Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 21 Next »

Business Context, Transaction Types and Volume

In the Northwest Region the states have existing fish ticket programs (actually 26 of them).  These were originally developed for revenue purposes, but the fish tickets have become multi-purpose documents, functioning as a receipt between buyer and seller, as a record of catch (and sometimes of effort) for fisheries management, as documentation of participation in a fishery, as a record of gross profit for calculation of crew shares, as documentation of value for economic analysis, and of course the original purpose of government tax records.

Examples of state fish tickets include whiting in Washington and Salmon in California.  The information captured on fish tickets has been standardized to the point that PACFIN can aggregate fish ticket data from each state into a regional database. 

Whiting fisheries in the Northwest Region are currently operating under an Exempted Fishing Permit (the shoreside whiting EFP).  The whiting EFP recognizes that there is a need to track bycatch on a near real-time basis, and proposed electronic reporting, or an e-ticket program, as a mechanism.  Under this proposal the e-ticket reporting is in parallel with the state's traditional paper fish tickets. PSMFC is currently developing this e-ticket program, emulating and coexisting with state fish ticket programs, capturing data into the PACFIN database directly from participating processors without going through the states (the states may subsequently data-enter from the paper copies into their own local databases, or, they may download data from PACFIN to complete their local databases.)  This pilot project is emulating state programs with no change in management approach, data elements, etc.  This approach anticipates that the new system will demonstrate the utility of e-tickets (near real-time tracking of catch and bycatch, speed of reconciling, increased efficiency) while allowing states flexibility and time to adopt at their convenience.

Under ammendment 10, which replaces the Whiting EFP program, e-reporting of whiting will continue to be required.  As the program gains maturity and acceptance it is hoped that the states may want to use e-ticket reporting for black cod or other fisheries.

The current whiting fishery fish ticket volume is 40 boats for up to 20 days of fishing, for a ceiling of approximately 800 transactions.  The potential of e-ticket transactions would eventually approach the total volume of fish tickets on the West Coast.

Business Drivers

Near to real-time information on catch and bycatch of overfished species is required as an element of National Standard 1 (NS1).  For the Whiting fishery an e-ticket provides the most effective mechanism for acquiring near real-time catch and bycatch information.  Fish ticket record-keeping and reporting regulations require processor and vessel operator signatures for accountability.  An e-signature feature is required to make e-ticket reporting (without a corresponding paper document for signatures) feasible.

By near real-time we mean an elapsed time of less than 48 hours from the completion of the vessel offload to data analysis in the agencies catch and bycatch monitoring systems.

Business Risk in the Permit Context

NIST 800-30: Risk Management Guide for Information Technology Systems defines risk as a function of the likelihood of a given threat-source's exercising a particular potential vulnerability, and the resulting impact of that adverse event on the organization.  The threat and vulnerability identification process that follows is based on NIST 800-30.

Users and functionality

The trawl fleet (whiting) is most technology sophisticated fleet in the Northwest Region, but, by regulation fish tickets are reported by processors.  Whiting processors are large permanent shoreside facilities which will be completely comfortable with this type of technology.  If/when e-ticket technology expands to other fisheries it is important to recognize that some processors are in the "white van fleet", without a fixed base of operations or any technology beyond a cell phone.

Data sensitivity and security

Information collected pursuant to requirements of the MSA is protected by its confidentiality provisions at § 402 and under its implementing regulations at 50 CFR Part 600 Subpart E, including NOAA Administrative Order (NAO) 216-100. Additional protections of the Privacy Act and FOIA apply to such data as well as those collected under the Halibut Act. 

Mitigating controls

Perhaps the most significant mitigating control is that in commercial fisheries transactions, both parties to the transaction (typically the fisher and the fish processor) are permitted entities and each has some responsibility for accurate and complete record-keeping and reporting (for example, the fisher may be required to keep a logbook showing fishing efforts and catch, while the processor is required to report fish purchased). In these transactions it is typical for the parties to the transactions to have opposite and balancing interests (for example, when a fisher is selling fish to a processor, the fisher wants the amount paid to be high, while the processor wants the amount paid to be low). These multiple sources of information and counter-balanced incentives tend to make deception more difficult to initiate and sustain.

Another mitigating control is that under the authority of the Debt Collection Improvement Act (31 U.S.C. 7701), NMFS would collect Tax Identification Number information from individuals in order to issue, renew, or transfer fishing permits or to make nonpermit registrations.

The vessels and processors involved are permitted and therefore have a prior "trusted relationship" with NMFS.  In many cases this prior relationship involves confirming vessel ownership with the US Coast Guard, verifying participation in prior fisheries through previously submitted state or federal fish tickets or logbooks, confirmation of business ownership, etc.

Threat and Vulnerability Identification

Vulnerability

Threat-source

Threat Action

Category of Harm

Likelihood of Occurrence

Impact of Harm

E-signature Cost Benefit Assessment

System unavailability

Error, component failure, or act of God

Power failure, network failure, computer component failure, operator error, software failure, capacity constraint,  etc.

Inconvenience, distress or damage to standing or reputation

Moderate: failures will happen, but competently managed systems typically have availability records of 99% or better

Low: for fishery management decision support typical availability is adequate.  Even in the event of a systemic failure fishery management decision-making would continue and unavailability would be a short-term inconvenience.  Smaller scale failures, for instance a failure that prevents reporting from one processor, would be a minor inconvenience.

