2019 08817

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

Federal Register / Vol. 84, No.

84 / Wednesday, May 1, 2019 / Notices 18493

expanding domain with a range of III. Data Standard (FIPS) 140–3, Security
applications and a broad diversity of OMB Control Number: 0693–0083. Requirements for Cryptographic
designs. NIST’s Engineering Laboratory Form Number(s): None. Modules. FIPS 140–3 includes
will be developing methods to evaluate Type of Review: Revision and references to existing International
performance of exoskeletons in two key extension of a current information Organization for Standardization/
areas (1) The fit and motion of the collection. International Electrotechnical
exoskeleton device with respect to the Affected Public: Individuals or Commission (ISO/IEC) 19790:2012(E)
users’ body and (2) The impact that households. Information technology—Security
using an exoskeleton has on the Estimated Number of Respondents: techniques—Security requirements for
performance of users executing tasks 250. cryptographic modules and ISO/IEC
that are representative of activities in Estimated Time per Response: 1.5 24759:2017(E) Information technology—
industrial settings. The results of these hours. Security techniques—Test requirements
experiments will inform future test Estimated Total Annual Burden for cryptographic modules. As
method development at NIST, other Hours: 375 hours. permitted by the standards, the NIST
organizations, and under the purview of Estimated Total Annual Cost to Special Publication (SP) series 800–140
the new American Society for Testing Public: $0. will specify updates, replacements, or
Materials (ASTM) Committee F48 on additions to the currently cited ISO/IEC
Exoskeletons and Exosuits. IV. Request for Comments standard as necessary.
For the first research topic, NIST will NIST invites comments on: (a) DATES: FIPS 140–3 is effective
evaluate the usefulness of a NIST Whether the proposed collection of September 22, 2019. FIPS 140–3 testing
prototype apparatus for measuring the information is necessary for the proper will begin on September 22, 2020. FIPS
difference in performance of a person performance of the functions of the 140–2 testing will continue for at least
wearing an exoskeleton versus the agency, including whether the a year after FIPS 140–3 testing begins.
person’s baseline without the information will have practical utility; ADDRESSES: FIPS 140–3 is available
exoskeleton while positioning loads and (b) the accuracy of the agency’s estimate electronically from the NIST website at:
tools. The NIST Position and Load Test of the burden (including hours and cost) https://csrc.nist.gov/publications/fips.
Apparatus for Exoskelons (PoLoTAE), of the proposed collection of Comments that were received on the
which presents abstractions of information; (c) ways to enhance the proposed changes are also published
industrial task challenges, will be quality, utility, and clarity of the electronically at https://csrc.nist.gov/
evaluated in this research. information to be collected; and (d) projects/fips-140-3-development.
For the second research topic, NIST ways to minimize the burden of the FOR FURTHER INFORMATION CONTACT:
will evaluate a method for measuring collection of information on Michael Cooper, (301) 975–8077,
the alignment of an exoskeleton to respondents, including through the use
human joint (knee) and any relative National Institute of Standards and
of automated collection techniques or Technology, 100 Bureau Drive, Mail
movement between the exoskeleton and other forms of information technology.
user. Measurement methods prototyped Stop 8930, Gaithersburg, MD 20899–
Comments submitted in response to 8930, email: michael.cooper@nist.gov.
by NIST for evaluating exoskeleton on this notice will be summarized and/or
mannequin position and motion will be SUPPLEMENTARY INFORMATION: NIST has
included in the request for OMB been participating in the ISO/IEC
applied to human subjects to verify the approval of this information collection;
usefulness of optical tracking system process for developing standards for
they also will become a matter of public cryptographic modules and working
and designed artifacts worn by users as record.
measurement methods. closely with international industry to
Participants will be chosen from Sheleen Dumas, unify several cryptographic security
volunteers within NIST and adult NIST Departmental Lead PRA Officer, Office of the standards. ISO/IEC 19790:2012(E),
visitors to participate in the study. Chief Information Officer, Commerce Information technology—Security
Gender and size diversity will be sought Department. techniques—Security requirements for
in the population of participants. No [FR Doc. 2019–08816 Filed 4–30–19; 8:45 am] cryptographic modules, is an
personally identifiable information (PII) BILLING CODE 3510–13–P international standard based on updates
will be recorded unless subject consent of the earlier versions of FIPS 140,
for PII disclosure is received. NIST Security Requirements for
intends to publish information on the DEPARTMENT OF COMMERCE Cryptographic Modules. ISO/IEC
analysis and results. 24759:2017(E), Information
National Institute of Standards and technology—Security techniques—Test
II. Method of Collection Technology requirements for cryptographic modules
Participants will give informed [Docket No. 170810743–8858–01] is an international standard based on
consent prior to participating in the the Derived Test Requirements for FIPS
research. Information may be collected RIN 0693–XC079 140–2, Security Requirements for
via a paper background questionnaire Cryptographic Modules. The National
which may include disclosure of health Announcing Issuance of Federal Technology Transfer and Advancement
information which may be relevant for Information Processing Standard Act (NTTAA), Public Law 104–113,
safety and research reasons. Data will be (FIPS) 140–3, Security Requirements directs Federal agencies with respect to
collected using a combination of heart for Cryptographic Modules their use of and participation in the
rate monitor, and video and still AGENCY: National Institute of Standards development of voluntary consensus
jbell on DSK30RV082PROD with NOTICES

cameras to collect time and subject and Technology (NIST), Commerce. standards. The NTTAA’s objective is for
activity to correlate heart rate with ACTION: Notice. Federal agencies to adopt voluntary
activity and an optical tracking system consensus standards, wherever possible,
which detects markers. Participants will SUMMARY: This notice announces the in lieu of creating proprietary, non-
be asked to complete a paper survey Secretary of Commerce’s issuance of consensus standards. The
once data is collected for the research. Federal Information Processing implementation of commercial

VerDate Sep<11>2014 19:24 Apr 30, 2019 Jkt 247001 PO 00000 Frm 00020 Fmt 4703 Sfmt 4703 E:\FR\FM\01MYN1.SGM 01MYN1
18494 Federal Register / Vol. 84, No. 84 / Wednesday, May 1, 2019 / Notices

cryptography, which is used to protect comments received from the public. The following is a summary and
U.S. non-national security information Though the standard was reviewed after analysis of the comments received
and information systems, is now five years, consensus to move forward during the public comment period, and
commoditized and built, marketed and was not achieved until the 2012 revision NIST’s responses to them, including the
used globally. Therefore, FIPS 140–3 of ISO/IEC 19790. interests, concerns, recommendations,
applies ISO/IEC 19790:2012(E) and ISO/ FIPS 140–3 supercedes FIPS 140–2. and issues considered in the
IEC 24759:2017(E) as the security FIPS 140–3 aligns with ISO/IEC development of FIPS 140–3:
requirements for cryptographic 19790:2012(E) with modifications of the Comment: Nine commenters
modules. The SP 800–140 series, which Annexes allowed by the specific user responded that they have been asked by
is currently under development, will be communities. The testing for these customers about testing for ISO/IEC
used to specify updates, replacements, requirements shall be in accordance standards or have had requests to test
or additions to requirements as allowed with ISO/IEC 24759:2017(E), with the using the ISO/IEC standard.
by ISO/IEC 19790:2012(E), with the modifications, additions or deletions of Response: NIST will be revising its
Cryptographic Module Validation vendor evidence and testing allowed as guidance by moving to the ISO/IEC
Program (CMVP) executing the role of a validation authority under paragraph standards embraced in FIPS 140–3.
the validation authority as defined in 5.2 of ISO/IEC 24759:2017(E). Comment: Seven commenters
the ISO/IEC standard.1 During the On August 12, 2015, NIST published responded that they were concerned
transition period prior to FIPS 140–3 a notice in the Federal Register (80 FR about the ability of researchers,
becoming effective, FIPS 140–2 testing 48295) requesting public comments on academics and small organizations to
will continue, and NIST will introduce the potential use of ISO/IEC standards obtain the ISO/IEC standard due to the
the SP 800–140 series documents (at for cryptographic algorithm and payment model used by ISO/IEC.
https://csrc.nist.gov/publications/ cryptographic module testing, Response: NIST intends to work with
sp800). The series is expected to consist conformance, and validation activities, the appropriate parties to help ensure
of: currently specified by FIPS 140–2. that the ISO/IEC standard will be made
• SP 800–140, FIPS 140–3 Derived Comments were submitted by 17 reasonably available to researchers,
Test Requirements (DTR); entities, including four accredited academics and small organizations.
• SP 800–140A, CMVP cryptographic testing laboratories, eight Comment: Eleven commenters
Documentation Requirements; vendors of cryptographic modules, one indicated that changing to the ISO/IEC
• SP 800–140B, CMVP Security Policy industry association, and four standard did not increase the risk of
Requirements; individuals. Some comments only using cryptography or decrease trust in
• SP 800–140C, CMVP Approved addressed specific aspects of the the use of cryptography as compared to
Security Functions; proposal. Eleven of the comments the current FIPS 140–2.
• SP 800–140D, CMVP Approved supported a revised standard, five were Response: NIST intends to make the
Sensitive Security Parameter Generation neutral and one was opposed. Many normative reference to the ISO/IEC
and Establishment Methods; comments asked for clarification on the standard specific to a version that NIST
• SP 800–140E, CMVP Approved continued use of implementation believes is acceptable to provide
Authentication Mechanisms; and guidance and administration guidance assurances in the cryptography used by
• SP 800–140F, CMVP Non-Invasive the Federal Government. In its role as
to the testing laboratories. NIST will
Attack Mitigation Test Metrics. the approval authority 2 under ISO/IEC
consolidate the implementation
FIPS 140–1, first published in 1994, 19790:2012(E), NIST is permitted to
guidance and administration guidance
was developed by a government and replace most of the supporting
into the SP 800–140 series documents,
industry working group. The working requirements with NIST guidance, most
which will be made available for public
group identified requirements for four of which are currently utilized in the
review and comment. Other comments
security levels for cryptographic existing FIPS 140–2.
provided feedback on perceived market
modules to provide for a wide spectrum Comment: One commenter expressed
demand, comparisons of test coverage
of data sensitivity (e.g., low value concern that adoption of an
between FIPS 140–2 and the ISO/IEC
administrative data, million-dollar international, consensus based standard
standards and the potential risks that
funds transfers, and life protecting data) would put the US in the position of
might be assumed with the use of the
and a diversity of application using future versions of the ISO/IEC
ISO/IEC standard. Most of the
environments (e.g., a guarded facility, standard as it is updated and evolves.
commenters were concerned about the
an office, and a completely unprotected Response: NIST plans on continuing
payment model for accessing and
location). Four security levels were its robust participation in the relevant
obtaining the ISO/IEC standards
specified for each of 11 requirement ISO/IEC working groups, and will
compared with the free access to the
areas. Each security level offered an thoroughly discuss any changes
current FIPS 140–2. All of the
increase in security over the preceding necessary to keep these requirements
suggestions, questions, and
level. These four increasing levels of relevant. If an update or change is made
recommendations within the scope of
security allowed cost-effective solutions to the ISO/IEC standards that NIST does
NIST’s request for comments were
that were appropriate for different not feel is adequate for the security
carefully reviewed, and changes were
degrees of data sensitivity and different needs of the Federal Government, NIST
made to the FIPS, where appropriate.
application environments. will have the flexibility to adopt a
Some comments submitted questions or
In 2001, FIPS 140–2 superseded FIPS different standard. By working with
raised issues that were related but
140–1. FIPS 140–2 incorporated changes ISO/IEC experts, NIST can maintain
outside the scope of this FIPS.
in applicable standards and technology
jbell on DSK30RV082PROD with NOTICES

