# Security Training for Surface Transportation Employees

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3A2016-28298

## Record

- **Collection:** Federal Register
- **Document type:** Proposed Rule
- **Published:** December 16, 2016
- **Citation:** 81 FR 91336

## Text

DEPARTMENT OF HOMELAND SECURITY
Transportation Security Administration
49 CFR Parts 1500, 1520, 1570, 1580, 1582, and 1584
[Docket No. TSA-2015-0001]
RIN 1652-AA55
Security Training for Surface Transportation Employees

AGENCY:

Transportation Security Administration, DHS.

ACTION:

Notice of proposed rulemaking (NPRM).

SUMMARY:

The Transportation Security Administration (TSA) is proposing to require security training for employees of higher-risk freight railroad carriers, public transportation agencies (including rail mass transit and bus systems), passenger railroad carriers, and over-the-road bus (OTRB) companies. Owner/operators of these higher-risk railroads, systems, and companies would be required to train employees performing security-sensitive functions, using a curriculum addressing preparedness and how to observe, assess, and respond to terrorist-related threats and/or incidents. As part of this rulemaking, TSA would also expand its current requirements for rail security coordinators and reporting of significant security concerns (currently limited to freight railroads, passenger railroads, and the rail operations of public transportation systems) to include the bus components of higher-risk public transportation systems and higher-risk OTRB companies. TSA also proposes to make the maritime and land transportation provisions of TSA's regulations consistent with other TSA regulations by codifying general responsibility to comply with security requirements; compliance, inspection, and enforcement; and procedures to request alternate measures for compliance. Finally, TSA is adding a definition for Transportation Security-Sensitive Materials (TSSM). Other provisions are being amended or added, as necessary, to implement these additional requirements.

While TSA will review and consider all comments submitted, TSA invites responses to a number of specific questions posed in the preamble of the NPRM.
See
the Comments Invited section under
SUPPLEMENTARY INFORMATION
that follows.

DATES:

Submit comments by March 16, 2017.

ADDRESSES:

You may submit comments, identified by the TSA docket number to this rulemaking, to the Federal Docket Management System (FDMS), a government-wide, electronic docket management system, using any one of the following methods:

Electronically:
You may submit comments through the Federal eRulemaking portal at
http://www.regulations.gov.
Follow the online instructions for submitting comments.

Mail, In Person, or Fax:
Address, hand-deliver, or fax your written comments to the Docket Management Facility, U.S. Department of Transportation, 1200 New Jersey Avenue SE., West Building Ground Floor, Room W12-140, Washington, DC 20590-0001; Fax 202-493-2251. The Department of Transportation (DOT), which maintains and processes TSA's official regulatory dockets, will scan the submission and post it to FDMS.

See

SUPPLEMENTARY INFORMATION
for format and other information about comment submissions.

FOR FURTHER INFORMATION CONTACT:

Harry Schultz (TSA Office of Security Policy and Industry Engagement) or Traci Klemm (TSA Office of the Chief Counsel) at telephone (571) 227-5563 or email to
SecurityTrainingPolicy@tsa.dhs.gov.

SUPPLEMENTARY INFORMATION:

Comments Invited

TSA invites interested persons to participate in this rulemaking by submitting written comments, data, or views. We also invite comments relating to the economic, environmental, energy, or federalism impacts that might result from this rulemaking action. See
ADDRESSES
above for information on where to submit comments.

With each comment, please identify the docket number at the beginning of your comments. TSA encourages commenters to provide their names and addresses. The most helpful comments reference a specific portion of the rulemaking, explain the reason for any recommended change, and include supporting data. You may submit comments and material electronically, in person, by mail, or fax as provided under
ADDRESSES
, but please submit your comments and material by only one means. If you submit comments by mail or delivery, submit them in an unbound format, no larger than 8.5 by 11 inches, suitable for copying and electronic filing.

If you want TSA to acknowledge receipt of comments submitted by mail, include with your comments a self-addressed, stamped postcard on which the docket number appears. We will stamp the date on the postcard and mail it to you.

TSA will file in the public docket all comments TSA receives, except for comments containing confidential information and Sensitive Security Information (SSI).
1

TSA will consider all comments received on or before the closing date for comments and will consider comments filed late to the extent practicable. The docket is available for public inspection before and after the comment closing date.

1
“Sensitive Security Information” or “SSI” is information obtained or developed in the conduct of security activities, the disclosure of which would constitute an unwarranted invasion of privacy, reveal trade secrets or privileged or confidential information, or be detrimental to the security of transportation. The protection of SSI is governed by 49 CFR parts 15 and 1520.

NPRM Specific Questions

While TSA will review and consider all comments submitted, TSA invites responses to the following five specific questions:

(1) The preferred avenue to submit security training programs to TSA, such as through email, secure Web site, or mailing address.

(2) TSA is proposing to use accumulated days of employment as one of the factors triggering whether an employee must be trained and requests comment specifically on how to calculate accumulated days and to ensure contractors are not used to avoid the requirements of this proposed rule.

(3) The use of previous training to satisfy requirements in the proposed rule.

(4) Options for harmonizing the proposed training schedule with existing training schedules and for adding efficiencies with other relevant regulatory requirements, including identification of any laws, regulations, or orders not identified by TSA that commenters believe would conflict with the provisions of the proposed rule.

(5) Options for ensuring training is effective in the absence of proficiency standards. For example, the proposed rule does not prescribe conditions for a pass/fail policy that may be associated with post-training testing, nor recommending a specified maximum number of times that an individual may take a test or evaluation to demonstrate knowledge and competency.

Handling of Confidential or Proprietary Information and Sensitive Security Information (SSI) Submitted in Public Comments

Do not submit comments that include trade secrets, confidential commercial

or financial information, or SSI to the public regulatory docket. Please submit such comments separately from other comments on the rulemaking. Comments containing this type of information must be appropriately marked as containing such information and submitted by mail to the address listed in
FOR FURTHER INFORMATION CONTACT
section.

TSA will not place comments containing SSI in the public docket, but will handle them in accordance with applicable safeguards and restrictions on access. TSA will hold documents containing SSI, confidential business information, or trade secrets in a separate file to which the public does not have access, and place a note in the public docket that TSA has received such materials from the commenter. If TSA determines, however, that portions of these comments may be made publicly available, TSA may include a redacted version of the comment in the public docket. If TSA receives a request to examine or copy information that is not in the public docket, TSA will treat it as any other request under the Freedom of Information Act (FOIA) (5 U.S.C. 552) and FOIA regulation of the Department of Homeland Security (DHS) found in 6 CFR part 5.

Reviewing Comments in the Docket

Please be aware that anyone is able to search the electronic form of all comments in any of our dockets by the name of the individual who submitted the comment (or signed the comment, if submitted on behalf of an association, business, labor union,
etc.
). You may review the applicable Privacy Act Statement published in the
Federal Register
on April 11, 2000 (65 FR 19477) and modified on January 17, 2008 (73 FR 3316), or you may visit
http://DocketsInfo.dot.gov.

You may review TSA's electronic public docket on the Internet at
http://www.regulations.gov.
In addition, DOT's Docket Management Facility provides a physical facility, staff, equipment, and assistance to the public. To obtain assistance or to review comments in TSA's public docket, you may visit this facility between 9:00 a.m. and 5:00 p.m., Monday through Friday, excluding legal holidays, or call (202) 366-9826. This docket operations facility is located in the West Building Ground Floor, Room W12-140 at 1200 New Jersey Avenue SE., Washington, DC 20590.

Availability of Rulemaking Document

An electronic copy can be obtained using the Internet by—

(1) Searching the electronic Federal Docket Management System (FDMS) Web page at
http://www.regulations.gov;

(2) Accessing the Government Printing Office's Web page at
http://www.gpo.gov/fdsys/browse/collection.action?collectionCode=FR
to view the daily published
Federal Register
edition; or accessing the “Search the
Federal Register
by Citation” in the “Related Resources” column on the left, if you need to do a Simple or Advanced search for information, such as a type of document that crosses multiple agencies or dates.

In addition, copies are available by writing or calling the individual in the
FOR FURTHER INFORMATION CONTACT
section. Make sure to identify the docket number of this rulemaking.

Abbreviations and Terms Used in This Document

AAR—Association of American Railroads

ABA—American Bus Association

Amtrak—National Railroad Passenger Corporation

APTA—American Public Transportation Association

CD—Compact Disc

CCTV—Closed-Circuit Television

CFATS—Chemical Facility Anti-Terrorism Standards

CFATS EAP—Expedited Approval Program for the CFATS program

CFATS RBPS—Risk-Based Performance Standards of the CFATS program

CFATS SSP—Site Specific Plans part of the CFATS program

DHS—Department of Homeland Security

DIF—Difficulty-Importance-Frequency

EOD—Explosives Ordinance Disposal

FMCSA—Federal Motor Carrier Safety Administration

FRA—Federal Railroad Administration

FTA—Federal Transit Administration

GAO—U.S. Government Accountability Office

GCC—Government Coordinating Council

HMR—Hazardous Materials Regulations

HSA—Homeland Security Act of 2002

HTUA—High Threat Urban Area

IED—Improvised Explosive Device

IFR—Interim Final Rule

IRFA—Initial Regulatory Flexibility Analysis

MOU—Memorandum of Understanding

NCTC—National Counterterrorism Center

NSI—Nationwide Suspicious Activity Reporting (SAR) Initiative

OAs—Oversight Agencies

OMB—Office of Management and Budget

OTRB—Over-the-Road Bus

PAG—Transit Policing and Security Peer Advisory Group

PHMSA—Pipeline and Hazardous Materials Safety Administration

PRA—Paperwork Reduction Act of 1995

PTPR—Public Transportation and Passenger Railroads

RFA—Regulatory Flexibility Act of 1980

RIA—Regulatory Impact Analysis

RSC—Rail Security Coordinator

RSSM—Rail Security-Sensitive Material

SBA—Small Business Administration

SCC—Sector Coordinating Council

SMS—Safety Management System

SSI—Sensitive Security Information

TIH—Toxic Inhalation Hazard

TSA—Transportation Security Administration

TSGP—Transit Security Grant Program

TSSM—Transportation Security Sensitive Material

UASI—Urban Area Security Initiative

UMRA—Unfunded Mandates Reform Act of 1995

VBIED—Vehicle-Borne Improvised Explosive Device

Table of Contents

I. Executive Summary

II. Background

A. Context and Purpose

B. Statutory Authorities

C. Rule Organization

III. Proposed Rule

A. Amendments to Part 1500

1. General Terms

2. Transportation Security-Sensitive Materials

B. Amendments to Part 1503

C. Amendments to Part 1520

D. Amendments to Part 1570

1. Overview of changes and structure

2. Subpart A—General

3. Subpart B—Security Programs

4. Subpart C—Operations

5. Subpart D—Security Threat Assessments

E. Security-Sensitive Employees (§§ 1580.3, 1582.3, and 1584.3)

F. Security Programs—Applicability (§§ 1580.301, 1582.301, and 1584.301)

1. Freight Railroads

2. Public Transportation and Passenger Railroads

3. Over-the-Road Buses

4. Foreign Owner/Operators

5. Preemption

G. Security Program General Requirements (§§ 1580.113, 1582.113, and 1584.113)

1. Information About the Owner/Operator

2. Information on How Training Will Be Provided

3. Ensuring Supervision of Untrained Employees and Providing Notice of Changes Affecting Training

4. Methods for Determining Effectiveness of Training

5. Relation to Other Training

H. Security Training and Knowledge for Security-Sensitive Employees (§§ 1580.115, 1582.115 and 1584.115)

1. Training Required for Security-Sensitive Employees

2. Limits on Use of Untrained Employees

3. Knowledge Required

I. Other Security Training Programs

1. Federal Railroad Administration Safety Training Requirements

2. Federal Transit Administration Safety Requirements

3. OTRB Safety Requirements

4. Hazardous Materials Regulations

a. Overlap With DOT Regulations Regarding Transportation of Hazardous Materials

b. Inspections and Enforcement

c. Overlap With Other DHS Regulations

J. Training Resources

K. Programmatic Alternatives

IV. Stakeholder Consultations

A. Multi-Modal Outreach

B. Freight Rail

C. Public Transportation and Passenger Rail

D. Over-the-Road Buses

E. Labor Unions

V. Rulemaking Analyses and Notices

A. Paperwork Reduction Act

B. Economic Impact Analyses

1. Regulatory Impact Analysis Summary

2. Executive Orders 12866 and 13563 Assessments

3. OMB A-4 Statement

4. Alternatives Considered

5. Regulatory Flexibility Assessment

6. International Trade Impact Assessment

7. Unfunded Mandates Assessment

C. Executive Order 13132, Federalism

D. Environmental Analysis

E. Energy Impact Analysis

I. Executive Summary

Purpose of the Regulatory Action

The purpose of this proposed rule is to solidify the enhanced baseline of security for higher-risk surface transportation operations by improving and sustaining the capability of employees to observe, assess, and respond to security risks and potential security breaches. These critical capabilities include identifying, reporting, and appropriately reacting to suspicious activity, suspicious items, dangerous substances, and security incidents that may be associated with terrorist reconnaissance, preparation, or action. The proposed requirements specifically apply to training employees performing security-sensitive job functions for higher-risk public transportation systems, railroad carriers (passenger and freight), and OTRB owner/operators. Preparing and training these employees to observe, assess, and respond to anomalies, threats, and incidents within their unique working environment may be the critical point for preventing a terrorist act and mitigating the consequences.

