Security Training for Surface Transportation Employees

Federal RegisterDec 16, 2016

Ask Donna

What actually matters in this document.

Text

DEPARTMENT OF HOMELAND SECURITY

Transportation Security Administration

49 CFR Parts 1500, 1520, 1570, 1580, 1582, and 1584

[Docket No. TSA-2015-0001]

RIN 1652-AA55

Security Training for Surface Transportation Employees

AGENCY:

Transportation Security Administration, DHS.

ACTION:

Notice of proposed rulemaking (NPRM).

SUMMARY:

The Transportation Security Administration (TSA) is proposing to require security training for employees of higher-risk freight railroad carriers, public transportation agencies (including rail mass transit and bus systems), passenger railroad carriers, and over-the-road bus (OTRB) companies. Owner/operators of these higher-risk railroads, systems, and companies would be required to train employees performing security-sensitive functions, using a curriculum addressing preparedness and how to observe, assess, and respond to terrorist-related threats and/or incidents. As part of this rulemaking, TSA would also expand its current requirements for rail security coordinators and reporting of significant security concerns (currently limited to freight railroads, passenger railroads, and the rail operations of public transportation systems) to include the bus components of higher-risk public transportation systems and higher-risk OTRB companies. TSA also proposes to make the maritime and land transportation provisions of TSA's regulations consistent with other TSA regulations by codifying general responsibility to comply with security requirements; compliance, inspection, and enforcement; and procedures to request alternate measures for compliance. Finally, TSA is adding a definition for Transportation Security-Sensitive Materials (TSSM). Other provisions are being amended or added, as necessary, to implement these additional requirements.

While TSA will review and consider all comments submitted, TSA invites responses to a number of specific questions posed in the preamble of the NPRM.

See

the Comments Invited section under

SUPPLEMENTARY INFORMATION

that follows.

DATES:

Submit comments by March 16, 2017.

ADDRESSES:

You may submit comments, identified by the TSA docket number to this rulemaking, to the Federal Docket Management System (FDMS), a government-wide, electronic docket management system, using any one of the following methods:

Electronically:

You may submit comments through the Federal eRulemaking portal at

http://www.regulations.gov.

Follow the online instructions for submitting comments.

Mail, In Person, or Fax:

Address, hand-deliver, or fax your written comments to the Docket Management Facility, U.S. Department of Transportation, 1200 New Jersey Avenue SE., West Building Ground Floor, Room W12-140, Washington, DC 20590-0001; Fax 202-493-2251. The Department of Transportation (DOT), which maintains and processes TSA's official regulatory dockets, will scan the submission and post it to FDMS.

See

SUPPLEMENTARY INFORMATION

for format and other information about comment submissions.

FOR FURTHER INFORMATION CONTACT:

Harry Schultz (TSA Office of Security Policy and Industry Engagement) or Traci Klemm (TSA Office of the Chief Counsel) at telephone (571) 227-5563 or email to

SecurityTrainingPolicy@tsa.dhs.gov.

SUPPLEMENTARY INFORMATION:

Comments Invited

TSA invites interested persons to participate in this rulemaking by submitting written comments, data, or views. We also invite comments relating to the economic, environmental, energy, or federalism impacts that might result from this rulemaking action. See

ADDRESSES

above for information on where to submit comments.

With each comment, please identify the docket number at the beginning of your comments. TSA encourages commenters to provide their names and addresses. The most helpful comments reference a specific portion of the rulemaking, explain the reason for any recommended change, and include supporting data. You may submit comments and material electronically, in person, by mail, or fax as provided under

ADDRESSES

, but please submit your comments and material by only one means. If you submit comments by mail or delivery, submit them in an unbound format, no larger than 8.5 by 11 inches, suitable for copying and electronic filing.

If you want TSA to acknowledge receipt of comments submitted by mail, include with your comments a self-addressed, stamped postcard on which the docket number appears. We will stamp the date on the postcard and mail it to you.

TSA will file in the public docket all comments TSA receives, except for comments containing confidential information and Sensitive Security Information (SSI).

1

TSA will consider all comments received on or before the closing date for comments and will consider comments filed late to the extent practicable. The docket is available for public inspection before and after the comment closing date.

1

“Sensitive Security Information” or “SSI” is information obtained or developed in the conduct of security activities, the disclosure of which would constitute an unwarranted invasion of privacy, reveal trade secrets or privileged or confidential information, or be detrimental to the security of transportation. The protection of SSI is governed by 49 CFR parts 15 and 1520.

NPRM Specific Questions

While TSA will review and consider all comments submitted, TSA invites responses to the following five specific questions:

(1) The preferred avenue to submit security training programs to TSA, such as through email, secure Web site, or mailing address.

(2) TSA is proposing to use accumulated days of employment as one of the factors triggering whether an employee must be trained and requests comment specifically on how to calculate accumulated days and to ensure contractors are not used to avoid the requirements of this proposed rule.

(3) The use of previous training to satisfy requirements in the proposed rule.

(4) Options for harmonizing the proposed training schedule with existing training schedules and for adding efficiencies with other relevant regulatory requirements, including identification of any laws, regulations, or orders not identified by TSA that commenters believe would conflict with the provisions of the proposed rule.

(5) Options for ensuring training is effective in the absence of proficiency standards. For example, the proposed rule does not prescribe conditions for a pass/fail policy that may be associated with post-training testing, nor recommending a specified maximum number of times that an individual may take a test or evaluation to demonstrate knowledge and competency.

Handling of Confidential or Proprietary Information and Sensitive Security Information (SSI) Submitted in Public Comments

Do not submit comments that include trade secrets, confidential commercial

or financial information, or SSI to the public regulatory docket. Please submit such comments separately from other comments on the rulemaking. Comments containing this type of information must be appropriately marked as containing such information and submitted by mail to the address listed in

FOR FURTHER INFORMATION CONTACT

section.

TSA will not place comments containing SSI in the public docket, but will handle them in accordance with applicable safeguards and restrictions on access. TSA will hold documents containing SSI, confidential business information, or trade secrets in a separate file to which the public does not have access, and place a note in the public docket that TSA has received such materials from the commenter. If TSA determines, however, that portions of these comments may be made publicly available, TSA may include a redacted version of the comment in the public docket. If TSA receives a request to examine or copy information that is not in the public docket, TSA will treat it as any other request under the Freedom of Information Act (FOIA) (5 U.S.C. 552) and FOIA regulation of the Department of Homeland Security (DHS) found in 6 CFR part 5.

Reviewing Comments in the Docket

Please be aware that anyone is able to search the electronic form of all comments in any of our dockets by the name of the individual who submitted the comment (or signed the comment, if submitted on behalf of an association, business, labor union,

etc.

). You may review the applicable Privacy Act Statement published in the

Federal Register

on April 11, 2000 (65 FR 19477) and modified on January 17, 2008 (73 FR 3316), or you may visit

http://DocketsInfo.dot.gov.

You may review TSA's electronic public docket on the Internet at

http://www.regulations.gov.

In addition, DOT's Docket Management Facility provides a physical facility, staff, equipment, and assistance to the public. To obtain assistance or to review comments in TSA's public docket, you may visit this facility between 9:00 a.m. and 5:00 p.m., Monday through Friday, excluding legal holidays, or call (202) 366-9826. This docket operations facility is located in the West Building Ground Floor, Room W12-140 at 1200 New Jersey Avenue SE., Washington, DC 20590.

Availability of Rulemaking Document

An electronic copy can be obtained using the Internet by—

(1) Searching the electronic Federal Docket Management System (FDMS) Web page at

http://www.regulations.gov;

(2) Accessing the Government Printing Office's Web page at

http://www.gpo.gov/fdsys/browse/collection.action?collectionCode=FR

to view the daily published

Federal Register

edition; or accessing the “Search the

Federal Register

by Citation” in the “Related Resources” column on the left, if you need to do a Simple or Advanced search for information, such as a type of document that crosses multiple agencies or dates.

In addition, copies are available by writing or calling the individual in the

FOR FURTHER INFORMATION CONTACT

section. Make sure to identify the docket number of this rulemaking.

Abbreviations and Terms Used in This Document

AAR—Association of American Railroads

ABA—American Bus Association

Amtrak—National Railroad Passenger Corporation

APTA—American Public Transportation Association

CD—Compact Disc

CCTV—Closed-Circuit Television

CFATS—Chemical Facility Anti-Terrorism Standards

CFATS EAP—Expedited Approval Program for the CFATS program

CFATS RBPS—Risk-Based Performance Standards of the CFATS program

CFATS SSP—Site Specific Plans part of the CFATS program

DHS—Department of Homeland Security

DIF—Difficulty-Importance-Frequency

EOD—Explosives Ordinance Disposal

FMCSA—Federal Motor Carrier Safety Administration

FRA—Federal Railroad Administration

FTA—Federal Transit Administration

GAO—U.S. Government Accountability Office

GCC—Government Coordinating Council

HMR—Hazardous Materials Regulations

HSA—Homeland Security Act of 2002

HTUA—High Threat Urban Area

IED—Improvised Explosive Device

IFR—Interim Final Rule

IRFA—Initial Regulatory Flexibility Analysis

MOU—Memorandum of Understanding

NCTC—National Counterterrorism Center

NSI—Nationwide Suspicious Activity Reporting (SAR) Initiative

OAs—Oversight Agencies

OMB—Office of Management and Budget

OTRB—Over-the-Road Bus

PAG—Transit Policing and Security Peer Advisory Group

PHMSA—Pipeline and Hazardous Materials Safety Administration

PRA—Paperwork Reduction Act of 1995

PTPR—Public Transportation and Passenger Railroads

RFA—Regulatory Flexibility Act of 1980

RIA—Regulatory Impact Analysis

RSC—Rail Security Coordinator

RSSM—Rail Security-Sensitive Material

SBA—Small Business Administration

SCC—Sector Coordinating Council

SMS—Safety Management System

SSI—Sensitive Security Information

TIH—Toxic Inhalation Hazard

TSA—Transportation Security Administration

TSGP—Transit Security Grant Program

TSSM—Transportation Security Sensitive Material

UASI—Urban Area Security Initiative

UMRA—Unfunded Mandates Reform Act of 1995

VBIED—Vehicle-Borne Improvised Explosive Device

Table of Contents

I. Executive Summary

II. Background

A. Context and Purpose

B. Statutory Authorities

C. Rule Organization

III. Proposed Rule

A. Amendments to Part 1500

1. General Terms

2. Transportation Security-Sensitive Materials

B. Amendments to Part 1503

C. Amendments to Part 1520

D. Amendments to Part 1570

1. Overview of changes and structure

2. Subpart A—General

3. Subpart B—Security Programs

4. Subpart C—Operations

5. Subpart D—Security Threat Assessments

E. Security-Sensitive Employees (§§ 1580.3, 1582.3, and 1584.3)

F. Security Programs—Applicability (§§ 1580.301, 1582.301, and 1584.301)

1. Freight Railroads

2. Public Transportation and Passenger Railroads

3. Over-the-Road Buses

4. Foreign Owner/Operators

5. Preemption

G. Security Program General Requirements (§§ 1580.113, 1582.113, and 1584.113)

1. Information About the Owner/Operator

2. Information on How Training Will Be Provided

3. Ensuring Supervision of Untrained Employees and Providing Notice of Changes Affecting Training

4. Methods for Determining Effectiveness of Training

5. Relation to Other Training

H. Security Training and Knowledge for Security-Sensitive Employees (§§ 1580.115, 1582.115 and 1584.115)

1. Training Required for Security-Sensitive Employees

2. Limits on Use of Untrained Employees

3. Knowledge Required

I. Other Security Training Programs

1. Federal Railroad Administration Safety Training Requirements

2. Federal Transit Administration Safety Requirements

3. OTRB Safety Requirements

4. Hazardous Materials Regulations

a. Overlap With DOT Regulations Regarding Transportation of Hazardous Materials

b. Inspections and Enforcement

c. Overlap With Other DHS Regulations

J. Training Resources

K. Programmatic Alternatives

IV. Stakeholder Consultations

A. Multi-Modal Outreach

B. Freight Rail

C. Public Transportation and Passenger Rail

D. Over-the-Road Buses

E. Labor Unions

V. Rulemaking Analyses and Notices

A. Paperwork Reduction Act

B. Economic Impact Analyses

1. Regulatory Impact Analysis Summary

2. Executive Orders 12866 and 13563 Assessments

3. OMB A-4 Statement

4. Alternatives Considered

5. Regulatory Flexibility Assessment

6. International Trade Impact Assessment

7. Unfunded Mandates Assessment

C. Executive Order 13132, Federalism

D. Environmental Analysis

E. Energy Impact Analysis

I. Executive Summary

Purpose of the Regulatory Action

The purpose of this proposed rule is to solidify the enhanced baseline of security for higher-risk surface transportation operations by improving and sustaining the capability of employees to observe, assess, and respond to security risks and potential security breaches. These critical capabilities include identifying, reporting, and appropriately reacting to suspicious activity, suspicious items, dangerous substances, and security incidents that may be associated with terrorist reconnaissance, preparation, or action. The proposed requirements specifically apply to training employees performing security-sensitive job functions for higher-risk public transportation systems, railroad carriers (passenger and freight), and OTRB owner/operators. Preparing and training these employees to observe, assess, and respond to anomalies, threats, and incidents within their unique working environment may be the critical point for preventing a terrorist act and mitigating the consequences.

Since its creation following the attacks of September 11, 2001, TSA has had statutory authority to assess a security risk for any mode of transportation, develop security measures for dealing with that risk, and enforce compliance with those measures.

2

This includes broad regulatory authority, which enables TSA to issue, rescind, and revise regulations as necessary to carry out its transportation security functions.

3

As part of the Implementing Recommendations of the 9/11 Commission Act of 2007 (9/11 Act),

4

Congress mandated that DHS use its authority to issue regulations and included in the statute minimum requirements for employees to be trained, subjects of training, and procedures for the submission and approval of training programs.

5

As part of this mandate, the 9/11 Act also requires higher-risk railroads and OTRBs to appoint security coordinators.

6

This NPRM would propose to implement those provisions.

2

See

Section 101 of the Aviation and Transportation Security Act (ATSA), Public Law 107-71, 115 Stat. 597 (Nov. 19, 2001), codified at 49 U.S.C. 114 (ATSA created TSA and established the agency's primary federal role to enhance security for all modes of transportation). Section 403(2) of the Homeland Security Act of 2002 (HSA), Public Law 107-296, 116 Stat. 2135 (Nov. 25, 2002), transferred all functions related to transportation security, including those of the Secretary of Transportation and the Under Secretary of Transportation for Security, to the Secretary of Homeland Security. Pursuant to DHS Delegation Number 7060.2, the Secretary delegated to the Administrator, subject to the Secretary's guidance and control, the authority vested in the Secretary with respect to TSA, including that in sec. 403(2) of the HSA.

3

49 U.S.C. 114(l)(1).

4

Public Law 110-53, 121 Stat. 266 (Aug. 3, 2007).

5

See

secs. 1408, 1517, and 1534 of the 9/11 Act, codified at 6 U.S.C. 1137, 1167, and 1184, respectively. For the remainder of this NPRM, TSA will refer to the codified section numbers.

6

See

secs. 1512 and 1181 of the 9/11 Act, codified at 6 U.S.C. 1162 and 1181, respectively. TSA addresses 6 U.S.C 1162(e)(1)(A) and 1181(e)(1)(A) in this rulemaking. TSA intends to address the other regulatory requirements of these provisions in separate rulemakings.

