81_FR_29380 81 FR 29289 - Information Sharing and Analysis Organization

81 FR 29289 - Information Sharing and Analysis Organization

DEPARTMENT OF HOMELAND SECURITY

Federal Register Volume 81, Issue 91 (May 11, 2016)

Page Range29289-29290
FR Document2016-11128

This Notice announces a request for public comment on draft products produced by the Information Sharing and Analysis Organization (ISAO) Standards Organization (SO) in partnership with the six established ISAO SO Standards Working Groups (SWG). This is the first iteration of draft products that will be used in the development of voluntary standards for Information Sharing and Analysis Organizations (ISAOs) as they relate to E.O. 13691.

Federal Register, Volume 81 Issue 91 (Wednesday, May 11, 2016)
[Federal Register Volume 81, Number 91 (Wednesday, May 11, 2016)]
[Notices]
[Pages 29289-29290]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2016-11128]


-----------------------------------------------------------------------

DEPARTMENT OF HOMELAND SECURITY

[Docket No. DHS-2015-0017]


Information Sharing and Analysis Organization

AGENCY: Department of Homeland Security.

ACTION: Notice and request for comments.

-----------------------------------------------------------------------

SUMMARY: This Notice announces a request for public comment on draft 
products produced by the Information Sharing and Analysis Organization 
(ISAO) Standards Organization (SO) in partnership with the six 
established ISAO SO Standards Working Groups (SWG). This is the first 
iteration of draft products that will be used in the development of 
voluntary standards for Information Sharing and Analysis Organizations 
(ISAOs) as they relate to E.O. 13691.

DATES: The comment period for the first iteration of the SWG draft 
voluntary standards for ISAOs will be open until Friday, June 17, 2016. 
Comments will be accepted after this date, but may not be reflected 
until later iterations of draft standards documents.

FOR FURTHER INFORMATION CONTACT: If you have questions concerning the 
draft voluntary standards documents, please contact the ISAO Standards 
Organization at [email protected].

SUPPLEMENTARY INFORMATION:

Background and Purpose

    On February 13, 2015, President Obama signed E.O. 13691 intended to 
enable and facilitate ``private companies, nonprofit organizations, and 
executive departments and agencies . . . to share information related 
to cybersecurity risks and incidents and collaborate to respond in as 
close to real time as possible.''
    In accordance with E.O. 13691, DHS has entered into a cooperative 
agreement with a non-governmental ISAO SO led by the University of 
Texas at San Antonio with support from the Logistics Management 
Institute (LMI) and the Retail Cyber Intelligence Sharing Center (R-
CISC). The ISAO SO is working with existing information sharing 
organizations, owners and operators of critical infrastructure, 
relevant agencies, and other public and private sector stakeholders to 
identify a common set of voluntary standards or guidelines for the 
creation and functioning of ISAOs.
    As part of this collaborative, transparent, and industry-driven 
process, the ISAO SO has established six working groups to assist in 
the development of voluntary standards. This notice is to request 
comment on the initial working group draft products. Your participation 
in this comment process is highly encouraged to ensure all equities are 
being met. To join a working group or to find out how else you can best 
participate, please visit www.ISAO.org or email [email protected].

Meeting Details

    To view details on the corresponding May 19, 2016 in person meeting 
in Anaheim, CA, please visit the Notice of Public Meeting Federal 
Register Notice and visit www.ISAO.org.

Submitting Written Comments

    The initial draft documents can be found and comments submitted 
directly to the ISAO SO at https://www.ISAO.org/products/drafts/. This 
method is preferred by the ISAO SO.
    You may also submit written comments to the docket using one of the 
following methods:
    (1) Federal eRulemaking Portal: http://www.regulations.gov. 
Although this is not a rulemaking action, comments are being submitted 
to the Federal eRulemaking Portal in an effort to provide transparency 
to the general public.
    (2) Email: [email protected]. Include the docket number in the 
subject line of the message.
    (3) Mail: ISAO Standards Organization, c/o LMI, 1777 NE Loop 410, 
Suite 808, San Antonio, TX 78217-5217.
    To avoid duplication, please use only one of these four methods. 
All comments must either be submitted to the online docket on or before 
June 17, 2016, or reach the Docket Management Facility by that date.
    Comments may be submitted directly to the ISAO SO using the method 
described above after June 17, 2016. However, these comments may not be 
reflected until later iterations of draft standards documents.

