Skip to content

Evidence request lists

FAA Cybersecurity Framework for Aviation

Evidence request list. 15 controls, 15 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

FAA Aviation Cybersecurity: Air Traffic Management and National Airspace System (NAS)

FAA-CSA-NAS
National Airspace System (NAS) and Air Traffic Management Cybersecurity

The FAA's National Airspace System (NAS) cybersecurity program protects the air traffic control + air traffic management infrastructure including: (a) en route + terminal air traffic control systems; (b) the NextGen ADS-B + NextGen Data Communications (Data Comm) + System Wide Information Management (SWIM) infrastructure; (c) NAS networks + facilities + ground systems supporting safe + efficient air traffic management. The NAS cybersecurity baseline is operationalised through: (a) FAA Order 1370.123A internal information-security baseline; (b) the FAA Cybersecurity Operations Center (FAA-CSOC); (c) coordination with CISA + DOT + DOD + Intelligence Community for threat intelligence + incident response; (d) supply chain cybersecurity for NextGen technology vendors. The NAS cybersecurity program operates the FAA's most safety-critical cybersecurity perimeter - a cyber-attack disrupting NAS

Artefacts an auditor will ask for
  • NAS-using operator cybersecurity integration evidence
  • Coordination with FAA-CSOC for major cyber incidents
  • NextGen technology cybersecurity assurance trail
Where this commonly fails
  • NAS interactions assumed inherently secure
  • No incident-response coordination procedure with FAA-CSOC
  • NextGen technology adoption without cybersecurity assurance

FAA Aviation Cybersecurity: Aircraft Cybersecurity Airworthiness (14 CFR Part 25 + ACs + RTCA DO-326A family)

FAA-CSA-AC25-21
Aircraft Network Security Architecture (FAA AC 25-21) - the AISD onboard-network framework

FAA Advisory Circular 25-21 establishes the cybersecurity architecture framework for transport-category aircraft (14 CFR Part 25) covering: (a) aircraft information system domain (AISD) architecture - the cabin systems + IFE + airline operations systems isolated from the safety-critical flight controls + avionics; (b) network security between aircraft domains (avionics + AISD + passenger information services PESD - the THREE-DOMAIN ARINC 811 architecture); (c) external network connectivity including SATCOM + Wi-Fi + cellular + 5G ground stations; (d) cybersecurity-related airworthiness requirements traceable to 14 CFR Part 25 Special Conditions on cybersecurity. AC 25-21 is the operational counterpart to RTCA DO-326A / ED-202A airworthiness security process specification. Aircraft manufacturers (Boeing + Airbus + Embraer + Bombardier + Gulfstream + Cessna + others) apply DO-326A + AC 25-

Artefacts an auditor will ask for
  • AC 25-21 + DO-326A compliance evidence in type certificate + supplemental type certificate (STC) submissions
  • Three-domain (avionics + AISD + PESD) architecture documentation
  • External-connectivity threat modeling + countermeasures
Where this commonly fails
  • Three-domain architecture not maintained (avionics + AISD + PESD isolation broken)
  • External connectivity treated as inherently trustworthy
  • AC 25-21 + DO-326A compliance evidence missing or stale
FAA-CSA-NPRM-2024
2024 FAA NPRM to Codify Cybersecurity as Part 23/25/27/29 Airworthiness Standard

The FAA's August 2024 Notice of Proposed Rulemaking (NPRM) proposes to codify cybersecurity as a standing airworthiness requirement across the 14 CFR Part 23 (normal-category small aeroplanes), Part 25 (transport-category large aeroplanes), Part 27 (normal-category rotorcraft), and Part 29 (transport-category rotorcraft) airworthiness regulations. Currently cybersecurity is addressed through individual Special Conditions imposed on a per-type-certificate basis; the NPRM would harmonise this into standard airworthiness requirements aligned with RTCA DO-326A + EASA Part-IS + EU Commission Implementing Regulation 2023/203 Part-IS. The NPRM addresses: (a) intentional unauthorised electronic interactions (IUEI) airworthiness assessment; (b) security risk acceptance + mitigation for cyber-physical safety effects; (c) continued airworthiness for cybersecurity throughout the aircraft lifecycle i

