Showing posts with label Aircraft Cybersecurity. Show all posts
Showing posts with label Aircraft Cybersecurity. Show all posts

Monday, June 1, 2026

Aircraft Cybersecurity Special Conditions

Today, the DOT’s Federal Aviation Administration (FAA) published a final special conditions notice in the Federal Register (91 FR 32325-32326) for “Honeywell International Inc., Boeing Model 757-200 Series Airplanes; Electronic System Security Protection from Unauthorized External Access”.  

The aircraft’s revised electronic system architecture and network configuration may may allow increased connectivity to and access from external network sources, and the FAA’s current certification standards do not adequately address that increased connectivity. These special conditions contain the additional safety standards that the Administrator considers necessary to establish a level of safety equivalent to those established by the existing airworthiness standards. 

I have previously discussed the FAA’s approach on these cybersecurity special conditions. In August of 2024, as part of a move on the part of the agency to obviate the need for these special conditions, the FAA published a notice of proposed rulemaking on “Equipment, Systems, and Network Information Security Protection”. The FAA has not yet submitted a final rule to OMB for approval. 

Today’s announced special conditions are not as extensive and inclusive as those proposed in the NPRM. Part of the reason for that is that the FAA typically provides detailed guidance on airworthiness criteria in a means of compliance (MOC) document that provides technical details to both the vendor and FAA inspectors on what the agency expects to see to meet the requirements (see my previous discussion here). 

Thursday, August 22, 2024

Review - FAA Publishes Transport Aircraft Cybersecurity NPRM

Yesterday, the DOT’s Federal Aviation Administration (FAA) published a notice of proposed rulemaking in the Federal Register (89 FR 67564-67572) on “Equipment, Systems, and Network Information Security Protection”. The proposed regulations would replace the current ad hoc cybersecurity requirements that the agency has been implementing on an as needed basis. The preamble notes:

“These changes would introduce type certification and continued airworthiness requirements to protect the equipment, systems, and networks of transport category airplanes, engines, and propellers against intentional unauthorized electronic interactions (IUEI) that could create safety hazards.”

Public Comments

The FAA is soliciting public comments on this proposed rulemaking. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # FAA-2024-1398). Comments should be submitted by October 21st, 2024.

Commentary

One complaint that has come up in the past (see my post on the Hummingbird UA airworthiness final rule, removed from paywall) has been the lack of specificity on the standards. The FAA continues in this rulemaking to provide very generic, vaguely worded cybersecurity standards. In the earlier Hummingbird rule, the FAA responded that:

“The level of detail regarding the assessment of failures and the required protection level of equipment, systems, and networks will be addressed in the means of compliance (MOC) to these airworthiness criteria.”

I am sure that the FAA would have a similar response to complaints about the broad, generic standards proposed in this NPRM.

 

For more details about the provisions of this rulemaking, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/faa-publishes-transport-aircraft - subscription required.

Saturday, September 3, 2022

Review - FAA Cybersecurity Special Provisions – Internal vs External Electronic Access

The DOT’s Federal Aviation Administration (FAA) has published two Special Conditions notices in Tuesday’s (available on line today) Federal Register ((87 FR 54349-54351 and 87 FR 54351-54353), both for Bombardier Model BD-700-1A10 and BD-700-1A11 Airplanes as modified by L2 Consulting Services. The two notices deal with electronic systems added to the Bombardier aircraft that are not adequately dealt with by current airworthiness regulations. Accordingly, these “special conditions contain the additional safety standards that the Administrator considers necessary to establish a level of safety equivalent to that established by the existing airworthiness standards.”

Each notice applies to the same base aircraft: “The Bombardier Model BD-700-1A10 and BD-700-1A11 airplanes are twin-engine, transport category airplanes, executive-interior business jets with a maximum takeoff weight of 93,500 pounds (42,410 Kg) and a maximum seating capacity of seventeen passengers and two crew members.”

Commentary

While these two sets of special condition requirements are worded differently than three other instances of aircraft cybersecurity special conditions that I have covered previously in my blog Chemical Facility Security New (here, here and here), the FAA continues to write broadly worded, performance-oriented cybersecurity standards for these aircraft. What is not publicly provided here is the guidance provided to FAA inspectors for processes by which those inspectors will evaluate how well the aircraft implement these special conditions in the type approval process.


For more details about the requirements of these special conditions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/faa-cybersecurity-special-conditions - subscription required.

