This emergency request is approved contingent on the agency publishing a 60-day notice for public comment within 120 days of approval.
table that charts list comparision
Inventory as of this Action
Requested
Previously Approved
04/30/2023
6 Months From Approved
10/31/2025
2,562
0
2,343
134,023
0
96,063
0
0
0
TSA intends to publish Security Directives (SD), which will be mandatory, and Information Circular (IC), which will be non-mandatory recommendations, to various surface transportation mode operators to address the ongoing cybersecurity threat using a risk-based approach to transportation security. The SDs would only apply to âHigher Riskâ Railroads and Rail Transit operations and the IC would apply to lower-risk operations to enhance the surface transportation integrated system to include transit bus operations and over-the-road bus (OTRB) owner/operators.
To protect against escalating cybersecurity threats, TSA intends to publish a Security Directive (SD) which will be mandatory, titled SD 1580/1582-2022-01 Rail Cybersecurity Mitigation Actions, Contingency Planning, and Testing. The purpose of this SD will be to reduce the vulnerability of critical railroad operations and facilities to cybersecurity threats through implementation of layered cybersecurity measures that provide defense-in-depth. The SD 1580/1582-2022-01 would apply to Owner/Operators of freight and passenger railroads, to include the âHigher Riskâ Freight railroads identified in 49 CFR 1580.101 and additional TSA-designated freight and passenger railroads. As this SD requires new information to be submitted to TSA, TSA is requesting emergency approval for a revision of OMB Control Number 1652-0074, Cybersecurity Measures for Surface Modes. TSA would continue to collect information under this Information Collection Request (ICR) for the previously issued SD-1580-21-01 , SD -1582-21-01 and IC 2021-01 issued on December 31, 2021, which remain in effect.
TSA is making program changes as a result of the new collections to be implemented upon issuance of SD 1580/1582-2022-01 and the revisions made to SD 1580-21-01, SD 1582-21-01, and IC 2021-01.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.