# Large Aircraft Security Program, Other Aircraft Operator Security Program, and Airport Operator Security Program

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3AE8-23685

## Record

- **Collection:** Federal Register
- **Document type:** Proposed Rule
- **Published:** October 30, 2008
- **Citation:** 73 FR 64790

## Text

DEPARTMENT OF HOMELAND SECURITY
Transportation Security Administration
49 CFR Parts 1515, 1520, 1522, 1540, 1542, 1544, and 1550
[Docket No. TSA-2008-0021]
RIN 1652-AA53
Large Aircraft Security Program, Other Aircraft Operator Security Program, and Airport Operator Security Program

AGENCY:

Transportation Security Administration, DHS.

ACTION:

Notice of proposed rulemaking.

SUMMARY:

The Transportation Security Administration (TSA) proposes to amend current aviation transportation security regulations to enhance the security of general aviation by expanding the scope of current requirements and by adding new requirements for certain large aircraft operators and airports serving those aircraft. TSA is proposing to require that all aircraft operations, including corporate and private operations, with aircraft with a maximum certificated takeoff weight (MTOW) above 12,500 pounds (“large aircraft”) adopt a large aircraft security program (LASP). This security program would be based on the current security program that applies to operators providing scheduled or charter services.

TSA also proposes to require large aircraft operators to contract with TSA-approved auditors to conduct audits of the operators' compliance with their security programs and with TSA-approved watch-list service providers to verify that their passengers are not on the No Fly and/or Selectee portions of the consolidated terrorist watch-list maintained by the Federal Government. This proposed rule describes the process and criteria under which auditors and companies that perform watch-list matching would obtain TSA approval.

TSA also proposes further security measures for large aircraft operators in all-cargo operations and for operators of passenger aircraft with a MTOW of over 45,500 kilograms (100,309.3 pounds), operated for compensation or hire. TSA also proposes to require that certain airports that serve large aircraft adopt security programs and amend the security program for full program and full all-cargo operators.

DATES:

Submit comments by December 29, 2008.

ADDRESSES:

You may submit comments, identified by the TSA docket number to this rulemaking, to the Federal Docket Management System (FDMS), a government-wide, electronic docket management system, using any one of the following methods:

Electronically:
You may submit comments through the Federal eRulemaking portal at
http://www.regulations.gov.
Follow the online instructions for submitting comments.

Mail, In Person, or Fax:
Address, hand-deliver, or fax your written comments to the Docket Management Facility, U.S. Department of Transportation, 1200 New Jersey Avenue, SE., West Building Ground Floor, Room W12-140, Washington, DC 20590-0001; Fax 202-493-2251. The Department of Transportation (DOT), which maintains and processes TSA's official regulatory dockets, will scan the submission and post it to FDMS.

See
SUPPLEMENTARY INFORMATION
for format and other information about comment submissions.

FOR FURTHER INFORMATION CONTACT:

For program questions:
Erik Jensen, Branch Chief—Policy, Plans & Stakeholder Affairs, Office of General Aviation, TSNM, TSA-28, Transportation Security Administration, 601 South 12th Street, Arlington, VA 22202-4220; telephone (571) 227-2401; facsimile (571) 227-2920; e-mail
LASP@dhs.gov.

For questions regarding Sensitive Security Information (SSI):
Andrew Colsky, Director, SSI Office, Office of the Special Counselor (OSC), TSA-31, Transportation Security Administration, 601 South 12th Street, Arlington, VA 22202-4220; telephone (571) 227-3513; facsimile (571) 227-2945; e-mail
SSI@dhs.gov.

SUPPLEMENTARY INFORMATION:

Comments Invited

TSA invites interested persons to participate in this rulemaking by submitting written comments, data, or views. We also invite comments relating to the economic, environmental, energy, or federalism impacts that might result from this rulemaking action. See
ADDRESSES
above for information on where to submit comments.

With each comment, please identify the docket number at the beginning of your comments. TSA encourages commenters to provide their names and addresses. The most helpful comments reference a specific portion of the rulemaking, explain the reason for any recommended change, and include supporting data. You may submit comments and material electronically, in person, by mail, or fax as provided under
ADDRESSES
, but please submit your comments and material by only one means. If you submit comments by mail or delivery, submit them in an unbound format, no larger than 8.5 by 11 inches, suitable for copying and electronic filing.

If you want TSA to acknowledge receipt of comments submitted by mail, include with your comments a self-addressed, stamped postcard on which the docket number appears. We will stamp the date on the postcard and mail it to you.

TSA will file in the public docket all comments received by TSA, except for comments containing confidential information and Sensitive Security Information (SSI).
1

TSA will consider all comments received on or before the closing date for comments and will consider comments filed late to the extent practicable. The docket is available for public inspection before and after the comment closing date.

1
“Sensitive Security Information” or “SSI” is information obtained or developed in the conduct of security activities, the disclosure of which would constitute an unwarranted invasion of privacy, reveal trade secrets or privileged or confidential information, or be detrimental to the security of transportation. The protection of SSI is governed by 49 CFR part 1520.

Handling of Confidential or Proprietary Information and Sensitive Security Information (SSI) Submitted in Public Comments

Do not submit comments that include trade secrets, confidential commercial, or financial information, or SSI to the public regulatory docket. Please submit such comments separately from other comments on the rulemaking. Comments containing this type of information should be appropriately marked as containing such information and submitted by mail to the address listed in
FOR FURTHER INFORMATION CONTACT
section.

Upon receipt of such comments, TSA will not place the comments in the public docket and will handle them in accordance with applicable safeguards and restrictions on access. TSA will hold them in a separate file to which the public does not have access, and place a note in the public docket that TSA has received such materials from the commenter. If TSA receives a request to examine or copy this information, TSA will treat it as any other request under the Freedom of Information Act (FOIA) (5 U.S.C. 552) and the Department of Homeland Security's (DHS) FOIA regulation found in 6 CFR part 5.

Reviewing Comments in the Docket

Please be aware that anyone is able to search the electronic form of all comments received into any of our

dockets by the name of the individual submitting the comment (or signing the comment, if submitted on behalf of an association, business, labor union, etc.). You may review the applicable Privacy Act Statement published in the
Federal Register
on April 11, 2000 (65 FR 19477), or you may visit
http://docketinfo.gov.

You may review TSA's electronic public docket on the Internet at
http://www.regulations.gov.
In addition, DOT's Docket Management Facility provides a physical facility, staff, equipment, and assistance to the public. To obtain assistance or to review comments in TSA's public docket, you may visit this facility between 9 a.m. 5 p.m., Monday through Friday, excluding legal holidays, or call (202) 366-9826. This docket operations facility is located in the West Building Ground Floor, Room W12-140 at 1200 New Jersey Avenue, SE., Washington, DC 20590.

Availability of Rulemaking Document

You can get an electronic copy using the Internet by—

(1) Searching the electronic Federal Docket Management System (FDMS) Web page at
http://www.regulations.gov
;

(2) Accessing the Government Printing Office's web page at
http://www.gpoaccess.gov/fr/index.html;
or

(3) Visiting TSA's Security Regulations web page at
http://www.tsa.gov
and accessing the link for “Research Center” at the top of the page.

In addition, copies are available by writing or calling the individual in the
FOR FURTHER INFORMATION CONTACT
section. Make sure to identify the docket number of this rulemaking.

Abbreviations and Terms Used in This Document

AICPA—American Institute of Certified Public Accountants

ALJ—Administrative Law Judge

AOSC—Aircraft Operator Security Coordinator

AOSSP—Aircraft Operator Standard Security Program

ATSA—Aviation and Transportation Security Act

CFR—Code of Federal Regulations

CHRC—Criminal History Records Check

CJIS—Criminal Justice Information Services

CBP—U.S. Customs and Border Protection

DHS—U.S. Department of Homeland Security

FAMs—Federal Air Marshals

FAA—Federal Aviation Administration

FACAOSSP—Full All-Cargo Aircraft Operator Standard Security Program

FBI—Federal Bureau of Investigation

FISMA—Federal Information Security Management Act

GA—General Aviation

HME—Hazardous Materials Endorsement

IPA—Independent Public Accounting firm

IT—Information Technology

LASP—Large Aircraft Security Program

LEO—Law Enforcement Officer

MTOW—Maximum Certificated Take-Off Weight

NIST—National Institute of Standards and Technology

PPSSP—Partial Program Standard Security Program

PCSSP—Private Charter Standard Security Program

SSI—Sensitive Security Information

STA—Security Threat Assessment

TSC—Terrorist Screening Center

TSA—Transportation Security Administration

TWIC—Transportation Worker Identification Credential

TFSSP—Twelve-Five Standard Security Program

Outline of the Notice of Proposed Rulemaking

I. Introduction

A. Current Standard Security Programs

B. Current Security Programs for Large Aircraft

C. Implementation and Compliance Schedule

II. Major Proposed Elements in This NPRM

A. Major Requirements in the Proposed Large Aircraft Security Program

B. Proposed Requirements for Certain Airports

C. Passenger Checking Against the Watch-list

D. Third-Party Audits for Large Aircraft Operators

E. Proposed Amendments to the Full Program and the Full All-Cargo Program

III. Section-by-Section Analysis

IV. Regulatory Requirements

A. Paperwork Reduction Act

B. Regulatory Impact Analyses

1. Regulatory Evaluation Summary

2. Executive Order 12866 Assessment

3. Regulatory Flexibility Act Assessment

4. International Trade Impact Assessment

5. Unfunded Mandates Assessment

C. Executive Order 13132, Federalism

D. Environmental Analysis

E. Energy Impact Analysis

List of Subjects

The Proposed Amendments

I. Introduction

The aviation industry is composed of thousands of operators that conduct different types of operations in numerous different types of aircraft. Many aircraft operators are air carriers or commercial operators that offer transportation to the public for compensation or hire. Others are general aviation (GA) operators that do not offer transportation to the public. These operators often are corporate or private owners of aircraft that operate their aircraft for their own use or provide transportation for compensation or hire only to certain customers without offering transportation to the public in general.
2

2
There is no statutory or regulatory definition of “general aviation.” For the purposes of this NPRM, we use the term to refer to aircraft operations that are not air carriers or commercial, governmental or military operators.

To date, the Federal Government's primary focus with regard to aviation security has been on air carriers and commercial operators that offer transportation for compensation or hire to the public. TSA requires these carriers and operators to develop and operate under a particular security program depending on the precise nature of their operations. A security program is a set of security procedures that will meet the requirements of applicable TSA regulations. For example, a security program would include specific measures to screen cargo, to transport Federal Air Marshals, to use personnel identification systems, and to provide training to employees, if the operator were subject to those requirements in TSA's regulation.

With few exceptions, TSA does not currently require security programs for GA aircraft operators. As vulnerabilities and risks associated with air carriers and commercial operators have been reduced or mitigated, terrorists may view general aviation aircraft as more vulnerable and thus attractive targets. If hijacked and used as a missile, these aircraft would be capable of inflicting significant damage.

The Federal Aviation Administration's (FAA) long-standing definition of “large aircraft” is an aircraft with a maximum certificated takeoff weight (MTOW) of over 12,500 pounds. See 14 CFR 1.1. Based on the aviation industry's familiarity with this definition and TSA's belief that aircraft of this size pose a potential risk, TSA is proposing to require security programs for all operators of aircraft—GA or otherwise—that have a MTOW of over 12,500 pounds, excluding certain governmental operations (collectively, “large aircraft operators”).
3

3
In general, aircraft that weigh over 12,500 pounds MTOW are those aircraft equipped with twin turboprop or turbojet engines. Typically corporate and charter aircraft have a seating configuration for 6-8 passengers, while similar aircraft used in scheduled passenger service would likely have 18 or more seats.