[[Page 29290]]

References

    Executive Order 13691 can be found at: https://www.whitehouse.gov/the-press-office/2015/02/13/executive-order-promoting-private-sector-cybersecurity-information-shari.
    For additional information about the ISAO Standards Organization, 
draft products, and how you can best participate in the standards 
development process, please go to www.ISAO.org or email 
[email protected].

    Authority: 6 U.S.C. 131-134; 6 CFR 29; E.O. 13691.

    Dated: May 9, 2016.
Andy Ozment,
Assistant Secretary, Cybersecurity and Communications, National 
Protection and Programs Directorate, Department of Homeland Security.
[FR Doc. 2016-11128 Filed 5-10-16; 8:45 am]
 BILLING CODE P



                                                                               Federal Register / Vol. 81, No. 91 / Wednesday, May 11, 2016 / Notices                                            29289

                                                     In compliance with Government                          Affected Public: State, local, and tribal           Logistics Management Institute (LMI)
                                                  Paperwork Elimination Act, States will                  governments.                                          and the Retail Cyber Intelligence
                                                  be permitted to electronically submit                     Number of Respondents: 56.                          Sharing Center (R–CISC). The ISAO SO
                                                  the information for their security plans,                 Estimated Time per Respondent:                      is working with existing information
                                                  certification packages, recertifications,               1,178 hours.                                          sharing organizations, owners and
                                                  extensions, and written exceptions                        Total Burden Hours: 446,246 hours.                  operators of critical infrastructure,
                                                  processes. States will be permitted to                    Dated: May 5, 2016.                                 relevant agencies, and other public and
                                                  submit electronic signatures but must                   Carlene C. Ileto,                                     private sector stakeholders to identify a
                                                  keep the original signature on file.                    Executive Director, Enterprise Business               common set of voluntary standards or
                                                  Additionally, because they contain                      Management Office.                                    guidelines for the creation and
                                                  sensitive security information (SSI), the               [FR Doc. 2016–11133 Filed 5–10–16; 8:45 am]
                                                                                                                                                                functioning of ISAOs.
                                                  security plans must be handled and                                                                               As part of this collaborative,
                                                                                                          BILLING CODE 9110–9B–P
                                                  protected in accordance with 49 CFR                                                                           transparent, and industry-driven
                                                  part 1520. 6 CFR 37.41(c). The final rule                                                                     process, the ISAO SO has established
                                                  does not dictate how States must submit                 DEPARTMENT OF HOMELAND                                six working groups to assist in the
                                                  their employees’ fingerprints to the FBI                SECURITY                                              development of voluntary standards.
                                                  for background checks; however it is                                                                          This notice is to request comment on
                                                  assumed States will do so via electronic                [Docket No. DHS–2015–0017]                            the initial working group draft products.
                                                  means or another means determined by                                                                          Your participation in this comment
                                                                                                          Information Sharing and Analysis
                                                  the FBI.                                                                                                      process is highly encouraged to ensure
                                                                                                          Organization
                                                     Information provided will be                                                                               all equities are being met. To join a
                                                  protected from disclosure to the extent                 AGENCY:  Department of Homeland                       working group or to find out how else
                                                  appropriate under applicable provisions                 Security.                                             you can best participate, please visit
                                                  of the Freedom of Information Act, the                  ACTION: Notice and request for                        www.ISAO.org or email Contact@
                                                  Privacy Act of 1974, the Driver’s Privacy               comments.                                             ISAO.org.
                                                  Protection Act, as well as DHS’s Privacy
                                                                                                          SUMMARY:   This Notice announces a                    Meeting Details
                                                  Impact Assessment for the REAL ID Act.
                                                     There have been no program changes                   request for public comment on draft                     To view details on the corresponding
                                                  or new requirements established as a                    products produced by the Information                  May 19, 2016 in person meeting in
                                                  result of this collection request.                      Sharing and Analysis Organization                     Anaheim, CA, please visit the Notice of
                                                  Extensions were covered in the initial                  (ISAO) Standards Organization (SO) in                 Public Meeting Federal Register Notice
                                                  request however it was incorrectly                      partnership with the six established                  and visit www.ISAO.org.
                                                  removed from the subsequent request.                    ISAO SO Standards Working Groups
                                                                                                          (SWG). This is the first iteration of draft           Submitting Written Comments
                                                     The Office of Management and Budget
                                                  is particularly interested in comments                  products that will be used in the                       The initial draft documents can be
                                                  which:                                                  development of voluntary standards for                found and comments submitted directly
                                                     1. Evaluate whether the proposed                     Information Sharing and Analysis                      to the ISAO SO at https://
                                                  collection of information is necessary                  Organizations (ISAOs) as they relate to               www.ISAO.org/products/drafts/. This
                                                  for the proper performance of the                       E.O. 13691.                                           method is preferred by the ISAO SO.
                                                  functions of the agency, including                      DATES: The comment period for the first                 You may also submit written
                                                  whether the information will have                       iteration of the SWG draft voluntary                  comments to the docket using one of the
                                                  practical utility;                                      standards for ISAOs will be open until                following methods:
                                                     2. Evaluate the accuracy of the                      Friday, June 17, 2016. Comments will be                 (1) Federal eRulemaking Portal:
                                                  agency’s estimate of the burden of the                  accepted after this date, but may not be              http://www.regulations.gov. Although
                                                  proposed collection of information,                     reflected until later iterations of draft             this is not a rulemaking action,
                                                  including the validity of the                           standards documents.                                  comments are being submitted to the
                                                  methodology and assumptions used;                       FOR FURTHER INFORMATION CONTACT: If                   Federal eRulemaking Portal in an effort
                                                     3. Enhance the quality, utility, and                 you have questions concerning the draft               to provide transparency to the general
                                                  clarity of the information to be                        voluntary standards documents, please                 public.
                                                  collected; and                                          contact the ISAO Standards                              (2) Email: Contact@ISAO.org. Include
                                                     4. Minimize the burden of the                        Organization at Contact@ISAO.org.                     the docket number in the subject line of
                                                  collection of information on those who                  SUPPLEMENTARY INFORMATION:                            the message.
                                                  are to respond, including through the                                                                           (3) Mail: ISAO Standards
                                                  use of appropriate automated,                           Background and Purpose                                Organization, c/o LMI, 1777 NE Loop
                                                  electronic, mechanical, or other                           On February 13, 2015, President                    410, Suite 808, San Antonio, TX 78217–
                                                  technological collection techniques or                  Obama signed E.O. 13691 intended to                   5217.
                                                  other forms of information technology,                  enable and facilitate ‘‘private                         To avoid duplication, please use only
                                                  e.g., permitting electronic submissions                 companies, nonprofit organizations, and               one of these four methods. All
                                                  of responses.                                           executive departments and agencies                    comments must either be submitted to
                                                                                                          . . . to share information related to                 the online docket on or before June 17,
                                                  Analysis
                                                                                                          cybersecurity risks and incidents and                 2016, or reach the Docket Management
mstockstill on DSK3G9T082PROD with NOTICES




