TSA Security Directives for Surface Transportation
TSA security directives requiring rail and transit operators to implement cybersecurity measures including 24/7 monitoring of critical systems.
What TSA SD 1580/82 draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Continuous Monitoring
Operators MUST implement 24/7 monitoring of signaling and interlocking databases for operational anomalies.
Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.
Incident Reporting
Cybersecurity incidents MUST be reported to CISA within 24 hours of discovery.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Access Control
REQUIRES implementation of access controls for critical operational technology systems.
Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.
Log Retention
Security logs MUST be retained for at least 1 year and available for TSA review.
Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.
What TSA SD 1580/82 covers
49 CFR Part 1520 — Sensitive Security Information
Information whose disclosure would be detrimental to transportation security. The directives themselves are SSI.
In scope
- Security programmes and contingency plans
- Vulnerability assessments
- Security inspection and investigative information
- Security measures and their performance specifications
What falls outside
SSI is not classified national security information, and the two carry different handling regimes — conflating them is the usual error.
The directives that create the cybersecurity obligations are themselves SSI, which is why their operative text is not publicly quotable here.
49 CFR Part 1520 · as at 2026-08
How TSA SD 1580/82 is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Transportation Security Administration.
Security Directives are issued and amended without notice-and-comment, and they bind the designated owner-operators directly. TSA opens an action by serving a Notice of Proposed Civil Penalty setting out the provision, the facts, and the proposed amount, which is drawn from its published sanction guidance rather than from the directive itself.
The directives are reissued periodically with new numbers and amended requirements, so the obligations in force change more often than a statute would.
Uncapped exposure that sits outside this instrument
These come from company law rather than from TSA SD 1580/82, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for TSA SD 1580/82,
not configured for it afterwards
Rail OT System Monitoring
Monitor signaling, interlocking, and train control databases 24/7
TSA SD Compliance Report
1-year log retention with immediate anomaly reporting
Rail System Data
Identify signaling, dispatch, and safety system data
OT Anomaly Detection
Real-time alerting for operational anomalies requiring 24hr reporting
Other Critical Infrastructure frameworks
Walk into the TSA SD 1580/82 audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.