Currently, TSA requires many large aircraft operators that are air carriers or commercial operators to implement security programs such as the Twelve-Five Security Program or the Private Charter Security Program.
4

TSA is

proposing to expand this requirement to include previously unregulated large aircraft operators—namely, GA with a MTOW of over 12,500 pounds. Doing so will expand the large aircraft operator population required to have a TSA-approved security program to approximately 10,000 operators from the approximately 650 operators today. In addition, TSA is proposing to establish a single large aircraft security program (LASP) to replace the various security programs used by currently regulated large aircraft operators, such as air carriers and commercial operators. It is TSA's view that the proposed rule would enhance security significantly.

4
Although aircraft operators that are subject to the full program under 49 CFR 1544.101(a), or the full all-cargo program under § 1544.101(h), operate large aircraft, TSA does not include them in

references to operators of large aircraft and large aircraft operators for purposes of this NPRM. Full program operators are generally known as the commercial airlines.

TSA recognizes that this would greatly increase the number and type of operators subject to a TSA-approved security program. TSA invites comments on the weight threshold of aircraft covered by this proposed rule. For instance, parties may choose to comment on whether the security goals discussed herein would be met if security programs were required for GA aircraft only over some greater weight threshold. For example, we explain below that aircraft over 45,500 kg (100,309.3 pounds) MTOW are currently covered by the “private charter” security program, which includes security measures in addition to those outlined in the “twelve-five” security program. Since incidents involving heavier aircraft have the potential to lead to greater damages and loss of life under one of the scenarios studied in our regulatory impact analysis, we specifically solicit comment on whether this would be a logical alternative weight threshold to consider for the increased security requirements for general aviation. Although TSA has concluded in this NPRM that the security benefits of the lower weight threshold of 12,500 lbs are justified by the risk and therefore justify the additional cost of the lower threshold, we welcome commenters' views on that topic, as well as on the cost-benefit impact of alternate weight thresholds.

Below is a list of the major requirements GA aircraft operators would be required to adopt under the LASP; a more detailed discussion of the LASP and the individual requirements is in sections II and III of this preamble:

• Ensure that their flight crew members have undergone a fingerprint-based criminal history records check (CHRC).

• Conduct watch-list matching of their passengers through TSA-approved watch-list matching service providers.

• Undergo a biennial audit of their compliance by a TSA-approved third party auditor.

• Comply with the current cargo requirements for the twelve-five all-cargo program if conducting an all-cargo operation.

• For aircraft with a MTOW of over 45,500 kilograms operated for compensation or hire, screen passengers and their accessible property.

• Check property on board for unauthorized persons.

In addition, TSA is proposing amendments to its regulations regarding airport security programs.
5

TSA is proposing to require additional airports to adopt security programs, because these airports serve aircraft operators that either currently must carry out a security program or would be required to have a security program under the proposed rule. TSA proposes to require the following airports to adopt a security program:

5
The regulations are in 49 CFR 1542.101.

• Reliever airports, which perform the function of relieving congestion at commercial service airports and provide more GA access to the overall community.

• Airports that regularly serve large aircraft with scheduled or public charter service.

A. Current Aircraft Operator Security Programs

TSA requires security programs for air carriers and commercial operators that require security measures for individuals, property, and cargo aboard aircraft. Currently TSA requires security programs for full program, full all-cargo, partial, private charter, and twelve-five program operators. For full program operators,
6

the standard security program
7

is called an aircraft operator standard security program (AOSSP). For the full all-cargo program operators
8

operating all-cargo aircraft over 45,500 kg MTOW, the standard security program is the full all-cargo aircraft operator standard security program (FACAOSSP). The partial program
9

applies to scheduled passenger or public charter operations in an aircraft with 31 or more, but 60 or fewer passenger seats that does not enplane from or deplane into a sterile area. The standard security program for private charters is the private charter standard security program.
10

For other scheduled or charter flights, or all-cargo operations, in an aircraft with a MTOW of over 12,500 pounds, the standard security program is the twelve-five standard security program.
11

6
49 CFR 1544.101(a).

7
A standard security program is a security program issued by TSA that serves as the baseline for a particular type of operator. An aircraft operator's security program consists of the appropriate standard security program, together with any amendments and alternative procedures to the security program, if approved by TSA.

8
49 CFR 1544.101(h).

9
49 CFR 1544.101(b).

10
49 CFR 1544.101(f).

11
49 CFR 1544.101(d).

The full program, the full all-cargo program, the partial program, the private charter program, and the twelve-five program aircraft operators all are covered under TSA regulations in 49 CFR part 1544. They all must hold FAA air carrier operating certificates or FAA operating certificates in accordance with the Federal Aviation Administration (FAA) regulations in 14 CFR part 119.
12

They all engage in interstate common carriage or intrastate common carriage.
13

TSA has also required certain operators not engaged in common carriage to hold and carry out security programs. Operators of aircraft with a MTOW of over 12,500 pounds must conduct operations in accordance with the FAA rules in 14 CFR part 125 (part 125 operators).
14

By notice published in the
Federal Register
, TSA required these operators to carry out the twelve-five standard security program for operations in aircraft over 12,500 pounds but not over 45,500 kg, and to carry out the private charter standard security program for operations in aircraft over 45,500 kg.
15

These part 125 operators conduct operations when common carriage is not involved. They may conduct operations for compensation or hire, however, and they may also conduct operations not for compensation or hire.
16

12
49 CFR 1544.1.

13
49 U.S.C. 40102 and 14 CFR 119.21.

14
14 CFR 119.23.

15
69 FR 61516 (Oct. 19, 2004).

16
14 CFR 119.3 and 119.23. After TSA adopted the full all-cargo program, it required part 125 operators in all-cargo operations using aircraft over 45,500 kg to have and carry out a full all-cargo program. See 71 FR 30478 (May 26, 2006).

Finally, all civil aircraft must operate under FAA regulations 14 CFR part 91, Air Traffic and General Operating Rules. These operators, when not also subject to another FAA regulation, such as part 119 or part 125, are often referred to in the industry as part 91 operators. TSA generally has not required such operators to carry out security measures.

The main objectives of the proposed rule are: (1) To merge the partial, private charter and twelve-five programs into a large aircraft security program and to

expand its scope to include general aviation operators using aircraft with a MTOW of over 12,500 pounds; and (2) to enhance the security of these operations.

B. Current Security Programs for Large Aircraft

Large aircraft are operated by a diverse group of air carriers, commercial operators, and GA operators. As stated above, to date, TSA has mandated security programs for the air carrier and commercial operator segments of the aviation industry including scheduled passenger operations, private charters, public charters, and all-cargo operations in large aircraft through the twelve-five program, the partial program, and the private charter program. With limited exceptions, TSA has not required security programs for large aircraft in general aviation.

Large GA aircraft are most often operated by corporate entities, though some large GA aircraft are operated by individuals. Corporate aviation, with a population of approximately 10,000 operators flying 15,000 aircraft, is largely unregulated for security purposes. Yet many of these aircraft are of the same size and weight of the air carriers and commercial operators that TSA regulates, and they could be used effectively to commit a terrorist act. Complicating the situation is the fact that many GA operators have the authorization to function under several different FAA regulations and operating certificates, which may require different TSA security programs or no TSA security program at all.

TSA considered developing a new regulatory program to be used solely on GA aircraft and their potential security risks. This decision would have created yet another security program applicable to large aircraft operators. Instead of five separate security programs that would apply to large aircraft operators depending on the type of service they provide, TSA is proposing one security program that would apply to all large aircraft operators (except certain government operations) and would replace the current security programs for partial program operators, twelve-five program operators, and private charter operators. The LASP would establish a consistent set of regulations for air carriers and commercial operators, as well as GA operators using large aircraft. Indeed, LASP would provide large aircraft operators not covered under the full program, or the full all-cargo security program, with one set of regulations that would form the core of their security programs distinct to their operational and security needs.

Table 1 below identifies the different types of large aircraft operators that currently are required to have a security program and the major security requirements for these operators. It also identifies the types of operators that would be subject to the new proposed LASP.

Table 1—Standard Security Programs Applicable to Aircraft Operators

An aircraft operator that operates this type of service, other than all-cargo
In this size aircraft
And

Must have this
program #

Currently using this standard security program
Would be using this standard security program under the NPRM

Scheduled passenger or public charter passenger *
61 or more passenger seats

Full Program § 1544.101(a)(1)
AOSSP
No change.

Scheduled passenger or public charter passenger *
60 or fewer passenger seats
It enplanes from, or deplanes into, an existing sterile area
Full Program § 1544.101(a)(2)
AOSSP
No change.

Scheduled passenger or public charter passenger *
31 or more but 60 or fewer passenger seats
It does not enplane from, or deplane into, an existing sterile area
Partial Program § 1544.101(b)(1)
Partial Program Standard Security Program (PPSSP)
Proposed LASSP **** with component for aircraft greater than 45,500 kg (if applicable).

Scheduled, public charter, or private charter; passenger *
More than 12,500 pounds MTOW
It does not enplane from, or deplane into, an existing sterile area, and it is not under a Full Program or a Partial Program
Twelve-Five Program § 1544.101(d)
Twelve-Five Standard Security Program (TFSSP)
Proposed LASSP.

Private charter *
Any size
It enplanes from, or deplanes into, an existing sterile area
Private Charter Program § 1544.101(f)(1)(i)
Private Charter Standard Security Program (PCSSP)
Proposed LASSP with component for aircraft greater than 45,500 kg (if applicable) and alternative procedures for enplaning from or deplaning into an existing sterile area.

Private charter *
More than 45,500 kg, OR 61 or more passenger seats
It does not enplane from, or deplane into, an existing sterile area, and it is not a government charter
Private Charter Program § 1544.101(f)(1)(ii)
PCSSP
Proposed LASSP with component for aircraft greater than 45,500 kg.

Under an FAA certificate issued under 14 CFR part 125 **
More than 45,500 kg MTOW
It is carrying passengers or property for compensation or hire and is not under another TSA security program
§ 1550.7; (69 FR 61516, 10/19/2004)
PCSSP
Proposed LASSP with component for aircraft greater than 45,500 kg or 61 or more seats.

Under an FAA certificate issued under 14 CFR part 125 **
61 or more passenger seats
It is carrying passengers or property for compensation or hire and is not under another TSA security program
§ 1550.7; (69 FR 61516, 10/19/2004)
PCSSP
Proposed LASSP with component for aircraft greater than 45,500 kg or 61 or more seats.

Under an FAA certificate issued under 14 CFR part 125 **
More than 45,500 kg MTOW
It is not carrying passengers or property for compensation or hire and not under another TSA security program
§ 1550.7; (69 FR 61516, 10/19/2004)
PCSSP
Proposed LASSP.

Under an FAA certificate issued under 14 CFR part 125 **
61 or more passenger seats
It is not carrying passengers or property for compensation or hire and not under another TSA security program
§ 1550.7; (69 FR 61516, 10/19/2004)
PCSSP
Proposed LASSP.

Under an FAA certificate issued under 14 CFR part 125 **
More than 12,500 pounds MTOW
It is not under another TSA security program
§ 1550.7
TFSSP
Proposed LASSP.

