Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

New TSA Directive Aims to Further Enhance Railway Cybersecurity

Train cybersecurity

The Transportation Security Administration (TSA) has issued a new directive whose goal is to improve the cybersecurity of railroad operations in the United States.

Train cybersecurity

The Transportation Security Administration (TSA) has issued a new directive whose goal is to improve the cybersecurity of railroad operations in the United States.

The new security directive is part of the White House’s efforts to strengthen critical infrastructure cybersecurity. The requirements outlined in the directive are aimed at passenger and freight railroad carriers designated by the TSA.

The goal is to help operators further enhance cyber preparedness and resilience, requiring them to take steps to prevent disruption and infrastructure degradation.

There are four major tasks that need to be completed by railway operators. This includes developing network segmentation policies and controls to ensure that operational technology (OT) systems are safe in case of an IT system compromise.

Another task is creating access controls to prevent unauthorized access to critical systems. In addition, operators must ensure that these critical systems are covered by continuous monitoring and detection policies and procedures.

They also need to ensure that operating systems, applications, drivers and firmware running on critical systems are always up to date and patched.

Rail operators will need to establish and execute a cybersecurity implementation plan, and regularly audit the effectiveness of their cybersecurity measures and address any identified issues.

ICS Cybersecurity Conference 2022

This security directive comes less than a year after the TSA issued new directives and recommendations aimed at strengthening the cyber defenses of US rail and airport operators.

Advertisement. Scroll to continue reading.

“The nation’s railroads have a long track record of forward-looking efforts to secure their network against cyber threats and have worked hard over the past year to build additional resilience, and this directive, which is focused on performance-based measures, will further these efforts to protect critical transportation infrastructure from attack,” said TSA administrator David Pekoske.

Threat actors attacking railways is not uncommon, with recent targets including Belarus, Italy, the UK, Israel and Iran. While researchers have shown that modern train systems are vulnerable to hacker attacks, these recent attacks targeted websites, ticketing and other IT systems, rather than control systems.

Related: Updated TSA Pipeline Cybersecurity Requirements Offer More Flexibility

Related: Rail System Cybersecurity Firm Cylus Raises $12 Million

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...