2024-2025 Global AI Trends Guide
On November 6, 2024, the Transportation Security Administration (TSA) published a Notice of Proposed Rulemaking (NPRM) that would mandate cyber risk management and reporting requirements for certain surface transportation owners and operators.
TSA’s NPRM would impose cybersecurity requirements on designated critical surface transportation sectors—including pipelines, freight railroads, passenger railroads, and bus operators—adapted from the cybersecurity framework developed by the National Institute of Standards and Technology and the cross-sector cybersecurity performance goals developed by the Cybersecurity and Infrastructure Security Agency (CISA). In particular, the rule would require:
The proposed rule iterates on previous TSA cybersecurity directives and mandates established after the 2021 Colonial Pipeline ransomware attack. TSA’s recent initiatives have focused on levying stricter cybersecurity requirements for railroad and pipeline operators. For example, on July 27, 2024, TSA reissued its Security Directive regarding oil and natural gas pipeline cybersecurity to mandate pipeline owners/operators annually submit updated cybersecurity plans, report security assessment results, test incident response plans, and ensure all security measures are reviewed every three years, while continuing to report incidents to CISA and maintain vulnerability assessments. On October 24, 2024, TSA renewed its cybersecurity requirements for passenger and freight railroad carriers to annually test their cybersecurity response plans, include key staff in security-related exercises, submit updated security assessment plans, and review all security measures every three years.
The November 6 NPRM expands the agency’s cybersecurity obligations transportation modes by including bus operators and introducing additional performance-based requirements, such as cyber risk management and incident reporting, across transportation critical sectors. TSA estimates the rule will impact nearly 300 transportation entities, including 73 freight railroads, 34 public transportation systems, 71 intercity bus operators, and 115 pipeline facilities.
Authored by Nathan Salminen and Baily Martin.
The agency invites public comments on potential ways to reduce regulatory burdens where possible. Comments are due by February 5, 2025.
TSA is accepting public comments on or before February 5, 2025 at 11:59 pm EST.