# Morris Petition Response

- **operation:** document
- **citation:** 0900006481cb817b
- **title:** Morris Petition Response
- **source type:** rulemaking
- **agency:** Pipeline and Hazardous Materials Safety Administration
- **status:** current
- **official:** true
- **published on:** Not available
- **effective on:** Not available
- **summary:** PHMSA reviewed Dr. Alan Morris's March 14, 2013 petition asking PHMSA to require installation of new-design programmable logic controllers (controllers) and staff training to mitigate malware attacks on pipeline industrial control systems. PHMSA denied the petition, stating it "does not have the authority to establish new infrastructure security standards for pipeline control systems," and identified the Transportation Security Administration (TSA) and the Department of Homeland Security (DHS) as having primary responsibility for infrastructure and cyber asset security for pipeline control systems. The letter cites TSA's Pipeline Security Guidelines and DHS's Chemical Facility Anti-Terrorism Standards (CFATS) as existing sources that include cybersecurity measures, notes PHMSA’s agreement that pipeline security is important, and offers a contact for further assistance. Scope and explicit
- **machine formats:** - **json:** https://regulus.evalyn.ai/document/regulations-gov-attachment-0900006481cb817b.json
- **markdown:** https://regulus.evalyn.ai/document/regulations-gov-attachment-0900006481cb817b.md
- **app url:** https://regulus.evalyn.ai/document/regulations-gov-attachment-0900006481cb817b
- **source url:** https://downloads.regulations.gov/PHMSA-2013-0253-0004/attachment_1.pdf
**body:**

<<<PAGE 1>>>

U.S. Department
of Transportation
Pipeline and Hazardous
Materials Safety
Administration
1200 New Jersey Avenue, SE
Washington, D.C. 20590
APR 2 0 2015
Dr. Alan Morris
Physical Engineer
Morris and Ward Consulting Engineers
4938 Hampden Lane #114
Bethesda, MD 20814
Dear Dr. Morris:
In a letter to the Pipeline and Hazardous Materials Safety Administration (PHMSA) dated
March 14, 2013, you submitted a petition for rulemaking to amend a portion of the Federal
Pipeline Safety Regulations.
Specifically, your letter proposes PHMSA require the installation of new-design programmable
logic computers (controllers) in the control systems of oil and gas pipelines and require pipeline
staff training in the programming and handling of non-rewritable memories. These proposals
would help block mal ware attacks on the industrial control systems of the affected facilities.
PHMSA reviewed your proposed changes and your rationale for your proposals. At this time,
PHMSA is denying your petition for rulemaking. PHMSA does not have the authority to
establish new infrastructure security standards for pipeline control systems. The Transportation
Security Administration (TSA) and the Department of Homeland Security (DHS) have primary
responsibility for infrastructure and cyber asset security, including security standards for pipeline
control systems. ·
TSA's Pipeline Security Guidelines include cyber asset security measures and can be found at:
www.tsa.gov/sites/default/fl.les/assets/pdf/lntermodal/tsa pipeline sec guideline april20ll.pdf.
Additionally, DHS developed Chemical Facility Anti-Terrorism Standards, which are applicable
to fixed energy and utility facilities that manufacture, store, and distribute certain chemicals-
some of which are transported by pipelines. These standards also include cybersecurity
requirements.
While PHMSA agrees that the security of pipeline systems is of tremendous importance,
PHMSA does not have the authority to undertake any rulemaking pertaining to your proposal at
this time.
We hope this information is helpful to you. If you have any questions or need further assistance,
please contact John Gale, Director of Standards and Rulemaking, at 202-366-0434.
Sincerely,
I~
Jeffrey D. Wiese
Associate Administrator for Pipeline Safety
- **truncated:** false
- **body characters:** 2289
