The new requirements were issued through Security Directive Pipeline-2021-02C on July 27, 2022. We break the new directive for you here.
Pipeline owners and operators in the scope of the latest security directive have 90 days to develop and submit their Cybersecurity Implementation Plan for review and approval. This means that after October 27, 2022, those who haven't created or adapted a detailed plan that covers critical cyber systems identification, network segmentation and access control measures, continuous monitoring, and patch management will be subject to fines.
The new approach supersedes previous directives and includes the following three core requirements:
How to Best Comply with the Directives: Network Modeling
The new Security Directive details the following list of documentation to establish compliance:
It’s recommended that pipeline security and compliance teams leverage this list as a starting point and walk backward to assess the gap between the information they currently have available and the expected deliverables from TSA.
The fastest way to produce accurate network diagrams and comprehensive firewall rulesets and filtering policies under such a tight deadline is to use network modeling technology.
Network modeling – or dynamic network representation – means proactively understanding which assets can connect to which services by building a model of the network using the configurations of OT firewall and router devices. It provides accurate, instant visibility of the network architecture and enables risk assessment without having to deploy any sensor or agent in the environment.
Need help? Contact Network Perception and let us help you with our network modeling capabilities to:
Network Perception proactively and continuously assures the security of critical OT assets with intuitive network segmentation verification and visualization.
Our platform takes essential auditing technology and makes it continuous for proactive OT network security that builds cyber resiliency. NP-View creates intuitive topological maps that serve as a GPS for both technical and non-technical users, providing a unified ruleset review and insight into how to ensure network security.
Threats don’t wait for an audit, and neither should you. With Network Perception, you know your risk now and always and protect your critical networks with:
Read more in our Whitepaper.
If you have questions or would like to know more about the most recent TSA deadline, please contact the Network Perception team at:
+1 (872) 245-4100 | info@network-perception.com | Talk to an OT/ICS Specialist TODAY