Summary of the Major Provisions

As discussed in section III.F. of this NPRM, TSA is proposing to apply the requirements to higher-risk operations, based on mode-specific assessments of risk. Based on these assessments, the requirements would apply to:

• Class I freight railroad carriers, railroads transporting Rail Security-Sensitive Materials (RSSMs) through identified High Threat Urban Areas (HTUAs) (applying those terms as defined in current 49 CFR 1580.3), and railroads that host other higher-risk rail operations. This would cover approximately 36 railroads.

• Public transportation and passenger railroads (PTPRs) operating in the eight regions with the highest transit-specific risk. This would cover approximately 46 systems.

• The National Railroad Passenger Corporation (Amtrak), an intercity passenger railroad.

• OTRB owner/operators providing fixed-route service (also referred to as regular route or scheduled service) to/through/from the highest-risk urban areas. This would cover approximately 202 OTRB owner/operators.

This NPRM proposes requiring the entities listed above to:

• Develop security training programs to enhance and sustain the capability of their security-sensitive employees to observe, assess, and respond to security incidents as well as to have the training necessary to implement their specific responsibilities in the event of a security incident.

• Submit the required security training program to TSA for review and approval.

• Implement the security training program and ensure all existing and new security-sensitive employees complete the required security training within the specified timeframes for initial and recurrent training.

• Maintain records demonstrating compliance and make the records available to TSA upon request for inspection and copying.

• Appoint security coordinators and alternates-who will be accessible to TSA 24 hours per day, 7 days per week-and transmit contact information for those individuals to TSA (an extension of current 49 CFR part 1580 requirements).

• Report significant security incidents or concerns to TSA (an extension of current 49 CFR part 1580 requirements).

• Review and update security training programs as necessary to address changing security measures or conditions.

The proposed rule would also amend 49 CFR part 1500 to streamline definitions for TSA's regulation and would add a definition of Transportation Security-Sensitive Materials (TSSMs). Proposed revisions to 49 CFR parts 1503 and 1520 would conform references and provisions related to enforcement and handling of SSI to the expanded scope of security requirements in the proposed rule.

The most significant proposed revisions are found in subchapter D of chapter XII of title 49. This subchapter would be retitled “Maritime and Surface Transportation Security,” reorganized, and expanded to include the proposed security program requirements. The general rules for subchapter D would continue to be in part 1570, but reorganized and expanded to address the new requirements proposed in this rule. This NPRM also proposes to add a new section (1570.7) to make it clear that owner/operators, employees, contractors, and other persons can be held liable for violating TSA's regulations. A similar provision is part of TSA's aviation-related regulations and adding it to subchapter D ensures consistency in enforcement across all modes of transportation. This provision is further discussed in section III.D.2 of this NPRM.

Some provisions currently limited to railroads under part 1580 would be

moved and revised to address the additional modes, such as provisions related to “compliance, inspection, and enforcement.” This necessitates reorganization and minor revisions to current part 1580. The impact of the proposed rule on the organization and scope of current 49 CFR part 1580 is discussed in section II.C. of this NPRM. The following table (Table 1) provides a summary of the requirements and their applicability (distinguishing between current requirements/applicability and proposed requirements/applicability).

Table 1—Summary of Proposed Requirements

[Current 49 CFR part 1580 requirements incorporated into this NPRM are indicated with an “X”; proposed requirements are indicated with a “P”]

Inspection

authority

(§ 1570.9)

Protecting

sensitive

security

information

(part 1520)

Security

coordinator

(§ 1570.201)

Reporting

security

incidents

(§ 1570.203)

Security

training

1

Freight railroad carriers

X

X

X

X

P

Rail hazardous materials shippers

X

X

X

X

Rail hazardous materials receivers in HTUAs

X

X

X

X

Owner/operators of private rail cars

X

X

X

X

Host railroads of freight or PTPR rail operations within scope of rule

X

X

X

X

P

PTPR operating rail transit systems on general railroad system, intercity passenger train service, and commuter train services

X

X

X

X

2

P

PTPR operating rail transit systems not part of general railroad system

X

X

X

X

2

P

Tourist, scenic, historic, and excursion rail owner/operators

X

X

X

X

PTPR operating bus transit or commuter bus systems in designated areas

P

P

P

P

P

OTRB owner/operators providing fixed-route service in designated areas

P

P

P

P

P

1

49 CFR part 1570, Subpart B (Security Programs); 49 CFR part 1580, Subpart B—Employee Security Training (freight railroads); 49 CFR part 1582, Subpart B—Employee Security Training (PTPR); and 49 CFR part 1584, Subpart B—Employee Security Training (OTRBs).

2

If Amtrak, or listed in proposed part 1582, Appendix A (a public transportation system, or part of a public transportation system).

Costs and Benefits

TSA estimates the overall cost of this proposed rule is $157.27 million over 10 years discounted at 7 percent. TSA estimates the cost of this proposed rule by the 4 affected parties (all costs are 10 years at 7 percent): For freight railroads the rule would cost a total of $90.74 million, for PTPR the cost is $53.14 million, for OTRB the cost is $12.08 million, and for TSA the cost is $1.31 million.

The proposed rule, if finalized, would enhance surface transportation security by reducing vulnerability to terrorist attacks in four different ways. First, the surface transportation employees in each of the three covered modes would be trained to identify security vulnerabilities. Second, these surface transportation employees would be better trained to recognize potentially threatening behavior and properly report that information. Third, these surface employees would be trained to respond to incidents, thereby mitigating the consequences of an attack. Finally, the covered surface transportation owner/operators would be required to report significant security concerns to TSA so that TSA can analyze potential threats across all modes.

This analysis reflects information obtained through a Notice published in the

Federal Register

in 2013

7

(2013 Notice). Through that Notice, TSA requested data needed to provide a more accurate understanding of the existing baseline and potential costs associated with the proposed rule. In particular, TSA requested information regarding programs currently implemented—whether as a result of regulatory requirements, grant requirements, in anticipation of a rule, voluntary, or otherwise—and the costs associated with those training programs.

7

78 FR 35945 (June 14, 2013).

II. Background

A. Context and Purpose

Surface transportation systems—including public transportation systems, intercity and commuter passenger railroads, freight railroads, intercity buses, and related infrastructure—are vital to our economy and essential to national security.

8

The potential for a terrorist attack exists at each stage of moving people, goods, and services throughout the Nation.

8

Surface Transportation and Rail Security Act of 2007, report of the Senate Committee on Commerce, Science, and Transportation at 2 (S. Rept. 110-29, Mar. 1, 2007), quoting Executive Order (E.O.) 13416 (Dec. 5, 2006), published at 71 FR 71033 (Dec. 7, 2006).

Recent attacks indicate the risk of terrorist attack to surface transportation. On August 21, 2015, there was an attempted mass shooting on a packed high-speed train bound for Paris from Amsterdam.

9

Metropolitan Police treated a December 5, 2015, knife attack in a London public transportation station as a terrorist incident.

10

There have been other documented terrorist attacks targeting surface transportation, including the attack in Madrid, Spain, on March 11, 2004, in which terrorists attacked four commuter trains using 10 improvised explosive devices (IED) that exploded near-simultaneously and resulted in the deaths of 191 people and injury to more than 1,800 people.

11

In July 2005, four coordinated suicide bombings occurred, three on separate trains through London Underground stations and the fourth on a double-

decker bus, killed 52 people.

12

In July 2008, a group linked to Lashkar-e-Tayyiba attacked Mumbai's Western Railway Line with seven IEDs during evening commute hours, killing 183 people.

13

In November 2008, this group committed another coordinated attack that included shooting and bombing operations at several targets—including a train station—and killed a total of 164 people.

14

More recently, U.S. news media reported that the Federal Bureau of Investigation (FBI) uncovered a plot to attack the PATH commuter rail system serving New York and New Jersey in mid-2006.

15

These previous events highlight the magnitude of the deadly consequences that an attack on surface transportation could have.

9

See

Michael Birnbaum, “A change of seats for 3 Americans led to saved lives on Paris-bound train,” Washington Post (Aug. 24, 2015), available at

https://www.washingtonpost.com/world/as-french-train-suspect-is-interrogated-questions-mount-on-europes-security/2015/08/23/088ff2fe-4923-11e5-9f53-d1e3ddfd0cda_story.html.

10

See

BBC, “Leytonstone Tube station stabbing a `terrorist incident' ” (Dec. 6, 2015), available at

http://www.bbc.com/news/uk-35018789.

11

Encyclopedia Britannica, “Madrid train bombings of 2004” (May 19, 2013), available at

http://www.britannica.com/event/Madrid-train-bombings-of-2004.

12

CNN, “July 7 2005 London Bombings Fast Facts” (updated June 29, 2016, 9:44 a.m.), available at

http://www.cnn.com/2013/11/06/world/europe/july-7-2005-london-bombings-fast-facts/.

13

Bureau of Diplomatic Security, “India 2013 Crime and Safety Report: Mumbai” (March 5, 2013), available at

https://www.osac.gov/pages/ContentReportDetails.aspx?cid=13701.

14

CNN, “Mumbai Terror Attacks Fast Facts” (updated Nov. 4, 2015, 11:57 a.m.), available at

http://www.cnn.com/2013/09/18/world/asia/mumbai-terror-attacks/.

15

Mary Frost, “NYC subways targeted in ISIS terror plot—NYPD, FBI evaluating threat level,” Brooklyn Daily Eagle (Sept. 25, 2014), available at

http://www.brooklyneagle.com/articles/2014/9/25/nyc-subways-targeted-isis-terror-plot-nypd-fbi-evaluating-threat-level.

As part of its ongoing communications with stakeholders, TSA has alerted owner/operators affected by this proposed rule to transportation-related threats and has worked with many of them to review and recognize potential vulnerabilities to their operations. The impact that security training can have on these operations was recognized by Congress when it mandated, and provided detailed requirements for, security training regulations as part of the 9/11 Act.

16

16

Public Law 110-53, 121 Stat. 266 (Aug. 3, 2007).

TSA recognizes that the owner/operators of surface transportations systems, both public and private, are principally responsible for the safety and security of the people using their services. As noted in Presidential Policy Directive/PPD-21, “Critical Infrastructure Security and Resilience:”

The Nation's critical infrastructure is diverse and complex. It includes distributed networks, varied organizational structures and operating models (including multinational ownership), interdependent functions and systems in both the physical space and cyberspace, and governance constructs that involve multi-level authorities, responsibilities, and regulations.

Critical infrastructure owners and operators are uniquely positioned to manage risks to their individual operations and assets, and to determine effective strategies to make them more secure and resilient.

17

17

PPD-21 (Feb. 12, 2013) (emphasis added).

Surface transportation employees—the people who provide and support these services—are a critical resource for protecting passengers and the transportation infrastructure.

As a result of TSA's programmatic efforts, as well as awareness of the requirements of the 9/11 Act, many owner/operators of higher-risk surface transportation operations have voluntarily implemented security training programs that address some of the requirements of this proposed rule. As noted in the economic analysis for this rulemaking, however, the private market may not provide adequate incentives for owner/operators to make a socially optimal investment in the full range of measures that would reduce the probability of a successful terrorist attack based on the economics of externalities. (Externalities are costs or benefits from an economic transaction experienced by parties “external” to the transaction.) Specifically, for surface mode owner/operators, the total consequences of an attack or other security incident to society may be greater than what would be suffered by the individual owner/operator of the infrastructure or facility.

Without ignoring the voluntary efforts of owner/operators to increase the baseline of their security, including by providing security training, TSA also recognizes a firm normally would not choose to make an investment in security over its privately optimal amount in a competitive market place, since such an investment would increase the firm's cost of production, placing it at a disadvantage when competing with companies that have not chosen to make a similar investment in security.

Focusing on the higher-risk operations and frontline employees (defined in the rule as those performing security-sensitive functions), this proposed rule would close gaps in the scope or breadth of training provided as part of voluntary efforts. To the extent resource and economic considerations could cause this voluntary commitment to abate in the future, this proposed rule, when finalized, should solidify these efforts and commitment to security training.

Thus, the purpose of this proposed rule is to solidify a baseline of security training for surface transportation by enhancing and sustaining the capability of frontline employees for higher-risk public transportation systems, railroad carriers (passenger and freight), and OTRB owner/operators to observe, assess, and respond to security risks and potential security breaches. These critical capabilities include identifying, reporting, and appropriately reacting to suspicious activity, suspicious items, dangerous substances, and security incidents that may be associated with terrorist reconnaissance, preparation, or action. An employee who is prepared and trained to observe, assess, and respond may be the critical point for preventing a terrorist act.

Security awareness training is an important and effective tool to enhance an employee's ability to detect and deter attacks by terrorists or others—particularly those with malicious intent to target surface transportation or use vehicles as delivery systems for weapons of mass destruction. Well-trained employees can serve as security force-multipliers. Their familiarity with the facilities and operating environments of their specific transportation systems makes them especially effective at recognizing situations and conditions that may pose a threat to the safety and security of passengers, cargo, and transportation infrastructure.

Employees who are prepared to execute their security-related responsibilities and trained to observe, assess, and respond bring an informed vigilance to their daily responsibilities. They are more capable of identifying and making timely reports to support inquiry by law enforcement and security personnel, increasing the potential for detection or disruption of terrorist planning, preparations, and observations. In the event an incident does occur, employees who understand their roles and responsibilities under the owner/operator's security planning and response documents are better prepared to initiate timely responsive actions to mitigate consequences and work with first responders.

This rulemaking is part of TSA's commitment to risk-based security and how it implicates policy decisions, resource commitments, and expectations. Passengers traveling through a higher-risk area or system (whether by bus or train) should be able to expect the same level of security regardless of the carrier. Communities in HTUAs should expect that the freight trains carrying RSSM

18

are operated by employees with a common baseline of security training, regardless of who owns or operates the train. The result is

a proposed rule that bases applicability primarily on the location where the transportation is operated (rather than constructs of ownership) and scope of employees to be trained on the functions they perform (rather than titles in position descriptions).

18

As previously noted, TSA is not proposing to modify these terms as defined in current 49 CFR 1580.3.

For these reasons, TSA proposes this regulation requiring owner/operators to implement employee security training programs for employees serving in security-sensitive positions in higher-risk operations. TSA explains aspects of the proposed rule more fully in section III of this NPRM.

B. Statutory Authorities

The security of the Nation's transportation systems is vital to the economic health and security of the United States. Ensuring transportation security while promoting the movement of legitimate travelers and commerce is a critical counter-terrorism mission assigned to TSA.

Since its creation following the attacks of September 11, 2001, TSA has had broad statutory authority to assess a security risk for any mode of transportation, develop security measures for dealing with that risk, and enforce compliance with those measures.

19

This includes broad regulatory authority, which enables TSA to issue, rescind, and revise regulations as necessary to carry out its transportation security functions.

20

19

See supra,

n. 2.

20

49 U.S.C. 114(l)(1).

Congress has determined that a regulation is necessary for owner/operators of public transportation systems, passenger railroads, freight railroads, and OTRBs to provide security training to their frontline employees. As part of the 9/11 Act,

21

Congress mandated that DHS use its authority to issue regulations and included in the statute minimum requirements for employees to be trained, subjects of training, and procedures for the submission and approval of training programs.

22

This NPRM proposes to implement these provisions.

21

Public Law 110-53, 121 Stat. 266 (Aug. 3, 2007).

22

See

6 U.S.C. 1137, 1167, and 1184.

The 9/11 Act includes a requirement to include “[l]ive situational training exercises” as part of its security training regulations.

