Skip to main content
 

39 CFR 501.11 - Reporting Postage Evidencing System security weaknesses.

There are 2 Updates appearing in the Federal Register for 39 CFR 501. Select the tab below to view, or View eCFR (GPOAccess)
§ 501.11
Reporting Postage Evidencing System security weaknesses.
(a) For purposes of this section, provider refers to the Postage Evidencing System provider authorized under § 501.2 and its foreign affiliates, if any, subsidiaries, assigns, dealers, independent dealers, employees, and parent corporations.
(b) Each authorized provider of a Postage Evidencing System must notify the Postal Service within twenty-four (24) hours, upon discovery of the following:
(1) All findings or results of any testing known to the provider concerning the security or revenue protection features, capabilities, or failings of any Postage Evidencing System sold, leased, or distributed by it that has been approved for sale, lease, or distribution by the Postal Service or any foreign postal administration; or has been submitted for approval by the provider to the Postal Service or other foreign postal administration(s).
(2) All potential security weaknesses or methods of tampering with the Postage Evidencing Systems that the provider distributes of which it knows or should know and the Postage Evidencing System model subject to each such method. Potential security weaknesses include but are not limited to suspected equipment defects, suspected abuse by a customer or provider employee, suspected security breaches of the Computerized Meter Resetting System (CMRS) or databases housing confidential customer data relating to the use of Postage Evidencing Systems, occurrences outside normal performance, or any repeatable deviation from normal Postage Evidencing System performance.
(c) Within a time limit corresponding to the potential revenue risk to postal revenue as determined by the Postal Service, the provider must submit a written report to the Postal Service. The report must include the circumstances, proposed investigative procedure, and the anticipated completion date of the investigation. The provider must also provide periodic status reports to the Postal Service during subsequent investigation and, on completion, must submit a summary of the investigative findings.
(d) The provider must establish and adhere to timely and efficient procedures for internal reporting of potential security weaknesses and shall provide a copy of such internal reporting procedures and instructions to the Postal Service for review.
(e) Failure to comply with this section may result in suspension of approval under § 501.6 or the imposition of sanctions under § 501.12.

Title 39 published on 2012-07-01

The following are only the Rules published in the Federal Register after the published date of Title 39.

For a complete list of all Rules, Proposed Rules, and Notices view the Rulemaking tab.

  • 2013-02-06; vol. 78 # 25 - Wednesday, February 6, 2013
    1. 78 FR 8407 - Authorization To Manufacture and Distribute Postage Evidencing Systems; Discontinued Indicia
      GPO FDSys XML | Text
      POSTAL SERVICE
      Final rule.
      Effective date: January 1, 2016.
      39 CFR Part 501

This is a list of United States Code sections, Statutes at Large, Public Laws, and Presidential Documents, which provide rulemaking authority for this CFR Part.

This list is taken from the Parallel Table of Authorities and Rules provided by GPO [Government Printing Office].

It is not guaranteed to be accurate or up-to-date, though we do refresh the database weekly. More limitations on accuracy are described at the GPO site.


United States Code
USC : Title 5 - GOVERNMENT ORGANIZATION AND EMPLOYEES

§ 552 - Public information; agency rules, opinions, orders, records, and proceedings

USC : Title 5 - APPENDIX

5a USC Rule - Definitions

USC : Title 39 - POSTAL SERVICE

§ 101 - Postal policy

§ 410 - Application of other laws

§ 2601 - Collection and adjustment of debts

§ 2605 - Suits to recover wrongful or fraudulent payments

Public Laws

95-452

Title 39 published on 2012-07-01

The following are ALL rules, proposed rules, and notices (chronologically) published in the Federal Register relating to 39 CFR 501 after this date.

  • 2013-02-06; vol. 78 # 25 - Wednesday, February 6, 2013
    1. 78 FR 8407 - Authorization To Manufacture and Distribute Postage Evidencing Systems; Discontinued Indicia
      GPO FDSys XML | Text
      POSTAL SERVICE
      Final rule.
      Effective date: January 1, 2016.
      39 CFR Part 501