Cylus presents rail-specific asset discovery, threat detection, investigation context, and mitigation playbooks across rolling stock, trackside, stations, communications, and control centers. A rail operator still has to join an alert to the affected topology, service state, safety constraints, accountable owner, and authorized response.
Phosphorus describes automated xIoT remediation for credentials, firmware, certificates, risky configurations, and unnecessary services. In an operating environment, safe automation still needs asset identity, engineering scope, approved preconditions, production timing, rollback, and observed process-state evidence.
Palo Alto Networks describes passive OT asset discovery, profiling, risk context, and policy controls. A device profile can inform review, but permitted communications still require validated identity, process context, zone and conduit intent, engineering constraints, approved rules, controlled change, and post-change evidence.
The published TSA directive states an effective period ending May 2, 2026. Its controls remain useful historical evidence, but current applicability requires a current TSA instrument and operator-specific authority—not a stale vendor mapping.
NIST Cybersecurity Framework 2.0 provides a taxonomy of cybersecurity outcomes across six functions, including the added Govern function. The framework can structure an OT program and its evidence, but it does not prescribe a safe control design, determine site-specific risk, or prove that an industrial system is secure or compliant.
The IAEA guidance covers computer security for nuclear-facility instrumentation and control across design, operation, maintenance, supporting environments, and decommissioning. That scope is broader than a point-in-time device inventory.