fingerprint templates stored in the TWIC to the TWIC-holder's live sample biometric, or by requiring the TWIC-holder to place the TWIC into a TWIC reader and enter a 6-, 7-, or 8-digit PIN selected by the TWIC-holder at the time of card activation.
Card authentication ensures that the TWIC is not counterfeit. Security personnel can authenticate a TWIC by visually inspecting the security features on the card. A TWIC reader authenticates the card by performing a challenge/response protocol using the Card Authentication Certificate (CAC) and the associated card authentication private key stored in the TWIC.
23
23
The TWIC reader will read the CAC from the TWIC and send a command to the TWIC requesting the card authentication private key be used to sign a random block of data (created and known to the TWIC reader). The TWIC reader will use the public key embedded in the CAC to verify that the signature of the random data block is valid. If the signature is valid, the TWIC reader will trust the TWIC submitted and will then pull the FASC—N and other information from the card for further processing. The CAC contains the FASC—N and a certificate of expiration date harmonized to the TWIC expiration date. This minimizes the need for the TWIC reader to pull more information from the TWIC (unless required for additional checking).
Card validation using a TWIC reader ensures that the TWIC has not expired or been revoked by TSA, or reported as lost, stolen, or damaged. Security personnel can validate whether a TWIC has expired by visually checking the TWIC's expiration date. A TSA-canceled TWIC is placed on TSA's official Canceled Card List (CCL), which is updated daily.
24
Using a TWIC reader, card validity is confirmed by finding no match on the CCL and electronically checking the expiration date on the TWIC. Checks against the CCL may be performed electronically by downloading the list onto a TWIC reader or integrated Physical Access Control System (PACS).
24
TSA's Canceled Card List is available online at:
https://twicprogram.tsa.dhs.gov/TWICWebApp.
B. Statutory and Regulatory History
This section discusses the statutory basis for this rulemaking, and summarizes the TWIC-related regulatory actions that precede this NPRM.
In the aftermath of the September 11, 2001 attacks, President George W. Bush signed Public Law 107-295, MTSA, 2002, which required the Secretary to publish rules that institute measures for the protection of U.S. maritime security as soon as practicable. On July 1, 2003, the Coast Guard published a series of six rules to promulgate maritime security requirements mandated by MTSA. These rules included the following ones: Implementation of National Maritime Security Initiatives (68 FR
39240); Area Maritime Security (68 FR 39284); Vessel Security (68 FR 39292); Facility Security (68 FR 39315); Outer Continental Shelf Facility Security (68 FR 39338); and Automatic Identification System (68 FR 39353). Most of these rules have been codified in 33 CFR subchapter H.
MTSA is the principal statutory authority for the TWIC program, and it requires the Secretary to issue regulations designed to prevent an individual from entering secure areas of MTSA-regulated vessels or facilities unless the individual holds a TWIC or is accompanied by another individual who holds a TWIC.
25
25
46 U.S.C. 70105(a)-(f).
On May 22, 2006, DHS, through the Coast Guard and TSA, published a notice of proposed rulemaking
26
(TWIC 1 NPRM) to implement the TWIC program in the maritime sector. On January 27, 2007, DHS, through the Coast Guard and TSA, issued a final rule
27
(TWIC 1 Final Rule) that required all credentialed merchant mariners and individuals granted unescorted access to secure areas of MTSA-regulated vessels or facilities to obtain a TWIC. Based on comments received in response to the TWIC 1 NPRM, and upon further analysis of the information available at the time, the Coast Guard concluded in the TWIC 1 Final Rule that it was premature to require the use of TWIC readers on vessels and at facilities.
28
The TWIC 1 Final Rule, however, stated that TWIC reader requirements would be addressed in a future rulemaking.
29
To date, TSA has issued approximately 2 million TWICs.
30
TWIC is now the single credential used throughout the maritime sector. For purposes of access control to MTSA-regulated vessels and facilities, security personnel only need to become familiar with the appearance and security features of one credential when determining whether to grant access to secure areas. Moreover, since the TWIC program is specifically designed for transportation security, it effectively ensures a vetted maritime workforce by establishing security-related eligibility criteria and by requiring each TWIC-holder to undergo TSA's security threat assessment as a precondition to obtaining a TWIC.
26
Transportation Worker Identification Credential (TWIC) Implementation in the Maritime Sector; Hazardous Materials Endorsement for a Commercial Driver's License, 71 FR 29396 (May 22, 2006).
27
Transportation Worker Identification Credential (TWIC) Implementation in the Maritime Sector; Hazardous Materials Endorsement for a Commercial Driver's License, 72 FR 3492 (Jan. 25, 2007).
28
See
72 FR 3512.
29
See
72 FR 3512.
30
For statistics and other general information about the TWIC program, visit the TSA Web site at
http://www.tsa.gov/twic.
Section 104 of the SAFE Port Act of 2006 focused on how to further incorporate TWIC and TWIC readers into the MTSA security regime. Specifically, the SAFE Port Act supplemented various MTSA credentialing requirements by, among other things, requiring the Secretary to: (1) Conduct a TWIC reader testing pilot program (TWIC Pilot) to evaluate the business processes, technology, and operational impacts of a TWIC reader requirement;
31
and (2) promulgate final regulations requiring the use of TWIC readers in a manner consistent with the findings of the TWIC Pilot.
32
31
46 U.S.C. 70105(k)(1).
32
46 U.S.C. 70105(k)(3).
While DHS collected data for the TWIC Pilot, the Coast Guard published the ANPRM on March 27, 2009, discussing the Coast Guard's preliminary thoughts on potential TWIC reader requirements, and opening a public dialog on how to best implement those requirements. The ANPRM proposed a framework that would separate individual MTSA-regulated vessels, MTSA-regulated facilities, and MTSA-regulated OCS facilities into one of three risk groups. Vessels and facilities are generally placed in higher risk groups based on the hazardous nature of the cargo handled or carried, or an increase in the number of passengers present. This framework is described more fully below in Section III.C., “Risk-Based Approach to Categorizing Vessels and Facilities.” The ANPRM proposed TWIC reader requirements for vessels and facilities in Risk Groups A and B, the two highest risk groups. For Risk Group C, the ANPRM proposed visual TWIC inspection requirements instead of TWIC reader requirements because we determined that the frequent electronic matching of a biometric would not be practical at lower risk vessels and facilities. This is consistent with the understanding that TWIC readers constitute one component of a multi-layered maritime security system, but are not necessary or appropriate for every vessel or facility.
Based on the public comments received in response to the ANPRM, the TWIC Pilot findings, and further analysis of the relevant issues, this NPRM reiterates many of the ANPRM's proposals, including retaining the ANPRM's risk-based framework for classifying vessels and facilities into the same three risk groups. Our analysis demonstrates that it is necessary to maximize the use of the TWIC's security features where the risk is highest, as described more fully below in Section III.C., “Risk-Based Approach to Categorizing Vessels and Facilities.” We also believe it is necessary to carefully weigh the costs and benefits of TWIC reader requirements on the regulated population.
The primary change in approach from the ANPRM to this NPRM is regarding the TWIC reader requirements for the different risk groups. Specifically, this NPRM proposes TWIC reader requirements for Risk Group A only. For Risk Groups B and C, this NPRM proposes to maintain the existing visual TWIC inspection requirements instead of TWIC reader requirements. This approach is designed to target the use of TWIC readers at the highest risk entities while minimizing the overall burden of the rule. Proposing TWIC reader requirements for Risk Group A only in this NPRM is indicative of our desire to minimize highest risks first, but should not be read to foreclose revised TWIC reader requirements in the future. We will continue to gather and analyze data to determine how the use of TWIC readers might be appropriate for each risk group. Any future changes will be made through rulemaking and the public will have an opportunity to comment.
The Coast Guard Authorization Act of 2010 (Pub. L. 111-281) (CGAA 2010) contains two provisions we refer to into this rulemaking. First, Section 809 of the CGAA 2010 authorizes the Secretary to exempt any credentialed mariner who is not granted unescorted access to secure areas of a vessel from the requirement to possess a TWIC. Second, Section 814 of the CGAA 2010 allows the Secretary to permit the use of alternate biometrics, such as a retina scan, to verify the identification of individuals using TWIC when the individual's fingerprints are not able to be taken or read.
C. Risk-Based Approach to Categorizing Vessels and Facilities
This section describes the ANPRM's risk-based approach for evaluating and categorizing types of vessels and facilities into risk groups.
The Coast Guard assembled a panel of maritime security subject matter experts from the Coast Guard and TSA to conduct a risk-based analysis of MTSA-regulated vessels and facilities. The panel determined that the Analytical Hierarchy Process (AHP) would provide an effective basis for applying the panel's judgment to weigh and apply several key factors to the assessment of types of vessels and facilities. The AHP
is the core methodology in the Expert Choice
33
collaborative decision support tool, which was used in the Coast Guard's risk-based analysis. The AHP was originally developed in the 1970s by Dr. Thomas Saaty, then a professor at the Wharton School, University of Pennsylvania. The methodology has since gained wide acceptance and is used by Fortune 500 companies, Federal agencies, and MBA programs as a structured technique for achieving solutions to complex problems. Federal agencies that have used the AHP/Expert Choice include the National Institute of Standards and Technology, Department of the Army, Department of the Air Force, Bureau of Land Management, Bureau of Engraving and Printing, Department of Agriculture, Department of Energy, Department of Housing and Urban Development, Department of State, Defense Information Systems Agency, Department of Veterans Affairs, and the Federal Aviation Administration.
33
Information about Expert Choice is available at
www.expertchoice.com.
The AHP provides a comprehensive and rational framework for structuring a problem, representing and quantifying its elements, relating those elements to overall goals, and for evaluating a set of alternative solutions. The AHP has been used by government and industry to assess alternatives and arrive at solutions when faced problems that present disparate criteria and factors to consider.
The Coast Guard's panel of subject matter experts identified 68 distinct types of vessels and facilities based on their purpose or operational description. The panel then assessed each of the 68 types of vessels and facilities using three factors: (1) Maximum consequences to that vessel or facility resulting from a terrorist attack; (2) criticality to the nation's health, economy, and national security; and (3) utility of the TWIC in reducing risk.
For the first factor (maximum consequence resulting from a terrorist attack), we used the Coast Guard's Maritime Security Risk Analysis Model (MSRAM). MSRAM is a terrorism risk-analysis tool the Coast Guard uses to perform risk analysis on Critical Infrastructure and Key Resources (CI/KR) in the maritime domain, given a range of terrorist attack scenarios. The purpose of MSRAM is to capture and rank the security risks facing different types of potential terrorist targets (e.g., waterfront facilities, vessels, bridges, and other infrastructure) spanning all CI/KR sectors in the nation's ports and on its waterways.
