(Washington DC) – This week the Transportation Security Administration announced a new cybersecurity directive regulating designated passenger and freight railroad carriers. Building on the TSA’s work to strengthen defenses in other transportation modes, this security directive will further enhance cybersecurity preparedness and resilience for the nation’s railroad operations.
“The nation’s railroads have a long track record of forward-looking efforts to secure their network against cyber threats and have worked hard over the past year to build additional resilience, and this directive, which is focused on performance – based measures, will further these efforts to protect critical transportation infrastructure from attack.” said TSA Administrator David Pekoske.
Passenger and railroad carriers are required to: 1. Establish and execute a TSA-approved Cybersecurity Implementation Plan that describes the specific cybersecurity measures that passenger and freight rail carriers are utilizing to achieve the security outcomes set forth in the security outcomes set forth in the security directive.
2. Establish a Cybersecurity Assessment Program to proactively test and regularly audit the effectiveness of cybersecurity measures and identify and resolve vulnerabilities within devices, networks, and systems.
