New
collection (Request for a new OMB Control Number)
No
Regular
02/03/2022
Requested
Previously Approved
36 Months From Approved
145
0
73
0
2,416
0
As a result of proposed rule, RIN
2105-AE26: Streamline and Update the Department of Transportation
Acquisition Regulation posted to the Federal Register, 86FR69452 on
December 7, 2021, TAR Case 2020-001, this is a request from the
Department of Transportation (DOT) for OMB approval of a new
Information Collection (IC). Under Public Law 113-283, Federal
Information Security Modernization Act of 2014, each agency of the
Federal Government must provide security for the information and
information systems that support the operations and assets of the
agency, including those provided or managed by another agency,
contractor, or other source. To comply with Public Law 113-283,
Federal Information Security Modernization Act of 2014, DOT
developed clauses 1252.239-72, Compliance with Safeguarding DOT
Sensitive Data Controls, and 1252.239-74, Safeguarding DOT
Sensitive Data and Cyber Incident Reporting. These clauses contain
the following information collection requirements from the public:
1252.239-72, Compliance with Safeguarding DOT Sensitive Data
Controls: Requires contractors to submit to the Government the
submittal and approval(s) of current or previous NIST 800-171
Variance requests and approvals. 1252.239-74, Safeguarding DOT
Sensitive Data and Cyber Incident Reporting: Requires contractors
to submit to the Government— • Submittal and approval(s) of current
or previous NIST 800-171 Variance requests and approvals, along
with subcontractor reporting of the same; • Cyber incident
reporting and assessment; and subcontractor reporting of the same;
• Submittal of malicious software; and • Submittal of media images
of known information systems and relevant monitoring / packet
capture data.
PL:
Pub.L. 113 - 283 1 Name of Law: Federal Information Security
Modernization Act of 2014
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.