Le Lézard
Classified in: Transportation, Science and technology
Subject: PSF

TSA renews cybersecurity requirements for passenger and freight railroad carriers


Requirements seek to reduce the risk cybersecurity threats pose to critical railroad operations and facilities

WASHINGTON, Oct. 23, 2023 /PRNewswire/ -- The Transportation Security Administration (TSA) announced updates to three security directives (SD) regulating passenger and freight railroad carriers in the continued effort to enhance the cybersecurity of surface transportation systems and associated infrastructure. These revised directives, which were set to expire on Oct. 24, have been renewed for one year, and include updates that seek to strengthen the industry's defenses against cyberattacks.

Developed with comprehensive input from industry stakeholders and federal partners, including the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Transportation's Federal Railroad Administration (FRA), the three security directives further enhance cybersecurity preparedness and resilience for the nation's critical railroad operations. It requires TSA-specified passenger and freight railroad carriers to take action to prevent disruption and degradation to their infrastructure with a flexible, performance-based approach, consistent with TSA's requirements for pipeline operators.

"The renewal is the right thing to do to keep the nation's railroad systems secure against cyber threats, and these updates sustain the strong cybersecurity measures already in place for the railroad industry," said TSA Administrator David Pekoske. "TSA's partnerships with CISA, FRA and the railroad industry have been, and will continue to be, instrumental in our work towards strengthening resilience and preventing harm."

The revised security directives, Enhancing Rail Cybersecurity, and the revised SD series, Enhancing Public Transportation and Passenger Railroad Cybersecurity, include a requirement for covered owners and operators to test a minimum of two objectives in their Cybersecurity Incident Response Plan every year. They also require including employees who have been identified by their positions as active participants in these exercises.

The revised security directive series, Rail Cybersecurity Mitigation Actions and Testing, also requires railroad owners and operators to annually submit an updated Cybersecurity Assessment Plan to TSA for review and approval and report the results from the previous year using a schedule for assessing and auditing specific cybersecurity measures for effectiveness such that all cybersecurity measures are assessed within a three-year period.

To view TSA's security directives and guidance documents, please visit: TSA Cybersecurity Toolkit or https://www.tsa.gov/sd-and-ea.

SOURCE Transportation Security Administration


These press releases may also interest you

at 07:30
The Fintech Open Source Foundation (FINOS), the financial services umbrella of the Linux Foundation, today announced the formation of the AI Readiness for Financial Services Industry (FSI) Special Interest Group (SIG) as part of its broader...

at 07:30
Silvaco Group, Inc. ("Silvaco"), a provider of TCAD, EDA software, and SIP solutions that enable semiconductor design and AI through software and innovation, today announced it has launched the roadshow for its initial public offering ("IPO") of...

at 07:30
nCino, Inc. , a pioneer in cloud banking for the global financial services industry, today announced that Libro Credit Union has selected nCino's Cloud Banking Platform to empower its employees through data, achieve faster time to value and create a...

at 07:27
In keeping with its growth plans, the global digital solutions company Marlabs LLC today announced the appointment of Arun Mukunda as its Chief Revenue Officer (CRO). Arun will join the company's executive leadership team. As the CRO, Arun will lead...

at 07:21
An interview event was held in Lianyungang City of east China's Jiangsu Province from April 26 to 30 to learn about the city's huge development over the past 40 years benefiting from China's reform and opening up. Since becoming one of the first...

at 07:18
Heimdal is proud to announce a strategic partnership with DACTA, aimed at significantly enhancing cybersecurity defenses across the Asia-Pacific (APAC) region. This partnership reflects Heimdal's commitment to extending its innovative cybersecurity...



News published on and distributed by: