2025-01422RuleWallet

DHS locks in rail cyber defenses for another year

Published Date: 1/21/2025

Rule

Summary

The Department of Homeland Security just confirmed that important security rules for critical rail companies are extended for another year with some updates. These changes help rail operators stay safer from growing cyber threats and keep their systems strong. The new rules took effect in late 2023 and mid-2024, so rail owners need to keep up or face risks.

Analyzed Economic Effects

5 provisions identified: 0 benefits, 5 costs, 0 mixed.

Directives Ratified and Extended

The Transportation Security Oversight Board ratified TSA Security Directive 1580-21-01B, 1582-21-01B, and 1580/82-2022-01A on November 22, 2023, and ratified 1580/82-2022-01C on July 29, 2024. If you are an owner or operator of a critical rail entity, the requirements in those directives remain in effect and some series now run through dates including October 24, 2024 and May 2, 2025.

Must Implement TSA‑Approved Cyber Plans

Covered rail owners/operators must establish and implement a TSA-approved Cybersecurity Implementation Plan (CIP) and a Cybersecurity Assessment Program (CAP) and submit an annual plan describing how they will assess and fix vulnerabilities. These performance-based requirements were part of the 1580/82-2022-01 series extended on October 24, 2023 and revised again in 2024.

Ongoing Incident Reporting and Response Duties

The directives require covered owners/operators to report cybersecurity incidents to CISA, designate a 24/7 cybersecurity coordinator, conduct vulnerability assessments, and maintain a Cybersecurity Incident Response Plan (CIRP) with specified testing exercises. These requirements originate from the December 2021 directives and were extended and clarified in 2023 and 2024.

Positive Train Control Now Covered

Security Directive 1580/82-2022-01C (effective July 1, 2024) specifically requires owners/operators to include Positive Train Control (PTC) systems in their list of Critical Cyber Systems, making PTC subject to the directive's performance-based cybersecurity measures.

Potential for Further Extensions

The TSOB authorized TSA to extend each security directive beyond current expiration dates if: (1) no changes other than extending the expiration date are made, (2) the TSA Administrator affirmatively determines extension is warranted, and (3) that determination is documented and TSOB-notified. This authorization was part of the ratification actions on November 22, 2023 and July 29, 2024.

Personalized for You

How does this regulation affect your finances?

Personalize government policy and PRIA will tell you what this federal register document means for your household, plus every other regulation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Key Dates

Rule Effective
Published Date
10/24/2023
1/21/2025

Department and Agencies

Department
Independent Agency
Agency
Homeland Security Department
Source: View HTML

Related Federal Register Documents

Previous / Next Documents

Back to Federal Register