TSA Pipeline Security
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
TSA Pipeline Security Guidelines: Corporate Security Programme
Establish a comprehensive corporate security programme covering pipeline facilities, addressing roles and responsibilities, scope of facilities and assets, governance and integration with broader corporate risk management.
- Corporate security policy and procedures
- Programme charter approved by senior management
- Scope document listing in-scope facilities and assets
- Annual programme review records
- Integration with enterprise risk management
- Programme scope omits gathering and processing facilities
- No periodic management review
- Roles and responsibilities not documented
Maintain a written corporate security plan that describes the operator's policies, programmes and procedures for protecting personnel, the public, the environment, the pipeline system, company assets and the continuity of operations.
- Current corporate security plan
- Plan owner and review schedule
- Distribution list and version control
- Linkage to incident response and business continuity plans
- Evidence of biennial plan review
- Plan not reviewed in the last 18 months
- Lacks measurable security objectives
- No cross reference to facility security plans
Maintain records relating to the security programme, including assessments, plans, training, incidents and audits, for the periods specified in corporate procedures and applicable law, and protect sensitive security information from unauthorised disclosure.
- Records retention schedule
- Sensitive Security Information handling procedure
- Document control register
- Access logs for sensitive records
- Disposal records for expired documents
- SSI handling procedure missing
- Retention periods inconsistent across business units
- Access to sensitive documents not logged
Periodically audit and review the corporate security programme and facility level implementation to assess compliance with the corporate plan, identify deficiencies and drive continuous improvement.
- Audit plan and schedule
- Audit reports with findings and corrective actions
- Self assessment templates and completed forms
- Management response to audit findings
- Trend analysis of audit results
- Audit cycle exceeds three years for any facility
- Findings closed without verification of effectiveness
- No trend analysis to identify systemic gaps
Establish a continuous improvement mechanism that captures lessons learned from incidents, exercises, audits and industry threat intelligence and translates them into updates of the security programme, risk assessments and facility measures.
- Lessons learned register
- Threat intelligence feed records
- Programme update history
- Management review minutes
- Metric dashboards tracking improvement
- Lessons learned recorded but not actioned
- No intelligence feed beyond TSA bulletins
- Improvement not measured
TSA Pipeline Security Guidelines: Criticality and Risk Assessment
Conduct a criticality assessment to identify the pipeline facilities considered critical based on the consequences of their loss or disruption, applying the criteria established in the TSA Pipeline Security Guidelines.
- Documented criticality methodology
- Criticality assessment results by facility
- Approval records from accountable executive
- Update schedule for criticality reviews
- Linkage to security risk assessment scope
- Methodology not aligned to TSA criteria
- Critical facility list not reviewed after acquisitions
- Consequence factors not weighted consistently
Conduct security risk assessments for critical pipeline facilities at intervals not greater than 18 months, evaluating threats, vulnerabilities and consequences and identifying mitigation measures appropriate to the level of risk.
- Risk assessment reports for each critical facility
- Threat, vulnerability and consequence ratings
- Mitigation tracker linked to findings
- Assessor qualifications
- Evidence of 18 month cadence
- Assessment intervals exceed 18 months
- Threat inputs not refreshed from current intelligence
- Mitigations identified but not implemented
TSA Pipeline Security Guidelines: Facility and Right of Way Security
Implement baseline and enhanced security measures at critical pipeline facilities, including access control, intrusion detection, surveillance, signage, lighting and barriers proportionate to the assessed risk.
- Facility security plans listing implemented measures
- Inspection records of fencing, gates and barriers
- Surveillance system coverage maps
- Lighting and signage inspection logs
- Maintenance records for physical security equipment
- Enhanced measures not deployed where risk warrants
- Surveillance recordings retained for less than 30 days
- Lighting outages not tracked
Apply security measures along pipeline rights of way including patrols, signage, public awareness and partnerships with local law enforcement to detect and deter unauthorised activity, tampering or interference with the pipeline.
