IT Asset Visibility for TSA Pipeline Security Compliance Houston Isn’t Optional
In 2025, the threat group Dragos tracks as VOLTZITE compromised cellular gateways across U.S. midstream operations. According to the Dragos 2026 oil and gas cybersecurity review, those devices sat at unmonitored OT edges where IT teams frequently had no visibility into their existence. Attackers then pivoted to engineering workstations and pulled configuration and alarm data that tells operators what would stop a process. The failure mode was an inventory gap as much as a firewall gap. Without a configuration management record, teams lacked a baseline, a monitoring scope, and a clear detection boundary. Colonial Pipeline remains the public reason TSA pipeline cybersecurity directives exist. The quieter daily problem for Houston operators is the same inventory gap at smaller scale. Building durable IT asset visibility for TSA pipeline security compliance in Houston means treating discovery-sourced inventory as operational infrastructure, not a pre-audit spreadsheet exercise.
What is the TSA Pipeline Security Directive?
The active security directive series
Covered pipeline operators currently work under two active Transportation Security Administration security directive series. SD Pipeline-2021-01G (effective January 16, 2026) requires operators to designate a Cybersecurity Coordinator who is a U.S. citizen, available around the clock, and the principal point of contact with TSA and CISA. It also requires cybersecurity incident reporting to CISA within twelve hours of identification and a Cybersecurity Vulnerability Assessment using the TSA form. SD Pipeline-2021-02G (effective May 3, 2026 through May 2, 2027) requires mitigation actions such as segmentation, access controls, and monitoring, plus contingency planning for backup data integrity and incident response, testing, and annual assessment. This article focuses on the IT-side inventory work underneath those mandates; implementing segmentation, access control, and monitoring on the OT network itself typically runs through OT-native security tooling built for SCADA and PLC environments, not general IT discovery.
Section 7’s asset inventory obligations
TSA Pipeline Security Guidelines Section 7 still anchors the asset work underneath those directives. Operators need a complete inventory of every connected device, computer, and workstation in the critical system environment. They must classify critical versus non-critical cyber assets, because that tier drives baseline versus enhanced security measures. They also need mapping of asset relationships and dependencies so mitigation and contingency plans match how systems actually connect.
A configuration management database is the system of record for that inventory when discovery keeps it current. The table below shows how classification and provisioning failures become compliance gaps.
| Situation | What Happens | Compliance Gap |
|---|---|---|
| Asset classified as non-critical in 2022, never re-inventoried | Asset reconfigured in 2024 and now meets critical criteria under Section 7, but the old tier remains on file | Annual Cybersecurity Assessment Plan carries the wrong criticality tier; TSA review flags the inconsistency |
| Engineering workstation added to a pilot OT project outside standard provisioning | Workstation never appears in the CMDB and sits outside the baseline inventory | Annual assessment cannot account for it; scanners flag it as unowned |
| Manual spreadsheet inventory reconciled only in the weeks before audit | Dozens of assets appear in network scans but not in ownership or impact documentation | CISA incident-scoping questions cannot be answered on a twelve-hour clock; forensic scope stays undefined |
What does the TSA Pipeline Security Directive require for asset inventory?
Covered operators must maintain a complete inventory of connected devices in the critical system environment, classify critical versus non-critical cyber assets, and map relationships that support mitigation and contingency planning under the active SD Pipeline directive series.
Why is IT asset visibility important for TSA compliance?
The inventory gap is widening
TSA’s directive line requires that every covered pipeline operator maintain a complete, accurate inventory of critical cyber assets. Across the industry, that inventory gap is widening faster than many teams can close it with annual spreadsheets.
The Zscaler ThreatLabz 2025 ransomware report found oil and gas ransomware attacks rose 935 percent year over year from April 2024 to April 2025. The report ties the surge to growing reliance on automation across rigs, pipelines, and infrastructure that inflates the attack surface. Dragos’s reporting on oil and gas shows three recurring gaps across findings:
- Malware detection gaps: 37 percent of findings
- IT/OT segmentation failures: 29 percent of findings
- Default credentials still in use: 26 percent of findings
CISA’s August 2025 joint OT asset inventory guidance, published with NSA, FBI, and international partners, names OT asset inventory a foundational requirement for vulnerability management in critical infrastructure. Deloitte’s energy and utilities cybersecurity brief ties IT/OT convergence directly to legacy complexity for operators who still treat inventory as a paperwork exercise.
Three failure modes in midstream assessment cycles
Three failure modes show up repeatedly in midstream assessment cycles:
- Asset classified once, never re-verified. A cyber asset is designated non-critical in an early Cybersecurity Vulnerability Assessment. The system stays in that tier through later cycles even after its operational role changes. Baseline measures apply where enhanced measures belong. Result: Security posture undersized relative to actual criticality; compliance finding during third-party assessment; remediation required before the next annual submission.
- Engineering workstation provisioned outside the standard pipeline. A pilot spins up an OT engineering workstation without IT asset provisioning. The workstation never appears in the CMDB, never receives an owner, and never enters network baseline or vulnerability scanning scope. Result: Asset stays invisible to the TSA inventory requirement and to incident-response scope; if compromised, the operator lacks a forensic timeline and impact boundary.
- Manual spreadsheet inventory reconciled only at audit time. The asset list lives on a shared drive and updates sporadically. The annual Cybersecurity Assessment Plan draws from that file. Network scans during assessment reveal dozens of assets missing from the sheet. Result: Assessment delayed pending reconciliation; findings issued; remediation compresses into the audit response window instead of running on a managed schedule.
Cybersecurity Asset Management (CSAM) programs that assign criticality and ownership in a living inventory give SecOps and configuration teams a shared place to keep those classifications current between directive cycles.
Why is IT asset visibility important for TSA compliance?
Accurate, current inventory supports criticality tiers, vulnerability prioritization, twelve-hour incident scoping, and assessable evidence. Without it, operators submit stale plans while ransomware pressure and IT/OT gaps keep expanding the surface that directives expect them to document.


The real cost of getting asset visibility wrong
For CIOs and compliance leaders
TSA Corporate Security Reviews and third-party assessments surface inventory gaps in plain language. A typical finding reads like this: asset classification tier cannot be verified for a material share of critical systems because documentation is missing or stale. The board question that follows is direct: are we compliant with the mandatory directive? Delay costs include a revised compliance statement, open findings, and reputational exposure with the regulator. Congressional Research Service report R49009 on cybersecurity regulatory harmonization tracks the still-open path from the November 2024 TSA NPRM (comments closed February 5, 2025) toward a possible final rule. As of mid-2026, the final rule has not been issued. Directives remain the binding instrument through the current 02G window, and any future rule is likely to raise documentation expectations rather than lower them.
For CMDB owners and ITAM teams
Based on reconciliation cycles typical of mid-to-large pipeline operations, CMDB owners often spend four to six hours each week reconciling spreadsheets against network scans. Annual assessment prep commonly burns eighty to one hundred twenty hours on manual CMDB cleanup, ownership verification, and relationship mapping. At an illustrative eighty-five dollars fully loaded per hour, that works out to roughly $6,800 to $10,200 per year in reconciliation labor alone: a working estimate, not a benchmarked industry figure.
That work documents what the environment already runs. It does not by itself improve controls. Spreadsheets also miss configuration drift after the last update. Scanners find IP addresses, so someone still has to attach owner, team, and remediation SLA before the record is useful under a twelve-hour CISA clock.
For Houston’s energy market
Rice Kinder Institute reporting on the Greater Houston energy economy describes more than 4,700 energy-related firms in the region. Nineteen of twenty-seven local Fortune 500 headquarters are energy-related, with deep concentration among publicly traded exploration and production firms. Midstream transport operators cluster along Houston and the Gulf Coast. When TSA has notified an operator that a pipeline is critical, the directives are mandatory. Many Houston midstream players are already on their second or third full Cybersecurity Assessment Plan cycle. Teams that keep inventory on a scheduled discovery cadence enter those windows with exportable evidence. Teams still living in shared drives spend autumn in reconciliation scrambles.
Establishing trusted runtime truth across complex energy networks gives CIOs and configuration owners a shared operational baseline before the next assessment letter lands.
How discovery-driven asset visibility fixes this
Three mechanisms that close the inventory gap
Remediating TSA inventory gaps requires moving from point-in-time documentation to discovery-driven infrastructure management. Three mechanisms map to verified platform capabilities.
- High-frequency scheduled discovery across hybrid environments. Agent-based and agentless discovery covers on-premises servers, network devices, cloud instances on AWS and Azure, and virtual machines on configurable schedules rather than one-time snapshots. Complete inventory under TSA is not static. New assets enter monthly. High-frequency cycles catch them within days of provisioning before they become invisible outliers. Discovery updates CMDB records as configurations change and tags environment type, exposure status, and discovered date. Annual assessment then starts from a current baseline. IT discovery on a high-frequency schedule is what keeps that baseline honest between assessment windows.
- Ownership and criticality workflows fill fields scanners cannot see. Technical fingerprints do not answer whether an asset controls a critical process, who owns remediation, or which SLA applies. Questionnaires and structured owner outreach populate ownership, business criticality, lifecycle status, and remediation team on the CI. Classification for baseline versus enhanced measures depends on that business context. When owners respond, CI records update, and ownership history remains available for assessment evidence.
- ViVID™ service maps for dependency analysis. After teams provide service definitions (manually, by spreadsheet, or via architecture tools), ViVID™ builds application-to-infrastructure dependency maps. SD-02 series work on architecture reviews for OT network segmentation and contingency planning depends on knowing what sits downstream of each asset. Service mapping gives change and architecture teams current relationship context for impact scope when a vulnerability hits a critical host.
From manual reconciliation to discovery-driven workflows
| TSA Task | Manual Approach | Discovery-Driven Approach |
|---|---|---|
| Annual inventory submission | Reconcile spreadsheet against last year, resolve discrepancies, export evidence | Export current CMDB snapshot; audit trail shows last-verified date per asset |
| Cybersecurity Vulnerability Assessment | Compile scanner outputs; match IPs to names by hand | CMDB carries asset context; findings link to owners, criticality, and tier |
| Architecture review (segmentation) | Hand-drawn diagrams; IT and OT meet in separate calls | Service maps show IT/OT boundary systems and dependencies from current discovery |
| Change management | Approvers verify impact from memory | Maps show dependents before the window; rollback scope is pre-validated |
| Incident response scoping | Rebuild owner and dependency under pressure | CMDB holds ownership, criticality, and dependency context within minutes |
Scope boundary (product-accurate): Discovery here covers on-premises infrastructure, cloud accounts, network devices, remote-access infrastructure, and IT systems touching the OT boundary. It does not replace floor-level OT device discovery for SCADA, PLC, or RTU fleets. That work belongs to OT-native tools with protocol-specific telemetry. Virima supplies the IT-side and IT/OT-boundary system of record those programs still need for ownership, change, and assessment evidence.
What is the difference between OT asset discovery and IT asset visibility for pipeline compliance?
OT-native tools inventory and monitor industrial controllers and protocols. IT asset visibility covers servers, workstations, network and remote-access gear, and cloud instances at the IT and IT/OT edge. TSA documentation needs both layers joined through ownership and dependency records.
TSA compliance in practice: illustrative scenarios
These scenarios trace the operational consequences of the three failure modes above — what actually happens downstream when classification drifts, provisioning skips inventory, or reconciliation waits for audit season. They reflect common midstream operating rhythms, not named customer case studies.
The annual renewal crunch
A CMDB owner at a mid-sized midstream operator gets a sixty-day alert before the Cybersecurity Vulnerability Assessment Plan is due. The spreadsheet was last updated eight months earlier. The organization has provisioned more than forty new VMs and decommissioned legacy servers after a named architecture lead approved retirement. It has also reassigned ownership of three critical systems and added a pilot OT historian server. Manual reconciliation can consume ninety-plus hours. Several assets lack owners. Two systems appear in scans but not on the sheet and trigger findings. With high-frequency scheduled discovery and earlier ownership outreach, assessment prep becomes export, spot-check recent changes, and submit. Labor drops on the order of seventy hours in programs that follow this pattern, with fewer last-minute unknowns.
The change window impact problem
Operations plans to patch a Windows Server hosting a SCADA historian service and opens an ITSM change. The manual path is email threads, partial dependency docs, and approval without full impact. Downstream monitoring goes dark; tickets arrive; the window stretches. With ViVID™ maps built from defined services, the change advisory board sees historian-to-HMI links and dependent operator workstations before approval. Maintenance lands in a notified window with fewer surprises.
The VOLTZITE pattern inside the fence
A remote access gateway is added for a temporary pilot connecting corporate IT to the OT network for remote maintenance. Months later, the pilot is permanent, but the device never entered standard inventory. It sits outside the CMDB, outside vulnerability scope, and outside baseline. Agentless network discovery detects the gateway, flags it as newly discovered, routes ownership to the network team, and brings the asset into classification and the next assessment cycle within days rather than quarters.
These patterns sit inside a broader inventory and security story. For the enterprise case on how CMDB-backed visibility supports cyber operations beyond a single directive cycle, see cybersecurity and IT asset visibility via CMDB.


How Virima supports TSA compliance documentation
Virima does not act as a GRC policy engine and does not certify TSA compliance. It supplies discovery-sourced inventory, configuration history, and dependency context that operators use inside their own assessment and ITSM workflows.
Immediate operational impact
When the Cybersecurity Vulnerability Assessment Plan is due, teams query the CMDB for inventory filtered by criticality tier, with ownership, last-verified date, and business context attached. Audit history shows when each asset was discovered, when ownership was assigned, and when configuration last changed. Reviewers can trace claims to discovery evidence instead of reconstructed spreadsheets.
Long-term classification integrity
High-frequency scheduled discovery limits the eleven-month decay curve after annual submission. New assets appear within days of provisioning. Ownership and criticality attributes stay on the CI. When a vulnerability is announced, operators filter by criticality and exposure to set remediation priority. Federal BOD clocks and sector directives differ in legal scope. The shared operational need is the same: you cannot tier response without a current asset list.
Integration with existing workflows
Through the integrations hub, Virima exchanges verified runtime data with platforms many pipeline operators already run, including ServiceNow and Jira Service Management. Discovered assets can enrich incident, change, and configuration records so compliance context travels in the same consoles teams use daily. Related reading on The role of CMDB compliance in IT security and risk management and Reporting & Auditing deepens the evidence pattern without treating the CMDB as the regulator.
Moving from spreadsheet compliance to a living asset record
| Phase | Before (Manual) | After (Discovery-Driven) |
|---|---|---|
| Inventory currency | Point-in-time update, often annual or pre-audit; ages quickly | High-frequency scheduled discovery plus ownership workflows; exportable for assessment |
| Compliance workflow | Audit-time scramble to reconcile sheets and export evidence | Ongoing governance; annual submission is export plus focused review |
Faster remediation. When a CVE lands, teams already know whether vulnerable software is installed, what criticality tier it carries, what exposure it has, and which dependents need coordinated patching.
Reduced audit friction. Requests for critical inventory and tier justification become filtered exports with business justification and ownership, not week-long reconstructions.
Getting started
- Deploy discovery across on-premises infrastructure and AWS/Azure accounts on an initial schedule (weekly for core systems, longer intervals for stable segments).
- Baseline the CMDB by reconciling first-pass discovery with existing IT asset records under clear authority rules.
- Populate ownership and criticality through structured owner outreach so each CI carries remediation context.
- Map dependencies with ViVID™ after service definitions are provided; feed maps into change and architecture review.
- Set review cadence ahead of the next Cybersecurity Assessment Plan: monthly completeness and freshness checks, quarterly ownership updates, pre-submission verification.
Maturity is typically a multi-quarter journey, not an overnight switch. Good inventory reduces assessment friction. It does not erase every control gap on its own. When operators already run ServiceNow or Jira Service Management, keep partner data exchange on the integrations hub rather than one-off spreadsheets between tools.
Build assessment-ready inventory for Houston pipeline operations
Houston midstream operators run under active TSA security directives while ransomware pressure and IT/OT complexity keep raising the cost of stale inventory. Spreadsheet compliance creates the appearance of control until scan deltas, twelve-hour incident questions, or third-party findings expose the gap. Operators who anchor IT asset visibility for TSA pipeline security compliance in Houston in discovery-sourced CMDB records walk into assessment windows with ownership, criticality, and dependency context already attached.
Asset visibility is the foundation. Audit readiness is the outcome.
Get the TSA Pipeline Asset Visibility Checklist — a five-step framework for turning discovery data into assessment-ready evidence before your next Cybersecurity Vulnerability Assessment Plan is due. Asset Request and Form Management for Better Control and Visibility
Already evaluating discovery platforms against your authorization and assessment boundaries? Request a demo.
Frequently Asked Questions
What does the TSA Pipeline Security Directive require for asset inventory?
Covered operators must inventory connected devices in the critical system environment, classify critical versus non-critical cyber assets, and support relationship mapping used in mitigation, contingency planning, and the annual Cybersecurity Vulnerability Assessment under the active SD Pipeline series.
Why is IT asset visibility important for TSA compliance?
Current inventory underpins criticality tiers, vulnerability priority, incident scoping on CISA timelines, and assessable evidence. Oil and gas ransomware volume rose sharply while detection and segmentation gaps remain elevated, so stale lists raise both operational and compliance risk.
What is the difference between OT asset discovery and IT asset visibility for pipeline compliance?
OT-native platforms cover industrial controllers and protocols. IT asset visibility covers servers, workstations, network and remote access infrastructure, and cloud instances at the IT and IT/OT boundary. Assessment-ready programs need both, joined through ownership and dependency records.
How does Virima’s CMDB support TSA Security Directive compliance documentation?
Virima’s discovery-fed CMDB holds inventory, ownership, criticality, configuration history, and dependency context used as evidence for Cybersecurity Vulnerability Assessment plans. It enables assessment workflows. It does not replace the operator’s compliance program or TSA determination.
Is the TSA pipeline cybersecurity directive becoming a permanent regulation?
The TSA NPRM was filed in November 2024; comments closed in February 2025. As of mid-2026, no final rule has been issued. SD Pipeline-2021-02G runs through May 2, 2027. CRS R49009 tracks rulemaking status for operators.