Comments that were outside the scope flexibility within the standards as
since the development of FIPS 140–1 as allowed by the validation authorities as
of this FIPS, but that were within the
well as changes that were based on
scope of one of the related Special 2 ISO/IEC 19790 defines the approval authority as
1 ISO/IEC 19790 defines the validation authority
Publications, are deferred for later any national or international organization/authority
as the entity that will validate the test results for consideration in the context of mandated to approve and/or evaluate security
conformance to this international standard. development of the SP 800–140 series. functions.

VerDate Sep<11>2014 19:24 Apr 30, 2019 Jkt 247001 PO 00000 Frm 00021 Fmt 4703 Sfmt 4703 E:\FR\FM\01MYN1.SGM 01MYN1
Federal Register / Vol. 84, No. 84 / Wednesday, May 1, 2019 / Notices 18495

described in the ISO/IEC standards. DATES: Comments and information must taking will have a negligible impact on
Should these measures prove be received no later than May 31, 2019. the species or stock(s) and will not have
insufficient, NIST can, through FIPS ADDRESSES: Comments should be an unmitigable adverse impact on the
140–3 or the SP 800–140 series addressed to Jolie Harrison, Chief, availability of the species or stock(s) for
development process, create a revised Permits and Conservation Division, taking for subsistence uses (where
standard, controlled by NIST, to Office of Protected Resources, National relevant). Further, NMFS must prescribe
maintain the most secure posture Marine Fisheries Service. Physical the permissible methods of taking and
possible. comments should be sent to 1315 East- other ‘‘means of effecting the least
FIPS 140–3 is available electronically West Highway, Silver Spring, MD 20910 practicable adverse impact’’ on the
from the NIST website at: https:// and electronic comments should be sent affected species or stocks and their
csrc.nist.gov/publications/fips. to ITP.Egger@noaa.gov. habitat, paying particular attention to
Authority: 44 U.S.C. 3553(f)(1), 15 U.S.C. Instructions: NMFS is not responsible rookeries, mating grounds, and areas of
278g–3. for comments sent by any other method, similar significance, and on the
to any other address or individual, or availability of such species or stocks for
Kevin A. Kimball, received after the end of the comment taking for certain subsistence uses
Chief of Staff. period. Comments received (referred to in shorthand as
[FR Doc. 2019–08817 Filed 4–30–19; 8:45 am] electronically, including all ‘‘mitigation’’); and requirements
BILLING CODE 3510–13–P attachments, must not exceed a 25- pertaining to the mitigation, monitoring
megabyte file size. Attachments to and reporting of such takings are set
electronic comments will be accepted in forth.
DEPARTMENT OF COMMERCE Microsoft Word or Excel or Adobe PDF National Environmental Policy Act
file formats only. All comments
National Oceanic and Atmospheric To comply with the National
received are a part of the public record
Administration Environmental Policy Act of 1969
and will generally be posted online at
(NEPA; 42 U.S.C. 4321 et seq.) and
https://www.fisheries.noaa.gov/permit/
RIN 0648–XG874 NOAA Administrative Order (NAO)
incidental-take-authorizations-under-
216–6A, NMFS must review our
marine-mammal-protection-act without
Taking of Marine Mammals Incidental proposed action (i.e., the issuance of an
change. All personal identifying
to Specific Activities; Taking of Marine incidental harassment authorization)
information (e.g., name, address) with respect to potential impacts on the
Mammals Incidental to Pile Driving and voluntarily submitted by the commenter
Removal Activities During human environment. This action is
may be publicly accessible. Do not consistent with categories of activities
Construction of a Cruise Ship Berth, submit confidential business
