Showing posts with label Pipeline Cybersecurity. Show all posts
Showing posts with label Pipeline Cybersecurity. Show all posts

Sunday, September 28, 2025

Review – HR 5062 Introduced – Pipeline Security

Last month Rep Johnson (D,TX) introduced HR 5062, the Pipeline Security Act. The bill would amend the Implementing Recommendations of the 9/11 Commission Act of 2007 by adding a new §1559, Pipeline Security. It would require the Transportation Security Administration (TSA) to take actions to regulate the cybersecurity protection of hazardous material pipelines. No new funding is authorized.

The bill is similar in intent to HR 9469, the Pipeline Security Act, that was introduced by Rep Garcia (D,CA) in September 2024. The House Homeland Security Committee held a business meeting on September 25th, 2024 where the bill was considered. The bill was amended and passed on a voice vote. No report was published nor was a revised version of the bill published. No further action was taken in the House. The earlier bill would have amended 49 USC 114 to specifically add pipeline cybersecurity to the list of responsibilities of the Transportation Security Administration.

Moving Forward

On September 3rd, 2025 the House Homeland Security Committee held a business meeting that included the consideration of HR 5062. By a vote of 22 to 0 the Committee, the bill was ordered reported favorably without amendment. That bipartisan support would indicate that the bill could be considered in the House under the suspension of the rules process, where the bill should pass with significant bipartisan support.

Commentary

The reality is that this bill is going to codify responsibility for actions that TSA is already taking. Bills such as this, however, are important in that they provide a legal backstop for charges that the agency has exceeded its authority. The current authority under 49 USC 114 is broadly written and could be argued to support the agency’s security directives and current rulemaking process.

 

For more information on the provisions of this bill, including additional commentary, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-5062-introduced-pipeline-security - subscription required.

Saturday, September 10, 2022

CRS Reports – TSA Pipeline Cybersecurity Directives

This week the Congressional Research Service (CRS) published a brief report on the TSA’s pipeline cybersecurity directives. It provides a summary of the two cybersecurity directives and the changes that TSA has made to those directives. The three-page report concludes with the summary of issues for congressional consideration:

“Issues may arise regarding harmonization between TSA’s requirements for cyber incident and ransomware reporting and future reporting regulations to be promulgated by CISA as required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022, enacted as part of the Consolidated Appropriations Act, 2022 (P.L. 117-103). Some in industry also have been critical of TSA issuing Security Directives under emergency authority rather than promulgating cybersecurity regulations through a traditional rulemaking process with more opportunity for industry input. Some industry analysts have questioned whether TSA has sufficient staff with enough cybersecurity and regulatory expertise to effectively administer its pipeline cybersecurity program. The quality, quantity, and timeliness of cybersecurity risk information originating with the government and being shared with the private sector also continues to be an area of focus. Congress also may choose to consider how TSA’s ongoing pipeline cybersecurity oversight will fit together with the nation’s overall strategy to protect critical infrastructure from cybersecurity threats.”

Saturday, July 30, 2022

Review - OMB Approves Yet Another TSA Pipeline Cybersecurity Emergency ICR – 7-29-22

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an emergency information collection request (ICR) revision for the TSA’s “Pipeline Corporate Security Review”. This is the same ICR (1652-0056) for which OIRA had just approved a three-year extension earlier this week. TSA submitted this emergency ICR revision to support another change to the pipeline security directive (Security Directive Pipeline-2021-02C) that was published this week.

Change in Burden Estimate

Unusually for an emergency ICR revision, the approved revision does include a change in burden estimate. According to the Supporting Document submitted to OIRA, the revised ICR includes three new information collection requirements. The table below shows all five elements of the revised ICR burden estimate.

Collection Requirements

Responses

Hrs/Resp

Burden

Pipeline Corporate Security Review (PCR) Initial Interviews

20

8

160

PCR Re-interview

20

3

60

Cybersecurity Implementation Plan (new)

100

400

40,000

Cybersecurity Incident Response Plan

100

80

8,000

Audits Plans of Cybersecurity Measures (new)

100

40

4,000

Compliance Documentation (new)

100

80

8,000

Totals

440

N/A

60,220

Old Estimate

331

N/A

12,830

Moving Forward

As with most emergency ICR revision requests, OIRA is only approving the revised data for six months. TSA will be required to go through the normal publish and comment process for that extension. Additionally, OIRA noted:

“Given that this is an emergency approval that does not have the benefit of public input prior to implementation, the agency will brief OIRA on the comments it has received and lessons learned as it implemented this package when this package is resubmitted during the next six months following the normal notice and comment procedures. TSA will also work toward allowing as much time for comment as possible on its emergencies to avoid new aspects of its collections going into effect without the benefit of public input.”