Friday, August 9, 2019

S 2181 Introduced – Aircraft Cybersecurity


Last month Sen. Markey (D,MA) introduced S 2181, the Cybersecurity Standards for Aircraft to Improve Resilience (Cyber AIR) Act of 2019. This bill is very similar to S 2764 that Markey introduced in the second half of the 114th Congress.

Differences


The major difference between the two bills is that the reporting congressional reporting requirements found in §5 of the earlier bill have been removed from the current version. That would have required annual reports to Congress on the attacks reported to the FAA by air carriers and manufacturers under provisions of §3.

Two other changes are found in §5 of the current bill. The formatting is changed from §6 of S 2764 and the last subparagraph {§6(c)(2)} from the earlier bill has been deleted in S 2181. That subparagraph would have required that the report to Congress from the FAA-FCC Leadership Group would have been required to be “submitted in unclassified form, but may include a classified annex”.

Moving Forward


Markey is still a member of the Senate Commerce, Science, and Transportation Committee and he has added a cosponsor {Sen. Blumenthal (D,CT)} who is a senior Democrat on that Committee. This increases the likelihood that this bill would see consideration in Committee. In the 114th Congress. I suspect that the bill, if considered, would receive substantial opposition from Republicans, thus killing any chances that the bill would move to the floor of the Senate.

Commentary


There is no reference in this bill to cooperation with the DHS Cybersecurity and Infrastructure Security Agency. CISA was not in existence when the earlier version of the bill was introduced, but I would have expected this version to be updated to substitute CISA for generic references to cooperation or coordination with ‘the Secretary of Homeland Security'. CISA is, of course, supposed to be the Federal government’s expert on all thing’s cybersecurity.

Over the years I have been a strong proponent of actively involving ICS-CERT and now CISA in anything involving Federal oversight of control system security in all of its guises. Mainly, I have asserted that the limited availability of control system security expertise in government (and to a somewhat lesser extent in the private sector) meant that that the localization of that talent in a single agency would probably make a great deal of sense. I am starting to rethink that proponency (hmmm, that may be a new word according to spell check).

First, it appears that DHS in general, and CISA in particular, has ‘deemphasized’ the importance of control system security expertise with the effective elimination of ICS-CERT. This has always been the problem of putting all of your ‘eggspertice’ in one administrative basket; bureaucratic adjustments in the size of that basket have unintended consequences outside of the agency’s mandate.

More importantly, not requiring safety regulatory agencies (like the FAA in this case) to have cybersecurity expertise in general, and control system expertise in particular, fails to recognize the impact of cybersecurity on safety. Safety regulators are going to increasingly become control-system cybersecurity regulators as more and more safety systems rely on interconnected control-system components. Safety regulatory agencies are going to have to be forced by Congress to formalize and grow their cybersecurity capabilities.

With that in mind, I would like to suggest an addition to §3 of the bill:

(c) The Secretary will establish within the FAA an Aviation Cybersecurity Office (ACO) to receive the cyberattack reports described in (a) and develop recommendations for, and implement, regulatory actions described in (b). The Director of the ACO will be familiar with avionics control systems and cybersecurity of such systems. Additionally, the ACO will:

(1) Receive cybersecurity incident reports from covered air carriers and covered manufacturers;
(2) Prepare anonymized reports on such incidents that would identify security vulnerabilities (as defined in 6 USC 1501) that could affect other carriers and manufacturers and coordinate the disclosures of those security vulnerabilities;
(3) Establish procedures and processes by which security researchers can report security vulnerabilities for further coordinated disclosure; and
(4) Coordinate with the National Cybersecurity and Communications Integration Center on sharing security vulnerability information.

Tuesday, September 4, 2018

Committee Hearings – Week of 09-02-18


This week the House and Senate will both be back in Washington with spending bills high on the priority list for the month. There is one cybersecurity hearing of potential interest this week.

Cybersecurity Hearing


On Thursday two subcommittees of the House Homeland Security Committee will be holding a hearing on “Understanding Cybersecurity Threats to America’s Aviation Sector”. There is no witness list available at this time.

While aircraft cybersecurity is a very likely topic, I expect that the main focus will be on cybersecurity for FAA systems, including airspace management systems.