An initial step in the MSRAM process is to calculate the maximum potential consequence resulting from the total loss of a target, factoring in injury and loss of life, economic and environmental impact, symbolic effect, and national security impact. MSRAM then assesses risk for a range of scenarios (each involving a combination of potential terrorist target and method of attack) in terms of threat, vulnerability, and consequence. MSRAM considers the response capability of the owner or operator, local first responders, and Federal agencies to mitigate the consequences of an attack. MSRAM also considers input from Area Maritime Security Committees (AMSCs).
34
34
AMSCs are committees established pursuant to 46 U.S.C. 70112(a)(2)(A). AMSCs are composed of at least seven members having an interest in the maritime security of a specific geographic area. AMSC members may be selected from government, public safety, law enforcement, maritime industry, and other port stakeholders. AMSCs assist in the development, review, and update of formal plans that detail maritime security measures and procedures for ports in a specific geographic area.
See
33 CFR part 103.
In consultation with representatives from AMSCs throughout the country, we have compiled MSRAM risk information from Coast Guard Sectors and Captains of the Port (COTPs) into a database that provides an overall national view of terrorism risk to maritime assets. For purposes of this proposed rule, we focused on MSRAM data specific to MTSA-regulated vessels and facilities, and used it to address the maximum consequence that would occur from the total loss of a vessel or facility caused by a TSI resulting from a terrorist attack. We averaged these MSRAM consequences across similar types of vessels and facilities to develop a standard risk for each type.
For the second factor (criticality to the nation's health, economy, and national security), we considered the impact of the total loss of a vessel or facility beyond the immediate local consequences, taking into account the regional or national impacts on human health, the economy, and national security.
For the third factor (TWIC utility), we considered the utility of the TWIC program in reducing a vessel or facility's vulnerability to a terrorist attack.
Using the AHP, we combined the above three factors and developed an overall risk ranking of vessels and facilities by type. As a first step in this process, the panel identified the 68 vessel and facility types, and the three criteria described above. As a second step, the panel considered different approaches to assigning numerical valued weights to the three factors. In determining the final weights, the panel chose the approach that best reflected its understanding of the maritime environment and TWIC program implementation, the importance of consequences in representing target attractiveness to terrorists, and the panel's expert perspective of risk. The actual numerical valued weights finalized by the panel are SSI. Finally, the panel used the AHP math in Expert Choice to calculate the priority scores for each vessel and facility type. At the end of this process, types of vessels and facilities with similar scores were combined into one of three risk groups. For a more detailed discussion of the panel's methodology, a copy of the panel's report, “Analysis of Transportation Worker Identification Credential (TWIC) Electronic Reader Requirements in the Maritime Sector” is available for viewing in the public docket for this rulemaking.
The ANPRM then proposed different TWIC-related requirements for each risk group. In determining the cutoff points between risk groups, risk rankings were graphed to identify natural breaks that occurred in the data. For vessels, these breaks generally occurred where there was a change in the hazardous nature of the cargo or where the number of passengers carried aboard a vessel increased. Similarly, for facilities, these breaks generally occurred where there was a change in the hazardous nature of the materials stored or handled at a facility, or where the number of passengers accessing a facility increased.
We engaged the Homeland Security Institute (HSI) to conduct an independent peer review of the risk-based analysis that formed the basis of the proposals in the ANPRM. HSI conducted its peer review in accordance with OMB Memorandum M-05-03, “Issuance of OMB's `Final Information Quality Bulletin for Peer Review'” (Dec. 16, 2004)
35
(OMB Review Guidelines). The OMB Review Guidelines establish government-wide guidance aimed at enhancing the practice of peer review of government science documents. Peer review is designed to increase the quality and credibility of the scientific information generated across the Federal government. The OMB Review Guidelines also discuss the concept of a “highly influential scientific assessment,” as one that would have at least one of the following characteristics: (1) Potential impact of
more than $500 million in any year; (2) novel, controversial, or precedent-setting; or (3) significant interagency interest. HSI advised that the TWIC program is, at a minimum, precedent-setting. Therefore, peer review of the Coast Guard's underlying analysis would be considered at the level of a “highly influential scientific assessment.”
35
OMB Memorandum M-05-03
is available for viewing at
http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2005/m05-03.pdf.
HSI conducted its peer review and issued a final report (HSI Report) on October 21, 2008. HSI independently reproduced the results based on the information provided in the Coast Guard report, “Analysis of Transportation Worker Identification Credential (TWIC) Electronic Reader Requirements in the Maritime Sector,” and deemed the process to be technically sound. The HSI report also acknowledged that “no decision-aid tools * * * including the AHP, should be considered to lead to unassailable results.”
36
A portion of the HSI Report is considered Sensitive Security Information (SSI) under 49 CFR Part 15. Therefore, a non-SSI version of the HSI Report is available for viewing in the public docket for this rulemaking. A summary of the HSI Report recommendations is provided below in Section III.G. “HSI Report.”
36
See
HSI Report, p. 2.
D. ANPRM Proposals
This section provides a summary of the ANPRM's proposals for TWIC reader requirements and other TWIC-related requirements. Later parts of Section III. “Background and Purpose” discuss the public comments received on the ANPRM, as well our responses to those comments. For a more detailed discussion of the ANPRM's proposals, please refer to the ANPRM at 74 FR 13360. We retain many of the ANPRM's proposals in the NPRM. We delete or modify a number of the ANPRM's proposals in the NPRM. To avoid any confusion, if you wish to focus specifically on the proposals in the NPRM, please refer to Section IV. “Section-by-Section Description of Proposed Rule.”
1. Classification of Vessels and Facilities Into Risk Groups
For vessels subject to 33 CFR part 104, the ANPRM proposed the following risk group classifications:
Risk Group A
(1) Vessels that carry Certain Dangerous Cargoes (CDC) in bulk;
(2) Vessels certificated to carry more than 1,000 passengers; and
(3) Towing vessels engaged in towing a barge or barges subject to paragraphs (1) or (2).
Risk Group B
(1) Vessels that carry hazardous materials other than CDC in bulk;
(2) Vessels subject to 46 CFR Chapter I, Subchapter D, that carry any flammable or combustible liquid cargoes or residues;
37
37
The intent as used here is to capture those tank vessels that are carrying the high flash point petroleums, like crude oil, that are not hazardous materials, whether inland, coastal, or seagoing.
(3) Vessels certificated to carry 500 to 1,000 passengers; and
(4) Towing vessels engaged in towing a barge or barges subject to paragraphs (1), (2), or (3).
Risk Group C
(1) Vessels carrying non-hazardous cargoes that are required to have a vessel security plan (VSP);
(2) Vessels certificated to carry less than 500 passengers;
(3) Towing vessels engaged in towing a barge or barges subject to paragraphs (1) or (2);
(4) Mobile Offshore Drilling Units (MODUs); and
(5) Offshore Supply Vessels (OSVs) subject to 46 CFR Chapter I, Subchapters L or I.
The risk group classifications in the ANPRM for facilities are similar to those for vessels. For facilities subject to 33 CFR part 105, the ANPRM proposed the following risk group classifications:
Risk Group A
(1) Facilities that handle CDC in bulk;
(2) Facilities that receive vessels certificated to carry more than 1,000 passengers; and
(3) Barge fleeting facilities that receive barges carrying CDC in bulk.
Risk Group B
(1) Facilities that receive vessels that carry hazardous materials other than CDC in bulk;
(2) Facilities that receive vessels subject to 46 CFR Chapter I, Subchapter D, that carry any flammable or combustible liquid cargoes or residues;
(3) Facilities that receive vessels certificated to carry 500 to 1,000 passengers; and
(4) Facilities that receive towing vessels engaged in towing a barge or barges carrying hazardous materials other than CDC in bulk, carrying crude oil, or towing vessels certificated to carry 500 to 1,000 passengers.
Risk Group C
(1) Facilities that receive vessels carrying non-hazardous cargoes that are required to have a VSP;
(2) Facilities that receive towing vessels engaged in towing a barge or barges carrying non-hazardous cargoes;
(3) Facilities that receive vessels certificated to carry less than 500 passengers.
The ANPRM proposed to classify all OCS facilities subject to 33 CFR part 106 into Risk Group B.
In the ANPRM, we contemplated the possibility that vessels and facilities may move from one risk group to another, based on the cargo handled or carried at any given time. In those instances, the owner or operator would be expected to explain, in an amended security plan, how their regulatory compliance program would change to reflect movement between risk groups, with particular attention to the security measures to be taken when moving from a lower risk group to a higher risk group.
2. TWIC Reader Requirements for Risk Group A
The ANPRM proposed TWIC reader requirements and other TWIC-related requirements for Risk Group A that would utilize the TWIC's most protective measures for identity verification, card authentication, and card validation.
For identity verification, owners and operators of vessels or facilities in Risk Group A would be required to either match the TWIC-holder's fingerprint to one of the fingerprint templates stored in the TWIC, or match the TWIC-holder's alternate biometric (e.g., retina scan, hand geometry, or other biometric) to one captured and stored in a PACS. A TWIC reader can work as a stand-alone unit, or it can be integrated into a facility's PACS. Either way, the owner or operator would be required to use a TWIC reader from the official list of TSA-approved TWIC readers. The biometric match would need to be made using a TWIC reader and/or PACS before the individual is granted unescorted access to secure areas.
When electronically matching biometrics within a PACS, an owner or operator would be permitted to use a different biometric than a fingerprint (e.g., an iris scan or hand geometry), stored in the PACS and matched to the biometric of the TWIC-holder. The owner or operator would be required to link their system to the TWIC in such a manner that the PACS precludes access to someone who does not have a TWIC, or to someone other than the
individual to whom the TWIC has been issued. This requirement means that the TWIC would need to be read and the stored biometric identifier matched against the TWIC-holder's fingerprint at least once, when the individual's information is entered into the PACS. Before relying on the alternate biometric, it must be verified, through a one-to-one fingerprint match, that the individual presenting the TWIC is actually the person to whom the TWIC was issued.
In the ANPRM, we recognized that while PIN verification could be used to enhance the accuracy of identity verification, this method presents operational and environmental challenges. The PIN can only be entered when the TWIC is inserted into a “contact” TWIC reader, where the TWIC is inserted into a slot allowing direct contact between the TWIC reader and the chip embedded in the TWIC. Comments received in response to the TWIC 1 NPRM, as well as recommendations from the National Maritime Security Advisory Committee (NMSAC), emphasized concerns over whether contact TWIC readers would be able to withstand the harsh conditions often present in a maritime environment. Additional concerns were raised as to whether maritime workers should be expected to remember a 6- to 8-digit PIN, especially workers who would not typically use the PIN on a regular basis. Concerns were also raised over the operational delays associated with a PIN requirement. In light of these concerns, and taking into account the level of security already provided via the TWIC's other features, the ANPRM did not propose a PIN requirement to enhance identity verification.