Since its creation following the attacks of September 11, 2001, TSA has had statutory authority to assess a security risk for any mode of transportation, develop security measures for dealing with that risk, and enforce compliance with those measures.
2

This includes broad regulatory authority, which enables TSA to issue, rescind, and revise regulations as necessary to carry out its transportation security functions.
3

As part of the Implementing Recommendations of the 9/11 Commission Act of 2007 (9/11 Act),
4

Congress mandated that DHS use its authority to issue regulations and included in the statute minimum requirements for employees to be trained, subjects of training, and procedures for the submission and approval of training programs.
5

As part of this mandate, the 9/11 Act also requires higher-risk railroads and OTRBs to appoint security coordinators.
6

This NPRM would propose to implement those provisions.

2

See
Section 101 of the Aviation and Transportation Security Act (ATSA), Public Law 107-71, 115 Stat. 597 (Nov. 19, 2001), codified at 49 U.S.C. 114 (ATSA created TSA and established the agency's primary federal role to enhance security for all modes of transportation). Section 403(2) of the Homeland Security Act of 2002 (HSA), Public Law 107-296, 116 Stat. 2135 (Nov. 25, 2002), transferred all functions related to transportation security, including those of the Secretary of Transportation and the Under Secretary of Transportation for Security, to the Secretary of Homeland Security. Pursuant to DHS Delegation Number 7060.2, the Secretary delegated to the Administrator, subject to the Secretary's guidance and control, the authority vested in the Secretary with respect to TSA, including that in sec. 403(2) of the HSA.

3
49 U.S.C. 114(l)(1).

4
Public Law 110-53, 121 Stat. 266 (Aug. 3, 2007).

5

See
secs. 1408, 1517, and 1534 of the 9/11 Act, codified at 6 U.S.C. 1137, 1167, and 1184, respectively. For the remainder of this NPRM, TSA will refer to the codified section numbers.

6

See
secs. 1512 and 1181 of the 9/11 Act, codified at 6 U.S.C. 1162 and 1181, respectively. TSA addresses 6 U.S.C 1162(e)(1)(A) and 1181(e)(1)(A) in this rulemaking. TSA intends to address the other regulatory requirements of these provisions in separate rulemakings.

Summary of the Major Provisions

As discussed in section III.F. of this NPRM, TSA is proposing to apply the requirements to higher-risk operations, based on mode-specific assessments of risk. Based on these assessments, the requirements would apply to:

• Class I freight railroad carriers, railroads transporting Rail Security-Sensitive Materials (RSSMs) through identified High Threat Urban Areas (HTUAs) (applying those terms as defined in current 49 CFR 1580.3), and railroads that host other higher-risk rail operations. This would cover approximately 36 railroads.

• Public transportation and passenger railroads (PTPRs) operating in the eight regions with the highest transit-specific risk. This would cover approximately 46 systems.

• The National Railroad Passenger Corporation (Amtrak), an intercity passenger railroad.

• OTRB owner/operators providing fixed-route service (also referred to as regular route or scheduled service) to/through/from the highest-risk urban areas. This would cover approximately 202 OTRB owner/operators.

This NPRM proposes requiring the entities listed above to:

• Develop security training programs to enhance and sustain the capability of their security-sensitive employees to observe, assess, and respond to security incidents as well as to have the training necessary to implement their specific responsibilities in the event of a security incident.

• Submit the required security training program to TSA for review and approval.

• Implement the security training program and ensure all existing and new security-sensitive employees complete the required security training within the specified timeframes for initial and recurrent training.

• Maintain records demonstrating compliance and make the records available to TSA upon request for inspection and copying.

• Appoint security coordinators and alternates-who will be accessible to TSA 24 hours per day, 7 days per week-and transmit contact information for those individuals to TSA (an extension of current 49 CFR part 1580 requirements).

• Report significant security incidents or concerns to TSA (an extension of current 49 CFR part 1580 requirements).

• Review and update security training programs as necessary to address changing security measures or conditions.

The proposed rule would also amend 49 CFR part 1500 to streamline definitions for TSA's regulation and would add a definition of Transportation Security-Sensitive Materials (TSSMs). Proposed revisions to 49 CFR parts 1503 and 1520 would conform references and provisions related to enforcement and handling of SSI to the expanded scope of security requirements in the proposed rule.

The most significant proposed revisions are found in subchapter D of chapter XII of title 49. This subchapter would be retitled “Maritime and Surface Transportation Security,” reorganized, and expanded to include the proposed security program requirements. The general rules for subchapter D would continue to be in part 1570, but reorganized and expanded to address the new requirements proposed in this rule. This NPRM also proposes to add a new section (1570.7) to make it clear that owner/operators, employees, contractors, and other persons can be held liable for violating TSA's regulations. A similar provision is part of TSA's aviation-related regulations and adding it to subchapter D ensures consistency in enforcement across all modes of transportation. This provision is further discussed in section III.D.2 of this NPRM.

Some provisions currently limited to railroads under part 1580 would be

moved and revised to address the additional modes, such as provisions related to “compliance, inspection, and enforcement.” This necessitates reorganization and minor revisions to current part 1580. The impact of the proposed rule on the organization and scope of current 49 CFR part 1580 is discussed in section II.C. of this NPRM. The following table (Table 1) provides a summary of the requirements and their applicability (distinguishing between current requirements/applicability and proposed requirements/applicability).

Table 1—Summary of Proposed Requirements
[Current 49 CFR part 1580 requirements incorporated into this NPRM are indicated with an “X”; proposed requirements are indicated with a “P”]

Inspection
authority
(§ 1570.9)

Protecting
sensitive
security
information
(part 1520)

Security
coordinator
(§ 1570.201)

Reporting
security
incidents
(§ 1570.203)

Security

training
1

Freight railroad carriers
X
X
X
X
P

Rail hazardous materials shippers
X
X
X
X

Rail hazardous materials receivers in HTUAs
X
X
X
X

Owner/operators of private rail cars
X
X
X
X

Host railroads of freight or PTPR rail operations within scope of rule
X
X
X
X
P

PTPR operating rail transit systems on general railroad system, intercity passenger train service, and commuter train services
X
X
X
X

2
P

PTPR operating rail transit systems not part of general railroad system
X
X
X
X

2
P

Tourist, scenic, historic, and excursion rail owner/operators
X
X
X
X

PTPR operating bus transit or commuter bus systems in designated areas
P
P
P
P
P

OTRB owner/operators providing fixed-route service in designated areas
P
P
P
P
P

1
49 CFR part 1570, Subpart B (Security Programs); 49 CFR part 1580, Subpart B—Employee Security Training (freight railroads); 49 CFR part 1582, Subpart B—Employee Security Training (PTPR); and 49 CFR part 1584, Subpart B—Employee Security Training (OTRBs).

2
If Amtrak, or listed in proposed part 1582, Appendix A (a public transportation system, or part of a public transportation system).

Costs and Benefits

TSA estimates the overall cost of this proposed rule is $157.27 million over 10 years discounted at 7 percent. TSA estimates the cost of this proposed rule by the 4 affected parties (all costs are 10 years at 7 percent): For freight railroads the rule would cost a total of $90.74 million, for PTPR the cost is $53.14 million, for OTRB the cost is $12.08 million, and for TSA the cost is $1.31 million.

The proposed rule, if finalized, would enhance surface transportation security by reducing vulnerability to terrorist attacks in four different ways. First, the surface transportation employees in each of the three covered modes would be trained to identify security vulnerabilities. Second, these surface transportation employees would be better trained to recognize potentially threatening behavior and properly report that information. Third, these surface employees would be trained to respond to incidents, thereby mitigating the consequences of an attack. Finally, the covered surface transportation owner/operators would be required to report significant security concerns to TSA so that TSA can analyze potential threats across all modes.

This analysis reflects information obtained through a Notice published in the
Federal Register
in 2013
7

(2013 Notice). Through that Notice, TSA requested data needed to provide a more accurate understanding of the existing baseline and potential costs associated with the proposed rule. In particular, TSA requested information regarding programs currently implemented—whether as a result of regulatory requirements, grant requirements, in anticipation of a rule, voluntary, or otherwise—and the costs associated with those training programs.

7
78 FR 35945 (June 14, 2013).

II. Background

A. Context and Purpose

Surface transportation systems—including public transportation systems, intercity and commuter passenger railroads, freight railroads, intercity buses, and related infrastructure—are vital to our economy and essential to national security.
8

The potential for a terrorist attack exists at each stage of moving people, goods, and services throughout the Nation.

8
Surface Transportation and Rail Security Act of 2007, report of the Senate Committee on Commerce, Science, and Transportation at 2 (S. Rept. 110-29, Mar. 1, 2007), quoting Executive Order (E.O.) 13416 (Dec. 5, 2006), published at 71 FR 71033 (Dec. 7, 2006).

Recent attacks indicate the risk of terrorist attack to surface transportation. On August 21, 2015, there was an attempted mass shooting on a packed high-speed train bound for Paris from Amsterdam.
9

Metropolitan Police treated a December 5, 2015, knife attack in a London public transportation station as a terrorist incident.
10

There have been other documented terrorist attacks targeting surface transportation, including the attack in Madrid, Spain, on March 11, 2004, in which terrorists attacked four commuter trains using 10 improvised explosive devices (IED) that exploded near-simultaneously and resulted in the deaths of 191 people and injury to more than 1,800 people.
11

In July 2005, four coordinated suicide bombings occurred, three on separate trains through London Underground stations and the fourth on a double-

decker bus, killed 52 people.
12

In July 2008, a group linked to Lashkar-e-Tayyiba attacked Mumbai's Western Railway Line with seven IEDs during evening commute hours, killing 183 people.
13

In November 2008, this group committed another coordinated attack that included shooting and bombing operations at several targets—including a train station—and killed a total of 164 people.
14

More recently, U.S. news media reported that the Federal Bureau of Investigation (FBI) uncovered a plot to attack the PATH commuter rail system serving New York and New Jersey in mid-2006.
15

These previous events highlight the magnitude of the deadly consequences that an attack on surface transportation could have.

9

See
Michael Birnbaum, “A change of seats for 3 Americans led to saved lives on Paris-bound train,” Washington Post (Aug. 24, 2015), available at
https://www.washingtonpost.com/world/as-french-train-suspect-is-interrogated-questions-mount-on-europes-security/2015/08/23/088ff2fe-4923-11e5-9f53-d1e3ddfd0cda_story.html.

10

See
BBC, “Leytonstone Tube station stabbing a `terrorist incident' ” (Dec. 6, 2015), available at
http://www.bbc.com/news/uk-35018789.