Artefacts an auditor will ask for
  • Tracking of the 2024 FAA NPRM + the comment period + final rule pipeline
  • Cross-reference to EASA Part-IS for type certificate validity in EU + US
  • Phased-implementation readiness for Part 23/25/27/29
Where this commonly fails
  • NPRM tracked at high level only without per-section impact analysis
  • No EASA Part-IS coordination for dual-validated aircraft + components
FAA-CSA-VulnMgmt
Vulnerability Management and Software Assurance for Aviation Systems

Vulnerability management + software assurance for aviation systems covers: (a) RTCA DO-178C 'Software Considerations in Airborne Systems' (the airworthiness software-assurance baseline - needs_licensed_copy); (b) DO-326A + DO-356A airworthiness security methods integrated with DO-178C; (c) Coordinated Vulnerability Disclosure (CVD) for aircraft + ATM + airport systems through the FAA Aviation CVD process + the joint A-ISAC CVD framework; (d) software bill of materials (SBOM) for aviation software per Executive Order 14028 + the NTIA SBOM minimum elements + RTCA DO-356A appendices; (e) third-party software-supplier vulnerability response SLAs; (f) coordination with CISA Known Exploited Vulnerabilities (KEV) catalog + sectoral threat-intelligence feeds. Aviation vulnerability management is constrained by the long airworthiness-certification cycle - a software patch may require months of ce

Artefacts an auditor will ask for
  • Vulnerability management policy specifying the airworthiness-certification path for patches
  • CVD intake + triage + disclosure procedure
  • SBOM repository for critical aviation software
Where this commonly fails
  • Vulnerability management treats aviation systems like IT - underestimates airworthiness-certification time
  • CVD intake absent + no public-facing security.txt or vulnerability reporting channel
  • SBOM not maintained for critical aviation software

FAA Aviation Cybersecurity: Governance, Strategy and FAA Order 1370.123A

FAA-CSA-Governance
FAA Cybersecurity Strategy, Governance and Order 1370.123A

The FAA Cybersecurity Strategy (updated 2022 + ongoing 2024 update) sets the FAA-wide policy framework for cybersecurity across the aviation system. The Strategy is implemented through FAA Order 1370.123A 'Information Security and Privacy Program' which establishes: (a) the FAA Chief Information Security Officer (CISO) function reporting to the FAA Administrator; (b) the FAA Information Security and Privacy Program covering all FAA information systems + facilities; (c) cybersecurity risk management aligned with NIST RMF + NIST 800-53 + NIST CSF 2.0; (d) the FAA Insider Threat Program; (e) FAA continuity of operations and crisis management for cyber events. The Strategy + Order 1370.123A together establish the FAA cybersecurity governance baseline for the FAA's own systems + indirectly through Advisory Circulars + airworthiness rulemaking for the aviation industry it regulates.

Artefacts an auditor will ask for
  • FAA Cybersecurity Strategy + Roadmap engagement evidence
  • Cross-reference to NIST 800-53 + CSF 2.0 implementation
  • FAA Order 1370.123A compliance for FAA-system-using operators
Where this commonly fails
  • FAA Cybersecurity Strategy not tracked
  • No internal cross-reference between NIST CSF 2.0 + FAA governance
FAA-CSA-Status
FAA Cybersecurity Framework for Aviation - corpus status

This corpus node tracks the FAA Cybersecurity Framework for Aviation as a DISTRIBUTED sector-application view. There is no single FAA-published 'Cybersecurity Framework for Aviation' document; the framework name is a label for the FAA's distributed aviation cybersecurity policy stack covering: (a) FAA Cybersecurity Strategy + Roadmap; (b) FAA Order 1370.123A Information Security and Privacy Program; (c) Advisory Circulars AC 119-1, AC 25-21, AC 23-XX series, AC 27-XX series, AC 120-76D; (d) 14 CFR Part 23/25/27/29 airworthiness cybersecurity provisions (Special Conditions historically; standing rule via 2024 NPRM expected to finalise 2025-2026); (e) RTCA / EUROCAE industry standards DO-326A / DO-356A / DO-355A / DO-178C (copyrighted, needs_licensed_copy); (f) the Aviation Cyber Initiative + Aviation Cybersecurity Working Group inter-agency coordination. Status: REFERENCED - sector-applic

Artefacts an auditor will ask for
  • Tracking of FAA Cybersecurity Strategy + Roadmap updates
  • 2024 NPRM tracking + final-rule preparation
  • ICAO Annex 17 + EASA Part-IS harmonisation analysis
Where this commonly fails
  • Treating this corpus node as the substantive source (it is a sector-application view; substance lives in distributed FAA + RTCA + ICAO sources)