Operating under 14 CFR part 91 only **
More than 12,500 pounds
It enplanes from, or deplanes into, an existing sterile area
General Aviation Operations using a sterile area § 1550.5
No standard program
Proposed LASSP with alternative procedures for enplaning from or deplaning into an existing sterile area.

Operating under 14 CFR part 91 only **
12,500 pounds or less
It enplanes from, or deplanes into, an existing sterile area
General Aviation Operations using a sterile area § 1550.5
No standard program
No change.

Operating under 14 CFR part 91 only **
More than 12,500 pounds
It is not under another TSA security program, and does not enplane from or deplane to an existing sterile area
Not required to have a security program
Not required to have a security program
Proposed LASSP.

Operating under 14 CFR part 91 only **
12,500 pounds or less
It is not under another TSA security program, and does not enplane from or deplane to an existing sterile area
Not required to have a security program
Not required to have a security program
No change.

Passenger operations into and out of Ronald Reagan Washington National Airport (DCA) ***
Any size
It is not under a Full Program
DCA Access Program part 1562
DCA Access Standard Security Program (DASSP)
No change.

Other operations **
Any size
Is not under any other required program but aircraft operator requests a security program
Limited program § 1544.101(g)
No standard program
No change.

* These aircraft operators are considered air carriers or commercial operators.
** These aircraft operators are considered general aviation.
*** May be air carriers, commercial operators, or general aviation operators.
**** After issuing the LASP final rule, TSA would develop and issue a standard security program to implement the LASP called the Large Aircraft Standard Security Program (LASSP).
# Cites in this column are to 49 CFR.

An all-cargo aircraft operator that
operates this type of service: ##

In this size aircraft
And

Must have this
program #

Currently using this standard
security program

Would be using this standard security
program under the NPRM

All-cargo
Greater than 45,500 kg, OR 61 or more passenger seats
Operating under a FAA certificate issued under 14 CFR part 119 or 125

Full All-Cargo Program
§ 1544.101(h)

Full All-Cargo Aircraft Operator Standard Security Program (FACAOSSP)
No change.

All-cargo
Over 12,500 lbs but not over 45,500 kg

Twelve-Five Program in all-cargo operations
§ 1544.101(d)

TFSSP in all-cargo operations
LASSP with all-cargo component.

All-cargo under an FAA certificate issued under 14 CFR part 125
More than 45,500 kg

FACAOSSP
FACAOSSP +
No change.

# Cites in this column are to 49 CFR.
## All-cargo operations carry cargo and authorized persons, but no passengers.

In developing the proposed rule, TSA analyzed the existing security programs to determine which security measures have been effective and would be appropriate for inclusion in the proposed LASP. The LASP would combine the essential elements of some of the current security programs into one consolidated and comprehensive program.

In this rulemaking, TSA is also proposing to reorganize certain existing regulations in 49 CFR part 1544. Specifically, TSA has clarified the meaning of the rule, simplified the text, and harmonized regulations between the different industry populations. This reorganization may affect the currently regulated population in addition to the proposed newly regulated population. TSA is also proposing to reorganize certain sections in 49 CFR part 1544 to account for the proposed addition of the LASP. The reorganization would not make any substantive changes to the regulations.

C. Implementation and Compliance Schedule

Based on industry data, TSA anticipates that this proposed rule would require approximately 10,000 aircraft operators and 315 airport operators, most of whom are not currently required to do so, to implement security programs. Due to the large number of aircraft operators and airport operators that would be required to implement security programs, TSA proposes using a phased approach in the implementation of the proposed rule. The proposed compliance schedule would allow for proper and adequate support and staffing within TSA and also would allow sufficient time for compliance on the part of the newly regulated aircraft operators and airport operators. Following issuance of a final rule, TSA would implement a communication plan commencing with a wide distribution of press releases, web-site postings, and industry association briefings and meetings. These briefings and meetings would communicate, educate, and confirm which operators would be affected by the final rule, what actions the aircraft operators and airport operators would be required to take to comply with the rule, and the time period within which the aircraft operator and airport operators would be required to submit their applications and other supporting documents. At that time, TSA would provide the process, procedures, and necessary forms to the aircraft operators and airport operators to enable the operators to apply for the large aircraft program, or the airport partial program, via a secure web-board.

TSA's implementation schedule would divide the country into five areas, taking into account which areas of the country contain the largest affected populations of aircraft operators and airport operators. TSA anticipates six phases of compliance, targeting approximately 20 percent of the large aircraft operator and airport operators population that currently do not hold security programs in each of the first five phases. The sixth and final phase would include aircraft operators that currently hold a security program.
17

The following timeline for compliance would start upon the effective date of the final rule, which would be 60 days after publication of the final rule in the
Federal Register
:

17
There are no airport operators that currently hold a partial program.

Phase 1, Mid-Atlantic region—months 1-4 after the effective date of the final rule.

Phase 2, North-East region—months 5-8 after the effective date of the final rule.

Phase 3, Southern region—months 9-12 after the effective date of the final rule.

Phase 4, Mid-West region—months 13-16 after the effective date of the final rule.

Phase 5, Western region—months 17-20 after the effective date of the final rule.

Phase 6, Existing security program holders—months 21-24 after the effective date of the final rule.

The phase in which a large aircraft operator would fall would be determined by where the aircraft is based. For large aircraft operators that have multiple bases for their aircraft, the phase would be determined by the location of the large aircraft operator's headquarters. We seek comment on this phased approach and on determining which phase would be applicable to each large aircraft operator based on the location of the aircraft or headquarters.

II. Major Elements in This NPRM

A. Major Requirements in the Proposed Large Aircraft Security Program

To provide greater consistency across all large aircraft operations, the proposed regulation would create the Large Aircraft Standard Security Program (LASSP) to replace the current security programs for partial program operators, twelve-five program operators, and private charter program operators. The major requirements in this proposed rule are based on the requirements in the Twelve-Five and the Private Charter Security Programs.

The proposed LASP provides a core security program for all large aircraft, irrespective of the FAA regulations under which they operate, whether they are air carriers, commercial operators, or GA. Beyond the core requirements for large aircraft with a MTOW of over 12,500 pounds, the proposed LASP would include a component for large aircraft with a MTOW of over 45,500 kilograms operated for compensation or hire. The following is a summary of the major security measures in the proposed LASP.

1. Proposed Core Requirements of the Large Aircraft Security Program in § 1544.103(e)

In TSA's experience, the current Twelve-Five Security Program has proven to be effective in safeguarding the operations of scheduled and charter operations in aircraft with MTOW of over 12,500 pounds without unduly burdening the aircraft operators. Accordingly, TSA would base the core requirements of the LASP on the Twelve-Five Security Program. The LASP, however, would include additional requirements that would

strengthen the existing security measures. Below is a discussion of the major requirements of the LASP.

Security Threat Assessment With Criminal History Records Check for Flight Crew Members

Under the current security programs that apply to large aircraft operators, TSA requires aircraft operators to ensure that their flight crew members have undergone a fingerprint-based criminal history records check (CHRC). TSA views this as an important security measure that should apply to flight crew members of all large aircraft. Pilots are in control of the aircraft and other flight crew members are in the cockpit and could obtain control of the aircraft. Consequently, TSA proposes to require that large aircraft operators ensure that all of their flight crew members undergo a security threat assessment (STA) that includes a CHRC and other analyses, including checks of appropriate terrorist watch-lists and other databases. The list of disqualifying crimes of the CHRC would be the same as for the full and full all-cargo operations. 49 CFR 1544.229 and 1544.230.

After TSA adopted the Twelve-Five Security Program requirements, it became clear that most operators of that size were not well-prepared to conduct adjudication of the CHRCs. Accordingly, while the twelve-five operators have been ensuring that their flight crew members submit their fingerprints, TSA has been adjudicating the criminal histories; that is, TSA reviews the history to determine whether the flight crew member has a disqualifying criminal offense. TSA is proposing to codify that practice and to charge a fee for the services. See the section-by-section analysis for proposed part 1544, subpart G.

TSA recognizes that a flight crew member may be contracted to work for more than one large aircraft operator. We seek comment on whether the STA should be transferable so that the flight crew member would need to undergo only one STA every five years, regardless of the number of employers the flight crew members may have within the five-year period. Potential employers would check the status of the flight crew member's STA through a mechanism required by TSA.

TSA also is considering ways to positively identify pilots conducting both domestic and international flight operations and effectively link them to the aircraft they are operating. We seek comment and recommended methods for positively identifying pilots and effectively linking them to the aircraft they are operating.

Watch-List Matching of Passengers

The Federal Government maintains a terrorist watch-list. The watch-list, which includes the No Fly List and the Selectee List components of the Terrorist Screening Database maintained by the Terrorist Screening Center (TSC), is the basis for the pre-flight passenger watch-list matching currently conducted by certain aircraft operators. Watch-list matching of passengers on large aircraft is an important security measure, because it can prevent individuals who are believed to pose a risk from boarding a large aircraft and, potentially, gaining control of the aircraft, to use it as a weapon. TSA studies have shown that significant loss of lives and other damage could result from such an incident. Matching passenger information against the No Fly List component of the terrorist watch-list would identify individuals who, if permitted to board aircraft, may pose a threat to the aircraft and/or persons on board. Matching passenger information against the Selectee List component of the terrorist watch-list also would identify individuals who may be potential threats and would allow TSA and/or the aircraft operators to take appropriate action, if necessary.

Under the current watch-list matching process, TSA provides the No Fly and Selectee List to twelve-five, partial program, and private charter aircraft operators to enable them to conduct the watch-list matching. When an aircraft operator receives passenger information that is similar to, or the same as, a name on the No Fly or Selectee List, the aircraft operator is required to notify law enforcement personnel and TSA in order to determine whether that passenger is in fact the individual listed on the No Fly or Selectee List. The aircraft operator may not board a passenger until TSA has instructed the aircraft operator that the passenger is clear to board the aircraft.

a.
Removing watch-list from aircraft operators
. Per Homeland Security Presidential Directive-16/National Security Presidential Directive-47, section 4012(a) of the Intelligence Reform and Terrorism Prevention Act,
18

and in support of 9/11 commission recommendations, the U.S. government is in the process of assuming control over watch-list matching in the aviation environment. TSA is concerned that providing the watch-list to approximately 10,000 large aircraft operators as part of the LASP program would increase the risk that the watch-list would be disseminated to unauthorized persons and that the watch-list would be misused and/or compromised. Since it is not possible to bring the watch-list matching function into the federal government in one step, TSA is considering ways to provide this list to a more limited set of holders while TSA considers the most effective method to assume the watch-list matching responsibility from all aircraft operators required to conduct watch-list matching through the Secure Flight program.

18
Public Law 108-458, 118 Stat. 3638, Dec. 17, 2004; 49 U.S.C. 44903 (j)(2).

TSA recognizes that the Secure Flight program has not yet achieved the operational capability to conduct watch-list matching for general aviation, nor is such capability anticipated by the time TSA would require large general aviation and charter aircraft operators to implement the LASP. Therefore, TSA is proposing a solution for watch-list matching in this NPRM for the time period in which the Secure Flight program does not have the capability to conduct watch-list matching for large aircraft passengers. If TSA is able to develop the capability for the Secure Flight program to conduct watch-list matching for large aircraft passengers, TSA may amend the scope of the Secure Flight program to include large aircraft operators in the final rule for this NPRM.
19

19
For example, proposed § 1560.1(a) may be amended to include large aircraft operators. See Secure Flight NPRM, 72 FR at 48387.

b.
Watch-list Service Providers.
Under the proposed rule, TSA would not provide the No Fly List to large aircraft operators, which means that TSA would no longer provide the watch-list to the approximately 800 aircraft operators now receiving it under the twelve-five program, partial program and private charter operators and would not begin providing it to the additional approximately 9,300 general aviation operators that would be under the LASP. Instead, TSA would provide the watch-list to watch-list service providers approved by TSA. Large aircraft operators would transmit their passenger information to these watch-list service providers, who would conduct the automated watch-list matching function and transmit the results back to the large aircraft operators.