11
Encyclopedia Britannica, “Madrid train bombings of 2004” (May 19, 2013), available at
http://www.britannica.com/event/Madrid-train-bombings-of-2004.

12
CNN, “July 7 2005 London Bombings Fast Facts” (updated June 29, 2016, 9:44 a.m.), available at
http://www.cnn.com/2013/11/06/world/europe/july-7-2005-london-bombings-fast-facts/.

13
Bureau of Diplomatic Security, “India 2013 Crime and Safety Report: Mumbai” (March 5, 2013), available at
https://www.osac.gov/pages/ContentReportDetails.aspx?cid=13701.

14
CNN, “Mumbai Terror Attacks Fast Facts” (updated Nov. 4, 2015, 11:57 a.m.), available at
http://www.cnn.com/2013/09/18/world/asia/mumbai-terror-attacks/.

15
Mary Frost, “NYC subways targeted in ISIS terror plot—NYPD, FBI evaluating threat level,” Brooklyn Daily Eagle (Sept. 25, 2014), available at
http://www.brooklyneagle.com/articles/2014/9/25/nyc-subways-targeted-isis-terror-plot-nypd-fbi-evaluating-threat-level.

As part of its ongoing communications with stakeholders, TSA has alerted owner/operators affected by this proposed rule to transportation-related threats and has worked with many of them to review and recognize potential vulnerabilities to their operations. The impact that security training can have on these operations was recognized by Congress when it mandated, and provided detailed requirements for, security training regulations as part of the 9/11 Act.
16

16
Public Law 110-53, 121 Stat. 266 (Aug. 3, 2007).

TSA recognizes that the owner/operators of surface transportations systems, both public and private, are principally responsible for the safety and security of the people using their services. As noted in Presidential Policy Directive/PPD-21, “Critical Infrastructure Security and Resilience:”

The Nation's critical infrastructure is diverse and complex. It includes distributed networks, varied organizational structures and operating models (including multinational ownership), interdependent functions and systems in both the physical space and cyberspace, and governance constructs that involve multi-level authorities, responsibilities, and regulations.
Critical infrastructure owners and operators are uniquely positioned to manage risks to their individual operations and assets, and to determine effective strategies to make them more secure and resilient.
17

17
PPD-21 (Feb. 12, 2013) (emphasis added).

Surface transportation employees—the people who provide and support these services—are a critical resource for protecting passengers and the transportation infrastructure.

As a result of TSA's programmatic efforts, as well as awareness of the requirements of the 9/11 Act, many owner/operators of higher-risk surface transportation operations have voluntarily implemented security training programs that address some of the requirements of this proposed rule. As noted in the economic analysis for this rulemaking, however, the private market may not provide adequate incentives for owner/operators to make a socially optimal investment in the full range of measures that would reduce the probability of a successful terrorist attack based on the economics of externalities. (Externalities are costs or benefits from an economic transaction experienced by parties “external” to the transaction.) Specifically, for surface mode owner/operators, the total consequences of an attack or other security incident to society may be greater than what would be suffered by the individual owner/operator of the infrastructure or facility.

Without ignoring the voluntary efforts of owner/operators to increase the baseline of their security, including by providing security training, TSA also recognizes a firm normally would not choose to make an investment in security over its privately optimal amount in a competitive market place, since such an investment would increase the firm's cost of production, placing it at a disadvantage when competing with companies that have not chosen to make a similar investment in security.

Focusing on the higher-risk operations and frontline employees (defined in the rule as those performing security-sensitive functions), this proposed rule would close gaps in the scope or breadth of training provided as part of voluntary efforts. To the extent resource and economic considerations could cause this voluntary commitment to abate in the future, this proposed rule, when finalized, should solidify these efforts and commitment to security training.

Thus, the purpose of this proposed rule is to solidify a baseline of security training for surface transportation by enhancing and sustaining the capability of frontline employees for higher-risk public transportation systems, railroad carriers (passenger and freight), and OTRB owner/operators to observe, assess, and respond to security risks and potential security breaches. These critical capabilities include identifying, reporting, and appropriately reacting to suspicious activity, suspicious items, dangerous substances, and security incidents that may be associated with terrorist reconnaissance, preparation, or action. An employee who is prepared and trained to observe, assess, and respond may be the critical point for preventing a terrorist act.

Security awareness training is an important and effective tool to enhance an employee's ability to detect and deter attacks by terrorists or others—particularly those with malicious intent to target surface transportation or use vehicles as delivery systems for weapons of mass destruction. Well-trained employees can serve as security force-multipliers. Their familiarity with the facilities and operating environments of their specific transportation systems makes them especially effective at recognizing situations and conditions that may pose a threat to the safety and security of passengers, cargo, and transportation infrastructure.

Employees who are prepared to execute their security-related responsibilities and trained to observe, assess, and respond bring an informed vigilance to their daily responsibilities. They are more capable of identifying and making timely reports to support inquiry by law enforcement and security personnel, increasing the potential for detection or disruption of terrorist planning, preparations, and observations. In the event an incident does occur, employees who understand their roles and responsibilities under the owner/operator's security planning and response documents are better prepared to initiate timely responsive actions to mitigate consequences and work with first responders.

This rulemaking is part of TSA's commitment to risk-based security and how it implicates policy decisions, resource commitments, and expectations. Passengers traveling through a higher-risk area or system (whether by bus or train) should be able to expect the same level of security regardless of the carrier. Communities in HTUAs should expect that the freight trains carrying RSSM
18

are operated by employees with a common baseline of security training, regardless of who owns or operates the train. The result is

a proposed rule that bases applicability primarily on the location where the transportation is operated (rather than constructs of ownership) and scope of employees to be trained on the functions they perform (rather than titles in position descriptions).

18
As previously noted, TSA is not proposing to modify these terms as defined in current 49 CFR 1580.3.

For these reasons, TSA proposes this regulation requiring owner/operators to implement employee security training programs for employees serving in security-sensitive positions in higher-risk operations. TSA explains aspects of the proposed rule more fully in section III of this NPRM.

B. Statutory Authorities

The security of the Nation's transportation systems is vital to the economic health and security of the United States. Ensuring transportation security while promoting the movement of legitimate travelers and commerce is a critical counter-terrorism mission assigned to TSA.

Since its creation following the attacks of September 11, 2001, TSA has had broad statutory authority to assess a security risk for any mode of transportation, develop security measures for dealing with that risk, and enforce compliance with those measures.
19

This includes broad regulatory authority, which enables TSA to issue, rescind, and revise regulations as necessary to carry out its transportation security functions.
20

19

See supra,
n. 2.

20
49 U.S.C. 114(l)(1).

Congress has determined that a regulation is necessary for owner/operators of public transportation systems, passenger railroads, freight railroads, and OTRBs to provide security training to their frontline employees. As part of the 9/11 Act,
21

Congress mandated that DHS use its authority to issue regulations and included in the statute minimum requirements for employees to be trained, subjects of training, and procedures for the submission and approval of training programs.
22

This NPRM proposes to implement these provisions.

21
Public Law 110-53, 121 Stat. 266 (Aug. 3, 2007).

22

See
6 U.S.C. 1137, 1167, and 1184.

The 9/11 Act includes a requirement to include “[l]ive situational training exercises” as part of its security training regulations.
23

As part of the Homeland Security Exercise and Evaluation Program (HSEEP), DHS describes the benefit of exercises “to test and validate plans and capabilities.”
24

While testing the effectiveness of training is important, the HSEEP focuses on the need to test effectiveness of the overall plan—a process that reveals any weaknesses in training. TSA has determined the intent of requiring exercises would be better met if owner/operators were required to test the effectiveness of their security plans—which would include testing employee understanding and capabilities related to their roles, responsibilities, protocols, and procedures. Therefore, TSA has decided to address this element in a separate rulemaking that will meet related 9/11 Act provisions for security planning.
25

23

See
6 U.S.C. 1137(c)(7), 1167(c)(8), and 1184(c)(8).

24

See
DHS, “Homeland Security Exercise and Evaluation Program (HSEEP)” (April 2013), available at
https://www.fema.gov/media-library-data/20130726-1914-25045-8890/hseep_apr13_.pdf.

25

See
requirements in 6 U.S.C. 1134 (public transportation), 1162 (railroads), and 1181 (OTRBs).

Finally, the 9/11 Act also requires DHS to define the term “security-sensitive material” as it relates to materials transported in commerce that pose “a significant risk to national security . . . due to the potential use of the material in an act of terrorism.”
26

The 9/11 Act states that the term must include specific, identified materials.
27

TSA has previously identified “security-sensitive materials” transported by freight railroad carriers as “Rail Security-Sensitive Materials” (RSSM).
28

As further discussed in section III.A.2 of this NPRM, TSA is proposing materials to be identified as “Transportation Security-Sensitive Materials (TSSM).”

26
6 U.S.C. 1151(13).

27
Materials to be included are Class 7 radioactive materials, Division 1.1, 1.2, or 1.3 explosives, materials poisonous or toxic by inhalation, including Division 2.3 gases and Division 6.1 materials, and select agents or toxins regulated by the Centers for Disease Control and Prevention under 42 CFR part 73.

28

See
49 CFR 1580.3 and 1580.100(b).

C. Rule Organization

Implementing requirements in the 9/11 Act for surface transportation regulations necessitates making other changes to TSA's regulations found in title 49 of the CFR. Some of these changes are technical revisions or additions, such as consolidating definitions used in multiple parts of TSA's regulations into part 1500 and adding cross-references to the new regulatory requirements as relevant for investigations (part 1503) and protection of SSI (part 1520).

The most significant changes are to subchapter D, which TSA proposes to rename “Maritime and Surface Transportation Security.” Subchapter D currently contains requirements related to security threat assessments (STAs) (parts 1570 and 1572) and rail security (1580). TSA is proposing to significantly reorganize and augment parts 1570 and 1580, and add parts 1582 (PTPR) and 1584 (Highway and Motor Carriers).

Many portions of the proposed rule are common to PTPR, freight, and OTRB operations. These are included in 49 CFR part 1570. Eliminating duplication of these requirements across multiple sections of TSA's regulations reduces unintended inconsistencies, both now and over time to the extent there are any amendments made to these regulations in the future. Because of these modifications, other organizational changes are being made to part 1570—including moving definitions that have applicability across multiple parts of TSA's regulations to part 1500 (discussed more fully in part III.A of this NPRM) and consolidating provisions related to security threat assessments into a new subpart D. The STA provisions are being moved but are otherwise unmodified. As a result, the substance of these provisions is not part of this notice and comment rulemaking.

TSA includes proposed requirements adapted to reflect the unique aspects of each mode in mode-specific parts of 49 CFR Chapter XII, Subchapter D—Maritime and Surface Transportation Security. Part 1580 would be revised to focus on freight railroads. Sections in current part 1580 applicable to PTPR systems would be moved to a new part 1582. TSA also proposes creating a new part 1584, which would include the requirements for OTRB.

With the exception of the following, provisions of current 49 CFR part 1580, Rail Transportation Security, applicable to freight railroads would be reorganized without substantive change. TSA proposes to move some provisions to part 1570—this revision would include the security coordinator and reporting requirements (which are being updated and clarified, and extended to include higher-risk buses).
29

Other provisions, such as “chain of custody” provisions for RSSMs, would be reorganized within part 1580 because of this proposed rule. Finally, current Appendix A to part 1580 would be modified to remove outdated references. Table 2 provides a distribution table for changes to current 49 CFR part 1580. To the extent sections are being moved, but not revised, they are not part of this notice and comment rulemaking.

29
These modifications are discussed in section III.C. of this NPRM.

Table 2—49 CFR Part 1580 Distribution Table

Former section
New section(s)

1580.1
1570.1, 1580.1, and 1582.1.

1580.3
1570.3, 1580.3, and 1582.3.

1580.5
1570.9.

1580.100
1500.3, 1580.101.

1580.101
1570.201.

1580.103
1580.203.

1580.105
1570.203.

1580.107
1580.205.

1580.109
1580.5 and 1582.5.

1580.111
1580.207.

