Skip to content

Evidence request lists

TSA Pipeline Cybersecurity Directives

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Assessment

TSAPIPE-4
Cybersecurity Assessment Programme and Annual Testing

Per TSA SD: Cybersecurity Assessment Programme including annual assessment + tabletop + technical assessment + maintain documentation.

Artefacts an auditor will ask for
  • TSA Pipeline evidence for TSAPIPE-4
Where this commonly fails
  • coordinator + 24-hr reporting partial

Implementation

TSAPIPE-1
Cybersecurity Implementation Plan and Coordinator

Per TSA Pipeline Cybersecurity Directives (SD02-2024-01 + Security Programs): implementation plan. Requirements include (a) Cybersecurity Implementation Plan + (b) Cybersecurity Coordinator Designation + 24/7 available + (c) Vulnerability Assessment + (d) Remediation Planning + (e) cooperate with TSA + CISA.

Artefacts an auditor will ask for
  • TSA Pipeline evidence for TSAPIPE-1
Where this commonly fails
  • coordinator + 24-hr reporting partial

Incident Reporting

TSAPIPE-3
Cybersecurity Incident Reporting to CISA

Per TSA SD: incident reporting to CISA within 24 hours of identification + cooperate with FBI + maintain incident log.

Artefacts an auditor will ask for
  • TSA Pipeline evidence for TSAPIPE-3
Where this commonly fails
  • coordinator + 24-hr reporting partial

Network Segmentation

TSAPIPE-2
OT/IT Network Segmentation and Access Control

Per TSA SD: segmentation. Requirements include (a) OT/IT Network Segmentation + (b) Access Control + privileged access + (c) maintain documented network architecture.

Artefacts an auditor will ask for
  • TSA Pipeline evidence for TSAPIPE-2
Where this commonly fails
  • coordinator + 24-hr reporting partial

TSA Security Directive: Assessment and Assurance

SD-02-10
Cybersecurity Assessment Program

Establish a program to proactively test and regularly audit the effectiveness of cybersecurity measures.

Artefacts an auditor will ask for
  • Annual cybersecurity assessment programme report
  • Architecture review attestation by qualified reviewer
  • NIST Cybersecurity Framework profile mapped to TSA controls
  • Performance-based metrics dashboard for TSA review
Where this commonly fails
  • Assessment scope omits acquired pipeline segments
  • Architecture reviewer independence questioned
  • Performance metrics lack outcome-based measures
SD-02-11
Annual Architecture Review

Test cybersecurity effectiveness through an annual cybersecurity architecture design review by a third party.

Artefacts an auditor will ask for
  • Annual cybersecurity assessment programme report
  • Architecture review attestation by qualified reviewer
  • NIST Cybersecurity Framework profile mapped to TSA controls
  • Performance-based metrics dashboard for TSA review
Where this commonly fails
  • Assessment scope omits acquired pipeline segments
  • Architecture reviewer independence questioned
  • Performance metrics lack outcome-based measures
SD-02-12
Performance-Based Compliance

Achieve mandated critical security outcomes using the most appropriate measures for specific systems and operations.

Artefacts an auditor will ask for
  • Annual cybersecurity assessment programme report
  • Architecture review attestation by qualified reviewer
  • NIST Cybersecurity Framework profile mapped to TSA controls
  • Performance-based metrics dashboard for TSA review
Where this commonly fails
  • Assessment scope omits acquired pipeline segments
  • Architecture reviewer independence questioned
  • Performance metrics lack outcome-based measures
SD-02-13
NIST Framework Alignment

Implement mitigation measures drawing on NIST guidelines and CISA recommendations for pipeline cybersecurity.

Artefacts an auditor will ask for
  • Annual cybersecurity assessment programme report
  • Architecture review attestation by qualified reviewer
  • NIST Cybersecurity Framework profile mapped to TSA controls
  • Performance-based metrics dashboard for TSA review
Where this commonly fails
  • Assessment scope omits acquired pipeline segments
  • Architecture reviewer independence questioned
  • Performance metrics lack outcome-based measures
TSA-SD-09
Annual Cybersecurity Assessment Plan

Establish, submit and maintain a Cybersecurity Assessment Plan that proactively assesses the effectiveness of the approved Cybersecurity Implementation Plan, including objective assessment of at least one third of the policies, procedures, measures and capabilities each year so that all are assessed within a three year period.

Artefacts an auditor will ask for
  • Current Cybersecurity Assessment Plan submitted to TSA
  • Three year assessment schedule
  • Independent assessor selection records
  • Annual assessment reports
  • Remediation tracking from prior assessments
Where this commonly fails
  • Annual coverage falls below one third of measures
  • Assessor independence not documented
  • Findings not remediated within agreed timelines
TSA-SD-15
Annual Cybersecurity Assessment report submission

Submit the Annual Cybersecurity Assessment report to TSA detailing the results of the previous year of assessment activities, including measures assessed, methodologies, findings, remediation status and plans for the upcoming year.

Artefacts an auditor will ask for
  • Submitted annual report with TSA acknowledgement
  • Findings register with severity and owners
  • Remediation closure evidence
  • Methodology and assessor independence statement
  • Plan for upcoming year with measures to be assessed
Where this commonly fails
  • Report omits open findings from prior years
  • Methodology section lacks rigour
  • Remediation owners not identified

TSA Security Directive: Critical Cyber System Protection

TSA-SD-05
Network segmentation between IT and OT

Implement network segmentation policies and controls to ensure that Operational Technology systems can continue to operate safely in the event that an Information Technology system has been compromised, with documented zones, conduits and allowed communications.

Artefacts an auditor will ask for
  • Segmentation policy document
  • Zone and conduit drawings with allowed flows
  • Firewall rule reviews evidencing default deny
  • Demilitarised zone architecture for IT and OT interconnections
  • Operational continuity testing with IT isolation
Where this commonly fails
  • Flat networks bridging corporate and OT
  • Allow rules not justified or reviewed
  • Remote vendor access circumventing segmentation
TSA-SD-06
Access control to Critical Cyber Systems

Implement access control measures to secure and prevent unauthorised access to Critical Cyber Systems, including identification, authentication, authorisation, multifactor authentication where feasible and management of privileged and shared accounts.

Artefacts an auditor will ask for
  • Access control policy applicable to OT environments
  • Privileged account inventory and review records
  • MFA enrolment records for remote and privileged access
  • Joiner mover leaver workflow evidence
  • Vendor access agreements and approval records
Where this commonly fails
  • Shared accounts in OT without compensating controls
  • MFA not enforced for vendor remote access
  • Privileged accounts reviewed less than quarterly
TSA-SD-08
Patch and vulnerability management

Reduce the risk of exploitation of unpatched systems by ensuring application of security patches and updates on Information Technology and Operational Technology systems with documented timelines, exception handling and compensating controls where patching is not feasible.

Artefacts an auditor will ask for
  • Patch policy with SLA by criticality
  • Vulnerability scan reports for IT and authorised scans or passive assessments for OT
  • Exception register with compensating controls
  • Vendor advisories tracking log
  • Evidence of patch deployment in OT change windows
Where this commonly fails
  • Exceptions remain open beyond stated timelines
  • No passive vulnerability detection for OT
  • Patch compliance reporting omits Critical Cyber Systems
TSA-SD-12
Configuration and change management

Manage configurations and changes to Critical Cyber Systems through authorised processes, including baselines, approval workflows, testing, rollback plans and documentation of differences from manufacturer configurations.

Artefacts an auditor will ask for
  • Configuration baselines for OT devices and applications
  • Change advisory board minutes
  • Pre and post change test records
  • Rollback procedures documented
  • Annual configuration drift assessment
Where this commonly fails
  • Baselines not maintained for legacy OT devices
  • Emergency changes not retroactively approved
  • No drift assessment conducted
TSA-SD-16
Physical security of cyber assets

Protect Critical Cyber Systems from unauthorised physical access, tampering and environmental hazards by applying controls such as access logging, surveillance, environmental monitoring and tamper detection on field cabinets, control rooms and data centres.

Artefacts an auditor will ask for
  • Physical access logs for control rooms and cabinets
  • Tamper evident seals and inspection records
  • Environmental monitoring records
  • Visitor management records
  • Site security risk assessments
Where this commonly fails
  • Field cabinets without tamper detection
  • Access logs retained shorter than audit needs
  • Joint physical and cyber response procedures missing

TSA Security Directive: Cybersecurity Implementation Plan

TSA-SD-03
Cybersecurity Implementation Plan approval

Develop, submit and obtain TSA approval of a Cybersecurity Implementation Plan describing the specific measures the owner or operator will use to achieve the security outcomes in TSA Security Directive SD02C and SD02D for both Information Technology and Operational Technology systems.

Artefacts an auditor will ask for
  • Current TSA approved Cybersecurity Implementation Plan
  • TSA approval letter and correspondence
  • Scope statement covering identified Critical Cyber Systems
  • Cross-reference matrix between plan sections and SD02C and SD02D outcomes
  • Change history and resubmission records
Where this commonly fails
  • Plan not resubmitted after material change
  • Critical Cyber Systems list incomplete
  • Plan describes intent without measurable controls
TSA-SD-04
Critical Cyber System identification

Identify and document Critical Cyber Systems, defined as any Information or Operational Technology system or data that, if compromised or exploited, could result in operational disruption to the TSA-designated critical pipeline or facility.

Artefacts an auditor will ask for
  • Asset inventory with Critical Cyber System tagging
  • Operational impact analysis supporting identification
  • Approval records from Cybersecurity Coordinator
  • Network diagrams showing Critical Cyber Systems boundaries
  • Annual review evidence
Where this commonly fails
  • Inventory excludes safety instrumented systems
  • Identification not refreshed after acquisitions
  • No documented criteria for inclusion

TSA Security Directive: Detection and Response

TSA-SD-07
Continuous monitoring and detection

Implement continuous monitoring and detection capabilities to identify cybersecurity threats and anomalous behaviour affecting Critical Cyber System operations, including logging, alerting, intrusion detection and detection of unauthorised code execution.

Artefacts an auditor will ask for
  • Logging standard listing required event sources
  • SIEM use case catalogue with OT specific detections
  • Sensor deployment maps for IT and OT
  • Alert review records with response times
  • Annual detection coverage assessment
Where this commonly fails
  • OT logs not centrally collected
  • Use cases focused on IT only
  • Alerts triaged but not closed with disposition
TSA-SD-10
Cybersecurity Incident Response Plan

Develop and maintain a Cybersecurity Incident Response Plan to reduce the risk of operational disruption that may result from a cybersecurity incident, addressing detection, containment, eradication, recovery and post-incident review, and ensure the plan is exercised.

Artefacts an auditor will ask for
  • Documented Cybersecurity Incident Response Plan
  • Annual exercise records with scenarios reflecting pipeline impact
  • Communications protocols with TSA and CISA
  • Post-incident review reports
  • Plan version control with TSA submission record
Where this commonly fails
  • Plan not tested against OT scenarios
  • Recovery objectives not defined for Critical Cyber Systems
  • After action items not closed
TSA-SD-13
Backups and recovery for Critical Cyber Systems

Implement and test backup and recovery procedures for Critical Cyber Systems to enable restoration of operations following a cybersecurity incident, including offline or immutable copies and recovery time objectives consistent with operational requirements.

Artefacts an auditor will ask for
  • Backup standard with frequency and retention
  • Offline or immutable copy storage records
  • Restoration test reports with timing
  • Recovery time and recovery point objectives for Critical Cyber Systems
  • Encryption and integrity verification records
Where this commonly fails
  • Backups stored only in online environment
  • Restoration not tested for OT components
  • RTOs and RPOs not aligned with operational needs

TSA Security Directive: Governance and Reporting

TSA-SD-01
TSA Cybersecurity Coordinator designation

Designate a primary Cybersecurity Coordinator who is a US citizen, available to TSA and CISA 24 hours a day, seven days a week, and authorised to speak on behalf of the owner or operator on cybersecurity matters relating to the TSA-designated critical pipeline.

Artefacts an auditor will ask for
  • Formal designation letter naming primary and alternate Cybersecurity Coordinators
  • Notification submission record to TSA and CISA
  • Citizenship verification documentation held on file
  • 24x7 contact roster with escalation paths
  • Annual review of designation and update notifications
Where this commonly fails
  • No alternate Cybersecurity Coordinator named
  • Contact details not updated within seven days of change
  • Coordinator lacks authority to commit the operator
TSA-SD-02
Cybersecurity incident reporting to CISA

Report cybersecurity incidents affecting Information and Operational Technology systems to the Cybersecurity and Infrastructure Security Agency without delay and in accordance with TSA reporting timeframes, including unauthorised access, denial of service, malicious code and physical attacks on cyber systems.

Artefacts an auditor will ask for
  • Incident response plan with CISA reporting procedures
  • Submission records to CISA with timestamps
  • Incident triage criteria mapped to TSA reportable events
  • Tabletop or simulation evidence of reporting drills
  • After action reviews following incidents
Where this commonly fails
  • Reporting thresholds not aligned with TSA definitions
  • No evidence of timely CISA submissions during prior incidents
  • Operational Technology incidents excluded from scope
TSA-SD-17
Cybersecurity Coordinator update notifications

Notify TSA and CISA of any change in the designated primary or alternate Cybersecurity Coordinator within the time period specified in the Security Directive, ensuring continuity of point of contact for the TSA-designated critical pipeline.

Artefacts an auditor will ask for
  • Notification log with date submitted and confirmation
  • Internal procedure governing notification timelines
  • Contact updates in TSA portal where available
  • Acting designation memos during transitions
  • Annual contact verification record
Where this commonly fails
  • Notifications submitted after the required window
  • Acting designations not documented
  • Alternate not updated when primary changes
TSA-SD-18
Performance based outcome measurement

Demonstrate that implemented cybersecurity measures achieve the performance based outcomes defined in TSA SD02C and SD02D, including evidence that controls operate effectively to prevent disruption to the TSA-designated critical pipeline.

Artefacts an auditor will ask for
  • Outcome mapping document linking each measure to a security outcome
  • Key control indicators and trends
  • Sample evidence files demonstrating effective operation
  • Independent attestations where available
  • Internal audit reports on cybersecurity programme
Where this commonly fails
  • Outcomes described but not measured
  • No trend analysis on control effectiveness
  • Internal audit excludes Critical Cyber Systems

TSA Security Directive: Training and Supply Chain

TSA-SD-11
Cybersecurity training and awareness

Provide cybersecurity training to personnel with access to Critical Cyber Systems, including role-based training for OT operators, system administrators and incident responders, and maintain records of completion.

Artefacts an auditor will ask for
  • Training plan by role
  • Completion records with timestamps
  • Phishing exercise results
  • Role-based curricula for OT engineers
  • Annual refresher schedule
Where this commonly fails
  • Generic training only, no OT context
  • Vendors and contractors not included
  • Completion records not retained for audit period
TSA-SD-14
Supply chain and third party risk

Manage cybersecurity risks introduced by third parties, including hardware, software and service providers with access to Critical Cyber Systems, through due diligence, contractual requirements, monitoring and incident notification clauses.

Artefacts an auditor will ask for
  • Vendor risk assessment records
  • Contract clauses for security and incident notification
  • Vendor inventory with criticality ratings
  • Software bill of materials for critical software
  • Annual vendor performance reviews
Where this commonly fails
  • Vendors with OT access not assessed
  • Software bill of materials not requested
  • Notification clauses absent from legacy contracts
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the TSA Pipeline Cybersecurity Directives framework page.