TSA is proposing this approach for two reasons. First, this would greatly reduce the number of entities receiving the watch-list, thus reducing the risk that it would be disseminated to unauthorized persons or misused. Second, having a small number of watch-list service providers conduct watch-list matching in accordance with

TSA standards would result in greater consistency in the application of the watch-list matching function. These watch-list service providers will have been determined to have appropriate security, including Information Technology (IT) security and performance capabilities, to perform this important function in the interim. TSA invites comments on the role that watch-list service providers may continue to have if the responsibility for watch-list matching shifts to the U.S. Government in the future. For example, would watch-list service providers offer their services to consolidate passenger information from large aircraft operators and to transmit the passenger information to Secure Flight?

While the watch-list service providers would perform the watch-list matching function, large aircraft operators would have several responsibilities under the proposed rule. Large aircraft operators would be responsible for all costs associated with watch-list matching, including any fee charged by the watch-list service providers.

c.
Compliance with CBP programs
. Large aircraft operators would not be required to transmit passenger information to their watch-list service providers for any flight for which the large aircraft operator has submitted advance passenger information to U.S. Customs and Border Protection (CBP) under 19 CFR part 122. For passengers on flights in commercial aircraft, as defined in 19 CFR 122.1, the large aircraft operator are required to submit advance passenger information under 19 CFR 122.49a and 122.75a and comply with the CBP boarding instruction regarding each passenger.

TSA notes that CBP published a notice of proposed rulemaking, “Advance Information on Private Aircraft Arriving in and Departing from the United States,” proposing to implement certain passenger manifest and advance passenger screening requirements for private aircraft departing foreign ports for U.S. destinations or departing the United States for foreign ports. Under the CBP proposed rule, a private aircraft, in contrast to a commercial aircraft,
20

is generally any aircraft engaged in a personal or business flight to or from the United States that is not carrying passengers and/or cargo for commercial purposes.
21

See 19 CFR 122.1(h). CBP's Advance Passenger Information System (APIS) requirements and proposed eAPIS requirements apply to both U.S.-operated and foreign-operated aircraft.

20
19 CFR 122.1(d) defines “commercial aircraft” as any aircraft transporting passengers and/or cargo for some payment or other consideration, including money or services rendered.

21
19 CFR 122.1(h) also defines a private aircraft as any aircraft leaving the United States carrying neither passengers nor cargo in order to lade passengers and/or cargo in a foreign area for commercial purposes; or returning to the United States carrying neither passengers nor cargo in ballast after leaving with passengers and/or cargo for commercial purposes.

To avoid process redundancies, DHS would require operators and pilots of private large aircraft that would be subject to this TSA proposed rule and CBP's eAPIS private aircraft regulations to submit their passenger manifest to CBP only and not to watch-list service providers. TSA would deem U.S. operators of private large aircraft to be in compliance with the proposed rule's requirements to submit passenger information for watch-list matching for international flights if the pilot submits passenger information required under the proposed eAPIS regulations. See proposed 19 CFR 122.22.

The TSA and CBP screening processes work in tandem for flights departing foreign ports destined for the United States and flights departing the United States for foreign destinations. If CBP grants the pilot landing rights under 19 CFR 122.49a, 122.75a, or 122.22, TSA would allow the large aircraft operator to permit all passengers, for whom the aircraft operator submitted advance passenger information to CBP, to board the aircraft. If CBP identifies a passenger as a selectee under 19 CFR 122.49a, 122.75a, or 122.22, TSA would allow the large aircraft operator to permit the passenger to board the aircraft, and TSA would require the large aircraft operator to comply with the procedures in its security program pertaining to passengers that are identified as selectees, as discussed in further detail below. If CBP identifies a passenger as “not cleared” under 19 CFR 122.49a, 122.75a, or 122.22, TSA would not allow the large aircraft operator to permit the passenger to board the aircraft. CBP would instruct the large aircraft operator to contact TSA regarding the passenger who has been identified as “not cleared” for further resolution.

d.
Passenger information
. This proposed rule would require large aircraft operators to request full name, gender, date of birth, and redress number
22

(if available) from all passengers. TSA has determined that an individual's full name, gender, and date of birth are critically important for effective automated watch-list matching of that individual against those individuals on the watch-list.
23

The full name is the primary attribute used to conduct watch-list matching and would be required for all passengers. Partial names would increase the likelihood of false positive matches, because partial names are more likely to match a number of different entries on the watch-list. As a result, this proposed rule would require individuals to provide their full names and would prohibit aircraft operators from boarding a passenger who does not provide a full name. Date of birth and gender would be optional for the passenger. This proposed requirement on passengers to provide the full name is consistent with TSA's proposal in the Secure Flight NPRM. In the Secure Flight NPRM, TSA proposes to require passengers on commercial flights operated by full program operators and foreign air carriers to provide their full name when they make a reservation for a flight. See proposed § 1540.107(b) in the Secure Flight NPRM, 72 FR at 48386.

22
The redress number is the number assigned by DHS to an individual processed through the redress procedures described in 49 CFR part 1560, subpart C, as proposed in the Secure Flight NPRM.

23

See
Secure Flight NPRM, 72 FR at 48364.

Many names do not indicate gender, because they can be used by either gender. Additionally, names not derived from the Latin alphabet, when transliterated into English, often do not denote gender. Providing information on gender will reduce the number of false positive watch-list matches, because the information will distinguish persons who have the same or similar names but who are of a different gender. The date of birth is also helpful in distinguishing a passenger from an individual on a watch-list with the same or similar name, thereby reducing the number of false positive watch-list matches.

This proposed rule would also require aircraft operators to request an individual's redress number, if available. DHS will assign this unique number to individuals who use the DHS Traveler Redress Inquiry Program (DHS TRIP), because they believe they have been incorrectly delayed or denied boarding. Individuals may be less likely to be delayed by false positive matches to the watch-list if they provide their redress number, if available.

Under the proposed rule, individuals would not be compelled to provide their gender, date of birth, or redress number when requested by the aircraft operators. However, without this information, the watch-list service provider may be unable to perform effective automated watch-list matching and, as a result, the individuals may be more likely to be denied boarding, or under certain circumstances, be subject

to additional screening. TSA is considering whether to require all individuals to provide their gender and date of birth to assist in the watch-list matching and resolution process.

The proposed rule would require large aircraft operators to transmit to the watch-list service provider the passengers' full names and also transmit the passengers' genders, dates of birth, and redress numbers, to the extent they are available. In addition, the proposed rule would require large aircraft operators to transmit certain information from an individual's passport (full name, passport number, country of issuance, expiration date, gender, and date of birth), if it is available and was provided to the aircraft operator. Based on TSA's experience in conducting security threat assessments that include watch-list matching, TSA has determined that passport information would help resolve possible false positive matches and make the watch-list matching process more accurate.

TSA is not proposing a minimum time in advance of the flight that large aircraft operators would be required to submit passenger information to the watch-list service provider. TSA anticipates that the large aircraft operators would work with their service providers to establish a minimum time that the service provider would need to complete watch-list matching in advance of a flight. Nevertheless, TSA seeks comment on whether it should establish a minimum time for submission of passenger information to the service providers, what that minimum time should be, and the reasons supporting the suggested minimum time.

Upon submission of the passenger information by the aircraft operator to the watch-list service provider, the service provider would conduct the automated vetting of the passenger information provided against the watch-list which is comprised of the No Fly and Selectee List components of the Terrorist Screening Database. The watch-list service provider would inform the aircraft operator of the results of the watch-list matching by transmitting instructions to the large aircraft operator for each passenger. The large aircraft operator would not be able to permit a passenger aboard an aircraft until the large aircraft operator receives the instructions from the watch-list service provider that would allow the aircraft operator to board the passenger. The large aircraft operator would be required to comply with the instructions.

Upon submission of the passenger information by the aircraft operator to the watch-list service provider, the service provider would conduct the automated comparison using the passenger information provided. If an automated comparison indicates that the passenger is not a match to the watch-list, the service provider would instruct the aircraft operator that the passenger is cleared to board the aircraft. If the automated comparison using the passenger information identifies a potential match to the watch-list, the watch-list service provider would contact TSA for resolution of the potential match. TSA would coordinate with the TSC for resolution if necessary and would provide further instructions concerning the passenger to the service provider.

If TSA cannot determine from the information provided by the watch-list service provider whether the individual is a match to the watch-list, it may be necessary for the passenger to provide additional information to resolve the possible match. In these instances, TSA would inform the watch-list service provider to instruct the large aircraft operator to contact TSA directly to resolve the possible match between the passenger and the watch-list record, and TSA would provide final instructions concerning the possible match and the passenger's status to the large aircraft operator.

e.
Aircraft operator procedures.
TSA believes that it is important for large aircraft operators and their pilots, as the in-flight security coordinators, to know whether a passenger is identified as a selectee so they can make appropriate security decisions. If the passenger is identified as a selectee, TSA would allow the large aircraft operator to permit the passenger to board the aircraft. However, TSA would require the aircraft operator to comply with the procedures described in its security program pertaining to passengers identified as selectees. Although TSA would not require large aircraft operators to conduct screening of selectees and their accessible property on a normal basis, if warranted by security considerations, TSA may require some or all large aircraft operators to screen selectees and their accessible property. In this circumstance, TSA would coordinate with the large aircraft operators on the appropriate screening protocols.

If the watch-list service provider instructs the large aircraft operator that a passenger must be denied boarding, the large aircraft operator would not be able to permit the passenger to board unless explicitly authorized by TSA.

Additionally, if the aircraft operator becomes aware that any data element in the passenger information has changed, the large aircraft operator would be required to transmit to the watch-list service provider updated passenger information, which includes the full name, and if available, gender, date of birth, redress number, and passport information. If the large aircraft operator sends updated passenger information to the watch-list service provider for a passenger for whom the service provider has already transmitted instruction, the large aircraft operator would not be able to permit the passenger on board until the large aircraft operator receives updated instructions from the watch-list service provider. Any previous instruction regarding the passenger would be void; the large aircraft operator would be required to comply with any updated instruction from the service provider.

f.
Master passenger list.
TSA recognizes that many large aircraft operators carry the same passengers on most or all of their flights and that it would be burdensome for the large aircraft operators to send the required information for the same individuals on each flight. Consequently, the proposed rule includes a provision for a master passenger list. Under this optional proposed provision, individuals on a master passenger list would be subject to continuous vetting of their names against the watch-list.
24

TSA would not require large aircraft operators to transmit information on these passengers every time they are on a flight operated by the large aircraft operator. This master list would be applied for domestic flights only; CBP would require aircraft operators and their pilots to transmit advance passenger information to CBP for international flights departing from or arriving in the United States under CBP's eAPIS NPRM, and passengers would need to present their passports pursuant to CBP regulations.

24
The proposed rule would define “continuous vetting” as the process in which the passenger's information is continuously matched against the most current watch-list.