1580.200
1582.101.

1580.201
1570.201.

1580.203
1570.203.

III. Proposed Rule

A. Amendments to Part 1500

1. General Terms

Consistent with the proposed rule's organization, TSA includes proposed definitions for terms relevant to several subchapters of TSA regulations, beyond the requirements of subchapter D, in part 1500. Terms relevant to several parts of subchapter D would be added to § 1570.3. Terms uniquely relevant to each mode would be included in the relevant parts (part 1580 (freight), part 1582 (PTPR), and part 1584 (OTRB)).

Many of the proposed definitions are identical, or nearly identical, to definitions codified in current 49 CFR part 1580. Some definitions are taken from the 9/11 Act. Other definitions are derived from existing Federal regulatory programs, particularly programs administered by DOT. A few definitions are based on industry sources. TSA's purpose is to use existing definitions that regulated parties are familiar with to the extent that the definitions are consistent with the 9/11 Act and the purposes of this NPRM. Where no existing definition is appropriate, TSA's subject matter experts developed the definition based upon the generally accepted and known use of terms within each of the modes subject to this proposed regulation. Table 3 provides additional information on the terms that would be added to part 1500.

Table 3—Explanation of Proposed Terms and Definitions

Summary of change
Explanation

Propose modifying definition of “Administrator”
This term is used in proposed sections regarding procedures for requesting alternative measures or challenges to required modifications. The definition is being updated to reflect TSA's transition to a DHS component.

Propose adding a definition for “Authorized representative”
This term is used in the definition of “Employee.” It is intended to ensure that any “authorized representatives” performing security-sensitive functions for an owner/operator receives the required security training, even if they are not considered a direct employee. More information can be found in the discussion of employees required to be trained in preamble section III.E.

Propose adding a definition for “Bus”
This term is used in several other terms defined in this proposed rule. TSA's review of DOT regulations identified several definitions for this term. The definition developed by TSA for the purposes of subchapter D is a composite of DOT's definitions adopted for TSA's purposes. While it is a broad definition on its own, the other terms in which it is used limit its application.

Propose adding a definition of “Bus transit system”
This term is used as part of the scope of what is intended by, and included within, the definition of public transportation. Consistent with the scope of other commuter transit systems, the definition is based upon an explanation of what constitutes “urban rapid transit service” in 49 CFR part 209, Appendix A.

Propose adding a definition for “Commuter bus system”
This term is used as part of the scope of what is intended by, and included within, the definition of public transportation. Consistent with the scope of other commuter transit systems, the definition is based upon the Federal Railroad Administration's (FRA's) explanation of “commuter service” for rail in 49 CFR part 209, and the Federal Motor Carrier Safety Administration's (FMCSA's) definition of “commuter service” in 49 CFR 374.303(g).

As part of reorganization of current 49 CFR part 1580, propose moving definition of “Commuter passenger train service” from 49 CFR 1580.3
This term is used as part of the scope of what is intended by, and included within, the definition of public transportation.

Propose moving definition of “DHS” from 49 CFR 1520.3
This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Propose moving definition of “DOT” from 49 CFR 1520.3
This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Proposed adding definition for “Fixed-route service”

Used within the scope of OTRB owner/operators subject to the proposed regulation (
see
proposed 49 CFR 1570.101 and 1584.1), this term is based on the definition of a fixed-route system found in 49 CFR 37.3.

Propose moving definition of “General railroad system of transportation” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Hazardous Material” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Heavy rail transit” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose adding a definition of “Host railroad”
This term, which is consistent with the definition in 49 CFR 236.1003, is used within the scope of this proposed rule relating to operations by railroad carriers. More information can be found in the preamble discussion in section III.F.1.

Propose moving definition of “Improvised explosive device (IED)” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Intercity passenger train service” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Light rail transit” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose adding a definition of “Motor vehicle”
Used throughout this proposed rule, TSA has determined that there is no consistent definition of “motor vehicle” within federal regulations. TSA has reviewed various DOT regulations and relies primarily on 49 CFR 390.5 for this definition as most applicable to this proposed regulation, choosing a definition that is inclusive with limitations provided in the relevant applicability sections.

Propose adding a definition for “Over-the-Road Bus (OTRB)”
This term, the definition of which is consistent with 6 U.S.C. 1151(4), is used within other definitions and the scope of this proposed rule relating to over-the-road bus owners. More information can be found in the preamble discussion in section III.F.3.

Propose moving definition of “owner/operator” from 49 CFR 1570.3 and modifying to eliminate cross-reference to title 33 of the CFR
Used in other definitions and throughout the proposed rule, the definition of this term is a modification of the current definition of “owner/operator” that affects 49 CFR, subchapter D. The modifications remove outdated references to make it the term appropriate for the broader scope of transportation regulated by TSA.

Propose moving definition of “Passenger car” from 49 CFR 1580.3 and adding “rail” to the term to read, “passenger rail car”
Part of reorganization of current 49 CFR part 1580. TSA is proposing to insert the word “rail” between “passenger” and “car” to avoid any confusion between rail and motor vehicle conveyances.

Propose adding a definition of “Passenger railroad carrier”
Used both in the scope of proposed subpart B of 49 CFR part 1570 (Security Coordinator and Reporting Requirements) and the scope of the training rule (proposed 49 CFR part 1582), this term is also used in the context of host railroad operations. More information can be found in the discussion in III.F.2. The definition is based on the definition for this term found in 49 CFR 239.7.

Propose moving definition of “Passenger train” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Private rail car” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose adding a definition of “Public transportation”
Used within other terms, this definition is based primarily on 49 U.S.C. 5302(14). Where the statute uses a definition that is characterized by what is excluded, TSA's definition focuses on what is included.

Propose adding a definition of “Public transportation agency”

This term is used to define the scope of owner/operators subject to the proposed rule.
See
proposed subpart B to 49 CFR parts 1570 and 1582.
See also
the preamble discussion in section III.F.2 for more information. (The 9/11 Act defines a “public transportation agency” as a publicly owned operator of public transportation eligible to receive Federal assistance under Chapter 53 of Title 49, United States Code.”). TSA reviewed the requirements of that statute in developing this definition. As noted above, the definition of “public transportation” is based on 49 U.S.C. 5302(14).

Propose moving definition of “Rail hazardous materials receiver” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Rail hazardous materials shipper” from 49 CFR 1580.3, with a non-significant amendment
Part of reorganization of current 49 CFR part 1580. As proposed, the definition of “offers or offeror” in 49 CFR 1580.3 would be deleted and a reference to the DOT definition for “person who offers or offeror” would be incorporated into the definition of “rail security-sensitive material.”

Propose moving definition of “Rail secure area” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Rail transit facility” from 49 CFR 1520.3 and 1580.3
This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Propose moving definition of “Rail transit system or `Rail Fixed Guideway System' ” from 49 CFR 1580.3 to proposed 1570.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Railroad carrier” from 49 CFR 1580.3
Part of reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Railroad” from 49 CFR 1580.3 and modifying it to define “Railroad transportation”
Part of reorganization of current 49 CFR part 1580. This proposed rule does not significantly change the definition.

Propose moving definition of “Record” from 49 CFR 1520.3
This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Propose adding definition of “Sensitive Security Information consistent with 49 CFR 1520.3 to 1570.3
This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR parts 1520 and 1570.

Propose moving definition of “State” from 49 CFR 1570.3
This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR parts 1520 and 1570.

Propose adding definition of “Transportation security equipment and systems”

The term is used in the context of the proposed requirement for security-sensitive employees to be trained on use of security equipment and systems.
See
for example, proposed 49 CFR 1580.155(c)(1). TSA's subject matter experts have developed this definition based on their work with the modes in conducting assessments and developing voluntary security action items.

Propose moving definition of “Tourist, scenic, historic, or excursion operation” from 49 CFR 1580.3
Part of the reorganization of current 49 CFR part 1580. This proposed rule does not change the definition.

Propose moving definition of “Transit” from 49 CFR 1580.3 with modifications to reflect broader scope of this proposed rule
Part of the reorganization of current 49 CFR part 1580. TSA proposes modifying this term to reflect the multimodal scope of the proposed training rule and have the term apply across all the modes.

Propose moving definition of “Transportation or transport” from 49 CFR 1580.3 with modifications to reflect broader scope of this proposed rule
Part of the reorganization of current 49 CFR part 1580. TSA proposes modifying this term to reflect the multimodal scope of the proposed training rule and have the term apply across all the modes.

Propose moving definition of “Transportation facility” from 49 CFR 1580.3 with modifications to reflect broader scope of this proposed rule
Part of the reorganization of current 49 CFR part 1580. TSA proposes modifying this term to reflect the multimodal scope of the proposed training rule and have the term apply across all the modes.

Propose adding definition of “Transportation Security-Sensitive Materials (TSSM)”

The definition is included to satisfy 9/11 Act requirements.
See
6 U.S.C. 1151(13). The term is defined in proposed 49 CFR 1570.3. More information can be found in the preamble discussion of the TSSM list in section III.A.2.

Propose moving definition of “TSA” from 49 CFR 1520.3
This term has general applicability to several parts of TSA's regulations beyond the provisions in 49 CFR part 1520.

Propose moving definition of “vulnerability assessment” from 49 CFR 1520.3
This term is being modified to streamline terminology rather than enumerating subcategories within each mode. It is being moved to 49 CFR part 1500 as it has relevance beyond the provisions in part 1520.

2. Transportation Security-Sensitive Materials

The 9/11 Act included a requirement for DHS to define “security-sensitive material.” “Security-sensitive material” is defined as “a material, or group or class of material, in a particular amount and form that the Secretary [of Homeland Security], in consultation with the Secretary of Transportation, determines, through rulemaking with opportunity for public comment, poses a significant risk to national security while being transported in commerce due to the potential use of the material in an act of terrorism.”
30

TSA has met the requirements of the 9/11 Act related to rail through its definition of RSSMs under current 49 CFR part 1580.
31

30
6 U.S.C. 1151(13).

31

See
49 CFR 1580.3 and 1580.100(b).
See also
discussion in 73 FR 72130 at 72134 (Nov. 26, 2008).

In March of 2010, DOT's Pipeline and Hazardous Materials Safety Administration (PHMSA) issued a final rule: “Hazardous Materials: Risk-Based Adjustment of Transportation Security Plan Requirements.”
32

This PHMSA final rule amended PHMSA's security requirements for hazardous material (hazmat) transportation under 49 CFR part 172 of the Hazardous Material Regulations (HMR),
33

applicable to freight railroad carriers, motor carriers, and shippers and receivers of hazmat. In addition to amendments to security planning requirements, the PHMSA final rule provided a revised list of hazardous materials for which a security plan is required. DOT worked closely with TSA to align the proposed lists of materials subject to their security programs with ongoing efforts by TSA. The materials considered included certain explosives, compressed gases and flammable liquids, poisonous gases and materials, corrosive materials, radioactive materials, and chemicals listed by the Chemical Weapons Convention. There were also requests to PHMSA to harmonize the list of materials for which security plans are required with the list of materials designated as high consequence dangerous goods for which enhanced security measures are recommended in the United Nations Model Regulations on the Transport of Dangerous Goods (UN Recommendations). Discussions regarding the materials identified in the PHMSA regulations can be found in the preambles to their relevant rulemakings.
34

32
75 FR 10974 (Mar. 9, 2010). Additional information is included in the preamble to the related NPRM.
See
73 FR 52558 (Sept. 9, 2008).

33
These regulations are also referred to as HM-232.

34

See supra,
n. 32.

TSA proposes to adopt the PHMSA list for purposes of defining TSSM. This approach avoids unnecessary duplication and ensures consistent alignment of the materials meeting this standard in Federal regulations. A discussion regarding the materials in the list can be found in the preamble to PHMSA's final rule.
35

35
75 FR at 10977.

B. Amendments to Part 1503

TSA is proposing minor amendments to part 1503 (Investigative and Enforcement Procedures) as necessary to conform these regulations to changes made by the proposed rule. In § 1503.101(b), the scope of statutory provisions is amended to add authorities in title 6 U.S.C. that are administered by the TSA Administrator—which are relevant to this proposed rule. These are conforming amendments with no cost impact.

