TSA Announces Stronger Cybersecurity Measures for Critical Transportation Agencies
Thursday, December 02, 2021 | Comments

The Department of Homeland Security’s (DHS) Transportation Security Administration (TSA) announced two new security directives and additional guidance for voluntary measures to strengthen cybersecurity across the transportation sector in response to the ongoing cybersecurity threat to surface transportation systems and associated infrastructure. These actions are among several steps DHS is taking to increase the cybersecurity of U.S. critical infrastructure.

“These new cybersecurity requirements and recommendations will help keep the traveling public safe and protect our critical infrastructure from evolving threats,” said Secretary of Homeland Security Alejandro N. Mayorkas. “DHS will continue working with our partners across every level of government and in the private sector to increase the resilience of our critical infrastructure nationwide.”

TSA is increasing the cybersecurity of the transportation sector through security directives, appropriately tailored regulations, and voluntary engagement with key stakeholders. In developing its approach, including these new security directives, TSA sought input from industry stakeholders and federal partners, including the DHS Cybersecurity and Infrastructure Security Agency (CISA), which provided expert guidance on cybersecurity threats to the transportation network and countermeasures to defend against them.

The new TSA security directives target higher-risk freight railroads, passenger rail, and rail transit, based on a determination that these requirements need to be issued immediately to protect transportation security. These directives require owners and operators to:
• Designate a cybersecurity coordinator;
• report cybersecurity incidents to CISA within 24 hours;
• Develop and implement a cybersecurity incident response plan to reduce the risk of an operational disruption; and,
• Complete a cybersecurity vulnerability assessment to identify potential gaps or vulnerabilities in their systems.

TSA is also releasing guidance recommending that all other lower-risk surface transportation owners and operators voluntarily implement the same measures. Further, TSA recently updated its aviation security programs to require that airport and airline operators implement the first two provisions above. TSA intends to expand the requirements for the aviation sector and issue guidance to smaller operators. TSA also expects to initiate a rulemaking process for certain surface transportation entities to increase their cybersecurity resiliency.

Would you like to comment on this story? Find our comments system below.

Post a comment
Name: *
Email: *
Title: *
Comment: *


No Comments Submitted Yet

Be the first by using the form above to submit a comment!


November 2022

8 - 10
Communications Marketing Conference (CMC)
Albuquerque, New Mexico

March 2023

27 - 30
International Wireless Communications Expo (IWCE) 2023
Las Vegas

More Events >

Site Navigation