Prior to collecting passenger information from an individual to place that individual on a master passenger list, the large aircraft operator would be required to inform the individual that he or she would have the option of being placed on the master passenger list, to provide the individual with notice of the purpose and procedures related to a master passenger list, and to obtain from the individual a signed, written statement affirmatively

requesting that he or she be placed on a master passenger list. These requirements would ensure that individuals would be informed that their inclusion in a master passenger list would be voluntary and contingent upon their providing written consent and that a watch-list service provider would continuously maintain their passenger information and compare the information against the watch-list.

In order to place an individual on the master passenger list, the large aircraft operator would be required to comply with the following: (1) Request and obtain the full name, gender, date of birth, redress number, and passport information of the individual; (2) transmit the passenger information and any updated passenger information to a watch-list service provider and designate the individual for continuous vetting; (3) ensure that the watch-list service provider is responsible for continuous vetting for that individual at the time the individual boards an aircraft; (4) receive an instruction that the individual is cleared in response to the initial transmission of passenger information or transmission of updated passenger information; and (5) receive any instruction to prohibit the individual from boarding an aircraft.

g.
Aircraft operators under a full program.
Under 49 CFR 1544.101(a), TSA requires full program aircraft operators to conduct watch-list matching of their passengers under their security program. Some of the full program aircraft operators also operate flights under the other security programs in 49 CFR 1544.101. Many of these aircraft operators use the same system or process to conduct watch-list matching for their flights operated under their full security program, as well as flights operated under their other security programs. Under the proposed rule, TSA would require full program aircraft operators to transmit the passenger information for passengers on their flights operated under the LASP to watch-list service providers approved by TSA to conduct the watch-list matching on their behalf. TSA requests comment on whether full program aircraft operators should be permitted to conduct watch-list matching for passengers on flights operated under their LASP using the system or process that they use for flights operated under their full security program, including TSA's Secure Flight Program when it is available.

h.
Privacy notice and data retention.
TSA would only receive passenger information if the watch-list service provider's automated vetting system identifies an individual as a potential match to the watch-list; this is much like the current practice where aircraft operators conduct watch-list matching pursuant to their security programs. TSA is considering requiring aircraft operators to provide a privacy notice to passengers in the LASP. Most LASP aircraft operators do not have a reservation system and are on-demand operations, such as charter, corporate, fractional, and recreational (friends and family) operations. LASP aircraft operators may find it challenging and burdensome to provide a privacy notice to their passengers when collecting the information. TSA is seeking comments on how a privacy notice could be provided during the collection of information while considering the feasibility, costs, and effectiveness of providing such notice. Should TSA require large aircraft operators to provide a privacy notice on web sites through which passenger service is offered, either on their own web site or through an internet travel web site that offers seats on charter flights, or via other means that would provide notice to passengers on aircraft operated by LASP operators?

TSA is considering data and record retention requirements for records for watch-list service providers and large aircraft operators. TSA seeks comment on whether the proposed record retention for the Secure Flight Program should be applied to large aircraft operators and watch-list service providers to ensure that personally identifiable information is not retained for longer than necessary. As explained in the Secure Flight NPRM, TSA would retain passenger information for seven days for passengers that are cleared, seven years for passengers that have been identified as potential matches to the watch-list, and 99 years for passengers who are confirmed matches to the watch-list under the Secure Flight Program.
25

If TSA were to require a similar record retention schedule for records collected, transmitted, and received under proposed § 1544.245 and part 1544, subpart F, large aircraft operators' watch-list service providers would retain and destroy passenger information and watch-list matching results in accordance to this schedule. TSA is also considering requiring large aircraft operators and watch-list service providers to retain passenger information for passengers who are cleared, for three years, to facilitate the audit that large aircraft operators would undergo every two years under proposed § 1544.243 and compliance oversight.

25
See Secure Flight NPRM, 72 FR at 48363.

i. Secure Flight.
As noted above, the long-term plan is for TSA to assume the watch-list matching responsibility from all aircraft operators required to conduct watch-list matching and to conduct the watch-list matching through the Secure Flight Program. Under the current stage of Secure Flight development, Secure Flight will not have the capability to conduct watch-list matching for large aircraft operators for several years.

Under the Secure Flight NPRM, TSA would assume the watch-list matching only for full program operators and certain foreign air carriers. If the Secure Flight Program is capable of assuming the watch-list matching responsibility from large aircraft operators when TSA would require implementation of the LASP, TSA may amend the scope of the Secure Flight regulations to include large aircraft operators in the final rule for this NPRM.

Under the Secure Flight Program, TSA may require large aircraft operators to collect and transmit the same data elements, called Secure Flight Passenger Data (SFPD), to TSA for all passengers that full program operators must collect and transmit for their passengers. Although, in the Secure Flight NPRM, TSA did not propose to cover the large aircraft population in the Secure Flight Program, TSA is proposing, in this LASP NPRM, to align the LASP passenger information requirements with those of the Secure Flight Program. Consequently, the passenger information requirement in proposed § 1544.245 of this LASP NPRM is similar to proposed § 1560.101 in the Secure Flight NPRM.
26

TSA's intent is to align the data requirements of LASP and the Secure Flight Program, so that they match when the final rules are implemented.

26
72 FR at 48388.

The methods for transmitting SFPD to TSA would be described in the standard security program for large aircraft operators. Possible methods of transmission may include a direct connection to TSA, similar to the connection that some full program operators will establish, and an internet-based application. Similar to the requirements proposed for the watch-list service provider, large aircraft operators would not be able to board passengers until they received boarding instructions from TSA. TSA would also require large aircraft operators to comply with the boarding instructions. TSA would transmit the boarding instructions after conducting the watch-list matching of the passengers.

TSA has determined that watch-list matching of passengers on large aircraft is an important security measure, because it can prevent individuals who are believed to pose a risk from boarding a large aircraft and, potentially, gaining control of the aircraft, to use it as a weapon or to cause harm to aviation or national security. Such considerations extend beyond the simple use of aircraft as missiles, but also include aircraft as delivery vectors for other catastrophic payloads (e.g., chemical, biological, radiological or nuclear materials). Given the security concerns, TSA believes a reliable mechanism for watch-list matching for large aircraft must be operational without undue delay. The watch-list matching service providers would provide the needed security and do so in a timely fashion. While the Secure Flight Program would also provide a reliable mechanism, its ability to absorb the watch-list matching function for the large aircraft population is likely to be several years away, and it is likely that it would not be available to address this important security need when TSA would be ready to implement the LASP. Thus, TSA believes that the using the watch-list service providers will be the more viable security solution for watch-list matching when TSA is ready to implement the LASP.

While TSA anticipates that Secure Flight would be the long-term mechanism for conducting watch-list matching of passengers, TSA seeks comments on whether the watch-list matching service providers should serve as part of the long-term solution to large aircraft watch-list matching, such as by gathering the passenger information from the aircraft operators and submitting it to TSA for watch-list matching, then receiving the results from TSA. One possible advantage of the watch-list service providers may be that the master passenger list system developed by these providers would remain undisturbed, a convenience for passengers on those lists and the large aircraft operators. Additionally, TSA seeks comment on whether maintaining the watch-list matching service providers may reduce the costs associated with a transition to the Secure Flight Program. There may also be benefit to TSA in limiting the number of different entities to which the Secure Flight program would maintain direct links, requiring only links with the watch-list service providers, not all large aircraft operators.

Audit Requirement

Due to the large size and widely-dispersed geographical locations of the aircraft operator population that would be subject to this proposed rule, TSA would need an effective mechanism to verify large aircraft operators' compliance with the large aircraft program. While TSA intends to develop a compliance program for, and conduct inspections of, large aircraft operators, it is not possible for TSA to visit approximately 10,000 large aircraft operators on a regular basis.

TSA proposes the use of TSA-approved third-party auditors. These TSA-approved third-party auditors would support existing TSA resources and would enhance compliance with TSA regulations and the aircraft operator's security program. Auditors would conduct audits of large aircraft operators for their compliance with their security program and TSA regulations. The auditors would submit their findings in the manner and form prescribed by TSA. Auditors' reports would assist TSA inspectors in the conduct of compliance inspections as necessary. TSA would use the third-party auditors' reports as one tool in establishing inspection priorities. The audits would also assist large aircraft operators in assessing the security measures in place for their own aircraft.

TSA proposes to require large aircraft operators to contract with TSA-approved auditors to conduct a biennial audit of their compliance with TSA regulations and their security programs. Large aircraft operators would initially undergo an audit within 60 days of TSA's approval of the large aircraft operators' security program and then every two years thereafter. Large aircraft operators would also be required to provide auditors access to their records, equipment, and facilities necessary for the auditor to conduct an audit. The aircraft operators would receive a copy of the audit report and would be provided an opportunity to submit comments on the audit report to TSA.

In this NPRM, TSA is proposing that large aircraft operators may select any TSA-approved auditor to perform the audit function. However, TSA is considering instituting a system that would assign auditors to large aircraft operators on a random basis in order to assure overall consistency of the auditing program, thereby enhancing security. TSA seeks comment on whether to include a system of assigning auditors in the final rule and on methods of doing so.

As stated above, many full program aircraft operators also operate flights under the private charter program. TSA routinely conducts inspections of full program aircraft operators, and these inspections include any private charter operations the aircraft operators may have. Given these TSA inspections, TSA requests comment on whether it is necessary to require full program aircraft operators that also operate flights under a LASP to contract with a third party auditor to conduct a biennial audit of their operations for compliance with their security program and TSA regulations.

Unauthorized Persons and Accessible Weapons on Board Large Aircraft

TSA would require large aircraft operators to apply security measures in their security program to prevent or deter the carriage of unauthorized persons and unauthorized weapons, explosives, incendiaries, and other destructive substances or items on board a large aircraft. This proposed security measure is designed to prevent unauthorized persons, such as a stowaway, or accessible weapons, from being placed in a large aircraft. Under the proposed security measure, the large aircraft operator would check for weapons and check any container, cargo, or company material that may be used to hide a stowaway, or explosives, incendiaries, or other destructive substances or items. The security program would describe the method for conducting the checks, such as visual inspection of the exterior of the persons or containers of certain sizes and weights, with further evaluation if necessary. This proposed rule would only apply to property that may be accessible to the cabin of the aircraft. For example, if the property is stowed in a cargo hold that would not allow access to the cabin of the aircraft, then that property would be exempt from inspection.

For purposes of screening passengers on air carrier flights under a full program, TSA considers weapons to include items on its prohibited items list, which is posted on TSA's Web site at
http://www.tsa.gov.
This list includes, among other things, guns, firearms, and certain sharp objects or tools such as knives, including steak knives and pocket knives. TSA is proposing to require large aircraft operators to adopt and carry out procedures to prevent passengers from carrying prohibited items onto the aircraft. We understand, however, that large aircraft operators currently not subject to a TSA security program
27

may have special circumstances that should be considered. TSA seeks comment on the following issues: First, for large aircraft

operators that are not carrying persons or property for compensation or hire, should “weapons” be limited to guns and firearms? Further, should there be a different requirement depending on whether the aircraft has a MTOW of 45,500 kg or less or more than 45,500 kg?

27
Private charters and twelve-five operators currently must ensure there are no prohibited items accessible in the cabin.

TSA understands that a significant portion of the large aircraft population may not have inaccessible cargo hold compartments, but may have a need to transport weapons, such as when transporting hunters. Therefore, TSA proposes that weapons may be stored in a cargo hold, if the aircraft has such a cargo hold, or may be stored in a locked box in the cabin under the direct control of the in-flight security coordinator. In these instances, the weapons would be considered inaccessible to the persons on board.