For card authentication, owners and operators of vessels or facilities in Risk Group A would be required to use a TWIC reader to screen individuals seeking access to secure areas. As with identity verification, owners and operators would be permitted to integrate TWIC into a PACS, provided that the owner or operator completes this integration before the TWIC-holder's information is added into the PACS, and before the TWIC-holder is granted unescorted access to secure areas.
For card validation, owners and operators of vessels or facilities in Risk Group A would be required to use a TWIC reader to check an individual's TWIC against the CCL. An owner or operator updates CCL information by downloading the current list onto the TWIC reader or PACS. At MARSEC Level 1, owners and operators would be required to update the CCL on a weekly basis. At MARSEC Levels 2 and 3, owners and operators would be required to update the CCL on a daily basis.
3. TWIC Reader Requirements for Risk Group B
The ANPRM proposed TWIC reader requirements and other TWIC-related requirements for Risk Group B that would differ depending on MARSEC Level. At MARSEC Levels 2 and 3, owners and operators of vessels or facilities in Risk Group B would be required to utilize the most protective measures of the TWIC for identity verification, card authentication, and card validation. Those requirements are the same as those described above with respect to Risk Group A.
At MARSEC Level 1, owners and operators would perform card authentication and card validation using a TWIC reader in the same manner required at higher MARSEC Levels. At MARSEC Level 1, however, owners and operators would not be required to use a TWIC reader to perform a biometric match for identity verification, subject to the exception described below. Instead, owners and operators would be permitted to perform identity verification by using the TWIC as a visual identity badge. The exception to this leniency at MARSEC Level 1 is that on a random basis, but at least 1 day per month, owners and operators would be required to perform identity verification using a TWIC reader to match the TWIC-holder's fingerprint to one stored in the TWIC.
The ANPRM's proposed requirements for Risk Group B were based on a determination that the TSI risk to such vessels and facilities at MARSEC Level 1 does not warrant a requirement to perform routine biometric identity verification using a TWIC reader.
4. TWIC Requirements for Risk Group C
The ANPRM proposed TWIC requirements for Risk Group C that would not involve the use of a TWIC reader at any MARSEC Level. Instead, owners and operators of vessels or facilities in Risk Group C would visually inspect the security features on the TWIC for identity verification, card authentication, and card validation. TWIC-holders working on vessels or at facilities in Risk Group C would periodically have their TWICs scanned using a TWIC reader during Coast Guard inspections and unannounced spot checks.
The ANPRM's proposed requirements for Risk Group C were based on our determination that, given the type of commodities and small number of passengers typical of this risk group, it is likely that these vessels and facilities present a less attractive target to individuals who wish to do harm than vessels and facilities in Risk Groups A and B. Nonetheless, vessels and facilities in Risk Group C still present some risk of being involved in a TSI. As a result, we determined that visual inspection of TWICs would be an appropriate security measure.
5. Recurring Unescorted Access
The concept of Recurring Unescorted Access (RUA) was first proposed in the TWIC 1 NPRM.
38
RUA was conceived as a means of providing flexibility to vessel owners and operators so that the TWIC program would provide them with a valuable security enhancement without unnecessarily burdening daily operations. As initially proposed, RUA would apply to vessels that would otherwise be required to use TWIC readers. RUA would allow the owners and operators of such vessels to grant certain TWIC-holders the privilege of entering secure areas on a repetitive basis without having their TWICs electronically scanned by a TWIC reader each time, provided that certain preconditions had been met.
38
See
71 FR 29410-29411.
The TWIC 1 NPRM cited two factors on which the decision to grant RUA privileges should be based: (1) The relationship of the individual to the vessel, or how well “known” the individual is; and (2) the individual's need to have frequent and unimpeded access to the vessel. We assumed that the crew of most vessels would consist of a relatively small number of individuals who would quickly become familiar enough with one another and readily distinguish each other from non-crewmembers. Accordingly, on such vessels, there would be no added benefit from repeated biometric identity verification using a TWIC reader.
Although RUA would exempt certain individuals from having their TWICs routinely scanned by a TWIC reader, these individuals would still need to present a TWIC for visual inspection. Additionally, prior to granting RUA privileges to a TWIC-holder, the vessel owner or operator would be required, among other things, to perform a one-time scan of the individual's TWIC using a TWIC reader for initial identity verification, card authentication, and card validity.
In addition to proposing RUA for vessels, the ANPRM also proposed RUA for facilities. Thus, owners and operators of vessels or facilities could grant RUA privileges to a number of individuals per vessel or facility.
Owners and operators would be required to explain their RUA procedures in an amended security plan.
As proposed in the ANPRM and based on a recommendation from the Towing Safety Advisory Committee (TSAC), RUA could be granted to a maximum of 14 individual TWIC-holders per vessel or facility. TSAC's rationale for establishing 14 as the maximum cut off for requiring TWIC readers on vessels is that these vessels have a reduced vulnerability because the individuals are all “known” to one another. The number was developed by taking into account the fact that for a small vessel, such as a towing vessel or offshore supply vessel, the crew would typically include up to one Master, one Chief Engineer, and three four-person crews who rotate through watch shifts.
6. TWIC Reader Approval, Calibration, and Compliance
In the ANPRM, we considered the possibility that some owners and operators may wish to incorporate TWIC reader requirements into an existing PACS. In those situations, the ANPRM proposed to require owners and operators to follow the standard/specification to be developed from the results of the TWIC Pilot.
The ANPRM stated that we were considering alternatives for how to ensure that TWIC readers are maintained in proper working order. The existing provisions in 33 CFR 104.235, 104.260, 105.225, 105.250, 106.230, and 106.255 would require TWIC readers to be inspected, tested, calibrated, and maintained in accordance with the manufacturers' recommendations, and that records of those actions be maintained as well. The ANPRM requested comments on whether TWIC readers should be subject to additional Coast Guard inspections or third-party audits.
7. Security Plan Amendment
The ANPRM proposed a requirement on owners and operators to amend their security plans to include TWIC requirements within 6 months of promulgation of a TWIC reader final rule. In the ANPRM, we indicated that we would consider re-evaluating this deadline, and we sought public comment on how long owners and operators should have to amend security plans to incorporate TWIC reader requirements. Security plan amendments would need to detail how the owner or operator would implement TWIC requirements, including those promulgated in the TWIC 1 Final Rule, and TWIC reader requirements, if applicable.
The ANPRM mentioned that we would consider additional security plan provisions that require the owner or operator to discuss procedures for handling TWIC-holders with poor quality or no fingerprints, as well as TWIC-holders who are otherwise unable to match a live fingerprint to one of the templates stored in the card. The ANPRM also mentioned that we were considering a requirement on owners and operators using a separate PACS to explain how they will protect personal identity information.
The ANPRM articulated our position that requests for waivers, alternatives, and equivalents would need to comply with existing regulatory requirements found in 33 CFR 101.120, 101.130, 104.130, 104.135, 105.130, 105.135, 106.125, and 106.130.
In the ANPRM, we stated our intent to not amend 33 CFR 101.120 regarding Alternative Security Programs (ASPs). Instead, we would exercise our existing authority, found in 33 CFR 101.120(d)(1)(ii), to require those organizations that have approved ASPs to amend them to incorporate the TWIC requirements. Please see Section IV.C. below for a discussion on our decision to eliminate this proposal from the NPRM.
An ASP is a third-party or industry organization-developed standard that the Coast Guard has determined provides an equivalent level of security to that established by 33 CFR parts 104 or 105. MTSA-regulated facilities that are members in good standing of trade organizations or industry groups may operate under an ASP, instead of an FSP, submitted by the trade organization or industry and approved by the Coast Guard.
39
The Coast Guard permits use of ASPs to tailor Coast Guard security requirements to diverse industries within the maritime community. ASPs allow owners and operators to participate in a development process with other industry groups, associations, or organizations, and to coordinate their compliance with Coast Guard security rules and other rules already implemented.
40
Practically, ASPs are written to address a group of owners and operators based on a business model. Thus, a security standard for the small passenger industry will be different from the industry standard for container vessels, simply based on the differences in their respective vulnerabilities and associated TSI consequence. In effect, ASPs allow the end-users to implement an existing security program as an alternative to creating an individual vessel- or facility-specific security plan. ASPs also lessen the numbers of security plans that must be reviewed and approved by the Coast Guard. Currently, there are 11 approved ASPs.
39
See
33 CFR 101.125.
40
See
68 FR 60449, 60454, and 60532 (October 22, 2003).
8. Recordkeeping
The ANPRM proposed to require owners and operators to maintain, for a period of 2 years, records captured by TWIC readers on each scan. Under the ANPRM, owners and operators would also maintain, for a period of 2 years, records on individuals to whom RUA was granted. Finally, the ANPRM indicated that we would consider whether to require owners and operators to maintain a record to demonstrate that they have completed required card validity checks.
9. Additional Persons Required To Obtain TWICs
MTSA requires the Secretary to issue TWICs to certain individuals unless the Secretary determines that an individual poses a security risk warranting denial of the card.
41
Section 70105(b)(2) of Title 46 U.S.C. lists the categories of individuals to whom this requirement applies.
41
46 U.S.C. 70105(b)(1).
We published the ANPRM prior the enactment of the CGAA 2010. At the time we published the ANPRM, the list of individuals to whom the Secretary was required to issue a TWIC included: (1) An individual allowed unescorted access to secure areas of a MTSA-regulated vessel or facility; (2) an individual issued a license, certificate of registry, or merchant mariners document; (3) a vessel pilot; (4) an individual engaged on a towing vessel that pushes, pulls, or hauls alongside a tank vessel; (5) an individual with access to SSI; (6) other individuals engaged in port security activities; and (7) other individuals as determined appropriate by the Secretary.
42
42
46 U.S.C. 70105(b)(2).
The Coast Guard implementing regulations in 33 CFR 101.514(a) require individuals to obtain a TWIC as a pre-condition to gaining unescorted access to secure areas of MTSA-regulated vessels and facilities. For purposes of Coast Guard regulation of these vessels and facilities, we believe that the language in 33 CFR 101.514(a) adequately covers the individuals required to obtain a TWIC. Nonetheless, at the time we published the ANPRM,
we were aware of a potential gap between MTSA and our regulations. Specifically, there may be some vessel pilots who do not hold Federal licenses, and there may be some individuals who are not credentialed mariners engaged on towing vessels that are not MTSA-regulated. Therefore, to avoid any possible gaps between MTSA and our regulations, we included a proposal in the ANPRM to explicitly include these individuals in the regulatory requirement to obtain a TWIC.
