The National Institute of Standards and Technology’s National Cybersecurity Center of Excellence (NCCoE) released this week final Transit Cybersecurity Framework Community Profile, a voluntary, risk-based resource designed to help U.S. transit agencies strengthen cybersecurity preparedness and resilience while maintaining safe and reliable services. The Transit Profile focuses on the operational systems, including IT and OT (operational technology), that transit agencies own and operate, as well as the challenges involved in managing these services. It addresses the growing cyberattack surface created by increasingly networked business and operational technology systems and maps recommended cybersecurity activities to the NIST Cybersecurity Framework 2.0 and relevant industry guidance.
Developed with transit agencies, federal transportation agencies, and other stakeholders, the profile focuses on securing critical assets, strengthening collaboration with stakeholders and suppliers to improve resilience and supply chain security, and continuously improving organizational processes and workforce cybersecurity capabilities.
The Transit Profile helps transit agencies focus resources on cybersecurity activities aligned with these strategic priorities by mapping them to relevant CSF Subcategories. This enables transit leaders to prioritize cybersecurity capabilities, perform gap analyses, and make informed risk-based decisions. It integrates industry-specific cybersecurity considerations and guidelines for agencies of all sizes, including small- and medium-sized transit agencies (SMTAs) with limited resources and supports scalable actions based on size and maturity.
Read the rest of the story at Industrial Cyber.


