<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-05-21-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>1652-AA74</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202110</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>1652</CODE>
            <NAME>Transportation Security Administration</NAME>
            <ACRONYM>TSA</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>1600</CODE>
            <NAME>Department of Homeland Security</NAME>
            <ACRONYM>DHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Surface Transportation Cybersecurity Measures </RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>On July 28, 2021, the President issued the National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems.&nbsp; Consistent with this priority of the Administration and in response to the ongoing cybersecurity threat to pipeline systems, TSA used its authority under 49 U.S.C. 114 to issue security directives to owners and operators of TSA-designated critical pipelines that transport hazardous liquids and natural gas to implement a number of urgently needed protections against cyber intrusions.&nbsp; The first directive, issued in May 2021, requires critical owner/operators to (1) Report confirmed and potential cybersecurity incidents to the Cybersecurity and Infrastructure Agency (CISA); (2) designate a Cybersecurity Coordinator to be available 24 hours a day, seven days a week; (3) review current cybersecurity practices; and (4) identify any gaps and related remediation measures to address cyber-related risks and report the results to TSA and CISA within 30 days of issuance of the SD.&nbsp; A second security directive issued in July requires these owners and operators to (1) Implement specific mitigation measures to protect against ransomware attacks and other known threats to information technology and operational technology systems; (2) develop and implement a cybersecurity contingency and recovery plan; and (3) conduct a cybersecurity architecture design review. TSA is committed to enhancing and sustaining cybersecurity and intends to issue a rulemaking that will codify certain requirements&nbsp;with respect to pipeline and certain other surface modes.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>First Time Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Long-Term Actions</RULE_STAGE>
        <MAJOR>Undetermined</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>Undetermined</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>49 CFR 1570</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>49 U.S.C. 114</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This rulemaking is necessary to address the ongoing cybersecurity threat to U.S. transportation modes.</p>
</body>
</html>]]></STMT_OF_NEED>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>TSA is in the process of determining the costs and benefits of this rulemaking.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>To Be Determined</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Undetermined</RFA_REQUIRED>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Undetermined</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>Undetermined</FEDERALISM>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Scott</FIRST_NAME>
                <LAST_NAME>Gorton</LAST_NAME>
                <TITLE>Executive Director, Surface Policy Division </TITLE>
                <AGENCY>
                    <CODE>1652</CODE>
                    <NAME>Transportation Security Administration</NAME>
                    <ACRONYM>TSA</ACRONYM>
                </AGENCY>
                <PHONE>571 227-1251</PHONE>
                <EMAIL>tsa-surface@tsa.dhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>Policy, Plans, and Engagement, 6595 Springfield Center Drive,</STREET_ADDRESS>
                    <CITY>Springfield</CITY>
                    <STATE>VA</STATE>
                    <ZIP>20598-6002</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
