← Frameworks / Infrastructure Regulation

TSA Pipeline Security Directives (SD-1 and SD-2)

Mandatory cybersecurity requirements for owner/operators of hazardous liquid and natural gas pipelines designated as critical infrastructure by TSA. Security Directive Pipeline-2021-01 (SD-1) requires cybersecurity coordinator designation, 24-hour incident reporting to CISA, vulnerability assessment, and remediation. Security Directive Pipeline-2021-02 (SD-2) mandates network segmentation, access control, continuous monitoring, patch management, cybersecurity implementation plans, architecture design review, testing, and training. Issued following the Colonial Pipeline ransomware attack.

Clause Title SP 800-53 Controls
SD-1 Sec 1 Cybersecurity Coordinator
SD-1 Sec 2 Incident Reporting
SD-1 Sec 3 Vulnerability Assessment
SD-1 Sec 4 Remediation Measures
SD-2 Sec A Network Segmentation
SD-2 Sec B Access Control Measures
SD-2 Sec C Continuous Monitoring and Detection
SD-2 Sec D Patch Management
SD-2 Sec E Cybersecurity Implementation Plan
SD-2 Sec F Cybersecurity Architecture Design Review
SD-2 Sec G Cybersecurity Testing
SD-2 Sec H Cybersecurity Training