On December 17, 2021, TSA issued the Security Directive (SD) 1580-21-01 series, Enhancing Rail Cybersecurity, and the SD 1582-21-01 series, Enhancing Public Transportation and Passenger Railroad Cybersecurity, which remain in effect as revised, mandating TSA-specified Owner/Operators of âhigher riskâ railroads and rail transit systems, respectively, to implement an array of cybersecurity measures to prevent disruption and degradation to their infrastructure; these security directives became effective December 31, 2021. In addition, on October 18, 2022, TSA issued the SD 1580/1582-2022-01 series, Rail Cybersecurity Mitigation Actions and Testing, which applies to Owner/Operators of the âHigher Riskâ freight railroads identified in 49 CFR 1580.101 and additional TSA-designated freight and passenger railroads. This security directive, which is complementary to the requirements in the previous directives, took effect on October 24, 2022. On October 26, 2022, OMB approved TSAâs request for an emergency approval, revising this information collection. See ICR Reference Number: 202210-1652-001. The collection covers both mandatory reporting under the security directives and collection of information voluntarily submitted under Information Circular (IC) 2021-01, Enhancing Surface Transportation Cybersecurity, which recommended voluntary implementation of actions and reporting by Owner/Operators not covered by the security directives. The OMB approval allowed for the additional institution of mandatory reporting requirements and collection of information voluntarily submitted. See ICR Reference Number: 202111-1652-003.
No program changes. However, TSA made several adjustments to this collection to more accurately estimate the costs associated with this collection. TSA updated the number of Owner/Operators that are subject to the information collection required by the SD series. The collection previously applied to 73 Owner/Operators and now it applies to 67 Railroads and/or Passenger rail operations. TSA also updated the number of freight rail, passenger rail, and OTRB entities that are subject to the collection required by the SD series and IC series. The collection previously applied to 457 freight rail entities, 115 passenger rail entities, and 209 OTRB entities. This updated collection now applies to 449 freight rail entities, 242 passenger rail entities, and 72 OTRB entities. In addition, all industry wage rates have been updated from 2021 to 2023 values.
Estimated hour burdens for respondents no longer include burden costs associated with the initial development and submission of the Cybersecurity Implementation Plans and the Cybersecurity Incident Response Plans. Owner/Operators to which this collection applies have already developed and submitted these plans to TSA. Accordingly, $3,200,067 in costs for Owner/Operators to develop Cybersecurity Implementation Plans and $6,532,377 in costs associated with the development of the Incident Response Plans are no longer included in the burden estimates. Similarly, the Cybersecurity Vulnerability Assessment is a one-time requirement that Owner/Operators have already completed. As a result, $3,429,433 in burden costs associated with the Vulnerability Assessment are no longer included.
Time burden estimates have been updated to include costs associated with the requirement that Owner/Operators conduct an annual review of their Cybersecurity Implementation Plans and update their plans, if necessary. Previously, only the time burden costs associated with the initial development of the Implementation Plans had been included. Time burden estimates have also been updated to reflect the recurring annual cost of completing the Annual Assessment Plan Report, including the associated costs of conducting the assessment and producing the report.
Burden costs associated with the designation of Cybersecurity Coordinators have also been adjusted, as Owner/Operators have already designated individuals to fill this role. The initial burden cost to all Owner/Operators for designating a Cybersecurity Coordinator, and an alternate, was previously estimated at $81,654. This initial cost to designate coordinators is no longer included, as the burden estimates have been revised to reflect the recurring annual costs of updating Cybersecurity Coordinator POC information, as required due to employee turnover and address updates.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.