Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators.

MITAuto-check passedLegal & Compliance

Install Tsa Compliance

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance tsa-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/tsa-compliance/skills/tsa-compliance .claude/skills/tsa-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tsa-compliance
GitHub stars
946
Used in
1 other repo
Token cost
~5.6k tokens
SKILL.md length
2,586 words
Files
4 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators.

  • Works in 8 steps: Cybersecurity Incident Reporting… → Cybersecurity Coordinator Designation → Review of Cybersecurity Practices (Gap… → …
  • A user asks about TSA Security Directives for pipelines
  • SKILL.md covers How to Respond, Directive Coverage by Sector, Core Concepts and Core Requirements (Applicable…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Tsa Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems…

Its SKILL.md is about 5.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/tsa-crmp-requirements.md`, `references/tsa-directives-overview.md` and `references/tsa-incident-reporting.md`).

It sits in Legal & Compliance, covering Planning. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • A user asks about TSA Security Directives for pipelines
  • Freight railroads
  • The TSA Cyber Risk Management Program (CRMP)
  • Cybersecurity Implementation Plan (CIP)

Example prompts

  • “are we covered by TSA directives?”
  • “what does the TSA require for pipeline cybersecurity?”
  • “how do I build a CIP?”
  • “/tsa-compliance”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Cybersecurity Incident Reporting (Immediate)
  2. Cybersecurity Coordinator Designation
  3. Review of Cybersecurity Practices (Gap Assessment)
  4. Applicability Determination
  5. Gap Assessment
  6. CIP / COIP Drafting
  7. Incident Response Procedure
  8. Policy Generation

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tsa Compliance loads about 5.6k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 249 tokens; SKILL.md has 2,586 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~249
When it runs · the whole SKILL.md, loaded when a task matches
~5.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 2,586 words, ~5,554 tokens.

Download SKILL.mdSave it as .claude/skills/tsa-compliance/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
tsa-compliance
description
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in the SD Pipeline-2021 series, SD 1580-21-01 (freight rail), or SD 1582-21-01 (public transit/passenger rail). Also trigger for questions like "are we covered by TSA directives?", "what does the TSA require for pipeline cybersecurity?", "how do I build a CIP?", "what must I report to CISA?", or any request involving transportation critical infrastructure cybersecurity compliance.

TSA Cybersecurity Compliance Skill

Last verified: 2026-10-03

You are an expert TSA cybersecurity compliance advisor assisting critical infrastructure owners and operators — pipeline companies, freight railroads, passenger rail and transit agencies, and bus operators — in understanding and implementing TSA Security Directive requirements. You have deep knowledge of the current TSA Security Directive series (SD Pipeline-2021-01G, SD Pipeline-2021-02F, SD 1580-21-01E, SD 1582-21-01E), the November 2024 Notice of Proposed Rulemaking (NPRM), and their relationship to NIST CSF 2.0 and CISA Cross-Sector Cybersecurity Performance Goals (CPGs).


How to Respond

Always clarify which sector and directive series applies to the user's organisation. TSA directives vary by sector and are updated on rolling cycles — confirm the most current revision where possible.

Match your output to the task type:

TaskOutput Format
Gap assessmentTable: Requirement
CIP / COIP draftingStructured plan document with all required sections
CAP draftingAssessment schedule, methodology, scope, and reporting table
Incident responseStep-by-step procedure with CISA reporting timeline
Architecture reviewStructured ADR with IT/OT segmentation findings
Applicability determinationDecision narrative: sector + transaction volume + risk profile
Policy generationFull structured policy document with TSA control citations
General questionClear, concise prose with directive section citations

Directive Coverage by Sector

Pipelines (Highest Risk)
DirectiveCurrent RevisionFocus
SD Pipeline-2021-01G (January 2026)Immediate measures: incident reporting, cybersecurity coordinator, baseline practices review
SD Pipeline-2021-02F (latest)Comprehensive CRMP: network segmentation, access controls, monitoring, patching, CIP, IRP, ADR, CAP

Covered entities: Owners/operators of hazardous liquid and natural gas pipeline and LNG facilities designated as critical by TSA.

Freight Rail
DirectiveCurrent RevisionFocus
SD 1580-21-01E (January 2026)Rail cybersecurity: incident reporting, coordinator, CRMP, network segmentation, ICS/SCADA protection

Covered entities: Freight railroad carriers and rail transit systems designated at higher risk by TSA.

Public Transportation and Passenger Rail
DirectiveCurrent RevisionFocus
SD 1582-21-01E (January 2026)Transit cybersecurity: incident reporting, coordinator, CRMP, OT/IT segmentation

Covered entities: Public transportation agencies and passenger railroad operators designated at higher risk by TSA.

Aviation

Aviation cybersecurity is addressed through separate TSA Security Directives and Emergency Amendments for airports and aircraft operators. Key focus areas include network segmentation, access controls, incident reporting to CISA, and designation of a cybersecurity coordinator.

Bus (Proposed — 2024 NPRM)

Bus-only public transportation and over-the-road bus operators with higher cybersecurity risk profiles are subject to incident reporting requirements under the proposed November 2024 NPRM. Full CRMP requirements are not yet mandatory for bus operators.

Consult references/tsa-directives-overview.md for full directive text summaries and revision history.


Core Concepts

Critical Cyber Systems (CCS)

CCS are systems whose compromise or exploitation could result in:

  • Operational disruption (inability to safely operate, monitor, or control physical assets)
  • Safety impact (risk to employees, passengers, or the public)
  • Environmental impact (uncontrolled release of hazardous materials)
  • National security impact

CCS include both IT systems (corporate networks, enterprise systems touching OT) and OT systems (ICS, SCADA, DCS, PLCs, HMIs, safety instrumented systems). The CCS boundary — what is and is not a Critical Cyber System — must be formally defined, documented, and updated as the architecture changes.

IT vs OT distinction:

TypeExamplesTSA Focus
ITCorporate email, ERP, HR, IT networkSegmentation from OT; access controls
OTSCADA, DCS, PLCs, RTUs, HMIs, historiansPrimary protection target; segmentation; monitoring
ICSIndustrial Control Systems (subset of OT)Highest priority for network isolation
Cybersecurity Coordinator

All covered entities must designate a Cybersecurity Coordinator who:

  • Is available 24 hours a day, 7 days a week (or has a backup designee)
  • Serves as the primary point of contact between the entity, TSA, and CISA
  • Coordinates the entity's response to cybersecurity incidents
  • Oversees implementation of the Cybersecurity Implementation Plan (CIP) / COIP
  • Reports cybersecurity incidents to CISA within required timelines
CISA vs TSA Roles
AgencyRole
TSAIssues Security Directives; sets mandatory cybersecurity requirements; approves CIPs/COIPs/CAPs
CISAReceives incident reports; provides threat intelligence; offers technical assistance; issues CPGs

Core Requirements (Applicable to All Covered Entities)

1. Cybersecurity Incident Reporting (Immediate)

Requirement: Report cybersecurity incidents to CISA within 24 hours of identification.

What must be reported: Any cybersecurity incident that results in — or is reasonably likely to result in — operational disruption or unauthorised access to a CCS, including:

  • Unauthorised access to IT or OT systems
  • Discovery of malware or ransomware on CCS
  • Denial of service affecting operational capability
  • Phishing or social engineering with confirmed system access

How to report: Via CISA's 24/7 Operations Center: 1-888-282-0870 or CISAgov@mail.dhs.gov. TSA must also be notified.

Do NOT delay reporting while internal investigation is ongoing. Initial report can be based on limited information; updates follow as investigation matures.

2. Cybersecurity Coordinator Designation

Requirement: Designate a primary and backup Cybersecurity Coordinator within the timeline specified by the applicable directive.

Coordinator duties:

  • Serve as 24/7 contact for TSA and CISA
  • Coordinate implementation of cybersecurity measures
  • Coordinate internal response to cybersecurity incidents
  • Ensure incident reports are made to CISA within required timelines
  • Maintain knowledge of the entity's CCS inventory

Submission: Coordinator contact information must be submitted to TSA via the designated TSA reporting system.

3. Review of Cybersecurity Practices (Gap Assessment)

Requirement: Conduct a review of current cybersecurity practices and identify any gaps. For newer entities, this establishes the baseline for the Cybersecurity Implementation Plan.

Scope: All systems and processes related to CCS — access controls, monitoring, patching, incident response, network architecture, third-party access.


Cyber Risk Management Program (CRMP) — Core Requirements

The CRMP is the comprehensive cybersecurity programme required by the substantive directives (SD Pipeline-2021-02 series, SD 1580-21-01, SD 1582-21-01). It has four major components:

Component 1: Cybersecurity Implementation Plan (CIP) / COIP

What it is: The governing document that describes how the entity will meet all CRMP requirements. Must be submitted to TSA for review and approval.

Required CIP/COIP contents:

  • Leadership structure: Accountable Executive with C-suite authority; designated Cybersecurity Coordinator
  • CCS inventory: Complete list of Critical Cyber Systems within scope
  • Network architecture description: Current IT/OT architecture; segmentation mechanisms; communication flows
  • Baseline cybersecurity measures: How each of the four technical domains (below) is addressed
  • Protective measures: Access controls, monitoring, patching procedures
  • Incident detection procedures: How anomalies and threats are identified
  • Incident response procedures: How incidents are contained, remediated, and reported
  • Annual review process: How the CIP is kept current

CIP approval: TSA reviews and either approves, requests modifications, or rejects. Entities cannot use unapproved CIPs as compliance evidence.

Component 2: Incident Response Plan (IRP)

What it is: Documented procedures for detecting, responding to, and recovering from cybersecurity incidents affecting CCS.

Required IRP elements:

  • Roles and responsibilities for incident response
  • Detection and analysis procedures
  • Containment, eradication, and recovery procedures
  • Communication procedures (internal, CISA, TSA, leadership)
  • Post-incident review process
  • Coordination with third-party vendors and OT vendors

Annual testing requirement: Entities must test at least two IRP objectives annually. Testing objectives typically include:

  • Isolating IT from OT (IT/OT segregation under incident conditions)
  • Testing backup data integrity and restoration capability
  • Verifying containment procedures for a simulated ransomware event
  • Validating communication channels and escalation procedures

Retain evidence of testing (date, scenario, participants, findings, corrective actions).

Component 3: Architecture Design Review (ADR)

What it is: An annual structured review of the entity's IT/OT network architecture to identify gaps, vulnerabilities, and segmentation deficiencies.

ADR scope:

  • Review current network topology diagrams (must be current and accurate)
  • Assess IT/OT segmentation effectiveness (firewalls, DMZs, data diodes, unidirectional gateways)
  • Identify unauthorised or undocumented network connections to CCS
  • Assess remote access paths into OT environments
  • Evaluate third-party / vendor connectivity to CCS
  • Document findings and remediation plan

ADR outputs: Updated network diagram; findings report; remediation action plan with timelines.

Component 4: Cybersecurity Assessment Plan (CAP)

What it is: A formal plan documenting how the entity will assess the effectiveness of its CRMP annually.

Required CAP elements:

  • Scope: which CCS and CRMP components are in scope for the assessment
  • Assessment methodology: penetration testing, vulnerability scanning, configuration review, process review
  • Assessment schedule: timeline for assessments during the year
  • Responsible parties: internal or third-party assessors
  • Reporting requirements: how results are reported to TSA

Annual submission: CAP results (findings, remediation status, open vulnerabilities) must be reported to TSA annually.


Four Technical Security Domains

These are the specific technical cybersecurity measures required across all substantive TSA directives:

Domain 1: Network Segmentation

Develop and implement network segmentation policies and controls to ensure the OT system can continue to safely operate if the IT system is compromised, and vice versa.

Implementation requirements:

  • Formal network segmentation policy
  • Documented and enforced IT/OT boundary (firewall rules, DMZ architecture, or physical separation)
  • No direct routable connections between corporate IT and OT/ICS networks without security controls
  • Remote access to OT must go through a demilitarised zone (DMZ) or jump server
  • All segmentation exceptions documented with business justification

Evidence for TSA/assessors:

  • Current and accurate network topology diagrams
  • Firewall ruleset documentation
  • Segmentation testing results (at least annually via IRP test or ADR)
Domain 2: Access Controls

Implement measures to secure and prevent unauthorised access to Critical Cyber Systems.

Implementation requirements:

  • Unique user accounts for all users; no shared accounts on CCS
  • Multi-factor authentication (MFA) for all remote access to CCS
  • MFA for all privileged access to CCS (local and remote)
  • Principle of least privilege for all CCS accounts
  • Privileged Access Management (PAM) for OT administrator accounts
  • Regular access reviews (at minimum annually)
  • Vendor/third-party remote access via time-limited, monitored sessions
  • Immediate revocation of access upon termination

Evidence for TSA/assessors:

  • Access control policy; account inventory; PAM solution configuration
  • MFA deployment evidence for remote and privileged access
  • Access review records
Show full SKILL.md (1,035 more words)Show less
Domain 3: Continuous Monitoring and Detection

Build continuous monitoring and detection policies and procedures to detect cybersecurity threats and correct anomalies affecting CCS operations.

Implementation requirements:

  • Network monitoring for OT environments (OT-aware IDS/IPS or network detection and response)
  • Log collection and retention from CCS (both IT and OT where feasible)
  • Baseline establishment for normal OT communications (protocol, frequency, endpoints)
  • Anomaly detection for deviations from OT baseline
  • Alerting and escalation procedures for detected anomalies
  • Monitoring of remote access sessions to CCS
  • Integration or escalation path to Security Operations Centre (SOC)

OT-specific monitoring considerations:

  • Passive monitoring preferred for OT (active scanning can disrupt industrial protocols)
  • OT-aware tools: Claroty, Dragos, Nozomi Networks, Armis, Microsoft Defender for IoT
  • Focus on detecting: lateral movement, unusual protocol use, unauthorised devices, credential abuse
Domain 4: Patch Management

Apply security patches and updates to operating systems, applications, drivers, and firmware on CCS in a timely manner using a risk-based methodology.

Implementation requirements:

  • Formal patch management policy with defined patch SLAs
  • Risk-based prioritisation: critical/high vulnerabilities patched faster than medium/low
  • OT-specific process: vendor approval, testing in non-production environment before deployment
  • Compensating controls for unpatchable legacy OT systems (network isolation, monitoring)
  • Regular vulnerability scanning of CCS (both IT and OT-accessible)
  • Exception process for patches requiring extended downtime (operational windows)

OT patching realities:

  • Vendor approval required for many OT patches (to avoid voiding warranties/support)
  • Patching windows may be limited to planned maintenance outages (quarterly, annual)
  • Legacy PLC/RTU firmware may be unpatchable — compensating controls required

Core Workflows

1. Applicability Determination

When asked whether an entity is covered by TSA directives:

  1. Ask: What sector? (pipeline, freight rail, passenger rail/transit, bus, aviation)
  2. Ask: Has TSA specifically notified/designated this entity as covered?
  3. Explain: TSA designates covered entities individually; not all operators in a sector are automatically covered
  4. Provide: Overview of coverage criteria and how to engage TSA for designation questions
  5. Note: The 2024 NPRM proposes broader coverage — if finalised, more entities will be subject to mandatory requirements
2. Gap Assessment

When asked to assess compliance:

  1. Ask: Which directive series applies? What sector? What revision is current for them?
  2. Produce a table covering all four technical domains + CIP/COIP, IRP, ADR, CAP requirements
  3. For each: Status (Compliant / Partial / Non-Compliant / N/A), Gap Description, Evidence Required
  4. Highlight highest-risk gaps (no incident reporting process, no IT/OT segmentation, no Cybersecurity Coordinator)
  5. Offer prioritised remediation roadmap
3. CIP / COIP Drafting

When asked to draft or review a CIP or COIP:

  1. Ask: Which directive applies? Entity type and size? Existing architecture and tools?
  2. Build the document following the required sections (see CRMP Component 1 above)
  3. Ensure language is outcome-focused and maps to TSA review criteria
  4. Flag sections requiring site-specific technical detail that cannot be generic
  5. Note: CIP/COIP must be submitted to TSA for approval before use as compliance evidence
4. Incident Response Procedure

When asked about incident response requirements:

  1. Provide the 24-hour CISA reporting requirement and contact information
  2. Describe required IRP elements and annual testing obligations
  3. Draft or review the IRP structure
  4. Provide a step-by-step incident response playbook template aligned to TSA requirements
5. Policy Generation

When generating TSA-aligned policies:

  • Always include: Purpose, Scope, Policy Statement, Roles & Responsibilities, Procedures, Review Cycle, TSA Directive references
  • Map each policy to the specific TSA directive section it satisfies

Common TSA-aligned policies:

PolicyPrimary Directive Requirement
Network Segmentation PolicyDomain 1 (all substantive directives)
Access Control PolicyDomain 2 (all substantive directives)
Privileged Access Management PolicyDomain 2
Remote Access Policy (OT)Domain 2
Continuous Monitoring PolicyDomain 3
Patch Management Policy (IT/OT)Domain 4
Cybersecurity Incident Response PlanIRP requirement (all directives)
Vendor / Third-Party Access PolicyDomain 2; CRMP
Critical Cyber System Inventory PolicyCCS definition requirement
Change Management Policy (OT)Domain 4; ADR

2024 NPRM — What's Coming

In November 2024, TSA published a Notice of Proposed Rulemaking (NPRM) that would transition current Security Directive requirements into permanent federal regulations. Key aspects:

AspectNPRM Proposal
Legal basisFormalises directives as regulation under 49 CFR
Sectors coveredPipelines, freight railroad, passenger rail/transit (higher-risk); bus operators (incident reporting only)
Core requirementsAnnual enterprise-wide cybersecurity evaluation; COIP; CAP
Framework alignmentExplicitly references NIST CSF 2.0 and CISA Cross-Sector CPGs
Annual evaluationCompare entity's current profile vs target profile using NIST CSF
Comment periodClosed February 5, 2025
Final rule timelineNot yet published; directives remain in force until rule is finalised

CISA Cross-Sector CPGs: TSA's NPRM aligns with CISA's Cybersecurity Performance Goals — a prioritised baseline of cybersecurity practices for critical infrastructure. CPGs map closely to NIST CSF subcategories and are grouped into IT/OT-specific goals.


Status Note — October 2026

Directives SD Pipeline-2021-01G and the 1580/1582 rail series remain operative; the November 2024 surface cyber risk management NPRM is still unfinalized. September 2026 activity was procedural only: a revised information-collection request (OMB 1652-0074) covering coordinator designation, 72-hour CISA reporting, IR plans and assessments, with sharply reduced burden estimates.

Reference Files

Load the appropriate reference file based on the task:

  • references/tsa-directives-overview.md — All active directive series with revision history, covered sectors, and requirements summary
  • references/tsa-crmp-requirements.md — Detailed CRMP component requirements: CIP/COIP, IRP, ADR, CAP, and the four technical domains with implementation guidance
  • references/tsa-incident-reporting.md — Incident reporting procedures, CISA contact details, timelines, what qualifies as a reportable incident, and post-incident obligations

When to load reference files:

  • Gap assessment or compliance review → load tsa-directives-overview.md + tsa-crmp-requirements.md
  • Incident has occurred or user asks about reporting → load tsa-incident-reporting.md
  • Architecture review or CIP/COIP drafting → load tsa-crmp-requirements.md
  • User asks about which directive applies → load tsa-directives-overview.md
  • NPRM or upcoming regulation questions → load tsa-directives-overview.md

Disclaimer

Outputs from this skill provide informational guidance based on publicly available TSA Security Directive summaries, Federal Register notices, and DHS/CISA publications. TSA Security Directives are Sensitive Security Information (SSI) — the full text of some directives is not publicly available. This skill does not constitute legal, regulatory, or professional compliance advice. Entities subject to TSA Security Directives should work directly with TSA, their legal counsel, and qualified OT/ICS cybersecurity professionals to ensure compliance with the specific directives applicable to their operations. Always verify against the current revision of the applicable directive from TSA.


This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/tsa-compliance/skills/tsa-compliance of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/tsa-crmp-requirements.md
  • references/tsa-directives-overview.md
  • references/tsa-incident-reporting.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Tsa Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tsa Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tsa Compliance this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~5.6kAutomated safety check: PassMIT
Gdpr Remediation Roadmapmukul975/Privacy-Data-Protection-Skills301—~452Automated safety check: PassApache-2.0
Designsynnaxlabs/synnax128—~4.5kAutomated safety check: PassCustom licence
Executing Plans Inlineobra/superpowers297k2 repos~5.1kAutomated safety check: PassMIT
Interview Meaddyosmani/agent-skills105k6 repos~3.8kAutomated safety check: PassMIT
OpenSpec Guided OnboardingFission-AI/OpenSpec72k1 repos~4.5kAutomated safety check: PassMIT

Similar skills

  • Gdpr Remediation Roadmap

    mukul975/Privacy-Data-Protection-Skills

    Guides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation.

    301 GitHub stars~452 tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Design

    synnaxlabs/synnax

    Process and hard rules for designing and planning complex new features, refactors, and re-architectures.

    128 GitHub stars~4.5k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    297k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Interview Me

    addyosmani/agent-skills

    Asks one question at a time, each with a best guess attached, until the agent is about 95 percent sure what you really want, before any plan, spec or code.

    105k GitHub starsUsed in 6 repos~3.8k tokens
    Agent WorkflowsAuto-check passed
  • OpenSpec Guided Onboarding

    Fission-AI/OpenSpec

    Walks you through a complete OpenSpec workflow cycle with narration while doing real work in your codebase.

    72k GitHub starsUsed in 1 repo~4.5k tokens
    Agent WorkflowsAuto-check passed
  • Writing Plans

    geeksblabla/stateofdev.ma

    A skill your agent uses when design is complete and you need detailed implementation tasks for engineers with zero codebase context - creates comprehensive implementation plans with exact file…

    163 GitHub starsUsed in 58 repos~661 tokens
    Agent WorkflowsAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Tsa Compliance

What does Tsa Compliance do?

Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Tsa Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators.

When should I use Tsa Compliance?

Tsa Compliance fits situations like: A user asks about TSA Security Directives for pipelines; freight railroads; the TSA Cyber Risk Management Program (CRMP); cybersecurity Implementation Plan (CIP).

How do I install Tsa Compliance in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a claude-code`. Or copy the skill folder (plugins/tsa-compliance/skills/tsa-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/tsa-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Tsa Compliance in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a codex`. Or copy the skill folder (plugins/tsa-compliance/skills/tsa-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/tsa-compliance in your project. Codex loads it when a task matches its description.

Can I use Tsa Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tsa-compliance, .gemini/skills/tsa-compliance, .github/skills/tsa-compliance and .opencode/skills/tsa-compliance in your project.

What does Tsa Compliance need to run?

SKILL.md names no scripts, command-line tools or credentials: Tsa Compliance is instructions for the agent only.

Does Tsa Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Tsa Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tsa Compliance use?

Tsa Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tsa Compliance use?

About 5.6k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9k tokens, read only when the agent opens those files.

What are the alternatives to Tsa Compliance?

Skills that share tags, products or a category with Tsa Compliance: Gdpr Remediation Roadmap (mukul975/Privacy-Data-Protection-Skills, 301 stars), Design (synnaxlabs/synnax, 128 stars), Executing Plans Inline (obra/superpowers, 297k stars) and Interview Me (addyosmani/agent-skills, 105k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tsa Compliance?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.