C. Amendments to Part 1520

TSA is also proposing to modify part 1520 (Protection of Sensitive Security Information). TSA is required to promulgate regulations governing the protection of information obtained or developed in carrying out security under the authority of ATSA
36

if public disclosure of that information could be detrimental to transportation security. TSA's current SSI regulation, 49 CFR part 1520, establishes certain requirements for the recognition, identification, handling, and dissemination of SSI, including restrictions on disclosure and civil

penalties for violations of those restrictions. DOT has nearly identical SSI authority (49 U.S.C. 40119) and a nearly identical SSI regulation (49 CFR part 15).
37

36

See
49 U.S.C. 114(r).

37
For more information on these regulations,
see
69 FR 28078 (May 18, 2004).

Because TSA is expanding the scope of its regulatory requirements in order to fulfill the mandates of the 9/11 Act, it is necessary to conform the SSI provisions to include these transportation security-related requirements. The proposed amendments are limited to: (1) Eliminating unnecessary terms from part 1520 that are added to part 1500 and (2) replacing the limiting term “rail transportation security requirement” with “surface transportation security requirement.” In some places, such as the definition of “vulnerability assessment” in § 1520.3, TSA is proposing to streamline a lengthy description of types of transportation to simply state “aviation, maritime, or surface transportation.”

The impact of these minor revisions should also be minimal. Under § 1520.7(j), any person who has access to SSI is required to protect it according to the requirements of the regulation. While some of the proposed population that would be affected by this rule has not previously been subject to TSA regulations, most of them have previously received SSI information from TSA, as well as training on the proper handling of SSI, and have procedures in place to ensure the requirements of the regulation are met.
38

38
Publicly available information on proper handling of SSI is available on TSA's Web site at
www.tsa.gov.

TSA's regulations for SSI have a counterpart in DOT regulations under 49 CFR part 15. Any comments received on these proposed amendments will be shared with DOT. As these are parallel rules, assuming there are changes to part 1520 adopted as part of this notice and comment rulemaking, DOT may subsequently make similar changes to part 15. We invite comments on the proposed changes to part 1520, and we will share with DOT any comments received on potential changes to part 15. We also invite comments on this process for making changes to both parts.

D. Amendments to Part 1570

1. Overview of Changes and Structure

TSA is proposing to divide part 1570 into four subparts: (1) Subpart A would cover general requirements applicable to all aspects of subchapter D to chapter XII of title 49; (2) subpart B provides the general framework for security programs; (3) subpart C covers operational requirements; and (4) subpart D would move and consolidate general provisions related to security threat assessments (STAs) which are more specifically addressed in part 1572. As previously discussed, mode—specific requirements are contained in subsequent parts. Because of the significant restructuring of part 1570, the proposed rule text includes the entirety of the revision—not just the parts that would be added because of this rulemaking. This includes terms applicable to the STAs required by part 1572, as well as related STA provisions that TSA proposes moving to new subpart D.

2. Subpart A—General

Terms and Definitions (§ 1570.3)

As previously indicated, TSA is proposing to move several terms from § 1570.3 to § 1500.3 as part of a general effort to streamline TSA's regulations by consolidating terms used in multiple parts. In addition, TSA is proposing to add the terms identified in Table 4 to § 1570.3 as they are used in multiple sections of subchapter D to chapter XII of title 49.

Table 4—Explanation of Proposed Terms and Definitions

Summary of change
Explanation

Propose adding definition of “Contractor”

This term is used in the definition of “employee” for purposes of this subchapter and is based on a definition of contractor used in DOT regulations,
see, e.g.,
49 CFR 655.4.

Propose adding definition for “Employee”

This term is used in several definitions, most notably, the definition of “security-sensitive employee,” which is the term used to define the scope of individuals who must be trained under the proposed rule (
see
discussion in III.E) and the requirements of the training program.
See
proposed definition of “security-sensitive employee” in 49 CFR 1580.3, 1582.3, and 1584.3. It is also used in sections regarding responsibility for compliance (proposed 49 CFR 1570.13), and terms used for “chain of custody” requirements in proposed 49 CFR 1580.3 (currently 49 CFR 1580.107).

Propose adding definition of “Immediate supervisor”
This term is used in the definition of “Employee.” It is intended to ensure that any “immediate supervisors” performing security-sensitive functions for an owner/operator receive the required security training. It is also intended to limit the layers of management that must receive security training to those who have an actual nexus to transportation security. More information can be found in the discussion of employees required to be trained in preamble section III.E.

Propose adding definition of “Security-sensitive employee”
This term is used in provisions of part 1570 as part of the proposed security training requirements. The definition provides a signal to find the appropriate mode-specific definitions in 49 CFR parts 1580, 1582, and 1584.

Propose adding definition of “Security-sensitive job function”
This term is used in provisions of part 1570 as part of the proposed security training requirements. The definition provides a signal to find the appropriate mode-specific definitions in 49 CFR parts 1580, 1582 and 1584.

Security Responsibilities for Employees and Other Persons (§ 1570.7)

In proposed § 1570.7, TSA is seeking to make its regulations regarding the responsibility for compliance consistent for all modes. Under 49 U.S.C. 114(f), TSA is required to enforce security related regulations and requirements and oversee the implementation of security measures for all modes of transportation.
39

As with the similar aviation regulation, the obligation for compliance is not limited to owner/operators specifically referenced under applicability provisions. Any person may be held to have violated these proposed rules, including contractors who provide service to owner/operators and the employees of such contractors. For example, a contractor who is authorized by an owner/operator to provide security training to individuals performing security-sensitive functions on the owner/operator's behalf would be expected to fulfill all of the responsibilities under these three parts with respect to such training. Similarly, contractors would also be subject to inspection for compliance with this proposed rule and enforcement actions when appropriate (
see
following discussion on proposed § 1570.9 for more information on TSA's investigatory and enforcement authority).

39

See
49 U.S.C. 114(f)(7) and (11). A similar provision applicable to aviation employees and other related persons is in 49 CFR 1540.105(a)(1) and (b).

Compliance, Inspection, and Enforcement (§ 1570.9)

TSA is mandated to: (1) Enforce its regulations and requirements; (2) oversee the implementation and ensure the adequacy of security measures; and (3) inspect, maintain, and test security facilities, equipment, and systems for all modes of transportation.
40

This mandate applies even in the absence of regulations stating the authority, but TSA has chosen to include a restatement of its authority in its regulations. The statute specifically requires TSA to—

40

See
49 U.S.C. 114(f).

• Assess threats to transportation;

• Enforce security-related regulations and requirements;

• Inspect, maintain, and test security of facilities, equipment, and systems;

• Ensure the adequacy of security measures for the transportation of cargo;

• Oversee the implementation, and ensure the adequacy, of security measures at airports and other transportation facilities;

• Require background checks for airport security screening personnel, individuals with access to secure areas of airports, and other transportation security personnel; and

• Carry out such other duties, and exercise such other powers, relating to transportation security as the Administrator considers appropriate, to the extent authorized by law.

While current part 1570 includes a provision stating TSA's compliance, inspection, and enforcement authority, it is not as detailed as what TSA has promulgated in more recent regulations.
41

Therefore, TSA is proposing to transfer the text of current § 1580.5 to subpart A as proposed § 1570.9, with minor modifications to reflect the addition of certain bus operations that have previously been unregulated by TSA.
42

41
Compare current § 1570.11 with current § 1580.5. The provision in part 1580 is also consistent with 49 CFR 1542.5, 1544.3. 1546.3, 1548.3, and 1549.3.

42
A more detailed discussion of current § 1580.5, still relevant to the proposed section, can be found in the preamble for current part 1580.
See
71 FR 76852 (Dec. 12, 2006) (NPRM) and 73 FR 72130 (Nov. 26, 2008) (Final Rule).

3. Subpart B—Security Programs

As previously noted, TSA intends to consolidate and avoid duplication of requirements in its regulations by placing all of the security program requirements that are consistent across all modes in subpart B. These include: (1) Submission, review, and approval of the program; (2) procedures for amending the program; (3) the training schedule (including initial and recurrent training, previous training, relation to other training, and failure to train); and (4) recordkeeping. Proposed requirements for which employees must be trained and content of the program are found in the proposed revisions to part 1580 (freight rail) and new parts 1582 (PTPR) and 1584 (OTRB).

Program Content (§ 1570.103)

Under the statutory requirements, TSA must issue regulations mandating security training for owner/operators of public transportation agencies, railroads, and OTRBs.
43

In proposing these regulations, TSA assumes that Congress intended the requirement to provide for the use of “existing procedures, protocols, and standards to satisfy the regulatory requirements” for vulnerability assessments and security plans apply equally to security training.
44

Proposed § 1570.3 implements these requirements by stating that each owner/operator required to have a security program under proposed parts 1580, 1582, and 1584 must address all of the identified requirements. In addition, the proposed section implements the requirement to allow for use of existing programs by allowing the owner/operators to include these existing programs as an appendix. The owner/operators would be required to cross-reference the relevant portions of the appendix or TSA could assume it is all part of the security program and enforce it as such.

43

See
6 U.S.C. 1137, 1167, and 1184.

44

See
6 U.S.C. 1162(j) and 1181(i) (use of existing procedures, protocols, and standards to satisfy regulatory requirements).

To minimize costs of compliance, TSA may identify pre-existing or widely-available training programs that meet some or all of this proposed rule's requirements. If owner/operators decide to use a program already determined by TSA to meet the proposed rules requirements, the owner/operator must notify TSA of the program name, presenter, modifications made to the training material since the program was approved by TSA, and the last date of modification. If TSA has already determined the program meets some or all of the requirements for the proposed rule and is applicable to the owner/operator's operations, it would be unnecessary for the owner/operator to submit a copy of the program to TSA for approval or include it in the appendix.

Responsibility for Determinations (§ 1570.105)

As part of this rulemaking, TSA is proposing to apply the requirements to the highest-risk operations within the three modes identified by the 9/11 Act. As part of the surface security requirements in the 9/11 Act, TSA is required to develop risk tiers.
45

The criteria used for determining the highest-risk tier for each mode is discussed in more detail in section III.F of this NPRM. The text of proposed § 1570.105(a) informs owner/operators that TSA has determined the applicability criteria, but it is the owner/operator's responsibility to determine whether their operations meet the criteria.

45
For public transportation, 6 U.S.C. 1137(e) states that any public transportation agency that receives a grant under 6 U.S.C. 1135 shall be required to develop and implement a training program pursuant to this section. The grant program implemented under sec. 1135 relies on high-risk determinations.
See also
6 U.S.C. 1162(a) and (h) and 1181(a) and (h) (Secretary shall identify risk tiers for freight railroads and OTRB and apply regulatory requirements to those at the highest-risk).

The proposed rule would require owner/operators to notify TSA within 30 days of the effective date of the final rule if they meet the criteria for applicability. In addition to publishing the regulatory requirements in the
Federal Register
, TSA will work with

the relevant associations for each of the modes to ensure their memberships are apprised of the requirements. TSA will identify the form and manner of notification in the final rule consistent with cost-effective methodologies at that time. Because the proposed rule would require owner/operators to determine whether the criteria apply, TSA could bring an enforcement action against an owner/operator that meets the criteria, but has failed to comply with the requirements.

The obligation to self-determine applicability also applies to new and existing operations (those commencing after publication of the final rule). They would be required to notify TSA no later than 90 calendar days before commencing operations or implementing modifications that would put them within the applicability of the requirements.

Recognition of Previous Training (§ 1570.107)

As previously noted, TSA is required to allow use of existing programs to satisfy the security program requirements implemented as a result of 9/11 Act's provisions.
46

Under proposed § 1570.107, an owner/operator could rely on previous training that occurred within the identified periods for initial or recurrent training. In order to use previous training, the owner/operator would need to validate the training provided satisfies the requirements of this proposed rule—including records of training, curriculum, and appropriateness for the employee and owner/operator's operations.