Subsequent legislation has caused us to eliminate part of this proposal from this NPRM. Section 809 of the CGAA 2010 changed the applicability of 46 U.S.C. 70105(b)(2)(B) and (D) so that the Secretary is now required to issue a TWIC to credentialed mariners and those engaged on towing vessels only if these individuals are allowed unescorted access to a secure area of a MTSA-regulated vessel. Section 809 has eliminated the gap with respect to mariners on towing vessels. Mariners who are allowed unescorted access to MTSA-regulated vessels are already covered in the existing regulatory requirement to obtain a TWIC. We no longer need to add a provision requiring mariners working on vessels that are not MTSA-regulated to obtain a TWIC. While there may be some vessel pilots that do not hold Federal licenses, we have not determined whether there is a population of State-licensed vessel pilots that are not otherwise required to obtain a TWIC because they access secure areas of MTSA-regulated vessels. We seek public comment on this subject and whether a specific provision to include them in the regulatory requirement to obtain a TWIC is necessary. If there is a population of State-licensed vessel pilots not covered under the current regulatory requirement to obtain a TWIC, we intend to revise 33 CFR 101.514 to cover that population. Please see Section IV.C. below for further discussion on our decision to eliminate or modify this proposal in this NPRM.
E. Public Comments Received in Response to the ANPRM and Public Meeting
This section provides a detailed discussion of the public comments received during the ANPRM's comment period and public meeting. This section also provides our responses to those comments.
We received approximately 100 comment letters in response to the ANPRM. In addition, we hosted a public meeting in Arlington, Virginia on May 6, 2009, to provide another forum for obtaining public feedback on the ANPRM.
43
Comments received at the public meeting aligned into approximately 20 categories. Copies of the public meeting sign-in sheets, written comments received, and a transcript of the public meeting, are available for viewing in the public docket for this rulemaking.
43
See
Transportation Worker Identification Credential (TWIC)—Reader Requirements, 74 FR 17444 (Apr. 15, 2009) to view the notice of public meeting; request for comments.
Commenters represented a wide range of individuals and entities, including: Federal, State, and local government officials; port authorities; representatives of affected industries, such as maritime, trucking, rail, security, port, and other facilities; professional/trade associations; labor unions; and private citizens. The comments received from these parties helped to inform the proposals in this NPRM.
1. General Comments
Numerous commenters supported the ANPRM's general approach to TWIC reader requirements and other TWIC-related requirements. Many recognized the potential value of the TWIC program to enhance transportation security in general, and maritime security in particular. Several commenters commended us for first publishing an ANPRM to solicit public input on a preliminary set of proposals before publishing an NPRM.
Several commenters cautioned us to implement TWIC reader requirements in a manner that does not unnecessarily burden affected industries. We believe the requirements proposed in this NPRM achieve that goal. Section V. “Regulatory Analysis” below provides a detailed discussion of the benefits and burdens associated with this proposed rule.
One commenter suggested that the NPRM should clarify which provisions specifically apply to vessels, and which apply to facilities. Similarly, two commenters suggested that we consider proposing separate sets of regulations for vessels and facilities.
Our proposals in this NPRM clearly distinguish between vessels and facilities. To clarify, 33 CFR part 101 sets forth general maritime security regulations, 33 CFR part 104 sets forth maritime security regulations specific to vessels, 33 CFR part 105 sets forth maritime security regulations specific to facilities, and 33 CFR part 106 sets forth maritime security regulations specific to OCS facilities. As described in greater detail below in Section IV., this NPRM proposes to add or amend relevant provisions in each of these parts. Please refer to Table ES-1 in the Executive Summary for a breakdown of the NPRM proposals by vessel, facility, and OCS facility.
Several commenters expressed general concerns about TWIC reader requirements. Some opposed any requirement to use TWIC readers, citing financial burdens and operational complications they believe would result from such requirements. Others highlighted differences between different types of vessels, and suggested that TWIC readers may not necessarily enhance security in each case. Commenters also raised concerns about increased traffic and other operational challenges associated with TWIC reader requirements.
As discussed more fully below in Sections IV. and V., this NPRM does not propose TWIC reader requirements for Risk Group B. This decision was based, in part, on comments received in response to the ANPRM. Many of the comments opposing TWIC reader requirements represented the interests of owners and operators of vessels or facilities assigned to Risk Group B. We have estimated the annualized cost of the TWIC reader requirements on vessels and facilities in Risk Group A at $26.5 million, at a 7 percent discount rate. Had we proposed TWIC reader requirements to also include Risk Group B facilities, the annualized cost would increase to $141.2 million, at a 7 percent discount rate. Moreover, including Risk Group B in the TWIC reader requirements would not only increase the annualized cost, but the average consequence figure (the monetized costs of fatalities and injuries resulting from a TSI) would drop by more than one-third. While this does not mean that there should be no TWIC reader requirements for Risk Group B, we believe this analysis supports our phased approach for requiring TWIC readers first for Risk Group A. We also wish to emphasize the utility of TWIC in enhancing security even when not used in conjunction with TWIC readers. Before mariners and other individuals were required to obtain a TWIC, they could access secure areas of MTSA-regulated vessels and facilities after presenting a State-issued driver's license or any number of other government-issued identification cards. This patchwork system of valid credentials required security personnel to become familiar with the appearance and security features of every type of acceptable credential. Moreover, since some government-issued credentials are used for purposes other than security, applicants are not necessarily screened
from a security threat perspective. Additionally, the eligibility criteria for some government-issued credentials do not preclude issuance to an individual with a felony criminal record.
The TWIC program mitigates the above shortcomings. Since April 15, 2009, TWIC has been the single credential used throughout the maritime sector. Accordingly, security personnel only need to become familiar with the appearance and security features of one credential. Moreover, unlike other government-issued credentials, TWIC is specifically designed for transportation security. Its purpose is to ensure a vetted maritime workforce by establishing security-related eligibility criteria, and by requiring each TWIC-holder to undergo TSA's security threat assessment as part of the process of applying for and obtaining a TWIC.
We will continue to analyze risk data and reassess the need to modify or add TWIC reader requirements in the future. We believe that this approach should alleviate the concerns raised by these commenters.
2. Statutory Authority
A number of commenters emphasized that the Secretary's authority to require TWIC readers on vessels is discretionary, and not mandated by MTSA. We agree with this comment.
One commenter requested clarification that if vessels in lower risk groups have not been determined by the Secretary to be at risk of a TSI, the SAFE Port Act prohibits TWIC reader requirements for such vessels. We disagree with this comment. The relevant portion of the SAFE Port Act provides: “The Secretary may not require the placement of an electronic reader for transportation security cards on a vessel unless: (1) The vessel has more individuals on the crew that are required to have a transportation security card than the number the Secretary determines, by regulation issued under subsection (k)(3), warrants such a reader; or (2) the Secretary determines that the vessel is at risk of a severe TSI.”
44
Under the SAFE Port Act, the Secretary could require vessels in lower risk groups to use TWIC readers if their crew size exceeds the minimum threshold, in this rule proposed as 14 individuals, established by regulation. While this NPRM does not propose TWIC reader requirements for Risk Groups B or C, the Coast Guard is not prohibited from doing so under the SAFE Port Act.
44
46 U.S.C. 70105(m).
One commenter noted that certain proposals in the ANPRM would apply to facilities that receive towing vessels engaged in towing a barge or barges carrying non-hazardous cargoes, facilities that receive vessels subject to 46 CFR Chapter I, Subchapter D, that carry any flammable or combustible liquid cargoes or residue, and facilities that receive vessels not transferring cargo. The commenter suggested that these facilities are not covered by MTSA, and therefore, should not be subject to TWIC reader requirements. We disagree with the suggestion that these facilities are not covered by MTSA. MTSA broadly defines the term “facility” to mean “any structure or facility of any kind located in, on, under, or adjacent to any waters subject to the jurisdiction of the United States.”
45
MTSA requires facility security plans (FSPs) for “facilities that the Secretary believes may be involved in a transportation security incident* * *.”
46
MTSA does not prohibit us from placing TWIC requirements on such facilities.
45
46 U.S.C. 70101(2).
46
46 U.S.C. 70103(c)(2)(A).
3. Risk-Based Approach
a. General
We received a broad range of comments with respect to the ANPRM's risk-based approach to classifying MTSA-regulated vessels and facilities. Many commenters expressed support for the ANPRM's risk-based approach. A number of commenters expressed support for a risk-based approach, but cited general reservations on the way such an approach was proposed in the ANPRM. Other commenters expressed opposition to the ANPRM's risk-based approach.
One argument cited by commenters opposing the ANPRM's risk-based approach is that vessels have already been divided into risk groups by MTSA with respect to security plan requirements, and by the Port Security Grant program. These commenters argued that to introduce another risk-based classification matrix would create too much complexity for affected industries. A larger group of commenters took the opposite view, however, arguing that the ANPRM's matrix should be based on additional variables, such as: Risk-reduction measures vessels and facilities have already implemented; size and type of vessel; port traffic volume; port location; port-wide risk; type, volume, and frequency of carrying or handling high-risk cargoes; characteristics of container cargoes and facilities; number of TWIC-holders with access to a vessel or facility; scenarios other than MSRAM's “total destruction” scenario; compliance costs; and other industry-specific considerations.
After considering these wide-ranging comments that fell on both sides of the issue, we continue to believe that the risk-based approach set forth in the ANPRM appropriately categorizes types of vessels and facilities based on their risk of being involved in a TSI, without creating an overly complex categorization system. Other existing risk-based categorization matrices are not tailored to TWIC requirements like the AHP/MSRAM approach described above. Additionally, as discussed more fully below in section III.G., “HSI Report,” HSI conducted a generally favorable independent peer review of the risk-based approach that formed the basis of the ANPRM's proposals.
Several commenters requested that the Coast Guard establish an appeals process whereby owners and operators could petition to have an assigned risk-ranking reviewed and lowered based on unique circumstances. We wish to clarify that an appeals process already exists for those directly affected by a decision or action taken pursuant to the Coast Guard's maritime security regulations.
47
Thus, owners and operators would be able to appeal a risk-ranking under the existing procedures. The establishment of a separate appeals process for petitioning TWIC-related risk-rankings is not necessary.
47
33 CFR 101.420; 33 CFR 104.150; 33 CFR 105.150; 33 CFR 106.145.
Other commenters suggested that COTPs should assign risk ratings to each vessel and facility on a case-by-case basis. We disagree with this approach because it is less predictable than a clear regulatory standard, and could lead to different standards being applied to similar vessels or facilities depending on their location.
b. MSRAM
Several commenters addressed the use of MSRAM as part of the ANPRM's risk-based approach. Some suggested that MSRAM should be updated to take into account risk-mitigation measures that industry has implemented since 2005. We will continue to update the MSRAM data, but we believe the data that informed the ANPRM provides an accurate basis for the regulatory proposals in this NPRM.
