TSA SD 1580/82Critical InfrastructureUnited StatesRail / Transit

TSA Security Directives for Surface Transportation

TSA security directives requiring rail and transit operators to implement cybersecurity measures including 24/7 monitoring of critical systems.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

TSA SD 1580/82SD 1580-21-01Spotting the abnormalAttribution to an individual

Continuous Monitoring

Operators MUST implement 24/7 monitoring of signaling and interlocking databases for operational anomalies.

Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.

TSA SD 1580/82SD 1580-21-01 §4Detecting it in time to notify

Incident Reporting

Cybersecurity incidents MUST be reported to CISA within 24 hours of discovery.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

TSA SD 1580/82SD 1582-21-01Least privilege and privileged use

Access Control

REQUIRES implementation of access controls for critical operational technology systems.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

TSA SD 1580/82SD 1580-21-01 §3Retention and availability

Log Retention

Security logs MUST be retained for at least 1 year and available for TSA review.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

What TSA SD 1580/82 covers

49 CFR Part 1520 — Sensitive Security Information

Information whose disclosure would be detrimental to transportation security. The directives themselves are SSI.

In scope

  • Security programmes and contingency plans
  • Vulnerability assessments
  • Security inspection and investigative information
  • Security measures and their performance specifications

What falls outside

SSI is not classified national security information, and the two carry different handling regimes — conflating them is the usual error.

The directives that create the cybersecurity obligations are themselves SSI, which is why their operative text is not publicly quotable here.

49 CFR Part 1520 · as at 2026-08

How TSA SD 1580/82 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Transportation Security Administration.

Security Directives are issued and amended without notice-and-comment, and they bind the designated owner-operators directly. TSA opens an action by serving a Notice of Proposed Civil Penalty setting out the provision, the facts, and the proposed amount, which is drawn from its published sanction guidance rather than from the directive itself.

The directives are reissued periodically with new numbers and amended requirements, so the obligations in force change more often than a statute would.

Uncapped exposure that sits outside this instrument

These come from company law rather than from TSA SD 1580/82, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for TSA SD 1580/82,
not configured for it afterwards

Policy Template

Rail OT System Monitoring

Monitor signaling, interlocking, and train control databases 24/7

Report

TSA SD Compliance Report

1-year log retention with immediate anomaly reporting

Classification

Rail System Data

Identify signaling, dispatch, and safety system data

Alert

OT Anomaly Detection

Real-time alerting for operational anomalies requiring 24hr reporting

Walk into the TSA SD 1580/82 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment