TSA Pipeline Cybersecurity Directives
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Assessment
Per TSA SD: Cybersecurity Assessment Programme including annual assessment + tabletop + technical assessment + maintain documentation.
- TSA Pipeline evidence for TSAPIPE-4
- coordinator + 24-hr reporting partial
Implementation
Per TSA Pipeline Cybersecurity Directives (SD02-2024-01 + Security Programs): implementation plan. Requirements include (a) Cybersecurity Implementation Plan + (b) Cybersecurity Coordinator Designation + 24/7 available + (c) Vulnerability Assessment + (d) Remediation Planning + (e) cooperate with TSA + CISA.
- TSA Pipeline evidence for TSAPIPE-1
- coordinator + 24-hr reporting partial
Incident Reporting
Per TSA SD: incident reporting to CISA within 24 hours of identification + cooperate with FBI + maintain incident log.
- TSA Pipeline evidence for TSAPIPE-3
- coordinator + 24-hr reporting partial
Network Segmentation
Per TSA SD: segmentation. Requirements include (a) OT/IT Network Segmentation + (b) Access Control + privileged access + (c) maintain documented network architecture.
- TSA Pipeline evidence for TSAPIPE-2
- coordinator + 24-hr reporting partial
TSA Security Directive: Assessment and Assurance
Establish a program to proactively test and regularly audit the effectiveness of cybersecurity measures.
- Annual cybersecurity assessment programme report
- Architecture review attestation by qualified reviewer
- NIST Cybersecurity Framework profile mapped to TSA controls
- Performance-based metrics dashboard for TSA review
- Assessment scope omits acquired pipeline segments
- Architecture reviewer independence questioned
- Performance metrics lack outcome-based measures
Test cybersecurity effectiveness through an annual cybersecurity architecture design review by a third party.
- Annual cybersecurity assessment programme report
- Architecture review attestation by qualified reviewer
- NIST Cybersecurity Framework profile mapped to TSA controls
- Performance-based metrics dashboard for TSA review
- Assessment scope omits acquired pipeline segments
- Architecture reviewer independence questioned
- Performance metrics lack outcome-based measures
Achieve mandated critical security outcomes using the most appropriate measures for specific systems and operations.
- Annual cybersecurity assessment programme report
- Architecture review attestation by qualified reviewer
- NIST Cybersecurity Framework profile mapped to TSA controls
- Performance-based metrics dashboard for TSA review
- Assessment scope omits acquired pipeline segments
- Architecture reviewer independence questioned
- Performance metrics lack outcome-based measures
Implement mitigation measures drawing on NIST guidelines and CISA recommendations for pipeline cybersecurity.
- Annual cybersecurity assessment programme report
- Architecture review attestation by qualified reviewer
- NIST Cybersecurity Framework profile mapped to TSA controls
- Performance-based metrics dashboard for TSA review
- Assessment scope omits acquired pipeline segments
- Architecture reviewer independence questioned
- Performance metrics lack outcome-based measures
Establish, submit and maintain a Cybersecurity Assessment Plan that proactively assesses the effectiveness of the approved Cybersecurity Implementation Plan, including objective assessment of at least one third of the policies, procedures, measures and capabilities each year so that all are assessed within a three year period.
- Current Cybersecurity Assessment Plan submitted to TSA
- Three year assessment schedule
- Independent assessor selection records
- Annual assessment reports
- Remediation tracking from prior assessments
- Annual coverage falls below one third of measures
- Assessor independence not documented
- Findings not remediated within agreed timelines
Submit the Annual Cybersecurity Assessment report to TSA detailing the results of the previous year of assessment activities, including measures assessed, methodologies, findings, remediation status and plans for the upcoming year.
- Submitted annual report with TSA acknowledgement
- Findings register with severity and owners
- Remediation closure evidence
- Methodology and assessor independence statement
- Plan for upcoming year with measures to be assessed
- Report omits open findings from prior years
- Methodology section lacks rigour
- Remediation owners not identified
TSA Security Directive: Critical Cyber System Protection
Implement network segmentation policies and controls to ensure that Operational Technology systems can continue to operate safely in the event that an Information Technology system has been compromised, with documented zones, conduits and allowed communications.