 

For more information about the revised ICR approved by OIRA, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-yet-another-tsa-pipeline - subscription required.

Saturday, March 12, 2022

CRS Reports – PHMSA and Pipeline Security

This week the Congressional Research Service (CRS) published a report on “DOT’s Federal Pipeline Safety Program: Background and Key Issues for Congress.” While this 27-page report is an overview of the broad scope of the Pipeline and Hazardous Materials Safety Administration’s responsibilities for pipeline safety, it does include a significant discussion about pipeline security (including cybersecurity) issues and potential issues related to security that may be of concern to Congress.

An interesting comment about PHMSA’s intent on cybersecurity is found on pages 18-19:

“The Deputy Secretary of Transportation subsequently testified that PHMSA intends to “leverage its authorities to inspect and enforce three critical components of pipeline operations” related to cybersecurity: system control room regulations, integrity management plan requirements,65 and emergency response plan regulations.66 The Deputy Secretary also stated that DOT’s Office of Intelligence, Security, and Emergency Response was collaborating with the National Security Council and interagency partners on a natural gas pipelines Industrial Control Systems Cybersecurity Initiative and that “DOT continues work with [its] sister agencies, especially TSA and CISA, to invest in world class research and pursue initiatives to address cybersecurity threats.67

Deputy Secretary Trottenberg’s testimony can be found here and the pipeline cybersecurity discussion is on pages 2-5.

Wednesday, March 2, 2022

Reader Comment – Pipeline Security and Ukraine

A long time reader pointed me at an article over at the new International Pipeline Resilience Organization web site and asked me what I knew about the organization. First part of that is simple, I’ve never heard of them, but they appear to be a new organization. Further, I have had very little contact with the pipeline industry, so I do not recognize any of the names listed on their ‘Leadership’ page. I do find it interesting that a large portion of their leadership comes from a single large law firm.

The article, though, that I have some thoughts on.

First off, nothing really new here except for the brief mentions about the benefits of joining their organization. The ‘increased cyber threat’ from Russia is a common thread seen in most of the messaging from most of the thought leaders in cybersecurity. The refrain goes that Russia has been aggressive in their cyber activities in stealing information and getting footholds in systems from the federal government to critical infrastructure long before their military crossed into Ukraine. And there were certainly a wide variety of cyber attacks against the Ukraine before the physical attacks started. So, we must (the conventional wisdom goes) expect that the Russians will attack our critical infrastructure.

I am sorry, but I have to take a contrarian stand here, the last thing Putin wants to see now is a really pissed off USA and/or NATO. He bit off more than he can conveniently chew and was obviously surprised at how well, NATO, the European Union, and the United States responded in a coordinated manner in exercising their individual and combined economic muscle in response to the Russian invasion. That combined with the strong nationalistic response from the citizens of the Ukraine, the unexpected leadership shown by large portions of the civilian government of the Ukraine, have all made the mission of the Russian armed forces much more difficult than expected.

 

Putin realizes that the last thing he needs to see at this point is an introduction of NATO forces into the conflict. Even just a NATO air campaign to remove Russia’s air superiority would almost certainly give the Ukrainian military the final tool it needs to repel the Russian forces, or worse yet, capture large portions of the stalled Russian equipment sitting in the mud of the steppes. This realization on Putin’s part is almost certainly a major reason for his threats about nuclear escalation. A significant cyberattack on critical infrastructure in NATO would be the final spur that would drive movement of NATO forces eastward.

So, we can ignore the cybersecurity ‘threat’ from Russia, right? Sorry, nothing in Eastern Europe is ever that simple. What we really have to concern ourselves with is the reaction of the masses in Russia. As the sanctions begin to take hold and Russians start to hear more from their disillusioned soldiers about the conditions in Ukraine (lack of food and fuel really hurts military morale), Putin is going to have to start worrying about an uprising back home. Putin’s concern about this possibility may be what has driven his keeping most of his military forces at home.

If that threat becomes real, then Putin might decide that he needs a NATO incursion into Ukraine to justify his actions. Again, the easiest way to encourage that response would be to execute a limited cyberattack on Western interests. And non-catastrophic cyberattacks on gas and fuel pipelines would be an effective target for such attacks. So, do not stop working on improving your cybersecurity posture.

Saturday, October 16, 2021

Review - TSA Publishes Top 100 Most Critical Pipelines 30-day ICR Revision Notice

This week the the TSA published a 30-day Information Collection Request (ICR) revision notice in the Federal Register (86 FR 57197-57198) for a revision to their “Critical Facility Information of the Top 100 Most Critical Pipelines” (1652-0050) ICR. The 60-day ICR notice was published on June 30th, 2021. This ICR revision is a follow-up to the approved emergency ICRs back in late May for increased cybersecurity reporting requirements in the TSA’s Pipeline Cybersecurity Directive and supporting the requirements of TSA Pipeline Security Directive #1.

