tsa-compliance
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in
npx skills add lawve-ai/awesome-legal-skills --skill tsa-compliance-tanaji-hemant-naik --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
What it does
Guides critical infrastructure owners and operators on TSA cybersecurity compliance across pipelines, freight rail, passenger rail/transit, and bus sectors. Helps determine applicable directive series (e.g., SD Pipeline-2021-01G/02, SD 1580-21-01, SD 1582-21-01) and provides structured outputs for gap assessments, CIP/COIP drafting, CAP drafting, incident response, architecture reviews, applicability determinations, and policy generation.
How it works
- It starts by requiring the user’s sector and directive series to be clarified.
- It matches the user’s task type (gap assessment, CIP/COIP drafting, CAP drafting, incident response, architecture review, applicability determination, or policy generation) to an Output Format described in a task table.
- It references core TSA requirements: incident reporting to CISA within 24 hours; designation of Cybersecurity Coordinators; CRMP components (CIP/COIP, IRP, ADR, CAP); and four technical domains (Network Segmentation, Access Controls, Continuous Monitoring and Detection, Patch Management).
- It instructs that outputs should be formatted as a structured plan or document appropriate to the task (e.g., CIP contents, IRP elements, ADR scope, CAP elements).
- It emphasizes that directives vary by sector and revision, and to confirm the most current revision where possible.
When to use it
Use when a user asks about TSA Security Directives for pipelines, freight rail, passenger rail, public transit, or bus operators; CRMP; CIP/COIP; CAP; incident reporting to CISA; Cybersecurity Coordinator; CCS; OT/IT segmentation; the November 2024 NPRM; or related directives, and when a sector-specific applicability or drafting task is needed.
What it can touch
- Tools: claude-code
- Outputs: structured policy-like documents (CIP/COIP, IRP, ADR, CAP), gap assessment tables, applicability narratives, incident response procedures, architecture reviews
Caveats
- Requires explicit sector and directive identification for accurate tailoring.
- Outputs must be created to reflect current revisions; verify latest revisions when drafting mandated documents.
- The skill discusses regulatory concepts and directives but does not itself enact reporting or TSA submissions.
# TSA Cybersecurity Compliance Skill > **Last verified:** 2026-07-03 You are an expert TSA cybersecurity compliance advisor assisting **critical infrastructure owners and operators** — pipeline companies, freight railroads, passenger rail and transit agencies, and bus operators — in understanding and implementing TSA Security Directive requirements. You have deep knowledge of the current TSA Security Directive series (SD Pipeline-2021-01G, SD Pipeline-2021-02F, SD 1580-21-01E, SD 1582-21-01E), the November 2024 Notice of Proposed Rulemaking (NPRM), and their relationship to NIST CSF 2.0 and CISA Cross-Sector Cybersecurity Performance Goals (CPGs). --- ## How to Respond Always clarify which sector and directive series applies to the user's organisation. TSA directives vary by sector and are updated on rolling cycles — confirm the most current revision where possible. Match your output to the task type: | Task | Output Format | |------|--------------| | Gap assessment | Table: Requirement | Status | Gap | Evidence Needed | Priority | | CIP / COIP drafting | Structured plan document with all required sections | | CAP drafting | Assessment schedule, methodology, scope, and reporting ta
- How to Respond
- Directive Coverage by Sector
- Pipelines (Highest Risk)
- Freight Rail
- Public Transportation and Passenger Rail
- Aviation
- Bus (Proposed — 2024 NPRM)
- Core Concepts
- Critical Cyber Systems (CCS)
- Cybersecurity Coordinator
- CISA vs TSA Roles
- Core Requirements (Applicable to All Covered Entities)
- 1. Cybersecurity Incident Reporting (Immediate)
- 2. Cybersecurity Coordinator Designation
What does the tsa-compliance skill do?
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in
How do I install it?
Run `npx skills add lawve-ai/awesome-legal-skills --skill tsa-compliance-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
