{"operation":"document","citation":"PHMSA Guidance, Pipeline Safety: Safeguarding and Securing Pipelines From Unauthorized Access","title":"Pipeline Safety: Safeguarding and Securing Pipelines From Unauthorized Access","source_type":"guidance","agency":"Pipeline and Hazardous Materials Safety Administration","status":"guidance","official":true,"published_on":null,"effective_on":null,"summary":"Pipeline Safety: Safeguarding and Securing Pipelines From Unauthorized Access Document 2016-29500.pdf (226.83 KB) PHMSA is issuing this Advisory Bulletin in coordination with the Department of Homeland Security's (DHS), Transportation Security Administration (TSA), to remind all pipeline owners and operators of the importance of safeguarding and securing their pipeline facilities and monitoring their Supervisory Cont","machine_formats":{"json":"https://regulus.evalyn.ai/document/phmsa-guidance-pipeline-safety-safeguarding-and-securing-pipelines-9ea9b8b8.json","markdown":"https://regulus.evalyn.ai/document/phmsa-guidance-pipeline-safety-safeguarding-and-securing-pipelines-9ea9b8b8.md"},"app_url":"https://regulus.evalyn.ai/document/phmsa-guidance-pipeline-safety-safeguarding-and-securing-pipelines-9ea9b8b8","source_url":"https://www.phmsa.dot.gov/regulatory-compliance/phmsa-guidance/pipeline-safety-safeguarding-and-securing-pipelines","body":"Pipeline Safety: Safeguarding and Securing Pipelines From Unauthorized Access\n\nDocument\n\n 2016-29500.pdf (226.83 KB)\n\n        PHMSA is issuing this Advisory Bulletin in coordination with the Department of Homeland Security's (DHS), Transportation Security Administration (TSA), to remind all pipeline owners and operators of the importance of safeguarding and securing their pipeline facilities and monitoring their Supervisory Control and Data Acquisition (SCADA) systems for abnormal operations and/or indications of unauthorized access or interference with safe pipeline operations. Additionally, this Advisory Bulletin is to remind the public of the dangers associated with tampering with pipeline system facilities.This Advisory Bulletin follows recent incidents in the United States that highlight threats to oil and gas infrastructure. On October 11, 2016, several unauthorized persons accessed and interfered with pipeline operations in four states, creating the potential for serious infrastructure damage and significant economic and environmental harm, as well as endangering public safety. While the incidents did not result in any damage or injuries, the potential impacts emphasize the need for increased awareness and vigilance.\n\n          Effective Date: Friday, December 9, 2016\n\n<<<PAGE 1>>>\n\nFederal Register / Vol. 81, No. 237 / Friday, December 9, 2016 / Notices\n89183\nuntil the period of availability expires,\nthe funds are fully expended, the funds\nare rescinded by Congress, or the funds\nare otherwise reallocated. To meet\nprogram oversight responsibilities, FTA\nmust continue to collect information\nuntil the period of availability expires,\nthe funds are fully expended, the funds\nare rescinded by Congress, or the funds\nare otherwise reallocated.\nRespondents: States, Metropolitan\nPlanning Organizations, and Local\nGovernmental Authorities.\nEstimated Annual Burden on\nRespondents: 15 hours for each of the\nrespondents.\nEstimated Total Annual Burden: 303\nhours.\nFrequency: Annual.\nWilliam Hyre,\nDeputy Associate Administrator for\nAdministration.\n[FR Doc. 2016–29505 Filed 12–8–16; 8:45 am]\nBILLING CODE P\nDEPARTMENT OF TRANSPORTATION\nPipeline and Hazardous Materials\nSafety Administration\n[Docket No. PHMSA–2016–0137)\nPipeline Safety: Safeguarding and\nSecuring Pipelines From Unauthorized\nAccess\nAGENCY: Pipeline and Hazardous\nMaterials Safety Administration\n(PHMSA); DOT.\nACTION: Notice; issuance of Advisory\nBulletin.\nmstockstill on DSK3G9T082PROD with NOTICES\nharm, as well as endangering public\nsafety. While the incidents did not\nresult in any damage or injuries, the\npotential impacts emphasize the need\nfor increased awareness and vigilance.\nFOR FURTHER INFORMATION CONTACT:\nOperators of pipelines subject to\nregulation by DOT, PHMSA, should\ncontact Nathan A. Schoenkin by phone\nat 202–366–4774 or by email at\nNathan.Schoenkin@dot.gov.