– Appointment of a primary and alternate Cybersecurity Coordinator with TSA;
– Reporting of cybersecurity incidents to the Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA);
– Completion of a cybersecurity self-assessment using a form provided by TSA; and
– Development and implementation of a Cyber Incident Response Plan.
Every Class I railroad and Amtrak, as well as many commuter and short line carriers, have chief information security officers and cybersecurity leads who will serve as the required Cybersecurity Coordinators. Further, railroads have conducted cybersecurity assessments on a recurring basis and have developed, exercised and applied Cyber Incident Response Plans. Through the AAR’s Railway Alert Network (RAN), railroads have been reporting significant cyber threats, incidents and security concerns to TSA, DHS and the Department of Transportation (DOT) since 2014. AAR does note that an unresolved issue is the appointment of cybersecurity coordinators by railroads headquartered in Canada and will work with TSA and its Canadian members to resolve that issue.###
For more information contact: AAR Media Relations at media@aar.org or 202-639-2345. About AAR: The AAR is the world’s leading railroad policy, research and technology organization focusing on the safety and productivity of rail carriers. AAR members include the major freight railroads of the U.S., Canada and Mexico, as well as Amtrak. Follow Us: Twitter / Facebook / LinkedIn / Signal Newsletter