Following the 2021 ransomware attack on a major U.S. fuel pipeline, the Transportation Security Administration began issuing security directives requiring certain pipeline owners and operators to take specific cybersecurity actions. The details of these directives have been revised and renewed over time, and the requirements apply to designated critical pipeline systems rather than to every company in the industry.
This primer gives a general view of the themes involved. It is not legal advice or a compliance manual. Operators should work from the current text of the directives that apply to them and consult their compliance and legal teams.
Who is affected
The directives apply to pipeline owners and operators that TSA has identified as critical. Contractors, service companies, and equipment vendors that work with those operators may encounter the requirements indirectly, through contract terms, access rules, and security questionnaires.
If you serve pipeline operators, treat their requirements as a customer expectation you will need to meet and document.
The main themes
Without citing specific provisions, the directives have generally addressed several areas.
Reporting incidents
Operators are expected to report significant cybersecurity incidents to CISA within defined timeframes and to designate a cybersecurity coordinator available around the clock. Service providers should know how to alert an operator quickly if they detect a problem that could affect it.
Assessing and planning
Operators are required to review their cybersecurity posture, identify gaps, and maintain plans to address them. This includes a cybersecurity implementation plan and incident response planning, along with exercises to test them.
Protecting critical systems
Requirements have addressed network segmentation between IT and OT, controlling access to critical systems, monitoring and detecting threats, and applying patches and security updates in a risk-based way. Segmentation is intended so that a compromise of business systems cannot easily reach operational systems.
Access control and authentication
Operators are expected to restrict access to critical cyber systems, use strong authentication, and manage accounts carefully. Remote access receives particular attention.
Continuous monitoring and detection
Operators are expected to monitor for anomalies and threats on critical systems and to have the capability to detect and respond.
Resilience and recovery
Planning for continued operations, including the ability to isolate affected systems and recover, is part of the picture.
What this means for service providers and contractors
If you do work for a pipeline operator, expect questions or requirements related to:
- How your staff authenticate and how remote access is controlled.
- Whether your laptops and tools are managed, patched, and protected.
- Your own incident detection and notification procedures.
- Background screening and training for personnel with access.
- Secure handling of drawings, configurations, and credentials.
- Proof of your practices, in the form of policies, logs, and records.
How to prepare
- Ask what applies. Request the specific requirements from your customer in writing.
- Document your controls. Policies, training records, access logs, and asset lists all provide evidence.
- Define an incident contact path. Know who at your company calls whom at the operator, and how fast.
- Separate your work environment. Use dedicated, managed devices for operator work.
- Test your response. Run a tabletop exercise that includes a scenario involving a customer's system.
Beyond compliance
The directives reflect good practice. Segmentation, strong access controls, monitoring, tested response plans, and reliable backups are valuable to any operator or contractor, regulated or not. NIST CSF 2.0 and CISA's guidance provide helpful frameworks for organizing a program, and companies in the sector can use them even without a regulatory mandate.
Questions worth asking your operator customer
- Which parts of the directives drive requirements for our work, and who is our contact?
- Do you require specific remote access tools or authentication methods?
- What is the expected notification timeline if we detect a problem?
- Do you need evidence of training or background screening, and in what form?
Written answers help you plan and give you something to point to during an audit or review.
Working with Ironfield Cyber
Ironfield Cyber helps energy sector contractors and smaller operators prepare for the security expectations that come with pipeline work, including documentation, remote access controls, and incident readiness. If a customer has sent you a security questionnaire, we can help you answer it accurately.