logo

TSA Proposes Cyber-Risk Mandates for Pipelines, Transportation Systems

ID: 0b716f47-b7a7-5ee1-9656-24f0c744a387

STIX ID: report--0b716f47-b7a7-5ee1-9656-24f0c744a387

Feed Name: Dark Reading

Date Published: 2024-11-15

Date Updated: 2026-04-21

Author: Jennifer Lawinski, Contributing Writer

...
...

The Transportation Security Administration announced a Notice of Proposed Rulemaking to require cybersecurity risk management and incident reporting across surface transportation and aviation, extending NIST-aligned practices and CISA performance goals; the proposal mandates comprehensive risk programs, incident reporting to CISA, designation of a physical security coordinator, annual cybersecurity evaluations, vulnerability assessments, and operational implementation plans, affecting about 73 freight railroads, 34 public transit and passenger rail agencies, 71 over-the-road bus operators, and 115 pipeline facilities, with public comments open until Feb. 2, 2025, as part of efforts following the Colonial Pipeline ransomware incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.