TSA Pipeline Security Directives (SD-1 and SD-2)
Mandatory cybersecurity requirements for owner/operators of hazardous liquid and natural gas pipelines designated as critical infrastructure by TSA. Security Directive Pipeline-2021-01 (SD-1) requires cybersecurity coordinator designation, 24-hour incident reporting to CISA, vulnerability assessment, and remediation. Security Directive Pipeline-2021-02 (SD-2) mandates network segmentation, access control, continuous monitoring, patch management, cybersecurity implementation plans, architecture design review, testing, and training. Issued following the Colonial Pipeline ransomware attack.
Clauses: 12
Avg Coverage: 78.3%
Publisher: Transportation Security Administration (TSA) Version: 2021 (reissued 2023) | Clause | Title | SP 800-53 Controls |
|---|---|---|
| SD-1 Sec 1 | Cybersecurity Coordinator | |
| SD-1 Sec 2 | Incident Reporting | |
| SD-1 Sec 3 | Vulnerability Assessment | |
| SD-1 Sec 4 | Remediation Measures | |
| SD-2 Sec A | Network Segmentation | |
| SD-2 Sec B | Access Control Measures | |
| SD-2 Sec C | Continuous Monitoring and Detection | |
| SD-2 Sec D | Patch Management | |
| SD-2 Sec E | Cybersecurity Implementation Plan | |
| SD-2 Sec F | Cybersecurity Architecture Design Review | |
| SD-2 Sec G | Cybersecurity Testing | |
| SD-2 Sec H | Cybersecurity Training |