FAA Aviation Cybersecurity: Information Sharing, Incident Response and Inter-Agency Collaboration

FAA-CSA-Operator-Cyber-IR
Aviation Cyber Incident Response and Reporting to FAA and NTSB

FAA + NTSB cyber-incident reporting requirements + processes: (a) cybersecurity incidents affecting aircraft + air traffic control + safety of flight must be reported to the FAA per AC 119-1 + the operator OpsSpec + per FAA Order 1370.123A for FAA systems; (b) cybersecurity events with safety implications fall within National Transportation Safety Board (NTSB) reporting scope under 49 CFR Part 830 'Notification + Reporting of Aircraft Accidents or Incidents'; (c) coordination with CISA via the Aviation Information Sharing and Analysis Center (A-ISAC) for cyber-threat intelligence sharing; (d) FAA's role in the federal Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) covered-entity reporting regime for aviation operators - 72-hour cyber-incident reporting + 24-hour ransom-payment reporting to CISA. The 2025 CIRCIA Final Rule implementation creates the FIRST mandatory fede

Artefacts an auditor will ask for
  • Cyber-incident reporting playbook covering FAA + NTSB + CIRCIA
  • A-ISAC membership + active participation evidence
  • CIRCIA 72-hour + 24-hour ransom reporting procedure
Where this commonly fails
  • No integrated cyber-incident reporting playbook
  • A-ISAC engagement limited to passive observation
  • CIRCIA reporting obligations not integrated into incident-response procedures

FAA Aviation Cybersecurity: Operator and Maintenance Cybersecurity (Operators + Continued Airworthiness)

FAA-CSA-AC119-1
Cybersecurity for Operators (FAA AC 119-1)

FAA Advisory Circular 119-1 'Cybersecurity for Operators' (issued 2020 + updates) provides FAA guidance to Part 119 air carriers + commercial operators on cybersecurity practices to manage cybersecurity risks to operations + safety. AC 119-1 covers: (a) cybersecurity governance + roles + responsibilities at the operator level; (b) cybersecurity risk assessment for aircraft + ground systems + electronic flight bags (EFBs); (c) cybersecurity incident response + reporting; (d) cybersecurity training for flight crew + maintenance + dispatch + ground personnel; (e) cybersecurity supply chain for aircraft components + maintenance providers + IT vendors; (f) coordination with the Aviation Cybersecurity Working Group (ACWG) + Aviation Cyber Initiative (ACI). AC 119-1 is GUIDANCE not regulation: operators voluntarily incorporate it into their FAA-accepted operations specifications (OpsSpecs) + sa

Artefacts an auditor will ask for
  • Operator-level cybersecurity program documented + integrated with the SMS
  • EFB cybersecurity controls per AC 119-1
  • Annual cybersecurity training records for crew + maintenance + dispatch
Where this commonly fails
  • AC 119-1 treated as optional with no integration into SMS
  • EFB cybersecurity gaps
  • Cybersecurity training limited to IT staff not extended to flight + maintenance personnel
FAA-CSA-AC23-XX
Continued Airworthiness for Cybersecurity (AC 23-XX / DO-355A / AC 119-1)

Continued airworthiness for cybersecurity addresses the ongoing-maintenance phase of an aircraft's lifecycle. The framework is articulated through: (a) RTCA DO-355A 'Information Security Guidance for Continuing Airworthiness'; (b) FAA AC 119-1 + AC 23-XX / AC 25-XX series advisory circulars; (c) the airworthiness-directive (AD) mechanism for safety-critical cybersecurity issues - FAA may issue ADs requiring operators to apply cybersecurity patches + reconfigurations within specified timeframes; (d) maintenance organisation (Part 145) cybersecurity program covering technician credentials + software-loading procedures + spare-parts authenticity verification + tooling cybersecurity. Continued airworthiness for cybersecurity is operationally critical because aircraft are in service for 25-40 years, requiring sustained cybersecurity attention across decades + multiple software / hardware upgr