23

As part of the Homeland Security Exercise and Evaluation Program (HSEEP), DHS describes the benefit of exercises “to test and validate plans and capabilities.”

24

While testing the effectiveness of training is important, the HSEEP focuses on the need to test effectiveness of the overall plan—a process that reveals any weaknesses in training. TSA has determined the intent of requiring exercises would be better met if owner/operators were required to test the effectiveness of their security plans—which would include testing employee understanding and capabilities related to their roles, responsibilities, protocols, and procedures. Therefore, TSA has decided to address this element in a separate rulemaking that will meet related 9/11 Act provisions for security planning.

25

23

See

6 U.S.C. 1137(c)(7), 1167(c)(8), and 1184(c)(8).

24

See

DHS, “Homeland Security Exercise and Evaluation Program (HSEEP)” (April 2013), available at

https://www.fema.gov/media-library-data/20130726-1914-25045-8890/hseep_apr13_.pdf.

25

See

requirements in 6 U.S.C. 1134 (public transportation), 1162 (railroads), and 1181 (OTRBs).

Finally, the 9/11 Act also requires DHS to define the term “security-sensitive material” as it relates to materials transported in commerce that pose “a significant risk to national security . . . due to the potential use of the material in an act of terrorism.”

26

The 9/11 Act states that the term must include specific, identified materials.

27

TSA has previously identified “security-sensitive materials” transported by freight railroad carriers as “Rail Security-Sensitive Materials” (RSSM).

28

As further discussed in section III.A.2 of this NPRM, TSA is proposing materials to be identified as “Transportation Security-Sensitive Materials (TSSM).”

26

6 U.S.C. 1151(13).

27

Materials to be included are Class 7 radioactive materials, Division 1.1, 1.2, or 1.3 explosives, materials poisonous or toxic by inhalation, including Division 2.3 gases and Division 6.1 materials, and select agents or toxins regulated by the Centers for Disease Control and Prevention under 42 CFR part 73.

28

See

49 CFR 1580.3 and 1580.100(b).

C. Rule Organization

Implementing requirements in the 9/11 Act for surface transportation regulations necessitates making other changes to TSA's regulations found in title 49 of the CFR. Some of these changes are technical revisions or additions, such as consolidating definitions used in multiple parts of TSA's regulations into part 1500 and adding cross-references to the new regulatory requirements as relevant for investigations (part 1503) and protection of SSI (part 1520).

The most significant changes are to subchapter D, which TSA proposes to rename “Maritime and Surface Transportation Security.” Subchapter D currently contains requirements related to security threat assessments (STAs) (parts 1570 and 1572) and rail security (1580). TSA is proposing to significantly reorganize and augment parts 1570 and 1580, and add parts 1582 (PTPR) and 1584 (Highway and Motor Carriers).

Many portions of the proposed rule are common to PTPR, freight, and OTRB operations. These are included in 49 CFR part 1570. Eliminating duplication of these requirements across multiple sections of TSA's regulations reduces unintended inconsistencies, both now and over time to the extent there are any amendments made to these regulations in the future. Because of these modifications, other organizational changes are being made to part 1570—including moving definitions that have applicability across multiple parts of TSA's regulations to part 1500 (discussed more fully in part III.A of this NPRM) and consolidating provisions related to security threat assessments into a new subpart D. The STA provisions are being moved but are otherwise unmodified. As a result, the substance of these provisions is not part of this notice and comment rulemaking.

TSA includes proposed requirements adapted to reflect the unique aspects of each mode in mode-specific parts of 49 CFR Chapter XII, Subchapter D—Maritime and Surface Transportation Security. Part 1580 would be revised to focus on freight railroads. Sections in current part 1580 applicable to PTPR systems would be moved to a new part 1582. TSA also proposes creating a new part 1584, which would include the requirements for OTRB.

With the exception of the following, provisions of current 49 CFR part 1580, Rail Transportation Security, applicable to freight railroads would be reorganized without substantive change. TSA proposes to move some provisions to part 1570—this revision would include the security coordinator and reporting requirements (which are being updated and clarified, and extended to include higher-risk buses).

29

Other provisions, such as “chain of custody” provisions for RSSMs, would be reorganized within part 1580 because of this proposed rule. Finally, current Appendix A to part 1580 would be modified to remove outdated references. Table 2 provides a distribution table for changes to current 49 CFR part 1580. To the extent sections are being moved, but not revised, they are not part of this notice and comment rulemaking.

29

These modifications are discussed in section III.C. of this NPRM.

Table 2—49 CFR Part 1580 Distribution Table

Former section

New section(s)

1580.1

1570.1, 1580.1, and 1582.1.

1580.3

1570.3, 1580.3, and 1582.3.

1580.5

1570.9.

1580.100

1500.3, 1580.101.

1580.101

1570.201.

1580.103

1580.203.

1580.105

1570.203.

1580.107

1580.205.

1580.109

1580.5 and 1582.5.

1580.111

1580.207.

1580.200

1582.101.

1580.201

1570.201.

1580.203

1570.203.

III. Proposed Rule

A. Amendments to Part 1500

1. General Terms

Consistent with the proposed rule's organization, TSA includes proposed definitions for terms relevant to several subchapters of TSA regulations, beyond the requirements of subchapter D, in part 1500. Terms relevant to several parts of subchapter D would be added to § 1570.3. Terms uniquely relevant to each mode would be included in the relevant parts (part 1580 (freight), part 1582 (PTPR), and part 1584 (OTRB)).

Many of the proposed definitions are identical, or nearly identical, to definitions codified in current 49 CFR part 1580. Some definitions are taken from the 9/11 Act. Other definitions are derived from existing Federal regulatory programs, particularly programs administered by DOT. A few definitions are based on industry sources. TSA's purpose is to use existing definitions that regulated parties are familiar with to the extent that the definitions are consistent with the 9/11 Act and the purposes of this NPRM. Where no existing definition is appropriate, TSA's subject matter experts developed the definition based upon the generally accepted and known use of terms within each of the modes subject to this proposed regulation. Table 3 provides additional information on the terms that would be added to part 1500.

Table 3—Explanation of Proposed Terms and Definitions

Summary of change

Explanation

Propose modifying definition of “Administrator”

This term is used in proposed sections regarding procedures for requesting alternative measures or challenges to required modifications. The definition is being updated to reflect TSA's transition to a DHS component.

Propose adding a definition for “Authorized representative”

This term is used in the definition of “Employee.” It is intended to ensure that any “authorized representatives” performing security-sensitive functions for an owner/operator receives the required security training, even if they are not considered a direct employee. More information can be found in the discussion of employees required to be trained in preamble section III.E.

Propose adding a definition for “Bus”

This term is used in several other terms defined in this proposed rule. TSA's review of DOT regulations identified several definitions for this term. The definition developed by TSA for the purposes of subchapter D is a composite of DOT's definitions adopted for TSA's purposes. While it is a broad definition on its own, the other terms in which it is used limit its application.

Propose adding a definition of “Bus transit system”

This term is used as part of the scope of what is intended by, and included within, the definition of public transportation. Consistent with the scope of other commuter transit systems, the definition is based upon an explanation of what constitutes “urban rapid transit service” in 49 CFR part 209, Appendix A.

Propose adding a definition for “Commuter bus system”

This term is used as part of the scope of what is intended by, and included within, the definition of public transportation. Consistent with the scope of other commuter transit systems, the definition is based upon the Federal Railroad Administration's (FRA's) explanation of “commuter service” for rail in 49 CFR part 209, and the Federal Motor Carrier Safety Administration's (FMCSA's) definition of “commuter service” in 49 CFR 374.303(g).

As part of reorganization of current 49 CFR part 1580, propose moving definition of “Commuter passenger train service” from 49 CFR 1580.3

This term is used as part of the scope of what is intended by, and included within, the definition of public transportation.

Propose moving definition of “DHS” from 49 CFR 1520.3

This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Propose moving definition of “DOT” from 49 CFR 1520.3

This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Proposed adding definition for “Fixed-route service”

Used within the scope of OTRB owner/operators subject to the proposed regulation (

see

proposed 49 CFR 1570.101 and 1584.1), this term is based on the definition of a fixed-route system found in 49 CFR 37.3.

Propose moving definition of “General railroad system of transportation” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Hazardous Material” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Heavy rail transit” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose adding a definition of “Host railroad”

This term, which is consistent with the definition in 49 CFR 236.1003, is used within the scope of this proposed rule relating to operations by railroad carriers. More information can be found in the preamble discussion in section III.F.1.

Propose moving definition of “Improvised explosive device (IED)” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Intercity passenger train service” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Light rail transit” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose adding a definition of “Motor vehicle”

Used throughout this proposed rule, TSA has determined that there is no consistent definition of “motor vehicle” within federal regulations. TSA has reviewed various DOT regulations and relies primarily on 49 CFR 390.5 for this definition as most applicable to this proposed regulation, choosing a definition that is inclusive with limitations provided in the relevant applicability sections.

Propose adding a definition for “Over-the-Road Bus (OTRB)”

This term, the definition of which is consistent with 6 U.S.C. 1151(4), is used within other definitions and the scope of this proposed rule relating to over-the-road bus owners. More information can be found in the preamble discussion in section III.F.3.

Propose moving definition of “owner/operator” from 49 CFR 1570.3 and modifying to eliminate cross-reference to title 33 of the CFR

Used in other definitions and throughout the proposed rule, the definition of this term is a modification of the current definition of “owner/operator” that affects 49 CFR, subchapter D. The modifications remove outdated references to make it the term appropriate for the broader scope of transportation regulated by TSA.

Propose moving definition of “Passenger car” from 49 CFR 1580.3 and adding “rail” to the term to read, “passenger rail car”

Part of reorganization of current 49 CFR part 1580. TSA is proposing to insert the word “rail” between “passenger” and “car” to avoid any confusion between rail and motor vehicle conveyances.

Propose adding a definition of “Passenger railroad carrier”

Used both in the scope of proposed subpart B of 49 CFR part 1570 (Security Coordinator and Reporting Requirements) and the scope of the training rule (proposed 49 CFR part 1582), this term is also used in the context of host railroad operations. More information can be found in the discussion in III.F.2. The definition is based on the definition for this term found in 49 CFR 239.7.

Propose moving definition of “Passenger train” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Private rail car” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose adding a definition of “Public transportation”

Used within other terms, this definition is based primarily on 49 U.S.C. 5302(14). Where the statute uses a definition that is characterized by what is excluded, TSA's definition focuses on what is included.

Propose adding a definition of “Public transportation agency”

This term is used to define the scope of owner/operators subject to the proposed rule.

See

proposed subpart B to 49 CFR parts 1570 and 1582.

See also

the preamble discussion in section III.F.2 for more information. (The 9/11 Act defines a “public transportation agency” as a publicly owned operator of public transportation eligible to receive Federal assistance under Chapter 53 of Title 49, United States Code.”). TSA reviewed the requirements of that statute in developing this definition. As noted above, the definition of “public transportation” is based on 49 U.S.C. 5302(14).

Propose moving definition of “Rail hazardous materials receiver” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Rail hazardous materials shipper” from 49 CFR 1580.3, with a non-significant amendment

Part of reorganization of current 49 CFR part 1580. As proposed, the definition of “offers or offeror” in 49 CFR 1580.3 would be deleted and a reference to the DOT definition for “person who offers or offeror” would be incorporated into the definition of “rail security-sensitive material.”

Propose moving definition of “Rail secure area” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Rail transit facility” from 49 CFR 1520.3 and 1580.3

This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Propose moving definition of “Rail transit system or `Rail Fixed Guideway System' ” from 49 CFR 1580.3 to proposed 1570.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Railroad carrier” from 49 CFR 1580.3

Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Railroad” from 49 CFR 1580.3 and modifying it to define “Railroad transportation”

Part of reorganization of current 49 CFR part 1580. This proposed rule does not significantly change the definition.

Propose moving definition of “Record” from 49 CFR 1520.3

This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Propose adding definition of “Sensitive Security Information consistent with 49 CFR 1520.3 to 1570.3

This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR parts 1520 and 1570.

Propose moving definition of “State” from 49 CFR 1570.3

This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR parts 1520 and 1570.

Propose adding definition of “Transportation security equipment and systems”

The term is used in the context of the proposed requirement for security-sensitive employees to be trained on use of security equipment and systems.

See

for example, proposed 49 CFR 1580.155(c)(1). TSA's subject matter experts have developed this definition based on their work with the modes in conducting assessments and developing voluntary security action items.

Propose moving definition of “Tourist, scenic, historic, or excursion operation” from 49 CFR 1580.3

Part of the reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Transit” from 49 CFR 1580.3 with modifications to reflect broader scope of this proposed rule

Part of the reorganization of current 49 CFR part 1580. TSA proposes modifying this term to reflect the multimodal scope of the proposed training rule and have the term apply across all the modes.

Propose moving definition of “Transportation or transport” from 49 CFR 1580.3 with modifications to reflect broader scope of this proposed rule

Part of the reorganization of current 49 CFR part 1580. TSA proposes modifying this term to reflect the multimodal scope of the proposed training rule and have the term apply across all the modes.

Propose moving definition of “Transportation facility” from 49 CFR 1580.3 with modifications to reflect broader scope of this proposed rule

Part of the reorganization of current 49 CFR part 1580. TSA proposes modifying this term to reflect the multimodal scope of the proposed training rule and have the term apply across all the modes.

Propose adding definition of “Transportation Security-Sensitive Materials (TSSM)”

The definition is included to satisfy 9/11 Act requirements.

See

6 U.S.C. 1151(13). The term is defined in proposed 49 CFR 1570.3. More information can be found in the preamble discussion of the TSSM list in section III.A.2.

Propose moving definition of “TSA” from 49 CFR 1520.3

This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Propose moving definition of “vulnerability assessment” from 49 CFR 1520.3

This term is being modified to streamline terminology rather than enumerating subcategories within each mode. It is being moved to 49 CFR part 1500 as it has relevance beyond the provisions in part 1520.

2. Transportation Security-Sensitive Materials

The 9/11 Act included a requirement for DHS to define “security-sensitive material.” “Security-sensitive material” is defined as “a material, or group or class of material, in a particular amount and form that the Secretary [of Homeland Security], in consultation with the Secretary of Transportation, determines, through rulemaking with opportunity for public comment, poses a significant risk to national security while being transported in commerce due to the potential use of the material in an act of terrorism.”

30

TSA has met the requirements of the 9/11 Act related to rail through its definition of RSSMs under current 49 CFR part 1580.

31

30

6 U.S.C. 1151(13).

31

See

49 CFR 1580.3 and 1580.100(b).

See also

discussion in 73 FR 72130 at 72134 (Nov. 26, 2008).

In March of 2010, DOT's Pipeline and Hazardous Materials Safety Administration (PHMSA) issued a final rule: “Hazardous Materials: Risk-Based Adjustment of Transportation Security Plan Requirements.”

32

This PHMSA final rule amended PHMSA's security requirements for hazardous material (hazmat) transportation under 49 CFR part 172 of the Hazardous Material Regulations (HMR),

33

applicable to freight railroad carriers, motor carriers, and shippers and receivers of hazmat. In addition to amendments to security planning requirements, the PHMSA final rule provided a revised list of hazardous materials for which a security plan is required. DOT worked closely with TSA to align the proposed lists of materials subject to their security programs with ongoing efforts by TSA. The materials considered included certain explosives, compressed gases and flammable liquids, poisonous gases and materials, corrosive materials, radioactive materials, and chemicals listed by the Chemical Weapons Convention. There were also requests to PHMSA to harmonize the list of materials for which security plans are required with the list of materials designated as high consequence dangerous goods for which enhanced security measures are recommended in the United Nations Model Regulations on the Transport of Dangerous Goods (UN Recommendations). Discussions regarding the materials identified in the PHMSA regulations can be found in the preambles to their relevant rulemakings.