46

See
6 U.S.C. 1162(j) and 1181(i) (use of existing procedures, protocols, and standards to satisfy regulatory requirements).

Security Training Program Submission, Review, and Approval (§ 1570.109)

The 9/11 Act's requirements include specific deadlines for submission of programs and TSA's review.
47

Proposed § 1570.109 identifies the required deadlines for submitting security training programs and TSA approval.

47

See
6 U.S.C. 1137(d)(1) and (2), 1167(d)(1) and (2), and 1184(d)(1) and (2) (must submit program 90 days from effective date, TSA must approve within 60 days of receipt or notify of need for revisions).

In general, not later than 90 days from the effective date of the final rule, owner/operators would be required to submit programs to TSA in a form and manner prescribed by TSA. Owner/operators commencing new businesses or operations that would make them subject to this proposed rule would be required to submit their security training programs to TSA no less than 60 days before commencing operations. In the final rule, TSA will provide details for submission (encouraging use of a secure Web site or other electronic submissions). TSA assumes submission would likely be by email or mail service, but requests comments on preferences. Consistent with requirements of the 9/11 Act, TSA would review the programs within 60 days of receipt and either approve them or specify changes that would be needed for approval.
48

If TSA requires changes, the owner/operator would be required to submit a modified training program that meets TSA's specifications within 30 days of notification by TSA of the needed changes. The section includes the availability to request reconsideration of any TSA-required modifications. TSA provides an analysis of burden and estimated costs associated with this information collection in section V.A. of this preamble and the draft OMB 83-I Supporting Statement for its information collection request, which is available in the docket for this rulemaking.

48

See
6 U.S.C. 1137(d)(1) and (2), 1167(d)(1) and (2), and 1184(d)(1) and (2) (TSA must approve within 60 days of receipt or notify of need for revisions).

Initial training (§ 1570.111(a))

Consistent with the 9/11 Act's requirements, TSA proposes that existing employees must be trained within one year of TSA's approval of the program.
49

As further required by the 9/11 Act, initial training for new employees or those transitioning to a covered job function (as identified in proposed Appendix B to parts 1580 (freight rail), 1582 (PTPR), and 1584 (OTRB), must occur within the first 60 days of the date an employee begins to perform a security-sensitive function.
50

49

See
6 U.S.C. 1137(d)(3), 1167(d)(3), and 1184(d)(3) (no later than 1 year after approval of security training program, owner/operator must have trained all covered employees).

50
This is a mandatory requirement for railroads and OTRB companies.
See
6 U.S.C. 1167(d)(3) and 1184(d)(3) (New employees must be trained within first 60 days of employment).

During the consultation process at the initial stages of this rulemaking, some stakeholders objected to a one-year deadline for completion of initial training. While the 9/11 Act does not provide for flexibility on the initial training schedule, TSA has attempted to address these concerns through provisions on recurrent and previous training (as discussed in section III.D.3 of this NPRM). In addition, TSA is proposing to include a section allowing regulated parties to request an extension if they cannot meet the required training schedule.
51

51

See
§ 1570.115(c) of this proposed rule.

Proposed § 1570.111(a)(3) is included to address the situation of non-permanent employees. TSA recognizes that some individuals may be intermittently employed as contractors or representatives to perform security-sensitive functions; they might not perform these functions for 60 or more consecutive calendar days. For example, an employee may function as a maintenance worker for a 30-day period and then, at a later date, perform that function for another period of 30 days or longer. This may also include individuals who are employed by multiple owner/operators, such as multiple-employer drivers.
52

The proposed rule would require that such individuals receive training within 60 calendar days after employment that meets the definition of a security-sensitive employee.
53

52
Such as individuals meeting the definition of “multiple-employer driver” in the Federal Motor Carrier Safety Administration (FMCSA) regulations at 49 CFR 390.5.

53

See
discussion of “security-sensitive employees” in section III.E. of this NPRM.

In general, this means that an employee would need to be trained within 60 days of beginning permanent employment in a position that may perform a security-sensitive function, whether full or part-time. If, however, an individual is employed on an intermittent or non-permanent basis, such as a contractor who is employed in a position that may perform a security-sensitive function for short durations, then the training would need to take place before the individual's total time of employment by the owner/operator equals sixty calendar days within a consecutive twelve-month period. TSA recognizes that some owner/operators may address this requirement by requiring training for all regular contractors or other individuals employed for short, but regular durations. TSA requests comments on other options for determining accumulated days of employment and for ensuring owner/operators do not engage in employment practices or use of contractors to avoid the requirements of this proposed rule.

As previously noted, the proposed rule includes a provision regarding use of previous training (
see
discussion on proposed § 1570.107). TSA is aware of stakeholder concerns regarding the schedule for initial training, but TSA is also aware that many of the affected owner/operators have already implemented initial employee security training—frequently through the use of

grant funds provided by DHS for that purpose.
54

TSA invites comments on these requirements as they appear in the proposed rule.

54
Congressional appropriations to FTA fund course offerings to public transportation agencies that meet some of the requirements in this proposed rule. Similarly, appropriations through DHS fund the provision of courses in prevention and response that are available to PTPR agencies. Further, FTA and FEMA courses that may meet portions of this proposed rule are listed among the approved vendors and programs for use of TSGP awards.

In meeting the initial training schedule, TSA expects that many owner/operators will rely on the provisions in proposed § 1570.107, which provides standards for accepting previous training. Under this section of the proposed rule, TSA would allow “training credit” to be given for employees who received training that satisfies the requirements of the proposed rule within one year before its effective date.

This may include emergency preparedness plans that railroads connected with the operation of passenger trains must implement to address such subjects as communication, employee training and qualification, joint operations, tunnel safety, liaison with emergency responders, on-board emergency equipment, and passenger safety information, as well as policies that transit agencies implement to ensure safety promotion to support the execution of the Transit Agency Safety Plan by all employees, agents, and contractors for the rail fixed guideway public transportation system.
55

See
discussion of these training programs in section III.I. of this NPRM. Similarly, public transportation agencies may have been providing training through funds granted under the TSGP.

55

Id.

The recordkeeping provisions of the proposed rule require an owner/operator to provide current and former employees with documentation upon request of any training completed to meet the requirements of this rule.
56

Options for compliance with this requirement could include providing employees with certificates to validate completed training.

56

See
§ 1570.121 of the proposed rule.

This proposed requirement anticipates situations where an employee may have received training from a previous owner/operator, as well as industry practices where employees may work for multiple owner/operators (such as commercial drivers operating OTRBs). If an owner/operator can validate that an employee has received the required training within the specified timeframe, the training would not need to be repeated. Because it would be the obligation of the current owner/operator to ensure that all training requirements are met, that owner/operator would be responsible for ensuring that any previous training courses satisfy the proposed rule's requirements and documenting that the training was received within the required timeframe.

Finally, there may be situations where “dual-hatted” or other specific-function employees are required to receive security training from other sources as part of their jobs, such as railroad police officers employed by the owner/operator. As indicated above, it is the obligation of the owner/operator to ensure and document the training, including training received under these circumstances.

Recurrent Training (§ 1570.111(b))

Recurrent training is essential for maintaining a high level of security awareness. The 9/11 Act recognizes this by requiring routine and ongoing training for public transportation employees.
57

Congress has left it to the discretion of TSA to determine the appropriate schedule for recurrent training and to require a similar schedule for railroad and OTRB employees.
58

57

See
6 U.S.C. 1137(f).

58

See
6 U.S.C. 1137(c)(11), 1167(c)(12), and 1184(c)(12).

TSA believes annual recurrent training is essential for transportation employees to maintain a high level of awareness, competency, and currency with overall changes in security posture within the surface transportation environment. TSA's decision is consistent with several key considerations, including: (1) Other TSA regulations requiring training, as well as similar training required for TSA employees; (2) the difficulty of learning, developing, and demonstrating security awareness in the dynamic aspects of the surface transportation environment, and (3) industry recommended guidelines for security awareness training.

TSA requires annual training for aviation workers. For example, regulations applicable to Ground Security Coordinators used by aircraft operators specifically require annual training.
59

Other aviation workers are required to receive annual recurrent training as part of the approved security program (including aircraft operators, indirect air carriers, air cargo, etc.).
60

59

See
49 CFR 1544.233.

60
The relevant security program requirements are under 49 CFR 1544.233, 1544.235, 1544.407, 1548.5, and 1549.103.

TSA's decision to require annual training is supported by the Difficulty-Importance-Frequency (DIF) model
61

that TSA uses for determining training requirements for its own employees.
62

The DIF model uses three design criteria: Difficulty, importance, and frequency.

61
Bill Melton & J. Bahlis, “ADVISOR Enterprise Difficulty-Importance-Frequency (DIF) Model Fact Sheet”, BNH Expert Software Inc. (February 23, 2011), available at
http://www.bnhexpertsoft.com/english/products/advent/ADVISOR_DIF_Model.pdf.
DIF is a standard instructional design tool used by a variety of users including the Department of Defense (DOD), the Department of Energy (DOE), and private sector education and healthcare providers, to determine training priority and frequency of training.

62
The proposed schedule is consistent with TSA's security awareness training for its own employees—including annual training on operational security (OPSEC), responding to active shooter incidents, and social engineering that could undermine security of information systems.

TSA's subject matter experts responsible for TSA-related training determined that measuring the proposed security training program against these standards supports annual training as: (1) The difficulty of learning surface transportation security awareness related information is at the medium/moderately difficult range because it requires decision making when applying what one has learned; (2) the importance of conducting this security training is at the high/very important range because the cost of failure is high and would cause damage and losses in the event of an attack; and (3) the frequency of how often the task would be performed is within medium range.

TSA's decision is also supported by the American Public Transportation Association (APTA) and their recommendations for security training: Security Awareness Training for Transit Employees.
63

Developed in collaboration and consultation with TSA and transportation industry stakeholders, the recommended practice provides minimum guidelines for security awareness training for all transit employees to strengthen transit system security. APTA “recommends that all transit employees be refreshed on transit security awareness objectives annually, in an abbreviated method at least . . . to reflect advancements or modifications to criminal and terrorist activities and reinforce the security awareness training that employees received initially.”

63
APTA Security Risk Management Working Group., “Security Awareness Training for Transit Employees” (March 2012), APTA-SS-SRM-RP-005-12.

TSA does not find it necessary to include the “abbreviated method” option used by APTA as part of the proposed rule for two reasons. First, the

First Observer
TM
program, discussed more fully in section III.J. of this NPRM, will meet most of the training requirements in approximately one hour. Having reviewed a wide variety of programs that could be used to meet elements of the 9/11 Act's requirements, TSA is not aware of any other existing material that could meet all of the proposed requirements in such an abbreviated period.
64

To the extent owner/operators intend to continue to use their existing training program to meet the regulatory requirements, they may want to consider using First Observer
TM
as an abbreviated form of recurrent training.

64
As part of the 2013 Notice, TSA included a matrix in the docket of training programs that meet elements of the 9/11 Act's requirements. The matrix is available in the docket for the 2013 Notice at:
https://www.regulations.gov/
(search for ”TSA-2013-0005-0084”). Of the 20 programs listed, none of them addressed all of the 9/11 Act requirements.

Second, owner/operators could request to use some other type of abbreviated security training as an alternative measure for compliance. Owner/operators may request to use alternative measures as part of the interactive and iterative process TSA intends to use for approval and review of required security programs, as detailed in proposed 49 CFR 1570.117. Under this proposed section, the owner/operator must establish that the alternative is in the best interest of the public and transportation security. When applied to recurrent training, TSA may require validation that the expected baseline of security awareness is reached and maintained with the abbreviated program. For example, the owner/operator may propose abbreviated training for employees who can pass a pre-test.

TSA is aware that an annual recurrent training requirement could present challenges for owner/operators who must also meet other regulatory training requirements. For example, FRA requires a two-year recurrent training schedule for the emergency preparedness training required under 49 CFR part 239 (emergency response and evacuation for rail passengers). The security training required by PHMSA under 49 CFR part 172 (securing transportation of hazardous materials) is on a three-year recurrent training cycle. As TSA does not control these training schedules, we cannot harmonize all of them through this rulemaking. To the extent, however, that owner/operators must comply with these other training requirements, they may be able to use them as part of their program to meet the meet recurrent training requirements. TSA is interested in comments regarding options for harmonizing training schedules and for adding efficiencies with other relevant regulatory requirements.

