EO 14028 Rolls on - Enhancing Rail Cybersecurity - TSA Directive
Nathan Boeger - CISSP-ISSAP
USN veteran. Simplifying OT / ICS Security. Compliance. DevSecOps. Neurodivergent & underserved population supporter.
Read ahead: Effective, Oct 24, 2022 TSA directs freight railroad carriers (Owner/Operators) to take four critical (straightforward) actions.?
Background: Executive Order 14028, Improving the Nation’s Cybersecurity, will continue to have a cascading (positive) impact throughout the US government, regulated industries, and (indirectly), private sector. It started by tasking the National Institute of Standards and Technology (NIST, under the Dept of Commerce) to solicit private sector and academia to release standards for “critical software”, which turned out to be pretty useful. Simultaneously, the Cybersecurity Infrastructure and Security Agency (CISA, under DHS), operationalizes cyber capabilities for the federal government and is making significant resources available to the private sector. At #mwise conference, CISA director Jen Easterly said that “water, hospitals, and K-12 schools” will be the focus of the next year.?She also teased "cybersecurity performance goals" based on the NIST Cybersecurity Framework (CSF) and highlighted that we currently "put the burden on the lease capable partners".
We’re seeing methodical, consistent direction in regulated industries. This should look very similar to TSA directives to Oil Pipeline (Owner/Operators).?I expect to see guidance to Water and Wastewater next.
Guidance: See the directive for more detail.
Is this helpful to the rail industry? Is it welcome to additional industries? Please share your thoughts in the comments below.
USN veteran. Simplifying OT / ICS Security. Compliance. DevSecOps. Neurodivergent & underserved population supporter.
1 年Yikes, I could barely even get sympathy "likes" with this one. I'm not all that inclined to keep writing on the subject. However... I think the Executive Order 14028, "Improving The Nation's Cybersecurity" is extremely impactful. It directs action from all US government agencies and prompted great work from National Institute of Standards and Technology (NIST) and Cybersecurity and Infrastructure Security Agency. Then follow on regulation, like Oil Pipeline and Railway from the Transportation Security Administration (TSA). I believe associated efforts drove software supply chain initiatives (e.g. #sbom). Much more to follow.
Family Nurse Practitioner with a passion for supporting those with serious illness
2 年Choo-choo! ??