Advisory Details
-
Issue Date:
December 1, 2023
-
Importance
Very High
-
Summary
Department of Homeland Security Transportation Security Administration publishes Security Directive Pipeline-2021-02D (SD02D) to supersede Security Directive Pipeline-2021-02C.
-
Systems Impacted
Owners and Operators of TSA designated Critical Hazardous Liquid Pipelines, Natural Gas Pipelines or Liquified Natural Gas Facilities. Refer to DHS TSA memorandum and attachment (Published July 26th, 2023) - TSA Pipeline Directive Memo
DHS TSA Issues Security Directive Pipeline-2021-02D to Replace Pipeline-2021-02C
- Owner/Operators to re-assess if they now have Critical Cyber Systems whenever their operation methods change.
- Owner/Operators to follow Section VI procedures if their Cybersecurity Implementation Plan changes due to the SD02D update.
- Cybersecurity Implementation Plan “Alternative Measures” and attachments from SD02C – Removed.
- TSA (post consultation) may inform Owner/Operators to include addition Critical Cyber Systems in their CIP.
- Owner/Operators are required to test at least two Cybersecurity Incident Response Plan objectives no less than annually. Identified employees (by position) must participate in the required CIRP exercise.
- Cybersecurity Assessment Program replaced with “Cybersecurity Assessment Plan” (CAP)
-
- Owner/Operators to submit annual CAP update for TSA approval (subsequent updates require approval also).
- CAP will include a timeline ensuring at least 30% of the policies, procedures, measures, and capabilities included in the CIP are evaluated annually – with 100% evaluated by three years.
- Annual CAP report submission to TSA required. Including CIP evaluation results and methods utilized for determining if the annually evaluated CIP items are proving effective as originally planned.
- All previously developed plans, assessments, test, and evaluations utilized to meet the requirements of SD02D (listed in the index) must now be included in the CIP and provided to the TSA as needed.
- Owner/Operators must submit all documentation in the manner defined by the TSA.
Actions and/or Recommendations
- Identify current client base which may be impacted by the new SD02D changes.
- Communicate with Mangan Cybersecurity to help navigate these new changes to SD02D.
About REAL Matters and Mangan Inc.
REAL Matters advisories are published to communicate cybersecurity threats and risks within the Operational Technology (OT) environment and where Critical Infrastructure vulnerabilities are identified. The purpose of this newsletter is to inform, propose suggested approaches to mitigate the risk as well as provide feedback on how Mangan Cybersecurity is approaching the issue(s) addressed.
Mangan Inc. is a nationally-recognized Specialty Engineering, Automation, and Integration company, providing a full-range of services to the Oil & Gas, Refining, Pipeline, Chemicals, and Life Sciences Industries. Established in Long Beach, California in 1990, Mangan’s multiple office locations include sites in California, Georgia, New Hampshire, North Carolina, Texas, and Louisiana. Mangan’s 350+ employee-owners bring expertise, innovation, and safety as their core mission to some of the largest companies in the world.