On the Floor


We have two bills that will be considered in the House this week under their suspension of the rules process that may be of interest to readers of this blog. Again, this process calls for limited debate, no floor amendments and a super-majority to pass; generally speaking these are non-controversial bills. The two bills of interest this week are:

• Today - HR 6438 – DHS Countering Unmanned Aircraft Systems Coordinator Act;
Wednesday - HR 5576 – Cyber Deterrence and Response Act of 2018

There are two spending bills from the Senate that may see some action this week. First is the motion to go to conference on HR 6157, Department of Defense Appropriations Act, 2019 and Democrat Motion to Instruct Conferees; this is mainly a proforma vote, though there is a remote (very remote) possibility that the House could accept the Senate amendments. That vote is expected today. Next is the expected conference report on HR 5895 – Energy and Water, Legislative Branch, and Military Construction and Veterans Affairs. This vote will come possibly later this week or next.

Friday, March 31, 2017

S 679 Introduced – Aircraft Cybersecurity

Last week Sen. Markey (D,MA) introduced S 679, the Cybersecurity Standards for Aircraft to Improve Resilience  (Cyber AIR) Act of 2017. This bill is very similar to S 2764 that was introduced in the 114th Congress and saw no action there.

Differences


There is one significant difference between this bill and S 2764; §5 from the earlier bill is not present in this bill. That section outlined the requirements for the DOT’s Federal Aviation Administration to provide annual reports to Congress on “on attempted and successful cyberattacks on any system on board an aircraft” {§5(a) in S 2764}.

Moving Forward



Markey is a member of the Senate Commerce, Science and Transportation Committee to which the bill was assigned for consideration. Thus, there is a possibility that that Committee could consider this bill. I don’t believe, however, that there have been sufficient change in the composition of the Senate to overcome the opposition that was seen when portions of this bill were proposed by Markey last session as amendments to HR 636, the FY 2017 FAA authorization bill and S 2658, the Senate version of the same bill.

Wednesday, March 22, 2017

Bills Introduced – 03-21-17

Yesterday with both the House and Senate in session there were 54 bills introduced. Of these four may be of specific interest to readers of this blog:

HR 1647 To establish a Water Infrastructure Trust Fund, and for other purposes. Rep. Blumenauer, Earl [D-OR-3]

HR 1653 To amend certain provisions of the Safe Drinking Water Act, and for other purposes. Rep. Latta, Robert E. [R-OH-5]

S 679 A bill to require the disclosure of information relating to cyberattacks on aircraft systems and maintenance and ground support systems for aircraft, to identify and address cybersecurity vulnerabilities to the United States commercial aviation system, and for other purposes. Sen. Markey, Edward J. [D-MA]

S 680 A bill to protect consumers from security and privacy threats to their motor vehicles, and for other purposes. Sen. Markey, Edward J. [D-MA]

The two water system bills will only receive further mention in this blog if they specifically address facility security or cybersecurity issues.


These two bills from Markey are almost certainly based upon bills that he introduced in the 114th Congress (S 2764 and S 1806 respectively). Neither bill saw any action in the previous session; perhaps it will be different this time.

Monday, April 11, 2016

S 2764 Introduced – Aircraft Cybersecurity

Last week Sen. Markey (D,MA) introduced S 2764, the Cybersecurity Standards for Aircraft to Improve Resilience (Cyber Air) Act of 2016. The bill replicates the three amendments that Markey proposed to HR 636, the FAA authorization bill currently under consideration in the Senate.

Definitions


With the combination of the three amendments §2 provides a common set of definitions. Terms included in this section are:

• Covered air carrier;
• Covered manufacturer;
• Cyberattack;
• Critical software systems; and
• Entry point.

The two critical terms are ‘cyberattack’ and ‘critical software systems’. Cyberattack is defined as “the unauthorized access to aircraft electronic control or communications systems or maintenance or ground support systems for aircraft, either wirelessly or through a wired connection” {§2(3)}. The term ‘critical software systems’ is defined as “software systems that can affect control over the operation of an aircraft” {§2(4)}.

Incident Reporting


Section 3 of the bill is essentially SA 3468, the first of three cybersecurity amendments that Markey proposed to HR 636. It would require the Administrator to prescribe regulations requiring air carriers and manufacturers to disclose cyberattacks to the FAA. The attacks would have to be reported whether or not they were successful. The attacks would have to be reported “whether or not the system is critical to the safe and secure operation of the aircraft, or any maintenance or ground support system for aircraft, operated by the air carrier or produced by the manufacturer, as the case may be” {§3(a)}.

