Agent skill · Security

tsa-compliance

Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in

Sushegaadgithub.com/SushegaadGitHub ↗
claude-codeMIT
Install
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 4
SKILL.md size: 21 KB
Bundled scripts: none
Path: plugins/tsa-compliance/skills/tsa-compliance/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 801
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

Provides expert guidance on TSA cybersecurity compliance for critical infrastructure in pipelines, freight rail, passenger rail, public transit, and bus operators, including CRMP components (CIP/COIP, IRP, ADR, CAP) and incident reporting to CISA.

How it works

  • Requires the agent to first ask for the sector and directive series applicable to the user's organization.
  • Supports task-specific outputs based on the user's request type (Gap assessment, CIP/COIP drafting, CAP drafting, Incident response, Architecture review, Applicability determination, Policy generation, General question).
  • For each output, formats match the TSA directive coverage by sector, providing structured guidance and required elements (e.g., CIP contents, IRP elements, ADR scope, CAP elements).
  • Emphasizes reporting to CISA within 24 hours of incident identification and designation of a Cybersecurity Coordinator with 24/7 availability.
  • Aligns with the CRMP four components and four technical security domains: Network Segmentation, Access Controls, Continuous Monitoring and Detection, Patch Management.

When to use it

  • When asked about TSA Security Directives for pipelines, freight rail, passenger rail, public transit, or bus operators; CRMP; CIP/COIP; CAP; incident reporting to CISA; Cybersecurity Coordinator designation; CCS; OT/IT segmentation; or the TSA NPRM.
  • For sector-specific directive status, network segmentation requirements, and monitoring/patching practices.

What it can touch

  • References to CIP/COIP contents, IRP elements, ADR scope, CAP elements, and the four domains (Network Segmentation, Access Controls, Continuous Monitoring and Detection, Patch Management).

Caveats

  • Based on current TSA directive series and NPRM status as described; exact revision numbers and timelines should be confirmed with TSA directly where possible.
  • Requires clarifying the sector and directive series before producing the task-specific output.
From the SKILL.md

# TSA Cybersecurity Compliance Skill > **Last verified:** 2026-07-03 You are an expert TSA cybersecurity compliance advisor assisting **critical infrastructure owners and operators** — pipeline companies, freight railroads, passenger rail and transit agencies, and bus operators — in understanding and implementing TSA Security Directive requirements. You have deep knowledge of the current TSA Security Directive series (SD Pipeline-2021-01G, SD Pipeline-2021-02F, SD 1580-21-01E, SD 1582-21-01E), the November 2024 Notice of Proposed Rulemaking (NPRM), and their relationship to NIST CSF 2.0 and CISA Cross-Sector Cybersecurity Performance Goals (CPGs). --- ## How to Respond Always clarify which sector and directive series applies to the user's organisation. TSA directives vary by sector and are updated on rolling cycles — confirm the most current revision where possible. Match your output to the task type: | Task | Output Format | |------|--------------| | Gap assessment | Table: Requirement | Status | Gap | Evidence Needed | Priority | | CIP / COIP drafting | Structured plan document with all required sections | | CAP drafting | Assessment schedule, methodology, scope, and reporting ta

What's inside
Steps it walks through
  1. How to Respond
  2. Directive Coverage by Sector
  3. Pipelines (Highest Risk)
  4. Freight Rail
  5. Public Transportation and Passenger Rail
  6. Aviation
  7. Bus (Proposed — 2024 NPRM)
  8. Core Concepts
  9. Critical Cyber Systems (CCS)
  10. Cybersecurity Coordinator
  11. CISA vs TSA Roles
  12. Core Requirements (Applicable to All Covered Entities)
  13. 1. Cybersecurity Incident Reporting (Immediate)
  14. 2. Cybersecurity Coordinator Designation
Ships with 3 files
  • references/tsa-crmp-requirements.md
  • references/tsa-directives-overview.md
  • references/tsa-incident-reporting.md
More from Claude-Skills-Governance-Risk-and-Compliance
All skills →
About this skill
What does the tsa-compliance skill do?

Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in

How do I install it?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going