- Segmentation policy document
- Zone and conduit drawings with allowed flows
- Firewall rule reviews evidencing default deny
- Demilitarised zone architecture for IT and OT interconnections
- Operational continuity testing with IT isolation
- Flat networks bridging corporate and OT
- Allow rules not justified or reviewed
- Remote vendor access circumventing segmentation
Implement access control measures to secure and prevent unauthorised access to Critical Cyber Systems, including identification, authentication, authorisation, multifactor authentication where feasible and management of privileged and shared accounts.
- Access control policy applicable to OT environments
- Privileged account inventory and review records
- MFA enrolment records for remote and privileged access
- Joiner mover leaver workflow evidence
- Vendor access agreements and approval records
- Shared accounts in OT without compensating controls
- MFA not enforced for vendor remote access
- Privileged accounts reviewed less than quarterly
Reduce the risk of exploitation of unpatched systems by ensuring application of security patches and updates on Information Technology and Operational Technology systems with documented timelines, exception handling and compensating controls where patching is not feasible.
- Patch policy with SLA by criticality
- Vulnerability scan reports for IT and authorised scans or passive assessments for OT
- Exception register with compensating controls
- Vendor advisories tracking log
- Evidence of patch deployment in OT change windows
- Exceptions remain open beyond stated timelines
- No passive vulnerability detection for OT
- Patch compliance reporting omits Critical Cyber Systems
Manage configurations and changes to Critical Cyber Systems through authorised processes, including baselines, approval workflows, testing, rollback plans and documentation of differences from manufacturer configurations.
- Configuration baselines for OT devices and applications
- Change advisory board minutes
- Pre and post change test records
- Rollback procedures documented
- Annual configuration drift assessment
- Baselines not maintained for legacy OT devices
- Emergency changes not retroactively approved
- No drift assessment conducted
Protect Critical Cyber Systems from unauthorised physical access, tampering and environmental hazards by applying controls such as access logging, surveillance, environmental monitoring and tamper detection on field cabinets, control rooms and data centres.
- Physical access logs for control rooms and cabinets
- Tamper evident seals and inspection records
- Environmental monitoring records
- Visitor management records
- Site security risk assessments
- Field cabinets without tamper detection
- Access logs retained shorter than audit needs
- Joint physical and cyber response procedures missing
TSA Security Directive: Cybersecurity Implementation Plan
Develop, submit and obtain TSA approval of a Cybersecurity Implementation Plan describing the specific measures the owner or operator will use to achieve the security outcomes in TSA Security Directive SD02C and SD02D for both Information Technology and Operational Technology systems.
- Current TSA approved Cybersecurity Implementation Plan
- TSA approval letter and correspondence
- Scope statement covering identified Critical Cyber Systems
- Cross-reference matrix between plan sections and SD02C and SD02D outcomes
- Change history and resubmission records
- Plan not resubmitted after material change
- Critical Cyber Systems list incomplete
- Plan describes intent without measurable controls
Identify and document Critical Cyber Systems, defined as any Information or Operational Technology system or data that, if compromised or exploited, could result in operational disruption to the TSA-designated critical pipeline or facility.
- Asset inventory with Critical Cyber System tagging
- Operational impact analysis supporting identification
- Approval records from Cybersecurity Coordinator
- Network diagrams showing Critical Cyber Systems boundaries
- Annual review evidence
- Inventory excludes safety instrumented systems
- Identification not refreshed after acquisitions
- No documented criteria for inclusion
TSA Security Directive: Detection and Response
Implement continuous monitoring and detection capabilities to identify cybersecurity threats and anomalous behaviour affecting Critical Cyber System operations, including logging, alerting, intrusion detection and detection of unauthorised code execution.
- Logging standard listing required event sources
- SIEM use case catalogue with OT specific detections
- Sensor deployment maps for IT and OT
- Alert review records with response times
- Annual detection coverage assessment
- OT logs not centrally collected
- Use cases focused on IT only
- Alerts triaged but not closed with disposition
Develop and maintain a Cybersecurity Incident Response Plan to reduce the risk of operational disruption that may result from a cybersecurity incident, addressing detection, containment, eradication, recovery and post-incident review, and ensure the plan is exercised.