Artefacts an auditor will ask for
  • Continued-airworthiness cybersecurity program + 25-40-year lifecycle plan
  • Airworthiness Directive (AD) compliance tracking for cybersecurity ADs
  • Part 145 maintenance organisation cybersecurity baseline
Where this commonly fails
  • Cybersecurity treated as point-in-time at delivery without lifecycle program
  • Airworthiness Directives for cybersecurity not tracked or applied on time
  • Part 145 maintenance organisation cybersecurity gaps (e.g. tooling unsecured + software loading not validated)
FAA-CSA-EFB
Electronic Flight Bag (EFB) Operational Authorisation Cybersecurity

FAA AC 120-76D (latest revision) addresses Electronic Flight Bag (EFB) operational authorisation including cybersecurity considerations: (a) EFB classification (Class 1 / Class 2 / Class 3 - portable + installed + integrated) with different cybersecurity baselines per class; (b) EFB software cybersecurity including OS hardening + application whitelisting + administrator controls; (c) EFB connectivity cybersecurity for SATCOM + Wi-Fi + cellular data uplinks; (d) EFB chart + manual update integrity verification via cryptographic signatures + chain-of-custody verification; (e) Bring-Your-Own-Device (BYOD) EFB cybersecurity for personal-device EFBs operating in Class 1; (f) coordination with aircraft AISD architecture per AC 25-21 to prevent EFB lateral movement into avionics. EFBs are a common attack-vector concern because they bridge passenger-domain network + crew operational data + somet

Artefacts an auditor will ask for
  • EFB cybersecurity baseline per EFB class
  • BYOD-EFB containerisation + remote-wipe
  • Chart-update cryptographic-verification evidence
Where this commonly fails
  • EFB cybersecurity not specified per EFB class
  • BYOD-EFB containerisation absent
  • Chart-update integrity not cryptographically verified
FAA-CSA-Personnel
Personnel Security Training and Insider Threat

Personnel security + insider threat for aviation cybersecurity covers: (a) FAA Order 1370.123A insider threat program for FAA employees + contractors; (b) operator + airport + maintenance organisation personnel security baseline including STA (Security Threat Assessment) + CHRC (Criminal History Records Check); (c) cybersecurity awareness training for cockpit crew + cabin crew + maintenance technicians + dispatch + ground handlers + airport workers; (d) insider threat detection for high-privilege roles (avionics technicians + system administrators + IT operations); (e) social engineering + phishing awareness specifically for aviation contexts (e.g. supplier impersonation + AOG urgency manipulation); (f) coordination with TSA on personnel screening + the Rap Back program for ongoing-vetting of badged personnel.

Artefacts an auditor will ask for
  • Aviation cybersecurity awareness training records
  • Insider-threat program (technical + behavioural indicators)
  • Ongoing STA / Rap Back vetting
Where this commonly fails
  • Insider-threat detection limited to off-the-shelf tooling
  • Aviation-specific cybersecurity training absent
  • Ongoing-vetting / Rap Back not subscribed

FAA Aviation Cybersecurity: Supply Chain, Workforce and Coordination with International + Federal Regimes

FAA-CSA-International
Coordination with EASA Part-IS, ICAO AVSEC and International Cybersecurity Frameworks

International cybersecurity coordination for aviation covers: (a) EASA Part-IS (EU Commission Implementing Regulation 2023/203) - the EU equivalent of FAA aviation cybersecurity framework, mandatory for EU-registered aircraft + operators + service providers + maintenance organisations + design organisations + production organisations; (b) FAA-EASA Bilateral Aviation Safety Agreement (BASA) + Implementation Procedures for Airworthiness covering mutual cybersecurity acceptance for type certificate cross-validation; (c) ICAO Annex 17 (Aviation Security / AVSEC) which historically addresses physical aviation security + has expanded into cybersecurity (since 2018 amendments); (d) ICAO Aviation Cybersecurity Strategy (2019); (e) ICAO Cybersecurity Action Plan (2022 update + ongoing); (f) coordination with allied nations on aviation cybersecurity standards including Five Eyes + EU Member States

Artefacts an auditor will ask for
  • EASA Part-IS coordination for dual-validated aircraft + operators
  • ICAO Annex 17 cybersecurity provisions tracked
  • BASA cybersecurity mutual recognition file
Where this commonly fails
  • Operating internationally without EASA Part-IS coordination
  • ICAO Annex 17 cybersecurity provisions not tracked
  • Type certificate cybersecurity work not validated under BASA
FAA-CSA-SupplyChain
Supply Chain Cybersecurity (CISA + NIST SSDF + Executive Orders alignment)