34

32

75 FR 10974 (Mar. 9, 2010). Additional information is included in the preamble to the related NPRM.

See

73 FR 52558 (Sept. 9, 2008).

33

These regulations are also referred to as HM-232.

34

See supra,

n. 32.

TSA proposes to adopt the PHMSA list for purposes of defining TSSM. This approach avoids unnecessary duplication and ensures consistent alignment of the materials meeting this standard in Federal regulations. A discussion regarding the materials in the list can be found in the preamble to PHMSA's final rule.

35

35

75 FR at 10977.

B. Amendments to Part 1503

TSA is proposing minor amendments to part 1503 (Investigative and Enforcement Procedures) as necessary to conform these regulations to changes made by the proposed rule. In § 1503.101(b), the scope of statutory provisions is amended to add authorities in title 6 U.S.C. that are administered by the TSA Administrator—which are relevant to this proposed rule. These are conforming amendments with no cost impact.

C. Amendments to Part 1520

TSA is also proposing to modify part 1520 (Protection of Sensitive Security Information). TSA is required to promulgate regulations governing the protection of information obtained or developed in carrying out security under the authority of ATSA

36

if public disclosure of that information could be detrimental to transportation security. TSA's current SSI regulation, 49 CFR part 1520, establishes certain requirements for the recognition, identification, handling, and dissemination of SSI, including restrictions on disclosure and civil

penalties for violations of those restrictions. DOT has nearly identical SSI authority (49 U.S.C. 40119) and a nearly identical SSI regulation (49 CFR part 15).

37

36

See

49 U.S.C. 114(r).

37

For more information on these regulations,

see

69 FR 28078 (May 18, 2004).

Because TSA is expanding the scope of its regulatory requirements in order to fulfill the mandates of the 9/11 Act, it is necessary to conform the SSI provisions to include these transportation security-related requirements. The proposed amendments are limited to: (1) Eliminating unnecessary terms from part 1520 that are added to part 1500 and (2) replacing the limiting term “rail transportation security requirement” with “surface transportation security requirement.” In some places, such as the definition of “vulnerability assessment” in § 1520.3, TSA is proposing to streamline a lengthy description of types of transportation to simply state “aviation, maritime, or surface transportation.”

The impact of these minor revisions should also be minimal. Under § 1520.7(j), any person who has access to SSI is required to protect it according to the requirements of the regulation. While some of the proposed population that would be affected by this rule has not previously been subject to TSA regulations, most of them have previously received SSI information from TSA, as well as training on the proper handling of SSI, and have procedures in place to ensure the requirements of the regulation are met.

38

38

Publicly available information on proper handling of SSI is available on TSA's Web site at

www.tsa.gov.

TSA's regulations for SSI have a counterpart in DOT regulations under 49 CFR part 15. Any comments received on these proposed amendments will be shared with DOT. As these are parallel rules, assuming there are changes to part 1520 adopted as part of this notice and comment rulemaking, DOT may subsequently make similar changes to part 15. We invite comments on the proposed changes to part 1520, and we will share with DOT any comments received on potential changes to part 15. We also invite comments on this process for making changes to both parts.

D. Amendments to Part 1570

1. Overview of Changes and Structure

TSA is proposing to divide part 1570 into four subparts: (1) Subpart A would cover general requirements applicable to all aspects of subchapter D to chapter XII of title 49; (2) subpart B provides the general framework for security programs; (3) subpart C covers operational requirements; and (4) subpart D would move and consolidate general provisions related to security threat assessments (STAs) which are more specifically addressed in part 1572. As previously discussed, mode—specific requirements are contained in subsequent parts. Because of the significant restructuring of part 1570, the proposed rule text includes the entirety of the revision—not just the parts that would be added because of this rulemaking. This includes terms applicable to the STAs required by part 1572, as well as related STA provisions that TSA proposes moving to new subpart D.

2. Subpart A—General

Terms and Definitions (§ 1570.3)

As previously indicated, TSA is proposing to move several terms from § 1570.3 to § 1500.3 as part of a general effort to streamline TSA's regulations by consolidating terms used in multiple parts. In addition, TSA is proposing to add the terms identified in Table 4 to § 1570.3 as they are used in multiple sections of subchapter D to chapter XII of title 49.

Table 4—Explanation of Proposed Terms and Definitions

Summary of change

Explanation

Propose adding definition of “Contractor”

This term is used in the definition of “employee” for purposes of this subchapter and is based on a definition of contractor used in DOT regulations,

see, e.g.,

49 CFR 655.4.

Propose adding definition for “Employee”

This term is used in several definitions, most notably, the definition of “security-sensitive employee,” which is the term used to define the scope of individuals who must be trained under the proposed rule (

see

discussion in III.E) and the requirements of the training program.

See

proposed definition of “security-sensitive employee” in 49 CFR 1580.3, 1582.3, and 1584.3. It is also used in sections regarding responsibility for compliance (proposed 49 CFR 1570.13), and terms used for “chain of custody” requirements in proposed 49 CFR 1580.3 (currently 49 CFR 1580.107).

Propose adding definition of “Immediate supervisor”

This term is used in the definition of “Employee.” It is intended to ensure that any “immediate supervisors” performing security-sensitive functions for an owner/operator receive the required security training. It is also intended to limit the layers of management that must receive security training to those who have an actual nexus to transportation security. More information can be found in the discussion of employees required to be trained in preamble section III.E.

Propose adding definition of “Security-sensitive employee”

This term is used in provisions of part 1570 as part of the proposed security training requirements. The definition provides a signal to find the appropriate mode-specific definitions in 49 CFR parts 1580, 1582, and 1584.

Propose adding definition of “Security-sensitive job function”

This term is used in provisions of part 1570 as part of the proposed security training requirements. The definition provides a signal to find the appropriate mode-specific definitions in 49 CFR parts 1580, 1582 and 1584.

Security Responsibilities for Employees and Other Persons (§ 1570.7)

In proposed § 1570.7, TSA is seeking to make its regulations regarding the responsibility for compliance consistent for all modes. Under 49 U.S.C. 114(f), TSA is required to enforce security related regulations and requirements and oversee the implementation of security measures for all modes of transportation.

39

As with the similar aviation regulation, the obligation for compliance is not limited to owner/operators specifically referenced under applicability provisions. Any person may be held to have violated these proposed rules, including contractors who provide service to owner/operators and the employees of such contractors. For example, a contractor who is authorized by an owner/operator to provide security training to individuals performing security-sensitive functions on the owner/operator's behalf would be expected to fulfill all of the responsibilities under these three parts with respect to such training. Similarly, contractors would also be subject to inspection for compliance with this proposed rule and enforcement actions when appropriate (

see

following discussion on proposed § 1570.9 for more information on TSA's investigatory and enforcement authority).

39

See

49 U.S.C. 114(f)(7) and (11). A similar provision applicable to aviation employees and other related persons is in 49 CFR 1540.105(a)(1) and (b).

Compliance, Inspection, and Enforcement (§ 1570.9)

TSA is mandated to: (1) Enforce its regulations and requirements; (2) oversee the implementation and ensure the adequacy of security measures; and (3) inspect, maintain, and test security facilities, equipment, and systems for all modes of transportation.

40

This mandate applies even in the absence of regulations stating the authority, but TSA has chosen to include a restatement of its authority in its regulations. The statute specifically requires TSA to—

40

See

49 U.S.C. 114(f).

• Assess threats to transportation;

• Enforce security-related regulations and requirements;

• Inspect, maintain, and test security of facilities, equipment, and systems;

• Ensure the adequacy of security measures for the transportation of cargo;

• Oversee the implementation, and ensure the adequacy, of security measures at airports and other transportation facilities;

• Require background checks for airport security screening personnel, individuals with access to secure areas of airports, and other transportation security personnel; and

• Carry out such other duties, and exercise such other powers, relating to transportation security as the Administrator considers appropriate, to the extent authorized by law.

While current part 1570 includes a provision stating TSA's compliance, inspection, and enforcement authority, it is not as detailed as what TSA has promulgated in more recent regulations.

41

Therefore, TSA is proposing to transfer the text of current § 1580.5 to subpart A as proposed § 1570.9, with minor modifications to reflect the addition of certain bus operations that have previously been unregulated by TSA.

42

41

Compare current § 1570.11 with current § 1580.5. The provision in part 1580 is also consistent with 49 CFR 1542.5, 1544.3. 1546.3, 1548.3, and 1549.3.

42

A more detailed discussion of current § 1580.5, still relevant to the proposed section, can be found in the preamble for current part 1580.

See

71 FR 76852 (Dec. 12, 2006) (NPRM) and 73 FR 72130 (Nov. 26, 2008) (Final Rule).

3. Subpart B—Security Programs

As previously noted, TSA intends to consolidate and avoid duplication of requirements in its regulations by placing all of the security program requirements that are consistent across all modes in subpart B. These include: (1) Submission, review, and approval of the program; (2) procedures for amending the program; (3) the training schedule (including initial and recurrent training, previous training, relation to other training, and failure to train); and (4) recordkeeping. Proposed requirements for which employees must be trained and content of the program are found in the proposed revisions to part 1580 (freight rail) and new parts 1582 (PTPR) and 1584 (OTRB).

Program Content (§ 1570.103)

Under the statutory requirements, TSA must issue regulations mandating security training for owner/operators of public transportation agencies, railroads, and OTRBs.

43

In proposing these regulations, TSA assumes that Congress intended the requirement to provide for the use of “existing procedures, protocols, and standards to satisfy the regulatory requirements” for vulnerability assessments and security plans apply equally to security training.

44

Proposed § 1570.3 implements these requirements by stating that each owner/operator required to have a security program under proposed parts 1580, 1582, and 1584 must address all of the identified requirements. In addition, the proposed section implements the requirement to allow for use of existing programs by allowing the owner/operators to include these existing programs as an appendix. The owner/operators would be required to cross-reference the relevant portions of the appendix or TSA could assume it is all part of the security program and enforce it as such.

43

See

6 U.S.C. 1137, 1167, and 1184.

44

See

6 U.S.C. 1162(j) and 1181(i) (use of existing procedures, protocols, and standards to satisfy regulatory requirements).

To minimize costs of compliance, TSA may identify pre-existing or widely-available training programs that meet some or all of this proposed rule's requirements. If owner/operators decide to use a program already determined by TSA to meet the proposed rules requirements, the owner/operator must notify TSA of the program name, presenter, modifications made to the training material since the program was approved by TSA, and the last date of modification. If TSA has already determined the program meets some or all of the requirements for the proposed rule and is applicable to the owner/operator's operations, it would be unnecessary for the owner/operator to submit a copy of the program to TSA for approval or include it in the appendix.

Responsibility for Determinations (§ 1570.105)

As part of this rulemaking, TSA is proposing to apply the requirements to the highest-risk operations within the three modes identified by the 9/11 Act. As part of the surface security requirements in the 9/11 Act, TSA is required to develop risk tiers.

45

The criteria used for determining the highest-risk tier for each mode is discussed in more detail in section III.F of this NPRM. The text of proposed § 1570.105(a) informs owner/operators that TSA has determined the applicability criteria, but it is the owner/operator's responsibility to determine whether their operations meet the criteria.

45

For public transportation, 6 U.S.C. 1137(e) states that any public transportation agency that receives a grant under 6 U.S.C. 1135 shall be required to develop and implement a training program pursuant to this section. The grant program implemented under sec. 1135 relies on high-risk determinations.

See also

6 U.S.C. 1162(a) and (h) and 1181(a) and (h) (Secretary shall identify risk tiers for freight railroads and OTRB and apply regulatory requirements to those at the highest-risk).

The proposed rule would require owner/operators to notify TSA within 30 days of the effective date of the final rule if they meet the criteria for applicability. In addition to publishing the regulatory requirements in the

Federal Register

, TSA will work with

the relevant associations for each of the modes to ensure their memberships are apprised of the requirements. TSA will identify the form and manner of notification in the final rule consistent with cost-effective methodologies at that time. Because the proposed rule would require owner/operators to determine whether the criteria apply, TSA could bring an enforcement action against an owner/operator that meets the criteria, but has failed to comply with the requirements.

The obligation to self-determine applicability also applies to new and existing operations (those commencing after publication of the final rule). They would be required to notify TSA no later than 90 calendar days before commencing operations or implementing modifications that would put them within the applicability of the requirements.

Recognition of Previous Training (§ 1570.107)

As previously noted, TSA is required to allow use of existing programs to satisfy the security program requirements implemented as a result of 9/11 Act's provisions.

46

Under proposed § 1570.107, an owner/operator could rely on previous training that occurred within the identified periods for initial or recurrent training. In order to use previous training, the owner/operator would need to validate the training provided satisfies the requirements of this proposed rule—including records of training, curriculum, and appropriateness for the employee and owner/operator's operations.

46

See

6 U.S.C. 1162(j) and 1181(i) (use of existing procedures, protocols, and standards to satisfy regulatory requirements).

Security Training Program Submission, Review, and Approval (§ 1570.109)

The 9/11 Act's requirements include specific deadlines for submission of programs and TSA's review.

47

Proposed § 1570.109 identifies the required deadlines for submitting security training programs and TSA approval.

47

See

6 U.S.C. 1137(d)(1) and (2), 1167(d)(1) and (2), and 1184(d)(1) and (2) (must submit program 90 days from effective date, TSA must approve within 60 days of receipt or notify of need for revisions).

In general, not later than 90 days from the effective date of the final rule, owner/operators would be required to submit programs to TSA in a form and manner prescribed by TSA. Owner/operators commencing new businesses or operations that would make them subject to this proposed rule would be required to submit their security training programs to TSA no less than 60 days before commencing operations. In the final rule, TSA will provide details for submission (encouraging use of a secure Web site or other electronic submissions). TSA assumes submission would likely be by email or mail service, but requests comments on preferences. Consistent with requirements of the 9/11 Act, TSA would review the programs within 60 days of receipt and either approve them or specify changes that would be needed for approval.

48

If TSA requires changes, the owner/operator would be required to submit a modified training program that meets TSA's specifications within 30 days of notification by TSA of the needed changes. The section includes the availability to request reconsideration of any TSA-required modifications. TSA provides an analysis of burden and estimated costs associated with this information collection in section V.A. of this preamble and the draft OMB 83-I Supporting Statement for its information collection request, which is available in the docket for this rulemaking.

48

See

6 U.S.C. 1137(d)(1) and (2), 1167(d)(1) and (2), and 1184(d)(1) and (2) (TSA must approve within 60 days of receipt or notify of need for revisions).

Initial training (§ 1570.111(a))

Consistent with the 9/11 Act's requirements, TSA proposes that existing employees must be trained within one year of TSA's approval of the program.

49

As further required by the 9/11 Act, initial training for new employees or those transitioning to a covered job function (as identified in proposed Appendix B to parts 1580 (freight rail), 1582 (PTPR), and 1584 (OTRB), must occur within the first 60 days of the date an employee begins to perform a security-sensitive function.

50

49

See

6 U.S.C. 1137(d)(3), 1167(d)(3), and 1184(d)(3) (no later than 1 year after approval of security training program, owner/operator must have trained all covered employees).

