Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

Beitnere-Le Galla pieņēmusi lēmumu nekandidēt Saeimas vēlēšanās ģimenes apstākļu dēļ

August 7, 2022

Unde activează fostul vicepremier pe Reintegrare, Vladislav Kulminski

August 7, 2022

Thatcher’s energy secretary says Tory leadership contenders’ response to price spike ‘inadequate’

August 7, 2022
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Sunday, August 7
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • Beitnere-Le Galla pieņēmusi lēmumu nekandidēt Saeimas vēlēšanās ģimenes apstākļu dēļ
  • Unde activează fostul vicepremier pe Reintegrare, Vladislav Kulminski
  • Thatcher’s energy secretary says Tory leadership contenders’ response to price spike ‘inadequate’
  • Jos sau nu guvernarea? Expert: Vom vedea situația când vor fi proteste
  • Ce cadouri a primit prim-ministra de la diferiți oficiali
  • Beijing continuing to send warships, aircraft toward Taiwan after Pelosi visit
  • Thousands of infected blood victims to receive £100,000 compensation
  • Penny Mordaunt claims Liz Truss ‘misinterpreted’ after dismissing cost of living ‘handouts’
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » TSA Revises and Reissues Cybersecurity Requirements for Pipeline Owners and Operators

TSA Revises and Reissues Cybersecurity Requirements for Pipeline Owners and Operators

July 22, 20224 Mins Read Cybersecurity
Share
Facebook Twitter LinkedIn Pinterest Email

The Transportation Security Administration (TSA) has announced the revision and reissuance of its Security Directive regarding oil and natural gas pipeline cybersecurity. This revised directive will continue the effort to build cybersecurity resiliency for the nation’s critical pipelines.

Developed with extensive input from industry stakeholders and federal partners, including the Department’s Cybersecurity and Infrastructure Security Agency (CISA), the reissued security directive for critical pipeline companies follows the directive announced in July 2021. The directive extends cybersecurity requirements for another year, and focuses on performance-based – rather than prescriptive – measures to achieve critical cybersecurity outcomes.

“TSA is committed to keeping the nation’s transportation systems safe from cyberattacks. This revised security directive follows significant collaboration between TSA and the oil and natural gas pipeline industry. The directive establishes a new model that accommodates variance in systems and operations to meet our security requirements,” said TSA Administrator David Pekoske. “We recognize that every company is different, and we have developed an approach that accommodates that fact, supported by continuous monitoring and auditing to assess achievement of the needed cybersecurity outcomes. We will continue working with our partners in the transportation sector to increase cybersecurity resilience throughout the system and acknowledge the significant work over the past year to protect this critical infrastructure.”

Following the May 2021 ransomware attack on a major pipeline, TSA issued several security directives mandating that critical pipeline owners and operators implement several urgently needed cybersecurity measures. In the fourteen months since this attack, the threat posed to this sector has evolved and intensified. Reducing this national security risk requires significant public and private collaboration.

Through this revised and reissued security directive, TSA continues to take steps that protect transportation infrastructure from evolving cybersecurity threats. TSA also intends to begin the formal rulemaking process, which will provide the opportunity for the submission and consideration of public comments.

The reissued security directive takes an innovative, performance-based approach to enhancing security, allowing industry to leverage new technologies and be more adaptive to changing environments. The security directive requires that TSA-specified owners and operators of pipeline and liquefied natural gas facilities take action to prevent disruption and degradation to their infrastructure to achieve the following security outcomes:

  1. Develop network segmentation policies and controls to ensure that the Operational Technology system can continue to safely operate in the event that an Information Technology system has been compromised and vice versa;
  2. Create access control measures to secure and prevent unauthorized access to critical cyber systems;
  3. Build continuous monitoring and detection policies and procedures to detect cybersecurity threats and correct anomalies that affect critical cyber system operations; and
  4. Reduce the risk of exploitation of unpatched systems through the application of security patches and updates for operating systems, applications, drivers and firmware on critical cyber systems in a timely manner using a risk-based methodology.

Pipeline owners and operators are required to:

  1. Establish and execute a TSA-approved Cybersecurity Implementation Plan that describes the specific cybersecurity measures the pipeline owners and operators are utilizing to achieve the security outcomes set forth in the security directive.
  2. Develop and maintain a Cybersecurity Incident Response Plan that includes measures the pipeline owners and operators will take in the event of operational disruption or significant business degradation caused by a cybersecurity incident.
  3. Establish a Cybersecurity Assessment Program to proactively test and regularly audit the effectiveness of cybersecurity measures and identify and resolve vulnerabilities within devices, networks, and systems.

These requirements are in addition to the previously established requirement to report significant cybersecurity incidents to CISA, establish a cybersecurity point of contact and conduct an annual cybersecurity vulnerability assessment.

Read the directive and further guidance at TSA

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

U.K. National Health Service Hit by Cyber Attack

August 6, 2022 Cybersecurity

IPAWS Advisory: Emergency Alert System (EAS) Vulnerability

August 5, 2022 Cybersecurity

GAO Warns Coast Guard of IT and OT Cybersecurity Vulnerabilities

August 5, 2022 Cybersecurity

TMF Invests in Improving Public-Facing Services, Bolstering Cybersecurity

August 4, 2022 Cybersecurity

Bipartisan Legislation Aims to Protect Federal Data Centers from Extreme Weather, Cyber Attacks, and Other Disasters

August 2, 2022 Cybersecurity

HSToday Welcomes Bob Kolasky, Former Head of DHS National Risk Management Center, as Editorial Board Member and Columnist

August 1, 2022 Cybersecurity
Don't Miss
Moldova

Unde activează fostul vicepremier pe Reintegrare, Vladislav Kulminski

By woe whAugust 7, 20220

Fostul vicepremier pe Reintegrare, Vladislav Kulminski, are o nouă funcție. Acesta participă la inspectarea navelor…

Thatcher’s energy secretary says Tory leadership contenders’ response to price spike ‘inadequate’

August 7, 2022

Jos sau nu guvernarea? Expert: Vom vedea situația când vor fi proteste

August 7, 2022

Ce cadouri a primit prim-ministra de la diferiți oficiali

August 7, 2022
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Thousands of infected blood victims to receive £100,000 compensation

August 7, 2022

Penny Mordaunt claims Liz Truss ‘misinterpreted’ after dismissing cost of living ‘handouts’

August 7, 2022

Liz Truss extends polling lead over Rishi Sunak in race for prime minister

August 7, 2022

China keeps up pressure on Taiwan with 4th day of drills

August 7, 2022

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2022 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.