# TSA Pipeline Security Directives (SD-1 and SD-2)

Framework id: `tsa_psd`. Infrastructure Regulation. Publisher: Transportation Security Administration (TSA). Version: 2021 (reissued 2023). Region: USA. Mapping licence: CC BY-SA 4.0.
Source text: https://www.tsa.gov/sd-and-ea

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (12, average coverage 78%)
- SD-1 Sec 1 Cybersecurity Coordinator: PM-01, PM-02, PM-10 (75%)
- SD-1 Sec 2 Incident Reporting: IR-01, IR-06, PM-15 (68%)
- SD-1 Sec 3 Vulnerability Assessment: RA-03, RA-05, CA-02, CA-08 (80%)
- SD-1 Sec 4 Remediation Measures: CA-05, PM-04, RA-07 (72%)
- SD-2 Sec A Network Segmentation: SC-07, SC-32, AC-04, SC-46 (82%)
- SD-2 Sec B Access Control Measures: AC-02, AC-03, AC-05, AC-06, AC-07, AC-17, IA-02, IA-05, IA-08 (85%)
- SD-2 Sec C Continuous Monitoring and Detection: SI-04, CA-07, AU-02, AU-06, SC-48, IR-04 (78%)
- SD-2 Sec D Patch Management: SI-02, CM-03, CM-04, RA-05, SA-22 (80%)
- SD-2 Sec E Cybersecurity Implementation Plan: PL-01, PL-02, PM-01, PM-09, CA-05 (78%)
- SD-2 Sec F Cybersecurity Architecture Design Review: PL-08, SA-08, SA-17, SC-07, SC-32 (75%)
- SD-2 Sec G Cybersecurity Testing: CA-08, CA-02, RA-05, SA-11 (82%)
- SD-2 Sec H Cybersecurity Training: AT-01, AT-02, AT-03, AT-04, PM-13 (85%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=tsa_psd
- Control-to-clause mappings as JSON: /api/v1/frameworks/tsa_psd?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/tsa-psd.json
- Page for people: /frameworks/tsa-psd/