While TSA is proposing annual recurrent training, a three-year recurrent cycle is included as a programmatic alternative. The results of the cost analysis for this alternative can be found in chapter III section K of the Regulatory Impact Analysis (RIA) for this rulemaking, which is included in the public docket.

Amendments to the Security Program (§§ 1570.113 and 1570.115)

Allowing owner/operators to revise or amend their programs, as proposed in § 1570.113, is a subset of addressing the 9/11 Act's requirements for implementation and submission or programs.
65

It is also consistent with TSA's statutory authority to allow exemptions from regulatory requirements.
66

Proposed § 1570.113 includes procedures allowing an owner/operator to submit a request to TSA to amend its program and the standard for TSA's approval of that request. The proposed section identifies appropriate reasons for amending programs, such as changes to an operating environment that could include new equipment or changes in station construction. If the operating environment changes, it is reasonable to expect that some aspects of the security training program would also need to be revised. TSA may approve an amendment if it is in the interest of public and transportation security and meets the required security standards. TSA could ask for additional information or time in order to makes its determination.

65

See
6 U.S.C. 1137(d) (public transportation), 1167(d) (railroads), and 1184(d) (OTRB).

66

See
49 U.S.C. 114(q) (Under Secretary may grant exemptions from regulatory requirements).

Similarly, TSA may need to require amendments in the interest of the public and transportation security. The 9/11 Act specifically provides that TSA must update the requirements, as appropriate, “to reflect new or changing security threats” and owner/operators shall change their programs and retrain employees as necessary within a reasonable time.
67

As indicated in proposed § 1570.115, TSA could require owner/operators to revise their training based on emerging threats or methods for addressing emerging threats. For example, the curriculum requirements identified in the 9/11 Act do not address training to respond to active shooter incidents. Following several active shooter incidents, including one that resulted in the death of a Transportation Security Officer in Los Angeles, Congress prioritized the need for this type of training.
68

As with other requirements imposed by TSA, the owner/operator could request a petition for reconsideration of TSA-required amendments.

67

See
6 U.S.C. 1137(d)(4) and 1167(d)(4) and 1184(d)(4).

68

See
Gerardo Hernandez Airport Security Act of 2015, Public Law 114-50, 159 Stat. 490 (Sept. 24, 2015).

Alternative Measures (§ 1570.117)

The proposed rule includes procedures allowing for an owner/operator to submit a request to use alternative measures to satisfy all of some of the requirements of subchapter D and the standard for TSA to approve such a request. For example, the owner/operator could request to extend the time periods for submitting its training program or for training all of its security-sensitive employees. In reviewing such a request, TSA would expect the owner/operator to demonstrate good cause for the extension. Under this provision, an owner/operator could request a waiver from some or all of the regulatory requirements. TSA could grant such a request under the authority 49 U.S.C. 114(q), which provides the TSA Administrator with authority to consider and grant requests from an owner/operator for a waiver from all or some of the regulatory requirements. For example, a freight railroad may meet the criteria for applicability, but the operations that trigger applicability may be a de minimis part of its overall business operations. In such a situation, the owner/operator might consider requesting either a complete waiver or an alternative that limits the requirements to a more discrete part of its business. Proposed § 1570.117 would include the procedures for requesting such a waiver, procedures for requesting the use of alternative measures, and identification of the types of information TSA would need in order to make a decision to grant such requests. In general, TSA would need to consider factors, such as risk associated with the type of operation, any relevant threat information, and any other factors relevant to potential risk to the public and transportation security.

Petitions for Reconsideration (§ 1570.119)

Proposed § 1570.119 describes the review and petition process for TSA's reconsideration when it denies a request for amendment, waiver, or alternative measures—as well as a TSA requirement to modify or amend a

program. If an owner/operator challenges the decision, the owner/operator would be required to submit a written petition for reconsideration within the time frame identified in the applicable section.
69

The petition would need to include a statement, with supporting documentation, explaining why the owner/operator believes the reason for the denial or for the amendment, as applicable, is incorrect. If the owner/operator requested the amendment, the results of the reconsideration could be confirmation of TSA's previous denial or approval of the proposed amendment. If the issue involves a TSA required amendment, the results of the reconsideration could be withdrawal, affirmation, or modification of the amendment. TSA would consider whether a disposition pursuant to proposed 49 CFR 1570.119 would constitute a final agency action for purposes of review under 49 U.S.C. 46110.

69
The proposed rule would require petitions for reconsideration to be submitted no later than 30 days of a TSA requirement to modify under § 1570.109, denial of an owner/operator-requested amendment under § 1570.111, or denial of a request for waiver or alternative measures under § 1570.117; submission would be required within 15 days for a TSA-required amendment under § 1570.113.

Recordkeeping Requirements (§ 1570.121)

TSA proposes that owner/operators create and maintain lists of their security-sensitive employees and when they received training that meets the requirements of the proposed rule. Specifically, records would need to include each trained employee's name, job title or function, date of hiring, and date and course information on the most recent security training that each employee received. Records for individual employees would need to reflect the training courses completed and date of completion. Training records for each employee of initial and recurrent training would need to be maintained by owner/operators for no less than five years from the date of the training and available at any location(s) specified in the security training program approved by TSA.

The proposed rule provides flexibility to owner/operators to decide whether to maintain the records in electronic format provided that (1) any electronic records system used is designed to prevent tampering, loss of data, or corruption of records, and (2) paper copies of records, and any amendments to those records, would be made available to TSA upon request for inspection or copying. Whether the records are kept in electronic or other form, the employee must be provided with proof of training upon request, at any time during the five-year recordkeeping period without regard to the requestor's current status as an employee of that entity. As discussed above in “Initial training (§ 1570.111(a)),” owner/operators may meet this requirement to provide proof of training by providing a certificate or other similar documentation to the employee upon completion of training. In order for TSA to allow any owner/operator to rely upon previous security training to satisfy the requirements of this proposed rule, it is critical that employees be able to validate whether they received previous training.

TSA assumes training records are unlikely to include SSI, but nonetheless provides a reminder in the proposed section that any SSI maintained as a result of these recordkeeping requirements must be maintained consistent with the standards in 49 CFR part 1520. For example, an owner/operator may decide to keep a copy of the content of the training program with the employee files (which is not required by the proposed rule), if the curriculum contains SSI information, any file it is in would need to be stored as required by the SSI regulations. Owner/operators needing additional information about appropriately maintaining SSI may contact TSA for assistance and/or find information on TSA's Web site.
70

70

See https://www.tsa.gov/for-industry/sensitive-security-information.

4. Subpart C—Operations

Under current regulations (49 CFR part 1580), TSA requires freight and passenger railroad carriers, rail transit systems, rail hazardous materials shippers, and certain rail hazardous materials receivers to appoint “rail security coordinators”
71

(RSCs) and report significant security concerns to TSA.
72

The RSC, serve as the security liaisons to TSA, providing a single point of contact for receiving communications and inquiries from TSA concerning threat information or security procedures, and coordinating responses with appropriate law enforcement and emergency response agencies. The information reported to TSA provides information from the frontline of rail transportation that can be used to identify developing threats based on consolidated reporting and trend analysis. Because of the benefits of this requirement to transportation security, TSA is proposing to extend these requirements to the modes of transportation covered by this proposed rule that are not currently subject to the requirements of 49 CFR part 1580.

71

See
49 CFR 1580.101 and 1580.201.

72

See
49 CFR 1580. 105 and 1580.203.

Security Coordinator Requirements (§ 1570.201)

As previously noted, TSA currently requires security coordinators for rail operations including freight, passenger, and public transportation. In addition to mandating security coordinators for railroads, the 9/11 Act also requires security coordinators for OTRB companies.
73

Consistent with this mandate, TSA proposes to extend the requirement to appoint a primary and at least one alternate security coordinator for OTRB companies and the bus operations of PTPR owner/operators (with a limited impact as most public transportation bus agencies are part of a larger system that is required to have a security coordinator under current 49 CFR part 1580). This would be accomplished by moving the provision from part 1580 to subpart C of the proposed rule and eliminating rail-specific terms from the text.

73

See
6 U.S.C. 1162(e)(1)(A) (“Identification of a security coordinator having authority—(i) to implement security actions under the plan; (ii) to coordinate security improvements; (iii) to receive immediate communications from appropriate Federal officials regarding railroad security”).

Security coordinators are a vital part of transportation security, providing TSA and other government agencies with an identified point of contact with access to company leadership and knowledge of the owner/operators operations, in the event it is necessary to convey extremely time-sensitive information about threats or security procedures to an owner/operator, particularly in situations requiring frequent information updates. The security coordinator and alternate provide TSA with a contact in a position to understand security problems; immediately raise issues with, or transmit information to, corporate or system leadership; and recognize when emergency response action is appropriate. The individuals must be accessible to TSA 24 hours per day, 7 days per week.

The proposed rule does not change the expectation that the security coordinator and alternate be appointed at the headquarters level. This proposed rule does not require the security coordinator or alternate to be a dedicated position staffed by an individual who has no other primary or additional duties. This proposed rule, however, does require that the owner/operator have a designated individual

that TSA may reach at all times. The proposed rule would require the following information for both the security coordinator and alternate: Name, title, telephone number(s), and email address. Any change in this information would have to be provided to TSA within seven days of the change taking effect.

As previously noted, this is not a new requirement for owner/operators of railroads, including the rail transit operations of PTPR owner/operators. If an owner/operator subject to this proposed rule has provided the required information for primary and alternate RSCs to TSA in the past, it would not have to take further action to meet the requirement.
74

This is the case for passenger rail carriers, freight railroad carriers, and rail transit systems operated by public transportation agencies.

74
The requirement to inform TSA of any changes is not modified by this proposed rulemaking. Therefore, those currently covered by the security coordinator and reporting requirements under current 49 CFR part 1580 must report information regarding changes to the names, titles, telephone numbers, and email addresses of the RSCs and alternate RSCs to TSA within seven calendar days of the change taking effect.

Extension and Modification of Requirement To Report Security Concerns (§ 1570.203)

TSA is proposing to make two changes to its existing requirements in part 1580 to report security concerns to TSA.
75

As with the security coordinator requirement, TSA proposes to move and consolidate the requirement into proposed § 1570.203 and extend it to bus operations.
76

75

See
current 49 CFR 1580.105 and 1580.203.

76
This extension is within TSA's discretion to require other actions or procedures determined to be appropriate to address the security of public transportation and OTRB operations.
See
6 U.S.C. 1134(c)(2)(I) and 1181(e)(1)(H).

TSA is also proposing to modify the security concerns to be reported to address a need for clarification and align with other relevant standards. Since publication of 49 CFR part 1580, some stakeholders have asked TSA for clarification of the events they are required to report pursuant to 49 CFR 1580.105 and 1580.203. Additionally, in December 2012, the U.S. Government Accountability Office (GAO) published a report on passenger rail security.
77

In the report, GAO stated that TSA has inconsistently overseen and enforced its rail security incident reporting requirement because the agency does not have guidance published, leading to considerable variation in the types and number of incidents reported. The GAO recommended that the agency develop guidance on the types of incidents that should be reported and this guidance should be disseminated to TSA inspectors and regulated entities, including rail and transit agencies. Pending this rulemaking, TSA provided information to the railroads and transit agencies subject to the requirements of part 1580 to provide more examples about the types of incidents that should be reported.

77

See
GAO, “Passenger Rail Security, Consistent Incident Reporting and Analysis Needed to Achieve Program Objectives,” GAO-13-20 (December 2012).