FAA would use the information disclosed by air carriers and manufacturers to inform future regulatory actions. The FAA would also be required to “notify air carriers, aircraft manufacturers, and other Federal agencies of cybersecurity vulnerabilities in systems on board an aircraft or maintenance or ground support systems for aircraft” {§3(b)}.

Cybersecurity and Operating/Manufacturing Certificates


Section 4 is essentially SA 3469. It would require the Secretary of Transportation to prescribe regulations incorporating cybersecurity standards into the requirements to obtain/maintain air carrier operating certificate or a production certificate under 49 USC Chapter 447. Those regulations would include requirements to {§4(b)(2)}:

• Require all entry points to the electronic systems of each aircraft operating in United States airspace and maintenance or ground support systems for such aircraft to be equipped with reasonable measures to protect against cyberattacks, including the use of isolation measures to separate critical software systems from noncritical software systems;
• Require the periodic evaluation of the measures described in subparagraph (A) for security vulnerabilities using best security practices, including the appropriate application of techniques such as penetration testing; and
• Require the entry point measures to be periodically updated based on the results of the evaluations conducted above.

Consumer Communications Equipment


Section 6 address the role of the DOT-FCC’s Commercial Aviation Communications Safety and Security Leadership Group as did amendment SA 3470. The bill would make them responsible for evaluating the cybersecurity vulnerabilities of broadband wireless communications equipment designed for consumer use on board aircraft operated by covered air carriers. They would be required to {§6(b)}:

• Ensure the development of effective methods for preventing foreseeable cyberattacks that exploit broadband wireless communications equipment designed for consumer use on board such aircraft; and
• Require the implementation by covered air carriers, covered manufacturers, and communications service providers of all technical and operational security measures that are deemed necessary and sufficient by the Leadership Group to prevent cyberattacks described above.

Reports to Congress

Section 5 of the bill can be found in the language of the first Markey amendment to HR 636. It requires an annual report to Congress on the attacks reported under provisions of §3.

Section 6(b) would require annual reports by the Leadership Group to Congress. Those reports would include {6(b)(1)}:

• The technical and operational security measures developed to prevent foreseeable cyberattacks that exploit broadband wireless communications equipment designed for consumer use on board aircraft operated by covered air carriers; and
• The steps taken by covered air carriers, covered manufacturers, and communications service providers to implement the measures described above.

Moving Forward


Markey is a rather junior Democrat on the Senate Commerce, Science and Transportation Committee. Normally this might provide him sufficient influence to have the Committee consider this bill. But slightly different versions of the HR 636 amendments that formed the basis for this bill were already considered and rejected by moderately bipartisan votes in the Committee during markup of S 2658. The Committee is extremely unlikely to take up this bill with that history.

Commentary


It looks like Markey is trying to make a name for himself as the cybersecurity Senator. He is well out in front of his colleagues in suggesting detailed legislative solutions to cybersecurity problems that most of his compatriots have not yet recognized as being serious problems. At this point that kind of leaves him as a voice crying in the wilderness. How long he will be willing to continue to do this in the face of general opposition in the Senate is an interesting political question.

Of course it will take a single high-visibility cyber incident to change Markey from a political odd ball into a prophet. If such an incident (probably with loss of life) occurs during the remainder of this session of Congress, we can expect that this bill would probably form the initial basis for the knee jerk reaction of the Senate.

With that in mind, let’s look at some of the problems that arise in legislation when politicians try to get too detailed in their technical mandates. The use of the term ‘critical software systems’ unnecessarily limits the application of this bill. It should instead read ‘critical control systems’ or maybe ‘critical electronic systems’ if one wanted to include electronic communications systems in the cybersecurity coverage. The way the bill is currently written, for example, completely ignores firmware issues.

In section 6 of the bill we see a similar problem with the use of the term ‘broadband wireless communications’ to describe potential cybersecurity problems caused by customer communications equipment. While wi-fi connections are a potential route of entry into critical aircraft systems, they are not the only consumer communications mode that may cause problems. Cyber radio and even potentially cell phone traffic could prove to be problematic in future configurations. To allow the broadest application of the intent of this section this probably would have been better written as ‘consumer communications equipment’.

One of the complaints I have heard repeatedly from cybersecurity specialists when we start talking about legislation in this realm is that such legislation is likely to be out-of-date or inadequately focused before the legislation is passed. Legislation like this bill is certainly what they are talking about. Legislation needs to be broadly written to allow the regulators with at least some technical background to address the changing technological environment in which the regulated industry operates.


