TSA Announces New Security Directives for Rail Sector
Time 2 Minute Read

On December 2, 2021, the Transportation Security Administration (“TSA”) announced that it issued two security directives requiring higher-risk freight railroads, passenger rail and rail transit to implement measures to strengthen cybersecurity within the sector. In its press release, the TSA stated that it determined these requirements needed to be issued immediately to protect the transportation sector. The TSA also stated that it sought input from industry stakeholders and federal partners, including the Cybersecurity and Infrastructure Security Agency (“CISA”), in developing its approach.

Key among the requirements in the security directives is a requirement to report cybersecurity incidents to CISA within 24 hours. The directives also require these rail transportation owners and operators to (1) designate a cybersecurity coordinator, (2) develop and implement a cybersecurity incident response plan, and (3) conduct a cybersecurity vulnerability assessment to identify potential gaps or vulnerabilities in their systems.

Homeland Security Secretary Alejandro Mayorkas said the new requirements “will help keep the traveling public safe and protect our critical infrastructure from evolving threats” and indicated that the Department of Homeland Security will continue public and private partnerships to increase the resilience of critical infrastructure. Ian Jefferies, President and Chief Executive Officer of the Association of American Railroads, said in a statement that “[r]ailroads take these threats seriously and value our productive work with government partners to keep the network safe.”

The press release also announces that the TSA is releasing guidance recommending that all other lower-risk rail transportation owners and operators voluntarily implement the same measures.

You May Also Be Interested In

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Time 5 Minute Read

On January 8, 2025, the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency published finalized Security Requirements for Restricted Transactions as designated by the Department of Justice in the DOJ’s final rulemaking, each pursuant to Executive Order 14117 (Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern). The Requirements and DOJ rule will go into effect on April 8, 2025.

Time 4 Minute Read

On December 27, 2024, the U.S. Department of Justice issued a comprehensive final rule implementing Executive Order 14117, Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern. The Final Rule will go into effect on April 8, 2025, with the exception of certain due diligence, audit and reporting obligations, which will become effective on October 5, 2025.

Time 4 Minute Read

In November 2024, the Department of Commerce’s Artificial Intelligence Safety Institute established a new taskforce to research and test AI models in areas critical to national security and public safety, while ODNI released guidance on the acquisition and use of foundation AI models, both part of the national security community’s response to the directives of the recent White House AI Memo and Executive Order 14110.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page