50

This is a mandatory requirement for railroads and OTRB companies.

See

6 U.S.C. 1167(d)(3) and 1184(d)(3) (New employees must be trained within first 60 days of employment).

During the consultation process at the initial stages of this rulemaking, some stakeholders objected to a one-year deadline for completion of initial training. While the 9/11 Act does not provide for flexibility on the initial training schedule, TSA has attempted to address these concerns through provisions on recurrent and previous training (as discussed in section III.D.3 of this NPRM). In addition, TSA is proposing to include a section allowing regulated parties to request an extension if they cannot meet the required training schedule.

51

51

See

§ 1570.115(c) of this proposed rule.

Proposed § 1570.111(a)(3) is included to address the situation of non-permanent employees. TSA recognizes that some individuals may be intermittently employed as contractors or representatives to perform security-sensitive functions; they might not perform these functions for 60 or more consecutive calendar days. For example, an employee may function as a maintenance worker for a 30-day period and then, at a later date, perform that function for another period of 30 days or longer. This may also include individuals who are employed by multiple owner/operators, such as multiple-employer drivers.

52

The proposed rule would require that such individuals receive training within 60 calendar days after employment that meets the definition of a security-sensitive employee.

53

52

Such as individuals meeting the definition of “multiple-employer driver” in the Federal Motor Carrier Safety Administration (FMCSA) regulations at 49 CFR 390.5.

53

See

discussion of “security-sensitive employees” in section III.E. of this NPRM.

In general, this means that an employee would need to be trained within 60 days of beginning permanent employment in a position that may perform a security-sensitive function, whether full or part-time. If, however, an individual is employed on an intermittent or non-permanent basis, such as a contractor who is employed in a position that may perform a security-sensitive function for short durations, then the training would need to take place before the individual's total time of employment by the owner/operator equals sixty calendar days within a consecutive twelve-month period. TSA recognizes that some owner/operators may address this requirement by requiring training for all regular contractors or other individuals employed for short, but regular durations. TSA requests comments on other options for determining accumulated days of employment and for ensuring owner/operators do not engage in employment practices or use of contractors to avoid the requirements of this proposed rule.

As previously noted, the proposed rule includes a provision regarding use of previous training (

see

discussion on proposed § 1570.107). TSA is aware of stakeholder concerns regarding the schedule for initial training, but TSA is also aware that many of the affected owner/operators have already implemented initial employee security training—frequently through the use of

grant funds provided by DHS for that purpose.

54

TSA invites comments on these requirements as they appear in the proposed rule.

54

Congressional appropriations to FTA fund course offerings to public transportation agencies that meet some of the requirements in this proposed rule. Similarly, appropriations through DHS fund the provision of courses in prevention and response that are available to PTPR agencies. Further, FTA and FEMA courses that may meet portions of this proposed rule are listed among the approved vendors and programs for use of TSGP awards.

In meeting the initial training schedule, TSA expects that many owner/operators will rely on the provisions in proposed § 1570.107, which provides standards for accepting previous training. Under this section of the proposed rule, TSA would allow “training credit” to be given for employees who received training that satisfies the requirements of the proposed rule within one year before its effective date.

This may include emergency preparedness plans that railroads connected with the operation of passenger trains must implement to address such subjects as communication, employee training and qualification, joint operations, tunnel safety, liaison with emergency responders, on-board emergency equipment, and passenger safety information, as well as policies that transit agencies implement to ensure safety promotion to support the execution of the Transit Agency Safety Plan by all employees, agents, and contractors for the rail fixed guideway public transportation system.

55

See

discussion of these training programs in section III.I. of this NPRM. Similarly, public transportation agencies may have been providing training through funds granted under the TSGP.

55

Id.

The recordkeeping provisions of the proposed rule require an owner/operator to provide current and former employees with documentation upon request of any training completed to meet the requirements of this rule.

56

Options for compliance with this requirement could include providing employees with certificates to validate completed training.

56

See

§ 1570.121 of the proposed rule.

This proposed requirement anticipates situations where an employee may have received training from a previous owner/operator, as well as industry practices where employees may work for multiple owner/operators (such as commercial drivers operating OTRBs). If an owner/operator can validate that an employee has received the required training within the specified timeframe, the training would not need to be repeated. Because it would be the obligation of the current owner/operator to ensure that all training requirements are met, that owner/operator would be responsible for ensuring that any previous training courses satisfy the proposed rule's requirements and documenting that the training was received within the required timeframe.

Finally, there may be situations where “dual-hatted” or other specific-function employees are required to receive security training from other sources as part of their jobs, such as railroad police officers employed by the owner/operator. As indicated above, it is the obligation of the owner/operator to ensure and document the training, including training received under these circumstances.

Recurrent Training (§ 1570.111(b))

Recurrent training is essential for maintaining a high level of security awareness. The 9/11 Act recognizes this by requiring routine and ongoing training for public transportation employees.

57

Congress has left it to the discretion of TSA to determine the appropriate schedule for recurrent training and to require a similar schedule for railroad and OTRB employees.

58

57

See

6 U.S.C. 1137(f).

58

See

6 U.S.C. 1137(c)(11), 1167(c)(12), and 1184(c)(12).

TSA believes annual recurrent training is essential for transportation employees to maintain a high level of awareness, competency, and currency with overall changes in security posture within the surface transportation environment. TSA's decision is consistent with several key considerations, including: (1) Other TSA regulations requiring training, as well as similar training required for TSA employees; (2) the difficulty of learning, developing, and demonstrating security awareness in the dynamic aspects of the surface transportation environment, and (3) industry recommended guidelines for security awareness training.

TSA requires annual training for aviation workers. For example, regulations applicable to Ground Security Coordinators used by aircraft operators specifically require annual training.

59

Other aviation workers are required to receive annual recurrent training as part of the approved security program (including aircraft operators, indirect air carriers, air cargo, etc.).

60

59

See

49 CFR 1544.233.

60

The relevant security program requirements are under 49 CFR 1544.233, 1544.235, 1544.407, 1548.5, and 1549.103.

TSA's decision to require annual training is supported by the Difficulty-Importance-Frequency (DIF) model

61

that TSA uses for determining training requirements for its own employees.

62

The DIF model uses three design criteria: Difficulty, importance, and frequency.

61

Bill Melton & J. Bahlis, “ADVISOR Enterprise Difficulty-Importance-Frequency (DIF) Model Fact Sheet”, BNH Expert Software Inc. (February 23, 2011), available at

http://www.bnhexpertsoft.com/english/products/advent/ADVISOR_DIF_Model.pdf.

DIF is a standard instructional design tool used by a variety of users including the Department of Defense (DOD), the Department of Energy (DOE), and private sector education and healthcare providers, to determine training priority and frequency of training.

62

The proposed schedule is consistent with TSA's security awareness training for its own employees—including annual training on operational security (OPSEC), responding to active shooter incidents, and social engineering that could undermine security of information systems.

TSA's subject matter experts responsible for TSA-related training determined that measuring the proposed security training program against these standards supports annual training as: (1) The difficulty of learning surface transportation security awareness related information is at the medium/moderately difficult range because it requires decision making when applying what one has learned; (2) the importance of conducting this security training is at the high/very important range because the cost of failure is high and would cause damage and losses in the event of an attack; and (3) the frequency of how often the task would be performed is within medium range.

TSA's decision is also supported by the American Public Transportation Association (APTA) and their recommendations for security training: Security Awareness Training for Transit Employees.

63

Developed in collaboration and consultation with TSA and transportation industry stakeholders, the recommended practice provides minimum guidelines for security awareness training for all transit employees to strengthen transit system security. APTA “recommends that all transit employees be refreshed on transit security awareness objectives annually, in an abbreviated method at least . . . to reflect advancements or modifications to criminal and terrorist activities and reinforce the security awareness training that employees received initially.”

63

APTA Security Risk Management Working Group., “Security Awareness Training for Transit Employees” (March 2012), APTA-SS-SRM-RP-005-12.

TSA does not find it necessary to include the “abbreviated method” option used by APTA as part of the proposed rule for two reasons. First, the

First Observer

TM

program, discussed more fully in section III.J. of this NPRM, will meet most of the training requirements in approximately one hour. Having reviewed a wide variety of programs that could be used to meet elements of the 9/11 Act's requirements, TSA is not aware of any other existing material that could meet all of the proposed requirements in such an abbreviated period.

64

To the extent owner/operators intend to continue to use their existing training program to meet the regulatory requirements, they may want to consider using First Observer

TM

as an abbreviated form of recurrent training.

64

As part of the 2013 Notice, TSA included a matrix in the docket of training programs that meet elements of the 9/11 Act's requirements. The matrix is available in the docket for the 2013 Notice at:

https://www.regulations.gov/

(search for ”TSA-2013-0005-0084”). Of the 20 programs listed, none of them addressed all of the 9/11 Act requirements.

Second, owner/operators could request to use some other type of abbreviated security training as an alternative measure for compliance. Owner/operators may request to use alternative measures as part of the interactive and iterative process TSA intends to use for approval and review of required security programs, as detailed in proposed 49 CFR 1570.117. Under this proposed section, the owner/operator must establish that the alternative is in the best interest of the public and transportation security. When applied to recurrent training, TSA may require validation that the expected baseline of security awareness is reached and maintained with the abbreviated program. For example, the owner/operator may propose abbreviated training for employees who can pass a pre-test.

TSA is aware that an annual recurrent training requirement could present challenges for owner/operators who must also meet other regulatory training requirements. For example, FRA requires a two-year recurrent training schedule for the emergency preparedness training required under 49 CFR part 239 (emergency response and evacuation for rail passengers). The security training required by PHMSA under 49 CFR part 172 (securing transportation of hazardous materials) is on a three-year recurrent training cycle. As TSA does not control these training schedules, we cannot harmonize all of them through this rulemaking. To the extent, however, that owner/operators must comply with these other training requirements, they may be able to use them as part of their program to meet the meet recurrent training requirements. TSA is interested in comments regarding options for harmonizing training schedules and for adding efficiencies with other relevant regulatory requirements.

While TSA is proposing annual recurrent training, a three-year recurrent cycle is included as a programmatic alternative. The results of the cost analysis for this alternative can be found in chapter III section K of the Regulatory Impact Analysis (RIA) for this rulemaking, which is included in the public docket.

Amendments to the Security Program (§§ 1570.113 and 1570.115)

Allowing owner/operators to revise or amend their programs, as proposed in § 1570.113, is a subset of addressing the 9/11 Act's requirements for implementation and submission or programs.

65

It is also consistent with TSA's statutory authority to allow exemptions from regulatory requirements.

66

Proposed § 1570.113 includes procedures allowing an owner/operator to submit a request to TSA to amend its program and the standard for TSA's approval of that request. The proposed section identifies appropriate reasons for amending programs, such as changes to an operating environment that could include new equipment or changes in station construction. If the operating environment changes, it is reasonable to expect that some aspects of the security training program would also need to be revised. TSA may approve an amendment if it is in the interest of public and transportation security and meets the required security standards. TSA could ask for additional information or time in order to makes its determination.

65

See

6 U.S.C. 1137(d) (public transportation), 1167(d) (railroads), and 1184(d) (OTRB).

66

See

49 U.S.C. 114(q) (Under Secretary may grant exemptions from regulatory requirements).

Similarly, TSA may need to require amendments in the interest of the public and transportation security. The 9/11 Act specifically provides that TSA must update the requirements, as appropriate, “to reflect new or changing security threats” and owner/operators shall change their programs and retrain employees as necessary within a reasonable time.

67

As indicated in proposed § 1570.115, TSA could require owner/operators to revise their training based on emerging threats or methods for addressing emerging threats. For example, the curriculum requirements identified in the 9/11 Act do not address training to respond to active shooter incidents. Following several active shooter incidents, including one that resulted in the death of a Transportation Security Officer in Los Angeles, Congress prioritized the need for this type of training.

68

As with other requirements imposed by TSA, the owner/operator could request a petition for reconsideration of TSA-required amendments.

67

See

6 U.S.C. 1137(d)(4) and 1167(d)(4) and 1184(d)(4).

68

See

Gerardo Hernandez Airport Security Act of 2015, Public Law 114-50, 159 Stat. 490 (Sept. 24, 2015).

Alternative Measures (§ 1570.117)

The proposed rule includes procedures allowing for an owner/operator to submit a request to use alternative measures to satisfy all of some of the requirements of subchapter D and the standard for TSA to approve such a request. For example, the owner/operator could request to extend the time periods for submitting its training program or for training all of its security-sensitive employees. In reviewing such a request, TSA would expect the owner/operator to demonstrate good cause for the extension. Under this provision, an owner/operator could request a waiver from some or all of the regulatory requirements. TSA could grant such a request under the authority 49 U.S.C. 114(q), which provides the TSA Administrator with authority to consider and grant requests from an owner/operator for a waiver from all or some of the regulatory requirements. For example, a freight railroad may meet the criteria for applicability, but the operations that trigger applicability may be a de minimis part of its overall business operations. In such a situation, the owner/operator might consider requesting either a complete waiver or an alternative that limits the requirements to a more discrete part of its business. Proposed § 1570.117 would include the procedures for requesting such a waiver, procedures for requesting the use of alternative measures, and identification of the types of information TSA would need in order to make a decision to grant such requests. In general, TSA would need to consider factors, such as risk associated with the type of operation, any relevant threat information, and any other factors relevant to potential risk to the public and transportation security.

Petitions for Reconsideration (§ 1570.119)

Proposed § 1570.119 describes the review and petition process for TSA's reconsideration when it denies a request for amendment, waiver, or alternative measures—as well as a TSA requirement to modify or amend a

program. If an owner/operator challenges the decision, the owner/operator would be required to submit a written petition for reconsideration within the time frame identified in the applicable section.

69

The petition would need to include a statement, with supporting documentation, explaining why the owner/operator believes the reason for the denial or for the amendment, as applicable, is incorrect. If the owner/operator requested the amendment, the results of the reconsideration could be confirmation of TSA's previous denial or approval of the proposed amendment. If the issue involves a TSA required amendment, the results of the reconsideration could be withdrawal, affirmation, or modification of the amendment. TSA would consider whether a disposition pursuant to proposed 49 CFR 1570.119 would constitute a final agency action for purposes of review under 49 U.S.C. 46110.

69

The proposed rule would require petitions for reconsideration to be submitted no later than 30 days of a TSA requirement to modify under § 1570.109, denial of an owner/operator-requested amendment under § 1570.111, or denial of a request for waiver or alternative measures under § 1570.117; submission would be required within 15 days for a TSA-required amendment under § 1570.113.

Recordkeeping Requirements (§ 1570.121)

TSA proposes that owner/operators create and maintain lists of their security-sensitive employees and when they received training that meets the requirements of the proposed rule. Specifically, records would need to include each trained employee's name, job title or function, date of hiring, and date and course information on the most recent security training that each employee received. Records for individual employees would need to reflect the training courses completed and date of completion. Training records for each employee of initial and recurrent training would need to be maintained by owner/operators for no less than five years from the date of the training and available at any location(s) specified in the security training program approved by TSA.

