TSA Introduces Groundbreaking Cyber Risk Management Regulation
The Transportation Security Administration (TSA) has taken a significant step in enhancing the cybersecurity of the nation’s vital transportation systems. By publishing a recent Notice of Proposed Rulemaking, TSA aims to implement strict cyber risk management and reporting obligations for specific owners and operators in the surface transportation sector.
Collaboration and Commitment to Cybersecurity
In his statement, TSA Administrator David Pekoske highlighted the close collaboration between TSA and industry partners that has shaped these proposed regulations. The essence of the rule is to further solidify the cybersecurity framework already being adopted by various surface transportation stakeholders. Pekoske emphasized the importance of industry and public feedback on the proposed regulations, underscoring the TSA's commitment to an inclusive regulatory process.
Performance-Based Requirements
This proposed rule builds upon TSA's longstanding performance-based requirements. Since 2021, TSA has issued annual Security Directives that reinforce cybersecurity measures. This initiative leverages established frameworks from the National Institute of Standards and Technology and aligns with cross-sector cybersecurity performance goals devised by the Cybersecurity and Infrastructure Security Agency (CISA).
Key Proposals of the New Rule
At the heart of this regulation are several key proposals aimed at strengthening cybersecurity across the transportation sector:
Establishing Comprehensive Cyber Risk Management Programs
The rule mandates that certain owner/operators, particularly those involved in pipeline, freight railroad, passenger railroad, and rail transit, who exhibit a heightened cybersecurity risk profile, must implement and uphold a robust cyber risk management program. This comprehensive approach ensures the readiness of these entities to face potential cyber threats.
Reporting Cybersecurity Incidents
Additionally, the proposed regulation requires these owner/operators, along with higher-risk bus-only public transportation and over-the-road bus operators, to report any significant cybersecurity incidents to CISA. This requirement extends beyond just physical security concerns, widening the net of accountability to include digital threats as well.
Designation of Security Coordinators
Another integral component involves extending TSA’s current requirements for rail and bus operations to pipeline owner/operators that are deemed higher-risk. This includes appointing a physical security coordinator responsible for reporting significant security issues, enhancing overall security through designated accountability.
The Importance of Effective Cybersecurity Posture
TSA firmly believes that maintaining a robust cybersecurity posture is critical for the ability of the surface transportation sector to effectively manage cyber risks. The proposed requirements are expected to significantly bolster the cybersecurity resilience across this essential sector, ensuring a safer transportation network for all.
Frequently Asked Questions
What is the purpose of the TSA's proposed rule?
The TSA's proposed rule aims to establish cyber risk management and reporting requirements for certain surface transportation owners and operators to enhance cybersecurity.
Who will be affected by the new cyber risk management program?
Pipelines, freight railroads, passenger railroads, and related transportation operators with high cybersecurity risks will be required to implement these programs.
What kind of reporting is required under the proposed rule?
Operators must report cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency (CISA) in addition to any significant physical security issues.
How does the TSA plan to involve industry feedback?
The TSA welcomes input from industry stakeholders and the public to refine the proposed regulations and ensure they meet sector needs.
Why is cybersecurity vital for surface transportation?
A strong cybersecurity framework is essential for protecting critical infrastructure and ensuring the transportation sector can manage potential cyber risks effectively.