[Code of Federal Regulations]
[Title 39, Volume 1]
[Revised as of January 1, 2007]
From the U.S. Government Printing Office via GPO Access
[CITE: 39CFR501.11]

[Page 165-166]
 
                        TITLE 39--POSTAL SERVICE
 
                 CHAPTER I--UNITED STATES POSTAL SERVICE
 
PART 501_AUTHORIZATION TO MANUFACTURE AND DISTRIBUTE POSTAGE
 
Sec.  501.11  Reporting Postage Evidencing System security weaknesses.

    (a) For purposes of this section, provider refers to the Postage 
Evidencing System provider authorized under Sec.  501.2 and its foreign 
affiliates, if any, subsidiaries, assigns, dealers, independent dealers, 
employees, and parent corporations.
    (b) Each authorized provider of a Postage Evidencing System must 
notify the Postal Service within twenty-four (24) hours, upon discovery 
of the following:
    (1) All findings or results of any testing known to the provider 
concerning the security or revenue protection features, capabilities, or 
failings of any Postage Evidencing System sold, leased, or distributed 
by it that has

[[Page 166]]

been approved for sale, lease, or distribution by the Postal Service or 
any foreign postal administration; or has been submitted for approval by 
the provider to the Postal Service or other foreign postal 
administration(s).
    (2) All potential security weaknesses or methods of tampering with 
the Postage Evidencing Systems that the provider distributes of which it 
knows or should know and the Postage Evidencing System model subject to 
each such method. Potential security weaknesses include but are not 
limited to suspected equipment defects, suspected abuse by a customer or 
provider employee, suspected security breaches of the Computerized Meter 
Resetting System (CMRS) or databases housing confidential customer data 
relating to the use of Postage Evidencing Systems, occurrences outside 
normal performance, or any repeatable deviation from normal Postage 
Evidencing System performance.
    (c) Within a time limit corresponding to the potential revenue risk 
to postal revenue as determined by the Postal Service, the provider must 
submit a written report to the Postal Service. The report must include 
the circumstances, proposed investigative procedure, and the anticipated 
completion date of the investigation. The provider must also provide 
periodic status reports to the Postal Service during subsequent 
investigation and, on completion, must submit a summary of the 
investigative findings.
    (d) The provider must establish and adhere to timely and efficient 
procedures for internal reporting of potential security weaknesses and 
shall provide a copy of such internal reporting procedures and 
instructions to the Postal Service for review.
    (e) Failure to comply with this section may result in suspension of 
approval under Sec.  501.6 or the imposition of sanctions under Sec.  
501.12.