\nInformation about PHMSA may be\nfound at http://phmsa.dot.gov. Pipeline\noperators with questions on TSA’s\nPipeline Security Guidelines should\ncontact Steven Froehlich by phone at\n571–227–1240 or by email at\nSteven.Froehlich@tsa.dhs.gov.\nSUPPLEMENTARY INFORMATION:\nI. Background\nIncident Details\nOn Tuesday October 11, 2016,\nindividuals contacted four pipeline\noperators informing them they would\nshut down the pipelines used to\ntransport crude oil from Canada to the\nUnited States. The operators (Enbridge,\nKinder Morgan, Spectra Energy, and\nTransCanada) took steps to prevent\ndamage to the pipelines and contacted\nlocal and federal law enforcement. The\nindividuals cut the chains and padlocks\nat valve sites near Leonard, Minnesota;\nBurlington, Washington; Eagle Butte,\nMontana; and Wahalla, North Dakota.\nThe individuals then closed valves on\nEnbridge’s Lines 4 and 67, Spectra\nEnergy’s Express Pipeline, and\nTransCanada’s Keystone Pipeline. The\nKinder Morgan Trans Mountain’s Puget\nSUMMARY: PHMSA is issuing this\nSound Pipeline was not operating at the\nAdvisory Bulletin in coordination with\ntime. Several individuals were arrested\nthe Department of Homeland Security’s\nby local law enforcement.\n(DHS), Transportation Security\nHad the pipeline operators not shut\nAdministration (TSA), to remind all\ndown their lines in response to the\npipeline owners and operators of the\nthreats, a pipeline rupture could have\nimportance of safeguarding and securing\noccurred. A pipeline rupture due to\ntheir pipeline facilities and monitoring\ntampering with valves can have\ntheir Supervisory Control and Data\nsignificant consequences such as death,\nAcquisition (SCADA) systems for\ninjury, and economic and\nabnormal operations and/or indications\nenvironmental harm.\nof unauthorized access or interference\nwith safe pipeline operations.\nAdditionally, this Advisory Bulletin is\nto remind the public of the dangers\nassociated with tampering with pipeline\nsystem facilities.\nThis Advisory Bulletin follows recent\nincidents in the United States that\nhighlight threats to oil and gas\ninfrastructure. On October 11, 2016,\nseveral unauthorized persons accessed\nand interfered with pipeline operations\nin four states, creating the potential for\nserious infrastructure damage and\nsignificant economic and environmental\nPipeline Safety and Security\nPHMSA and TSA have a mutual\ninterest in ensuring coordinated,\nconsistent, and effective activities that\nimprove interagency cooperation on\ntransportation security and safety\nmatters. PHMSA focuses on the safety of\nthe Nation’s pipelines and administers\nthe pipeline safety regulatory program\n(49 CFR part 190–199). TSA focuses on\nthe security of the Nation’s pipelines\nand has authored Pipeline Security\nGuidelines for operators available\nonline at https://www.tsa.gov/sites/\ndefault/files/\ntsapipelinesecurityguidelines-2011.pdf.\nII. Advisory Bulletin (ADB–2016–06)\nTo: Owners and Operators of\nHazardous Liquid, Carbon Dioxide and\nGas Pipelines\nSubject: Safeguarding and Securing\nPipelines from Unauthorized Access\nAdvisory: PHMSA is issuing this\nAdvisory Bulletin in coordination with\nTSA to remind all pipeline owners and\noperators of the importance of\nsafeguarding and securing their pipeline\nfacilities and monitoring their SCADA\nsystems for abnormal operations and/or\nindications of unauthorized access or\ninterference with safe pipeline\noperations. Additionally, this Advisory\nBulletin is to remind the public of the\ndangers associated with tampering with\npipeline system facilities.\nIf You See Something, Say SomethingTM\nTampering with pipeline facilities can\nhave deleterious effects on the safety of\nthe Nation’s pipeline system. Tampering\nor acts of sabotage can also lead to the\nloss of life, injury, and significant harm\nto the economy and environment. At 49\nCFR 190.291, any person that willingly\nand knowingly injures or destroys, or\nattempts to injure or destroy a pipeline\nfacility is subject to a fine in Title 18 of\nthe United States Code and\nimprisonment for a term not to exceed\n20 years for each offense. Individuals\nare reminded that ‘‘If you See\nSomething, Say Something’’TM applies\nto the safety and security of our national\npipeline infrastructure. Individuals that\nsee something suspicious should reach\nout to their local law enforcement.