Additional Requirements

The LASP would also include the following requirements: designation of Aircraft Operator Security Coordinators, Ground Security Coordinators, and In-Flight Security Coordinators; regulations concerning law enforcement personnel; the carriage of TSA Federal Air Marshals (FAMs) onboard an aircraft; the aviation security contingency plan; and procedures for handling bomb and air piracy threats. These proposed requirements are discussed in further detail in the Section-by-Section Analysis portion of the preamble.

The economic analysis for this NPRM suggests that the aircraft operator security coordinator requirement is the highest-cost measure in this proposed rule, and TSA invites comment on whether there is a more cost-effective means of meeting the same or substantially similar security goals as detailed herein. Although our preliminary view is that the benefits of the security coordinator requirements as proposed justify their costs, we are interested in comment on alternatives. Is there a current industry practice that could provide a suitable alternative? Should certain general aviation operators be exempted from the requirements or portions of the requirements? Are there operational limitations that prevent aircraft operators from designating security coordinators for multiple flight segments? TSA also invites comments on the use of a single individual for multiple security coordinator roles. Comments that specifically address the costs and benefits of alternatives to the security coordinator requirements would be welcome.

2. Aircraft of MTOW Over 45,500 kg or With a Passenger Seating Configuration of 61 Seats or More Operated for Compensation or Hire

TSA has determined that aircraft over 45,500 kilograms or with a passenger seating configuration of 61 seats or more operated for compensation or hire should be subject to increased security requirements. The current private charter program, which applies to aircraft of this size and weight, includes more security measures than the current twelve-five program. Part 125 (14 CFR) operators using this size aircraft also currently must comply with the private charter program. This approach is supported by the International Civil Aviation Organization (ICAO), which requires that aircraft of more than 60 passengers, or with a MTOW of over 45,500 kilograms, be regulated and protected from intrusion and ballistic threats.

Although the private charter program would be merged into the large aircraft program, TSA believes that maintaining a higher level of security for aircraft over 45,500 kilograms, or with a passenger seating configuration of 61 seats or more, operated for compensation or hire would be an important security measure. Thus, for these aircraft, the proposed rule would continue the requirements now in the Private Charter Program for the operators to inspect passengers and their property and to perform CHRCs on their employees who conduct screening.

3. All-Cargo Operations

TSA recently issued a final rule regarding air cargo security, including all-cargo operations in an aircraft with a MTOW over 12,500 pounds. See Final Rule for Air Cargo Security Requirements, 71 FR 30478 (May 26, 2006).
28

Because cargo security remains an important part of aviation security, TSA proposes to retain the requirements for all-cargo operations in the LASP. Consequently, large aircraft all-cargo operations would be required to comply with the cargo requirements in 49 CFR 1544.202 and 1544.205(a), (b), (d), and (f) in addition to the core requirements of the LASP.

28
The effective date of the final rule was Oct. 23, 2006.

The large aircraft all-cargo program would replace the existing Twelve-Five All-Cargo Program. Current aircraft operators that are subject to the Twelve-Five All-Cargo Program would be subject to the proposed requirements for large aircraft in all-cargo operations. Additionally, 14 CFR part 125 operators in all-cargo operations, which currently are required to comply with the Twelve-Five All-Cargo Program, would also be subject to § 1544.202.

All-cargo operations with an aircraft with an MTOW of over 45,500 kilograms currently must use the full all-cargo program and this would be reflected in the rule.

4. Sensitive Security Information

Protection of Sensitive Security Information (SSI), as codified at 49 CFR part 1520, would apply to each aircraft operator operating under the large aircraft program. Airport and aircraft operator security programs and related amendments, Security Directives and Information Circulars, technical specifications of security screening and detection systems and devices, among other types of information, constitute SSI under current 1520.5 and are prohibited from public disclosure. Watch-list service providers' instructions to the large aircraft operators would also be SSI. The SSI regulations would apply to LASPs as well.

Access to SSI is strictly limited to those covered persons with a need to know, as defined in 49 CFR 1520.7 and 1520.11. In general, a person has a need to know specific SSI when he or she requires access to the information to carry out transportation security activities that are government-approved, -accepted, -funded, -recommended, or -directed, including for purposes of training on, and supervision of, such activities or to provide legal or technical advice to airport operators, aircraft operators or their employees regarding security-related requirements. Accordingly, the protection of SSI would apply to each large aircraft operator operating under a security program pursuant to 1544.101(b).

5. Existing and Proposed Requirements for Large Aircraft

Table 2 below illustrates the requirements for large aircraft operators and whether these requirements would be new or modified for current holders of security programs. The table indicates how the proposed rule would affect the current large aircraft operators. The first column describes the proposed content requirements for the LASP. The remaining five columns list five types of aircraft operators that would be required to adopt and implement the large aircraft security program under the proposed rule. The table indicates whether each type of aircraft operator is currently required to comply with each content requirement of the proposed LASP or whether the proposed content requirement is a new requirement for

the aircraft operator. Additionally, as part of this rule, TSA would modify some of the content requirements for the current Twelve-Five Security Program and the Private Charter Security Program. The table also indicates existing requirements that would be modified under the proposed rule.

Table 3 compares the proposed large aircraft program with the Full Program and the Full All-Cargo Program.

Table 2—Regulatory Requirements for Large Aircraft

Description of proposed LASP
requirement

Scheduled or charter operations required to have a twelve-five
program

All-cargo operations required to have a twelve-five program

Private charters required to have a private charter
program

Scheduled or charter operations in aircraft with 31-60 seats required to have a partial
program

Large aircraft operators not currently required to have a security program

Acceptance & screening of individuals and accessible property (§ 1544.201)
Does not apply
Does not apply
Currently applies and would continue
Does not apply
Does not apply.

Acceptance and screening of cargo (§ 1544.205)
Does not apply
Currently applies and would continue
Does not apply
Does not apply
Does not apply.

Persons and property on board a large aircraft (§ 1544.206)
New requirement
Does not apply
New requirement
New requirement
New requirement.

Screening of individuals and property (§ 1544.207)
Does not apply
Does not apply
Currently applies and would continue
Does not apply
Does not apply.

Required to have security coordinators (§ 1544.215)
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
New requirement.

Provision of law enforcement personnel at airports serving the aircraft operators (§ 1544.217)
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
New requirement.

Carriage of accessible weapons on board aircraft (§ 1544.219)
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
New requirement.

Requirement to transport FAMs (§ 1544.223)
Currently applies; would be modified
Currently applies; would be modified
New requirement
Currently applies; would be modified
New requirement.

Provide for security of aircraft and facilities (§ 1544.225)
New requirement
New requirement
Currently applies and would continue
New requirement
New requirement.

Security training for security coordinators and crew (§ 1544.233)
New requirement
New requirement
Currently applies and would continue
New requirement
New requirement.

Training Program—Individual security-related duties (§ 1544.235)
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
New requirement.

Program to permit passengers to provide volunteer emergency services (§ 1544.241)
New requirement
New requirement
New requirement
New requirement
New requirement.

Required to undergo third-party audits (§ 1544.243)
New requirement
New requirement
New requirement
New requirement
New requirement.

Required to send flight manifest to approved vendor for watch-list matching of passengers (§ 1544.245)
New requirement
New requirement
New requirement
New requirement
New requirement.

Security threat assessment with criminal history records check for flight crew (part 1544, subpart G)
New requirement
New requirement
New requirement
New requirement
New requirement.

Develop and implement contingency plan in response to threats (§§ 1544.301(a) & (b))
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
New requirement.

Bomb and hijacking threats (§ 1544.303)
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
New requirement.

Comply with security directives and information circulars (§ 1544.305)
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
Currently applies and would continue
New requirement.

Table 3—Comparison of Aircraft Operator Security Programs

Description of security requirement

Full program
operators

Full all-cargo program operators

Proposed large aircraft program
operators

Acceptance & screening of individuals and accessible property (§ 1544.201)
X

X

Screening of individuals and property (watch-list & accessible weapons) (§ 1544.202)

X
X

Acceptance and screening of checked baggage (§  1544.203)
X

Acceptance and screening of cargo and accessible property (§  1544.205)
X
X
X

Check property on board (§ 1544.206)

X

Screening of individuals and property (§ 1544.207)
X
X
X

Use of metal detection devices (§ 1544.209)
X
X

Use of X-ray systems (§ 1544.211)
X
X

Use of explosives detection systems (§ 1544.213)
X

Required to have security coordinators (§ 1544.215)
X
X
X

Provision for law enforcement personnel at airports serving the aircraft operators (§ 1544.217)
X
X
X

Carriage of accessible weapons on board aircraft (§ 1544.219)
X
X
X

Carriage of prisoners under the control of armed law enforcement officers (§ 1544.221)
X

Requirement to transport FAMs (§ 1544.223)
X
X
X

Provide for security of aircraft and facilities (§ 1544.225)
X
X
X

Exclusive area agreements (§ 1544.227)
X
X

Access to cargo and security threat assessments for cargo personnel in the United States (§ 1544.228)
X
X

CHRC: Unescorted access to SIDA, screening, baggage/cargo checks (§ 1544.229)
X
X

CHRC: Flight crew members (§ 1544.230)
X
X

Airport-approved and exclusive area personnel identification systems (§ 1544.231)
X
X

Security training for security coordinators and crew (§ 1544.233)
X
X
X

Training Program—Individual security-related duties (§ 1544.235)
X
X
X

Flight deck privileges (§ 1544.237)
X
X

Program to permit passengers to provide volunteer emergency services (§ 1544.241)
X

X

Required to undergo third-party audits (§ 1544.243)

X

Required to send flight manifest to approved vendor for watch-list matching of passengers (§ 1544.245)

X

Security threat assessment with criminal history records check for flight crew, individuals authorized to perform screening functions, applicants to become TSA-approved auditors, and watch-list service provider cover personnel (Part 1544, subpart G)

X

Develop and implement contingency plan in response to threats (§ 1544.301)
X
X
X

Bomb and hijacking threats (§ 1544.303)
X
X
X

Comply with security directives and information circulars (§ 1544.305)
X
X
X

B. Proposed Requirements for Certain Airports

Currently, the regulations extend airport security program requirements to airports that regularly serve aircraft operations using full programs, partial programs, private charter programs, and corresponding foreign air carriers.
29

These regulations for airport operators provide for the safety and security of persons and property on an aircraft operating in air transportation against an act of criminal violence and aircraft piracy. An enhanced security environment at the airports where large aircraft operate would support enhanced security for the large aircraft. Thus, as part of the proposal to provide security for large aircraft through a large aircraft program for aircraft operators, TSA also proposes to require certain airports that serve large aircraft to adopt a security program.

29
49 CFR 1544.101(a), (b), and (f), and 1546.101(a), (b), (c), and (d). However, there are no airports that currently hold a security program because they regularly serve an aircraft operator holding a partial program or a private charter program, or their foreign air carrier equivalent.

There are thousands of GA airports that serve large aircraft. TSA considered the heavy burden involved for all these airports to adopt a security program. Many are very small and may have limited resources and limited large aircraft activity. TSA proposes to require two types of airports to hold a security program because of the type of service they provide.

The first type of airport that would be required to hold a partial program is a GA airport that is designated as a “reliever” airport by the Secretary of Transportation, as defined in 49 U.S.C. 47102(22). These airports perform the function of relieving congestion at a commercial service airport by diverting GA from the commercial services airport to the reliever airport and provide more GA access to the overall community. Reliever airports are generally near metropolitan areas and thus serve and are close to large populations—thus the need for greater security at these airports.