                                                    Agency: Office of the Secretary, DHS.                 collaborate to respond in as close to real            Facility by that date.
                                                    Title: REAL ID: Minimum Standards                     time as possible.’’                                     Comments may be submitted directly
                                                  for Driver’s Licenses and Identification                   In accordance with E.O. 13691, DHS                 to the ISAO SO using the method
                                                  Cards Acceptable by Federal Agencies                    has entered into a cooperative                        described above after June 17, 2016.
                                                  for Official Purposes.                                  agreement with a non-governmental                     However, these comments may not be
                                                    OMB Number: 1601–0005.                                ISAO SO led by the University of Texas                reflected until later iterations of draft
                                                    Frequency: Annually.                                  at San Antonio with support from the                  standards documents.


                                             VerDate Sep<11>2014   17:20 May 10, 2016   Jkt 238001   PO 00000   Frm 00041   Fmt 4703   Sfmt 4703   E:\FR\FM\11MYN1.SGM   11MYN1


                                                  29290                        Federal Register / Vol. 81, No. 91 / Wednesday, May 11, 2016 / Notices

                                                  References                                              I. Civil Money Penalties, Withdrawals                 identification number of a terminated
                                                     Executive Order 13691 can be found                   of FHA Approval, Suspensions,                         employee to be used to access FHA
                                                  at: https://www.whitehouse.gov/the-                     Probations, Reprimands, and                           Connection; and (j) failed to require it’s
                                                  press-office/2015/02/13/executive-                      Settlements                                           appraiser to explain the use of a
                                                  order-promoting-private-sector-                         1. Allied First Bank, SB, Oswego, IL                  comparable sale that was over 12
                                                  cybersecurity-information-shari.                             [Docket No. 15–1506–MR]                          months old.
                                                     For additional information about the                    Action: On June 19, 2015, the Board                3. Bogman Inc., Silver Spring, MD
                                                  ISAO Standards Organization, draft                      entered into a settlement agreement                        [Docket No. 15–1507–MR]
                                                  products, and how you can best                          with Allied First Bank, SB (‘‘AFB’’) that                Action: On August 11, 2015, the
                                                  participate in the standards                            required AFB to pay a civil money                     Board entered into a settlement
                                                  development process, please go to                       penalty in the amount of $17,000                      agreement with Bogman Inc.,
                                                  www.ISAO.org or email Contact@                          without admitting fault or liability.                 (‘‘Bogman’’) that required Bogman to
                                                  ISAO.org.                                                  Cause: The Board took this action                  pay a civil money penalty in the amount
                                                                                                          based on the following violations of                  of $50,000 without admitting fault or
                                                    Authority: 6 U.S.C. 131–134; 6 CFR 29;
                                                                                                          HUD/FHA requirements alleged by                       liability and to submit, on a quarterly
                                                  E.O. 13691.
                                                                                                          HUD: AFB (a) improperly used the                      basis during the period of one year,
                                                    Dated: May 9, 2016.                                   name of FHA in certain correspondence                 written reports, describing the
                                                  Andy Ozment,                                            to imply the correspondence was from                  methodology and findings of quality
                                                  Assistant Secretary, Cybersecurity and                  and/or endorsed by HUD/FHA; (b)                       control reviews performed by an
                                                  Communications, National Protection and                 failed to timely notify HUD that AFB                  independent third party regarding
                                                  Programs Directorate, Department of                     has entered into a written agreement                  Bogman’s compliance with applicable
                                                  Homeland Security.                                      with the Federal Reserve Board of                     HUD Handbooks and Mortgagee Letters,
                                                  [FR Doc. 2016–11128 Filed 5–10–16; 8:45 am]             Chicago on May 22, 2014 and; (c) failed               including compliance with servicing
                                                  BILLING CODE P                                          to timely notify HUD that AFB had                     and loss mitigation requirements.
                                                                                                          entered into a consent order with the                    Cause: The Board took this action
                                                                                                          Federal Deposit Insurance Corporation                 based on the following violations of
                                                  DEPARTMENT OF HOUSING AND                               and the State of Illinois Department of               HUD/FHA requirements alleged by
                                                  URBAN DEVELOPMENT                                       Financial and Professional Regulation.                HUD: Bogman (a) failed to properly