Not only are legislators likely to get the technical details wrong, but legislators take even longer to adapt to change than do regulators. When you add the legislative delay on top of the regulatory delay you end up with obsolete regulations attempting to control completely unforeseen circumstances.

Friday, April 8, 2016

Bills Introduced – 04-07-16

The Senate was still alone on the Hill yesterday and a total of 13 bills were introduced. Of those only one was of potential specific interest to readers of this blog:

S 2764 A bill to require the disclosure of information relating to cyberattacks on aircraft systems and maintenance and ground support systems for aircraft, to identify and address cybersecurity vulnerabilities to the United States commercial aviation system, and for other purposes. Sen. Markey, Edward J. [D-MA]


By the description given this bill looks like the three amendments that Markey introduced on Wednesday to HR 636. That is an interesting move on his part. It would suggest that he does not think that those amendments will be considered on the Senate floor (I made that comment yesterday), but that they have some chance of being considered separately before the end of the year. That is highly unlikely since in an election year neither the Senate or the House typically take up legislation that should have been included in an authorization bill that was passed.

Wednesday, April 6, 2016

RTCA Announces Aeronautical Systems Security Meeting

Today the DOT’s Federal Aviation Administration (FAA) published a meeting notice in the Federal Register (81 FR 20049) for a 3-day public meeting of RTCA Special Committee 216, Aeronautical Systems Security. The meeting will be in Washington, DC on May 3rd thru 5th, 2016.

The agenda includes a meeting on the first day and working group sessions on the second two days. The agenda includes:

• SC-216 New Scope and Terms of Reference review;
• Overview of WG-72;
• Overview of DO-356, Airworthiness Security Methods and Considerations;
• SC-216 Structure and Organization of Work.

WG-72 is a EUROCAE working group looking at developing guidelines to address security concerns for aeronautical systems in order to ensure safe, secure and efficient operations amid the growing use of highly integrated electronic systems and network technologies used on-board aircraft. This makes it roughly a counterpart to SC 216; with whom WG-72 coordinates.

DO-356 is a working document (current version was published in 2014) that addresses the assessment of the acceptability of the airworthiness security risk and the design and verification of the airworthiness security attributes as related to system safety and airworthiness for passenger aircraft.


The meeting is open to the public, but there is only limited seating. The chairman may allow public comments to be made on the topics being discussed. Anyone wishing to make such comments should contact Karan Hofmann (khofmann@rtca.org).

Tuesday, September 1, 2015

FAA Advisory Meeting Will Include Aircraft Cybersecurity

The FAA published a meeting announcement in today’s Federal Register (80 FR 52839) for a public meeting of their Aviation Rulemaking Advisory Committee (ARAC) on September 17th, 2015 in Washington, DC. At this meeting the ARAC will receive status updates from a number of working groups, including the Aircraft Systems Information Security/Protection (ASISP) Working Group.

The ASISP was formed in February of this year and tasked with providing “recommendations regarding Aircraft Systems Information Security/ Protection (ASISP) rulemaking, policy, and guidance on best practices for airplanes and rotorcraft, including both certification and continued airworthiness.”

This meeting is open to the public, but there is limited seating so you should confirm your attendance with Renee Pocius (email Renee.Pocius@faa.gov). There have been provisions made for attending the meeting by telephone and Ms. Pocius should be contacted to make the arrangements for that as well. There will be a public comment period at the meeting. Coordination with Ms. Pocius for presenting an oral statement should be made by September 10th. Physical copies (25 each) of written statements may be provided to Ms. Pocius prior to the meeting or brought to the meeting.

Commentary

It is not clear at this time whether the ASISP update will include any actual recommendations for regulatory actions. Given the short amount of time that the Working Group has been in operation, I would be surprised if this was anything more than a list of areas of potential concern and an idea of how much longer it might be before a recommendation was provided to the full Committee.

It is a shame to see that the FAA is still stuck in the 1960’s. The requirement to deliver 25 physical copies of written statements is archaic in the extreme. Most Federal Agencies use the Federal eRulemaking Portal (www.Regulations.gov) for the purpose of submitting written statements for meetings of this sort. This ensures that not only can the Committee members and staff have ready access to the documents, but the public has such access as well. And don’t even get me started about the failure to provide even a toll free line for the telephone bridge access to this meeting, much less an electronic connection. No wonder the Agency is having problems trying to modernize its traffic control systems; it has not bothered to modernize its administrative procedures.


 
/* Use this with templates/template-twocol.html */