- Documented Cybersecurity Incident Response Plan
- Annual exercise records with scenarios reflecting pipeline impact
- Communications protocols with TSA and CISA
- Post-incident review reports
- Plan version control with TSA submission record
- Plan not tested against OT scenarios
- Recovery objectives not defined for Critical Cyber Systems
- After action items not closed
Implement and test backup and recovery procedures for Critical Cyber Systems to enable restoration of operations following a cybersecurity incident, including offline or immutable copies and recovery time objectives consistent with operational requirements.
- Backup standard with frequency and retention
- Offline or immutable copy storage records
- Restoration test reports with timing
- Recovery time and recovery point objectives for Critical Cyber Systems
- Encryption and integrity verification records
- Backups stored only in online environment
- Restoration not tested for OT components
- RTOs and RPOs not aligned with operational needs
TSA Security Directive: Governance and Reporting
Designate a primary Cybersecurity Coordinator who is a US citizen, available to TSA and CISA 24 hours a day, seven days a week, and authorised to speak on behalf of the owner or operator on cybersecurity matters relating to the TSA-designated critical pipeline.
- Formal designation letter naming primary and alternate Cybersecurity Coordinators
- Notification submission record to TSA and CISA
- Citizenship verification documentation held on file
- 24x7 contact roster with escalation paths
- Annual review of designation and update notifications
- No alternate Cybersecurity Coordinator named
- Contact details not updated within seven days of change
- Coordinator lacks authority to commit the operator
Report cybersecurity incidents affecting Information and Operational Technology systems to the Cybersecurity and Infrastructure Security Agency without delay and in accordance with TSA reporting timeframes, including unauthorised access, denial of service, malicious code and physical attacks on cyber systems.
- Incident response plan with CISA reporting procedures
- Submission records to CISA with timestamps
- Incident triage criteria mapped to TSA reportable events
- Tabletop or simulation evidence of reporting drills
- After action reviews following incidents
- Reporting thresholds not aligned with TSA definitions
- No evidence of timely CISA submissions during prior incidents
- Operational Technology incidents excluded from scope
Notify TSA and CISA of any change in the designated primary or alternate Cybersecurity Coordinator within the time period specified in the Security Directive, ensuring continuity of point of contact for the TSA-designated critical pipeline.
- Notification log with date submitted and confirmation
- Internal procedure governing notification timelines
- Contact updates in TSA portal where available
- Acting designation memos during transitions
- Annual contact verification record
- Notifications submitted after the required window
- Acting designations not documented
- Alternate not updated when primary changes
Demonstrate that implemented cybersecurity measures achieve the performance based outcomes defined in TSA SD02C and SD02D, including evidence that controls operate effectively to prevent disruption to the TSA-designated critical pipeline.
- Outcome mapping document linking each measure to a security outcome
- Key control indicators and trends
- Sample evidence files demonstrating effective operation
- Independent attestations where available
- Internal audit reports on cybersecurity programme
- Outcomes described but not measured
- No trend analysis on control effectiveness
- Internal audit excludes Critical Cyber Systems
TSA Security Directive: Training and Supply Chain
Provide cybersecurity training to personnel with access to Critical Cyber Systems, including role-based training for OT operators, system administrators and incident responders, and maintain records of completion.
- Training plan by role
- Completion records with timestamps
- Phishing exercise results
- Role-based curricula for OT engineers
- Annual refresher schedule
- Generic training only, no OT context
- Vendors and contractors not included
- Completion records not retained for audit period
Manage cybersecurity risks introduced by third parties, including hardware, software and service providers with access to Critical Cyber Systems, through due diligence, contractual requirements, monitoring and incident notification clauses.
- Vendor risk assessment records
- Contract clauses for security and incident notification
- Vendor inventory with criticality ratings
- Software bill of materials for critical software
- Annual vendor performance reviews
- Vendors with OT access not assessed
- Software bill of materials not requested
- Notification clauses absent from legacy contracts
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the TSA Pipeline Cybersecurity Directives framework page.