Enhancing Surface Cyber Risk Management

ICR 202409-1652-001

OMB:

Federal Form Document

Forms and Documents
Document
Name
Status
Supporting Statement A
2024-11-07
Supplementary Document
2024-04-12
Supplementary Document
2024-04-12
IC Document Collections
IC ID
Document
Title
Status
266906 Unchanged
266905 Unchanged
266904 Unchanged
266903 Unchanged
266902 Unchanged
266901 Unchanged
266900 Unchanged
266899 Unchanged
266898 Unchanged
266897 Unchanged
266896 Unchanged
266895 Unchanged
266894 Unchanged
266893 Unchanged
266892 Unchanged
266891 Unchanged
266890 Unchanged
266888 Unchanged
266887 Unchanged
266886 Unchanged
266883 Unchanged
266881 Unchanged
266877 Unchanged
266875 Unchanged
266874 Unchanged
266871 Unchanged
266869 Unchanged
266868 Unchanged
266866 Unchanged
266864 Unchanged
266862 Unchanged
266860 Unchanged
266855 Unchanged
266853 Unchanged
266849 Unchanged
266848 Unchanged
266846 Unchanged
266845 Unchanged
266842 Unchanged
266839 Unchanged
266838 Unchanged
266836 Unchanged
266835 Unchanged
266818 Unchanged
ICR Details
202409-1652-001
Received in OIRA 202403-1652-002
DHS/TSA
Enhancing Surface Cyber Risk Management
New collection (Request for a new OMB Control Number)   No
Regular 11/12/2024
  Requested Previously Approved
36 Months From Approved
535,070 0
99,790 0
0 0

TSA’s Enhancing Surface Cyber Risk Management (CRM) Notice of Proposed Rulemaking (NPRM) codifies the cybersecurity requirements in these SDs along with additional requirements, and reorganizes these requirements to align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by the Cybersecurity Infrastructure and Security Agency (CISA) . The CRM NPRM addresses the pervasive cybersecurity threats to the Nation’s most critical pipeline, freight, and public transportation and passenger rail infrastructure.

PL: Pub.L. 110 - 53 1405
   PL: Pub.L. 110 - 53 1512
   PL: Pub.L. 110 - 53 1531
   US Code: 49 USC 114
  
None

1652-AA74 Proposed rulemaking 89 FR 88488 11/07/2024

No

44
IC Title Form No. Form Name
FR - CAP Annual Report of Scheduled Testing of COIP - 30 % annually and 100% every 3 years – A part of CAP (Reporting)
FR _ Accountable Executive Information Submission - Included in COIP (Reporting)
FR _ Annual Identification of Critical Cyber Systems - Included in COIP (Recordkeeping)
FR _ CIRP Annual Exercise - Included in COIP (Record keeping)
FR _ Compliance Recordkeeping
FR _ Cybersecurity Assessment Plan (CAP) for TSA Approval (Reporting)
FR _ Cybersecurity Coordinator Information Submission - Included in COIP (Reporting)
FR _ Cybersecurity Evaluation (CSE) - Owner/operator holds for TSA inspection (Record keeping)
FR _ Cybersecurity Incident Response Plan (CIRP) - Included in COIP (Record keeping)
FR _ Cybersecurity Operational Implementation Plan (COIP) Submission - Submitted to TSA for review and approval (Reporting)
FR _ Cybersecurity Training Recordkeeping - Included in COIP (Record keeping)
FR _ Initial Cybersecurity Training Plan Development and Submission - Included in COIP (Reporting)
FR _ Initial Identification of Critical Cyber Systems and Network Architecture - Included in COIP (Record keeping)
FR _ Modified Cybersecurity Training Plan Development and Submission - Included in COIP (Reporting)
PTPR _ Accountable Executive Information Submission - Included in COIP (Reporting)
PTPR _ Annual Identification of Critical Cyber Systems - Included in COIP (Recordkeeping)
PTPR _ CAP Annual Report of Scheduled Testing of COIP - 30 % annually and 100% every 3 years – A part of CAP (Reporting)
PTPR _ CIRP Annual Exercise - Included in COIP (Record keeping)
PTPR _ Compliance Recordkeeping
PTPR _ Cybersecurity Assessment Plan (CAP) for TSA Approval (Reporting)
PTPR _ Cybersecurity Coordinator Information Submission - Included in COIP (Reporting)
PTPR _ Cybersecurity Evaluation (CSE) - Owner/operator holds for TSA inspection (Record keeping)
PTPR _ Cybersecurity Incident Response Plan (CIRP) - Included in COIP (Record keeping)
PTPR _ Cybersecurity Operational Implementation Plan (COIP) Submission - Submitted to TSA for review and approval (Reporting)
PTPR _ Cybersecurity Training Recordkeeping - Included in COIP (Record keeping)
PTPR _ Initial Identification of Critical Cyber Systems and Network Architecture - Included in COIP (Record keeping)
PTPR _ Modified Cybersecurity Training Plan Development and Submission - Included in COIP (Reporting)
PTPR_Initial Cybersecurity Training Plan Development and Submission - Included in COIP (Reporting)
Pipelines - Physical Security Coordinator Information Submission (Reporting)
Pipelines _ Accountable Executive Information Submission - Included in COIP (Reporting)
Pipelines _ Annual Identification of Critical Cyber Systems - Included in COIP (Recordkeeping)
Pipelines _ CAP Annual Report of Scheduled Testing of COIP - 30 % annually and 100% every 3 years – A part of CAP (Reporting)
Pipelines _ CIRP Annual Exercise - Included in COIP (Record keeping)
Pipelines _ Compliance Recordkeeping
Pipelines _ Cybersecurity Assessment Plan (CAP) for TSA Approval (Reporting)
Pipelines _ Cybersecurity Coordinator Information Submission - Included in COIP (Reporting)
Pipelines _ Cybersecurity Evaluation (CSE) - Owner/operator holds for TSA inspection (Record keeping)
Pipelines _ Cybersecurity Incident Response Plan (CIRP) - Included in COIP (Record keeping)
Pipelines _ Cybersecurity Operational Implementation Plan (COIP) Submission - Submitted to TSA for review and approval (Reporting)
Pipelines _ Cybersecurity Training Recordkeeping - Included in COIP (Record keeping)
Pipelines _ Initial Cybersecurity Training Plan Development and Submission - Included in COIP (Reporting)
Pipelines _ Initial Identification of Critical Cyber Systems and Network Architecture - Included in COIP (Record keeping)
Pipelines _ Modified Cybersecurity Training Plan Development and Submission - Included in COIP (Reporting)
Pipelines _ Report Significant Physical Security Concerns to TSA (Reporting)

  Total Request Previously Approved Change Due to New Statute Change Due to Agency Discretion Change Due to Adjustment in Estimate Change Due to Potential Violation of the PRA
Annual Number of Responses 535,070 0 0 535,070 0 0
Annual Time Burden (Hours) 99,790 0 0 99,790 0 0
Annual Cost Burden (Dollars) 0 0 0 0 0 0
Yes
Changing Regulations
No
This is a new collection, stemming from the CRM NPRM.

$1,633,316
No
    No
    No
No
No
No
No
Nicole Raymond 703 507-0442 [email protected]

  No

On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
 
 
 
 
 
 
 
    (i) Why the information is being collected;
    (ii) Use of information;
    (iii) Burden estimate;
    (iv) Nature of response (voluntary, required for a benefit, or mandatory);
    (v) Nature and extent of confidentiality; and
    (vi) Need to display currently valid OMB control number;
 
 
 
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.
11/12/2024


© 2024 OMB.report | Privacy Policy