AP

TSA requires rail and airports to strengthen cybersecurity

Dec 2, 2021, 12:38 PM | Updated: 1:53 pm

RICHMOND, Va. (AP) — The Transportation Security Administration is issuing new directives and recommendations aimed at strengthening the cybersecurity defenses of U.S. rail and airport operators.

The Biden administration said the requirements made public Thursday are part of a broader effort at protecting the nation’s critical infrastructure from ongoing cyberespionage and a surge in disruptive ransomware attacks.

“These new cybersecurity requirements and recommendations will help keep the traveling public safe,” Homeland Security Secretary Alejandro Mayorkas said in a statement. He had previously previewed the new regulations in October.

The new TSA directives require most passenger and freight rail operators to identify a cybersecurity point person, report incidents within 24 hours to the Cybersecurity and Infrastructure Security Agency, conduct a vulnerability assessment and develop a contingency and recovery plan in case of malicious cyber activity. They go into effect at the end of the year and the TSA said it is making similar changes to requirements for airport operators.

The TSA said it is recommending but not mandating cybersecurity requirements to some smaller and lower-risk rail and airport operators.

The new regulations are similar to ones issued in May for pipeline operators following the Colonial Pipeline ransomware attack that disrupted gas supplies in several states.

Republican lawmakers have expressed concern that the TSA has crafted new cybersecurity directives without enough transparency and input from affected industries.

“We believe that care must be taken to avoid unnecessarily burdensome requirements that shift resources away from responding to cyberattacks to regulatory compliance,” a group of Republican senators said in an October letter to DHS’ Office of Inspector General asking for a review of TSA’s process for developing new cybersecurity regulations.

Victoria Newhouse, a TSA deputy assistant administrator, said at a congressional hearing Thursday that the agency had worked closely with private industry officials in crafting the regulations. She said that included a classified briefing with freight and passenger rail executives earlier this week to share intelligence reports about cyber threats to their industry and to solicit input on regulations.

The Biden administration has been pushing aggressively for greater private sector reporting of cyber incidents to the federal government. The Justice Department recently indicated it would sue government contractors and other companies who receive U.S. government grants if they fail to report breaches of their computer systems or misrepresent their cybersecurity practices.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Republican presidential candidates, from left, former Arkansas Gov. Asa Hutchinson, former New Jers...

Associated Press

3rd Republican presidential debate is set for Nov. 8 in Miami, with the strictest qualifications yet

The third Republican presidential debate will be held in Miami on Nov. 8, a day after several states hold off-year elections.

3 days ago

During the equinox, the Earth’s axis and its orbit line up so that both hemispheres get an equal ...

Associated Press

The fall equinox is here. What does that mean?

The equinox arrives on Saturday, marking the start of the fall season for the Northern Hemisphere. But what does that actually mean?

3 days ago

Ray Epps Ray Epps, an Arizona man who became the center of a conspiracy theory about Jan. 6, 2021, ...

Associated Press

Ray Epps, an Arizona man who supported Trump, pleads guilty to Capital riot charge

Ray Epps, the target of a conspiracy theory about the Jan. 6, 2021, attack, pleaded guilty on Wednesday to a misdemeanor charge.

5 days ago

Former President Donald Trump repeatedly declined in an interview aired Sunday, Sept. 17, 2023, to ...

Associated Press

Trump refuses to say in a TV interview how he watched the Jan. 6 attack unfold at the US Capitol

Former President Donald Trump repeatedly declined in an interview aired Sunday to answer questions about whether he watched the Capitol riot.

9 days ago

This frame grab from video, provided by the Mexican government, shows Ovidio Guzman Lopez being det...

Associated Press

Mexico extradites son of ‘El Chapo,’ Ovidio Guzman Lopez to US

The son of notorious cartel leader Joaquin “El Chapo” Guzmán, Ovidio Guzman Lopez was extradited to the U.S. on Friday.

9 days ago

This frame grab from video, provided by the Mexican government, shows Ovidio Guzman Lopez being det...

Sponsored Content by

The son of notorious cartel leader Joaquin “El Chapo” Guzmán, Ovidio Guzman Lopez was extradited to the U.S. on Friday.

Sponsored Articles

...

SCHWARTZ LASER EYE CENTER

Key dates for Arizona sports fans to look forward to this fall

Fall brings new beginnings in different ways for Arizona’s professional sports teams like the Cardinals and Coyotes.

...

Mayo Clinic

Game on! Expert sports physicals focused on you

With tryouts quickly approaching, now is the time for parents to schedule physicals for their student-athlete. The Arizona Interscholastic Association requires that all student-athletes must have a physical exam completed before participating in team practices or competition.

...

DAY & NIGHT AIR CONDITIONING, HEATING AND PLUMBING

Here are the biggest tips to keep your AC bill low this summer

PHOENIX — In Arizona during the summer, having a working air conditioning unit is not just a pleasure, but a necessity. No one wants to walk from their sweltering car just to continue to be hot in their home. As the triple digits hit around the Valley and are here to stay, your AC bill […]

TSA requires rail and airports to strengthen cybersecurity