The second type of airport is an airport that regularly serves scheduled or public charter operations in large aircraft. These operations have fare-paying passengers on a regular basis. TSA proposes to require these airports to adopt the partial program. This program would provide a basic level of security enhancement to compliment and support the security measures that TSA would require large aircraft operators to adopt and implement.

Table 4 below illustrates how the proposed rule would affect the various types of airports. Table 5 compares the three types of airport security programs—complete program, supporting program, and partial program. TSA believes that the requirements of the partial program for airport operators would not be burdensome for reliever airports, and airports that regularly serve scheduled or public charter operations, to adopt and carry out. TSA also believes that the requirement for these airports to implement security programs will not place a significant burden on local law

enforcement agencies, because TSA expects that there will be few incidents requiring law enforcement response at these airports.

Table 4—Airport Operator Security Programs

An airport operator must have this program
Current: If it regularly serves aircraft operations under these security programs in 49 CFR
Proposed: If it meets the following criteria:

Complete program § 1542.101(a)
full program under § 1544.101(a)(1); or foreign air carrier program under § 1546.101(a)
No change.

Supporting program § 1542.101(b)
full program under § 1544.101(a)(2); or
Regularly serves full program aircraft operator under § 1544.101(a)(2) (no change); or

private charter program under § 1544.101(f); or
Regularly serves foreign air carrier aircraft operator program under § 1546.101(b) (no change); or

foreign air carrier program under § 1546.101(c)
Regularly serves foreign air carrier under § 1546.101(c) (no change).

Partial program § 1542.101(c)
partial program under § 1544.101(b); or
Regularly serves large aircraft operator in scheduled or public charter passenger operations under § 1544.101(b); or

foreign air carrier program under § 1546.101(d)
Is a reliever airport.

None required *
twelve-five program under § 1544.101(d)
Large aircraft not described above.

None required *
limited program under § 1544.101(g)
No change.

None required *
full all-cargo program under § 1544.101(h)
No change.

* TSA may enter airports to inspect an aircraft operator that is operating under a part 1544 or 1546 security program. 49 CFR 1542.5(e).

Table 5—Comparison of Airport Security Programs

Description of security requirement
Complete program
Supporting program
Partial program

Designate Airport Security Coordinator (§ 1542.3)
X
X
X

Description of secured areas of the airport
X

Description of the Airport Operations Area
X

Description of the Security Identification Display Area (SIDA)
X

Description of the sterile area
X

Criminal history records check of airport operator, airport user, individuals with unescorted access to a SIDA, and individuals seeking unescorted access authority
X

Description of personnel identification systems (§ 1542.211)
X

Escort procedures (§ 1542.211(e))
X

Challenge procedures (§ 1542.211(d))
X

Training program for individuals performing security-related functions for the airport operator (§ 1542.213)
X

Training program for law enforcement personnel (§ 1542.217(c)(2)
X
X
X

Description of law enforcement support
X
X
X

System for maintaining records (§ 1542.221)
X
X
X

Procedures and description of facilities and equipment used to support TSA inspection of individuals, property, and aircraft operator and foreign air carrier screening functions
X

Contingency plan (§ 1542.301)
X
X

Procedures for the distribution, storage, and disposal of Sensitive Security Information (including security program, Security Directives, Information Circulars, and implementing instructions), and, as appropriate, classified information
X
X
X

Procedures for posting of public advisories (§ 1542.305))
X
X
X

Incident management procedures (§ 1542.307)
X
X
X

Alternate security procedures, if any, that the airport intends to use in the event of natural disasters, and other emergency and unusual conditions.
X

Exclusive area agreement (§ 1542.111)
X

Airport tenant security program (§ 1542.113)
X

In addition to the two types of airports in the proposed rule text, TSA requests comments on whether other types of airports should also be required to adopt a security program, such as the partial program. For example, should TSA require airports that regularly serve aircraft used in private charter operations-aircraft with MTOW of over 45,500 kilograms or a passenger seating configuration of 61 or more seats—to adopt a partial program? If TSA were to adopt such an approach, how should TSA determine whether an airport “regularly serves” a large aircraft with MTOW of over 45,500 kilograms or a passenger seat configuration of 61 or more seats? Should TSA require airports that serve any large aircraft with MTOW of over 45,500 kilograms or a passenger seat configuration of 61 or more seats to adopt a partial program, regardless of frequency?

In addition to the proposed amendments to § 1542.101(b) and (c), TSA is seeking comments on whether the content requirements of the partial program and the supporting program should be amended. For example, TSA is considering whether it should require airport security coordinators at locations with partial programs to undergo the same security training that airport security coordinators at locations with a supporting or complete program under § 1542.3 undergo or whether a shorter training program would be appropriate.

TSA is also considering whether airport operators should be required to

undertake a risk-based self assessment of their security programs. The “TSA Information Publication (A-001), Security Guidelines for General Aviation,” includes the Airport Characteristic Measurement Tool, which lists the most significant airport characteristics that can potentially affect a facility's security posture.

TSA may develop a computer based training, available online or in a DVD format, which incorporates GA security awareness, elements of the existing “TSA Information Publication (A-001), Security Guidelines for General Aviation Airports,” and industry best practices. Airport operators may be able to use this training and accompanying self-assessment tool to fulfill a risk-based self assessment should TSA decide to include it as part of the partial program.

C. Passenger Checking Against the Watch-List

As discussed above in section II.A of the preamble, the proposed rule would require large aircraft operators to transmit passenger information to third-party entities called watch-list service providers to conduct watch-list matching of their passengers. Because watch-list service providers would perform an important security function, TSA is proposing to require potential watch-list service providers to obtain approval from TSA prior to conducting watch-list matching for any large aircraft operator. The proposed approval process would ensure that the watch-list service provider has the appropriate personnel and systems to process and keep secure sensitive and personally identifiable information.

The following are the major requirements that potential watch-list matching service providers would have to satisfy to obtain approval from TSA. The individual requirements are described and discussed in further detail in the section-by-section analysis of proposed § 1544.503.

• Demonstrate ability to conduct automated watch-list matching and continuous vetting.

• Adopt and implement a system security plan for the system that contains personally identifiable information or is used to conduct watch-list matching.

• Demonstrate ability to receive passenger information from large aircraft operators and transmit watch-list matching results back to large aircraft operators.

• Successfully undergo a suitability assessment by TSA.

• Watch-list service provider's covered personnel would be required to successfully complete security threat assessments.

• Adopt a security program that complies with TSA requirements.

The proposed rule describes the approval process that would apply and includes a provision allowing prospective watch-list service providers to seek reconsideration of an initial disapproval.

Once TSA approves a watch-list service provider, the provider would have several responsibilities. TSA lists the major responsibilities below and then describes them in greater detail in the section-by-section analysis of proposed §§ 1544.513 and 1544.515.

• Carry out its security program, which details the requirements for conducting watch-list matching, security of the systems and physical property used to conduct watch-list matching, and training of personnel.

• Develop and execute procedures to identify, handle, and protect Sensitive Security Information and maintain the confidentiality of other information provided by TSA and aircraft operators.

• Submit to inspection by TSA.

Under the proposed rule, TSA would retain the authority to withdraw a watch-list service provider's approval to conduct watch-list matching if the watch-list service provider failed to meet the qualification requirements or its responsibilities under the rule or if it were in the interest of transportation or national security. Watch-list service providers would be able to seek reconsideration of the withdrawal of approval to conduct watch-list matching from the Assistant Secretary or designee.

D. Third-Party Audits for Large Aircraft Operators

As described in section II.A of this NPRM, TSA would require large aircraft operators to contract with TSA-approved auditors to conduct audits of their compliance with TSA regulations and their security programs. To ensure that auditors have the qualification and responsibilities to produce audits that would be useful to TSA and the large aircraft operators and to identify, handle, and protect Sensitive Security Information and other sensitive information, TSA proposes the following major qualifications and responsibilities that would apply to auditors. These qualifications and responsibilities, as well as other requirements, are described and discussed in further detail in the section-by-section analysis of proposed part 1522.

• Successfully undergo a TSA security threat assessment.

• Currently hold or be able to obtain a certification or accreditation from an organization recognized by TSA.

• Have sufficient knowledge and skills to conduct a security audit of an aircraft operator.

• Receive initial and biennial training.

• Conduct independent and impartial audits, submit audit reports to TSA, and retain audit reports for 36 months.

• Identify, handle, and protect Sensitive Security Information and keep confidential other information provided by TSA and large aircraft operators.

• Submit to inspection by TSA.

The proposed rule describes the approval process that would apply to auditors. Auditors would be able to seek reconsideration of the disapproval to be a TSA-approved auditor from the Assistant Secretary or designee.

Under the proposed rule, TSA would be able to withdraw approval of an auditor or responsibilities under the proposed rule or in the interest of transportation or national security. Auditors would be able to seek reconsideration of the withdrawal of approval to conduct audits from the Assistant Secretary or designee.

E. Proposed Amendments to the Full Program and the Full All-Cargo Program

As part of this NPRM, TSA is also proposing a few minor amendments to the full program and the full all-cargo program. TSA proposes to require these aircraft operators to provide the following information when they submit their security program for approval under § 1544.105: business name; other names including ``doing business as''; state of incorporation; tax identification number; and the address of the aircraft operator's primary place of business or headquarters. This information would provide TSA the means to identify the aircraft operators and to obtain basic information about the aircraft operator in the course of reviewing a new security program for approval.

Additionally, TSA proposes to add a provision of voluntary services to the full program and the full all-cargo program, as explained in further detail in the section-by-section analysis of proposed § 1544.241. Finally, as explained in the section-by-section analysis of § 1544.101, TSA proposes to clarify that the full program applies to operators holding FAA operating certificates under 14 CFR part 119 and that the full all-cargo program applies to operators holding FAA operating certificates under 14 CFR part 119 or part 125.

III. Section-By-Section Analysis

The proposed rule sets forth the security regulations that would apply to large aircraft operators, including the requirements for the security program. TSA is also proposing to amend several other sections of part 1544 and adding new subparts F and G to set forth the procedures for watch-list service providers to obtain TSA approval and for large aircraft flight crews, auditors, and watch-list service providers' covered personnel to obtain security threat assessments, respectively. TSA is proposing to add a new provision in part 1540 to govern withdrawals of approved security programs. In addition, TSA is proposing to add a new part 1522, which establishes procedures for accrediting third-party auditors and for prescribing their functions in the LASP program. With respect to airports serving large aircraft, TSA is proposing to amend portions of part 1542 by regulating reliever airports, as designated by the Secretary of Transportation. TSA is also proposing changes to part 1520 to include the proposed LASP in the coverage of the regulations regarding Sensitive Security Information and minor changes to part 1550 to maintain consistency between regulations.

Part 1520—Protection of Sensitive Security Information

Section 1520.5 Sensitive Security Information

TSA proposes to amend § 1520.5(b)(1)(i) to protect watch-list service provider security programs as Sensitive Security Information. The watch-list service provider would have access to, and handle information on, the No Fly and Selectee Lists, which are SSI. The proposed change to this section would protect this SSI from unauthorized disclosure by the TSA-approved auditor, the watch-list service provider, the aircraft operator, or any other covered person.