\nInformed, alert communities play a vital\nrole in keeping our Nation’s energy\ninfrastructure safe. Emphasizing that\n‘‘Homeland Security Starts with\nHometown Security,’’ DHS encourages\nbusinesses to ‘‘Connect, Plan for, Train,\nand Report’’. Tools and resources to\nhelp businesses plan, prepare, and\nprotect themselves from suspicious\nactivities or attacks are located online at\nhttps://www.dhs.gov/hometown-\nsecurity.\nRelationships With Local Law\nEnforcement\nPHMSA reminds pipeline operators\nthat a strong relationship with local law\nenforcement is extremely beneficial for\nsafe pipeline operations. Two-way\ncommunications between operators and\nlaw enforcement can help to stop threats\nbefore they occur. Relationships should\nbe cultivated well in advance of an\nincident to facilitate mutually\ndependable communication during an\nincident.\nVerDate Sep<11>2014 18:13 Dec 08, 2016 Jkt 241001 PO 00000 Frm 00142 Fmt 4703 Sfmt 4703 E:\\FR\\FM\\09DEN1.SGM 09DEN1\n\n<<<PAGE 2>>>\n\nmstockstill on DSK3G9T082PROD with NOTICES\n89184 Federal Register / Vol. 81, No. 237 / Friday, December 9, 2016 / Notices\nIncreased Security Patrols\nPipeline operators should consider\nincreasing the frequency of security\npatrols along their right of ways.\nOperators may want to consider the use\nof new technologies to aid in pipeline\nsecurity patrols, such as unmanned\naerial systems if authorized in the areas\nof operation. Frequent patrols may help\ninform pipeline companies of\nindividuals who regularly congregate\nnear a pipeline, or of potentially unsafe\nconditions at a valve or pump station.\nInformation regarding suspicious\nindividuals should be promptly\nforwarded to federal, state, and local\nlaw enforcement.\nProtection of Facilities\nPHMSA’s Office of Pipeline Safety\nrequires pipeline operators to provide\nprotection for valves on hazardous\nliquid pipelines at 49 CFR 195.420(c).\nAdditionally, at 49 CFR 195.436,\nhazardous liquid pipeline operators are\nrequired to provide protection for each\npumping station, breakout tank area,\nand other exposed facility from\nvandalism and unauthorized entry.\nFurthermore, at 49 CFR 192.179(b)(1),\nnatural and other gas pipeline operators\nmust ensure that the valve and\noperating device to open or close the\nvalve must be protected from tampering\nand damage. PHMSA recommends that\npipeline operators review their valve\nand facility protection measures and\nconsider taking additional steps to\nsecure them.\nOperators should evaluate what type\nof locks and security fences are being\nused at valve stations and if they are\ncapable of preventing unauthorized\npersonnel from gaining access to\npipeline valve facilities. Pipeline\noperators may choose to make\nmechanical operation of valves more\ndifficult without proper equipment.\nThe use of deterrent text and signage\nat pipeline facilities may be beneficial to\ndecrease acts of sabotage against a\npipeline facility. The text should\ninclude the potential consequences if a\nvalve is closed improperly and a rupture\nwas to occur. Additionally the deterrent\ntext should include reference to the\nPHMSA regulation found at 49 CFR\n190.291 discussing the criminal\npenalties for tampering with pipeline\nfacilities. Remote facilities should\nconsider equipping the facilities with\nmotion sensing cameras and/or motion\ndetectors to alert control centers of\ntampering.\nSCADA System Monitoring\nDue to the criticality of SCADA\nsystems in the safe operations of a\npipeline, operators should have strong\nprotocols in place to ensure the systems\nwill not be tampered with. SCADA\nsystems can be tampered with or\ndisabled by a physical or cyber vector.