Hoonah, Alaska identified in Categorical Exclusion B4
information or otherwise sensitive or (incidental harassment authorizations
AGENCY: National Marine Fisheries protected information. with no anticipated serious injury or
Service (NMFS), National Oceanic and FOR FURTHER INFORMATION CONTACT: mortality) of the Companion Manual for
Atmospheric Administration (NOAA), Stephanie Egger, Office of Protected NOAA Administrative Order 216–6A,
Commerce. Resources, NMFS, (301) 427–8401. which do not individually or
ACTION: Notice; proposed incidental Electronic copies of the application and cumulatively have the potential for
harassment authorization; request for supporting documents, as well as a list significant impacts on the quality of the
comments on proposed authorization of the references cited in this document, human environment and for which we
and possible renewal. may be obtained online at: https:// have not identified any extraordinary
www.fisheries.noaa.gov/permit/ circumstances that would preclude this
SUMMARY: NMFS has received a request incidental-take-authorizations-under- categorical exclusion. Accordingly,
Duck Point Development II, LLC. (DPD) marine-mammal-protection-act. In case NMFS has preliminarily determined
for authorization to take marine of problems accessing these documents, that the issuance of the proposed IHA
mammals incidental pile driving and please call the contact listed above. qualifies to be categorically excluded
removal activities during construction SUPPLEMENTARY INFORMATION: from further NEPA review.
of a second cruise ship berth and new We will review all comments
lightering float at Cannery Point (Icy Background
submitted in response to this notice
Strait) on Chichagof Island near The MMPA prohibits the ‘‘take’’ of prior to concluding our NEPA process
Hoonah, Alaska. Pursuant to the Marine marine mammals, with certain or making a final decision on the IHA
Mammal Protection Act (MMPA), NMFS exceptions. Sections 101(a)(5)(A) and request.
is requesting comments on its proposal (D) of the MMPA (16 U.S.C. 1361 et
to issue an incidental harassment seq.) direct the Secretary of Commerce Summary of Request
authorization (IHA) to incidentally take (as delegated to NMFS) to allow, upon On December 28, 2018 NMFS
marine mammals during the specified request, the incidental, but not received a request DPD for an IHA to
activities. NMFS is also requesting intentional, taking of small numbers of take marine mammals incidental to pile
comments on a possible one-year marine mammals by U.S. citizens who driving and removal activities during
renewal that could be issued under engage in a specified activity (other than construction of a second cruise ship
certain circumstances and if all commercial fishing) within a specified berth and new lightering float at
requirements are met, as described in geographical region if certain findings Cannery Point (Icy Strait) on Chichagof
Request for Public Comments at the end are made and either regulations are Island near Hoonah, Alaska. The
jbell on DSK30RV082PROD with NOTICES

of this notice. NMFS will consider issued or, if the taking is limited to application was deemed adequate and
public comments prior to making any harassment, a notice of a proposed complete on April 3, 2019. The
final decision on the issuance of the incidental take authorization may be applicant’s request is for take nine
requested MMPA authorizations and provided to the public for review. species of marine mammals by Level B
agency responses will be summarized in Authorization for incidental takings harassment and three species by Level
the final notice of our decision. shall be granted if NMFS finds that the A harassment. Neither DPD nor NMFS

VerDate Sep<11>2014 19:24 Apr 30, 2019 Jkt 247001 PO 00000 Frm 00022 Fmt 4703 Sfmt 4703 E:\FR\FM\01MYN1.SGM 01MYN1

You might also like