Federal Audit Finds Gaps In Aviation Cybersecurity Oversight

A federal audit found gaps in aviation cybersecurity oversight, including unclear responsibilities between the FAA and TSA.

Shutterstock [Gorodenkoff]
Gemini Sparkle

Key Takeaways:

  • A federal audit by the Government Accountability Office (GAO) revealed significant gaps in U.S. government oversight of aviation cybersecurity, citing unclear responsibilities at the Transportation Security Administration (TSA) and incomplete strategy implementation by the Federal Aviation Administration (FAA).
  • The FAA has only partially implemented its cybersecurity strategy (four of seven objectives) and failed to fully report all cybersecurity activities and costs, hindering complete understanding and future funding decisions by federal officials.
  • The audit concluded with five recommendations for the FAA and TSA, including a call for the TSA to update its cybersecurity roadmap and more clearly define its roles and responsibilities.
See a mistake? Contact us.

A federal audit has found gaps in how the U.S. government oversees aviation cybersecurity, including unclear responsibilities at the Transportation Security Administration (TSA) and incomplete implementation of the Federal Aviation Administration’s (FAA) cybersecurity strategy.

The Government Accountability Office (GAO) released its report July 16 after reviewing the FAA and TSA’s roles in protecting aviation systems. The review found that the agencies face challenges implementing cybersecurity strategies and clearly defining who is responsible for protecting critical aviation infrastructure.

The FAA has not fully implemented its cybersecurity strategy, according to the audit. Of seven objectives supporting the agency’s cybersecurity goals, three were fully implemented and four were only partially implemented.

The audit also found that the FAA did not report all of its cybersecurity activities and costs to the Office of Management and Budget during fiscal years 2024 through 2026. The agency’s budget submissions, for example, did not include spending on cybersecurity activities supporting research and development.

GAO said incomplete reporting could make it more difficult for Congress and federal officials to get a complete picture of the FAA’s cybersecurity spending and make future funding decisions.

The audit did identify some areas where the FAA is following established practices. GAO found that the agency’s aircraft certification and system security authorization processes generally align with federal and industry practices for addressing cybersecurity risks involving avionics and ground systems.

The GAO issued five recommendations to the FAA and TSA, including a call for TSA to update its cybersecurity roadmap and more clearly define its roles and responsibilities.

Amelia Walsh

Amelia Walsh is a private pilot who enjoys flying her family’s Columbia 350. She is based in Colorado and loves all things outdoors including skiing, hiking, and camping.
Sign-up for newsletters & special offers!

Get the latest stories & special offers delivered directly to your inbox

SUBSCRIBE

Please support AVweb.

It looks like you’re using an ad blocker. Ads keep AVweb free and fund our reporting.
Please whitelist AVweb or continue with ads enabled.