Other commenters requested additional information about MSRAM in order for them to comment on its utility in developing a risk-based classification system. In response, we emphasize that the ANPRM and this
preamble set forth the general principles that underlie MSRAM as a risk-analysis tool. The AHP/MSRAM process generates risk scores for facility and vessel types. These scores are based on factors related to TSI consequence. Since this information is designated as SSI, the publication of more specific MSRAM data is prohibited under 49 CFR Part 15.
c. Movement Between Risk Groups
Several commenters agreed with the ANPRM's proposal to permit movement between risk groups by vessels and facilities that handle or carry dangerous cargoes only on a limited basis. Several other commenters took the opposite view, arguing that movement between risk groups would create a burdensome and confusing set of requirements, and would also introduce unfair economic incentives in favor of facilities in lower risk groups.
We continue to favor a flexible approach that allows for the option of vessels and facilities to move between risk groups based on the cargo handled or carried at a given time. This would ensure appropriate utilization of TWIC readers when dangerous cargoes are present, without imposing undue burdens when dangerous cargoes are not. Owners and operators who do not wish to take advantage of this flexibility would not be required to do so. Owners and operators who wish to take advantage of this flexibility would be expected to explain, in an amended security plan, how changes at their vessel or facility qualify for a higher or lower risk group and address the change in risk.
A number of commenters suggested alternatives to the ANPRM's approach with respect to movement between risk groups. Several argued in favor of a uniform set of TWIC requirements applicable to all vessels and facilities, which would obviate the need for regulatory provisions dealing with movement between risk groups. Two commenters suggested that facilities in Risk Group C should always retain their classification in that group, regardless of whether they handle dangerous cargoes on an infrequent basis.
We do not believe that a “one size fits all” approach to TWIC requirements is efficient or effective. Instead, we favor a more targeted approach that requires TWIC readers for vessels and facilities deemed higher risk, and requires less stringent TWIC requirements for vessels and facilities not deemed higher risk. We also generally disagree with an approach that would permit a vessel or facility to comply with the requirements of a lower risk group while handling or carrying cargoes that would otherwise trigger the TWIC requirements of a higher risk group. Therefore, this NPRM proposes to give the option for vessels and facilities to move between risk groups based on the cargo handled or carried at a given time.
Two commenters suggested that facilities in Risk Group C should be permitted to appeal to the COTP for a special operating designation to cover their infrequent handling of dangerous cargoes. We reiterate that an owner or operator may apply for a waiver of any requirement the owner or operator considers unnecessary, as provided in 33 CFR 104.130, 105.130, and 106.125. We also wish to note that if such a waiver is granted, an owner or operator is not required to update their security plan after approval of the waiver.
Three commenters requested clarification of the proposed TWIC requirements in scenarios where a vessel assigned to a higher risk group calls on a facility assigned to a lower risk group. One commenter suggested that, in such cases, we should allow time for TWIC infrastructures to be updated.
We wish to clarify that, according to our risk-based approach, facilities are classified by the types of commodities they handle and the types of vessels they receive. Thus, a facility that receives Risk Group A vessels would be categorized as a Risk Group A facility. We request additional comments on specific scenarios that might warrant further consideration of potential regulatory requirements to address the interaction of vessels and facilities in different risk groups.
Some commenters suggested that the regulations should provide for multiple risk group assignments within one facility for situations where one portion of the facility handles dangerous cargoes, while another portion does not. We are considering granting this request. If we grant this request, we expect the regulations to reflect that plans for multiple risk group assignments within a facility would be reviewed on a case-by-case basis and subject to COTP approval. We request additional comments from the public that specifically describe how multiple risk group assignments might apply to their facilities. We note that in the TWIC 1 Final Rule, we provided facilities with greater flexibility by revising 33 CFR 105.115 to allow owners and operators to redefine their “secure area” as only that portion of their access control area that is directly related to maritime transportation. We seek comments from the public on whether the additional flexibility of being able to further modify a facility's footprint by assigning different portions of the facility to different risk groups is necessary or appropriate.
d. MARSEC Levels
Several commenters agreed in principle with the ANPRM's approach of imposing enhanced TWIC requirements at higher MARSEC Levels, but questioned why there was little difference between the ANPRM's TWIC reader requirements for Risk Groups A and B at different MARSEC Levels. These commenters suggested alternative approaches, all of which were variations on the theme that TWIC reader requirements should become more stringent as MARSEC Levels are elevated. Other commenters disagreed with the ANPRM's approach, but proposed stricter requirements, suggesting that all MTSA-regulated vessels and facilities should be required to use TWIC readers at elevated MARSEC Levels. Another commenter disagreed with the ANPRM's approach, arguing that to impose different TWIC reader requirements depending on MARSEC Level is overly complex and would provide no added security benefits.
We recognize that the system of MARSEC Levels creates a useful mechanism for the Coast Guard to elevate security requirements at times of heightened risk. Nonetheless, we use this mechanism in a targeted manner, and at this time, we do not believe that elevated TWIC reader requirements at higher MARSEC Levels are generally practical or appropriate. In considering the comments above, we note the change we have made from the ANPRM to this NPRM with respect to TWIC reader requirements. In the ANPRM, we proposed TWIC reader requirements for Risk Groups A and B, with stricter TWIC reader requirements for both risk groups at higher MARSEC Levels. The ANPRM's stricter TWIC reader requirements would have primarily affected Risk Group B because the ANPRM proposed routine biometric scanning with a TWIC reader for Risk Group A at all MARSEC Levels. For example, the ANPRM would have required Risk Group B to use TWIC readers at MARSEC Level 1 for card authentication (i.e., no routine biometric scan) and once-monthly biometric identity verification. The ANPRM, however, would have only required Risk Group B to regularly use TWIC readers for biometric identity verification at higher MARSEC Levels.
In this NPRM, we have eliminated the proposed TWIC reader requirements for Risk Group B. The requirements for
routine biometric scanning with a TWIC reader for Risk Group A remain the same as in the ANPRM. Note that we propose increased requirements at higher MARSEC Levels to the extent that the NPRM would require Risk Group A to perform daily updates of CCL information at higher MARSEC Levels, instead of the weekly updates required at MARSEC Level 1.
We also note that data from the TWIC Pilot demonstrated that switching between different TWIC reader modes of operation negatively impacted the efficiency of TWIC reader use by complicating the learning process for TWIC-holders. According to the TWIC Pilot, TWIC-holders were confused by the different procedural requirements for the different TWIC reader modes of operation, regardless of attempts to inform TWIC-holders in advance of mode changes. This often resulted in delays caused by TWIC-holders' confusion as to whether or not they needed to place their finger on the TWIC reader's fingerprint sensor. In contrast, the TWIC Pilot found that when TWIC readers were used in the same mode of operation for a sustained period of time, TWIC-holders became familiar with a consistent throughput procedure, resulting in more efficient processing. While more stringent TWIC reader requirements might seem appropriate at higher MARSEC Levels, the TWIC Pilot demonstrated the importance of a consistent user experience. We also note that according to existing regulations in 33 CFR 101.405, the Coast Guard may issue MARSEC Directives setting forth mandatory measures if we determine that additional security measures are necessary to respond to specific threats.
Consistent with the findings of the TWIC Pilot, the TWIC reader requirements proposed in this NPRM call for no switching between TWIC reader modes, and also call for little variation in requirements at higher MARSEC Levels. The only difference between the requirements proposed in the ANPRM and this NPRM based on MARSEC Level is that, at MARSEC Level 1, owners and operators of vessels or facilities in Risk Group A would be required to perform card validity checks based on CCL information that has been updated weekly, whereas at higher MARSEC Levels, the CCL updates would be required daily. The increased risk associated with elevated MARSEC Levels warrants this requirement to update the CCL information more frequently. The Coast Guard seeks public comment on this approach.
e. CCL and “Privilege Granting”
Most of the comments we received regarding the CCL recognized some benefits to card validation requirements that involve checking TWICs against this list. One commenter, however, stated that the benefits of such requirements would not outweigh the burdens. We disagree with this comment. Invalid TWICs are placed on the CCL if they are lost, stolen, damaged, or revoked by TSA for cause. The benefit of a requirement to check TWICs against the CCL is that it enables owners and operators to limit the access to secure areas of our nation's transportation system to individuals that hold a TWIC. We estimate the burden of updating CCL information into the TWIC reader or PACS to be approximately 30 minutes per week. For a more detailed discussion of the costs and benefits associated with this proposed rule, see Section V. “Regulatory Analyses” below.
Three commenters requested that more frequent or real-time updated CCL information be made available. These commenters argued that access to real-time CCL information would enhance security better than the method proposed in the ANPRM, which requires owners and operators to update CCL information on a weekly or daily basis depending on the particular MARSEC Level. Other commenters felt that daily or weekly download requirements are reasonable.
We believe that the requirements to download the CCL weekly or daily (based on MARSEC level) strike a reasonable balance between security and practicality. Owners and operators who wish to download CCL information more frequently would be able to do so.
Two commenters requested functionality that would enable CCL information to be downloaded directly into an entity's PACS. We confirm that this functionality exists via Internet connection.
Other commenters requested functionality that would make CCL information available through additional mechanisms, such as wireless connection to a TWIC reader, manual download to a TWIC reader, access via smart-phone, or a searchable Internet database accessible via the Homeport
48
or other secure system. We emphasize that the CCL information is available via the Internet through a wireless device or manual download to a TWIC reader.
49
48
Homeport is a publicly accessible internet portal located at
https://homeport.uscg.mil,
which provides users with current maritime security information. It also serves as the Coast Guard's communication tool designed to support the sharing, collection, and dissemination of sensitive but unclassified information to targeted groups of registered users within the port population.
49
The CCL is updated daily and is publicly available for download on the Internet at
https://twicprogram.tsa.dhs.gov/TWICWebApp/.
Seven commenters expressed concerns over the CCL because it groups together individuals who are legitimate security threats with individuals who merely have a lost or stolen TWIC. These commenters felt that individuals in the latter categories would be unduly stigmatized by being placed on the CCL together with individuals identified as security threats. Accordingly, they argued that the CCL should focus exclusively on individuals determined to be security threats.
We wish to clarify that the CCL does not contain names, any personally identifiable information, or any security information. The CCL is simply a list of TWIC numbers that have not yet expired, but are no longer valid for entry to secure areas due to their reported loss or theft, being revoked by TSA, or replaced administratively due to damage, or other reason.
We also note that the Coast Guard does not maintain or control the content of the CCL. The CCL is maintained and controlled by TSA. The Coast Guard has shared these comments with TSA for use in future planning. Facility and vessel owners and operators should understand that a variety of factors could cause a TWIC to be listed on the CCL.