The proposed rule provides flexibility to owner/operators to decide whether to maintain the records in electronic format provided that (1) any electronic records system used is designed to prevent tampering, loss of data, or corruption of records, and (2) paper copies of records, and any amendments to those records, would be made available to TSA upon request for inspection or copying. Whether the records are kept in electronic or other form, the employee must be provided with proof of training upon request, at any time during the five-year recordkeeping period without regard to the requestor's current status as an employee of that entity. As discussed above in “Initial training (§ 1570.111(a)),” owner/operators may meet this requirement to provide proof of training by providing a certificate or other similar documentation to the employee upon completion of training. In order for TSA to allow any owner/operator to rely upon previous security training to satisfy the requirements of this proposed rule, it is critical that employees be able to validate whether they received previous training.

TSA assumes training records are unlikely to include SSI, but nonetheless provides a reminder in the proposed section that any SSI maintained as a result of these recordkeeping requirements must be maintained consistent with the standards in 49 CFR part 1520. For example, an owner/operator may decide to keep a copy of the content of the training program with the employee files (which is not required by the proposed rule), if the curriculum contains SSI information, any file it is in would need to be stored as required by the SSI regulations. Owner/operators needing additional information about appropriately maintaining SSI may contact TSA for assistance and/or find information on TSA's Web site.

70

70

See https://www.tsa.gov/for-industry/sensitive-security-information.

4. Subpart C—Operations

Under current regulations (49 CFR part 1580), TSA requires freight and passenger railroad carriers, rail transit systems, rail hazardous materials shippers, and certain rail hazardous materials receivers to appoint “rail security coordinators”

71

(RSCs) and report significant security concerns to TSA.

72

The RSC, serve as the security liaisons to TSA, providing a single point of contact for receiving communications and inquiries from TSA concerning threat information or security procedures, and coordinating responses with appropriate law enforcement and emergency response agencies. The information reported to TSA provides information from the frontline of rail transportation that can be used to identify developing threats based on consolidated reporting and trend analysis. Because of the benefits of this requirement to transportation security, TSA is proposing to extend these requirements to the modes of transportation covered by this proposed rule that are not currently subject to the requirements of 49 CFR part 1580.

71

See

49 CFR 1580.101 and 1580.201.

72

See

49 CFR 1580. 105 and 1580.203.

Security Coordinator Requirements (§ 1570.201)

As previously noted, TSA currently requires security coordinators for rail operations including freight, passenger, and public transportation. In addition to mandating security coordinators for railroads, the 9/11 Act also requires security coordinators for OTRB companies.

73

Consistent with this mandate, TSA proposes to extend the requirement to appoint a primary and at least one alternate security coordinator for OTRB companies and the bus operations of PTPR owner/operators (with a limited impact as most public transportation bus agencies are part of a larger system that is required to have a security coordinator under current 49 CFR part 1580). This would be accomplished by moving the provision from part 1580 to subpart C of the proposed rule and eliminating rail-specific terms from the text.

73

See

6 U.S.C. 1162(e)(1)(A) (“Identification of a security coordinator having authority—(i) to implement security actions under the plan; (ii) to coordinate security improvements; (iii) to receive immediate communications from appropriate Federal officials regarding railroad security”).

Security coordinators are a vital part of transportation security, providing TSA and other government agencies with an identified point of contact with access to company leadership and knowledge of the owner/operators operations, in the event it is necessary to convey extremely time-sensitive information about threats or security procedures to an owner/operator, particularly in situations requiring frequent information updates. The security coordinator and alternate provide TSA with a contact in a position to understand security problems; immediately raise issues with, or transmit information to, corporate or system leadership; and recognize when emergency response action is appropriate. The individuals must be accessible to TSA 24 hours per day, 7 days per week.

The proposed rule does not change the expectation that the security coordinator and alternate be appointed at the headquarters level. This proposed rule does not require the security coordinator or alternate to be a dedicated position staffed by an individual who has no other primary or additional duties. This proposed rule, however, does require that the owner/operator have a designated individual

that TSA may reach at all times. The proposed rule would require the following information for both the security coordinator and alternate: Name, title, telephone number(s), and email address. Any change in this information would have to be provided to TSA within seven days of the change taking effect.

As previously noted, this is not a new requirement for owner/operators of railroads, including the rail transit operations of PTPR owner/operators. If an owner/operator subject to this proposed rule has provided the required information for primary and alternate RSCs to TSA in the past, it would not have to take further action to meet the requirement.

74

This is the case for passenger rail carriers, freight railroad carriers, and rail transit systems operated by public transportation agencies.

74

The requirement to inform TSA of any changes is not modified by this proposed rulemaking. Therefore, those currently covered by the security coordinator and reporting requirements under current 49 CFR part 1580 must report information regarding changes to the names, titles, telephone numbers, and email addresses of the RSCs and alternate RSCs to TSA within seven calendar days of the change taking effect.

Extension and Modification of Requirement To Report Security Concerns (§ 1570.203)

TSA is proposing to make two changes to its existing requirements in part 1580 to report security concerns to TSA.

75

As with the security coordinator requirement, TSA proposes to move and consolidate the requirement into proposed § 1570.203 and extend it to bus operations.

76

75

See

current 49 CFR 1580.105 and 1580.203.

76

This extension is within TSA's discretion to require other actions or procedures determined to be appropriate to address the security of public transportation and OTRB operations.

See

6 U.S.C. 1134(c)(2)(I) and 1181(e)(1)(H).

TSA is also proposing to modify the security concerns to be reported to address a need for clarification and align with other relevant standards. Since publication of 49 CFR part 1580, some stakeholders have asked TSA for clarification of the events they are required to report pursuant to 49 CFR 1580.105 and 1580.203. Additionally, in December 2012, the U.S. Government Accountability Office (GAO) published a report on passenger rail security.

77

In the report, GAO stated that TSA has inconsistently overseen and enforced its rail security incident reporting requirement because the agency does not have guidance published, leading to considerable variation in the types and number of incidents reported. The GAO recommended that the agency develop guidance on the types of incidents that should be reported and this guidance should be disseminated to TSA inspectors and regulated entities, including rail and transit agencies. Pending this rulemaking, TSA provided information to the railroads and transit agencies subject to the requirements of part 1580 to provide more examples about the types of incidents that should be reported.

77

See

GAO, “Passenger Rail Security, Consistent Incident Reporting and Analysis Needed to Achieve Program Objectives,” GAO-13-20 (December 2012).

TSA is also modifying the list of reportable significant security concerns to be more consistent with the Nationwide Suspicious Activity Reporting (SAR) Initiative (NSI). The NSI is a partnership between Federal, State, local, tribal, and territorial law enforcement that “establishes a national capacity for gathering, documenting, processing, analyzing and sharing SAR information . . . in a manner that rigorously protects the privacy and civil liberties of Americans.”

78

The NSI defines “suspicious activity” as “observed behavior reasonably indicative of pre-operational planning associated with terrorism or other criminal activity.”

79

78

See

Nationwide SAR Initiative (NSI), “About the NSI” (accessed Nov. 3, 2016), available at

http://nsi.ncirc.gov/about_nsi.aspx.

79

Id.

The NSI implements a standardized, integrated approach to gathering, documenting, processing, analyzing, and sharing information about suspicious activity that is potentially terrorism-related. In applying this approach, standards have been developed, setting criteria for the types of activities that warrant reporting as suspicious and potentially terrorism-related. These criteria recognize the capability of law enforcement and security professionals to apply their experience and expertise to identify significant security concerns by focusing on the nature of the incidents and the context in which they occur. The standardized approach among law enforcement officers and security officials with surface transportation entities produces more informative reports that can more effectively focus investigative efforts and intelligence analysis for potential trends and indicators of terrorism-related activity.

Thus, TSA intends to ensure clarity by incorporating the examples previously provided to industry and consistency by aligning its regulations with the concepts of the NSI. The proposed list of reportable incidents can be found in proposed Appendix A to part 1570 and includes not only a list of incidents, but descriptions and examples to assist regulated parties in making a determination of whether an incident fits within the reporting requirements.

Finally, TSA is proposing to modify the schedule for reporting incidents. Currently the regulation requires immediate reporting to TSA. If, however, there is an immediate threat, the first priority is to notify and work with first responders. Therefore, TSA is proposing to remove the necessity for immediacy and, instead, require notification within 24 hours of the incident (

see

proposed 49 CFR 1570.203(a)). This will enable TSA to obtain timely information without undermining the ability of the owner/operator to appropriately handle a situation requiring their full attention.

Examples for Reporting Information (§ 1570.203(b))

As previously noted, TSA has almost a decade of experience with incidents reported by railroads under current 49 CFR part 1580. Based on this experience, TSA recognizes that its ability to analyze the data and improve the quality of information disseminated back to its stakeholders is proportional to the quality of information it receives. Proposed § 1570.203(b) is consistent with the previous reporting requirements, which reflected the need for detailed and verified information from individual owner/operators to enhance TSA's ability to provide timely and useful information products to all of the relevant stakeholders. While not included in the rule text, Table 5 is being provided to assist security coordinators and other responsible officials to understand TSA's expectations for the types of information that are needed in order to meet the standards of § 1570.203(b).

Table 5—Examples of Reporting Information Required by Proposed § 1570.203(c)

Reporting requirements in proposed § 1570.203(

c

)

Examples

(1) The name of the reporting individual and contact information, including a telephone number or e-mail address

• Company Representative: Joe BLOGGS.

• Company: ABC Rail Road Company.

• Address: XXXXX, XX (Street), XXXXX (City), XX (State), XXXXX (ZIP).

• Phone: (111) 123-1234.

• POC Email:

Reporting.Official@ABCRR.com.

(2) The affected freight or passenger train, transit vehicle, motor vehicle, station, terminal, rail hazardous materials facility, or other facility or infrastructure, including identifying information and current location

• Locomotive: ABCRR, Reporting Marks.

• Locomotive Number 1234.

• Rail Car: ABCRR Railcar Number XXXX 001234.

• Train: ABCRR Train Number XXX of XX, etc.

• Facility: ABCRR (Rail Yard, Subway Station, Passenger Station, Storage Yard, Repair Facility, etc.) and facility physical address.

• Right of Way: Mile Post Marker, Sub-division, and physical address (as much as known).

(3) Scheduled origination and termination locations for the affected freight or passenger train, transit vehicle, or motor vehicle, including departure and designation city and route

• ABCRR, Northern Corridor Express-Boston to New York, XYZ Line, via X, Y and Z Cities. Train Number XXX of XX is currently located at: MP 123.12, XXX Sub-division, XXXX (City), XX (State).

• Transit Vehicle: ABCRR LRV Number XXXXX etc. Route: XXX North Corridor. Is currently located at XXXX Line Section or XXX Station, Street, City, State, ZIP.

(4) Description of the threat, incident, or activity, including who has been notified and what action has been taken

• At XXXX hours, January 01, 2020.

• ABCRR Police Sergeant, Joe BLOGGS, badge number XXXX, ABCRR Police Department (ABCPD) reported the following: At WWWW hours, January 01, 2020, a suspicious person (described as a white male, approximately 6′0″ tall, 190 lbs., blonde hair, approximately 35 to 40 years of age, wearing a long black knee-length coat, blue jeans, red sneakers, and a XXXX ball club baseball hat) was detected adjacent to the ticket vending machine at the street level entrance to the XXst Street and YYYYY Avenue, Station, XXXX (City), XX (State). The person was deemed suspicious because although the temperature at the time was 85 degrees, he was wearing a knee-length heavy black coat. The individual was sweating and exhibited nervousness when security officials were present (the individual looked away every time a security official appeared, so as to not reveal his face). The individual had a black “Traveler,” “Expandable” suitcase with him (estimated measurements: 36″ W X 24″H X 12″ D) with a red piece of ribbon tied to the handle. At WWW5 hours, the individual rapidly departed the area when a security official began to approach him, leaving the black suitcase behind. A review of the Closed-circuit television (CCTV) surveillance system determined the individual had arrived at the station at VV30 hours in a Red, 4-door, Land Rover, VA License Plate XX123XXXX, which was parked adjacent to the XXXXX. Closed-circuit television revealed the vehicle was being driven by a white female with shoulder length blonde hair, approximately 35 years of age. A check of the VA DOT License registry revealed the vehicle is registered to Joe DOE, DOB: XX/XX/XXXX, POB: XXXXX (City), XX (State) and Jane (NEE: SMITH) DOE, DOB: XX/XX/XXXX, POB: XXXXX (City), XX (State) of 1234 West Disobedience Street, Anytown, VA 202XX, Phone Number: (XXX) XXX-XXXX. A check of the VA driver's license registry revealed similar/matching descriptions of Joe and Jane DOE to those persons identified during the incident. At ZZZZ hours, a XXXX City Police Explosive Ordnance Demolition (EOD) team conducted an examination of the black suitcase with x-ray equipment and determined the suitcase contained an unknown device comprised of wiring and circuitry. Explosive Ordinance Disposal (EOD) disrupted the suitcase, which yielded negative secondary results. EOD's examination of the suitcase's contents revealed limited amounts of women's clothing and what appeared to be the inner workings of a radio. At ZZZ1 hours, the scene was cleared by XXXX City Police EOD Sergeant Jeff BOMBGARTEN, badge number XXXX who secured the suitcase and its contents and transported them away from the facility.

(5) The names and other available biographical data, and/or descriptions (including vehicle or license plate information) of individuals or vehicles known or suspected to be involved in the threat, incident, or activity

• Witness: Joe SMITH, DOB: XX/XX/XXXX, POB: XXXX City, XX State. Address: XXXXX, XX Street, XXXX City, XX State, Phone Number (XXX) XXX-XXXX, ABCRR, XXXX (Address), (XXX) XXX-XXXX.

• Security: Fred ARRESTER, Sergeant, XXXX (City) Police Department, Badge # XXXX, Phone Number: (XXX) XXX-XXXX.

• Suspected Associate: Mrs. Jane DOE.

• DOB: XX/XX/XXXX, POB: XXXX City, XX State. Address: XXXXX, XX (Street), XXXX (City), XX (State), Phone Number (XXX) XXX-XXXX, ABCRR, XXXX (Address), (XXX) XXX-XXXX.

(6) The source of any threat information

• Jane DOE, DOB: XX/XX/XXXX, POB: XXXX (City), XX (State). Address: XXXXX, XX (Street), XXXX (City), XX (State), Phone Number (XXX) XXX-XXXX, ABCRR, XXXX (Address), (XXX) XXX-XXXX.

5. Subpart D—Security Threat Assessments

As previously noted, TSA is including the full text of revised part 1570 as it would look with the proposed changes—including three sections related to STAs generally unaffected by this rulemaking. As part of this rulemaking, TSA would move all sections of current part 1570 limited to STAs to a new subpart D, to consist of §§ 1570.301 (formerly § 1570.7—fraudulent use or manufacture; responsibilities of persons), 1570.303 (formerly § 1570.9—inspection of credential); and 1570.305 (formerly § 1570.13—false statements regarding security background checks by public transportation agency or railroad carrier). Only the last provision (§ 1570.305) has been revised, with revisions limited to removing definitions for terms that have been added elsewhere as part of this rulemaking.

E. Security-Sensitive Employees (§§ 1580.3, 1582.3, and 1584.3)

As part of requiring security training for frontline employees of railroads, PTPR, and OTRB owner/operators-the 9/11 Act provided definitions for “frontline employee” within each mode of transportation.

80

For the reasons discussed below, TSA is proposing to use the term “security-sensitive employees,” with specific definitions of the term for freight rail, PTPR, and OTRB operations. These proposed definitions, which would appear in §§ 1580.3 (freight rail), 1582.3 (PTPR), and 1584.3 (OTRB), would need to be used by owner/operators to determine which employees must receive security training.