\nPHMSA is aware of prior intrusion\nattempts on pipeline infrastructure. An\noperator should harden physical and\nsoftware borders around SCADA\nsystems to limit the risk to the safe\noperation of pipelines. The following\nmethods can be used to harden the\nsoftware and physical borders around\nthe SCADA system: (1) Segregating the\ncontrol system network from the\ncorporate network; (2) Limiting remote\nconnection ports to the control system,\nand if necessary requiring token-based\nauthentication to gain access; (3)\nAdding physical protection around\nremote sites with SCADA network\naccess; (4) Enhancing user access\ncontrol on SCADA system networks and\ndevices and limiting access to critical\nsystem to individuals with a safety/\nbusiness need; and [5] Employing\napplication whitelisting and strict\npolicies on peripheral devices (to\ninclude removable media, printers,\nscanners, etc.) connected to the SCADA\nnetwork.\nFurthermore, DHS’s Industrial Control\nSystem Cyber Emergency Response\nTeam (ICS–CERT) developed a guidance\ndocument titled: ‘‘Recommended\nPractice: Improving Industrial Control\nSystem Cybersecurity with Defense-in-\nDepth Strategies.’’ The document\nprovides guidance for developing\nmitigation strategies for specific cyber\nthreats and direction on how to create\na Defense-in-Depth security program for\ncontrol system environments, and is\navailable online at https://ics-cert.us-\ncert.gov/sites/default/files/\nrecommended\n_practices/NCCIC_\nICS-\nCERT\n_Defense_\nin\n_Depth_\n2016\n_\nS508C.pdf.\nIncident and Accident Reporting\nOperators are reminded that incidents\nand accidents must be promptly\nreported to the appropriate federal,\nstate, and local agency. Requirements\nfor immediate notification of certain\nincident and accident reporting\nrequirements are found at 49 CFR 191.5\nand 195.52. Furthermore, since\ntampering with a pipeline can lead to a\nrelease, PHMSA recommends that\noperators should contact the National\nResponse Center by telephone to 800–\n424–8802 (in Washington, DC, 202–\n267–2675) following any physical\nsecurity event that may interfere with\nthe safe operation of a pipeline. Please\nnote only ‘‘unclassified’’ incident\ndetails should be reported by phone to\nthe National Response Center.\nTSA recommends in its Pipeline\nSecurity Guidelines that pipeline\noperators notify the Transportation\nSecurity Operations Center via phone at\n866–615–5150 or email at TSOC.ST@\ndhs.gov as soon as possible to report\nsecurity concerns or suspicious activity.\nFurthermore it is recommended that\npipeline operators notify DHS’s ICS–\nCERT if the operator has an Industrial\nControl System concern with a cyber\nsecurity nexus. Operators can report to\nICS–CERT by emailing ics-cert@\nhq.dhs.gov or by calling 877–776–7585.\nPHMSA has coordinated with several\ncomponents within DHS and the\nDepartment of Energy on this Advisory\nBulletin.\nIssued in Washington, DC, on December 5,\n2016, under authority delegated in 49 CFR\n1.97.\nAlan K. Mayberry,\nActing Associate Administrator for Pipeline\nSafety.\n[FR Doc. 2016–29500 Filed 12–8–16; 8:45 am]\nBILLING CODE 4910–60–P\nDEPARTMENT OF VETERANS\nAFFAIRS\nMyVA Federal Advisory Committee;\nNotice of Meeting\nThe Department of Veterans Affairs\n(VA) gives notice under the Federal\nAdvisory Committee Act, 5 U.S.C. App.\n2., that the MyVA Advisory Committee\n(MVAC) will meet January 10–11, 2017,\nat the Department of Veterans Affairs,\nGeorgetown University Lohrfink\nAuditorium—Ground Floor,\nGeorgetown McDonough School of\nBusiness, Rafik B. Hariri Building, 37th\nand O Street NW., Washington, DC\n20057. The meeting is open to the\npublic.\nThe purpose of the Committee is to\nadvise the Secretary, through the\nExecutive Director, MyVA Task Force\nOffice, regarding the MyVA initiative\nand VA’s ability to rebuild trust with\nVeterans and other stakeholders,\nimprove service delivery with a focus\non Veteran outcomes, and set the course\nfor longer-term excellence and reform of\nVA.\nOn January 10, from 8:00 a.m. to 6:00\np.m., the Committee will convene an\nopen session to discuss the progress on\nand the integration of the work in the\nfive key MyVA work streams—Veteran\nExperience (explaining the efforts\nconducted to improve the Veteran’s\nexperience), Employees Experience,\nSupport Services Excellence (such as\ninformation technology, human\nresources, and finance), Performance\nImprovement (projects undertaken to\nVerDate Sep<11>2014 18:13 Dec 08, 2016 Jkt 241001 PO 00000 Frm 00143 Fmt 4703 Sfmt 4703 E:\\FR\\FM\\09DEN1.SGM 09DEN1","truncated":false,"body_characters":15205}