How to prepare leadership for a TSA cybersecurity assessment

  • TSA Pipeline Security Directives
  • Leadership
  • Cybersecurity Assessment Plan

A TSA audit meeting is not graded on the documents alone. The Cybersecurity Coordinator can walk in with a complete Implementation Plan, a current Assessment Plan, and every piece of evidence on the checklist, and the meeting can still go sideways the moment an auditor asks a question the paperwork doesn’t answer. That happens more often than most leadership teams expect, and it’s usually not because the program is weak. It’s because the people in the room who could speak to the program’s substance weren’t the ones TSA was asking.

What the paperwork actually proves, and what it doesn’t

The Implementation Plan, the Assessment Plan, and the evidence trail behind each SD requirement prove that a program exists and that it’s been executed on schedule. They don’t, by themselves, prove that the people responsible for it understand why it’s built the way it is. An auditor’s follow-up question, why this control instead of a stricter one, what happens if the one-third assessment rotation slips a quarter, who actually has authority to isolate OT from IT during a live incident, tests exactly that gap. A Coordinator can answer procedural questions all day. Some of what comes up requires someone with actual operating authority over the program to answer directly, in the room, without going back to check.

That’s the vantage point worth naming here: having sat on the executive side of that table, the questions that stall a meeting are rarely about the documents themselves. They’re about whether the person answering actually owns the decision being asked about, or is relaying someone else’s.

The three things leadership needs to be able to speak to

Not the full text of the directives, and not the technical detail behind every control. Three specific things, each of which has come up directly in this kind of meeting before.

First, who the Coordinator is, and whether that’s current. SD Pipeline-2021-01G requires a primary and alternate Cybersecurity Coordinator on file with TSA, reachable 24/7, with any change filed within seven days. This is usually the first thing confirmed in the room. A designation that’s stale on paper, the wrong phone number, a role that changed six months ago and was never updated, reads as evidence the rest of the program might be stale too, even when it isn’t.

Second, where the Assessment Plan is in its cycle, and what the one-third rotation has covered. The annual Assessment Plan cycle requires at least one-third of the Implementation Plan’s policies, procedures, and capabilities assessed every year, reaching full coverage over three years. Leadership doesn’t need to recite the schedule from memory. Leadership does need to know, without checking, roughly where the program stands in that rotation and what’s coming due, because that’s a question about program health, not a paperwork detail.

Third, who has authority to isolate OT from IT during an incident, and whether that’s been tested. The Incident Response Plan names IT/OT isolation as its own objective, separate from general containment, and requires an annual exercise of at least two of its four objectives with the named position-holders actually participating. If leadership can’t say who makes that call or when it was last practiced, that’s a real gap, not a formality, and it’s the kind of gap an auditor’s question surfaces immediately.

Why this can’t be delegated entirely to the Coordinator

The Coordinator role exists precisely so there’s a single accountable point of contact for TSA, and a well-run program leans on that role heavily. But the Coordinator’s internal-coordination duty depends on having enough authority, or a direct line to someone who does, to make real decisions. When TSA’s questions reach past process into judgment, why the program made the choices it made, what leadership would actually do in a scenario the plan describes, that authority has to be visible in the room. A Coordinator fielding a question that isn’t theirs to answer, with no one present who can answer it directly, is the scenario that turns a routine meeting into a longer one.

Preparing for the meeting, not just the audit

The distinction that matters here: preparing documents is a compliance task, and most programs are reasonably good at it by the time an assessment comes around. Preparing the people who’ll be in the room is a different task, closer to a briefing than a checklist, and it’s the one that gets skipped when time is short. A short pre-meeting walkthrough, covering the three points above plus whatever’s specific to that cycle’s Assessment Plan findings, closes most of the gap.

For what to have on file before that walkthrough happens, see the evidence checklist. For a structured view of where a program’s gaps are likely to sit before TSA finds them, the Readiness Check is built for exactly that.

All posts