- Patrol schedule and completion records
- Aerial patrol reports or equivalent monitoring evidence
- Public awareness programme materials
- Law enforcement liaison records
- Encroachment incident log
- Patrol frequency below corporate standard
- Public awareness materials outdated
- Encroachment incidents not closed
Implement graduated security measures aligned to changes in the threat environment, including response to threat advisories from TSA, DHS or other authorities, with specific actions to be taken at each elevated threat level.
- Threat level response matrix
- Records of advisory receipt and actions taken
- Communications procedures for threat changes
- Field implementation evidence
- After action review of threat level responses
- No documented graduated response actions
- Advisory receipt not logged
- Field staff unaware of current threat level
Apply specific security measures to liquefied natural gas peak shaving and liquefaction facilities in scope of the guidelines, addressing access control, perimeter security, tank protection and coordination with FERC and Coast Guard where applicable.
- LNG facility security plan
- Perimeter inspection records
- Tank area access logs
- Coordination records with FERC and US Coast Guard
- Exercise records for LNG specific scenarios
- Peak shaving facilities omitted from scope
- Coordination evidence limited to annual contact
- Tank area access not logged
TSA Pipeline Security Guidelines: Incident Response and Exercises
Conduct security drills and exercises at intervals appropriate to the facility criticality and risk environment to validate the effectiveness of security plans, identify gaps and improve response coordination.
- Annual exercise programme calendar
- Exercise scenarios documented
- After action reports
- Corrective action tracking
- Participation records
- Exercises focused on safety only
- After action items not closed
- Critical facility staff not exercised
Establish procedures to respond to security incidents, including detection, classification, notification to authorities including TSA and NRC where applicable, containment, recovery and post-incident review.
- Incident response plan covering physical and cyber events
- Notification matrix including TSA, FBI and NRC
- Incident log with classifications
- Post-incident review reports
- Linkage to emergency response plans
- Notifications not made within required timeframes
- Plan does not integrate physical and cyber events
- Post incident reviews not conducted
Maintain effective communication and coordination with federal, state, tribal and local stakeholders, including TSA, law enforcement and emergency responders, to support information sharing, incident response and joint planning.
- Stakeholder contact register
- Liaison meeting minutes
- Information sharing agreements
- Joint exercise participation records
- Notification protocols agreed with responders
- Stakeholder contacts not refreshed
- No participation in regional sector forums
- Notification protocols not exercised
TSA Pipeline Security Guidelines: Personnel Security and Training
Conduct background investigations of personnel and contractors having access to critical pipeline facilities, consistent with applicable law, and maintain records of screening, eligibility decisions and periodic re-screening.
- Background investigation policy
- Records of completed checks per role
- Contractor screening evidence
- Disqualification criteria documented
- Re-screening schedule
- Contractors granted access without screening
- Records not retained per policy
- No re-screening for long tenure personnel
Provide security awareness training to all employees and contractors with access to critical facilities, covering threat recognition, reporting suspicious activity, insider threat indicators and roles during a security incident.
- Training curriculum and materials
- Completion records
- Refresher schedule
- Suspicious activity reporting procedure
- Awareness campaign communications
- Contractors not included in awareness programme
- No insider threat indicators in curriculum
- Refresher cycle exceeds 24 months
Develop and maintain an insider threat programme to deter, detect and respond to threats originating from individuals with authorised access, integrating personnel security, behavioural indicators, technical monitoring and reporting channels.
- Insider threat programme document
- Cross functional working group records
- Behavioural indicator catalogue and training
- Anonymous reporting channel statistics
- Case management procedure
- No formal insider threat programme
- Reporting channels not communicated to staff
- Cases not tracked centrally
TSA Pipeline Security Guidelines: Pipeline Cyber Asset Security
Identify pipeline cyber assets supporting operations and apply baseline cyber security measures aligned to the seven sections of the TSA Pipeline Security Guidelines Appendix B Pipeline Cyber Asset Security Measures.
- Pipeline cyber asset inventory with classifications
- Implementation status against Appendix B sections
- Network architecture documentation
- Access control records for cyber assets
- Monitoring and detection evidence
- Inventory missing OT control systems
- Appendix B implementation status not tracked
- Network architecture not documented
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.