                                                  [Docket No. FR–5948–N–01]                               2. American Home Free Mortgage,                       establish and implement a Quality
                                                                                                               Prosper, TX [Docket No. 14–1682–                 Control Plan; (b) used the services of a
                                                  Mortgagee Review Board:                                      MR]                                              third party servicer that was not an
                                                  Administrative Actions                                     Action: On May 21, 2015, the Board                 approved HUD/FHA approved
                                                                                                          voted to withdraw the FHA approval of                 mortgagee; (c) failed to properly service
                                                  AGENCY:  Office of the Assistant                                                                              defaulted FHA insured loans and failed
                                                                                                          American Home Free Mortgage
                                                  Secretary for Housing–Federal Housing                                                                         to ensure its foreclosure management
                                                                                                          (‘‘AHFM’’) on a permanent basis. On
                                                  Commissioner, HUD.                                                                                            review checklist was in compliance
                                                                                                          July 24, 2015, the Board entered into a
                                                  ACTION: Notice.                                         settlement agreement with AHFM that                   with HUD/FHA requirements; and (d)
                                                                                                          required AHFM to pay a civil money                    failed to use the proper loss mitigation
                                                  SUMMARY:   In compliance with Section                                                                         techniques with borrowers.
                                                  202(c)(5) of the National Housing Act,                  penalty in the amount of $169,419, and
                                                                                                          to abide by the Board’s action                        4. City First Mortgage Services LLC.,
                                                  this notice advises of the cause and
                                                                                                          concerning the permanent withdrawal                        Bountiful, UT [Docket No. 15–
                                                  description of administrative actions
                                                                                                          of its FHA approval.                                       1657–MR]
                                                  taken by HUD’s Mortgagee Review
                                                                                                             Cause: The Board took this action                     Action: On June 30, 2015, the Board
                                                  Board against HUD-approved
                                                                                                          based on the following violations of                  issued a letter of reprimand to City First
                                                  mortgagees.
                                                                                                          HUD/FHA requirements alleged by                       Mortgage Services, LLC., (‘‘CFMS’’), and
                                                  FOR FURTHER INFORMATION CONTACT:                        HUD: AHFM (a) submitted false                         also required CFMS to pay a civil
                                                  Nancy A. Murray, Secretary to the                       certifications to HUD/FHA in 2010,                    money penalty in the amount of
                                                  Mortgagee Review Board, 451 Seventh                     2012 and 2013 for the annual                          $40,500.
                                                  Street SW., Room B–133/3150,                            recertifications of its FHA approval; (b)                Cause: The Board took this action
                                                  Washington, DC 20410–8000; telephone                    failed to ensure that individuals                     based on the following violations of
                                                  (202) 708–2224 (this is not a toll-free                 originating FHA insured loans were                    HUD/FHA requirements alleged by
                                                  number). Persons with hearing or                        exclusively employed by AHFM; (c)                     HUD: CFMS (a) failed to comply with
                                                  speech impairments may access this                      failed to implement a Quality Control                 Generally Accepted Accounting
                                                  number through TTY by calling the toll-                 Plan in compliance with HUD/FHA                       Principles; (b) falsely certified to HUD/
                                                  free Federal Information Service at (800)               requirements; (d) failed to conduct                   FHA that it had complied with all HUF/
                                                  877–8339.                                               Quality Control reviews in accordance                 FHA regulations in its June 25, 2014
                                                  SUPPLEMENTARY INFORMATION: Section                      with HUD/FHA requirements; (e)                        annual certification; (c) failed to
                                                  202(c)(5) of the National Housing Act                   participated in a scheme to inflate the               promptly notify HUD/FHA it had
                                                  (12 U.S.C. 1708(c)(5)) requires that HUD                amount of fees collected in loan                      entered into a consent order with the
                                                  ‘‘publish a description of and the cause                transactions by disguising them as                    State of Illinois Department of Financial
                                                  for administrative action against a HUD-                construction fees; (f) submitted loan                 and Professional Regulation, Division of
mstockstill on DSK3G9T082PROD with NOTICES