Aviation supply chain cybersecurity covers: (a) Executive Order 14028 'Improving the Nation's Cybersecurity' SBOM + secure software development practices + NIST SSDF (SP 800-218) alignment; (b) CISA Cyber Performance Goals (CPGs) v1.0.1 + sector-specific CPGs for aviation; (c) Federal Acquisition Regulation (FAR) + Defense Federal Acquisition Regulation Supplement (DFARS) cybersecurity clauses for aviation contracts including DFARS 252.204-7012 + 7019 + 7020 + 7021 (CMMC); (d) the Foreign Investment Risk Review Modernization Act (FIRRMA) + CFIUS reviews for critical-technology aviation acquisitions; (e) the Countering CCP Drones Act + American Security Drone Act restrictions on country-of-concern aviation electronics; (f) Aviation Cyber Initiative (ACI) supply chain working group + industry-FAA-DOT-DHS-DOD coordination on critical aviation technology supply chains. Supply chain cybersecu

Artefacts an auditor will ask for
  • EO 14028 / SSDF compliance attestation
  • CISA CPG implementation evidence
  • DFARS / CMMC contractor cybersecurity validation
  • Country-of-concern supply-chain due diligence
Where this commonly fails
  • Supply chain cybersecurity limited to direct suppliers without N-th tier
  • SBOM produced but not regularly updated or maintained
  • Country-of-concern supply-chain risk not assessed

FAA Aviation Cybersecurity: UAS, Airports and Emerging Domains

FAA-CSA-Airport
Airport Cybersecurity (FAA + TSA + ACI coordination)

Airport cybersecurity is coordinated across: (a) FAA-certificated airports (14 CFR Part 139) cybersecurity guidance for operational systems (airfield operations + lighting + ground vehicles + ramp operations); (b) Transportation Security Administration (TSA) cybersecurity directives for designated critical airports under SD-1580-21-01 series + TSA Cybersecurity Performance Goals (CPGs); (c) Aviation Cyber Initiative (ACI) joint FAA + TSA + DOT + CISA airport cybersecurity coordination; (d) state + local airport authority cybersecurity programs covering passenger processing systems + baggage handling systems + airport networks + check-in + biometric facial recognition (CBP Biometric Exit Program); (e) airport-specific NIST CSF 2.0 implementations + sector-specific cybersecurity profiles. Airport cybersecurity has matured rapidly post-Colonial Pipeline (2021) + the TSA's expansion of cyber

Artefacts an auditor will ask for
  • Airport cybersecurity program for FAA + TSA-covered facilities
  • TSA cybersecurity directive compliance file
  • Cross-reference to NIST CSF 2.0 airport-sector profile
Where this commonly fails
  • Airport cybersecurity ignored as a 'tenant' concern
  • TSA cybersecurity directives not tracked
  • Biometric system cybersecurity not assessed
FAA-CSA-UAS-Drone
Unmanned Aircraft Systems (UAS / Drones) Cybersecurity

Unmanned Aircraft Systems (UAS) cybersecurity is governed through: (a) 14 CFR Part 107 (small UAS rule) including operational restrictions + remote pilot certification; (b) Remote ID Rule (effective 16 September 2023) requiring UAS to broadcast identification + location information in real-time - has cybersecurity implications for spoofing + jamming + privacy; (c) UAS Traffic Management (UTM) cybersecurity for low-altitude airspace integration - the UTM ecosystem of USS (UAS Service Suppliers) + DSS (Discovery + Synchronization Service); (d) Beyond Visual Line of Sight (BVLOS) operations cybersecurity (NPRM 2024-2025) requiring command-and-control link security + cyber-resilience for autonomous operations; (e) UAS supply chain cybersecurity including the FAA's screening against UAS from certain countries of concern per the Countering CCP Drones Act + American Security Drone Act. UAS cybe

Artefacts an auditor will ask for
  • UAS cybersecurity policy covering Part 107 + Remote ID compliance
  • UTM cybersecurity integration for USS + DSS
  • Supply-chain due diligence for country-of-concern drone components
Where this commonly fails
  • UAS cybersecurity treated separately from manned-aircraft cybersecurity program
  • Remote ID privacy implications not addressed
  • Country-of-concern drone supply chain not screened
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FAA Cybersecurity Framework for Aviation framework page.