TSA MANDATED CYBERSECURITY IMPLEMENTATION PLAN

Overview

A $12B+ Class A national rail-based transportation supplier had been ordered by the TSA to fulfill Security Directive 1580/82-2022-01 as part of an industry mandate. The directive was to identify and fortify their critical IT systems to enable isolation in the event of a cyber attack, helping to avoid a national security threat or disruption to the supply chain.

 

Lexico helped to define and identify business processes key to the continued operation of critical services, map those processes against the IT/OT systems required to enable those processes, and analyze those systems for any cybersecurity gaps. A Cybersecurity Implementation Plan was then drafted to be submitted to the TSA.

 

The goal was to conduct this work in a manner that would feed into broader cybersecurity plans, including the mapping of TSA requirements to NIST 800-53 and SOC 2. The frameworks developed are repeatable and able to be incorporated into the broader operating model and security program. Lexico orchestrated a cross-functional, cross line-of-business effort that factored in a balanced set of considerations such as manual workarounds, impacts on operations, service levels, risk, and financials. All considerations were matrixed against the various lines of business and their importance to national security.

Pain Points

  • Client had 110+ critical systems making it cost prohibitive to isolate all the systems.
  • Define a Critical Application and account for differing viewpoints; get to a manageable and accurate scope     (110 apps ➝ ~15).
  • Bring alignment between the Business and IT, who already had a gauge on what systems were critical.
  • Determine the best way to balance needs and timing of the directive with something that’s meaningful and useful to the client.
  • Short timeline; In just six weeks, determine the appropriate level of detail in the Cyber Implementation Plan, taking into consideration remediation commitments, and financial and resource implications.

Solution Profile

  • Developed a framework for assessing criticality of IT systems.
  • Identified the critical commodities that needed to continue to ship in the event of a cyber threat and to what levels.
  • Orchestrated a workshop with business and IT. Identified where manual business processes could be utilized to achieve the desired levels.
  • Where manual processes could not sustain the levels, identified what IT systems were required to enable them.

Results

  • Developed a Cybersecurity Implementation Plan (4 systems) that allowed the railroad to sustain moving 8% of its most critical freight during a cyber attack lasting 3-5 days.
  • Identified an additional 12 systems allowing the railroad to move ~20% of its freight and minimize customer and financial hardships.