                                                  approved mortgagee’’ by the                             case binders that falsely identified fees             Banking and paid a $2,500 fine to settle
                                                  Department’s Mortgagee Review Board                     as construction costs or fees; (g)                    allegations that it allowed an unlicensed
                                                  (‘‘Board’’). In compliance with the                     provided false certifications to HUD/                 office, branch manager and loan
                                                  requirements of Section 202(c)(5), this                 FHA regarding conflicts of interests; (h)             originator to conduct business without
                                                  notice advises of actions that have been                allowed personnel involved in the day-                the proper licenses or sponsorship from
                                                  taken by the Board in its meetings from                 to-day origination process to conduct                 CFMS; and (d) failed to timely notify
                                                  October 1, 2014 to September 30, 2015.                  Quality Control reviews; (i) allowed the              HUD/FHA that it had entered into a


                                             VerDate Sep<11>2014   17:20 May 10, 2016   Jkt 238001   PO 00000   Frm 00042   Fmt 4703   Sfmt 4703   E:\FR\FM\11MYN1.SGM   11MYN1



Document Created: 2016-05-11 01:11:27
Document Modified: 2016-05-11 01:11:27
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice and request for comments.
DatesThe comment period for the first iteration of the SWG draft voluntary standards for ISAOs will be open until Friday, June 17, 2016. Comments will be accepted after this date, but may not be reflected until later iterations of draft standards documents.
ContactIf you have questions concerning the draft voluntary standards documents, please contact the ISAO Standards Organization at [email protected]
FR Citation81 FR 29289 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR