Skip to content

Evidence request lists

TSA Pipeline Security

Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

TSA Pipeline Security Guidelines: Corporate Security Programme

TSA-PSG-01
Corporate security programme

Establish a comprehensive corporate security programme covering pipeline facilities, addressing roles and responsibilities, scope of facilities and assets, governance and integration with broader corporate risk management.

Artefacts an auditor will ask for
  • Corporate security policy and procedures
  • Programme charter approved by senior management
  • Scope document listing in-scope facilities and assets
  • Annual programme review records
  • Integration with enterprise risk management
Where this commonly fails
  • Programme scope omits gathering and processing facilities
  • No periodic management review
  • Roles and responsibilities not documented
TSA-PSG-02
Security plan documentation

Maintain a written corporate security plan that describes the operator's policies, programmes and procedures for protecting personnel, the public, the environment, the pipeline system, company assets and the continuity of operations.

Artefacts an auditor will ask for
  • Current corporate security plan
  • Plan owner and review schedule
  • Distribution list and version control
  • Linkage to incident response and business continuity plans
  • Evidence of biennial plan review
Where this commonly fails
  • Plan not reviewed in the last 18 months
  • Lacks measurable security objectives
  • No cross reference to facility security plans
TSA-PSG-13
Recordkeeping and document control

Maintain records relating to the security programme, including assessments, plans, training, incidents and audits, for the periods specified in corporate procedures and applicable law, and protect sensitive security information from unauthorised disclosure.

Artefacts an auditor will ask for
  • Records retention schedule
  • Sensitive Security Information handling procedure
  • Document control register
  • Access logs for sensitive records
  • Disposal records for expired documents
Where this commonly fails
  • SSI handling procedure missing
  • Retention periods inconsistent across business units
  • Access to sensitive documents not logged
TSA-PSG-14
Programme audit and review

Periodically audit and review the corporate security programme and facility level implementation to assess compliance with the corporate plan, identify deficiencies and drive continuous improvement.

Artefacts an auditor will ask for
  • Audit plan and schedule
  • Audit reports with findings and corrective actions
  • Self assessment templates and completed forms
  • Management response to audit findings
  • Trend analysis of audit results
Where this commonly fails
  • Audit cycle exceeds three years for any facility
  • Findings closed without verification of effectiveness
  • No trend analysis to identify systemic gaps
TSA-PSG-18
Continuous improvement and lessons learned

Establish a continuous improvement mechanism that captures lessons learned from incidents, exercises, audits and industry threat intelligence and translates them into updates of the security programme, risk assessments and facility measures.

Artefacts an auditor will ask for
  • Lessons learned register
  • Threat intelligence feed records
  • Programme update history
  • Management review minutes
  • Metric dashboards tracking improvement
Where this commonly fails
  • Lessons learned recorded but not actioned
  • No intelligence feed beyond TSA bulletins
  • Improvement not measured

TSA Pipeline Security Guidelines: Criticality and Risk Assessment

TSA-PSG-03
Criticality assessment of pipeline facilities

Conduct a criticality assessment to identify the pipeline facilities considered critical based on the consequences of their loss or disruption, applying the criteria established in the TSA Pipeline Security Guidelines.

Artefacts an auditor will ask for
  • Documented criticality methodology
  • Criticality assessment results by facility
  • Approval records from accountable executive
  • Update schedule for criticality reviews
  • Linkage to security risk assessment scope
Where this commonly fails
  • Methodology not aligned to TSA criteria
  • Critical facility list not reviewed after acquisitions
  • Consequence factors not weighted consistently
TSA-PSG-04
Security risk assessment process

Conduct security risk assessments for critical pipeline facilities at intervals not greater than 18 months, evaluating threats, vulnerabilities and consequences and identifying mitigation measures appropriate to the level of risk.

Artefacts an auditor will ask for
  • Risk assessment reports for each critical facility
  • Threat, vulnerability and consequence ratings
  • Mitigation tracker linked to findings
  • Assessor qualifications
  • Evidence of 18 month cadence
Where this commonly fails
  • Assessment intervals exceed 18 months
  • Threat inputs not refreshed from current intelligence
  • Mitigations identified but not implemented

TSA Pipeline Security Guidelines: Facility and Right of Way Security

TSA-PSG-05
Facility security measures for critical pipeline facilities

Implement baseline and enhanced security measures at critical pipeline facilities, including access control, intrusion detection, surveillance, signage, lighting and barriers proportionate to the assessed risk.

Artefacts an auditor will ask for
  • Facility security plans listing implemented measures
  • Inspection records of fencing, gates and barriers
  • Surveillance system coverage maps
  • Lighting and signage inspection logs
  • Maintenance records for physical security equipment
Where this commonly fails
  • Enhanced measures not deployed where risk warrants
  • Surveillance recordings retained for less than 30 days
  • Lighting outages not tracked
TSA-PSG-06
Pipeline right of way and onshore security

Apply security measures along pipeline rights of way including patrols, signage, public awareness and partnerships with local law enforcement to detect and deter unauthorised activity, tampering or interference with the pipeline.

Artefacts an auditor will ask for
  • Patrol schedule and completion records
  • Aerial patrol reports or equivalent monitoring evidence
  • Public awareness programme materials
  • Law enforcement liaison records
  • Encroachment incident log
Where this commonly fails
  • Patrol frequency below corporate standard
  • Public awareness materials outdated
  • Encroachment incidents not closed
TSA-PSG-11
Threat level response measures

Implement graduated security measures aligned to changes in the threat environment, including response to threat advisories from TSA, DHS or other authorities, with specific actions to be taken at each elevated threat level.

Artefacts an auditor will ask for
  • Threat level response matrix
  • Records of advisory receipt and actions taken
  • Communications procedures for threat changes
  • Field implementation evidence
  • After action review of threat level responses
Where this commonly fails
  • No documented graduated response actions
  • Advisory receipt not logged
  • Field staff unaware of current threat level
TSA-PSG-16
Liquefied natural gas facility security

Apply specific security measures to liquefied natural gas peak shaving and liquefaction facilities in scope of the guidelines, addressing access control, perimeter security, tank protection and coordination with FERC and Coast Guard where applicable.

Artefacts an auditor will ask for
  • LNG facility security plan
  • Perimeter inspection records
  • Tank area access logs
  • Coordination records with FERC and US Coast Guard
  • Exercise records for LNG specific scenarios
Where this commonly fails
  • Peak shaving facilities omitted from scope
  • Coordination evidence limited to annual contact
  • Tank area access not logged

TSA Pipeline Security Guidelines: Incident Response and Exercises

TSA-PSG-09
Drills and exercises

Conduct security drills and exercises at intervals appropriate to the facility criticality and risk environment to validate the effectiveness of security plans, identify gaps and improve response coordination.

Artefacts an auditor will ask for
  • Annual exercise programme calendar
  • Exercise scenarios documented
  • After action reports
  • Corrective action tracking
  • Participation records
Where this commonly fails
  • Exercises focused on safety only
  • After action items not closed
  • Critical facility staff not exercised
TSA-PSG-10
Security incident response

Establish procedures to respond to security incidents, including detection, classification, notification to authorities including TSA and NRC where applicable, containment, recovery and post-incident review.

Artefacts an auditor will ask for
  • Incident response plan covering physical and cyber events
  • Notification matrix including TSA, FBI and NRC
  • Incident log with classifications
  • Post-incident review reports
  • Linkage to emergency response plans
Where this commonly fails
  • Notifications not made within required timeframes
  • Plan does not integrate physical and cyber events
  • Post incident reviews not conducted
TSA-PSG-15
Communication and coordination with stakeholders

Maintain effective communication and coordination with federal, state, tribal and local stakeholders, including TSA, law enforcement and emergency responders, to support information sharing, incident response and joint planning.

Artefacts an auditor will ask for
  • Stakeholder contact register
  • Liaison meeting minutes
  • Information sharing agreements
  • Joint exercise participation records
  • Notification protocols agreed with responders
Where this commonly fails
  • Stakeholder contacts not refreshed
  • No participation in regional sector forums
  • Notification protocols not exercised

TSA Pipeline Security Guidelines: Personnel Security and Training

TSA-PSG-07
Personnel security and background screening

Conduct background investigations of personnel and contractors having access to critical pipeline facilities, consistent with applicable law, and maintain records of screening, eligibility decisions and periodic re-screening.

Artefacts an auditor will ask for
  • Background investigation policy
  • Records of completed checks per role
  • Contractor screening evidence
  • Disqualification criteria documented
  • Re-screening schedule
Where this commonly fails
  • Contractors granted access without screening
  • Records not retained per policy
  • No re-screening for long tenure personnel
TSA-PSG-08
Security awareness training

Provide security awareness training to all employees and contractors with access to critical facilities, covering threat recognition, reporting suspicious activity, insider threat indicators and roles during a security incident.

Artefacts an auditor will ask for
  • Training curriculum and materials
  • Completion records
  • Refresher schedule
  • Suspicious activity reporting procedure
  • Awareness campaign communications
Where this commonly fails
  • Contractors not included in awareness programme
  • No insider threat indicators in curriculum
  • Refresher cycle exceeds 24 months
TSA-PSG-17
Insider threat programme

Develop and maintain an insider threat programme to deter, detect and respond to threats originating from individuals with authorised access, integrating personnel security, behavioural indicators, technical monitoring and reporting channels.

Artefacts an auditor will ask for
  • Insider threat programme document
  • Cross functional working group records
  • Behavioural indicator catalogue and training
  • Anonymous reporting channel statistics
  • Case management procedure
Where this commonly fails
  • No formal insider threat programme
  • Reporting channels not communicated to staff
  • Cases not tracked centrally

TSA Pipeline Security Guidelines: Pipeline Cyber Asset Security

TSA-PSG-12
Pipeline Cyber Asset Security Measures

Identify pipeline cyber assets supporting operations and apply baseline cyber security measures aligned to the seven sections of the TSA Pipeline Security Guidelines Appendix B Pipeline Cyber Asset Security Measures.

Artefacts an auditor will ask for
  • Pipeline cyber asset inventory with classifications
  • Implementation status against Appendix B sections
  • Network architecture documentation
  • Access control records for cyber assets
  • Monitoring and detection evidence
Where this commonly fails
  • Inventory missing OT control systems
  • Appendix B implementation status not tracked
  • Network architecture not documented
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.