TSA is also modifying the list of reportable significant security concerns to be more consistent with the Nationwide Suspicious Activity Reporting (SAR) Initiative (NSI). The NSI is a partnership between Federal, State, local, tribal, and territorial law enforcement that “establishes a national capacity for gathering, documenting, processing, analyzing and sharing SAR information . . . in a manner that rigorously protects the privacy and civil liberties of Americans.”
78

The NSI defines “suspicious activity” as “observed behavior reasonably indicative of pre-operational planning associated with terrorism or other criminal activity.”
79

78

See
Nationwide SAR Initiative (NSI), “About the NSI” (accessed Nov. 3, 2016), available at
http://nsi.ncirc.gov/about_nsi.aspx.

79

Id.

The NSI implements a standardized, integrated approach to gathering, documenting, processing, analyzing, and sharing information about suspicious activity that is potentially terrorism-related. In applying this approach, standards have been developed, setting criteria for the types of activities that warrant reporting as suspicious and potentially terrorism-related. These criteria recognize the capability of law enforcement and security professionals to apply their experience and expertise to identify significant security concerns by focusing on the nature of the incidents and the context in which they occur. The standardized approach among law enforcement officers and security officials with surface transportation entities produces more informative reports that can more effectively focus investigative efforts and intelligence analysis for potential trends and indicators of terrorism-related activity.

Thus, TSA intends to ensure clarity by incorporating the examples previously provided to industry and consistency by aligning its regulations with the concepts of the NSI. The proposed list of reportable incidents can be found in proposed Appendix A to part 1570 and includes not only a list of incidents, but descriptions and examples to assist regulated parties in making a determination of whether an incident fits within the reporting requirements.

Finally, TSA is proposing to modify the schedule for reporting incidents. Currently the regulation requires immediate reporting to TSA. If, however, there is an immediate threat, the first priority is to notify and work with first responders. Therefore, TSA is proposing to remove the necessity for immediacy and, instead, require notification within 24 hours of the incident (
see
proposed 49 CFR 1570.203(a)). This will enable TSA to obtain timely information without undermining the ability of the owner/operator to appropriately handle a situation requiring their full attention.

Examples for Reporting Information (§ 1570.203(b))

As previously noted, TSA has almost a decade of experience with incidents reported by railroads under current 49 CFR part 1580. Based on this experience, TSA recognizes that its ability to analyze the data and improve the quality of information disseminated back to its stakeholders is proportional to the quality of information it receives. Proposed § 1570.203(b) is consistent with the previous reporting requirements, which reflected the need for detailed and verified information from individual owner/operators to enhance TSA's ability to provide timely and useful information products to all of the relevant stakeholders. While not included in the rule text, Table 5 is being provided to assist security coordinators and other responsible officials to understand TSA's expectations for the types of information that are needed in order to meet the standards of § 1570.203(b).

Table 5—Examples of Reporting Information Required by Proposed § 1570.203(c)

Reporting requirements in proposed § 1570.203(
c
)

Examples

(1) The name of the reporting individual and contact information, including a telephone number or e-mail address

• Company Representative: Joe BLOGGS.
• Company: ABC Rail Road Company.
• Address: XXXXX, XX (Street), XXXXX (City), XX (State), XXXXX (ZIP).

• Phone: (111) 123-1234.

• POC Email:
Reporting.Official@ABCRR.com.

(2) The affected freight or passenger train, transit vehicle, motor vehicle, station, terminal, rail hazardous materials facility, or other facility or infrastructure, including identifying information and current location

• Locomotive: ABCRR, Reporting Marks.
• Locomotive Number 1234.
• Rail Car: ABCRR Railcar Number XXXX 001234.
• Train: ABCRR Train Number XXX of XX, etc.
• Facility: ABCRR (Rail Yard, Subway Station, Passenger Station, Storage Yard, Repair Facility, etc.) and facility physical address.

• Right of Way: Mile Post Marker, Sub-division, and physical address (as much as known).

(3) Scheduled origination and termination locations for the affected freight or passenger train, transit vehicle, or motor vehicle, including departure and designation city and route

• ABCRR, Northern Corridor Express-Boston to New York, XYZ Line, via X, Y and Z Cities. Train Number XXX of XX is currently located at: MP 123.12, XXX Sub-division, XXXX (City), XX (State).
• Transit Vehicle: ABCRR LRV Number XXXXX etc. Route: XXX North Corridor. Is currently located at XXXX Line Section or XXX Station, Street, City, State, ZIP.

(4) Description of the threat, incident, or activity, including who has been notified and what action has been taken

• At XXXX hours, January 01, 2020.
• ABCRR Police Sergeant, Joe BLOGGS, badge number XXXX, ABCRR Police Department (ABCPD) reported the following: At WWWW hours, January 01, 2020, a suspicious person (described as a white male, approximately 6′0″ tall, 190 lbs., blonde hair, approximately 35 to 40 years of age, wearing a long black knee-length coat, blue jeans, red sneakers, and a XXXX ball club baseball hat) was detected adjacent to the ticket vending machine at the street level entrance to the XXst Street and YYYYY Avenue, Station, XXXX (City), XX (State). The person was deemed suspicious because although the temperature at the time was 85 degrees, he was wearing a knee-length heavy black coat. The individual was sweating and exhibited nervousness when security officials were present (the individual looked away every time a security official appeared, so as to not reveal his face). The individual had a black “Traveler,” “Expandable” suitcase with him (estimated measurements: 36″ W X 24″H X 12″ D) with a red piece of ribbon tied to the handle. At WWW5 hours, the individual rapidly departed the area when a security official began to approach him, leaving the black suitcase behind. A review of the Closed-circuit television (CCTV) surveillance system determined the individual had arrived at the station at VV30 hours in a Red, 4-door, Land Rover, VA License Plate XX123XXXX, which was parked adjacent to the XXXXX. Closed-circuit television revealed the vehicle was being driven by a white female with shoulder length blonde hair, approximately 35 years of age. A check of the VA DOT License registry revealed the vehicle is registered to Joe DOE, DOB: XX/XX/XXXX, POB: XXXXX (City), XX (State) and Jane (NEE: SMITH) DOE, DOB: XX/XX/XXXX, POB: XXXXX (City), XX (State) of 1234 West Disobedience Street, Anytown, VA 202XX, Phone Number: (XXX) XXX-XXXX. A check of the VA driver's license registry revealed similar/matching descriptions of Joe and Jane DOE to those persons identified during the incident. At ZZZZ hours, a XXXX City Police Explosive Ordnance Demolition (EOD) team conducted an examination of the black suitcase with x-ray equipment and determined the suitcase contained an unknown device comprised of wiring and circuitry. Explosive Ordinance Disposal (EOD) disrupted the suitcase, which yielded negative secondary results. EOD's examination of the suitcase's contents revealed limited amounts of women's clothing and what appeared to be the inner workings of a radio. At ZZZ1 hours, the scene was cleared by XXXX City Police EOD Sergeant Jeff BOMBGARTEN, badge number XXXX who secured the suitcase and its contents and transported them away from the facility.

(5) The names and other available biographical data, and/or descriptions (including vehicle or license plate information) of individuals or vehicles known or suspected to be involved in the threat, incident, or activity

• Witness: Joe SMITH, DOB: XX/XX/XXXX, POB: XXXX City, XX State. Address: XXXXX, XX Street, XXXX City, XX State, Phone Number (XXX) XXX-XXXX, ABCRR, XXXX (Address), (XXX) XXX-XXXX.
• Security: Fred ARRESTER, Sergeant, XXXX (City) Police Department, Badge # XXXX, Phone Number: (XXX) XXX-XXXX.

• Suspected Associate: Mrs. Jane DOE.

• DOB: XX/XX/XXXX, POB: XXXX City, XX State. Address: XXXXX, XX (Street), XXXX (City), XX (State), Phone Number (XXX) XXX-XXXX, ABCRR, XXXX (Address), (XXX) XXX-XXXX.

(6) The source of any threat information
• Jane DOE, DOB: XX/XX/XXXX, POB: XXXX (City), XX (State). Address: XXXXX, XX (Street), XXXX (City), XX (State), Phone Number (XXX) XXX-XXXX, ABCRR, XXXX (Address), (XXX) XXX-XXXX.

5. Subpart D—Security Threat Assessments

As previously noted, TSA is including the full text of revised part 1570 as it would look with the proposed changes—including three sections related to STAs generally unaffected by this rulemaking. As part of this rulemaking, TSA would move all sections of current part 1570 limited to STAs to a new subpart D, to consist of §§ 1570.301 (formerly § 1570.7—fraudulent use or manufacture; responsibilities of persons), 1570.303 (formerly § 1570.9—inspection of credential); and 1570.305 (formerly § 1570.13—false statements regarding security background checks by public transportation agency or railroad carrier). Only the last provision (§ 1570.305) has been revised, with revisions limited to removing definitions for terms that have been added elsewhere as part of this rulemaking.

E. Security-Sensitive Employees (§§ 1580.3, 1582.3, and 1584.3)

As part of requiring security training for frontline employees of railroads, PTPR, and OTRB owner/operators-the 9/11 Act provided definitions for “frontline employee” within each mode of transportation.
80

For the reasons discussed below, TSA is proposing to use the term “security-sensitive employees,” with specific definitions of the term for freight rail, PTPR, and OTRB operations. These proposed definitions, which would appear in §§ 1580.3 (freight rail), 1582.3 (PTPR), and 1584.3 (OTRB), would need to be used by owner/operators to determine which employees must receive security training.

80

See
6 U.S.C. 1151(6) (railroads), 6 U.S.C. 1131(4) (public transportation), and 6 U.S.C. 1151(5) (OTRB and railroad frontline employees, respectively).

TSA's proposed definition began with an analysis of the employees listed in the 9/11 Act's definitions of “frontline employees” and whether there are any other employees who may be in a position to spot suspicious activity because of where they work, their interaction with the public, or their access to information (such as cleaning the restrooms, selling tickets and providing assistance to passengers, maintaining equipment and operations in vulnerable areas, or operating a train or bus). TSA also considered who would need to know how to report or respond to these potential threats. The only gap identified between the employees stipulated in the 9/11 Act and those that would fall under the discretionary category are those who have specific responsibilities under any security plan the organization may have. While most of these individuals are likely identified in other categories, from a security perspective it is essential that there are no gaps, particularly where individuals may have responsibility for responding to a terrorist-related emergency.

As a result of this analysis, TSA proposes that employees who perform functions with a direct nexus to, or impact on, transportation security be designated as “security-sensitive employees” based on their job functions. While TSA has proposed a specific list of job functions relevant to the mode, these roughly fall into similar categories. Table 6 aligns these categories with the definitions of frontline employee in the 9/11 Act.

Table 6—Comparison of Security Training NPRM Proposed Categories for “Security-Sensitive Employees” to 9/11 Act Definitions of “Frontline Employees” Who Must Be Trained

Proposed rule—security-sensitive job functions
9/11 Act—Definitions of frontline employees
6 U.S.C. 1151(6) Railroad frontline employees

6 U.S.C. 1131(4) Public transportation frontline
employees *

6 U.S.C. 1151(5) OTRB frontline employees

A. Operating a vehicle
Locomotive engineers, conductors, trainmen, and other onboard employees
Transit vehicle driver or operator
Drivers.

B. Inspecting and maintaining vehicles
Maintenance and maintenance support personnel, and bridge tenders
Maintenance and maintenance support employee
Maintenance and maintenance support personnel.

C. Inspecting or maintaining building or transportation infrastructure

D. Controlling dispatch or movement of a vehicle
Dispatchers
Dispatchers
Dispatchers.

E. Providing security of the owner/operator's equipment and property
Security personnel
Security employee, or transit police
Security personnel.

F. Loading or unloading cargo or baggage
and/or
G. Interacting with travelling public (on board a vehicle or within a transportation facility)

Locomotive engineers, conductors, and other onboard employees
Station attendant, customer service employee, and any other employee who has direct contact with riders on a regular basis
Ticket agents [and] other terminal employees.

H. Complying with security programs or measures, including those required by federal law (a catch-all category that would include a small number of employees such as security coordinators and any other individuals who may have responsibility for carrying out aspects of the owner/operator's security program or measures who are not otherwise

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3A2016-28298. Public record. Not legal advice.
