Agent skill · Security

tsa-compliance

Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in

lawve-aigithub.com/lawve-aiGitHub ↗
claude-codeNOASSERTION
Install
npx skills add lawve-ai/awesome-legal-skills --skill tsa-compliance-tanaji-hemant-naik --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 6
SKILL.md size: 21 KB
Bundled scripts: none
Path: skills/tsa-compliance-tanaji-hemant-naik/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 618
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

Guides critical infrastructure owners and operators on TSA cybersecurity compliance across pipelines, freight rail, passenger rail/transit, and bus sectors. Helps determine applicable directive series (e.g., SD Pipeline-2021-01G/02, SD 1580-21-01, SD 1582-21-01) and provides structured outputs for gap assessments, CIP/COIP drafting, CAP drafting, incident response, architecture reviews, applicability determinations, and policy generation.

How it works

  • It starts by requiring the user’s sector and directive series to be clarified.
  • It matches the user’s task type (gap assessment, CIP/COIP drafting, CAP drafting, incident response, architecture review, applicability determination, or policy generation) to an Output Format described in a task table.
  • It references core TSA requirements: incident reporting to CISA within 24 hours; designation of Cybersecurity Coordinators; CRMP components (CIP/COIP, IRP, ADR, CAP); and four technical domains (Network Segmentation, Access Controls, Continuous Monitoring and Detection, Patch Management).
  • It instructs that outputs should be formatted as a structured plan or document appropriate to the task (e.g., CIP contents, IRP elements, ADR scope, CAP elements).
  • It emphasizes that directives vary by sector and revision, and to confirm the most current revision where possible.

When to use it

Use when a user asks about TSA Security Directives for pipelines, freight rail, passenger rail, public transit, or bus operators; CRMP; CIP/COIP; CAP; incident reporting to CISA; Cybersecurity Coordinator; CCS; OT/IT segmentation; the November 2024 NPRM; or related directives, and when a sector-specific applicability or drafting task is needed.

What it can touch

  • Tools: claude-code
  • Outputs: structured policy-like documents (CIP/COIP, IRP, ADR, CAP), gap assessment tables, applicability narratives, incident response procedures, architecture reviews

Caveats

  • Requires explicit sector and directive identification for accurate tailoring.
  • Outputs must be created to reflect current revisions; verify latest revisions when drafting mandated documents.
  • The skill discusses regulatory concepts and directives but does not itself enact reporting or TSA submissions.
From the SKILL.md

# TSA Cybersecurity Compliance Skill > **Last verified:** 2026-07-03 You are an expert TSA cybersecurity compliance advisor assisting **critical infrastructure owners and operators** — pipeline companies, freight railroads, passenger rail and transit agencies, and bus operators — in understanding and implementing TSA Security Directive requirements. You have deep knowledge of the current TSA Security Directive series (SD Pipeline-2021-01G, SD Pipeline-2021-02F, SD 1580-21-01E, SD 1582-21-01E), the November 2024 Notice of Proposed Rulemaking (NPRM), and their relationship to NIST CSF 2.0 and CISA Cross-Sector Cybersecurity Performance Goals (CPGs). --- ## How to Respond Always clarify which sector and directive series applies to the user's organisation. TSA directives vary by sector and are updated on rolling cycles — confirm the most current revision where possible. Match your output to the task type: | Task | Output Format | |------|--------------| | Gap assessment | Table: Requirement | Status | Gap | Evidence Needed | Priority | | CIP / COIP drafting | Structured plan document with all required sections | | CAP drafting | Assessment schedule, methodology, scope, and reporting ta

What's inside
Steps it walks through
  1. How to Respond
  2. Directive Coverage by Sector
  3. Pipelines (Highest Risk)
  4. Freight Rail
  5. Public Transportation and Passenger Rail
  6. Aviation
  7. Bus (Proposed — 2024 NPRM)
  8. Core Concepts
  9. Critical Cyber Systems (CCS)
  10. Cybersecurity Coordinator
  11. CISA vs TSA Roles
  12. Core Requirements (Applicable to All Covered Entities)
  13. 1. Cybersecurity Incident Reporting (Immediate)
  14. 2. Cybersecurity Coordinator Designation
Ships with 5 files
  • LICENSE
  • README.md
  • references/tsa-crmp-requirements.md
  • references/tsa-directives-overview.md
  • references/tsa-incident-reporting.md
More from awesome-legal-skills
All skills →
About this skill
What does the tsa-compliance skill do?

Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in

How do I install it?

Run `npx skills add lawve-ai/awesome-legal-skills --skill tsa-compliance-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going