One commenter suggested that we use a vehicle, such as the Homeport system, to notify employers when an employee has been identified as a national security threat or otherwise deemed ineligible to hold a TWIC. In response to this comment, we note that national security threats are dealt with in the manner prescribed by relevant law enforcement agencies, and typically do not involve release of any information that could compromise an ongoing investigation, including whether an individual may pose a national security threat. We also note, however, that TSA requires all TWIC applicants to acknowledge that TSA may notify employers and facility owners and operators if there is an imminent threat of risk to individuals or property.
Several commenters expressed opinions on the ANPRM's proposal regarding a “privilege granting” system, which would enable an owner or operator to register with TSA the names of specific TWIC-holders granted access to secure areas. TSA would then contact the owner or operator directly when a registered individual has been added to
the CCL. Approximately 20 commenters stated that they would prefer a privilege-granting system over a requirement to continually download or manually check CCL information. One of these commenters suggested that privilege granting should actually be a minimum requirement for all owners and operators of vessels and facilities in Risk Group C, because this would confer a meaningful security benefit at little cost. Most of the commenters supporting a privilege-granting system opposed the proposition to pay a fee for it. Two commenters suggested that if a fee were to be charged, the NPRM should include a fee estimate so that the public would have more of a basis on which to comment.
Several commenters were not in favor of the ANPRM's privilege-granting system. One simply felt it is unnecessary. Another cited employee privacy concerns. One commenter stated that a privilege-granting system might provide some benefit to vessels, but would not benefit facilities. Another stated that a privilege-granting system would not be a viable option for tug or barge operators because these operators do not know which individuals require access to which vessels or facilities.
After considering the comments and further analysis, we have decided not to include a privilege-granting system in this NPRM. The population of TWIC-holders granted access to any given vessel or facility often changes, which means that a privilege-granting system would be labor-intensive, costly, and impractical to maintain. Moreover, we believe that creating and maintaining a privilege-granting system would require substantial government and/or industry resources, and commenters were generally unwilling to pay fees that would be necessary to create and maintain such a system.
One commenter requested information on how vessels operating outside of available wireless Internet access zones would download necessary CCL updates. We wish to clarify that there would be no obligation to download updated CCL information when there are no new individuals seeking access to secure areas. For example, a vessel designated as a secure area that is underway for an extended period of time with the same crew would not need to download updated CCL information if card validity was properly confirmed when the TWIC-holders boarded the vessel. We request additional comments from the public regarding practical scenarios in which a vessel might not be able to download necessary CCL updates within the prescribed frequency (weekly or daily, depending on MARSEC Level). Additionally, we request comments from the public regarding the regulatory requirements that we should put in place when vessels are in one of those scenarios. One possibility would be to continue to require the use of TWIC readers for identity verification, card authentication, and card validity, even though the CCL might not have been updated within the prescribed frequency. This would electronically confirm that the TWIC has not expired, and also confirm no match against the most recently downloaded version of the CCL. The owner or operator would be required to update the CCL at the next available opportunity. We request comments from the public on this proposal or any preferred alternatives we should consider.
One commenter requested guidance on the obligations an employer might have if notified by TSA that a former employee's TWIC has been revoked. We wish to clarify that generally, no such notification would be forthcoming. We note, as mentioned above, that TSA requires all TWIC applicants to acknowledge that TSA may notify employers and facility owners and operators if there is an imminent threat of risk to individuals or property. In those scenarios, TSA would provide appropriate case-specific guidance to the employer at the time of any such TSA notification.
Several commenters requested additional general guidance on any proposed requirements to perform card validation using CCL information. We will consider whether and how to issue additional guidance, as necessary.
f. PIN Usage
Approximately 30 commenters agreed with the ANPRM's approach that TWIC-holders should not be required to input their PINs in order to be granted access to secure areas. Among the reasons commenters cited in opposing a PIN requirement were: intermittent use makes PINs hard to remember; difficulty of retrieving forgotten PINs; throughput delays and other disruptions; and lack of an appreciable security benefit once a biometric match has been established.
In the ANPRM, we recognized the operational and environmental challenges that a PIN requirement would present. The TWIC Pilot also noted that since many TWIC-holders had rarely, if ever, used their PINs since activating their TWICs, some workers could not remember their PINs. These individuals were then required to visit a TWIC enrollment center to reset their PINs. The TWIC Pilot also noted that inputting the PIN is not necessary to conduct a biometric match. Consistent with the comments and TWIC Pilot findings, this NPRM does not propose a requirement that TWIC-holders enter their PINs in order to access secure areas.
Several commenters also requested that PINs not be required during Coast Guard spot checks and inspections. We note that such a proposal was not included in the ANPRM. Existing regulation already requires mariners to provide their PINs to Coast Guard personnel upon request.
50
For example, when a mariner's fingerprints cannot be read using a TWIC reader, Coast Guard personnel may require the mariner to provide the PIN. To account for this and other instances when a mariner's identity cannot be verified by means other than the TWIC and PIN, we are retaining the existing provision that requires mariners to provide PIN information to Coast Guard personnel upon request.
50
See
33 CFR 101.515(d)(2).
Some commenters acknowledged that PIN verification may be useful in certain circumstances, and that there are certain advantages associated with PINs. One commenter noted that PIN usage would be a viable alternative when fingerprint matching is not possible. We agree with this comment and have addressed this issue below in section IV.F. “TWIC Inspection Requirements in Special Circumstances.”
Another commenter suggested that TWIC readers designed to only check PINs might be less expensive than TWIC readers that perform other functions. We believe that the operational and environmental challenges presented by a PIN requirement outweigh this possible cost advantage.
One commenter stated that PINs are another line of defense against forged TWICs. We agree with this comment, but do not believe it warrants a PIN requirement. Although this NPRM does not propose to require PIN verification, owners and operators may choose to impose their own PIN verification requirement on individuals before granting them access to secure areas.
Finally, several commenters requested that we implement a more widely available and accessible system for resetting forgotten PINs. This comment relates to TSA's procedures for resetting PINs. We have provided these comments to TSA for their consideration. TSA currently protects PINs by securely locking them on the card as required by the Federal Information Processing Standards 201-1 (FIPS 201). PIN reset requires virtual private network (VPN) access to the
TWIC system available only at TWIC enrollment centers. TSA is looking at possible alternatives and updates to the current PIN reset policy.
4. Utility of TWIC Readers in Reducing TSI Vulnerability
Many commenters acknowledged the utility of the TWIC program in reducing TSI vulnerability, though they expressed differing opinions on the utility of TWIC readers in that regard. Some asserted that TWIC readers would not reduce risks, especially on small vessels where crewmembers are familiar with one another, and on vessels where restricted areas are already protected by other access control mechanisms. Several of these commenters expressed the opinion that TWIC effectively reduces risk insofar as personnel are required to complete a rigorous security threat assessment in order to obtain a TWIC; yet, they believe that TWIC readers would provide no additional risk reduction benefit. Although one of these commenters acknowledged the potential utility of TWIC readers at large facilities and on large vessels, this group of commenters generally opposed all of the proposed TWIC reader requirements.
Other commenters took the opposite view. Several argued that the TWIC's security benefits would only be realized through the institution of a standard requirement to use TWIC readers at all MTSA-regulated vessels and facilities. One point emphasized by this group of commenters is that visual inspection as a means of identity verification would not effectively detect counterfeit TWICs.
One commenter favored an approach in which TWIC readers are used in addition to—not in place of—visual comparison of the TWIC-holder to the photograph on the TWIC. Another commenter favored an approach in which owners and operators would be required to conduct random electronic biometric matches using a TWIC reader, as opposed to using a TWIC reader each time an individual accesses secure areas. Finally, one commenter suggested that we include an option that would allow owners and operators to schedule periodic Coast Guard visits for the purpose of conducting comprehensive inspections using the Coast Guard's portable TWIC readers.
The wide ranging nature of these comments demonstrates the need for an analysis of the impacts of TWIC reader requirements in the maritime sector. Similarly, Congress had also mandated a thorough analysis of TWIC reader utility in the SAFE Port Act by requiring the Secretary to “ * * * conduct a pilot program to test the business processes, technology, and operational impacts required to deploy * * * [TWIC] readers at secure areas of the maritime transportation system.”
51
At the time we published the ANPRM and received the comments above, TSA had not yet completed data collection for the TWIC Pilot. TSA completed data collection for the TWIC Pilot on May 31, 2011. In accordance with the SAFE Port Act, we crafted the proposals in this NPRM in a manner consistent with the findings of the TWIC Pilot.
52
51
46 U.S.C. 70105(k).
52
46 U.S.C. 70105(k).
The TWIC Pilot was designed to assess, among other things, the utility of TWIC readers in enhancing security. The TWIC Pilot found that when designed, installed, and operated in a manner consistent with the business considerations of the vessel or facility, TWIC readers enhance security by reducing the risk that an unauthorized individual could gain access to secure areas. The TWIC Pilot also found that TWIC readers enhance security by enabling owners and operators to assign secure area access privileges to a limited population of TWIC-holders. The proposals in this NPRM to require TWIC readers are consistent with the findings of the TWIC Pilot and were developed to reduce TSI vulnerability at MTSA-regulated facilities and vessels.
5. TWIC Reader Requirements on Vessels
Many commenters expressed opposition to any requirement for TWIC readers on vessels. These commenters argued that TWIC readers on vessels would be expensive, impractical, ineffective in enhancing security, and would put U.S.-flagged vessels at a competitive disadvantage relative to foreign-flagged vessels that can operate without TWIC readers. Instead, these commenters favored using TWIC as a visual identity badge on vessels. They argued that the greatest value of the TWIC program is not as an access control device, but rather as a reliable, standardized means to establish the identity and background of new employees. The commenters emphasized that TWIC readers would likely cause logistical problems, and would be unnecessary on vessels in which crew size is relatively small, because crewmembers are familiar with one another. Finally, the commenters believed that TWIC readers are unnecessary on vessels because, in most cases, TWIC-holders accessing vessels have already had their TWICs checked using a TWIC reader at shore-side facilities and during Coast Guard inspections.
One commenter felt that there might be limited utility to TWIC readers on vessels. Another commenter proposed an alternative approach that would require vessel owners and operators to specify a certain percentage of individuals on board for random biometric matches using a TWIC reader.
As mentioned previously, we rely on the TWIC Pilot's finding that TWIC readers enhance security when used properly. Additionally, we recognize that many of the commenters arguing against the proposed requirement for TWIC readers on vessels expressed the interest of owners and operators of vessels in Risk Group B. After considering the public comments and additional analysis, we have eliminated from this NPRM the proposal to require TWIC readers on vessels in Risk Group B. As discussed more fully below in Section IV., “Section-by-Section Description of Proposed Rule,” this NPRM proposes TWIC reader requirements for vessels in Risk Group A only. Moreover, this NPRM proposes to exempt from TWIC reader requirements all vessels with 14 or fewer TWIC-holding crewmembers. These measures should alleviate most of the concerns raised by commenters with respect to the costs and logistics of TWIC readers on vessels and on the limits for utility on vessels with 14 or fewer crewmembers.
