Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

Maryland Man Pleads Guilty to Federal Charge for Threatening a Member of Congress

January 27, 2023

Când urmează CtEDO să publice soluția sa în cauza Filat

January 27, 2023

Tauber îl vrea pe Șor premier și nu neagă că ar candida la Președinție

January 27, 2023
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Friday, January 27
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • Maryland Man Pleads Guilty to Federal Charge for Threatening a Member of Congress
  • Când urmează CtEDO să publice soluția sa în cauza Filat
  • Tauber îl vrea pe Șor premier și nu neagă că ar candida la Președinție
  • Urmărirea penală în privința lui Andronachi și a unui complice, la final
  • SEAL Team Six kills key ISIS facilitator Bilal al-Sudani, 10 operatives in counterterrorism mission in Somalia
  • Victor Nichituș: Guvernul stă cu mâna întinsă către structurile europene
  • Jeremy Hunt warns economic ‘discipline’ needed to get inflation under control
  • Va candida la funcția de bașcan al Găgăuziei? Răspunsul lui Stoianoglo
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » TSA Issues New Cybersecurity Requirements for Passenger and Freight Railroad Carriers

TSA Issues New Cybersecurity Requirements for Passenger and Freight Railroad Carriers

October 19, 20223 Mins Read Cybersecurity
Share
Facebook Twitter LinkedIn Pinterest Email

The Transportation Security Administration (TSA) has announced a new cybersecurity security directive regulating designated passenger and freight railroad carriers. Building on the TSA’s work to strengthen defenses in other transportation modes, this security directive will further enhance cybersecurity preparedness and resilience for the nation’s railroad operations.

Developed with extensive input from industry stakeholders and federal partners, including the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Transportation’s Federal Railroad Administration (FRA), this Enhancing Rail Cybersecurity – SD 1580/82-2022-01 directive strengthens cybersecurity requirements and focuses on performance-based measures to achieve critical cybersecurity outcomes.

“The nation’s railroads have a long track record of forward-looking efforts to secure their network against cyber threats and have worked hard over the past year to build additional resilience, and this directive, which is focused on performance-based measures, will further these efforts to protect critical transportation infrastructure from attack,” said TSA Administrator David Pekoske. “We are encouraged by the significant collaboration between TSA, FRA, CISA and the railroad industry in the development of this security directive.

The security directive requires that TSA-specified passenger and freight railroad carriers take action to prevent disruption and degradation to their infrastructure to achieve the following critical security outcomes:

  1. Develop network segmentation policies and controls to ensure that the Operational Technology system can continue to safely operate in the event that an Information Technology system has been compromised and vice versa;
  2. Create access control measures to secure and prevent unauthorized access to critical cyber systems;
  3. Build continuous monitoring and detection policies and procedures to detect cybersecurity threats and correct anomalies that affect critical cyber system operations; and
  4. Reduce the risk of exploitation of unpatched systems through the application of security patches and updates for operating systems, applications, drivers, and firmware on critical cyber systems in a timely manner using a risk-based methodology.

Passenger and freight railroad carriers are required to:

  1. Establish and execute a TSA-approved Cybersecurity Implementation Plan that describes the specific cybersecurity measures the passenger and freight rail carriers are utilizing to achieve the security outcomes set forth in the security directive.
  2. Establish a Cybersecurity Assessment Program to proactively test and regularly audit the effectiveness of cybersecurity measures and identify and resolve vulnerabilities within devices, networks, and systems.

This is the latest in TSA’s performance-based security directives; previous security directives include requirements such as reporting significant cybersecurity incidents to CISA, establishing a cybersecurity point of contact, developing and adopting a cybersecurity incident response plan, and completing a cybersecurity vulnerability assessment. 

TSA also intends to begin a rulemaking process, which would establish regulatory requirements for the rail sector following a public comment period.

Find out more at TSA’s cybersecurity toolkit

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

U.K. Warns of Targeted Phishing Attacks from Russia and Iran

January 26, 2023 Cybersecurity

FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony’s Horizon Bridge Currency Theft

January 25, 2023 Cybersecurity

CISA Releases Report for K-12 Schools to Help Address Evolving Cybersecurity Threats

January 24, 2023 Cybersecurity

Vulnerabilities in TP-Link routers, WR710N-V1-151022 and Archer C5 V2

January 24, 2023 Cybersecurity

Arrests Across Europe and U.S. in Bitzlato Crackdown

January 24, 2023 Cybersecurity

GAO Highlights Urgent Federal Cybersecurity Issues

January 23, 2023 Cybersecurity
Don't Miss
Moldova

Când urmează CtEDO să publice soluția sa în cauza Filat

By woe whJanuary 27, 20230

Curtea Europeană a Drepturilor Omului (CtEDO) va face publică soluția sa în cauza Filat c.…

Tauber îl vrea pe Șor premier și nu neagă că ar candida la Președinție

January 27, 2023

Urmărirea penală în privința lui Andronachi și a unui complice, la final

January 26, 2023

SEAL Team Six kills key ISIS facilitator Bilal al-Sudani, 10 operatives in counterterrorism mission in Somalia

January 26, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Jeremy Hunt warns economic ‘discipline’ needed to get inflation under control

January 26, 2023

Va candida la funcția de bașcan al Găgăuziei? Răspunsul lui Stoianoglo

January 26, 2023

Tăbîrță, despre integrarea UE: Moldova nu a avut evoluții democratice

January 26, 2023

Munteanu l-a criticat pe Nosatîi pentru poziția privind chestiunea NATO

January 26, 2023

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2023 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.