Glossary
/
Standards & Regulation

TSA Security Directive 1580/82

Also known as:
TSA SD-1580/82-2022 · Rail Cybersecurity Mitigation Actions and Testing

TSA Security Directives 1580/82 are US Transportation Security Administration directives, first issued in 2022 and renewed annually, for freight and passenger rail owners and operators. They require network segmentation, access control, continuous monitoring and detection, and patch management for critical cyber systems.

How it works

The directives require covered rail operators to identify their critical cyber systems and implement a TSA-approved Cybersecurity Implementation Plan. Core measures include segmenting OT from IT so that OT can operate if IT is compromised, controlling and monitoring access to critical systems, continuously monitoring for and detecting threats, and reducing exploitable vulnerabilities through timely patching.

Operators must also maintain an incident response plan, report incidents to CISA, and conduct annual assessments demonstrating that the required measures are effective.

Why it matters for security

The directives make specific OT security capabilities a regulatory obligation for US rail: asset identification, segmentation validation, continuous detection and evidence of effectiveness. Rail operators need tooling that can demonstrate each requirement across wayside and onboard environments, including PTC.

Related solution

Meeting TSA Security Directive requirements

Segmentation validation, continuous detection and evidence of effectiveness across wayside and onboard.

See the solution →

Related terms

Ready to protect your rail?

Our specialists will help you back on track

Talk with an Expert