Section 1520.7—Covered Persons

As explained in the section-by-section analysis of proposed part 1522 and § 1544.243, TSA would require large aircraft operators to engage independent TSA-approved auditors to audit their compliance with their security programs and TSA regulations. TSA-approved auditors would have access to and handle SSI regarding the aircraft operator and TSA security standards as they relate to large aircraft operators. Similarly, the watch-list service provider would have access to and handle the No Fly and Selectee Lists, which are SSI. Accordingly, TSA would amend § 1520.7(a) to include TSA-approved auditors and watch-list service providers as covered persons that are subject to the requirements of part 1520 as they apply to SSI.

Part 1522—TSA Approved Auditors

As described in section II.D, aircraft operators subject to this rule would need to engage independent TSA-approved auditors to audit their compliance with their security programs. TSA is proposing a new part 1522 to establish a framework for this new third-party auditor program. This third-party auditor program would initially apply only to aircraft operators under the LASP. TSA may expand its use to other programs in the future. The broad scope of part 1522 would allow TSA to use the process set forth in part 1522 for other programs that it may determine may benefit from an audit program.

Part 1522 would have two components: (1) qualifications and procedures for individuals who seek TSA's approval for conducting audits; and (2) specific qualifications and required content of audit reports for the LASP. The first of these components would apply to all programs in which TSA would require third-party auditors. The second component would apply to the LASP.

Subpart A—General

Section 1522.1 Scope and Terms Used in This Part

Proposed § 1522.1 explains that individuals who wish to conduct audits of operators' compliance with security programs must obtain TSA's approval in accordance with part 1522. Section 1522.1 also defines terms used in the subpart. Proposed § 1522.1 defines “applicant” to mean the individual who is seeking to become a TSA-approved auditor.

Section 1522.1 defines “conflict of interest” as a situation when the TSA-approved auditor has a personal impairment that might affect their ability to do their work and report their findings impartially. This definition is derived from the Government Auditing Standards established by the Government Accountability Office (GAO) for ensuring that auditors do not have personal impairments that would interfere with their ability to maintain their independence. The proposed definition includes examples of conflict of interest situations, such as family or employment relationships. Relationships with family members that may be a conflict of interest would include relationships with parents, children, and siblings.

Other proposed examples of conflict of interest include financial relationships and business relationships between the auditor and the operators to be audited. Financial interest would include, for example, the auditor owning stocks or bonds of the operator or the auditor having an employment, rather than a contractual, relationship with the operator. Examples of business relationships that would give rise to a conflict of interest would be where the auditor had previous decision-making or managerial authority that would affect current operations or program being audited. Additionally, an auditor or the company that employs the auditor would not be able to provide non-audit services to the operator if the non-audit services relate to the operator's security program. TSA seeks comments on these examples as well as suggestions for other examples that TSA should consider. TSA is also considering expressing the conflict of interest concept as auditor independence. Rather than defining and prohibiting conflicts of interest, TSA would define independence and would require an auditor to have independence from the entity the auditor would audit. If TSA were to adopt a definition of “independence” in the final rule, the definition of “independence” would describe circumstances similar to those described in the proposed definition of “conflict of interest.” This approach would be consistent with the GAO's Government Auditing Standards and the Securities and Exchange Commissions regulations at 17 CFR 210.2-01 concerning audits by certified public accountants.

The final definition in proposed § 1522.1 is “TSA-approved auditor” or “auditor.” These terms would mean an individual who has been approved under proposed part 1522 to conduct an audit under 49 CFR chapter XII.

Section 1522.3 Qualifications

Section 1522.3 would establish qualifications for third-party auditors that would apply to such auditors in any program in which TSA would require their use. These qualifications are designed to ensure that auditors have the resources and expertise required to conduct an audit and to prepare the required reports. With respect to qualifications, TSA is proposing that auditors have experience with Federal statutes and regulations and have a certification or accreditation from a highly-regarded organization in the appropriate field. Such an organization might include, for

example, the International Standards Organization. For auditors that would be involved with the large aircraft program, the International Civil Aviation Organization or the International Business Aviation Council would also be acceptable. TSA would make publicly available a list of acceptable accreditation or certification organizations. TSA requests comments on whether this qualification is appropriate and on other organizations that might have the stature to provide the necessary certification or accreditation.

Finally, applicants would be required to undergo a successful security threat assessment that includes a criminal history records check.

The proposed rule text does not require auditors to be U.S. citizens, U.S. nationals, or lawful permanent residents of the United States. We invite comments on whether individuals with these important duties should be subject to such a qualification.

Section 1522.5 Application

Proposed § 1522.5 describes the information and documentation that applicants would be required to submit to TSA. The information would include the applicant's name, business address, business phone number, and business e-mail address. TSA would also require the applicant to submit a copy of his or her accreditation or certification from one of the organizations TSA determines are acceptable for this purpose and a statement of how he or she meets the requirements in proposed § 1522.3.

Section 1522.7 TSA Review and Approval

Proposed § 1522.7 describes the review and approval process which TSA would carry out upon receipt of the auditor's application. The procedures by which TSA would review applications for the third-party auditor program may involve several steps. After TSA receives an application, TSA would decide whether to approve or disapprove the application and would send a written notice of approval or disapproval to the applicant. If the application is disapproved, the applicant would be able to seek reconsideration under proposed § 1522.9.

Section 1522.9 Reconsideration of Disapproval of an Application

Proposed § 1522.9 describes the review and petition process for reconsideration of disapproval of the auditor's application. If an applicant seeks to challenge the disapproval of his or her application, the applicant would be required to submit a written petition for reconsideration within 30 days of receipt of the notice of disapproval. The petition would include a statement explaining why the applicant believes he or she meets the criteria in § 1522.3 with any supporting documentation. Reconsideration may result in confirmation of the disapproval or in a determination that the application should be approved.

Section 1522.11 Withdrawal of Approval

Under proposed § 1522.11, TSA would be able to withdraw the approval of an auditor if the auditor ceased to meet the qualification standards, the auditor failed to meet his or her responsibilities, or it is in the interest of security or the public. If TSA withdraws an auditor's approval, the auditor would no longer be able to perform an audit under TSA regulations.

Under proposed § 1522.11, before revoking an auditor's authority, TSA would provide the auditor with a proposed notice of withdrawal of approval that would include the basis for the withdrawal of approval. The auditor would be able to file a written petition for reconsideration to challenge the proposed notice. To challenge the proposed notice of withdrawal of approval, an auditor would be required to submit the petition for reconsideration within 30 days of receipt of the proposed notice. Reconsideration may result in confirmation of the disapproval or in a determination that the application should be approved. If the auditor does not file a petition for reconsideration, the proposed notice of withdrawal of approval would become a final notice 31 days after the auditor receives the proposed notice.

In emergency situations, proposed § 1522.11 would allow TSA to issue an emergency notice of withdrawal of approval that would be effective upon receipt by the auditor. The auditor would be able to challenge the emergency notice of withdrawal of approval by submitting a written petition for reconsideration but submission of the petition would not stay the withdrawal of approval.

Section 1522.13 Responsibilities of TSA-Approved Auditors

Proposed § 1522.13 prescribes the responsibilities of TSA-approved auditors. Auditors would not be allowed to undertake an audit where the auditor had a conflict of interest as defined in proposed § 1522.1. Auditors would be required to submit reports to TSA that meet TSA standards for the particular program. Auditors would be required to comply with TSA's regulations for identifying, handling, and protecting SSI. Under this section, auditors would also be prohibited from disclosure of any proprietary information. Importantly, if an auditor conducting an audit believes that there is an instance of noncompliance that presents an imminent threat to transportation security or public safety, the auditor would be required to notify TSA immediately. The auditor would not be authorized to require any remedial action.

Section 1522.15 Fraud and Intentional Falsification of Records

Proposed § 1522.15 includes provisions that would prohibit any person from making or providing any fraudulent statements, reports, records, access mediums, or identification. Any falsification of records or fraudulent actions would be a violation of the regulations and 18 U.S.C. 1001, and it would be a basis for TSA to withdraw the auditor's approval under proposed § 1522.13.

Section 1522.17 Inspections

Under proposed § 1522.17, auditors would be required to permit TSA to inspect their facilities and copy records. This section would allow TSA to evaluate the auditor's performance and an operator's compliance with TSA regulations and its security program.

Subpart C—Auditors for the Large Aircraft Security Program

Section 1522.201 Applicability

Proposed § 1522.201 states that subpart C would apply to auditors seeking to obtain TSA's approval to conduct audits for the large aircraft program.

Section 1522.203 Additional Qualification Requirements

Proposed § 1522.203 describes the additional requirements that auditors for the LASP would be required to meet to be considered for approval. These requirements would include:

• At least five years of experience in inspection or auditing relating to governmental programs in security or aviation;

• Three professional references;

• Accreditation from an outside organization within the last ten years; and

• Knowledge and ability to assess compliance with Federal statutes and regulations.

These additional requirements would demonstrate that the auditor possesses

sufficient experience and knowledge in auditing compliance with governmental programs and that the auditor has credentials that reflect knowledge of the aviation industry. Auditors would be able to satisfy the five-year experience requirement as a government employee or private consultant or contractor. TSA requests comments on these requirements as well as other requirements that TSA should consider for auditors of LASPs.

Section 1522.205 Audit Report

Section 1522.205 would require an auditor to prepare an audit report that would include information about the audit process and the auditor's findings and conclusions of the audit. TSA would require the auditor to submit the audit report within 30 days after the audit was conducted. TSA would also require the auditor to sign an attestation that the audit was performed professionally and impartially. The audit report would be an important tool in TSA's compliance program by enabling TSA to evaluate a large aircraft operator's compliance with TSA regulations and the operator's security program and to ascertain if additional TSA action is required.

Section 1522.207 Training

Under proposed § 1522.207, TSA would require auditors to undergo initial and recurrent training. Through the initial training, auditors would acquire the necessary information on the process, procedures, and forms associated with the TSA-required audit. Recurrent TSA prescribed training would provide auditors with up-to-date information and would ensure that the auditor has maintained the necessary expertise to continue to perform audits. Recurrent training would be required every 24 months.

Section 1522.209 Biennial Review

To ensure that a TSA-approved auditor continues to possess the requisite qualification and expertise to conduct audits, TSA would require the auditor to submit to a biennial review. The review would consist of submitting evidence that an auditor's training has been successfully completed and is current and that an auditor continues to hold the necessary accreditation or certification.

Part 1540—Civil Aviation Security: General Rules

Section 1540.107 Submission to Screening and Inspection

As discussed in section II.A, TSA would require large aircraft operators to contract with a watch-list service provider to determine whether their passengers may board the aircraft. Watch-list service providers, who must be approved by TSA, would compare passenger names against the watch-list.

Under proposed § 1544.245(b), large aircraft operators would be required to request and obtain the full name of their passengers to transmit their passengers' information to a watch-list service provider to conduct watch-list matching prior to the passengers boarding the aircraft. Because full name is essential in conducting effective watch-list matching, TSA proposes to require passengers to provide their full name when the large aircraft operator requests their full name.

TSA has published the Secure Flight NPRM, which also includes a proposal to require individuals who make reservations for a covered flight to provide their full names.
30

Under the proposed Secure Flight Program, full name would be the full name that appears on the individual's verifying identity document. A verifying identity document would be an unexpired photo identification issued by a government (Federal, State, or tribal) bearing the individual's full name and date of birth or an unexpired foreign passport. Examples of verifying identity documents are driver's licenses and passports. Accordingly, proposed § 1540.107(c) would apply the

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3AE8-23685. Public record. Not legal advice.