Some commenters expressed the opinion that on small vessels, even a requirement to use the TWIC as a visual identity badge is an unnecessary burden that would confer little or no security benefit. We disagree with this comment. A security benefit is conferred when a vessel owner or operator is able to confirm that each entrant to a secure area holds a TWIC.
One commenter requested clarification as to whether a vessel owner or operator would be required to check TWICs electronically on days the vessel does not sail. We wish to clarify that TWIC reader requirements are triggered when individuals are granted access to secure areas, regardless of whether a vessel sails.
6. TWIC Reader Requirements for Risk Group A
a. Risk Group A Classification
Two commenters questioned why Risk Group A includes facilities that handle bulk CDC, but does not include facilities that handle non-bulk Division 1.1 or 1.2 explosives. We reiterate that based on the AHP/MSRAM data and analysis, facilities that handle non-bulk
substances did not warrant placement in Risk Group A. Such facilities generated lower AHP scores because unlike bulk CDC, Division 1.1 or 1.2 explosives are segregated and kept in smaller quantities.
b. Risk Group A TWIC Reader Requirements
Six commenters representing owners and operators of large vessels or facilities expressed general concerns that the ANPRM's proposed TWIC reader requirements would present significant operational challenges. Another commenter stated that it would be burdensome if TWIC readers had to be manually updated to keep CCL information current.
In considering these comments, we note that the TWIC Pilot elicited a variety of lessons learned with respect to the operational impacts of deploying TWIC readers in the maritime sector. The TWIC Pilot generally found that when TWIC readers are designed, installed, and operated in a manner consistent with the business considerations of the vessel or facility, they function properly.
We believe that the proposals in this NPRM appropriately consider the findings of the TWIC Pilot and implement the TWIC reader requirements mandated by MTSA and the SAFE Port Act in a manner that enhances the nation's maritime security without imposing undue burdens. More information on the economic analysis for this proposed rule is provided below in Section V. “Regulatory Analyses.”
We also note that in the TWIC 1 Final Rule, we revised 33 CFR 105.115 to permit owners and operators to redefine their “secure area” as only that portion of their access control area that is directly related to maritime transportation. This revision was intended to provide greater flexibility to facility owners and operators in dealing with the operational impacts of implementing the TWIC program at each individual facility. Additionally, as discussed above, we are also considering allowing multiple risk group designations within one facility, to account for situations where one portion of a facility handles dangerous cargoes and another portion does not.
7. TWIC Reader Requirements for Risk Group B
a. Risk Group B Classification
Numerous commenters expressed the opinion that Risk Group B is over-inclusive in terms of the types of vessels and facilities covered. Many argued that OCS facilities subject to 33 CFR part 106 do not present risks that warrant placement in Risk Group B.
Two commenters argued that tank vessels as defined in 33 CFR Subchapter D should not be placed in Risk Group B. One commenter suggested that with respect to crewmembers on Subchapter D vessels, the only requirement to scan their TWICs using a TWIC reader should be upon initial hiring at the employer's home office.
One commenter whose vessel is licensed for 800 passengers and carries a crew of six argued that TWIC reader requirements would be a financial burden that provides no appreciable security benefit. In response, we note that in this NPRM, we do not propose to require TWIC readers for Risk Group B.
One commenter argued that facilities handling no hazardous materials other than asphalt cement do not present risks that warrant placement in Risk Group B. The commenter requested that we specifically exclude from Risk Group B facilities that handle products designated as hazardous only due to storage and handling at elevated temperatures. Two commenters suggested that for purposes of this rule, the term “hazardous materials” should not be defined by reference to 49 CFR 172. One of these commenters argued that this definition would cover many products that present little or no risks. Instead, the commenter suggested that we adopt the definition of “hazardous materials” used by TSA and/or the Pipeline and Hazardous Materials Safety Administration.
We wish to clarify that the term “hazardous materials” is defined in 33 CFR part 101.105 as those materials subject to regulation under 46 CFR parts 148, 150, 151, 153, or 154, or 49 CFR parts 171 through 180. We believe that the types of vessels and facilities referenced in the comments above are appropriately placed in Risk Group B based on the AHP/MSRAM analysis. We further believe that the comments above seeking re-classification out of Risk Group B resulted from the ANPRM's proposal to require TWIC readers for Risk Group B. We reiterate that, based on the comments and additional analysis, this NPRM does not propose TWIC reader requirements for Risk Group B.
b. Risk Group B TWIC Reader Requirements
One commenter believed that the ANPRM's proposed requirements for Risk Group B are appropriate. Another commenter argued that identity verification upon each entry to a secure area would be too burdensome. Another commenter argued that the proposed TWIC reader requirements in the ANPRM for Risk Group B at MARSEC Level 2 would be too burdensome. Finally, two commenters argued that, as a general matter, the ANPRM's proposals are too burdensome because they would require vessels and facilities in Risk Group B to have both a TWIC reader and a security guard to visually inspect TWICs as well.
Several commenters argued that the ANPRM's requirement for Risk Group B to conduct random monthly scans using a TWIC reader would be costly and provide minimal security benefits, especially if done on a low volume or non-work day. Other commenters requested clarification as to whether the ANPRM's approach would require monthly scans on all TWIC-holders associated with a vessel or facility, or only on the TWIC-holders visiting the vessel or facility on a specific day.
Several commenters proposed alternative TWIC requirements for Risk Group B. Some suggested approaches that rely less on TWIC readers than did the ANPRM's approach. For example, two commenters suggested requiring only visual TWIC checks for identity verification, card authentication, and card validation as a routine matter at MARSEC Level 1. Thus, scans using a TWIC reader would only be required once per month at MARSEC Level 1, but would remain a standard procedure at higher MARSEC Levels. Another commenter suggested that card validity checks should be required on small vessels less frequently than as proposed in the ANPRM. Two commenters opposed the ANPRM's requirement to perform monthly scans using a TWIC reader at MARSEC Level 1.
Other commenters suggested alternative approaches that rely more on TWIC readers than did the ANPRM's approach. For example, several commenters suggested that owners and operators of vessels or facilities in Risk Group B should always be required to use TWIC readers to perform identity verification, arguing that visual checks are less reliable. Some of these commenters argued that unlike random monthly scans using a TWIC reader, routine use of TWIC readers would provide TWIC-holders the benefit of a consistent user experience.
Based on the comments and further analysis, this NPRM does not propose TWIC reader requirements for Risk Group B. We have estimated the annualized cost of the TWIC reader requirements on vessels and facilities in Risk Group A at $26.5 million, at a 7 percent discount rate. Had we proposed TWIC reader requirements to also
include Risk Group B facilities, the annualized cost would be $141.2 million, at a 7 percent discount rate. Moreover, including Risk Group B in the TWIC reader requirements would not only increase the annualized cost, the average consequence figure (the monetized costs of fatalities and injuries resulting from a TSI) drops by more than one-third. While this does not mean that there should be no TWIC reader requirements for Risk Group B, we believe this analysis supports our phased approach for requiring TWIC readers first for Risk Group A.
We also wish to emphasize the utility of TWIC in enhancing security even when not used in conjunction with TWIC readers. Before mariners and other individuals were required to obtain a TWIC, they could access secure areas of MTSA-regulated vessels and facilities after presenting a State-issued driver's license or any number of other government-issued identification cards. This patchwork system of valid credentials required security personnel to become familiar with the appearance and security features of every type of acceptable credential. Moreover, since some government-issued credentials are used for purposes other than security, applicants are not necessarily screened from a security threat perspective. Additionally, the eligibility criteria for some government-issued credentials do not preclude issuance to an individual with a felony criminal record.
The TWIC program mitigates the above shortcomings. Since April 15, 2009, TWIC has been the single credential used throughout the maritime sector. Accordingly, security personnel only need to become familiar with the appearance and security features of one credential. Moreover, unlike other government-issued credentials, TWIC is specifically designed for transportation security. Its purpose is to ensure a vetted maritime workforce by establishing security-related eligibility criteria, and by requiring each TWIC-holder to undergo TSA's security threat assessment as part of the process of applying for and obtaining a TWIC.
As we go forward with our phased approach to implementing TWIC reader requirements, we will continue to evaluate the use of TWIC readers on vessels and at facilities, and determine the need for additional or different TWIC reader requirements. Proposing requirements for Risk Group A only in this NPRM is indicative of our desire to minimize highest risks first, but should not be read to foreclose revised TWIC reader requirements in the future.
Several commenters argued that container (cargo) facilities present risks that actually warrant the more stringent TWIC reader requirements of Risk Group A rather than those of Risk Group B. In response, we note that, based on the AHP/MSRAM analysis, being a container facility alone did not automatically cause a facility to be categorized in Risk Group B. In addition, several factors led the Coast Guard to decide not to require TWIC readers for most of these facilities at this time. First, there are limits on the additional risk reduction (above and beyond the credentialing and visual identification purposes of the TWIC itself) of TWIC readers at container facilities. Security risk in the maritime sector can be considered as following one of three high-level scenarios: (1) The asset in question could be the target of an attack; (2) the asset in question could be used as a weapon for an attack; or (3) the asset could be used to enable or facilitate an attack elsewhere. For container facilities, the first scenario brings low risk given the number of personnel concentrated and exposed to an attack and limited storage of hazardous materials. Similarly, the second scenario brings low risk as containers bring low risk of use as a weapon. Furthermore, the use of TWIC readers, or other access control features, would not mitigate the threat associated with the contents of a container. The TWIC reader serves as an additional access control measure, but would not improve screening of cargoes for dangerous substances or devices. The third scenario is the primary risk driver for container facilities, with the risk of containers used to smuggle illicit materials and/or personnel into the country. The additional verifications provided by TWIC readers, however, would bring limited utility to this scenario. Those individuals looking to access the contents of the container could do so after the container exits the secured area. As such, TWIC readers bring limited additional risk reduction over the TWIC itself. Additionally, requiring TWIC readers at container facilities brings significant costs, as these facilities typically have a higher number of access points per facility (and therefore would incur more capital costs) and higher numbers of personnel accessing the facility. While the additional time to use the TWIC reader to conduct a biometric match over the visual inspection is limited on an individual basis, the high volume of workers could cause the associated delay costs to accrue to much more significant levels than other facility types. Given the large numbers of truck drivers accessing these facilities, these delays would also be accompanied by increased air emissions, resulting in greater potential for environmental impact. Therefore, in this NPRM, only those container facilities that are otherwise categorized in Risk Group A would be required to use TWIC readers. We will continue to assess whether container facilities warrant additional consideration with respect to TWIC reader requirements. We welcome additional comments from the public on the risk group classification of container facilities.