 

System unavailability

Vandalism

Internet security exploit such as denial-of-service attack

Inconvenience, distress or damage to standing or reputation

Low: this is not an high-profile Internet system and should not be a particularly attractive target.  Also, if necessary, the system could be hosted in a data center with an incident response capability that could deal with all but the most sophisticated attacks. 

Low: even in the event of a systemic failure fishery management decision-making would continue and unavailability would be a short-term inconvenience

 

System misuse

System administrator, operator, or other agency user

Abuse of insider knowledge and access for unauthorized use or release of information

Unauthorized release of sensitive information

Low: agency staff have significant incentives to behave appropriately and periodic training in ethics and computer security

Moderate: at worst, a release of personal or commercially sensitive information to unauthorized parties resulting in loss of confidentiality with an expected serious adverse effect on organizational operations.

 

Under-reporting or misreporting catch

Fisher and processor in collusion

Fisher and processor collude to under-report or misreport, to mislead fisheries managers and evade fisheries management controls

Harm to agency programs or public interests

Low: permitted parties have a lot to lose and there are enough checks and balances in the system to discourage fraud

Moderate: at worst, a serious adverse effect to public interests.  For example, in a commercial landing the species could be misreported from an overfished species to a less restricted species to evade a fisheries closure action, with potentially significant damage to the overfished species public resource

 

Impersonation in e-ticket transactions

Common criminal/identity thief

Impersonation using stolen identity credentials, to receive full market price for stolen fish

Inconvenience, distress or damage to standing or reputation

Low: e-ticket transactions take place in a context of fish delivery, and the fisher and processor are normally known to each other

Low: someone would be likely to notice and when detected, the impact could be effectively mitigated.  The impact would be limited to the parties whose identity and fish have been stolen

 

Impersonation in e-ticket transactions

Competitor

Impersonation using stolen identity credentials, to sell fish without debiting own quota

Inconvenience, distress or damage to standing or reputation

Low: a competitor might have a motive, but an electronic system does not make them more likely to have means or opportunity.  Risk exposure is not significantly different in electronic transactions than it is in paper transactions.

Low: impersonated parties would be likely to notice and when detected, the impact could be effectively mitigated

 

Repudiation to escape accountability

Customer (fisher or processor)

Signer claims "I didn't sign that"

Inconvenience, distress or damage to standing or reputation

Low: in most cases a customer who repudiated an e-ticket document submission could then be prosecuted for fishing or processing without meeting record-keeping and reporting obligations.  There will generally be independent evidence of the fishing or processing activity (follow the fish.)

Low: agency might expend effort to resolve, but the distress would be limited and short-term

 

Categories of Harm and Impact Definitions for reference

HARM

LOW IMPACT

MODERATE IMPACT

HIGH IMPACT

Inconvenience, distress, or damage to standing or reputation

at worst, limited, short-term inconvenience, distress or embarrassment to any party

at worst, serious short term or limited long-term inconvenience, distress or damage to the standing or reputation of any party

severe or serious long-term inconvenience, distress or damage to the standing or reputation of any party (ordinarily reserved for situations with particularly severe effects or which affect many individuals)

Financial loss

at worst, an insignificant or inconsequential unrecoverable financial loss to any party

at worst, a serious unrecoverable financial loss to any party

severe or catastrophic unrecoverable financial loss to any party

Agency liability

at worst, an insignificant or inconsequential agency liability

at worst, a serious agency liability

severe or catastrophic agency liability

Harm to agency programs or public interests

at worst, a limited adverse effect on organizational operations or assets, or public interests. Examples of limited adverse effects are: (1) mission capability degradation to the extent and duration that the organization is able to perform its primary functions with noticeably reduced effectiveness, or (2) minor damage to organizational assets or public interests

at worst, a serious adverse effect on organizational operations or assets, or public interests. Examples of serious adverse effects are: (1) significant mission capability degradation to the extent and duration that the organization is able to perform its primary functions with significantly reduced effectiveness; or (2) significant damage to organizational assets or public interests

a severe or catastrophic adverse effect on organizational operations or assets, or public interests. Examples of severe or catastrophic effects are: (1) severe mission capability degradation or loss of to the extent and duration that the organization is unable to perform one or more of its primary functions; or (2) major damage to organizational assets or public interests

Unauthorized release of sensitive information

at worst, a limited unauthorized release of personal, U.S. government sensitive, or commercially sensitive information to unauthorized parties resulting in a loss of confidentiality with an expected limited adverse effect on organizational operations, organizational assets, or individuals

at worst, a release of personal, U.S. government sensitive, or commercially sensitive information to unauthorized parties resulting in loss of confidentiality with an expected serious adverse effect on organizational operations, organizational assets, or individuals.

a release of personal, U.S. government sensitive, or commercially sensitive information to unauthorized parties resulting in loss of confidentiality with an expected severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals

Harm to personal safety

at worst, minor injury not requiring medical treatment

at worst, moderate risk of minor injury or limited risk of injury requiring medical treatment

a risk of serious injury or death

Civil or criminal violations

at worst, a risk of civil or criminal violations of a nature that would not ordinarily be subject to enforcement efforts

at worst, a risk of civil or criminal violations that may be subject to enforcement efforts

a risk of civil or criminal violations that are of special importance to enforcement programs

  • No labels