80

See

6 U.S.C. 1151(6) (railroads), 6 U.S.C. 1131(4) (public transportation), and 6 U.S.C. 1151(5) (OTRB and railroad frontline employees, respectively).

TSA's proposed definition began with an analysis of the employees listed in the 9/11 Act's definitions of “frontline employees” and whether there are any other employees who may be in a position to spot suspicious activity because of where they work, their interaction with the public, or their access to information (such as cleaning the restrooms, selling tickets and providing assistance to passengers, maintaining equipment and operations in vulnerable areas, or operating a train or bus). TSA also considered who would need to know how to report or respond to these potential threats. The only gap identified between the employees stipulated in the 9/11 Act and those that would fall under the discretionary category are those who have specific responsibilities under any security plan the organization may have. While most of these individuals are likely identified in other categories, from a security perspective it is essential that there are no gaps, particularly where individuals may have responsibility for responding to a terrorist-related emergency.

As a result of this analysis, TSA proposes that employees who perform functions with a direct nexus to, or impact on, transportation security be designated as “security-sensitive employees” based on their job functions. While TSA has proposed a specific list of job functions relevant to the mode, these roughly fall into similar categories. Table 6 aligns these categories with the definitions of frontline employee in the 9/11 Act.

Table 6—Comparison of Security Training NPRM Proposed Categories for “Security-Sensitive Employees” to 9/11 Act Definitions of “Frontline Employees” Who Must Be Trained

Proposed rule—security-sensitive job functions

9/11 Act—Definitions of frontline employees

6 U.S.C. 1151(6) Railroad frontline employees

6 U.S.C. 1131(4) Public transportation frontline

employees *

6 U.S.C. 1151(5) OTRB frontline employees

A. Operating a vehicle

Locomotive engineers, conductors, trainmen, and other onboard employees

Transit vehicle driver or operator

Drivers.

B. Inspecting and maintaining vehicles

Maintenance and maintenance support personnel, and bridge tenders

Maintenance and maintenance support employee

Maintenance and maintenance support personnel.

C. Inspecting or maintaining building or transportation infrastructure

D. Controlling dispatch or movement of a vehicle

Dispatchers

Dispatchers

Dispatchers.

E. Providing security of the owner/operator's equipment and property

Security personnel

Security employee, or transit police

Security personnel.

F. Loading or unloading cargo or baggage

and/or

G. Interacting with travelling public (on board a vehicle or within a transportation facility)

Locomotive engineers, conductors, and other onboard employees

Station attendant, customer service employee, and any other employee who has direct contact with riders on a regular basis

Ticket agents [and] other terminal employees.

H. Complying with security programs or measures, including those required by federal law (a catch-all category that would include a small number of employees such as security coordinators and any other individuals who may have responsibility for carrying out aspects of the owner/operator's security program or measures who are not otherwise identified in the previous categories)

Any other employees of railroad carriers that the Secretary determines should receive security training

Any other employee of a public transportation agency that the Secretary determines should receive security training

Other employees of an over-the-road bus operator or terminal owner or operator that the Secretary determines should receive security training.

* Definition of 1151(6) applies to passenger rail operations.

In general, TSA proposes to define mode-specific “security-sensitive employees” as employees performing one of the security-sensitive job functions identified in a proposed appendix for each part. The definition of “employee” in proposed § 1570.3 includes immediate supervisors, contractors, and other authorized representatives. The intent is that anyone who performs a security-sensitive function must have the training, including managers, supervisors, or others who perform the function or who so directly supervise the performance of a function that their nexus to the job function is equivalent to the employee. For example, a yardmaster in freight railroad operations would be considered a security-sensitive employee because he or she directs security-sensitive functions, even if not in the direct management chain of all individuals performing those functions. At the same time, individuals within a corporate structure who neither perform a security-sensitive function nor have direct management responsibilities over individuals who do are unlikely to have a position within the corporation with a significant nexus to transportation. To the extent there are such individuals in the management structure, they would not be considered “security-sensitive” employees.

In choosing the term “security-sensitive employee,” TSA recognized the relationship of this proposed rule to other regulatory requirements applicable to the population covered by this proposed rule. The Department of Transportation uses the terms “safety-sensitive function” and “safety-sensitive employees” in its regulations to identify employees whose functions require special measures to

ensure

(emphasis added) safety, such as drug and alcohol testing and rules governing hours of service.

81

TSA proposes using the term “security-sensitive” to identify employees whose job functions require special measures to

enhance

(emphasis added) security.

81

See

49 CFR 40.1;

see also

49 U.S.C. 20140, 21101-21108, 49 CFR parts 219 and 228, 49 CFR 382.107 (motor carriers), and 49 CFR 655.4 (public transportation).

The scope of security-sensitive employees is broader than safety-sensitive employees. In other words, having analyzed the job functions that are regulated as safety-sensitive, TSA has determined that while there are some security-sensitive employees that may not be in safety-sensitive employees, there are no safety-sensitive employees that are not also security-sensitive employees. In the rail context, owner/operators have already identified employees in safety-sensitive positions because they are covered by the Federal hours of service laws

82

during a duty tour. Therefore, TSA proposes to include any rail employee subject to the Federal hours of service laws (49 U.S.C. 211) in the designation of security-sensitive employees to reduce the regulatory impact of identifying these individuals. To further reduce the impact of these proposed training requirements, TSA and DOT anticipate that owner/operators will provide training sessions that meet the requirements of DOT and the proposed requirements of TSA.

82

49 U.S.C. 21101

et seq.

The relevant definitions are included in 49 U.S.C. 21101.

TSA also recognizes that each mode covered by the NPRM has unique operating environments and functions. To address unique aspects of each mode, the security-sensitive functions are identified in mode-specific tables within the proposed rule.

83

These tables provide general categories and accompanying modal-specific security-sensitive functions. All employees performing “security-sensitive functions” as described in the appendices must be trained. The table in proposed part 1580 Appendix B is unique in that it includes examples of the job titles related to these functions based on historic use of these terms for railroads. The job titles, however, are provided solely as a resource to help understand the functions described; whether an employee must be trained is based upon the function, not the job title.

83

See

proposed Appendices B to parts 1580 (freight railroad), 1582 (passenger railroad and public transportation), and 1584 (OTRB).

TSA encourages owner/operators to consider other employees within a corporate structure who may not be performing a security-sensitive function as identified in the proposed rule, but who could provide an additional layer of security if they received security training. Furthermore, if an owner/operator identifies positions or functions not listed by TSA as security-sensitive, but which have the nexus to transportation security that is intended to be covered by the proposed rule, TSA would encourage the owner/operator to identify and include those employees within its security training program.

Finally, TSA is aware that some freight rail employees identified as

“security-sensitive” may also be considered “hazmat employees” and, therefore, subject to security training under 49 CFR 172.704 (these provisions are part of the hazardous materials regulations promulgated by PHMSA). It is not, however, a one-to-one correlation as determining which employees should be identified as “security-sensitive” for purposes of receiving training under this proposed rule is not the same analysis as that conducted for determining if an individual meets the definition of “hazmat employees” who must receive training under the PHMSA rule. As a result, there may be some overlap, but the group of individual employees that must be trained under the separate rules is unlikely to be identical. The effect of the overlap on training requirements is further discussed in section III.G of this NPRM.

F. Security Programs—Applicability (§§ 1580.301, 1582.301, and 1584.301)

As previously noted, the 9/11 Act mandates regulations requiring security training for frontline employees of public transportation agencies (6 U.S.C. 1137); railroads (6 U.S.C. 1167); and OTRBs (6 U.S.C. 1184). In implementing these requirements, TSA considered the operations and security risks associated with each mode identified in the 9/11 Act. This analysis determined risk consistent with DHS's official definition of risk as the “potential for an adverse outcome assessed as a function of threats, vulnerabilities, and consequences associated with an incident, event, or occurrence.”

84

As TSA focuses on the risk associated with acts of terrorism, this analysis considers threat as informed by intelligence, potential consequences of a terrorist attack, and inherent vulnerabilities in transportation systems and operations.

84

DHS Risk Lexicon, 2010 Edition, at 27.

In general, the security training requirements of this proposed rule would apply to owner/operators

85

with operations that meet the criteria identified in §§ 1580.301, 1582.301, and 1584.301. From a counter-terrorism perspective, TSA has determined that less than 300 out of approximately 10,000 surface transportation operations meet this criteria. Consistent with its commitment to a risk-based approach to transportation security, the proposed rule would only apply to these higher-risk operations. Nonetheless, TSA also encourages lower-risk operations to implement security training programs consistent with the requirements in this proposed rule.

85

See

proposed definition of “owner/operator” in § 1500.3 and discussion of terms in section III.A.1, Table 3, of this NPRM.

While the proposed criteria assume general similarities for operations within each mode, TSA recognizes that not all owner/operators have similar corporate structures and that there are many considerations affecting organizational decisions. TSA considered an applicability determination that would require a parent corporation to provide security training to its employees if one subsidiary triggered the requirements. But there may be some owner/operators that are subsidiaries of subsidiaries to a parent company that have no other transportation-related assets. Recognizing these variations in corporate structure, TSA is proposing to limit the requirements to the level of the subsidiary whose operations would trigger applicability. During the review and approval process, TSA would work with owner/operators in an effort to address any compliance issues based on corporate structure. For example, owner/operator A may be organized to make each regional area a separate subsidiary. As such, only the subsidiary that meets the applicability requirements would be required to develop a security training program. Owner/operator B may be a single entity for purposes of corporate-legal structure, with branches rather than subsidiaries providing service on specific routes. Under the rule, the entire corporation would be subject to the requirements based on the operations of one route. In this situation, owner/operator A could choose to submit a proposed alternative that would apply the requirements to branches and a handful of headquarters or other regional employees that provide them operational support. The submission requirements and procedures for requesting alternative measures are discussed in section III.D.3 of this NPRM.

The following section describes how TSA considered each of these risk elements in determining applicability for the proposed rule.

1. Freight Railroad

Approximately 574 freight railroads operate on the general railroad system of transportation in the United States.

86

The general railroad system of transportation is a shared rail network in which multiple railroad operators may use the same tracks for multiple purposes. Thus, a very small railroad operator may be using the same tracks as a large operator, and a freight railroad will often operate on the same tracks as a passenger rail operator. The geographic scope of this mode includes railroads operating on nearly 140,000 miles of track throughout North America.

87

The freight rail system transports 40 percent of intercity freight volume and approximately one-third of U.S. exports to ports and other distribution centers.

88

Commodities and products include consumer goods, agriculture and food products, motor vehicles, coal, chemicals, paper and lumber, and other commodities including ores, petroleum, and minerals.

89

In addition, freight rail lines are used for the operation of most of the commuter and intercity passenger railroads outside of the northeast corridor and freight rail personnel are sometimes used, on a contractual basis, to operate passenger trains.

86

Under 49 CFR part 209, Appendix A, the “general railroad system of transportation” is defined as “the network of standard gage track over which goods may be transported throughout the nation and passengers may travel between cities and within metropolitan and suburban areas.”

87

Association of American Railroads (AAR), “Railroad Facts, 2014 Edition” at pgs. 3 and 5 (2014).

88

Id.

89

Id.

Class I railroads

90

account for 69 percent of U.S. freight rail mileage and 90 percent of the employees. They are the only providers of intercity freight rail transportation, supporting major economic sectors in 44 states. Outside of the Northeast Corridor, Amtrak is dependent on Class I railroads for its operations—over 70 percent of Amtrak's routes operate on track owned by other railroads.

91

90

TSA is not modifying the definition of “Class I” in current 49 CFR part 1580, which incorporates by reference the Surface Transportation Board's classification of railroads based on annual operating revenues. The following are currently designated as Class I railroads: BNSF Railway, CSX Transportation, Grand Trunk Corporation, Kansas City Southern Railway, Norfolk Southern Combined Railroad Subsidiaries, Soo Line Corporation, and Union Pacific Railroad.

91

See

DeGood, Kevin, “Understanding Amtrak and the Importance of Passenger Rail in the United States” (posted June 4, 2015), available at

https://www.americanprogress.org/issues/economy/report/2015/06/04/114298/understanding-amtrak-and-the-importance-of-passenger-rail-in-the-united-states/. See also

Amtrak, “A Message from Amtrak Regarding On-Time Performance” (posted Feb. 8, 2015), available at

http://blog.amtrak.com/2015/02/message-amtrak-regarding-time-performance/.

Threat

Intelligence reviews of various attacks worldwide, as well as analysis of seized documents and the interrogation of captured and arrested suspects, reveal historic interest in carrying out attacks on railroad systems. For freight rail, the threat is greatest for shipments of RSSM, such as poison or toxic inhalation hazards (TIH), which could be directly

targeted or used as a weapon of mass effect with devastating physical and psychological consequences. Materials designated as RSSM are a subset of hazardous materials designated by PHMSA under 49 CFR 172.800(b).

92

92

TSA is proposing to adopt the list in 49 CFR 172.800(b) for purposes of meeting the requirement in sec. 1501 of the 9/11 Act to define transportation-related security-sensitive materials. This definition is discussed in section III.A.2 of this NPRM.

Vulnerability

The diversity and expanse of the North American railroad system presents a unique preparedness challenge related to preventing, responding to, and recovering from potentially devastating effects. The rail network is vast and the owner/operators vary in size and communities served. Numerous passenger and commuter rail systems throughout the country operate at least partially over tracks or rights-of-way owned by freight railroads.

Consequences

The interdependency of the railroad infrastructure—bridges, tunnels, dispatch and control centers, tracks, signals, and switches—means that threats and incidents affecting one railroad could impact many others on the general railroad system of transportation. A successful terrorist attack on the U.S. rail system could affect the functioning of private businesses and the government, and cause cascading effects far beyond the targeted physical location. Such an attack could result in significant losses in terms of human casualties, property destruction, and economic effects, as well as damage to public morale and confidence. Disruption or delay of rail service would also have adverse impacts on other sectors. For example, freight railroads have a critical role in the support of the energy sector and are responsible for the transportation of more than 70 percent of all U.S. coal shipments. They are also a critical part of the supply chain for military weapons and supplies. While railroads have been able to quickly respond to delays caused by natural disasters, such as the 2013 flooding in Colorado that washed-out tracks and delayed coal shipments and Amtrak service, this requires rerouting and can cause significant over-crowding and delays on lines used to move passengers and cargo pending restoration of damaged infrastructure.

93

Similarly, the release of TIH or other materials designated as RSSM could be catastrophic if it occurs in a metropolitan area or near critical resources that could be contaminated by the release.

93

See

“Colorado floods wash out tracks, delay coal shipments, Amtrak service,” The Denver Post (Sept. 16, 2013), available at

http://www.denverpost.com/2013/09/16/colorado-floods-wash-out-tracks-delay-coal-shipments-amtrak-service/.

Risk Determination

TSA has determined that the highest-risk freight railroads are those designated as Class I based on their revenue (over $72.9 billion in 2013) and the Nation's dependence on these systems to move both freight in support of critical sectors and passengers. Similarly, there are other shortlines (also known as Class II or Class III railroads) that are also higher-risk because they transport RSSM through HTUAs. Finally, to the extent the preceding does not capture freight railroads hosting higher-risk passenger railroads, the hosting relationship and dual use of infrastructure puts such railroads into the higher-risk category.

Proposed Applicability

Based on this risk determination, TSA is proposing to cover a railroad if it is designated as Class I, transports RSSM in one or more of the areas listed in current Appendix A to 49 CFR part 1580, or hosts a higher-risk rail operation (including freight railroads and the intercity or commuter systems identified in proposed § 1582.101). This would cover approximately 36 freight railroads.

