EO 14028 Rolls on - Enhancing Rail Cybersecurity - TSA Directive

EO 14028 Rolls on - Enhancing Rail Cybersecurity - TSA Directive

Read ahead: Effective, Oct 24, 2022 TSA directs freight railroad carriers (Owner/Operators) to take four critical (straightforward) actions.?

Background: Executive Order 14028, Improving the Nation’s Cybersecurity, will continue to have a cascading (positive) impact throughout the US government, regulated industries, and (indirectly), private sector. It started by tasking the National Institute of Standards and Technology (NIST, under the Dept of Commerce) to solicit private sector and academia to release standards for “critical software”, which turned out to be pretty useful. Simultaneously, the Cybersecurity Infrastructure and Security Agency (CISA, under DHS), operationalizes cyber capabilities for the federal government and is making significant resources available to the private sector. At #mwise conference, CISA director Jen Easterly said that “water, hospitals, and K-12 schools” will be the focus of the next year.?She also teased "cybersecurity performance goals" based on the NIST Cybersecurity Framework (CSF) and highlighted that we currently "put the burden on the lease capable partners".

We’re seeing methodical, consistent direction in regulated industries. This should look very similar to TSA directives to Oil Pipeline (Owner/Operators).?I expect to see guidance to Water and Wastewater next.

Guidance: See the directive for more detail.

  1. Designate a cybersecurity coordinator to work with TSA and CISA. This is a security clearance eligible US citizen, who will be designated in writing and “accessible 24/7”.
  2. Report cybersecurity incidents (unauthorized access, malicious software, denial of service, or disruption incidents) to CISA within 24 hours in a specific way.
  3. Develop a Cybersecurity Incident Response Plan. Specifics provided.?
  4. Conduct a Cybersecurity Vulnerability Assessment with remediation plan and report to CISA. Functions and categories are based on CSF.?

Is this helpful to the rail industry? Is it welcome to additional industries? Please share your thoughts in the comments below.

Nathan Boeger - CISSP-ISSAP

USN veteran. Simplifying OT / ICS Security. Compliance. DevSecOps. Neurodivergent & underserved population supporter.

1 年

Yikes, I could barely even get sympathy "likes" with this one. I'm not all that inclined to keep writing on the subject. However... I think the Executive Order 14028, "Improving The Nation's Cybersecurity" is extremely impactful. It directs action from all US government agencies and prompted great work from National Institute of Standards and Technology (NIST) and Cybersecurity and Infrastructure Security Agency. Then follow on regulation, like Oil Pipeline and Railway from the Transportation Security Administration (TSA). I believe associated efforts drove software supply chain initiatives (e.g. #sbom). Much more to follow.

回复
Lisa "Kitty" Boeger

Family Nurse Practitioner with a passion for supporting those with serious illness

2 年

Choo-choo! ??

要查看或添加评论,请登录

Nathan Boeger - CISSP-ISSAP的更多文章

  • How can I learn about data integrity and electronic records in FDA regulated industries?

    How can I learn about data integrity and electronic records in FDA regulated industries?

    Induction: This article introduces key concepts ?? and shares useful links. I helped author a newly released guide…

    12 条评论
  • INFOSEC fundamentals for OT professionals

    INFOSEC fundamentals for OT professionals

    Introduction: Operational Technology (OT) is increasingly becoming “IT performing OT functions”. What the heck does…

    9 条评论
  • My 41 day journey to 2000 followers

    My 41 day journey to 2000 followers

    Introduction: This outlines my 41 day LinkedIn sprint ?? to 2053 followers and 1739 connections. I started last month…

    27 条评论
  • OT Security Tools Work Both Ways

    OT Security Tools Work Both Ways

    Read ahead: The OT/ICS crowd needs to be told that “tools can be used for good or bad” about as much as my military…

    21 条评论
  • Weak Authentication is an OT Safety Issue

    Weak Authentication is an OT Safety Issue

    Read ahead: Demand strong authentication for Operations Technology (OT) systems as a matter of safety. Applicability:…

    6 条评论
  • "Dual Homing" is an OT no-go

    "Dual Homing" is an OT no-go

    Read ahead: The Strong and The Wise resist the urge to connect their PCs directly to OT and IT environments…

    27 条评论
  • ALL YOUR AIR GAPS ARE BELONG TO US

    ALL YOUR AIR GAPS ARE BELONG TO US

    Read ahead: The term “air gap” should catch your full attention and skepticism. Does an “air gapped” network achieve…

    18 条评论

社区洞察

其他会员也浏览了