There were three comments received on the 60-day notice published for this propose ICR revision. The TSA published their responses [.docx download link] to the issues raised in those comments. As required by 44 U.S.C. 3501 et seq., TSA is again requesting comments on the 30-day ICR notice published this week. Comments may be submitted directly to OIRA by accessing the ICR page for this collection and clicking on the ‘Comment’ box near the top center of the page. Comments should be submitted by November 15th, 2021.

For more details about this ICR notice, including details about the new Pipeline Cybersecurity Self-Assessment form, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/tsa-publishes-top-100-most-critical - subscription required.

Friday, September 24, 2021

TSOB Ratifies TSA Pipeline Security Directive #2

Today DHS published a notice in the Federal Register (86 FR 52953) announcing that the Transportation Security Oversight Board (TSOB) has ratified Transportation Security Administration (TSA) Security Directive Pipeline-2021-02. That security directive was issued on July 19th, 2021.

This review and ratification is required under 49 USC 114(l)(2)(B). That subparagraph only allows an emergency order to last for 90-days unless ratified by the TSOB. According to today’s notice, the TSOB met on August 4th, 2021 and ratified the Security Directive ‘in its entirety’ on August 17th, 2021.

The TSOB was established under 49 USC 115. It consists of seven members or their designees

• The Secretary of Homeland Security,

• The Secretary of Transportation,

• The Attorney General,

• The Secretary of Defense,

• The Secretary of the Treasury,

• The Director of National Intelligence, and

• One member appointed by the President to represent the National Security Council.

Saturday, September 11, 2021

Pipeline Cybersecurity – CRS Report

This week the Congressional Research Service published a report on pipeline cybersecurity. According to the introduction (pg 1):

“This report discusses cybersecurity risks to natural gas, oil, and refined products pipelines, including to control systems and information technology, as well as ransomware. It summarizes the history of major pipeline cybersecurity warnings and cyberattacks in the United States over the last 15 years. It examines the federal role in protecting U.S. pipelines from cyber threats, including the agencies involved and their pipeline cybersecurity activities. It discusses the federal response to the Colonial Pipeline cyberattack. The report concludes with an overview of selected issues for Congress, including legislative proposals to change federal pipeline security programs.”

Topics covered in the report include:

· Pipeline Cybersecurity Risks,

· The Federal Role in Pipeline Cybersecurity,

· Federal Agency Pipeline Security Activities,

· DHS and DOT Cooperation,

· GAO Pipeline Security Reports, and

· Issues for Congress

Since this is a report from the Congressional Research Service (presumably at the request of a member of Congress), the concluding section of the report is important. It outlines some questions about pipeline cybersecurity that Congress could address in the legislative process. Those questions include:

· Which agency (or agencies) should be responsible for collecting, analyzing, and/or disseminating threat information?

· Which agency (or agencies) should be responsible for developing mitigating strategies to cybersecurity threats?

· Does the intelligence community need to improve collection about adversary targeting of critical infrastructure?

· How will the government track the disposition of information shared and assess the efficacy of information-sharing programs?

· Is classified information a barrier to information sharing, or is pertinent information able to be disseminated in an unclassified manner?

· Has the cyber risk information-sharing model authorized in the Cybersecurity Act of 2015 (PL 114-113, Division N) been successful, or do barriers exist to effective information sharing among sector partners?

Thursday, July 8, 2021

TSA Publishes STSAC Appointment Notice – 7-8-21

Today the Transportation Security Administration published a request for applicants notice in the Federal Register (86 FR 36148) for “Appointment to the Surface Transportation Security Advisory Committee”. According to the notice summary:

“STSAC's mission is to provide advice, consultation, and recommendations to the TSA Administrator on improving surface transportation security matters, including developing, refining, and implementing policies, programs, initiatives, rulemakings, and security directives pertaining to surface transportation security, while adhering to sensitive security guidelines.”

STSAC members represent each mode of surface transportation, including:

• Associations representing such modes of surface transportation,

• Labor organizations representing such modes of surface transportation,

• Groups representing the users of such modes of surface transportation, including asset manufacturers, as appropriate,

• Relevant law enforcement, first responders, and security experts, and

• Such other groups as the Administrator considers appropriate.

The STSAC web site provides more information on what the Committee does. While not specifically mentioned on the site, I suspect that a major topic of conversation at the next meeting (8-19-21) will be pipeline cybersecurity. Interestingly, that topic was not mentioned in the STSAC FY 2021 recommendations document, but ransomware attacks have a way of changing priorities.

According to the notice, TSA is specifically looking for five applicants “with specific expertise in the pipeline mode of surface transportation and cybersecurity across all surface transportation modes.”

Interested applicants may contact Judith Harroun-Lord, STSAC Designated Federal Officer, via email STSAC@tsa.dhs.gov. They need to provide:

• Complete professional resume.

• Statement of interest and reasons for application, including the membership category and how you represent a significant portion of that constituency, and also provide a brief explanation of how you can contribute to one or more TSA strategic initiative, based on your prior experience with TSA, or your review of current TSA strategic documents that can be found at www.tsa.gov/about/strategy.

• Home and work addresses, telephone number, and email address.

Thursday, May 20, 2021

HR 3243 Introduced - Pipeline Security Act

Last week Rep Cleaver (D,MO) introduced HR 3243, the Pipeline Security Act. The bill would amend 49 USC 114, specifically charging the Transportation Security Administration with responsibility for pipeline cybersecurity. Additionally, the bill would require the establishment, and outline the responsibilities, of a pipeline security section within TSA.

The Homeland Security Committee considered the bill earlier this week in a markup hearing. After considering and adopting three separate amendments, the bill was ordered reported and favorably recommended to the full House. One of the amendments would raise the status of the TSA pipeline cybersecurity program by changing the ‘section’ to a ‘pipeline security division’.

Moving Forward

The unanimous consent adoption for this bill in Committee would indicate that the bill has strong bipartisan support. That would normally mean that it should move easily to the floor of the House, probably under the suspension of the rules process. Unfortunately, bipartisan support is not all that a bill needs to move forward. In this case there are at least three other committees (the Science, Space, and Technology Committee, the Energy and Commerce Committee, and the Transportation and Infrastructure Committee) that think that they should have oversight responsibilities for cybersecurity in pipelines.

The language in this bill would specifically cut them out of the oversight process. That is why the §1631 language was shoehorned into 6 USC Title XVI (the CISA title) instead of in 49 USC where the TSA §114 is. That means that two Committee Chairs and a number of influential congresscritters are going to work hard to stop this bill from moving forward. This chair infighting has delayed a large number of homeland security related initiatives over the years, chemical facility security being a prime example. At this point I do not see the House leadership moving this bill forward.

For a more detailed review of the contents of the bill and the amendments adopted in Committee, see my post (subscription required) on ‘CFSN Detailed Analysis’ on Substack.com.

Tuesday, February 18, 2020

Pipeline Safety and Cybersecurity


The Pipeline and Hazardous Material Safety Administration (PHMSA) has increasingly begun to require technological solutions to on going safety problems with both gas transmission and hazardous material pipelines. A good example of that reliance can be found in the notice of proposed rulemaking (NPRM) that PHMSA issued earlier this month requiring the use of automated valves to limit the damage caused when pipelines rupture. Unfortunately, PHMSA’s failure to address cybersecurity issues related to the sensors and control systems associated with such technological solutions reduces the effectiveness of those measures.

Part of the reason that PHMSA has failed to act is that Congress has not provided PHMSA or DOT in general with specific authority to regulate the cybersecurity of pipeline infrastructure. The primary responsibility for pipeline security rests with the under funded and woefully understaffed surface transportation security folks within the Transportation Security Administration (TSA). But TSA has been both unwilling and unable to address cybersecurity issues beyond issuing broad guidelines and hoping for industry voluntary compliance with those guidelines.

The time has come for PHMSA to realize that it has an inherent responsibility to ensure that the technologies that it mandates for pipeline safety purposes are specifically protected against cyberattacks and that the failure of cybersecurity protections should trigger the same reporting requirements that accompany the failure of physical controls.

For example, in the current NPRM PHMSA could change the wording of the new §192.745(c) to read:

(c )For each valve installed under § 192.179(e) and each rupture-mitigation valve under § 192.634 that is a remote control shut-off or automatic shut-off valve, or that is based on alternative equivalent technology, the operator must:

(1) conduct a point-to-point verification between SCADA displays and the mainline valve, sensors, and communications equipment in accordance with § 192.631(c) and (e);

(2) demonstrate that the SCADA system, the mainline valve, sensors, and communications equipment are covered under a written cybersecurity plan that identifies:

(A) each of the open ports on each component and the processes, controls or devices protecting each open port against unauthorized communications attempts;

(B) procedures that are in place to ensure that all vendor security notices and advisories for each device are:

(I) reviewed in a timely manner, and
(II) the subject of a subsequent security risk assessment where appropriately adopted risk mitigation measures are implemented in a timely manner;

(C) the reporting processes that will be used to notify management of any incidents, equipment failures or loss of process view or control that might indicate a cyber intrusion or attack, and

(D) how the organization will respond to vulnerability reports from both within and outside of the organization.

NOTE: A copy of this post will be submitted as a comment on the NPRM in question.

 
/* Use this with templates/template-twocol.html */