{"operation":"document","citation":"0900006481cb817b","title":"Morris Petition Response","source_type":"rulemaking","agency":"Pipeline and Hazardous Materials Safety Administration","status":"current","official":true,"published_on":null,"effective_on":null,"summary":"PHMSA reviewed Dr. Alan Morris's March 14, 2013 petition asking PHMSA to require installation of new-design programmable logic controllers (controllers) and staff training to mitigate malware attacks on pipeline industrial control systems. PHMSA denied the petition, stating it \"does not have the authority to establish new infrastructure security standards for pipeline control systems,\" and identified the Transportation Security Administration (TSA) and the Department of Homeland Security (DHS) as having primary responsibility for infrastructure and cyber asset security for pipeline control systems. The letter cites TSA's Pipeline Security Guidelines and DHS's Chemical Facility Anti-Terrorism Standards (CFATS) as existing sources that include cybersecurity measures, notes PHMSA’s agreement that pipeline security is important, and offers a contact for further assistance. Scope and explicit","machine_formats":{"json":"https://regulus.evalyn.ai/document/regulations-gov-attachment-0900006481cb817b.json","markdown":"https://regulus.evalyn.ai/document/regulations-gov-attachment-0900006481cb817b.md"},"app_url":"https://regulus.evalyn.ai/document/regulations-gov-attachment-0900006481cb817b","source_url":"https://downloads.regulations.gov/PHMSA-2013-0253-0004/attachment_1.pdf","body":"<<<PAGE 1>>>\n\nU.S. Department\nof Transportation\nPipeline and Hazardous\nMaterials Safety\nAdministration\n1200 New Jersey Avenue, SE\nWashington, D.C. 20590\nAPR 2 0 2015\nDr. Alan Morris\nPhysical Engineer\nMorris and Ward Consulting Engineers\n4938 Hampden Lane #114\nBethesda, MD 20814\nDear Dr. Morris:\nIn a letter to the Pipeline and Hazardous Materials Safety Administration (PHMSA) dated\nMarch 14, 2013, you submitted a petition for rulemaking to amend a portion of the Federal\nPipeline Safety Regulations.\nSpecifically, your letter proposes PHMSA require the installation of new-design programmable\nlogic computers (controllers) in the control systems of oil and gas pipelines and require pipeline\nstaff training in the programming and handling of non-rewritable memories. These proposals\nwould help block mal ware attacks on the industrial control systems of the affected facilities.\nPHMSA reviewed your proposed changes and your rationale for your proposals. At this time,\nPHMSA is denying your petition for rulemaking. PHMSA does not have the authority to\nestablish new infrastructure security standards for pipeline control systems. The Transportation\nSecurity Administration (TSA) and the Department of Homeland Security (DHS) have primary\nresponsibility for infrastructure and cyber asset security, including security standards for pipeline\ncontrol systems. ·\nTSA's Pipeline Security Guidelines include cyber asset security measures and can be found at:\nwww.tsa.gov/sites/default/fl.les/assets/pdf/lntermodal/tsa pipeline sec guideline april20ll.pdf.\nAdditionally, DHS developed Chemical Facility Anti-Terrorism Standards, which are applicable\nto fixed energy and utility facilities that manufacture, store, and distribute certain chemicals-\nsome of which are transported by pipelines. These standards also include cybersecurity\nrequirements.\nWhile PHMSA agrees that the security of pipeline systems is of tremendous importance,\nPHMSA does not have the authority to undertake any rulemaking pertaining to your proposal at\nthis time.\nWe hope this information is helpful to you. If you have any questions or need further assistance,\nplease contact John Gale, Director of Standards and Rulemaking, at 202-366-0434.\nSincerely,\nI~\nJeffrey D. Wiese\nAssociate Administrator for Pipeline Safety","truncated":false,"body_characters":2289}