TSA Pipeline Security Guideline Update
ID: 3ad2d50e-b5d8-50b4-a26c-cfa74b2d6164
STIX ID: report--3ad2d50e-b5d8-50b4-a26c-cfa74b2d6164
Feed Name: Dragos Blog
This report summarizes TSA’s updated Pipeline Security Guidelines and Security Directive, which mandate a 24/7 Cybersecurity Coordinator (with an alternate), baseline and enhanced asset management for OT, regular cyber risk and vulnerability assessments, and a 12-hour requirement to report cyber/physical incidents impacting IT/OT to CISA with specific details (IPs, domains, malware, compromised accounts, impacts, response activities, and incident types). It advises pipeline owners/operators to evaluate maturity using frameworks (e.g., C2M2), understand real-world threats, test incident response plans (including tabletop exercises and new reporting requirements), and improve OT asset visibility to create a sustainable, long-term cybersecurity roadmap.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
