tsa-compliance

Guides TSA Security Directive compliance for pipeline, rail, and transit operators.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill tsa-compliance-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: tsa-compliance
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/tsa-compliance
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill tsa-compliance-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Critical infrastructure owners and operators in pipeline, freight rail, passenger rail, and transit sectors struggle to interpret TSA Security Directives, determine applicability, and produce required compliance artifacts like CIPs, IRPs, ADRs, and CAPs. ## Core Features & Use Cases - Applicability & Gap Assessment: Determine which directive series applies (SD Pipeline-2021, SD 1580-21-01, SD 1582-21-01) and produce structured gap tables across the four technical domains. - Compliance Document Drafting: Generate Cybersecurity Implementation Plans, Incident Response Plans, Architecture Design Reviews, and Cybersecurity Assessment Plans aligned to TSA review criteria. - Incident Reporting Guidance: Walk through the 24-hour CISA reporting obligation with contact channels, reportable incident criteria, and notification logs. - Use Case: A pipeline operator asks "what does TSA require for OT/IT segmentation?" and receives directive-cited implementation guidance covering network segmentation, access controls, monitoring, and patch management. ## Quick Start Ask the assistant to perform a TSA compliance gap assessment for your pipeline or rail operation against the current Security Directive revision.

Frequently Asked Questions about tsa-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine if TSA Security Directives apply to my organization?

TSA designates covered entities individually by sector, so not all pipeline, rail, or transit operators are automatically covered. Identify your sector, check whether TSA has notified or designated your entity, and review the applicable directive series such as SD Pipeline-2021, SD 1580-21-01, or SD 1582-21-01.

What must a TSA Cybersecurity Implementation Plan include?

A CIP must include an Accountable Executive and Cybersecurity Coordinator, a Critical Cyber System inventory, network architecture description, measures across the four technical domains, incident detection and response procedures, and an annual review process. It must be submitted to TSA for approval before use as compliance evidence.

How do I report a cybersecurity incident to CISA under TSA directives?

Report to CISA within 24 hours of identifying the incident via the 24/7 Operations Center at 1-888-282-0870 or [email protected], and also notify TSA. Initial reports can contain limited information, with follow-up updates as the investigation matures.

What are the four technical domains required by TSA directives?

The four domains are network segmentation between IT and OT, access controls including MFA for remote and privileged access, continuous monitoring and anomaly detection for Critical Cyber Systems, and risk-based patch management with compensating controls for legacy OT systems.

Does the November 2024 TSA NPRM change current compliance obligations?

No, the NPRM comment period closed in February 2025 but the final rule is not yet published, so existing Security Directives remain in force. The NPRM would formalize requirements into 49 CFR regulation, add bus operator incident reporting, and explicitly align with NIST CSF 2.0 and CISA CPGs.

What are the limitations of TSA compliance guidance from this skill?

TSA Security Directives are Sensitive Security Information, so full directive text is not publicly available and guidance is based on public summaries. The output is informational only, not legal advice, and entities should verify requirements against the current directive revision with TSA and qualified counsel.