In proposing this applicability, TSA recognizes that joint operations are common within this industry and include agreements such as allowing another railroad carrier to operate over track it does not own.

94

In these situations, the “host railroad” that owns the track exercises operational control of the movement of trains of the other railroads (the “tenant” railroads) while they are using that track.

95

Under the proposed rule, both the host and tenant railroads would be required to have a training program that appropriately addresses the ramifications of the hosting relationship. For example, the host railroad's training program would need to address the operational considerations of the hosting relationship, such as training dispatchers on their role and responsibilities in halting the tenant railroad's operations over a segment of track that has just been destroyed by an IED. Similarly, a tenant railroad subject to the security training requirements of proposed 49 CFR part 1582 (PTPR), would need to address the operational considerations of the hosting relationship, such as instructing its train and engine employees on the proper communication procedures to follow when informing the host railroad of a suspicious package blocking the track. Under either example, the host and tenant railroad owner/operators would only be responsible for training their own employees.

94

TSA's use of this term in this proposed rule is consistent with industry's general understanding of its meaning and 49 CFR 239.7, which defines “joint operations” as “rail operations conducted by more than one railroad on the same track, except as necessary for the purpose of interchange, regardless of whether such operations are the result of: (1) Contractual arrangements between the railroads; (2) Order of a government agency or a court of law: or (3) Any other legally binding directive.”

95

In recognition of these situations, TSA is proposing to add a definition of the term “host railroad” to 49 CFR 1500.3. The term “host railroad” is defined to mean “a railroad that has effective control over a segment of track.”

TSA also understands that some commuter passenger train services are owned by public transportation agencies, but operated by private companies (such as freight railroad carriers). This is not a hosting relationship. In this situation, TSA would consider the freight railroad carrier (the private company) to be a contractor of the PTPR owner/operator (the owner/operator of the passenger train service). TSA would hold the PTPR owner/operator primarily responsible for compliance and for ensuring that all security-sensitive employees receive the required training, whether they are employed directly by the PTPR owner/operator or contractor. In other words, the PTPR owner/operator would have the obligation to train the freight railroad carrier's employees that are performing security-sensitive functions related to the passenger train service. To the extent the contract between the PTPR owner/operator and the freight railroad includes a provision for the freight railroad to train its own employees, such training would need to be documented in the PTPR owner/operator's security training program. TSA would expect the passenger operation to clearly state in its security training program, as part of the submission process under proposed 49 CFR 1570.109, that the freight railroad carrier would conduct the training and provide the required information on that training.

Alternative Considered

TSA considered expanding the applicability of the proposed rule to a broader scope of owner/operators that would be responsible for developing their own security training program. The parameters for this alternative population include all freight railroad owner/operators operating within, or through, any geographic areas

designated for purposes of the FY 2015 Urban Area Security Initiative (UASI) Program regions. TSA estimates that this alternative would cover a total of 69 freight railroads in 26 metropolitan areas. TSA estimates that this alternative would have a cost of approximately $91.99 million for freight railroad owner/operators over a 10-year period (at a 7 percent discount rate). The basis for the estimates of benefits and costs are included in the RIA for this rulemaking, which is included in the public docket.

TSA rejected this alternative because the agency has determined that the proposed applicability aligns with its commitment to risk-based security policy and outcomes-based regulation. TSA has consistently recognized the security risks associated with transport of RSSM through the areas identified in Appendix A to current 49 CFR part 1580. The security basis for identifying these areas has not changed. Furthermore, expanding beyond the proposed applicability was unnecessary to gain the intended security benefits as it would not represent a corresponding expansion of employees trained since 90 percent of railroad employees would receive training as a result of the proposed rule's applicability. Additionally, when compared to the ten-year costs of the proposed applicability rule for freight railroad owner/operators ($90.74 million at 7 percent), this alternative would result in $1.25 million in additional costs.

2. Public Transportation and Passenger Railroads

There are more than 7,000 PTPR systems operating in the United States.

96

As part of an intermodal system of transportation, commuter passenger railroads provide critical regional services, such as between a central city and adjacent suburbs during morning and evening peak periods, as well as connecting to other modes of transportation through multimodal systems and within multimodal infrastructures. Since 1995, public transit ridership is up 39 percent, outpacing population growth, which is up 21 percent, and vehicle miles traveled (VMT), which is up 25 percent.

97

While passenger railroads primarily operate on the same track as freight railroads, they have many similarities to public transportation because of the operational concerns related to transporting people. Amtrak operates the Nation's primary intercity passenger rail service over a 22,000-mile network (primarily over leased, freight railroad tracks), serving more than 500 stations in 46 states and the District of Columbia. Many of these stations are multimodal transportation facilities located in higher-risk areas.

96

APTA, “2014 Public Transportation Fact Book,” 65th Edition, at 6, (Nov. 2014), available at

http://www.apta.com/resources/statistics/Documents/FactBook/2014-APTA-Fact-Book.pdf.

97

See

“Quick Facts” on APTA's Web site as of Jan. 27, 2016, available at

http://www.apta.com/mediacenter/ptbenefits/Pages/default.aspx.

Threat

Based on incidents in other countries, TSA assesses that terrorists view PTPR systems as attractive targets because they carry large numbers of people, are open and easily accessible to the public, are critical to regional transportation systems, and are vital to local economies. Terrorists have targeted rail and bus systems overseas. Notable incidents include the sarin gas attacks on the Tokyo subway system in April 1995; the multiple detonations of IEDs left on commuter trains in Madrid in March 2004; the multiple suicide attacks employing IEDs on the London Underground and a double-decker bus in London in July 2005; the multiple detonations of IEDs on commuter trains in the greater Mumbai area in July 2006; and, the double suicide attacks and two incidents of IED detonations in Dagestan and Moscow, respectively, in March, June, and August 2010.

TSA's Office of Intelligence and Analysis assesses with high confidence that terrorists remain intent on perpetrating attacks against this mode. In the period between January 1 and December 31, 2014, there were 144 reported attacks on mass transit systems overseas. Of these attacks, 76 targeted buses and associated infrastructure and 68 targeted mass transit and passenger rail systems and associated infrastructure.

Vulnerability

Attributes of PTPR systems essential to their efficiency also create potential security vulnerabilities that terrorists seek to exploit. Unlike strict access controls applicable to air transport, the public transportation system's multiple stops and interchanges lead to high passenger turnover, which is difficult to monitor effectively. In addition, the broad geographical coverage of passenger rail networks provides numerous options for access and getaway and affords the ability to use the system itself as the means to reach the location to conduct the attack.

Consequences

A potential terrorist attack on a public transportation center in a major metropolitan area can result in a large number of victims, both killed and wounded, as well as significant infrastructure damage. Rail system bombings in Madrid, London, and Mumbai—all involving use of multiple IEDs—are tragic reminders of this reality. Attacks could be isolated, having minimal effect on the total operating system, or could result in a major impact that has national implications: an attack on an intercity passenger railroad operating on the general system of transportation could potentially shut down railroad operation support for specific sectors. The disruption of any portion of the operation can confuse the public, directly affect businesses, and lead to panic. Attacks on multiple portions of a PTPR system exacerbate these impacts.

Risk Determination

In the context of resource allocations under the Transit Security Grant Program (TSGP), DHS has determined the highest transit-specific risk areas and transit systems using a model approved by the Secretary and vetted by Congress.

98

DHS has consistently considered several factors when determining risk for PTPR, including credible and specific international and domestic terrorist threats based on information provided by the intelligence community, system and infrastructure vulnerabilities, and consequences primarily in terms of the impact on the mission. As the mission of PTPR systems is to transport people, the consequences include the potential for devastating casualties.

99

TSA believes this model is an appropriate method for determining applicability for purposes of this rulemaking.

98

Federal Emergency Management Agency (FEMA) Grant Programs Directorate, “Risk Methodology

,

Fiscal Year 2015 Report to Congress, Calculating Risk for the FY 2015 DHS Preparedness Grant Programs” (December 21, 2015).

99

Id.

at 25-26.

An analysis of the transit-specific risk scores developed using the DHS method indicates a natural and significant break in the risk curve (delta between risk scores of one urban area to the next) between the top eight regions with the highest transit-specific risk and the others.

100

When combined, these areas represent over 94 percent of the total transit-specific risk to all urban areas across the Nation. Within each of these areas, DHS has identified the systems with the highest-risk based on considerations related to ridership, location of services provided (use of the same stations and stops), and

relationship between feeder and primary systems.

100

This analysis is based on SSI and/or classified intelligence information. As a result, TSA may not share details of the information or the analysis.

Proposed Applicability

Using this criteria, TSA is proposing to apply the requirements of this proposed rule to the systems identified in proposed 49 CFR part 1582, Appendix A. These 47 PTPR systems (46 PTPR plus Amtrak) are the systems with the highest risk operating in the eight regions with the highest transit-specific risk. Applying the rule's requirements to these 47 PTPR systems, corresponds to enhanced security for more than 80 percent of all PTPR passengers.

TSA is also proposing to apply the requirements to any PTPR owner/operator that hosts a high-risk freight railroad as identified in proposed § 1580.101. The reasons previously discussed for the parallel applicability to freight railroads in a hosting relationship with a high-risk passenger railroad apply equally to passenger railroads hosting high-risk freight railroads.

Alternative Considered

TSA considered expanding the applicability of a security training program to a broader scope of owner/operators. The parameters for this alternative population include all PTPR operations within or through a UASI region. TSA estimates that this alternative would cover a total of 253 PTPR owner/operators in 26 metropolitan areas. TSA estimates that this alternative would have a cost of approximately $127.88 million for PTPR owner/operators over a 10-year period (at a 7 percent discount rate). The basis for the estimates of benefits and costs are included in the RIA for this rulemaking, which is included in the public docket.

TSA rejected this alternative because the agency has determined that the proposed applicability aligns with its commitment to risk-based security policy and outcomes-based regulation. The risk analysis used for developing the TSGP funding allocations begins with identification of the UASI regions and then takes into consideration unique aspects of PTPR operations within that UASI in light of known risks. To adopt the UASI designations for applicability would ignore the second, critical step of the analysis used for TSGP allocations. By linking applicability to those agencies that have historically and consistently been designated as highest-risk for purposes of TSGP funding allocation, the proposed applicability links the greatest regulatory burden to those systems that the Federal government has determined merit the greatest funding allocations to address security. The majority of the funding under the TSGP goes to the highest-risk regions to ensure the greater risk is being addressed (94 percent in FY 15 and 95 percent in FY 14).

Based on these considerations, the negative impact of a broader regulatory requirement would not have a corresponding benefit to security—especially recognizing that the systems covered under the proposed applicability transport 80 percent of the PTPR ridership. Additionally, when compared to the ten-year costs of the proposed applicability rule for PTPR owner/operators ($53.14 million at 7%), this alternative would result in $74.74 million in additional costs.

3. Over-the-Road Buses

Highways are the largest and most prevalent component of the Nation's transportation network. Virtually every location within the continental United States is accessible by highway. The system today encompasses more than four million miles of roadway on which more than 600,000 bridges and 650 tunnels offer possible chokepoints. Within that system, commercial buses offer the most cost-effective intercity transportation to thousands of communities. For many people, fixed-route, intercity bus service is the only alternative to private vehicles.

It is estimated that there are over 3,300 private OTRB owner/operators operating approximately 29,000 buses and employing over 118,000 people in full and part-time jobs within the United States.

101

These owner/operators primarily conduct interstate operations that include wholly-owned bus terminals, shared terminals with other transportation modes (such as passenger rail), or pre-determined pick-up and drop-off locations (which may not be on the owner/operator's property).

101

For purposes of this discussion, an OTRB is considered the same as a motorcoach, which is consistent with the industry's interchangeable use of this term. For example, the Motorcoach Census 2015, commissioned by the American Bus Association (ABA), states: “a motorcoach, or over-the-road bus (OTRB), is defined as a vehicle designed for long-distance transportation of passengers, characterized by integral construction with an elevated passenger deck located over a baggage compartment. It is at least 35 feet in length with a capacity of more than 30 passengers . . . . This definition of a motorcoach excludes the typical city transit bus city sightseeing buses, such as double-decker buses and trolleys.”

See

ABA, “Motorcoach Census 2015,” at 7 (Feb. 11, 2016), available at

http://www.buses.org/assets/images/uploads/general/Motorcoach%20Census%202015.pdf.

In general, OTRBs have an average capacity of 55-60 passengers per bus and carry approximately 751 million passengers annually to thousands of destinations within the United States and to/from Canada and Mexico. Destinations include urban areas and passenger transfer points with close proximity to many of the most iconic and valuable sites in the Nation.

Threat

According to TSA's intelligence analysts and subject matter experts, buses represent attractive targets for terrorists, especially as it relates to hijacking, because they can be used as a vehicle-borne improvised explosive device (VBIED), provide the potential for large numbers of casualties, or could serve as a source for hostages. While there has not been a terrorist attack against a bus in the United States, threats and terrorist actions against motor coaches have occurred in other nations, including Israel, Spain, and the United Kingdom. As the Volpe National Transportation Systems Center noted, the industry provides terrorists with a “physically dispersed, easily accessed, high volume, target rich environment with potential for mass casualties.”

102

Over-the-Road Buses “serve all large metropolitan areas and travel in close proximity to some of the nation's most visible and populated sites, such as sporting events, major tourist attractions, and national landmarks.”

103

102

Volpe National Transportation Systems Center, “Security Enhancement Study for the U.S. Motorcoach Industry,” at vii (May 2003), available at

http://ntl.bts.gov/lib/55000/55200/55204/Security_enhancement_motorcoach_industry_exec_summ.pdf.

103

Id.

TSA identifies that the most likely threat would be represented by an IED brought aboard by a passenger or delivered by another vehicle in close proximity to the OTRB. There is also the potential threat of an attacker intent on capturing control of the bus and using it as a delivery system for a weapon of mass destruction against a high-value destination. Terrorists with access to this type of vehicle could use its capacity to transport as much as 12 tons of explosives. Coupled with the use of such vehicles in urban centers and in daily proximity to high-value buildings or venues, an OTRB could serve as a VBIED.

Vulnerability

Over-the-Road Buses travel on open roads, often on scheduled and predictable routes, with only a driver and passengers. While OTRBs are used to transport large volumes of passengers and baggage (either in the under-floor storage area or accessible to the

passenger), most owner/operators do not screen passengers and baggage for threats. Furthermore, OTRBs generally have large cargo compartments that can be reached without boarding the bus. As previously noted, a high number of OTRBs operate in urban settings and have the ability to gain close proximity to high-profile targets and highly-populated areas. These operations are vulnerable to a potential terrorist—providing frequent and predictable access to a vehicle that could either be targeted or exploited by an individual with malicious intent: It is relatively easy to perform reconnaissance, purchase a ticket, and travel anonymously with baggage that does not undergo screening.

Consequences

The consequence of a successful attack on an individual OTRB in a remote location is assumed to be the loss of the vehicle and many of its passengers. The same vehicle as a VBIED aimed at a high-value target is much greater. The National Counterterrorism Center (NCTC) states that one VBIED containing 4,000 kg of homemade explosives is equivalent to 200 pipe bombs or 20 suicide vests.

104

104

See

“TNT EQUIVALENTS” at

https://www.nctc.gov/site/methods.html#sarin.

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.

Security Training for Surface Transportation Employees · 81 FR 91336 | Frix