TSA Security Directives (pipelines and rail): cited answers and gap reviews
TSA Security Directives set cybersecurity requirements for pipelines, freight and passenger rail, and public transit. Compliance Colleague covers the directives, the Cybersecurity Implementation Plan and assessment plans, OT/IT segmentation and incident reporting.
What it covers
- The SD Pipeline-2021 series and the rail and transit directives
- Cybersecurity Implementation Plan and Assessment Plan
- Critical Cyber Systems and OT/IT segmentation
- Incident reporting to CISA and the Cybersecurity Coordinator
- The November 2024 proposed rule
Questions you can ask
- “Which of our systems are Critical Cyber Systems?”
- “What must our Cybersecurity Implementation Plan cover for segmentation?”
- “How quickly must we report a cybersecurity incident to CISA?”
Every answer cites the TSA Security Directives requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- An OT/IT network diagram checked for segmentation between zones
- Your Cybersecurity Implementation Plan checked against the directive
- An incident response procedure checked for reporting steps
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk TSA Security Directives to other standards
With TSA Security Directives in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
What it’s built from
Compliance Colleague works from our own clause-referenced material, checked against: Security Directives and Emergency Amendments (public information page) (Transportation Security Administration (TSA)); Enhancing Surface Cyber Risk Management (notice of proposed rulemaking) (Transportation Security Administration (TSA), Federal Register). It cites the clause so you can check it against your own copy.
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
More United States standards
NIST CSF · NIST SP 800-53 · NIST AI RMF · FedRAMP · CMMC 2.0 · HIPAA · CCPA / CPRA · ITAR · EAR · Section 508
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.