8. TWIC Requirements for Risk Group C
a. Risk Group C Classification
One commenter supported the ANPRM's classification of OSVs in Risk Group C. One commenter suggested that the passenger cutoff number for vessels in Risk Group C should not be 500. Instead, this commenter argued that the cutoff number should be 49 overnight passengers or 150 passengers, similar to the Coast Guard's vessel safety regulations. In response, we reiterate that the AHP/MSRAM analysis considered factors based on TSI consequence. These factors are different than the factors that underpin the Coast Guard's safety regulations. The passenger cutoff numbers derived from the AHP/MSRAM analysis are more appropriate for defining the risk-based framework for TWIC reader requirements.
b. Risk Group C TWIC Requirements
Many commenters agreed with the ANPRM's approach that TWIC reader requirements would not appreciably enhance security for vessels and facilities in Risk Group C. One commenter further argued that since vessels and facilities in Risk Group C are so low risk, even visual TWIC inspections would be an unnecessary burden that would confer no security benefit. As noted above, however, several commenters took the opposing view, broadly asserting that owners and operators of all MTSA-regulated vessels and facilities (including those in Risk Group C) should be required to use TWIC readers to control access to secure areas.
We believe that although vessels and facilities in Risk Group C present a less likely target for individuals wishing to do harm, these vessels and facilities still hold the potential of being involved in a TSI and with consequences that could still be significant. A security benefit is conferred when an owner or operator is able to confirm that each entrant to secure areas holds a TWIC, as the TWIC serves as evidence that the person has
successfully passed TSA's security threat assessment. Accordingly, this NPRM proposes the same requirements as the ANPRM for Risk Group C, which includes requirements to visually inspect TWICs before granting unescorted access to secure areas, as is already required in the current regulations.
Some commenters asked whether vessels and facilities in Risk Group C would need dedicated security guards to perform visual TWIC checks, and what credentials these security guards would need to possess. Under current regulations (which would not change under this NPRM) for vessels and facilities categorized in this NPRM as Risk Group C, security personnel must visually inspect the TWIC of each person seeking unescorted access to secure areas. Our regulations do not require the use of “dedicated security guards,” but do require that the security personnel doing visual inspection of TWICs have certain knowledge, training, and experience. It is important for owners, operators, and others with security duties to be familiar with the technologies embedded in the TWIC, particularly the features that make the TWIC resistant to tampering and forgery. Those who would be examining TWICs at access control points should be familiar enough with the TWIC's physical appearance so that variations or alterations are easily recognized. Relevant security training requirements for personnel on vessels and at facilities are found at 33 CFR 104.210, 104.215, 104.220, 104.225, 105.205, 105.210, 105.215, 106.205, 106.210, 106.215, and 106.220.
9. Physical Placement of TWIC Readers
Eight commenters requested clarification as to whether TWIC readers would be required at the access points to each secure area or at the perimeter access points to the vessel or facility. Three commenters suggested that vessels should not be required to place TWIC readers at every access point to a secure area. Instead, according to these commenters, vessels required to have TWIC readers should only be required to place them at the main access points to the vessels. Several commenters expressed concerns that if TWIC readers are required at the access points to each secure area on vessels, safety would be compromised in emergency situations when crewmembers need immediate access to those areas.
We wish to clarify that for both vessels and facilities, the term “secure area” is defined as “* * * the area * * * over which the owner/operator has implemented security measures for access control * * *. It does not include passenger access areas, employee access areas, or public access areas * * *.”
53
For facilities, the secure area may encompass the entire facility, or the facility may consist of a combination of secure areas and public access areas. Similarly, for vessels, the secure area may encompass the entire vessel, or the vessel may consist of a combination of secure areas and passenger and employee access areas.
53
33 CFR 101.105.
This NPRM proposes different requirements for vessels and facilities with respect to the placement of TWIC readers. For facilities, this NPRM proposes to require TWIC readers at the access points to each secure area. If the entire facility is designated as a secure area, then TWIC readers would only be required at the access points to the facility itself. If the secure area does not encompass the entire facility, then TWIC readers would be required at the access points to each secure area.
For vessels, this NPRM proposes to require TWIC readers at the access points to the vessel itself, regardless of whether the secure area encompasses the entire vessel. Thus, even if the secure area does not encompass the entire vessel (e.g., a passenger vessel consisting of secure areas and passenger and employee access areas), TWIC readers would only be required at the access points to the vessel itself. TWIC-holders may be granted unescorted access to the vessel's secure areas after the TWIC has been verified, validated, and authenticated at a vessel access control point. TWIC-holders may then move between secure areas and passenger and employee access areas without processing through a TWIC reader each time. We request additional comments from the public on the proposed regulatory provisions regarding the placement of TWIC readers for vessels and facilities, and how to minimize crewmembers from entering secure and/or restricted areas if they do not hold a TWIC.
With respect to emergency situations, we partially addressed this issue in the TWIC 1 Final Rule, and added a paragraph to 33 CFR 101.514 clarifying that emergency personnel need not have TWICs to obtain unescorted access to secure areas during emergencies. Moreover, this NPRM does not propose to require TWIC readers on vessels at each access point to a secure area. Instead, TWIC readers would only be required at the access points to the vessel itself.
One commenter suggested that with respect to OCS facilities, the appropriate location for TWIC reader placement is not on the facility itself, but, rather, at the shore-side points of embarkation for the facility. This comment echoes a recommendation from NMSAC in the TWIC 1 NPRM,
54
to which we responded that OCS facilities where access is limited and can be controlled by reading the TWIC at the point of embarkation may continue to do so. Note that this NPRM does not propose TWIC reader requirements for any OCS facilities. Accordingly, OCS facilities where access is limited and can be controlled by visually inspecting the TWIC at the point of embarkation may do so.
54
See
71 FR 29405.
One commenter suggested that owners and operators of facilities should not be required to use TWIC readers on docks and other waterside access points. In response, we emphasize that we are not proposing a blanket exemption from TWIC reader requirements on docks and other waterside access points. As proposed in this NPRM, owners and operators of facilities in Risk Group A would be required to ensure that access to secure areas is limited to individuals whose TWICs have been scanned by a TWIC reader.
We also note that in the TWIC 1 Final Rule, we revised 33 CFR 105.115 to provide greater flexibility to facility owners and operators by allowing them the option to redefine their “secure area” as only that portion of their access control area that is directly related to maritime transportation. Thus, facilities whose footprint includes portions that are not directly related to maritime transportation can submit an FSP for Coast Guard approval that removes those areas from the definition of the facility's “secure area” for Coast Guard regulatory purposes. Such facilities would typically include refineries, chemical plants, factories, mills, power plants, smelting operations, or recreational boat marinas. As discussed above, we are also considering allowing multiple risk group designations within one facility, to account for situations where one portion of a facility handles dangerous cargoes and another portion does not. Owners and operators should comply with TWIC reader requirements in a manner that considers the specific nature of their facilities and their access points, and they may take advantage of regulatory provisions that would minimize the impact on operations.
10. Recurring Unescorted Access
Numerous commenters generally supported the ANPRM's provision
regarding RUA as a means of providing relief to owners and operators otherwise required to use TWIC readers. Many of these commenters expressed differing opinions regarding the proposed cutoff number of 14. Six commenters stated that 14 is an appropriate cutoff number. More than 25 commenters felt that the cutoff number should be higher. One commenter felt that the cutoff number should be lower. Several commenters argued that 14 is an arbitrary cutoff number, though they offered no rationale or alternative cutoff number. Five commenters suggested that the cutoff number should be approved by the COTP on a case-by-case basis, considering factors such as an entity's size and whether a vessel operates with multiple crews.
Several commenters requested clarification regarding whether an entity could grant RUA privileges to contractors, vendors, and other frequent visitors.
Approximately eight commenters opposed the ANPRM's RUA proposal, suggesting instead that we should simply exempt all vessels with fewer than 14 TWIC-holders on board from TWIC reader requirements. One commenter noted that such an exemption would fall squarely within the SAFE Port Act's provision that prohibits requiring TWIC readers on vessels that the Secretary has determined do not have the requisite number of TWIC-holders as crewmembers.
55
55
46 U.S.C. 70105(m)(1).
Two commenters argued that RUA would compromise security by granting unescorted access to secure areas without requiring individuals to undergo screening using a TWIC reader.
One commenter felt the phrase “recurring unescorted access” could be misinterpreted to mean that an individual may require an escort to access a secure area, even if the individual is a TWIC-holder.
Several commenters opposed a requirement to perform the initial biometric scan using a TWIC reader on TWIC-holders granted RUA. Their rationale was that TSA already performs reliable biometric identity verification prior to the issuance of each individual's TWIC. Some commenters also raised concerns of potential fraud that could arise if, as suggested in the ANPRM, an owner or operator pursued an agreement with a facility or other company to borrow or otherwise have access to a TWIC reader in order to perform the one-time initial biometric verification.
One commenter felt that the proposed initial biometric scan requirement would be appropriate. Another commenter felt that owners and operators should be required to perform an electronic biometric scan using a TWIC reader at the beginning of each shift for each TWIC-holder granted RUA.
Three commenters argued that owners and operators granting RUA privileges should not be required to purchase a TWIC reader to perform initial biometric scans on RUA grantees. Two commenters suggested that an Internet-based system would provide the most practical method for keeping track of RUA grantees.
One commenter called attention to the fact that employee records regarding individuals granted RUA would be kept by the employer, not the Coast Guard or TSA.
After considering the comments and further analysis discussed below in Section IV., “Section-by-Section Description of Proposed Rule,” we have removed from this NPRM the RUA provisions proposed in the ANPRM. RUA was previously proposed to introduce flexibility and provide relief to vessels otherwise required to use TWIC readers, based on the familiarity that exists between a relatively small number of crewmembers. This NPRM incorporates two important proposals, however, that render RUA an unnecessary provision. First, unlike the ANPRM, which proposed TWIC reader requirements for Risk Groups A and B, this NPRM proposes TWIC reader requirements for Risk Group A only. Second, this NPRM proposes a broad exemption from TWIC reader requirements for all vessels with 14 or fewer TWIC-holding crewmembers. This exemption is based on the SAFE Port Act's provision that prohibits requiring TWIC readers on vessels that the Secretary has determined do not have the requisite number of TWIC-holders as crewmembers.
56
These two changes render the need for RUA as a mechanism for regulatory relief unnecessary.
56
46 U.S.C. 70105(m)(1).
11. TWIC Reader Durability,
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.