GAO: TSA Hasn't Defined Its Aviation Cyber Role
FAA clearly assigned its responsibilities; TSA didn't, and industry stakeholders told GAO the confusion that creates is itself a risk.
TL;DR
The GAO found FAA has clearly defined the roles of the entities responsible for its aviation cybersecurity goals. TSA hasn't. Its 2018 Cybersecurity Roadmap is outdated, no longer aligned with DHS's latest cybersecurity strategy, and doesn't identify which offices are responsible for airport and aircraft operator security programs. Industry stakeholders told GAO they were confused about TSA's role and guidance. The FAA Reauthorization Act of 2024 mandated the review.
The asymmetry is the finding. FAA defined the roles and responsibilities of the entities that carry out its aviation cybersecurity goals and objectives. TSA, which oversees airport and aircraft operator security programs, did not. Its 2018 Cybersecurity Roadmap doesn't name the offices accountable for implementation or define the agency's cybersecurity role in its own oversight programs. GAO's conclusion: until TSA updates the roadmap, it "cannot fully hold relevant entities accountable or enable continuous improvements."
Industry noticed. Airlines and trade groups told GAO they were confused about TSA's role and found some of the guidance hard to parse. Jennifer Franks, who directs GAO's Center for Enhanced Cybersecurity, told Federal News Network that stakeholders flagged the need to "streamline that information" early in the review. The confusion matters operationally, she said, the handoff between TSA-managed ground systems and FAA-managed airspace systems involves interconnected networks where unidentified risks can accumulate.
The 2018 roadmap also predates the current DHS Cybersecurity Strategy and no longer aligns with it. And there's a budget problem on the FAA side: seven FAA entities carry out the agency's cybersecurity strategy, funded by budget requests ranging from roughly $42 million to $11 billion across fiscal years 2024 through 2026. But FAA hasn't fully reported that cybersecurity spending, making it harder to track what's being bought and why.
The gaps aren't in one agency. They sit in the seam between two. FAA has done its part on role definition. TSA hasn't. Until it does, the industry that operates in both domains is working from incomplete guidance.
Published ·Deep Fathom